Skip to content

chore: release#754

Open
openstack-experimental-release-plz[bot] wants to merge 1 commit into
mainfrom
release-plz-2026-06-05T09-00-15Z
Open

chore: release#754
openstack-experimental-release-plz[bot] wants to merge 1 commit into
mainfrom
release-plz-2026-06-05T09-00-15Z

Conversation

@openstack-experimental-release-plz

@openstack-experimental-release-plz openstack-experimental-release-plz Bot commented Jun 5, 2026

Copy link
Copy Markdown
Contributor

🤖 New release

  • openstack-keystone-config: 0.1.0
  • openstack-keystone-core-types: 0.1.1
  • openstack-keystone-api-types: 0.1.0 -> 0.1.1 (✓ API compatible changes)
  • openstack-keystone-audit: 0.1.0
  • openstack-keystone-auth-plugin-runtime: 0.1.0
  • openstack-keystone-key-repository: 0.1.0
  • openstack-keystone-local-emergency-store: 0.1.0
  • openstack-keystone-storage-api: 0.1.0
  • openstack-keystone-core: 0.1.1 -> 0.1.2 (✓ API compatible changes)
  • openstack-keystone-storage-crypto: 0.1.0
  • openstack-keystone-storage-crypto-pkcs11: 0.1.0
  • openstack-keystone-storage-crypto-tpm: 0.1.0
  • openstack-keystone-distributed-storage: 0.1.0 -> 0.1.1 (✓ API compatible changes)
  • openstack-keystone-api-key-driver-raft: 0.1.0
  • openstack-keystone-password-hashing: 0.1.0
  • openstack-keystone-appcred-driver-sql: 0.1.0
  • openstack-keystone-assignment-driver-sql: 0.1.0
  • openstack-keystone-catalog-driver-sql: 0.1.0
  • openstack-keystone-credential-driver-sql: 0.1.0
  • openstack-keystone-auth-plugin-identity-driver-raft: 0.1.0
  • openstack-keystone-federation-driver-sql: 0.1.0
  • openstack-keystone-identity-driver-ldap: 0.1.0
  • openstack-keystone-identity-driver-sql: 0.1.0
  • openstack-keystone-idmapping-driver-sql: 0.1.0
  • openstack-keystone-k8s-auth-driver-raft: 0.1.0
  • openstack-keystone-k8s-auth-driver-sql: 0.1.0
  • openstack-keystone-mapping-driver-raft: 0.1.0
  • openstack-keystone-oauth2-client-driver-raft: 0.1.0
  • openstack-keystone-oauth2-key-driver-raft: 0.1.0
  • openstack-keystone-oauth2-session-driver-raft: 0.1.0
  • openstack-keystone-resource-driver-sql: 0.1.0
  • openstack-keystone-revoke-driver-sql: 0.1.0
  • openstack-keystone-role-driver-sql: 0.1.0
  • openstack-keystone-scim-driver-raft: 0.1.0
  • openstack-keystone-token-driver-fernet: 0.1.1
  • openstack-keystone-token-driver-jws: 0.1.0
  • openstack-keystone-token-restriction-driver-sql: 0.1.0
  • openstack-keystone-trust-driver-sql: 0.1.0
  • openstack-keystone-webauthn: 0.1.0
  • openstack-keystone: 0.1.1 -> 0.1.2 (✓ API compatible changes)
  • openstack-keystone-cli-manage: 0.1.0
Changelog

openstack-keystone-config

0.1.0 - 2026-07-27

Added

  • (config) Revoke Vault token on shutdown (#1088)
  • Generalize marker pagination for v3/v4 lists (#1086)
  • (config) Add Vault-backed configuration (#1051)
  • (logging) Add native journald log writer (#1081)
  • (identity) Add PATCH to few resources (#1076)
  • (ldap) Add LDAP identity driver (#1047)
  • (adr0028) Add local-quorum-bypass emergency rotation (#1032)
  • Add catalog CRUD API and bootstrap support (#1029)
  • (adr0026) Add RFC 8628 Device Authorization Grant (#1023)
  • (adr0026) Add authorization code flow with PKCE (#1015)
  • (adr0026) Add client_credentials token endpoint (#1014)
  • (adr0026) Phase 2 client registration & OIDC discovery (#1013)
  • (adr0026) Phase 0 token abstraction and JWS driver (#1010)
  • (api) capture client IP via proxy headers & SPIFFE (Start capturing client information in the request processing #358 follow-up) (#908)
  • (identity) Add per-user auth rate limiting (#996)
  • (adr0025) Complete imlpementation (#969)
  • (api) Add global IP rate limiting framework (ADR-0022 phase 1) (#846)
  • (scim) Harden RFC 7644 compliance, add docs (#968)
  • (adr0025) Phase 1 (1.1+1.2) (#952)
  • (security) Wrap secrets with secrecy crate (#369) (#912)
  • (scim) ADR 0024 - Phase 5 (#951)
  • (scim) ADR 0024 - Phase 1+2 (#925)
  • (fernet) Unify credential/token key repositories (#915)
  • Start ADR 0025 immplementation (#911)
  • (credential) Implement Phase 3 of ADR 0019 (#909)
  • Prepare PKCS#11/TPM KEK support in storage (#907)
  • (credential) Implement ADR 0019 phases 1-2 (#897)
  • Implement stateless SCIM ingress auth (ADR 0021) (#891)
  • (auth) Password hashing parity with Python Keystone (#859)
  • (audit) Implement CADF audit framework Phase 2 (#872)
  • (storage) SPIFFE checks, RBAC, rate limiting, auto-join (#861)
  • (storage) Harden preflight and erase dev KEK (#860)
  • Add bootstrap cli command (#809)
  • (mapping) ADR-0020 (mapping engine) phase 1 (#794)
  • Add inter-provider event notification system (#784)
  • Add SO_PEERCRED peer credential validation (#775)
  • Validate password for compliance conformity (#774)
  • Enforce minimum range boundaries for security
  • Add role-imply rest api (#750)
  • Add user update functionality (#747)
  • Make drivers more dynamic (#737)
  • Add keystone container with opa and policies (#738)
  • Add Admin interface over the UDS (#735)
  • Add spiffe provider (#733)
  • Introduce SecurityContext (#710)
  • Add skeleton for the spiffe mTLS integration (#695)
  • Implement ConfigManager for config watching (#691)
  • Improve the code (#686)
  • Add k8s-auth raft driver (#676)
  • Add raft support under skaffold (#667)
  • Introduce raft backend for webauthn (#658)
  • Introduce the keystone-manage cli managing raft (#656)

Fixed

  • (security) Address security review findings (#1049)
  • (passkey) Prevent user enumeration (#905)

