Skip to content

chore: release - #754

Open
openstack-experimental-release-plz[bot] wants to merge 1 commit into
mainfrom
release-plz-2026-06-05T09-00-15Z
Open

openstack-experimental-release-plz[bot] wants to merge 1 commit into
mainfrom
release-plz-2026-06-05T09-00-15Z

Conversation

@openstack-experimental-release-plz

@openstack-experimental-release-plz openstack-experimental-release-plz Bot commented Jun 5, 2026

Copy link
Copy Markdown
Contributor

🤖 New release

  • openstack-keystone-config: 0.1.0
  • openstack-keystone-core-types: 0.1.1
  • openstack-keystone-api-types: 0.1.0 -> 0.1.1 (✓ API compatible changes)
  • openstack-keystone-audit: 0.1.0
  • openstack-keystone-auth-plugin-core: 0.1.0
  • openstack-keystone-key-repository: 0.1.0
  • openstack-keystone-local-emergency-store: 0.1.0
  • openstack-keystone-metrics: 0.1.0
  • openstack-keystone-storage-api: 0.1.0
  • openstack-keystone-core: 0.1.1 -> 0.1.2 (✓ API compatible changes)
  • openstack-keystone-storage-crypto: 0.1.0
  • openstack-keystone-storage-crypto-pkcs11: 0.1.0
  • openstack-keystone-storage-crypto-tpm: 0.1.0
  • openstack-keystone-distributed-storage: 0.1.0 -> 0.1.1 (✓ API compatible changes)
  • openstack-keystone-api-key-driver-raft: 0.1.0
  • openstack-keystone-auth-plugin-runtime: 0.1.0
  • openstack-keystone-password-hashing: 0.1.0
  • openstack-keystone-appcred-driver-sql: 0.1.0
  • openstack-keystone-assignment-driver-sql: 0.1.0
  • openstack-keystone-assignment-driver-openfga: 0.1.0
  • openstack-keystone-catalog-driver-sql: 0.1.0
  • openstack-keystone-credential-driver-sql: 0.1.0
  • openstack-keystone-auth-plugin-identity-driver-raft: 0.1.0
  • openstack-keystone-domain-config-driver-fs: 0.1.0
  • openstack-keystone-domain-config-driver-sql: 0.1.0
  • openstack-keystone-federation-driver-sql: 0.1.0
  • openstack-keystone-identity-driver-ldap: 0.1.0
  • openstack-keystone-identity-driver-sql: 0.1.0
  • openstack-keystone-idmapping-driver-sql: 0.1.0
  • openstack-keystone-k8s-auth-driver-raft: 0.1.0
  • openstack-keystone-k8s-auth-driver-sql: 0.1.0
  • openstack-keystone-mapping-driver-raft: 0.1.0
  • openstack-keystone-oauth2-client-driver-raft: 0.1.0
  • openstack-keystone-oauth2-key-driver-raft: 0.1.0
  • openstack-keystone-oauth2-session-driver-raft: 0.1.0
  • openstack-keystone-policy-store-driver-sql: 0.1.0
  • openstack-keystone-resource-driver-sql: 0.1.0
  • openstack-keystone-revoke-driver-sql: 0.1.0
  • openstack-keystone-role-driver-sql: 0.1.0
  • openstack-keystone-scim-driver-raft: 0.1.0
  • openstack-keystone-token-driver-fernet: 0.1.1
  • openstack-keystone-token-driver-jws: 0.1.0
  • openstack-keystone-token-restriction-driver-sql: 0.1.0
  • openstack-keystone-trust-driver-sql: 0.1.0
  • openstack-keystone-webauthn: 0.1.0
  • openstack-keystone: 0.1.1 -> 0.1.2 (✓ API compatible changes)
  • openstack-keystone-cli-manage: 0.1.0
Changelog

openstack-keystone-config

0.1.0 - 2026-09-19

Added

  • (devstack) Pilot ksm SPIFFE mTLS transport (#1239)
  • Hot-reload fs per-domain config files (#1225)
  • (adr0034) Route assignment ops per domain (#1219)
  • (adr0034) Add per-domain driver config surface (#1216)
  • (assignment) Add OpenFGA assignment driver (#1206)
  • (domain-config) Add resolution layer (#1199)
  • (domain-config) Add filesystem driver (#1197)
  • (spiffe) Derive spiffe claims (#1193)
  • Add vendor data JWT API for SPIRE integration (#1192)
  • (core) Reconnect database connection on new config (#1188)
  • (policy) Implement legacy Policy API (/v3/policies) (#1127)
  • Add domain config types and backend trait (#1138)
  • (adr0031) Add HTTP request metrics (#1134)
  • (config) Support configurable log file rotation (#1128)
  • Add connection_debug to tune SQL query logging (#1109)
  • (pagination) Add pagination to remaining places (#1106)
  • (config) Revoke Vault token on shutdown (#1088)
  • Generalize marker pagination for v3/v4 lists (#1086)
  • (config) Add Vault-backed configuration (#1051)
  • (logging) Add native journald log writer (#1081)
  • (identity) Add PATCH to few resources (#1076)
  • (ldap) Add LDAP identity driver (#1047)
  • (adr0028) Add local-quorum-bypass emergency rotation (#1032)
  • Add catalog CRUD API and bootstrap support (#1029)
  • (adr0026) Add RFC 8628 Device Authorization Grant (#1023)
  • (adr0026) Add authorization code flow with PKCE (#1015)
  • (adr0026) Add client_credentials token endpoint (#1014)
  • (adr0026) Phase 2 client registration & OIDC discovery (#1013)
  • (adr0026) Phase 0 token abstraction and JWS driver (#1010)
  • (api) capture client IP via proxy headers & SPIFFE (Start capturing client information in the request processing #358 follow-up) (#908)
  • (identity) Add per-user auth rate limiting (#996)
  • (adr0025) Complete imlpementation (#969)
  • (api) Add global IP rate limiting framework (ADR-0022 phase 1) (#846)
  • (scim) Harden RFC 7644 compliance, add docs (#968)
  • (adr0025) Phase 1 (1.1+1.2) (#952)
  • (security) Wrap secrets with secrecy crate (#369) (#912)
  • (scim) ADR 0024 - Phase 5 (#951)
  • (scim) ADR 0024 - Phase 1+2 (#925)
  • (fernet) Unify credential/token key repositories (#915)
  • Start ADR 0025 immplementation (#911)
  • (credential) Implement Phase 3 of ADR 0019 (#909)
  • Prepare PKCS#11/TPM KEK support in storage (#907)
  • (credential) Implement ADR 0019 phases 1-2 (#897)
  • Implement stateless SCIM ingress auth (ADR 0021) (#891)
  • (auth) Password hashing parity with Python Keystone (#859)
  • (audit) Implement CADF audit framework Phase 2 (#872)
  • (storage) SPIFFE checks, RBAC, rate limiting, auto-join (#861)
  • (storage) Harden preflight and erase dev KEK (#860)
  • Add bootstrap cli command (#809)
  • (mapping) ADR-0020 (mapping engine) phase 1 (#794)
  • Add inter-provider event notification system (#784)
  • Add SO_PEERCRED peer credential validation (#775)
  • Validate password for compliance conformity (#774)
  • Enforce minimum range boundaries for security
  • Add role-imply rest api (#750)
  • Add user update functionality (#747)
  • Make drivers more dynamic (#737)
  • Add keystone container with opa and policies (#738)
  • Add Admin interface over the UDS (#735)
  • Add spiffe provider (#733)
  • Introduce SecurityContext (#710)
  • Add skeleton for the spiffe mTLS integration (#695)
  • Implement ConfigManager for config watching (#691)
  • Improve the code (#686)
  • Add k8s-auth raft driver (#676)
  • Add raft support under skaffold (#667)
  • Introduce raft backend for webauthn (#658)
  • Introduce the keystone-manage cli managing raft (#656)

Fixed

  • Next round of security review fixes (#1241)
  • (adr0034) Post implementation fixes (#1223)
  • Avoid blocking notify's event thread in watch_loop (#1125)
  • Fix flaky test (#1110)
  • (security) Address security review findings (#1049)
  • (passkey) Prevent user enumeration (#905)

