Bug 1412816
| Summary: | [RFE] Multi-site: deploy overcloud using pre-existing Keystone database | ||
|---|---|---|---|
| Product: | Red Hat OpenStack | Reporter: | Ian Pilcher <ipilcher> |
| Component: | openstack-tripleo-heat-templates | Assignee: | Jiri Stransky <jstransk> |
| Status: | CLOSED WONTFIX | QA Contact: | Arik Chernetsky <achernet> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | high | ||
| Version: | 11.0 (Ocata) | CC: | hrybacki, jcoufal, mburns, nkinder, rcritten, rhel-osp-director-maint, royoung, scohen, taosawa, yohmura |
| Target Milestone: | --- | Keywords: | FutureFeature |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2018-12-08 18:14:21 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 1476902, 1592486 | ||
|
Description
Ian Pilcher
2017-01-12 21:30:07 UTC
A few additional thoughts around this ... We believe that we won't hit the SELECT ... FOR UPDATE issue that forces us to use a single Galera writer in the general case: https://bugs.launchpad.net/keystone/+bug/1325143 Rolling N+1 upgrades should be possible by following the correct procedure: https://specs.openstack.org/openstack/keystone-specs/specs/keystone/newton/manage-migration.html This may require logic to disable the db_sync command that we use to upgrade the database schema in the normal upgrade case. Also, we're going to want to put each region's service accounts (neutron, heat, nova, ... maybe admin) into a separate region-specific Keystone domain in order to avoid collisions between the different regions. This domain will still use "local" (Keystone database) storage, and is distinct from the Active Directory/LDAP/SAML/etc. domain(s) used for normal user authentication. I'm not sure if this is possible with TripleO today. *** Bug 1368965 has been marked as a duplicate of this bug. *** Closing as WONT FIX. Upstream is presently holding discussions related to how Keystone will fit into the Edge model. |