Other

  • Revise documentation layout (#1069)
  • Moves health and metrics endpoints to dedicated listener on separate port (#910)
  • Move jsonwebtoken to keystone crate (#820)
  • mapping engine phase 3 - migrate SPIFFE (#811)
  • Rename identity_mapping to idmapping (#788)
  • Replace Regex with str::find for db connection (#760)
  • Redesign SecurityContext with two-phase validation (#717)
  • Split out remaining sql drivers (#633)
  • Split config into standalone crate (#628)

openstack-keystone-core-types

0.1.1 - 2026-07-27

Added

  • Add immutable option for project, domain, role (#1097)
  • Generalize marker pagination for v3/v4 lists (#1086)
  • (identity) Add trust create/delete and REST CRUD (#1079)
  • (catalog) Expose /v3/regions REST API (#1078)
  • (identity) Add PATCH to few resources (#1076)
  • (ldap) Add LDAP identity driver (#1047)
  • (test) Add tempest identity compatibility (#998)
  • (adr0028) Add local-quorum-bypass emergency rotation (#1032)
  • Add catalog CRUD API and bootstrap support (#1029)
  • (adr0026) Add RFC 8628 Device Authorization Grant (#1023)
  • (adr0026) Phase 6a (#1017)
  • (adr0026) Add Phase 5 offline token verification (#1016)
  • (adr0026) Add authorization code flow with PKCE (#1015)
  • (adr0026) Add client_credentials token endpoint (#1014)
  • (adr0026) Phase 2 client registration & OIDC discovery (#1013)
  • (adr0026) Phase 1 crypto engine & JWKS endpoint (#1011)
  • (adr0026) Phase 0 token abstraction and JWS driver (#1010)
  • (identity) Add per-user auth rate limiting (#996)
  • (adr0025) Complete imlpementation (#969)
  • (api) Add global IP rate limiting framework (ADR-0022 phase 1) (#846)
  • (adr0025) Phase 1 (1.1+1.2) (#952)
  • (security) Wrap secrets with secrecy crate (#369) (#912)
  • (scim) ADR 0024 - Phase 4 (protocol surface completion) (#929)
  • (scim) ADR 0024 - Phase 3 (#928)
  • (scim) ADR 0024 - Phase 1+2 (#925)
  • (credential) Implement Phase 3 of ADR 0019 (#909)
  • (credential) Implement ADR 0019 phases 1-2 (#897)
  • Implement stateless SCIM ingress auth (ADR 0021) (#891)
  • Audit framework (ADR-0023) phase 3 (#880)
  • (audit) Implement CADF audit framework Phase 2 (#872)
  • Migrate federation to new mapping engine (#839)
  • Add access rule CRD to appcred provider (#806)
  • ADR-0020 mapping phase 4 (#818)
  • (mapping) ADR-0020 (mapping engine) phase 1 (#794)
  • Add endpoint CRUD to catalog provider (#785)
  • Add inter-provider event notification system (#784)
  • Add service CRUD to the catalog provider (#773)
  • Validate password for compliance conformity (#774)
  • Return 401 on roleless scoped contexts (#742)
  • Add region CRUD to catalog SQL driver (#761)
  • Add role-imply rest api (#750)
  • Add role imply API (#749)
  • Add user update functionality (#747)
  • Add spiffe binding API (#740)
  • Add Admin interface over the UDS (#735)
  • Add spiffe provider (#733)
  • Expand role info in expand_implied_roles (#730)
  • Introduce SecurityContext (#710)
  • Improve the code (#686)
  • Add k8s-auth raft driver (#676)
  • Introduce the keystone-manage cli managing raft (#656)

Fixed

  • (api) Default enabled/domain_id on create (#1073)
  • (security) Address security review findings (#1049)
  • (federation) Allow long external unique_id values (#1033)
  • Unify ApiClient scope validation, fix nextest filter (#947)
  • Finalize ADR 0021 work (#906)
  • Resolve raft replication state races (#884)
  • (k8s_auth) Flatten k8s.aud claim from JWT TokenReview (#834)
  • Align "extra" property handling (#787)

Other

  • Revise documentation layout (#1069)
  • (security) Close mutation-testing gaps in auth/policy (#1056)
  • Move jsonwebtoken to keystone crate (#820)
  • mapping engine phase 3 - migrate SPIFFE (#811)
  • Rename identity_mapping to idmapping (#788)
  • Make resolve_implied_roles optional (#764)
  • Redesign SecurityContext with two-phase validation (#717)
  • Unify state initialization in test (#642)
  • Small optimization of the derives (#638)
  • Split the core-types crate (#640)

openstack-keystone-api-types

0.1.1 - 2026-07-27

Added

  • Add immutable option for project, domain, role (#1097)
  • Generalize marker pagination for v3/v4 lists (#1086)
  • (identity) Add trust create/delete and REST CRUD (#1079)
  • (catalog) Expose /v3/regions REST API (#1078)
  • (identity) Add PATCH to few resources (#1076)
  • (ldap) Add LDAP identity driver (#1047)
  • (test) Add tempest identity compatibility (#998)
  • (adr0028) Add local-quorum-bypass emergency rotation (#1032)
  • Add catalog CRUD API and bootstrap support (#1029)
  • (adr0026) Extend keystone-manage oauth2 CLI (#1020)
  • (adr0026) Phase 6a (#1017)
  • (adr0026) Add client_credentials token endpoint (#1014)
  • (adr0026) Phase 2 client registration & OIDC discovery (#1013)
  • (adr0026) Phase 1 crypto engine & JWKS endpoint (#1011)
  • (identity) Add per-user auth rate limiting (#996)
  • (adr0025) Complete imlpementation (#969)
  • (identity) Implement user password change endpoint (#970)
  • (api) Add global IP rate limiting framework (ADR-0022 phase 1) (#846)
  • (adr0025) Phase 1 (1.1+1.2) (#952)
  • (security) Wrap secrets with secrecy crate (#369) (#912)
  • (scim) ADR 0024 - Phase 5 (#951)
  • (scim) ADR 0024 - Phase 1+2 (#925)
  • (credential) Implement Phase 3 of ADR 0019 (#909)
  • ADR 0021 admin surface, simulate-access, and janitor (#896)
  • Implement stateless SCIM ingress auth (ADR 0021) (#891)
  • Migrate federation to new mapping engine (#839)
  • ADR-0020 mapping phase 4 (#818)
  • (mapping) ADR-0020 phase 2 (#807)
  • (mapping) ADR-0020 (mapping engine) phase 1 (#794)
  • Validate password for compliance conformity (#774)
  • Add system-user-role assignments API (#762)
  • Add role-imply rest api (#750)
  • Add user update functionality (#747)
  • Add api to list user roles on project (#639)
  • Add domain CRUD operations (#743)
  • Add spiffe binding API (#740)
  • Add spiffe provider (#733)
  • Introduce SecurityContext (#710)
  • Add skeleton for the spiffe mTLS integration (#695)
  • Improve the code (#686)

Fixed

  • Address multiple tempest failures (#1083)
  • (api) Default enabled/domain_id on create (#1073)
  • (security) Address security review findings (#1049)
  • (federation) Allow long external unique_id values (#1033)
  • Unify ApiClient scope validation, fix nextest filter (#947)
  • Finalize ADR 0021 work (#906)

