[openstack-dev] [tripleo] Fernet Key rotation
Adam Young
ayoung at redhat.com
Wed Aug 10 14:11:50 UTC 2016
On 08/09/2016 09:21 PM, Adam Young wrote:
> On 08/09/2016 06:00 PM, Zane Bitter wrote:
>>
>> In either case a good mechanism might be to use a Heat Software
>> Deployment via the Heat API directly (i.e. not as part of a stack) to
>> push changes to the servers. (I say 'push' but it's more a case of
>> making the data available for os-collect-config to grab it.)
>
> This is the part that interests me most. The rest, I'll code in
> python and we can call either from mistral or from Cron. What would a
> stack like this look like? Are there comparable examples?
>
>
> __________________________________________________________________________
>
> OpenStack Development Mailing List (not for usage questions)
> Unsubscribe:
> OpenStack-dev-request at lists.openstack.org?subject:unsubscribe
> http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev
So, another aspect to the problem is also that this needs to be done
initially as part of the overcloud deployment. If we go Fernet, the
keys need to be in place when the Keystone servers boot.
More information about the OpenStack-dev
mailing list