[Openstack] [openstack][keystone]Keystone Token HA

Ross Annetts ross.annetts at digitalpacific.com.au
Mon Dec 21 05:24:20 UTC 2015


Hi Ajay,

Memcached does not provide any replication, you basically just set up 
individual memcached servers and specify multiple servers on the client 
side. So if you lose one of the memcached servers (or its restarted) 
then you lose all the data that it holds, but at least the client has 
other places to store data. If using UUID tokens then you are going to 
want to use SQL backend in a HA environment. Alternatively have a look 
at using fernet token provider instead, for fernet you only need to 
worry about rotation and replication of keys rather than the replication 
of actual tokens themselves.

Regards,
Ross

On 18/12/2015 6:26 PM, Ajay Kalambur (akalambu) wrote:
> Hi
> If we deploy Keystone using memcached as token backend we see that 
> bringing down 1 of 3 memcache servers results in some tokens getting 
> invalidated. Does memcached not support replication of tokens
> So if we wanted HA w.r.t keystone tokens should we use SQL backend for 
> tokens?
>
> Ajay
>
>
>
> _______________________________________________
> Mailing list: http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack
> Post to     : openstack at lists.openstack.org
> Unsubscribe : http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openstack.org/pipermail/openstack/attachments/20151221/f3d3482a/attachment.html>


More information about the Openstack mailing list