Other

  • (test) Improve testing of the oauth2 OP (#1024)
  • Move jsonwebtoken to keystone crate (#820)
  • (tests) Reorganize integration_api tests (#815)
  • mapping engine phase 3 - migrate SPIFFE (#811)
  • Rename identity_mapping to idmapping (#788)
  • Further align workspace features (#772)
  • Make resolve_implied_roles optional (#764)
  • Redesign SecurityContext with two-phase validation (#717)
  • Small optimization of the derives (#638)
  • Split the core-types crate (#640)
  • Introduce features in api-types crate (#624)
  • Slim down api-types crate (#622)

openstack-keystone-audit

0.1.0 - 2026-07-27

Added

  • (audit) Complete ADR-0023 audit implementation (#887)
  • Audit framework (ADR-0023) phase 3 (#880)
  • (audit) Implement CADF audit framework Phase 2 (#872)

openstack-keystone-auth-plugin-runtime

0.1.0 - 2026-07-27

Added

  • (adr0025) Complete imlpementation (#969)

openstack-keystone-key-repository

0.1.0 - 2026-07-27

Added

  • (adr0026) Add previous-key and JTI-revocation janitor (#1021)
  • (adr0026) Add Phase 5 offline token verification (#1016)
  • (adr0026) Add client_credentials token endpoint (#1014)
  • (adr0026) Phase 0 token abstraction and JWS driver (#1010)
  • (scim) ADR 0024 - Phase 1+2 (#925)
  • (fernet) Unify credential/token key repositories (#915)

Fixed

  • Widen Fernet key index from i8 to u32 (#1080)
  • Support macOS dev builds and fs watcher shutdown (#1009)

Other

  • (deps) bump pkcs8 from 0.10.2 to 0.11.0 (#1061)

openstack-keystone-local-emergency-store

0.1.0 - 2026-07-27

Added

  • (test) Add tempest identity compatibility (#998)
  • (adr0028) Add local-quorum-bypass emergency rotation (#1032)

openstack-keystone-storage-api

0.1.0 - 2026-07-27

Added

  • (adr0026) Phase 1 crypto engine & JWKS endpoint (#1011)
  • (storage) Cert validity and SVID TTL enforcement (#886)
  • (storage) SPIFFE checks, RBAC, rate limiting, auto-join (#861)
  • (storage) Complete ADR-0016-v2 (#844)
  • (storage) implement ADR 0016-v2 Phases 1-4 — encrypted storage with quarantine (#840)

Fixed

  • (webauthn) Rotate raft ceremony-state keyspaces (#890)

Other

  • (storage) Decouple core from storage (#832)

openstack-keystone-core

0.1.2 - 2026-07-27

Added

  • Auto-register backend drivers via inventory (#1105)
  • Add immutable option for project, domain, role (#1097)
  • (config) Revoke Vault token on shutdown (#1088)
  • (identity) Add trust create/delete and REST CRUD (#1079)
  • (identity) Add PATCH to few resources (#1076)
  • (tempest) Improve tempest testing (#1046)
  • (test) Add tempest identity compatibility (#998)
  • (adr0028) Add local-quorum-bypass emergency rotation (#1032)
  • (adr0026) Add RFC 8628 Device Authorization Grant (#1023)
  • (adr0026) Add previous-key and JTI-revocation janitor (#1021)
  • (adr0026) Phase 6a (#1017)
  • (adr0026) Add Phase 5 offline token verification (#1016)
  • (adr0026) Add authorization code flow with PKCE (#1015)
  • (adr0026) Add client_credentials token endpoint (#1014)
  • (adr0026) Phase 2 client registration & OIDC discovery (#1013)
  • (adr0026) Phase 1 crypto engine & JWKS endpoint (#1011)
  • (adr0026) Phase 0 token abstraction and JWS driver (#1010)
  • (api) capture client IP via proxy headers & SPIFFE (Start capturing client information in the request processing #358 follow-up) (#908)
  • (identity) Add per-user auth rate limiting (#996)
  • (adr0025) Complete imlpementation (#969)
  • (api) Add global IP rate limiting framework (ADR-0022 phase 1) (#846)
  • (adr0025) Phase 1 (1.1+1.2) (#952)
  • (security) Wrap secrets with secrecy crate (#369) (#912)
  • (scim) ADR 0024 - Phase 5 (#951)
  • (scim) ADR 0024 - Phase 4 (protocol surface completion) (#929)
  • (scim) ADR 0024 - Phase 3 (#928)
  • (scim) ADR 0024 - Phase 1+2 (#925)
  • (credential) Implement Phase 3 of ADR 0019 (#909)
  • (credential) Implement ADR 0019 phases 1-2 (#897)
  • ADR 0021 admin surface, simulate-access, and janitor (#896)
  • Implement stateless SCIM ingress auth (ADR 0021) (#891)
  • (audit) Complete ADR-0023 audit implementation (#887)
  • (storage) Cert validity and SVID TTL enforcement (#886)
  • Audit framework (ADR-0023) phase 3 (#880)
  • (auth) Password hashing parity with Python Keystone (#859)
  • (audit) Implement CADF audit framework Phase 2 (#872)
  • Migrate federation to new mapping engine (#839)
  • Add access rule CRD to appcred provider (#806)
  • ADR-0020 mapping phase 4 (#818)
  • Add bootstrap cli command (#809)
  • (mapping) ADR-0020 (mapping engine) phase 1 (#794)
  • Add endpoint CRUD to catalog provider (#785)
  • Add inter-provider event notification system (#784)
  • Add service CRUD to the catalog provider (#773)
  • Validate password for compliance conformity (#774)
  • Return 401 on roleless scoped contexts (#742)
  • Add region CRUD to catalog SQL driver (#761)
  • Add timing attack protection and failed auth tracking (#758)
  • Add role-imply rest api (#750)
  • Add role imply API (#749)
  • Add user update functionality (#747)
  • Add domain CRUD operations (#743)
  • Add spiffe binding API (#740)
  • Normalize the policy enforcer structure (#741)
  • Make drivers more dynamic (#737)
  • Add Admin interface over the UDS (#735)
  • Add spiffe provider (#733)
  • Expand role info in expand_implied_roles (#730)
  • Introduce SecurityContext (#710)
  • Talk to OPA over unix socket (#701)
  • Add skeleton for the spiffe mTLS integration (#695)
  • Implement ConfigManager for config watching (#691)
  • Improve the code (#686)
  • Add k8s-auth raft driver (#676)
  • Add basic healthcheck endpoint (#671)
  • Make raft storage available through state (#657)

Fixed

  • (api) Default enabled/domain_id on create (#1073)
  • (security) Do not allow ec2cred token to do anything (#1071)
  • (security) Address security review findings (#1049)
  • (adr0026) Bind Token Exchange grant to the issuing domain (#1019)
  • Unify ApiClient scope validation, fix nextest filter (#947)
  • Finalize ADR 0021 work (#906)
  • (ci) Prepare workflows for merge queue (#902)
  • Resolve raft replication state races (#884)
  • (core) Eliminate mapping race condition (#876)
  • (k8s_auth) Flatten k8s.aud claim from JWT TokenReview (#834)
  • (auth) Close admin SVID impersonation gap (#833)

