Bug 1293274 - keystone tokens are not flushed on the instack-node
Summary: keystone tokens are not flushed on the instack-node
Keywords:
Status: CLOSED DUPLICATE of bug 1289614
Alias: None
Product: Red Hat OpenStack
Classification: Red Hat
Component: instack-undercloud
Version: 8.0 (Liberty)
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
: 8.0 (Liberty)
Assignee: James Slagle
QA Contact: yeylon@redhat.com
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2015-12-21 09:40 UTC by Attila Fazekas
Modified: 2016-04-18 07:11 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2015-12-21 13:31:53 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Description Attila Fazekas 2015-12-21 09:40:44 UTC
Description of problem:
I have 181993 token in the token table in small deployment after 10 day of usage.

Version-Release number of selected component (if applicable):
instack-0.0.8-1.el7ost.noarch
instack-undercloud-2.2.0-1.el7ost.noarch
openstack-tripleo-0.0.7-1.el7ost.noarch
openstack-tripleo-image-elements-0.9.7-1.el7ost.noarch
openstack-tripleo-puppet-elements-0.0.2-1.el7ost.noarch
openstack-tripleo-heat-templates-0.8.7-2.el7ost.noarch
openstack-tripleo-common-0.0.2-4.el7ost.noarch

Expected results:

The expired tokens are removed from the database within 1-3 hour.


Additional info:

On the overcloud I have a crontab entry for the keystone user:
sudo crontab -l -u keystone
# HEADER: This file was autogenerated at 2015-12-11 05:29:31 -0500 by puppet.
# HEADER: While it can still be managed manually, it is definitely not recommended.
# HEADER: Note particularly that the comments starting with 'Puppet Name' should
# HEADER: not be deleted, as doing so could cause duplicate cron jobs.
# Puppet Name: keystone-manage token_flush
PATH=/bin:/usr/bin:/usr/sbin SHELL=/bin/sh
1 0 * * * sleep `expr ${RANDOM} \% 3600`; keystone-manage token_flush >>/var/log/keystone/keystone-tokenflush.log 2>&1


I would like to see a similar crontab entry for the undercloud,
alternatively  KTLW token cloud be used,
which does not populates the token table.

Comment 2 Mike Burns 2015-12-21 13:31:53 UTC

*** This bug has been marked as a duplicate of bug 1289614 ***


Note You need to log in before you can comment on or make changes to this bug.