Repository navigation
Use inet6-aware memcached_servers for [keystone_authtoken] in nova.conf - #1217
yushoyamaguchi wants to merge 1 commit into
Conversation
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: yushoyamaguchi The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
Hi @yushoyamaguchi. Thanks for your PR. I'm waiting for a openstack-k8s-operators member to verify that this patch is reasonable to test. If it is, they should reply with Regular contributors should join the org to skip this step. Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 SummarySummary by CodeRabbit
WalkthroughThe Nova configuration template selects Memcached server addresses based on the TLS setting. Functional tests compare the rendered server lists with values from the Memcached instance. ChangesMemcached server configuration
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix · Severity of issue fixed: Medium Merge Risk: ⚪ Minimal · up to No actionable defect is established in the reviewed change. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
Build succeeded (check pipeline). ✔️ openstack-meta-content-provider SUCCESS in 3h 47m 15s |
Issue with unconditional switch to MemcachedServersWithInetThis PR will fix non-TLS IPv6 deployments, but will break TLS-enabled deployments. Here's why: Background
See How keystonemiddleware works
The ProblemWhen TLS is enabled:
The Correct FixShould match the pattern in {{if .MemcachedTLS}}
memcached_servers={{ .MemcachedServers }} // Port 11212, pymemcache handles IPv6
memcache_tls_enabled = true
{{else}}
memcached_servers={{ .MemcachedServersWithInet }} // Port 11211 with inet6: prefix
{{end}}This way:
Historical ContextCommit 2750f8e switched from |
lmiccini
left a comment
There was a problem hiding this comment.
Should match the pattern in [cache] section:
{{if .MemcachedTLS}}
memcached_servers={{ .MemcachedServers }} // Port 11212, pymemcache handles IPv6
memcache_tls_enabled = true
{{else}}
memcached_servers={{ .MemcachedServersWithInet }} // Port 11211 with inet6: prefix
{{end}}
07352f4 to
0dfba4f
Compare
Use MemcachedServersWithInet in [keystone_authtoken] when memcached TLS is disabled for IPv6 usecase. Signed-off-by: Yusho Yamaguchi <ysh.824@outlook.jp>
0dfba4f to
badf6d1
Compare
|
@lmiccini |
fix #1216
[cache]'s non-TLS branch already renders memcache_servers with the inet6: prefix (.MemcachedServersWithInet), required by python-memcached on IPv6 deployments — otherwise it defaults to AF_INET and DNS resolution fails outright. [keystone_authtoken] was still using the plain .MemcachedServers variable, so token cache lookups never connect and every authenticated request falls through to a live Keystone call after ~30s of failed lookups (3 servers × ~2 failed A-record attempts each).