Other

  • (deps) Bump sea-orm and sea-orm-migration to 2.0 (#1089)
  • Revise documentation layout (#1069)
  • (security) Close mutation-testing gaps in auth/policy (#1056)
  • Extract password hashing into own crate (#1055)
  • (test) Improve testing of the oauth2 OP (#1024)
  • (deps) bump scrypt from 0.11.0 to 0.12.0 (#923)
  • Reorganize dockerfile and deps (#857)
  • (core) Remove spiffe crate dependency (#858)
  • Wrap ServiceState under ExecutionContext (#856)
  • (storage) Decouple core from storage (#832)
  • (core) Eliminate XxxProvider enums (#830)
  • Move jsonwebtoken to keystone crate (#820)
  • mapping engine phase 3 - migrate SPIFFE (#811)
  • (deps) bump hmac from 0.12.1 to 0.13.0 (#801)
  • Rename identity_mapping to idmapping (#788)
  • Consolidate password update flows (#778)
  • Further align workspace features (#772)
  • Make resolve_implied_roles optional (#764)
  • Redesign SecurityContext with two-phase validation (#717)
  • (deps) bump jsonwebtoken from 10.3.0 to 10.4.0 (#707)
  • Introduce dynamic plugins (#643)
  • Small optimization of the derives (#638)
  • Split the core-types crate (#640)
  • Split out remaining sql drivers (#633)
  • Split more drivers to separate crates (#632)
  • Drop unnecessary derives to help compilation (#631)
  • Drop unnecessary tracing directives (#627)
  • Split config into standalone crate (#628)
  • Rework http client pool (#629)
  • Make assignment sql driver a standalone crate (#626)
  • Move assignment parameters resolution to driver (#625)
  • Introduce features in api-types crate (#624)
  • Slim down api-types crate (#622)
  • Split out webauthn into crate (#621)
  • Split out token-fernet driver (#620)
  • Prepare slit out of the FernetTokenProvider (#619)
  • Move benchmark into the proper crate (#614)

openstack-keystone-storage-crypto

0.1.0 - 2026-07-27

Added

  • (scim) ADR 0024 - Phase 3 (#928)
  • (storage) Add PKCS#11 KEK provider crate (#917)
  • (storage) Cert validity and SVID TTL enforcement (#886)
  • (audit) Implement CADF audit framework Phase 2 (#872)
  • (storage) SPIFFE checks, RBAC, rate limiting, auto-join (#861)
  • (storage) Harden preflight and erase dev KEK (#860)
  • (storage) Complete ADR-0016-v2 (#844)
  • (storage) implement ADR 0016-v2 Phases 1-4 — encrypted storage with quarantine (#840)

Other

  • (deps) Batch update dependencies (#875)

openstack-keystone-storage-crypto-pkcs11

0.1.0 - 2026-07-27

Added

  • (adr0026) Phase 1 crypto engine & JWKS endpoint (#1011)
  • (storage) Add PKCS#11 KEK provider crate (#917)

openstack-keystone-storage-crypto-tpm

0.1.0 - 2026-07-27

Added

  • (adr0026) Phase 1 crypto engine & JWKS endpoint (#1011)
  • (storage) Add PKCS#11 KEK provider crate (#917)

openstack-keystone-distributed-storage

0.1.1 - 2026-07-27

Added

  • (test) Add tempest identity compatibility (#998)
  • (adr0028) Add local-quorum-bypass emergency rotation (#1032)
  • (adr0026) Phase 1 crypto engine & JWKS endpoint (#1011)
  • (storage) Add PKCS#11 KEK provider crate (#917)
  • Prepare PKCS#11/TPM KEK support in storage (#907)
  • Implement background DEK re-encryption pipeline (#898)
  • ADR 0021 admin surface, simulate-access, and janitor (#896)
  • (storage) Cert validity and SVID TTL enforcement (#886)
  • (storage) SPIFFE checks, RBAC, rate limiting, auto-join (#861)
  • (storage) Harden preflight and erase dev KEK (#860)
  • (storage) Add SPIFFE mTLS support to Raft gRPC (#852)
  • (cli) Add cli storage subcommands per ADR 0016-v2 (#850)
  • (storage) Complete ADR-0016-v2 (#844)
  • (storage) implement ADR 0016-v2 Phases 1-4 — encrypted storage with quarantine (#840)
  • (mapping) ADR-0020 phase 2 (#807)
  • (adr) Add updated revision of the DS ADR (#795)
  • (mapping) ADR-0020 (mapping engine) phase 1 (#794)
  • Add skeleton for the spiffe mTLS integration (#695)
  • Implement ConfigManager for config watching (#691)
  • Improve the code (#686)
  • Add k8s-auth raft driver (#676)
  • Add SetIndex/RemoveIndex storage commands (#675)
  • Add basic healthcheck endpoint (#671)
  • Add metadata for raft data (#670)
  • Add transaction support for Raft storage (#669)
  • Add initial benchmarks for the storage (#668)
  • Add raft support under skaffold (#667)
  • Introduce raft backend for webauthn (#658)
  • Prepare raft storage promotion (#659)
  • Make raft storage available through state (#657)
  • Introduce the keystone-manage cli managing raft (#656)

Fixed

  • Support macOS dev builds and fs watcher shutdown (#1009)
  • Finalize ADR 0021 work (#906)
  • (ci) Prepare workflows for merge queue (#902)
  • Further polish storage crate (#892)
  • (webauthn) Rotate raft ceremony-state keyspaces (#890)
  • Resolve raft replication state races (#884)

Other

  • Silence some clippy warnings (#1030)
  • (deps) Batch update dependencies (#875)
  • (core) Remove spiffe crate dependency (#858)
  • Add SpiFFE Raft integration test by skaffold (#854)
  • Wrap ServiceState under ExecutionContext (#856)
  • (storage) Decouple core from storage (#832)
  • Update raft drivers mocking (#791)
  • Add mock raft storage for unittest (#790)
  • Make core crates a workspace dependency (#736)
  • Redesign SecurityContext with two-phase validation (#717)
  • (deps) Bump openraft to alpha17 (#641)

openstack-keystone-api-key-driver-raft

0.1.0 - 2026-07-27

Added

  • Auto-register backend drivers via inventory (#1105)
  • Generalize marker pagination for v3/v4 lists (#1086)
  • ADR 0021 admin surface, simulate-access, and janitor (#896)
  • Implement stateless SCIM ingress auth (ADR 0021) (#891)

openstack-keystone-password-hashing

0.1.0 - 2026-07-27

Other

  • Extract password hashing into own crate (#1055)

openstack-keystone-appcred-driver-sql

0.1.0 - 2026-07-27

Added

  • Auto-register backend drivers via inventory (#1105)
  • (security) Wrap secrets with secrecy crate (#369) (#912)
  • Add access rule CRD to appcred provider (#806)
  • Make drivers more dynamic (#737)

Other

  • (deps) Bump sea-orm and sea-orm-migration to 2.0 (#1089)
  • Extract password hashing into own crate (#1055)
  • (core) Eliminate XxxProvider enums (#830)
  • Move jsonwebtoken to keystone crate (#820)
  • Further align workspace features (#772)

openstack-keystone-assignment-driver-sql

0.1.0 - 2026-07-27

Added

  • Auto-register backend drivers via inventory (#1105)
  • (audit) Implement CADF audit framework Phase 2 (#872)
  • Add role-imply rest api (#750)
  • Make drivers more dynamic (#737)

Fixed

  • Respect group_id param in assignment list (#953)
  • (ci) Prepare workflows for merge queue (#902)

