feat(keystone): use shared memcached cache for mod_auth_openidc - #12542
Draft
bbobrov wants to merge 1 commit into
Draft
feat(keystone): use shared memcached cache for mod_auth_openidc#12542bbobrov wants to merge 1 commit into
bbobrov wants to merge 1 commit into
Conversation
Point mod_auth_openidc at the shared memcached instance (OIDCCacheType memcache) so any keystone-api replica can validate the OIDC auth state/nonce and read the server-side session, removing the intrinsic need for ingress session affinity during the WebSSO flow. The memcached host uses the short ".svc" form to stay portable across clusters (the FQDN svc.kubernetes.<region>.<tld> does not resolve where cluster.local is used), mirroring the SAML SP's StorageService approach. Entries are namespaced with an oidc_ key prefix and encrypted at rest via the existing OIDCCryptoPassphrase (OIDCCacheEncrypt defaults On); the connection is unauthenticated as memcached runs without SASL/TLS.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Point mod_auth_openidc at the shared memcached instance (OIDCCacheType memcache) so any keystone-api replica can validate the OIDC auth state/nonce and read the server-side session, removing the intrinsic need for ingress session affinity during the WebSSO flow.
The memcached host uses the short ".svc" form to stay portable across clusters (the FQDN svc.kubernetes.. does not resolve where cluster.local is used), mirroring the SAML SP's StorageService approach. Entries are namespaced with an oidc_ key prefix and encrypted at rest via the existing OIDCCryptoPassphrase (OIDCCacheEncrypt defaults On); the connection is unauthenticated as memcached runs without SASL/TLS.