Change the user synchronization schedule
Overview
CAST Imaging synchronizes users and groups from Keycloak automatically, so that the Users tab lists the accounts your authentication system currently provides - see Manage user permissions. This page explains how to change the schedule on which that synchronization runs.
Changing the schedule does not affect the Refresh button, which forces a synchronization at any time.
When does the synchronization run by default?
By default the synchronization runs every day at 0300, in the time zone of the server.
The interface converts that time to the time zone of the user viewing it, so the schedule displayed next to the Refresh button differs from one user to another. Where the server is in France, for example, the synchronization runs at 0300 French time: a user in France sees 3:00 AM and a user in India sees 6:30 AM. Both describe the same event.
Defining the schedule
The schedule is a cron expression of six fields, in this order:
| Field | Values |
|---|---|
| second | 0-59 |
| minute | 0-59 |
| hour | 0-23 |
| day-of-month | 1-31 |
| month | 1-12 or JAN-DEC |
| day-of-week | 0-7 (0 and 7 are Sunday) or MON-SUN |
The default schedule is therefore expressed as:
0 0 3 * * *
This is not the same cron format as the one used by the snapshot retention schedule, which takes a seventh field for the year.
How the schedule is displayed
The interface describes the schedule in words next to the Refresh button - runs every day at 3:00 AM, for example. Where an expression describes a schedule that cannot be phrased that way, the expression itself is displayed instead. This applies to a schedule that:
- fires more than once a day - any list, range or step in the second, minute or hour field, or
*in the hour field:0 0 */2 * * *,0 0 9,17 * * *,0 0 9-17 * * *,0 0/30 9 * * *,0 0 * * * * - pins both the day-of-month and the day-of-week:
0 0 9 15 * MON - pins the day-of-week together with a month:
0 0 9 * 6 MON - pins the day-of-week as something other than a plain list of days:
0 0 9 * * */2,0 0 9 * * 1/2 - pins the day-of-month as something other than one fixed day:
0 0 9 1,15 * *,0 0 9 1-5 * *,0 0 9 */2 * * - pins a month but leaves the day open:
0 0 3 * 2 * - pins more than one month:
0 0 9 15 1,6 *,0 0 9 15 1-6 *
Changing the schedule
Microsoft Windows
- Edit the following file - where it does not exist, create it manually:
%PROGRAMFILES%\CAST\Imaging\CAST-Imaging-Control-Panel\application-default.yml
- Add or set the following lines, replacing the expression with your own schedule:
auth-service:
keycloak:
users-sync:
cron: 0 0 3 * * *
- Restart the CAST Imaging Control Panel Microsoft Windows service to apply the new schedule.
The same setting can be made in application.yml in the same folder, but that file is overwritten when you update to a new release, so CAST recommends application-default.yml, which is preserved.
Linux via Docker/Podman
- Create or re-use an existing
docker-compose.override.ymlfile for theimaging-servicescomponent (see Managing docker-compose.yml files) and add the following entry within theservices:control-panel:environmentsection, replacing the expression with your own schedule:
services:
control-panel:
environment:
- AUTHSERVICE_KEYCLOAK_USERSSYNC_CRON=0 0 3 * * *
- Restart the imaging-services service to apply the new schedule:
cd /opt/cast/installation/imaging-services
sudo docker compose down
sudo docker compose up -d
Checking that the new schedule has been applied
Open the Users tab in User permissions. The schedule displayed next to the Refresh button reflects the expression you configured, converted to your own time zone, and the last successful synchronization is shown alongside it.