Other

  • Wrap ServiceState under ExecutionContext (#856)
  • (storage) Decouple core from storage (#832)
  • Move jsonwebtoken to keystone crate (#820)
  • Further align workspace features (#772)
  • Make resolve_implied_roles optional (#764)

openstack-keystone-catalog-driver-sql

0.1.0 - 2026-07-27

Added

  • Auto-register backend drivers via inventory (#1105)
  • Generalize marker pagination for v3/v4 lists (#1086)
  • (mapping) ADR-0020 (mapping engine) phase 1 (#794)
  • Add endpoint CRUD to catalog provider (#785)
  • Add inter-provider event notification system (#784)
  • Add service CRUD to the catalog provider (#773)
  • Add region CRUD to catalog SQL driver (#761)
  • Make drivers more dynamic (#737)

Fixed

  • Align "extra" property handling (#787)

Other

  • (deps) Bump sea-orm and sea-orm-migration to 2.0 (#1089)
  • Move jsonwebtoken to keystone crate (#820)
  • Further align workspace features (#772)

openstack-keystone-credential-driver-sql

0.1.0 - 2026-07-27

Added

  • Auto-register backend drivers via inventory (#1105)
  • Generalize marker pagination for v3/v4 lists (#1086)
  • (adr0026) Phase 1 crypto engine & JWKS endpoint (#1011)
  • (adr0026) Phase 0 token abstraction and JWS driver (#1010)
  • (fernet) Unify credential/token key repositories (#915)
  • (credential) Enforce Null Key check at startup (#913)
  • (credential) Implement Phase 3 of ADR 0019 (#909)
  • (credential) Implement ADR 0019 phases 1-2 (#897)

Fixed

  • Widen Fernet key index from i8 to u32 (#1080)

Other

  • (deps) Bump sea-orm and sea-orm-migration to 2.0 (#1089)

openstack-keystone-auth-plugin-identity-driver-raft

0.1.0 - 2026-07-27

Added

  • Auto-register backend drivers via inventory (#1105)
  • (adr0025) Complete imlpementation (#969)

openstack-keystone-federation-driver-sql

0.1.0 - 2026-07-27

Added

  • Auto-register backend drivers via inventory (#1105)
  • Generalize marker pagination for v3/v4 lists (#1086)
  • (security) Wrap secrets with secrecy crate (#369) (#912)
  • (scim) ADR 0024 - Phase 5 (#951)
  • Migrate federation to new mapping engine (#839)
  • Make drivers more dynamic (#737)

Other

  • (deps) Bump sea-orm and sea-orm-migration to 2.0 (#1089)
  • Move jsonwebtoken to keystone crate (#820)
  • Further align workspace features (#772)

openstack-keystone-identity-driver-ldap

0.1.0 - 2026-07-27

Added

  • Auto-register backend drivers via inventory (#1105)
  • (ldap) Add LDAP identity driver (#1047)

Other

  • (security) Close mutation-testing gaps in auth/policy (#1056)

openstack-keystone-identity-driver-sql

0.1.0 - 2026-07-27

Added

  • Auto-register backend drivers via inventory (#1105)
  • Generalize marker pagination for v3/v4 lists (#1086)
  • (identity) Add per-user auth rate limiting (#996)
  • (identity) Implement user password change endpoint (#970)
  • (security) Wrap secrets with secrecy crate (#369) (#912)
  • (scim) ADR 0024 - Phase 5 (#951)
  • (scim) ADR 0024 - Phase 3 (#928)
  • (scim) ADR 0024 - Phase 1+2 (#925)
  • (auth) Password hashing parity with Python Keystone (#859)
  • (mapping) ADR-0020 (mapping engine) phase 1 (#794)
  • Add inter-provider event notification system (#784)
  • Add timing attack protection and failed auth tracking (#758)
  • Add role-imply rest api (#750)
  • Add user update functionality (#747)
  • Make drivers more dynamic (#737)

Fixed

  • (api) Default enabled/domain_id on create (#1073)
  • (federation) Allow long external unique_id values (#1033)
  • (identity) Support federated existence checks (#1012)
  • Validate password complexity before storing password (#845)
  • Align "extra" property handling (#787)

Other

  • (deps) Bump sea-orm and sea-orm-migration to 2.0 (#1089)
  • Extract password hashing into own crate (#1055)
  • Silence some clippy warnings (#1030)
  • Move jsonwebtoken to keystone crate (#820)
  • Consolidate password update flows (#778)
  • Further align workspace features (#772)

openstack-keystone-idmapping-driver-sql

0.1.0 - 2026-07-27

Added

  • Auto-register backend drivers via inventory (#1105)
  • Make drivers more dynamic (#737)

Fixed

  • (ci) Prepare workflows for merge queue (#902)

Other

  • Move jsonwebtoken to keystone crate (#820)
  • Rename identity_mapping to idmapping (#788)

openstack-keystone-k8s-auth-driver-raft

0.1.0 - 2026-07-27

Added

  • Auto-register backend drivers via inventory (#1105)
  • Generalize marker pagination for v3/v4 lists (#1086)
  • ADR-0020 mapping phase 4 (#818)
  • (mapping) ADR-0020 (mapping engine) phase 1 (#794)
  • Add user update functionality (#747)
  • Make drivers more dynamic (#737)

Other

  • (storage) Decouple core from storage (#832)
  • Update raft drivers mocking (#791)
  • Add mock raft storage for unittest (#790)

openstack-keystone-k8s-auth-driver-sql

0.1.0 - 2026-07-27

Added

  • Auto-register backend drivers via inventory (#1105)
  • Generalize marker pagination for v3/v4 lists (#1086)
  • ADR-0020 mapping phase 4 (#818)
  • Make drivers more dynamic (#737)

Other

  • (deps) Bump sea-orm and sea-orm-migration to 2.0 (#1089)
  • Wrap ServiceState under ExecutionContext (#856)
  • Move jsonwebtoken to keystone crate (#820)

openstack-keystone-mapping-driver-raft

0.1.0 - 2026-07-27

Added

  • Auto-register backend drivers via inventory (#1105)
  • (mapping) ADR-0020 phase 2 (#807)
  • (mapping) ADR-0020 (mapping engine) phase 1 (#794)

Other

  • (storage) Decouple core from storage (#832)

`openstack-keystone-oauth2-client-dri

@github-actions

github-actions Bot commented Jun 5, 2026

Copy link
Copy Markdown

🦢 Load Test Results

Goose Attack Report

Plan Overview

Action Started Stopped Elapsed Users
Increasing 26-07-27 15:22:37 26-07-27 15:22:52 00:00:15 0 → 30
Maintaining 26-07-27 15:22:52 26-07-27 15:23:22 00:00:30 30
Decreasing 26-07-27 15:23:22 26-07-27 15:23:22 00:00:00 0 ← 30

Request Metrics

Method Name # Requests # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
DELETE DELETE /v3/auth/tokens 445 0 122.00 24 157 14.83 0.00
DELETE DELETE /v3/projects/:id (teardown) 2 0 54.00 30 78 0.07 0.00
DELETE DELETE /v3/users/:id (teardown) 3 0 59.33 37 79 0.10 0.00
GET 4020 0 116.42 86 225 134.00 0.00
GET GET /v3/auth/tokens (validate new) 444 0 122.77 68 152 14.80 0.00
GET GET /v3/projects/:id 598 0 100.27 75 128 19.93 0.00
GET GET /v3/projects/:id (catalog) 598 0 100.38 79 127 19.93 0.00
GET GET /v3/users/:id 893 0 100.74 81 129 29.77 0.00
GET GET /v3/users/:id (catalog) 720 0 100.51 85 127 24.00 0.00
POST POST /v3/auth/tokens 442 0 94.01 84 114 14.73 0.00
Aggregated 8165 0 110.34 24 225 272.17 0.00

Response Time Metrics

Method Name 50%ile (ms) 60%ile (ms) 70%ile (ms) 80%ile (ms) 90%ile (ms) 95%ile (ms) 99%ile (ms) 100%ile (ms)
DELETE DELETE /v3/auth/tokens 120 120 120 130 130 130 150 157
DELETE DELETE /v3/projects/:id (teardown) 30 30 30 78 78 78 78 78
DELETE DELETE /v3/users/:id (teardown) 62 62 62 62 79 79 79 79
GET 100 110 110 120 180 190 190 225
GET GET /v3/auth/tokens (validate new) 120 120 130 130 130 130 150 150
GET GET /v3/projects/:id 99 100 100 100 110 110 120 128
GET GET /v3/projects/:id (catalog) 100 100 100 100 110 110 120 127
GET GET /v3/users/:id 100 100 100 100 110 110 120 129
GET GET /v3/users/:id (catalog) 100 100 100 100 110 110 120 127
POST POST /v3/auth/tokens 94 95 95 97 100 100 110 110
Aggregated 100 110 110 120 130 180 190 225

Status Code Metrics

Method Name Status Codes
DELETE DELETE /v3/auth/tokens 445 [204]
DELETE DELETE /v3/projects/:id (teardown) 2 [204]
DELETE DELETE /v3/users/:id (teardown) 3 [204]
GET 4,020 [200]
GET GET /v3/auth/tokens (validate new) 444 [200]
GET GET /v3/projects/:id 598 [200]
GET GET /v3/projects/:id (catalog) 598 [200]
GET GET /v3/users/:id 893 [200]
GET GET /v3/users/:id (catalog) 720 [200]
POST POST /v3/auth/tokens 442 [201]
Aggregated 450 [204], 7,273 [200], 442 [201]

Transaction Metrics

Transaction # Times Run # Fails Average (ms) Min (ms) Max (ms) RPS Failures/s
ReadHeavy
0.0 0 0 0.00 0 0 0.00 0.00
0.1 681 0 107.88 96 135 22.70 0.00
0.2 680 0 100.59 86 133 22.67 0.00
0.3 680 0 100.02 90 129 22.67 0.00
TokenLifecycle
1.0 0 0 0.00 0 0 0.00 0.00
1.1 445 0 339.95 187 387 14.83 0.00
ValidateToken
2.0 0 0 0.00 0 0 0.00 0.00
2.1 660 0 182.67 115 225 22.00 0.00
UserCRUD
3.0 0 0 0.00 0 0 0.00 0.00
3.1 0 0 0.00 0 0 0.00 0.00
3.2 893 0 100.80 81 130 29.77 0.00
3.3 3 0 59.33 37 79 0.10 0.00
ProjectCRUD
4.0 0 0 0.00 0 0 0.00 0.00
4.1 0 0 0.00 0 0 0.00 0.00
4.2 598 0 100.31 75 128 19.93 0.00
4.3 2 0 54.50 31 78 0.07 0.00
UserRead
5.0 0 0 0.00 0 0 0.00 0.00
5.1 722 0 107.62 96 140 24.07 0.00
5.2 720 0 100.57 85 127 24.00 0.00
ProjectRead
6.0 0 0 0.00 0 0 0.00 0.00
6.1 597 0 100.61 90 124 19.90 0.00
6.2 598 0 100.44 79 127 19.93 0.00
Aggregated 7279 0 123.78 31 387 242.63 0.00

Scenario Metrics

Transaction # Users # Times Run Average (ms) Min (ms) Max (ms) Scenarios/s Iterations
ReadHeavy 7 678 309.59 289 349 22.60 96.86
TokenLifecycle 5 440 340.89 319 387 14.67 88.00
ValidateToken 4 656 182.87 165 225 21.87 164.00
UserCRUD 3 890 100.83 89 130 29.67 296.67
ProjectCRUD 2 596 100.36 90 128 19.87 298.00
UserRead 5 718 208.81 192 253 23.93 143.60
ProjectRead 4 594 201.60 188 241 19.80 148.50
Aggregated 30 4572 196.65 89 387 152.40 1235.62

View full report

@github-actions

github-actions Bot commented Jun 5, 2026

Copy link
Copy Markdown

🐰 Bencher Report

Projectkeystone
Branchrelease-plz-2026-06-05T09-00-15Z
Testbedubuntu-latest
Click to view all benchmark results
BenchmarkLatencyBenchmark Result
nanoseconds (ns)
(Result Δ%)
Upper Boundary
nanoseconds (ns)
(Limit %)
Command_Serde/apply/remove📈 view plot
🚷 view threshold
87,398.00 ns
(-71.83%)Baseline: 310,270.70 ns
1,597,327.62 ns
(5.47%)
Command_Serde/apply/set📈 view plot
🚷 view threshold
99,118.00 ns
(-70.19%)Baseline: 332,506.39 ns
1,575,659.60 ns
(6.29%)
Command_Serde/pack/delete📈 view plot
🚷 view threshold
127.44 ns
(+6.99%)Baseline: 119.11 ns
155.79 ns
(81.80%)
Command_Serde/pack/delete_index📈 view plot
🚷 view threshold
113.81 ns
(+8.19%)Baseline: 105.20 ns
136.02 ns
(83.67%)
Command_Serde/pack/set📈 view plot
🚷 view threshold
194.27 ns
(+1.74%)Baseline: 190.94 ns
248.48 ns
(78.18%)
Command_Serde/pack/set_index📈 view plot
🚷 view threshold
114.86 ns
(+9.22%)Baseline: 105.16 ns
136.09 ns
(84.40%)
Command_Serde/unpack/delete📈 view plot
🚷 view threshold
221.43 ns
(+19.51%)Baseline: 185.29 ns
261.08 ns
(84.81%)
Command_Serde/unpack/delete_index📈 view plot
🚷 view threshold
179.94 ns
(+15.94%)Baseline: 155.20 ns
212.78 ns
(84.57%)
Command_Serde/unpack/set📈 view plot
🚷 view threshold
283.59 ns
(+8.71%)Baseline: 260.87 ns
352.55 ns
(80.44%)
Command_Serde/unpack/set_index📈 view plot
🚷 view threshold
177.59 ns
(+16.60%)Baseline: 152.31 ns
208.26 ns
(85.28%)
Payload_encryption/pack/remove_cmd📈 view plot
🚷 view threshold
119.02 ns
(+6.11%)Baseline: 112.17 ns
147.67 ns
(80.60%)
Payload_encryption/pack/set_cmd📈 view plot
🚷 view threshold
189.17 ns
(-3.28%)Baseline: 195.58 ns
262.52 ns
(72.06%)
Payload_encryption/unpack/remove_cmd📈 view plot
🚷 view threshold
218.43 ns
(+11.89%)Baseline: 195.21 ns
276.45 ns
(79.01%)
Payload_encryption/unpack/set_cmd📈 view plot
🚷 view threshold
290.81 ns
(+6.41%)Baseline: 273.29 ns
375.09 ns
(77.53%)
Raft_1Node_Latency/prefix/1node📈 view plot
🚷 view threshold
4,431,500.00 ns
(+68.07%)Baseline: 2,636,633.59 ns
6,289,617.66 ns
(70.46%)
Raft_1Node_Latency/read/1node📈 view plot
🚷 view threshold
35,604.00 ns
(-7.29%)Baseline: 38,404.62 ns
54,268.68 ns
(65.61%)
Raft_1Node_Latency/remove/1node📈 view plot
🚷 view threshold
278,600.00 ns
(-65.37%)Baseline: 804,428.59 ns
3,892,727.22 ns
(7.16%)
Raft_1Node_Latency/write/1node📈 view plot
🚷 view threshold
300,710.00 ns
(-68.53%)Baseline: 955,433.28 ns
5,441,369.49 ns
(5.53%)
build_snapshot/default📈 view plot
🚷 view threshold
111,180.00 ns
(-9.94%)Baseline: 123,444.67 ns
208,750.06 ns
(53.26%)
fernet token/project📈 view plot
🚷 view threshold
1,577.40 ns
(+12.28%)Baseline: 1,404.82 ns
1,776.72 ns
(88.78%)
get_data_keyspace📈 view plot
🚷 view threshold
0.35 ns
(+12.42%)Baseline: 0.31 ns
0.38 ns
(91.81%)
get_db📈 view plot
🚷 view threshold
0.35 ns
(+13.06%)Baseline: 0.31 ns
0.38 ns
(92.41%)
get_fernet_token_timestamp/project📈 view plot
🚷 view threshold
151.17 ns
(+8.49%)Baseline: 139.34 ns
179.74 ns
(84.11%)
get_keyspace📈 view plot
🚷 view threshold
4.76 ns
(-14.46%)Baseline: 5.56 ns
12.51 ns
(38.03%)
🐰 View full continuous benchmarking report in Bencher

@openstack-experimental-release-plz
openstack-experimental-release-plz Bot force-pushed the release-plz-2026-06-05T09-00-15Z branch 22 times, most recently from d04a4df to 7fe2614 Compare June 12, 2026 09:11
@openstack-experimental-release-plz
openstack-experimental-release-plz Bot force-pushed the release-plz-2026-06-05T09-00-15Z branch 6 times, most recently from 3966098 to 805ed8e Compare June 15, 2026 10:08
@openstack-experimental-release-plz
openstack-experimental-release-plz Bot force-pushed the release-plz-2026-06-05T09-00-15Z branch 28 times, most recently from fd0af7c to 53568cd Compare June 26, 2026 20:00
@github-actions

github-actions Bot commented Jul 17, 2026

Copy link
Copy Markdown

🧪 Tempest Identity Compatibility Results (advisory, non-blocking)

rust

Totals
======
Ran: 119 tests in 35.6359 sec.
 - Passed: 57
 - Skipped: 4
 - Expected Fail: 0
 - Unexpected Success: 0
 - Failed: 58
Sum of execute time for each test: 23.7550 sec.
Failed test IDs
===== FAILED TESTS (target=rust) =====
tempest.api.identity.admin.v3.test_application_credentials.ApplicationCredentialsV3AdminTest.test_create_application_credential_with_roles[id-3b3dd48f-3388-406a-a9e6-4d078a552d0e]
tempest.api.identity.admin.v3.test_credentials.CredentialsTestJSON.test_credentials_create_get_update_delete[id-7cd59bf9-bda4-4c72-9467-d21cab278355,smoke]
tempest.api.identity.admin.v3.test_default_project_id.TestDefaultProjectId.test_default_project_id[id-d6110661-6a71-49a7-a453-b5e26640ff6d]
tempest.api.identity.admin.v3.test_groups.GroupsV3TestJSON.test_group_users_add_list_delete[id-1598521a-2f36-4606-8df9-30772bd51339,smoke]
tempest.api.identity.admin.v3.test_groups.GroupsV3TestJSON.test_list_user_groups[id-64573281-d26a-4a52-b899-503cb0f4e4ec]
tempest.api.identity.admin.v3.test_inherits.InheritsV3TestJSON.test_inherit_assign_check_revoke_roles_on_projects_group[id-26021436-d5a4-4256-943c-ded01e0d4b45]
tempest.api.identity.admin.v3.test_inherits.InheritsV3TestJSON.test_inherit_assign_check_revoke_roles_on_projects_user[id-18b70e45-7687-4b72-8277-b8f1a47d7591]
tempest.api.identity.admin.v3.test_inherits.InheritsV3TestJSON.test_inherit_assign_list_check_revoke_roles_on_domains_group[id-c7a8dda2-be50-4fb4-9a9c-e830771078b1]
tempest.api.identity.admin.v3.test_inherits.InheritsV3TestJSON.test_inherit_assign_list_check_revoke_roles_on_domains_user[id-4e6f0366-97c8-423c-b2be-41eae6ac91c8]
tempest.api.identity.admin.v3.test_inherits.InheritsV3TestJSON.test_inherit_assign_list_revoke_user_roles_on_domain[id-3acf666e-5354-42ac-8e17-8b68893bcd36]
tempest.api.identity.admin.v3.test_inherits.InheritsV3TestJSON.test_inherit_assign_list_revoke_user_roles_on_project_tree[id-9f02ccd9-9b57-46b4-8f77-dd5a736f3a06]
tempest.api.identity.admin.v3.test_domains.DomainsTestJSON.test_create_domain_without_description[id-2abf8764-309a-4fa9-bc58-201b799817ad]
tempest.api.identity.admin.v3.test_domains.DomainsTestJSON.test_create_update_delete_domain[id-f2f5b44a-82e8-4dad-8084-0661ea3b18cf,smoke]
tempest.api.identity.admin.v3.test_domain_configuration.DomainConfigurationTestJSON.test_create_domain_config_and_show_config_groups_and_options[id-9e3ff13c-f597-4f01-9377-d6c06c2a1477]
tempest.api.identity.admin.v3.test_domain_configuration.DomainConfigurationTestJSON.test_create_update_and_delete_domain_config[id-7161023e-5dd0-4612-9da0-1bac6ac30b63]
tempest.api.identity.admin.v3.test_domain_configuration.DomainConfigurationTestJSON.test_create_update_and_delete_domain_config_groups_and_opts[id-c7510fa2-6661-4170-9c6b-4783a80651e9]
tempest.api.identity.admin.v3.test_domain_configuration.DomainConfigurationTestJSON.test_show_default_group_config_and_options[id-11a02bf0-6f94-4380-b3b0-c8dc18fc0d22]
tempest.api.identity.admin.v3.test_domains.DomainsTestJSON.test_domain_delete_cascades_content[id-d8d318b7-d1b3-4c37-94c5-3c5ba0b121ea]
tempest.api.identity.admin.v3.test_domains.DomainsTestJSON.test_list_domains_filter_by_enabled[id-3fd19840-65c1-43f8-b48c-51bdd066dff9]
tempest.api.identity.admin.v3.test_list_users.UsersV3TestJSON.test_list_users_with_not_enabled[id-bff8bf2f-9408-4ef5-b63a-753c8c2124eb]
tempest.api.identity.admin.v3.test_list_projects.ListProjectsStaticTestJSON.test_list_projects[id-1d830662-22ad-427c-8c3e-4ec854b0af44]
tempest.api.identity.admin.v3.test_domains_negative.DomainsNegativeTestJSON.test_create_domain_with_name_length_over_64[id-37b1bbf2-d664-4785-9a11-333438586eae,negative]
tempest.api.identity.admin.v3.test_domains_negative.DomainsNegativeTestJSON.test_delete_active_domain[gate,id-1f3fbff5-4e44-400d-9ca1-d953f05f609b,negative]
setUpClass (tempest.api.identity.admin.v3.test_endpoint_groups.EndPointGroupsTest)
tempest.api.identity.admin.v3.test_policies.PoliciesTestJSON.test_create_update_delete_policy[id-e544703a-2f03-4cf2-9b0f-350782fdb0d3,smoke]
tempest.api.identity.admin.v3.test_policies.PoliciesTestJSON.test_list_policies[id-1a0ad286-2d06-4123-ab0d-728893a76201]
tempest.api.identity.admin.v3.test_oauth_consumers.OAUTHConsumersV3Test.test_create_and_show_consumer[id-c8307ea6-a86c-47fd-ae7b-5b3b2caca76d]
tempest.api.identity.admin.v3.test_oauth_consumers.OAUTHConsumersV3Test.test_delete_consumer[id-fdfa1b7f-2a31-4354-b2c7-f6ae20554f93]
tempest.api.identity.admin.v3.test_oauth_consumers.OAUTHConsumersV3Test.test_list_consumers[id-09ca50de-78f2-4ffb-ac71-f2254036b2b8]
tempest.api.identity.admin.v3.test_oauth_consumers.OAUTHConsumersV3Test.test_update_consumer[id-080a9b1a-c009-47c0-9979-5305bf72e3dc]
tempest.api.identity.admin.v3.test_project_tags.IdentityV3ProjectTagsTest.test_list_update_delete_project_tags[id-7c123aac-999d-416a-a0fb-84b915ab10de]
setUpClass (tempest.api.identity.admin.v3.test_roles.RolesV3TestJSON)
tempest.api.identity.admin.v3.test_projects.ProjectsTestJSON.test_create_is_domain_project[id-a7eb9416-6f9b-4dbb-b71b-7f73aaef59d5]
tempest.api.identity.admin.v3.test_list_projects.ListProjectsTestJSON.test_list_projects_with_enabled[id-0fe7a334-675a-4509-b00e-1c4b95d5dae8]
tempest.api.identity.admin.v3.test_list_projects.ListProjectsTestJSON.test_list_projects_with_parent[id-6edc66f5-2941-4a17-9526-4073311c1fac]
tempest.api.identity.admin.v3.test_projects.ProjectsTestJSON.test_project_create_with_parent[id-1854f9c0-70bc-4d11-a08a-1c789d339e3d]
tempest.api.identity.admin.v3.test_projects.ProjectsTestJSON.test_project_get_equals_list[id-d1db68b6-aebe-4fa0-b79d-d724d2e21162]
tempest.api.identity.admin.v3.test_trusts.TrustsV3TestJSON.test_get_trusts_all[id-4773ebd5-ecbf-4255-b8d8-b63e6f72b65d,smoke]
tempest.api.identity.admin.v3.test_tokens.TokensV3TestJSON.test_get_available_domain_scopes[id-ec5ecb05-af64-4c04-ac86-4d9f6f12f185]
tempest.api.identity.v3.test_catalog.IdentityCatalogTest.test_catalog_standardization[id-56b57ced-22b8-4127-9b8a-565dfb0207e2]
tempest.api.identity.admin.v3.test_tokens.TokensV3TestJSON.test_rescope_token[id-565fa210-1da1-4563-999b-f7b5b67cf112]
tempest.api.identity.admin.v3.test_trusts.TrustsV3TestJSON.test_get_trusts_query[id-6268b345-87ca-47c0-9ce3-37792b43403a]
tempest.api.identity.admin.v3.test_projects_negative.ProjectsNegativeStaticTestJSON.test_create_projects_name_length_over_64[id-502b6ceb-b0c8-4422-bf53-f08fdb21e2f0,negative]
tempest.api.identity.admin.v3.test_trusts.TrustsV3TestJSON.test_trust_expire[id-0ed14b66-cefd-4b5c-a964-65759453e292]
tempest.api.identity.v3.test_api_discovery.TestApiDiscovery.test_api_media_types[id-657c1970-4722-4189-8831-7325f3bc4265,smoke]
tempest.api.identity.v3.test_api_discovery.TestApiDiscovery.test_api_version_resources[id-b9232f5e-d9e5-4d97-b96c-28d3db4de1bd,smoke]
tempest.api.identity.v3.test_api_discovery.TestApiDiscovery.test_identity_v3_existence[id-79aec9ae-710f-4c54-a4fc-3aa25b4feac3]
tempest.api.identity.v3.test_api_discovery.TestApiDiscovery.test_list_api_versions[id-721f480f-35b6-46c7-846e-047e6acea0dc,smoke]
tempest.api.identity.admin.v3.test_users_negative.UsersNegativeTest.test_create_user_for_non_existent_domain[id-e75f006c-89cc-477b-874d-588e4eab4b17,negative]
tempest.api.identity.admin.v3.test_trusts.TrustsV3TestJSON.test_trust_impersonate[id-5a0a91a4-baef-4a14-baba-59bf4d7fcace]
tempest.api.identity.v3.test_application_credentials.ApplicationCredentialsV3Test.test_create_application_credential[id-8080c75c-eddc-4786-941a-c2da7039ae61]
tempest.api.identity.v3.test_application_credentials.ApplicationCredentialsV3Test.test_create_application_credential_expires[id-852daf0c-42b5-4239-8466-d193d0543ed3]
tempest.api.identity.v3.test_application_credentials.ApplicationCredentialsV3Test.test_list_application_credentials[id-ff0cd457-6224-46e7-b79e-0ada4964a8a6]
tempest.api.identity.v3.test_application_credentials.ApplicationCredentialsV3Test.test_query_application_credentials[id-9bb5e5cc-5250-493a-8869-8b665f6aa5f6]
tempest.api.identity.v3.test_tokens.TokensV3Test.test_validate_token[id-a9512ac3-3909-48a4-b395-11f438e16260]
tempest.api.identity.admin.v3.test_trusts.TrustsV3TestJSON.test_trust_noimpersonate[id-ed2a8779-a7ac-49dc-afd7-30f32f936ed2]
tempest.api.identity.admin.v3.test_users.UsersV3TestJSON.test_list_user_projects[id-a831e70c-e35b-430b-92ed-81ebbc5437b8]
tempest.api.identity.v3.test_projects.IdentityV3ProjectsTest.test_list_projects_returns_only_authorized_projects[id-86128d46-e170-4644-866a-cc487f699e1d]
===== END FAILED TESTS (target=rust) =====

View full run

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants