To support cleaning the token table, puppet needs to schedule a periodic task: keystone-manage token-flush. This should probably run once a minute, since the longer we go between runsm, the more of a performance impact we might see from table locking.
It'll require us to use a new Puppet module. Setting Mid-Feb so we have time to test it properly.
After investigating I found that Puppet actually has cron job resource. Since this bug is A2 targeted we need patch ASAP, hence I'm taking it.
Tested with: openstack-keystone-2013.2.2-1.el6ost.noarch python-keystoneclient-0.4.1-4.el6ost.noarch python-keystone-2013.2.2-1.el6ost.noarch
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHSA-2014-0233.html