Other

  • (config) Fix flaky notify watcher tests (#1112)
  • Revise documentation layout (#1069)
  • Moves health and metrics endpoints to dedicated listener on separate port (#910)
  • Move jsonwebtoken to keystone crate (#820)
  • mapping engine phase 3 - migrate SPIFFE (#811)
  • Rename identity_mapping to idmapping (#788)
  • Replace Regex with str::find for db connection (#760)
  • Redesign SecurityContext with two-phase validation (#717)
  • Split out remaining sql drivers (#633)
  • Split config into standalone crate (#628)

openstack-keystone-core-types

0.1.1 - 2026-09-19

Added

  • Hot-reload fs per-domain config files (#1225)
  • (adr0034) Route assignment ops per domain (#1219)
  • (adr0034) Build per-instance assignment backends (#1218)
  • (adr0034) Add per-domain driver config surface (#1216)
  • Resolve local/public ids for non-default backends (#1207)
  • (assignment) Add OpenFGA assignment driver (#1206)
  • (idmapping) Add id-mapping write paths (#1205)
  • (domain-config) Dispatch identity ops per domain (#1202)
  • (domain-config) Add resolution layer (#1199)
  • (domain-config) Add filesystem driver (#1197)
  • Add vendor data JWT API for SPIRE integration (#1192)
  • Add domain config SQL driver (#1139)
  • (policy) Implement legacy Policy API (/v3/policies) (#1127)
  • Add domain config types and backend trait (#1138)
  • Add cargo-fuzz targets (#1130)
  • Add OS-EP-FILTER provider CRUD to the catalog (#1075)
  • (pagination) Add pagination to remaining places (#1106)
  • Add immutable option for project, domain, role (#1097)
  • Generalize marker pagination for v3/v4 lists (#1086)
  • (identity) Add trust create/delete and REST CRUD (#1079)
  • (catalog) Expose /v3/regions REST API (#1078)
  • (identity) Add PATCH to few resources (#1076)
  • (ldap) Add LDAP identity driver (#1047)
  • (test) Add tempest identity compatibility (#998)
  • (adr0028) Add local-quorum-bypass emergency rotation (#1032)
  • Add catalog CRUD API and bootstrap support (#1029)
  • (adr0026) Add RFC 8628 Device Authorization Grant (#1023)
  • (adr0026) Phase 6a (#1017)
  • (adr0026) Add Phase 5 offline token verification (#1016)
  • (adr0026) Add authorization code flow with PKCE (#1015)
  • (adr0026) Add client_credentials token endpoint (#1014)
  • (adr0026) Phase 2 client registration & OIDC discovery (#1013)
  • (adr0026) Phase 1 crypto engine & JWKS endpoint (#1011)
  • (adr0026) Phase 0 token abstraction and JWS driver (#1010)
  • (identity) Add per-user auth rate limiting (#996)
  • (adr0025) Complete imlpementation (#969)
  • (api) Add global IP rate limiting framework (ADR-0022 phase 1) (#846)
  • (adr0025) Phase 1 (1.1+1.2) (#952)
  • (security) Wrap secrets with secrecy crate (#369) (#912)
  • (scim) ADR 0024 - Phase 4 (protocol surface completion) (#929)
  • (scim) ADR 0024 - Phase 3 (#928)
  • (scim) ADR 0024 - Phase 1+2 (#925)
  • (credential) Implement Phase 3 of ADR 0019 (#909)
  • (credential) Implement ADR 0019 phases 1-2 (#897)
  • Implement stateless SCIM ingress auth (ADR 0021) (#891)
  • Audit framework (ADR-0023) phase 3 (#880)
  • (audit) Implement CADF audit framework Phase 2 (#872)
  • Migrate federation to new mapping engine (#839)
  • Add access rule CRD to appcred provider (#806)
  • ADR-0020 mapping phase 4 (#818)
  • (mapping) ADR-0020 (mapping engine) phase 1 (#794)
  • Add endpoint CRUD to catalog provider (#785)
  • Add inter-provider event notification system (#784)
  • Add service CRUD to the catalog provider (#773)
  • Validate password for compliance conformity (#774)
  • Return 401 on roleless scoped contexts (#742)
  • Add region CRUD to catalog SQL driver (#761)
  • Add role-imply rest api (#750)
  • Add role imply API (#749)
  • Add user update functionality (#747)
  • Add spiffe binding API (#740)
  • Add Admin interface over the UDS (#735)
  • Add spiffe provider (#733)
  • Expand role info in expand_implied_roles (#730)
  • Introduce SecurityContext (#710)
  • Improve the code (#686)
  • Add k8s-auth raft driver (#676)
  • Introduce the keystone-manage cli managing raft (#656)

Fixed

  • Next round of security review fixes (#1241)
  • Use proper token issued_at time (#1194)
  • Register UserType in OpenAPI components schema (#1151)
  • Fix ID sanitizer and capture client IP in audit (#1126)
  • (api) Default enabled/domain_id on create (#1073)
  • (security) Address security review findings (#1049)
  • (federation) Allow long external unique_id values (#1033)
  • Unify ApiClient scope validation, fix nextest filter (#947)
  • Finalize ADR 0021 work (#906)
  • Resolve raft replication state races (#884)
  • (k8s_auth) Flatten k8s.aud claim from JWT TokenReview (#834)
  • Align "extra" property handling (#787)

Other

  • (api) Harden v3 authorization and authentication coverage (#1166)
  • (identity) Remove service account API methods (#1152)
  • Extend workspace unsafe/unwrap/expect lints (#1120)
  • Revise documentation layout (#1069)
  • (security) Close mutation-testing gaps in auth/policy (#1056)
  • Move jsonwebtoken to keystone crate (#820)
  • mapping engine phase 3 - migrate SPIFFE (#811)
  • Rename identity_mapping to idmapping (#788)
  • Make resolve_implied_roles optional (#764)
  • Redesign SecurityContext with two-phase validation (#717)
  • Unify state initialization in test (#642)
  • Small optimization of the derives (#638)
  • Split the core-types crate (#640)

openstack-keystone-api-types

0.1.1 - 2026-09-19

Added

  • (devstack) Pilot ksm SPIFFE mTLS transport (#1239)
  • (assignment) Add OpenFGA assignment driver (#1206)
  • (domain-config) Dispatch identity ops per domain (#1202)
  • (domain-config) Add configuration API (#1201)
  • Add vendor data JWT API for SPIRE integration (#1192)
  • (api) Log response body for all 4xx/5xx errors (#1171)
  • (api) Log error details in IntoResponse (#1169)
  • (policy) Implement legacy Policy API (/v3/policies) (#1127)
  • Filter user listing by type (#813)
  • (loadtest) Add more auth tests (#1119)
  • (pagination) Add pagination to remaining places (#1106)
  • Add immutable option for project, domain, role (#1097)
  • Generalize marker pagination for v3/v4 lists (#1086)
  • (identity) Add trust create/delete and REST CRUD (#1079)
  • (catalog) Expose /v3/regions REST API (#1078)
  • (identity) Add PATCH to few resources (#1076)
  • (ldap) Add LDAP identity driver (#1047)
  • (test) Add tempest identity compatibility (#998)
  • (adr0028) Add local-quorum-bypass emergency rotation (#1032)
  • Add catalog CRUD API and bootstrap support (#1029)
  • (adr0026) Extend keystone-manage oauth2 CLI (#1020)
  • (adr0026) Phase 6a (#1017)
  • (adr0026) Add client_credentials token endpoint (#1014)
  • (adr0026) Phase 2 client registration & OIDC discovery (#1013)
  • (adr0026) Phase 1 crypto engine & JWKS endpoint (#1011)
  • (identity) Add per-user auth rate limiting (#996)
  • (adr0025) Complete imlpementation (#969)
  • (identity) Implement user password change endpoint (#970)
  • (api) Add global IP rate limiting framework (ADR-0022 phase 1) (#846)
  • (adr0025) Phase 1 (1.1+1.2) (#952)
  • (security) Wrap secrets with secrecy crate (#369) (#912)
  • (scim) ADR 0024 - Phase 5 (#951)
  • (scim) ADR 0024 - Phase 1+2 (#925)
  • (credential) Implement Phase 3 of ADR 0019 (#909)
  • ADR 0021 admin surface, simulate-access, and janitor (#896)
  • Implement stateless SCIM ingress auth (ADR 0021) (#891)
  • Migrate federation to new mapping engine (#839)
  • ADR-0020 mapping phase 4 (#818)
  • (mapping) ADR-0020 phase 2 (#807)
  • (mapping) ADR-0020 (mapping engine) phase 1 (#794)
  • Validate password for compliance conformity (#774)
  • Add system-user-role assignments API (#762)
  • Add role-imply rest api (#750)
  • Add user update functionality (#747)
  • Add api to list user roles on project (#639)
  • Add domain CRUD operations (#743)
  • Add spiffe binding API (#740)
  • Add spiffe provider (#733)
  • Introduce SecurityContext (#710)
  • Add skeleton for the spiffe mTLS integration (#695)
  • Improve the code (#686)

Fixed

  • Next round of security review fixes (#1241)
  • (api-types) Allow empty domain description (#1237)
  • (types) Remove invalid PartialEq from AppCred wrappers (#1191)
  • (logging) Surface 5xx causes at error level (#1172)
  • Register UserType in OpenAPI components schema (#1151)
  • Map raft-not-available to proper HTTP status codes (#1149)
  • (api) Fix pagination limit, filters, and rows (#1115)
  • Address multiple tempest failures (#1083)
  • (api) Default enabled/domain_id on create (#1073)
  • (security) Address security review findings (#1049)
  • (federation) Allow long external unique_id values (#1033)
  • Unify ApiClient scope validation, fix nextest filter (#947)
  • Finalize ADR 0021 work (#906)

