Re: [Openstack-operators] Database cleanup policy

2014-10-30 Thread Morgan Fainberg
Hi Abel, For Keystone we already have a way to prune out expired records: keystone-manage token_flush This can be run via cron (recommended). The reason for the side band tool is that keystone does not have an internal scheduler for periodic tasks (not a common use keystone needs to do across

[Openstack-operators] [Keystone] LDAP Assignment Backend Use Survey

2015-01-06 Thread Morgan Fainberg
e LDAP Assignment backend which only contains Projects/Tenants and Roles/Grants. Cheers, Morgan Fainberg ___ OpenStack-operators mailing list OpenStack-operators@lists.openstack.org http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-operators

Re: [Openstack-operators] [Keystone] LDAP Assignment Backend Use Survey

2015-01-07 Thread Morgan Fainberg
As a note, since I've seen some responses about users and/or groups on this survey, I will be sending a survey about identity out today. This survey is strictly about projects/tenants and roles/role assignments in LDAP. Sent via mobile > On Jan 6, 2015, at 11:22, Morgan Fainber

[Openstack-operators] [Keystone] LDAP Identity Use Survey

2015-01-12 Thread Morgan Fainberg
The Keystone development team is looking for deployment feedback regarding the use of the LDAP Identity backend. The Identity backend only covers Users and Groups. We are looking to get an idea of types (read-only, read-write, etc) and reasons for use of the LDAP backend. The answers to this su

[Openstack-operators] [Keystone] Deprecation of LDAP Assignment (Only Affects Project/Tenant/Role/Assignment info in LDAP)

2015-01-28 Thread Morgan Fainberg
ading through the whole email! Please feel free to chat with the development team on IRC or via the Mailing List to discuss any other issues / concerns related to this change. Cheers, Morgan Fainberg Keystone PTL ___ OpenStack-operators mailing list Open

[Openstack-operators] [all] SQL Schema Downgrades: A Good Idea?

2015-01-29 Thread Morgan Fainberg
From an operator perspective I wanted to get input on the SQL Schema Downgrades. Today most projects (all?) provide a way to downgrade the SQL Schemas after you’ve upgraded. Example would be moving from Juno to Kilo and then back to Juno. There are some odd concepts when handling a SQL migration

Re: [Openstack-operators] [openstack-dev] Resources owned by a project/tenant are not cleaned up after that project is deleted from keystone

2015-02-02 Thread Morgan Fainberg
I think the simple answer is "yes". We (keystone) should emit notifications. And yes other projects should listen. The only thing really in discussion should be: 1: soft delete or hard delete? Does the service mark it as orphaned, or just delete (leave this to nova, cinder, etc to discuss) 2:

Re: [Openstack-operators] [openstack-dev] Resources owned by a project/tenant are not cleaned up after that project is deleted from keystone

2015-02-02 Thread Morgan Fainberg
On February 2, 2015 at 1:31:14 PM, Joe Gordon (joe.gord...@gmail.com) wrote: On Mon, Feb 2, 2015 at 10:28 AM, Morgan Fainberg wrote: I think the simple answer is "yes". We (keystone) should emit notifications. And yes other projects should listen. The only thing really in discuss

Re: [Openstack-operators] [all] SQL Schema Downgrades: A Good Idea?

2015-02-08 Thread Morgan Fainberg
As a follow up on this topic, the specification for this change has been proposed to the openstack-specs (cross-project) specifications repository:   https://review.openstack.org/#/c/152337/ Feedback from the operators would be greatly appreciated. —Morgan --  Morgan Fainberg On January 30

[Openstack-operators] [Keystone] Deprecation of Eventlet deployment in Kilo (Removal for "M"-release)

2015-02-19 Thread Morgan Fainberg
The Keystone development team is planning to deprecate deployment of Keystone under Eventlet during the Kilo cycle. Support for deploying under eventlet will be dropped as of the “M”-release of OpenStack. The reasoning behind this move is multifaceted but the core of the reasons are as follows:

Re: [Openstack-operators] OpenStack services and ca certificate config entries

2015-03-25 Thread Morgan Fainberg
This sounds like something we can bake into the session object to make it easier / more consistent. --Morgan Sent via mobile > On Mar 25, 2015, at 14:03, John Dewey wrote: > > I faced this very issue in the past. We solved the problem by adding the CA > to the system bundle (as you stated)

Re: [Openstack-operators] logging for Keystone on user/project delete/create operations

2015-04-16 Thread Morgan Fainberg
it, and explaining what you just said here: >> >> https://blueprints.launchpad.net/keystone > > Adding a blueprint for discussion would be a good idea if you think you want > a change to the project. > > >> >> I’d also try to contact Keystone PTL (I’m not

Re: [Openstack-operators] [openstack-dev] [tc] Who is allowed to vote for TC candidates

2015-05-01 Thread Morgan Fainberg
gt; 427 North Tatnall Street > Ste. 58461 > Wilmington, Delaware 19801-2230 > Toll-free: (844) 4-AQORN-NOW ext. 101 > International: +1 302-387-4660 > Direct: +1 916-246-2072 > > > On Fri, May 1, 2015 at 12:22 PM, Morgan Fainberg < > morgan.fainb...@gmail.com> wr