Keystone UUID token validation latency limits under concurrent load
0 reputation · 24 Nov 2025, 05:18 UTC
OpenStack Keystone utilizes UUID tokens that require a database lookup for each validation request. In high-concurrency environments, this architecture can lead to increased latency due to lock contention on the token table, particularly when backed by a Galera cluster.
While token caching via memcached or Redis is a documented mitigation in keystone.conf, there is a trade-off between reducing validation latency and the immediacy of token revocation. Alternatively, Fernet tokens eliminate the database lookup entirely by storing the token data within the token itself.
When designing for high-throughput authentication, it is unclear which approach provides the most stable latency profile without compromising security requirements.
- Does the latency overhead of UUID tokens scale linearly with concurrent requests, or is there a specific saturation point for the database backend?
- How does the latency profile of Fernet tokens compare to UUID tokens with an optimized caching layer under peak load?