Other

  • (api) Harden v3 authorization and authentication coverage (#1166)
  • (identity) Remove service account API methods (#1152)
  • Feature/expose app credential (#948)
  • (api) Expand v3 coverage and enforce EC2 token restrictions (#1084)
  • Extend workspace unsafe/unwrap/expect lints (#1120)
  • (test) Improve testing of the oauth2 OP (#1024)
  • Move jsonwebtoken to keystone crate (#820)
  • (tests) Reorganize integration_api tests (#815)
  • mapping engine phase 3 - migrate SPIFFE (#811)
  • Rename identity_mapping to idmapping (#788)
  • Further align workspace features (#772)
  • Make resolve_implied_roles optional (#764)
  • Redesign SecurityContext with two-phase validation (#717)
  • Small optimization of the derives (#638)
  • Split the core-types crate (#640)
  • Introduce features in api-types crate (#624)
  • Slim down api-types crate (#622)

openstack-keystone-audit

0.1.0 - 2026-09-19

Added

  • (audit) Complete ADR-0023 audit implementation (#887)
  • Audit framework (ADR-0023) phase 3 (#880)
  • (audit) Implement CADF audit framework Phase 2 (#872)

Fixed

  • Fix ID sanitizer and capture client IP in audit (#1126)

Other

  • Extend workspace unsafe/unwrap/expect lints (#1120)

openstack-keystone-auth-plugin-core

0.1.0 - 2026-09-19

Other

  • Split extism out of core's dependency tree (#1148)

openstack-keystone-key-repository

0.1.0 - 2026-09-19

Added

  • (adr0026) Add previous-key and JTI-revocation janitor (#1021)
  • (adr0026) Add Phase 5 offline token verification (#1016)
  • (adr0026) Add client_credentials token endpoint (#1014)
  • (adr0026) Phase 0 token abstraction and JWS driver (#1010)
  • (scim) ADR 0024 - Phase 1+2 (#925)
  • (fernet) Unify credential/token key repositories (#915)

Fixed

  • (deps) Bump p256 to 0.14, unpin rand_core (#1247)
  • Widen Fernet key index from i8 to u32 (#1080)
  • Support macOS dev builds and fs watcher shutdown (#1009)

Other

  • (deps) bump pem from 3.0.6 to 4.0.0 (#1162)
  • (deps) bump pkcs8 from 0.10.2 to 0.11.0 (#1061)

openstack-keystone-local-emergency-store

0.1.0 - 2026-09-19

Added

  • (test) Add tempest identity compatibility (#998)
  • (adr0028) Add local-quorum-bypass emergency rotation (#1032)

Other

  • Extend workspace unsafe/unwrap/expect lints (#1120)

openstack-keystone-metrics

0.1.0 - 2026-09-19

Added

  • (metrics) Add shared Prometheus primitives crate (#1186)

openstack-keystone-storage-api

0.1.0 - 2026-09-19

Added

  • (storage) Add ephemeral state machine records (#1198)
  • (adr0026) Phase 1 crypto engine & JWKS endpoint (#1011)
  • (storage) Cert validity and SVID TTL enforcement (#886)
  • (storage) SPIFFE checks, RBAC, rate limiting, auto-join (#861)
  • (storage) Complete ADR-0016-v2 (#844)
  • (storage) implement ADR 0016-v2 Phases 1-4 — encrypted storage with quarantine (#840)

Fixed

  • (webauthn) Rotate raft ceremony-state keyspaces (#890)

Other

  • Extend workspace unsafe/unwrap/expect lints (#1120)
  • (storage) Decouple core from storage (#832)

openstack-keystone-core

0.1.2 - 2026-09-19

Added

  • (oauth2) Add secondary indexes to raft driver (#1327)
  • Hot-reload fs per-domain config files (#1225)
  • (adr0034) Reload assignment bundle on config change (#1220)
  • (adr0034) Route assignment ops per domain (#1219)
  • (adr0034) Build per-instance assignment backends (#1218)
  • (adr0034) Gate sources on domain_config (#1217)
  • Resolve local/public ids for non-default backends (#1207)
  • (assignment) Add OpenFGA assignment driver (#1206)
  • (idmapping) Add id-mapping write paths (#1205)
  • (domain-config) Dispatch identity ops per domain (#1202)
  • (domain-config) Add configuration API (#1201)
  • (domain-config) Add resolution layer (#1199)
  • (spiffe) Derive spiffe claims (#1193)
  • Add vendor data JWT API for SPIRE integration (#1192)
  • (core) Reconnect database connection on new config (#1188)
  • (metrics) Add shared Prometheus primitives crate (#1186)
  • Add domain config SQL driver (#1139)
  • (policy) Implement legacy Policy API (/v3/policies) (#1127)
  • Add domain config types and backend trait (#1138)
  • Add SCIM scenarios; Fix findings (#1136)
  • Add cargo-fuzz targets (#1130)
  • Add SPIFFE SVID health check to readiness probe (#1121)
  • Add OS-EP-FILTER provider CRUD to the catalog (#1075)
  • Add per-request cache framework (ADR 0030) (#1114)
  • Auto-register backend drivers via inventory (#1105)
  • Add immutable option for project, domain, role (#1097)
  • (config) Revoke Vault token on shutdown (#1088)
  • (identity) Add trust create/delete and REST CRUD (#1079)
  • (identity) Add PATCH to few resources (#1076)
  • (tempest) Improve tempest testing (#1046)
  • (test) Add tempest identity compatibility (#998)
  • (adr0028) Add local-quorum-bypass emergency rotation (#1032)
  • (adr0026) Add RFC 8628 Device Authorization Grant (#1023)
  • (adr0026) Add previous-key and JTI-revocation janitor (#1021)
  • (adr0026) Phase 6a (#1017)
  • (adr0026) Add Phase 5 offline token verification (#1016)
  • (adr0026) Add authorization code flow with PKCE (#1015)
  • (adr0026) Add client_credentials token endpoint (#1014)
  • (adr0026) Phase 2 client registration & OIDC discovery (#1013)
  • (adr0026) Phase 1 crypto engine & JWKS endpoint (#1011)
  • (adr0026) Phase 0 token abstraction and JWS driver (#1010)
  • (api) capture client IP via proxy headers & SPIFFE (Start capturing client information in the request processing #358 follow-up) (#908)
  • (identity) Add per-user auth rate limiting (#996)
  • (adr0025) Complete imlpementation (#969)
  • (api) Add global IP rate limiting framework (ADR-0022 phase 1) (#846)
  • (adr0025) Phase 1 (1.1+1.2) (#952)
  • (security) Wrap secrets with secrecy crate (#369) (#912)
  • (scim) ADR 0024 - Phase 5 (#951)
  • (scim) ADR 0024 - Phase 4 (protocol surface completion) (#929)
  • (scim) ADR 0024 - Phase 3 (#928)
  • (scim) ADR 0024 - Phase 1+2 (#925)
  • (credential) Implement Phase 3 of ADR 0019 (#909)
  • (credential) Implement ADR 0019 phases 1-2 (#897)
  • ADR 0021 admin surface, simulate-access, and janitor (#896)
  • Implement stateless SCIM ingress auth (ADR 0021) (#891)
  • (audit) Complete ADR-0023 audit implementation (#887)
  • (storage) Cert validity and SVID TTL enforcement (#886)
  • Audit framework (ADR-0023) phase 3 (#880)
  • (auth) Password hashing parity with Python Keystone (#859)
  • (audit) Implement CADF audit framework Phase 2 (#872)
  • Migrate federation to new mapping engine (#839)
  • Add access rule CRD to appcred provider (#806)
  • ADR-0020 mapping phase 4 (#818)
  • Add bootstrap cli command (#809)
  • (mapping) ADR-0020 (mapping engine) phase 1 (#794)
  • Add endpoint CRUD to catalog provider (#785)
  • Add inter-provider event notification system (#784)
  • Add service CRUD to the catalog provider (#773)
  • Validate password for compliance conformity (#774)
  • Return 401 on roleless scoped contexts (#742)
  • Add region CRUD to catalog SQL driver (#761)
  • Add timing attack protection and failed auth tracking (#758)
  • Add role-imply rest api (#750)
  • Add role imply API (#749)
  • Add user update functionality (#747)
  • Add domain CRUD operations (#743)
  • Add spiffe binding API (#740)
  • Normalize the policy enforcer structure (#741)
  • Make drivers more dynamic (#737)
  • Add Admin interface over the UDS (#735)
  • Add spiffe provider (#733)
  • Expand role info in expand_implied_roles (#730)
  • Introduce SecurityContext (#710)
  • Talk to OPA over unix socket (#701)
  • Add skeleton for the spiffe mTLS integration (#695)
  • Implement ConfigManager for config watching (#691)
  • Improve the code (#686)
  • Add k8s-auth raft driver (#676)
  • Add basic healthcheck endpoint (#671)
  • Make raft storage available through state (#657)

Fixed

  • (deps) Bump p256 to 0.14, unpin rand_core (#1247)
  • Match real app-cred id field in route plugin (#1242)
  • Next round of security review fixes (#1241)
  • (adr0034) Post implementation fixes (#1223)
  • Use proper token issued_at time (#1194)
  • (logging) Surface 5xx causes at error level (#1172)
  • Register UserType in OpenAPI components schema (#1151)
  • (api) Fix pagination limit, filters, and rows (#1115)
  • Fix ID sanitizer and capture client IP in audit (#1126)
  • (api) Default enabled/domain_id on create (#1073)
  • (security) Do not allow ec2cred token to do anything (#1071)
  • (security) Address security review findings (#1049)
  • (adr0026) Bind Token Exchange grant to the issuing domain (#1019)
  • Unify ApiClient scope validation, fix nextest filter (#947)
  • Finalize ADR 0021 work (#906)
  • (ci) Prepare workflows for merge queue (#902)
  • Resolve raft replication state races (#884)
  • (core) Eliminate mapping race condition (#876)
  • (k8s_auth) Flatten k8s.aud claim from JWT TokenReview (#834)
  • (auth) Close admin SVID impersonation gap (#833)

Other

  • (adr0034) Add per-domain assignment driver tests (#1222)
  • (deps) Bump argon2 from 0.5.3 to 0.6.0 (#1184)
  • (identity) Remove service account API methods (#1152)
  • Feature/expose app credential (#948)
  • (api) Expand v3 coverage and enforce EC2 token restrictions (#1084)
  • Split extism out of core's dependency tree (#1148)
  • Add SECURITY note to important method (#1132)
  • Extend workspace unsafe/unwrap/expect lints (#1120)
  • (db) 3 optimizations for DB queries (#1111)
  • (deps) Bump sea-orm and sea-orm-migration to 2.0 (#1089)
  • Revise documentation layout (#1069)
  • (security) Close mutation-testing gaps in auth/policy (#1056)
  • Extract password hashing into own crate (#1055)
  • (test) Improve testing of the oauth2 OP (#1024)
  • (deps) bump scrypt from 0.11.0 to 0.12.0 (#923)
  • Reorganize dockerfile and deps (#857)
  • (core) Remove spiffe crate dependency (#858)
  • Wrap ServiceState under ExecutionContext (#856)
  • (storage) Decouple core from storage (#832)
  • (core) Eliminate XxxProvider enums (#830)
  • Move jsonwebtoken to keystone crate (#820)
  • mapping engine phase 3 - migrate SPIFFE (#811)
  • (deps) bump hmac from 0.12.1 to 0.13.0 (#801)
  • Rename identity_mapping to idmapping (#788)
  • Consolidate password update flows (#778)
  • Further align workspace features (#772)
  • Make resolve_implied_roles optional (#764)
  • Redesign SecurityContext with two-phase validation (#717)
  • (deps) bump jsonwebtoken from 10.3.0 to 10.4.0 (#707)
  • Introduce dynamic plugins (#643)
  • Small optimization of the derives (#638)
  • Split the core-types crate (#640)
  • Split out remaining sql drivers (#633)
  • Split more drivers to separate crates (#632)
  • Drop unnecessary derives to help compilation (#631)
  • Drop unnecessary tracing directives (#627)
  • Split config into standalone crate (#628)
  • Rework http client pool (#629)
  • Make assignment sql driver a standalone crate (#626)
  • Move assignment parameters resolution to driver (#625)
  • Introduce features in api-types crate (#624)
  • Slim down api-types crate (#622)
  • Split out webauthn into crate (#621)
  • Split out token-fernet driver (#620)
  • Prepare slit out of the FernetTokenProvider (#619)
  • Move benchmark into the proper crate (#614)

openstack-keystone-storage-crypto

0.1.0 - 2026-09-19

Added

  • (scim) ADR 0024 - Phase 3 (#928)
  • (storage) Add PKCS#11 KEK provider crate (#917)
  • (storage) Cert validity and SVID TTL enforcement (#886)
  • (audit) Implement CADF audit framework Phase 2 (#872)
  • (storage) SPIFFE checks, RBAC, rate limiting, auto-join (#861)
  • (storage) Harden preflight and erase dev KEK (#860)
  • (storage) Complete ADR-0016-v2 (#844)
  • (storage) implement ADR 0016-v2 Phases 1-4 — encrypted storage with quarantine (#840)

Other

  • Bump deps and whitelist rustsec advisory (#1140)
  • (deps) Batch update dependencies (#875)

openstack-keystone-storage-crypto-pkcs11

0.1.0 - 2026-09-19

Added

  • (adr0026) Phase 1 crypto engine & JWKS endpoint (#1011)
  • (storage) Add PKCS#11 KEK provider crate (#917)

Other

  • Extend workspace unsafe/unwrap/expect lints (#1120)

openstack-keystone-storage-crypto-tpm

0.1.0 - 2026-09-19

Added

  • (adr0026) Phase 1 crypto engine & JWKS endpoint (#1011)
  • (storage) Add PKCS#11 KEK provider crate (#917)

Other

  • Extend workspace unsafe/unwrap/expect lints (#1120)

openstack-keystone-distributed-storage

0.1.1 - 2026-09-19

Added

  • (devstack) Pilot ksm SPIFFE mTLS transport (#1239)
  • (storage) Bump openraft to 0.10.0-alpha.34 (#1230)
  • (storage) Add ephemeral state machine records (#1198)
  • (metrics) Add shared Prometheus primitives crate (#1186)
  • Add SCIM scenarios; Fix findings (#1136)
  • (test) Add tempest identity compatibility (#998)
  • (adr0028) Add local-quorum-bypass emergency rotation (#1032)
  • (adr0026) Phase 1 crypto engine & JWKS endpoint (#1011)
  • (storage) Add PKCS#11 KEK provider crate (#917)
  • Prepare PKCS#11/TPM KEK support in storage (#907)
  • Implement background DEK re-encryption pipeline (#898)
  • ADR 0021 admin surface, simulate-access, and janitor (#896)
  • (storage) Cert validity and SVID TTL enforcement (#886)
  • (storage) SPIFFE checks, RBAC, rate limiting, auto-join (#861)
  • (storage) Harden preflight and erase dev KEK (#860)
  • (storage) Add SPIFFE mTLS support to Raft gRPC (#852)
  • (cli) Add cli storage subcommands per ADR 0016-v2 (#850)
  • (storage) Complete ADR-0016-v2 (#844)
  • (storage) implement ADR 0016-v2 Phases 1-4 — encrypted storage with quarantine (#840)
  • (mapping) ADR-0020 phase 2 (#807)
  • (adr) Add updated revision of the DS ADR (#795)
  • (mapping) ADR-0020 (mapping engine) phase 1 (#794)
  • Add skeleton for the spiffe mTLS integration (#695)
  • Implement ConfigManager for config watching (#691)
  • Improve the code (#686)
  • Add k8s-auth raft driver (#676)
  • Add SetIndex/RemoveIndex storage commands (#675)
  • Add basic healthcheck endpoint (#671)
  • Add metadata for raft data (#670)
  • Add transaction support for Raft storage (#669)
  • Add initial benchmarks for the storage (#668)
  • Add raft support under skaffold (#667)
  • Introduce raft backend for webauthn (#658)
  • Prepare raft storage promotion (#659)
  • Make raft storage available through state (#657)
  • Introduce the keystone-manage cli managing raft (#656)

Fixed

  • (storage) Adopt leader's DEK when nodes join (#1328)
  • Support macOS dev builds and fs watcher shutdown (#1009)
  • Finalize ADR 0021 work (#906)
  • (ci) Prepare workflows for merge queue (#902)
  • Further polish storage crate (#892)
  • (webauthn) Rotate raft ceremony-state keyspaces (#890)
  • Resolve raft replication state races (#884)

Other

  • Bump openraft version to 0.10.0.a31 (#1137)
  • Silence some clippy warnings (#1030)
  • (deps) Batch update dependencies (#875)
  • (core) Remove spiffe crate dependency (#858)
  • Add SpiFFE Raft integration test by skaffold (#854)
  • Wrap ServiceState under ExecutionContext (#856)
  • (storage) Decouple core from storage (#832)
  • Update raft drivers mocking (#791)
  • Add mock raft storage for unittest (#790)
  • Make core crates a workspace dependency (#736)
  • Redesign SecurityContext with two-phase validation (#717)
  • (deps) Bump openraft to alpha17 (#641)

openstack-keystone-api-key-driver-raft

0.1.0 - 2026-09-19

Added

@github-actions

github-actions Bot commented Jun 5, 2026

Copy link
Copy Markdown

🦢 Load Test Results

Goose Attack Report

Plan Overview

Action Started Stopped Elapsed Users
Increasing 26-09-19 15:35:24 26-09-19 15:35:47 00:00:23 0 → 45
Maintaining 26-09-19 15:35:47 26-09-19 15:36:17 00:00:30 45
Decreasing 26-09-19 15:36:17 26-09-19 15:36:17 00:00:00 0 ← 45

Request Metrics

Method Name # Requests # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
DELETE DELETE /v3/auth/tokens 44 0 547.05 50 715 1.47 0.00
DELETE DELETE /v3/projects/:id (teardown) 1 0 173.00 173 173 0.03 0.00
DELETE DELETE /v3/roles/:id (teardown) 1 0 97.00 97 97 0.03 0.00
DELETE DELETE /v3/users/:id (teardown) 2 0 182.00 141 223 0.07 0.00
DELETE DELETE /v4/mappings/rulesets/:mapping_id (teardown) 1 0 262.00 262 262 0.03 0.00
DELETE DELETE /v4/oauth2/:domain_id/clients/:provider_id (teardown) 1 0 237.00 237 237 0.03 0.00
GET 594 0 593.20 274 859 19.80 0.00
GET GET /SCIM/v2/:domain_id/Users (sync reconcile list) 1933 1933 15.03 1 700 64.43 64.43
GET GET /v3/auth/tokens (validate new) 44 0 548.48 142 726 1.47 0.00
GET GET /v3/auth/tokens (validate revoked) 44 0 508.93 30 659 1.47 0.00
GET GET /v3/projects/:id 55 0 552.55 356 689 1.83 0.00
GET GET /v3/projects/:id (catalog) 82 0 555.10 374 750 2.73 0.00
GET GET /v3/role_assignments 42 0 568.64 300 744 1.40 0.00
GET GET /v3/role_assignments?role.id 42 0 562.52 365 729 1.40 0.00
GET GET /v3/role_assignments?scope.domain.id 43 0 506.67 210 675 1.43 0.00
GET GET /v3/role_assignments?user.id 42 0 538.64 370 698 1.40 0.00
GET GET /v3/roles 108 0 562.42 356 703 3.60 0.00
GET GET /v3/roles/:id 55 0 551.45 259 733 1.83 0.00
GET GET /v3/users/:id 104 0 580.29 366 733 3.47 0.00
GET GET /v3/users/:id (catalog) 104 0 578.67 375 744 3.47 0.00
GET GET /v4/api-keys 27 0 531.67 399 651 0.90 0.00
GET GET /v4/api-keys/:client_id 26 0 615.58 503 744 0.87 0.00
GET GET /v4/mappings/rulesets 28 0 557.71 407 713 0.93 0.00
GET GET /v4/mappings/rulesets/:mapping_id 27 0 548.15 408 687 0.90 0.00
GET GET /v4/oauth2/:domain_id/.well-known/openid-configuration 873 0 50.94 10 172 29.10 0.00
GET GET /v4/oauth2/:domain_id/clients 28 0 543.89 430 694 0.93 0.00
GET GET /v4/oauth2/:domain_id/clients/:provider_id 28 0 544.39 395 639 0.93 0.00
GET GET /v4/oauth2/:domain_id/jwks 873 0 51.45 11 196 29.10 0.00
GET GET /v4/scim_realms 18 0 551.39 303 671 0.60 0.00
GET GET /v4/scim_realms/:domain_id/:provider_id 18 0 542.83 374 642 0.60 0.00
POST POST /v3/auth/tokens 43 0 500.77 317 644 1.43 0.00
POST POST /v3/auth/tokens (password, invalid) 35 0 890.69 526 1399 1.17 0.00
POST POST /v3/auth/tokens (password, project-scoped) 57 0 1224.82 819 1666 1.90 0.00
POST POST /v3/auth/tokens (password, unscoped) 56 0 976.52 607 1570 1.87 0.00
POST POST /v3/auth/tokens (rescope to system) 97 0 631.10 234 803 3.23 0.00
POST POST /v3/auth/tokens (rescope, invalid project) 58 0 524.24 235 672 1.93 0.00
POST POST /v3/auth/tokens (system-scoped, bootstrap admin) 52 0 1206.94 778 1779 1.73 0.00
POST POST /v4/api-keys/:client_id/revoke (teardown) 1 0 319.00 319 319 0.03 0.00
PUT PUT /v4/scim_realms/:domain_id/:provider_id 18 0 609.44 433 754 0.60 0.00
Aggregated 5705 1933 241.15 1 1779 190.17 64.43

Response Time Metrics

Method Name 50%ile (ms) 60%ile (ms) 70%ile (ms) 80%ile (ms) 90%ile (ms) 95%ile (ms) 99%ile (ms) 100%ile (ms)
DELETE DELETE /v3/auth/tokens 600 600 600 600 700 700 700 700
DELETE DELETE /v3/projects/:id (teardown) 173 173 173 173 173 173 173 173
DELETE DELETE /v3/roles/:id (teardown) 97 97 97 97 97 97 97 97
DELETE DELETE /v3/users/:id (teardown) 141 141 141 220 220 220 220 220
DELETE DELETE /v4/mappings/rulesets/:mapping_id (teardown) 262 262 262 262 262 262 262 262
DELETE DELETE /v4/oauth2/:domain_id/clients/:provider_id (teardown) 237 237 237 237 237 237 237 237
GET 600 600 600 700 700 700 800 859
GET GET /SCIM/v2/:domain_id/Users (sync reconcile list) 7 8 10 12 16 22 410 700
GET GET /v3/auth/tokens (validate new) 600 600 600 600 700 700 700 700
GET GET /v3/auth/tokens (validate revoked) 500 500 600 600 600 600 659 659
GET GET /v3/projects/:id 600 600 600 600 600 689 689 689
GET GET /v3/projects/:id (catalog) 600 600 600 600 600 700 700 750
GET GET /v3/role_assignments 600 600 600 600 700 700 700 700
GET GET /v3/role_assignments?role.id 600 600 600 600 700 700 700 700
GET GET /v3/role_assignments?scope.domain.id 500 500 600 600 600 600 675 675
GET GET /v3/role_assignments?user.id 500 500 600 600 600 698 698 698
GET GET /v3/roles 600 600 600 600 700 700 700 700
GET GET /v3/roles/:id 600 600 600 600 600 700 700 700
GET GET /v3/users/:id 600 600 600 700 700 700 700 700
GET GET /v3/users/:id (catalog) 600 600 600 600 700 700 700 700
GET GET /v4/api-keys 500 600 600 600 600 600 651 651
GET GET /v4/api-keys/:client_id 600 600 700 700 700 700 700 700
GET GET /v4/mappings/rulesets 600 600 600 600 700 700 700 700
GET GET /v4/mappings/rulesets/:mapping_id 600 600 600 600 600 687 687 687
GET GET /v4/oauth2/:domain_id/.well-known/openid-configuration 46 50 60 69 84 95 130 170
GET GET /v4/oauth2/:domain_id/clients 500 600 600 600 600 694 694 694
GET GET /v4/oauth2/:domain_id/clients/:provider_id 500 600 600 600 600 600 600 600
GET GET /v4/oauth2/:domain_id/jwks 46 53 62 70 83 94 130 196
GET GET /v4/scim_realms 600 600 600 600 600 600 671 671
GET GET /v4/scim_realms/:domain_id/:provider_id 500 600 600 600 600 600 600 600
POST POST /v3/auth/tokens 500 500 500 600 600 600 600 600
POST POST /v3/auth/tokens (password, invalid) 900 900 1,000 1,000 1,000 1,000 1,000 1,000
POST POST /v3/auth/tokens (password, project-scoped) 1,000 1,000 1,000 1,000 1,000 1,666 1,666 1,666
POST POST /v3/auth/tokens (password, unscoped) 900 1,000 1,000 1,000 1,000 1,000 1,000 1,570
POST POST /v3/auth/tokens (rescope to system) 600 700 700 700 700 800 800 800
POST POST /v3/auth/tokens (rescope, invalid project) 500 500 600 600 600 600 672 672
POST POST /v3/auth/tokens (system-scoped, bootstrap admin) 1,000 1,000 1,000 1,000 1,000 1,779 1,779 1,779
POST POST /v4/api-keys/:client_id/revoke (teardown) 319 319 319 319 319 319 319 319
PUT PUT /v4/scim_realms/:domain_id/:provider_id 600 600 700 700 700 700 754 754
Aggregated 48 79 490 600 600 700 1,000 1,779

Status Code Metrics

Method Name Status Codes
DELETE DELETE /v3/auth/tokens 44 [204]
DELETE DELETE /v3/projects/:id (teardown) 1 [204]
DELETE DELETE /v3/roles/:id (teardown) 1 [204]
DELETE DELETE /v3/users/:id (teardown) 2 [204]
DELETE DELETE /v4/mappings/rulesets/:mapping_id (teardown) 1 [204]
DELETE DELETE /v4/oauth2/:domain_id/clients/:provider_id (teardown) 1 [204]
GET 594 [200]
GET GET /SCIM/v2/:domain_id/Users (sync reconcile list) 1,903 [429], 30 [401]
GET GET /v3/auth/tokens (validate new) 44 [200]
GET GET /v3/auth/tokens (validate revoked) 44 [404]
GET GET /v3/projects/:id 55 [200]
GET GET /v3/projects/:id (catalog) 82 [200]
GET GET /v3/role_assignments 42 [200]
GET GET /v3/role_assignments?role.id 42 [200]
GET GET /v3/role_assignments?scope.domain.id 43 [200]
GET GET /v3/role_assignments?user.id 42 [200]
GET GET /v3/roles 108 [200]
GET GET /v3/roles/:id 55 [200]
GET GET /v3/users/:id 104 [200]
GET GET /v3/users/:id (catalog) 104 [200]
GET GET /v4/api-keys 27 [200]
GET GET /v4/api-keys/:client_id 26 [200]
GET GET /v4/mappings/rulesets 28 [200]
GET GET /v4/mappings/rulesets/:mapping_id 27 [200]
GET GET /v4/oauth2/:domain_id/.well-known/openid-configuration 873 [200]
GET GET /v4/oauth2/:domain_id/clients 28 [200]
GET GET /v4/oauth2/:domain_id/clients/:provider_id 28 [200]
GET GET /v4/oauth2/:domain_id/jwks 873 [200]
GET GET /v4/scim_realms 18 [200]
GET GET /v4/scim_realms/:domain_id/:provider_id 18 [200]
POST POST /v3/auth/tokens 43 [201]
POST POST /v3/auth/tokens (password, invalid) 35 [401]
POST POST /v3/auth/tokens (password, project-scoped) 57 [201]
POST POST /v3/auth/tokens (password, unscoped) 56 [201]
POST POST /v3/auth/tokens (rescope to system) 97 [201]
POST POST /v3/auth/tokens (rescope, invalid project) 58 [401]
POST POST /v3/auth/tokens (system-scoped, bootstrap admin) 52 [201]
POST POST /v4/api-keys/:client_id/revoke (teardown) 1 [200]
PUT PUT /v4/scim_realms/:domain_id/:provider_id 18 [200]
Aggregated 305 [201], 3,280 [200], 123 [401], 44 [404], 1,903 [429], 50 [204]

Transaction Metrics

Transaction # Times Run # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
ReadHeavy
0.0 0 0 0.00 0 0 0.00 0.00
0.1 107 0 604.64 389 777 3.57 0.00
0.2 105 0 565.45 318 734 3.50 0.00
0.3 105 0 556.31 395 736 3.50 0.00
TokenLifecycle
1.0 0 0 0.00 0 0 0.00 0.00
1.1 44 0 2107.86 541 2462 1.47 0.00
ValidateToken
2.0 0 0 0.00 0 0 0.00 0.00
2.1 92 0 664.75 433 859 3.07 0.00
UserCRUD
3.0 0 0 0.00 0 0 0.00 0.00
3.1 0 0 0.00 0 0 0.00 0.00
3.2 104 0 580.31 366 733 3.47 0.00
3.3 2 0 182.00 141 223 0.07 0.00
ProjectCRUD
4.0 0 0 0.00 0 0 0.00 0.00
4.1 0 0 0.00 0 0 0.00 0.00
4.2 55 0 552.58 356 689 1.83 0.00
4.3 1 0 173.00 173 173 0.03 0.00
RoleCRUD
5.0 0 0 0.00 0 0 0.00 0.00
5.1 0 0 0.00 0 0 0.00 0.00
5.2 55 0 551.47 259 733 1.83 0.00
5.3 1 0 97.00 97 97 0.03 0.00
RoleList
6.0 0 0 0.00 0 0 0.00 0.00
6.1 108 0 562.44 356 703 3.60 0.00
RoleAssignmentList
7.0 0 0 0.00 0 0 0.00 0.00
7.1 42 0 568.67 300 744 1.40 0.00
7.2 42 0 538.69 371 698 1.40 0.00
7.3 43 0 506.70 210 675 1.43 0.00
7.4 42 0 562.60 365 730 1.40 0.00
UserRead
8.0 0 0 0.00 0 0 0.00 0.00
8.1 104 0 604.12 274 852 3.47 0.00
8.2 104 0 578.72 375 744 3.47 0.00
ProjectRead
9.0 0 0 0.00 0 0 0.00 0.00
9.1 81 0 566.84 385 738 2.70 0.00
9.2 82 0 555.17 374 750 2.73 0.00
PasswordAuth
10.0 56 0 976.59 607 1570 1.87 0.00
10.1 57 0 1224.86 819 1666 1.90 0.00
PasswordAuthNegative
11.0 35 0 890.80 527 1399 1.17 0.00
Rescope
12.0 0 0 0.00 0 0 0.00 0.00
12.1 97 0 631.14 234 803 3.23 0.00
RescopeNegative
13.0 0 0 0.00 0 0 0.00 0.00
13.1 58 0 524.29 235 672 1.93 0.00
SystemScopeAuth
14.0 52 0 1207.00 778 1779 1.73 0.00
ApiKeyCRUD
15.0 0 0 0.00 0 0 0.00 0.00
15.1 0 0 0.00 0 0 0.00 0.00
15.2 26 0 615.65 503 744 0.87 0.00
15.3 27 0 531.67 399 651 0.90 0.00
15.4 1 0 319.00 319 319 0.03 0.00
MappingCRUD
16.0 0 0 0.00 0 0 0.00 0.00
16.1 0 0 0.00 0 0 0.00 0.00
16.2 27 0 548.15 408 687 0.90 0.00
16.3 28 0 557.75 407 713 0.93 0.00
16.4 1 0 262.00 262 262 0.03 0.00
OAuth2ClientCRUD
17.0 0 0 0.00 0 0 0.00 0.00
17.1 0 0 0.00 0 0 0.00 0.00
17.2 28 0 544.43 395 639 0.93 0.00
17.3 28 0 543.96 430 694 0.93 0.00
17.4 1 0 237.00 237 237 0.03 0.00
OAuth2Discovery
18.0 873 0 51.48 11 196 29.10 0.00
18.1 873 0 50.97 10 172 29.10 0.00
ScimRealmRead
19.0 0 0 0.00 0 0 0.00 0.00
19.1 18 0 542.83 374 642 0.60 0.00
19.2 18 0 551.39 303 671 0.60 0.00
19.3 18 0 609.44 433 754 0.60 0.00
ScimSync
20.0 0 0 0.00 0 0 0.00 0.00
20.1 0 0 0.00 0 0 0.00 0.00
20.2 0 0 0.00 0 0 0.00 0.00
20.3 1933 0 15.05 1 700 64.43 0.00
20.4 1932 0 0.00 0 0 64.40 0.00
20.5 1932 0 0.00 0 0 64.40 0.00
20.6 1 0 0.00 0 0 0.03 0.00
Aggregated 9439 0 145.76 1 2462 314.63 0.00

Scenario Metrics

Transaction # Users # Times Run Average (ms) Min (ms) Max (ms) Scenarios/s Iterations
ReadHeavy 6 104 1738.62 1355 2059 3.47 17.33
TokenLifecycle 3 41 2187.27 1547 2462 1.37 13.67
ValidateToken 2 90 667.54 433 859 3.00 45.00
UserCRUD 2 102 583.99 370 733 3.40 51.00
ProjectCRUD 1 54 554.89 356 689 1.80 54.00
RoleCRUD 1 54 556.89 415 733 1.80 54.00
RoleList 2 106 565.08 365 703 3.53 53.00
RoleAssignmentList 3 42 2204.50 1587 2490 1.40 14.00
UserRead 4 103 1196.48 849 1423 3.43 25.75
ProjectRead 3 80 1127.93 788 1348 2.67 26.67
PasswordAuth 4 54 2236.63 1521 2898 1.80 13.50
PasswordAuthNegative 1 34 896.00 527 1399 1.13 34.00
Rescope 2 95 636.45 462 803 3.17 47.50
RescopeNegative 1 57 529.39 347 672 1.90 57.00
SystemScopeAuth 2 50 1209.30 778 1779 1.67 25.00
ApiKeyCRUD 1 26 1151.50 943 1395 0.87 26.00
MappingCRUD 1 27 1112.37 827 1393 0.90 27.00
OAuth2ClientCRUD 1 27 1089.22 929 1273 0.90 27.00
OAuth2Discovery 3 871 102.82 25 265 29.03 290.33
ScimRealmRead 1 18 1728.33 1323 1921 0.60 18.00
ScimSync 1 1932 15.07 1 700 64.40 1932.00
Aggregated 45 3967 342.23 1 2898 132.23 2851.75

Error Metrics

Method Name # Error
GET GET /SCIM/v2/:domain_id/Users (sync reconcile list) 48 401 Unauthorized: GET /SCIM/v2/:domain_id/Users (sync reconcile list)
POST POST /SCIM/v2/:domain_id/Users (sync provision) 1 401 Unauthorized: POST /SCIM/v2/:domain_id/Users (sync provision)
POST POST /v3/auth/tokens (password, invalid) 82 401 Unauthorized: POST /v3/auth/tokens (password, invalid)
POST POST /v3/auth/tokens (rescope, invalid project) 148 401 Unauthorized: POST /v3/auth/tokens (rescope, invalid project)
GET GET /v3/auth/tokens (validate revoked) 150 404 Not Found: GET /v3/auth/tokens (validate revoked)
GET GET /SCIM/v2/:domain_id/Users (sync reconcile list) 2169 429 Too Many Requests: GET /SCIM/v2/:domain_id/Users (sync reconcile list)

View full report

@github-actions

github-actions Bot commented Jun 5, 2026

Copy link
Copy Markdown

🐰 Bencher Report

Projectkeystone
Branchrelease-plz-2026-06-05T09-00-15Z
Testbedubuntu-latest
Click to view all benchmark results
BenchmarkLatencyBenchmark Result
nanoseconds (ns)
(Result Δ%)
Upper Boundary
nanoseconds (ns)
(Limit %)
Command_Serde/apply/remove📈 view plot
🚷 view threshold
136,720.00 ns
(-53.09%)Baseline: 291,440.62 ns
1,448,357.86 ns
(9.44%)
Command_Serde/apply/set📈 view plot
🚷 view threshold
146,190.00 ns
(-68.26%)Baseline: 460,542.28 ns
3,321,060.90 ns
(4.40%)
Command_Serde/pack/delete📈 view plot
🚷 view threshold
131.68 ns
(+13.12%)Baseline: 116.41 ns
158.91 ns
(82.87%)
Command_Serde/pack/delete_index📈 view plot
🚷 view threshold
117.67 ns
(+13.63%)Baseline: 103.55 ns
139.44 ns
(84.39%)
Command_Serde/pack/set📈 view plot
🚷 view threshold
211.24 ns
(+11.51%)Baseline: 189.43 ns
253.54 ns
(83.32%)
Command_Serde/pack/set_index📈 view plot
🚷 view threshold
117.78 ns
(+13.74%)Baseline: 103.55 ns
139.99 ns
(84.13%)
Command_Serde/unpack/delete📈 view plot
🚷 view threshold
196.40 ns
(+7.32%)Baseline: 183.00 ns
270.92 ns
(72.49%)
Command_Serde/unpack/delete_index📈 view plot
🚷 view threshold
162.42 ns
(+6.56%)Baseline: 152.42 ns
219.60 ns
(73.96%)
Command_Serde/unpack/set📈 view plot
🚷 view threshold
296.56 ns
(+13.27%)Baseline: 261.82 ns
375.22 ns
(79.04%)
Command_Serde/unpack/set_index📈 view plot
🚷 view threshold
173.90 ns
(+15.60%)Baseline: 150.43 ns
215.09 ns
(80.85%)
Payload_encryption/pack/remove_cmd📈 view plot
🚷 view threshold
123.04 ns
(+12.57%)Baseline: 109.30 ns
151.95 ns
(80.97%)
Payload_encryption/pack/set_cmd📈 view plot
🚷 view threshold
205.69 ns
(+3.87%)Baseline: 198.03 ns
274.32 ns
(74.98%)
Payload_encryption/unpack/remove_cmd📈 view plot
🚷 view threshold
206.80 ns
(+8.06%)Baseline: 191.38 ns
284.65 ns
(72.65%)
Payload_encryption/unpack/set_cmd📈 view plot
🚷 view threshold
306.30 ns
(+13.19%)Baseline: 270.61 ns
390.67 ns
(78.40%)
Raft_1Node_Latency/prefix/1node📈 view plot
🚷 view threshold
2,536,700.00 ns
(-17.85%)Baseline: 3,087,777.33 ns
8,510,044.82 ns
(29.81%)
Raft_1Node_Latency/read/1node📈 view plot
🚷 view threshold
43,555.00 ns
(+16.87%)Baseline: 37,269.47 ns
53,010.19 ns
(82.16%)
Raft_1Node_Latency/remove/1node📈 view plot
🚷 view threshold
379,170.00 ns
(-68.94%)Baseline: 1,220,650.31 ns
11,552,389.31 ns
(3.28%)
Raft_1Node_Latency/write/1node📈 view plot
🚷 view threshold
390,980.00 ns
(-60.86%)Baseline: 998,917.03 ns
7,587,887.21 ns
(5.15%)
build_snapshot/default📈 view plot
🚷 view threshold
112,660.00 ns
(-7.74%)Baseline: 122,106.27 ns
267,279.45 ns
(42.15%)
fernet token/project📈 view plot
🚷 view threshold
1,484.20 ns
(+6.38%)Baseline: 1,395.15 ns
1,829.28 ns
(81.14%)
get_data_keyspace📈 view plot
🚷 view threshold
0.31 ns
(+0.97%)Baseline: 0.31 ns
0.39 ns
(80.47%)
get_db📈 view plot
🚷 view threshold
0.31 ns
(+0.79%)Baseline: 0.31 ns
0.39 ns
(80.32%)
get_fernet_token_timestamp/project📈 view plot
🚷 view threshold
144.00 ns
(+4.07%)Baseline: 138.37 ns
183.99 ns
(78.26%)
get_keyspace📈 view plot
🚷 view threshold
4.31 ns
(-25.76%)Baseline: 5.80 ns
12.70 ns
(33.90%)
🐰 View full continuous benchmarking report in Bencher

@openstack-experimental-release-plz
openstack-experimental-release-plz Bot force-pushed the release-plz-2026-06-05T09-00-15Z branch 22 times, most recently from d04a4df to 7fe2614 Compare June 12, 2026 09:11
@openstack-experimental-release-plz
openstack-experimental-release-plz Bot force-pushed the release-plz-2026-06-05T09-00-15Z branch 6 times, most recently from 3966098 to 805ed8e Compare June 15, 2026 10:08
@openstack-experimental-release-plz
openstack-experimental-release-plz Bot force-pushed the release-plz-2026-06-05T09-00-15Z branch 28 times, most recently from fd0af7c to 53568cd Compare June 26, 2026 20:00
@github-actions

github-actions Bot commented Jul 17, 2026

Copy link
Copy Markdown

🧪 Tempest Identity Compatibility Results (advisory, non-blocking)

rust

Totals
======
Ran: 133 tests in 30.9768 sec.
 - Passed: 66
 - Skipped: 4
 - Expected Fail: 0
 - Unexpected Success: 0
 - Failed: 63
Sum of execute time for each test: 23.2270 sec.
Failed test IDs
===== FAILED TESTS (target=rust) =====
tempest.api.identity.admin.v3.test_application_credentials.ApplicationCredentialsV3AdminTest.test_create_application_credential_with_roles[id-3b3dd48f-3388-406a-a9e6-4d078a552d0e]
tempest.api.identity.admin.v3.test_domain_configuration.DomainConfigurationTestJSON.test_create_domain_config_and_show_config_groups_and_options[id-9e3ff13c-f597-4f01-9377-d6c06c2a1477]
tempest.api.identity.admin.v3.test_credentials.CredentialsTestJSON.test_credentials_create_get_update_delete[id-7cd59bf9-bda4-4c72-9467-d21cab278355,smoke]
tempest.api.identity.admin.v3.test_domain_configuration.DomainConfigurationTestJSON.test_create_update_and_delete_domain_config_groups_and_opts[id-c7510fa2-6661-4170-9c6b-4783a80651e9]
tempest.api.identity.admin.v3.test_domain_configuration.DomainConfigurationTestJSON.test_show_default_group_config_and_options[id-11a02bf0-6f94-4380-b3b0-c8dc18fc0d22]
tempest.api.identity.admin.v3.test_domains.DomainsTestJSON.test_create_domain_without_description[id-2abf8764-309a-4fa9-bc58-201b799817ad]
tempest.api.identity.admin.v3.test_domains.DomainsTestJSON.test_create_update_delete_domain[id-f2f5b44a-82e8-4dad-8084-0661ea3b18cf,smoke]
tempest.api.identity.admin.v3.test_domains.DomainsTestJSON.test_domain_delete_cascades_content[id-d8d318b7-d1b3-4c37-94c5-3c5ba0b121ea]
tempest.api.identity.admin.v3.test_domains.DomainsTestJSON.test_list_domains_filter_by_enabled[id-3fd19840-65c1-43f8-b48c-51bdd066dff9]
tempest.api.identity.admin.v3.test_domains_negative.DomainsNegativeTestJSON.test_create_domain_with_name_length_over_64[id-37b1bbf2-d664-4785-9a11-333438586eae,negative]
tempest.api.identity.admin.v3.test_domains_negative.DomainsNegativeTestJSON.test_delete_active_domain[gate,id-1f3fbff5-4e44-400d-9ca1-d953f05f609b,negative]
tempest.api.identity.admin.v3.test_default_project_id.TestDefaultProjectId.test_default_project_id[id-d6110661-6a71-49a7-a453-b5e26640ff6d]
tempest.api.identity.admin.v3.test_projects_negative.ProjectsNegativeStaticTestJSON.test_create_projects_name_length_over_64[id-502b6ceb-b0c8-4422-bf53-f08fdb21e2f0,negative]
tempest.api.identity.admin.v3.test_groups.GroupsV3TestJSON.test_group_users_add_list_delete[id-1598521a-2f36-4606-8df9-30772bd51339,smoke]
tempest.api.identity.admin.v3.test_groups.GroupsV3TestJSON.test_list_user_groups[id-64573281-d26a-4a52-b899-503cb0f4e4ec]
setUpClass (tempest.api.identity.admin.v3.test_endpoint_groups.EndPointGroupsTest)
tempest.api.identity.admin.v3.test_inherits.InheritsV3TestJSON.test_inherit_assign_check_revoke_roles_on_projects_group[id-26021436-d5a4-4256-943c-ded01e0d4b45]
tempest.api.identity.admin.v3.test_inherits.InheritsV3TestJSON.test_inherit_assign_check_revoke_roles_on_projects_user[id-18b70e45-7687-4b72-8277-b8f1a47d7591]
tempest.api.identity.admin.v3.test_inherits.InheritsV3TestJSON.test_inherit_assign_list_check_revoke_roles_on_domains_group[id-c7a8dda2-be50-4fb4-9a9c-e830771078b1]
tempest.api.identity.admin.v3.test_inherits.InheritsV3TestJSON.test_inherit_assign_list_check_revoke_roles_on_domains_user[id-4e6f0366-97c8-423c-b2be-41eae6ac91c8]
tempest.api.identity.admin.v3.test_inherits.InheritsV3TestJSON.test_inherit_assign_list_revoke_user_roles_on_domain[id-3acf666e-5354-42ac-8e17-8b68893bcd36]
tempest.api.identity.admin.v3.test_roles.RolesV3TestJSON.test_assignments_for_domain_roles[id-3859df7e-5b78-4e4d-b10e-214c8953842a]
tempest.api.identity.admin.v3.test_inherits.InheritsV3TestJSON.test_inherit_assign_list_revoke_user_roles_on_project_tree[id-9f02ccd9-9b57-46b4-8f77-dd5a736f3a06]
tempest.api.identity.admin.v3.test_roles.RolesV3TestJSON.test_assignments_for_implied_roles_create_delete[id-c8828027-df48-4021-95df-b65b92c7429e]
tempest.api.identity.admin.v3.test_roles.RolesV3TestJSON.test_grant_list_revoke_role_to_group_on_domain[id-4bf8a70b-e785-413a-ad53-9f91ce02faa7]
tempest.api.identity.admin.v3.test_roles.RolesV3TestJSON.test_grant_list_revoke_role_to_group_on_project[id-cbf11737-1904-4690-9613-97bcbb3df1c4]
tempest.api.identity.admin.v3.test_roles.RolesV3TestJSON.test_grant_list_revoke_role_to_group_on_system[id-c888fe4f-8018-48db-b959-542225c1b4b6]
tempest.api.identity.admin.v3.test_roles.RolesV3TestJSON.test_grant_list_revoke_role_to_user_on_domain[id-6c9a2940-3625-43a3-ac02-5dcec62ef3bd]
tempest.api.identity.admin.v3.test_roles.RolesV3TestJSON.test_implied_domain_roles[id-eb1e1c24-1bc4-4d47-9748-e127a1852c82]
tempest.api.identity.admin.v3.test_roles.RolesV3TestJSON.test_implied_roles_create_check_show_delete[id-c90c316c-d706-4728-bcba-eb1912081b69]
tempest.api.identity.admin.v3.test_roles.RolesV3TestJSON.test_role_create_update_show_list[id-18afc6c0-46cf-4911-824e-9989cc056c3a,smoke]
tempest.api.identity.admin.v3.test_list_projects.ListProjectsTestJSON.test_list_projects_with_enabled[id-0fe7a334-675a-4509-b00e-1c4b95d5dae8]
tempest.api.identity.admin.v3.test_list_projects.ListProjectsTestJSON.test_list_projects_with_parent[id-6edc66f5-2941-4a17-9526-4073311c1fac]
tempest.api.identity.admin.v3.test_list_projects.ListProjectsStaticTestJSON.test_list_projects[id-1d830662-22ad-427c-8c3e-4ec854b0af44]
tempest.api.identity.admin.v3.test_list_users.UsersV3TestJSON.test_list_users_with_not_enabled[id-bff8bf2f-9408-4ef5-b63a-753c8c2124eb]
tempest.api.identity.admin.v3.test_oauth_consumers.OAUTHConsumersV3Test.test_create_and_show_consumer[id-c8307ea6-a86c-47fd-ae7b-5b3b2caca76d]
tempest.api.identity.admin.v3.test_oauth_consumers.OAUTHConsumersV3Test.test_delete_consumer[id-fdfa1b7f-2a31-4354-b2c7-f6ae20554f93]
tempest.api.identity.admin.v3.test_oauth_consumers.OAUTHConsumersV3Test.test_list_consumers[id-09ca50de-78f2-4ffb-ac71-f2254036b2b8]
tempest.api.identity.admin.v3.test_oauth_consumers.OAUTHConsumersV3Test.test_update_consumer[id-080a9b1a-c009-47c0-9979-5305bf72e3dc]
tempest.api.identity.admin.v3.test_project_tags.IdentityV3ProjectTagsTest.test_list_update_delete_project_tags[id-7c123aac-999d-416a-a0fb-84b915ab10de]
tempest.api.identity.v3.test_catalog.IdentityCatalogTest.test_catalog_standardization[id-56b57ced-22b8-4127-9b8a-565dfb0207e2]
tempest.api.identity.admin.v3.test_users.UsersV3TestJSON.test_list_user_projects[id-a831e70c-e35b-430b-92ed-81ebbc5437b8]
tempest.api.identity.admin.v3.test_projects.ProjectsTestJSON.test_create_is_domain_project[id-a7eb9416-6f9b-4dbb-b71b-7f73aaef59d5]
tempest.api.identity.admin.v3.test_tokens.TokensV3TestJSON.test_get_available_domain_scopes[id-ec5ecb05-af64-4c04-ac86-4d9f6f12f185]
tempest.api.identity.admin.v3.test_projects.ProjectsTestJSON.test_project_create_with_parent[id-1854f9c0-70bc-4d11-a08a-1c789d339e3d]
tempest.api.identity.admin.v3.test_projects.ProjectsTestJSON.test_project_get_equals_list[id-d1db68b6-aebe-4fa0-b79d-d724d2e21162]
tempest.api.identity.admin.v3.test_tokens.TokensV3TestJSON.test_rescope_token[id-565fa210-1da1-4563-999b-f7b5b67cf112]
tempest.api.identity.v3.test_projects.IdentityV3ProjectsTest.test_list_projects_returns_only_authorized_projects[id-86128d46-e170-4644-866a-cc487f699e1d]
tempest.api.identity.admin.v3.test_users_negative.UsersNegativeTest.test_create_user_for_non_existent_domain[id-e75f006c-89cc-477b-874d-588e4eab4b17,negative]
tempest.api.identity.admin.v3.test_trusts.TrustsV3TestJSON.test_get_trusts_all[id-4773ebd5-ecbf-4255-b8d8-b63e6f72b65d,smoke]
tempest.api.identity.v3.test_api_discovery.TestApiDiscovery.test_api_media_types[id-657c1970-4722-4189-8831-7325f3bc4265,smoke]
tempest.api.identity.v3.test_api_discovery.TestApiDiscovery.test_api_version_resources[id-b9232f5e-d9e5-4d97-b96c-28d3db4de1bd,smoke]
tempest.api.identity.v3.test_api_discovery.TestApiDiscovery.test_identity_v3_existence[id-79aec9ae-710f-4c54-a4fc-3aa25b4feac3]
tempest.api.identity.v3.test_tokens.TokensV3Test.test_validate_token[id-a9512ac3-3909-48a4-b395-11f438e16260]
tempest.api.identity.v3.test_api_discovery.TestApiDiscovery.test_list_api_versions[id-721f480f-35b6-46c7-846e-047e6acea0dc,smoke]
tempest.api.identity.admin.v3.test_trusts.TrustsV3TestJSON.test_get_trusts_query[id-6268b345-87ca-47c0-9ce3-37792b43403a]
tempest.api.identity.v3.test_application_credentials.ApplicationCredentialsV3Test.test_create_application_credential[id-8080c75c-eddc-4786-941a-c2da7039ae61]
tempest.api.identity.v3.test_application_credentials.ApplicationCredentialsV3Test.test_create_application_credential_expires[id-852daf0c-42b5-4239-8466-d193d0543ed3]
tempest.api.identity.v3.test_application_credentials.ApplicationCredentialsV3Test.test_list_application_credentials[id-ff0cd457-6224-46e7-b79e-0ada4964a8a6]
tempest.api.identity.v3.test_application_credentials.ApplicationCredentialsV3Test.test_query_application_credentials[id-9bb5e5cc-5250-493a-8869-8b665f6aa5f6]
tempest.api.identity.admin.v3.test_trusts.TrustsV3TestJSON.test_trust_expire[id-0ed14b66-cefd-4b5c-a964-65759453e292]
tempest.api.identity.admin.v3.test_trusts.TrustsV3TestJSON.test_trust_impersonate[id-5a0a91a4-baef-4a14-baba-59bf4d7fcace]
tempest.api.identity.admin.v3.test_trusts.TrustsV3TestJSON.test_trust_noimpersonate[id-ed2a8779-a7ac-49dc-afd7-30f32f936ed2]
===== END FAILED TESTS (target=rust) =====

View full run

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants