settings: deployment behind a nginx, ldap login for the users.
rolling oc out was a nightmare. we tried several major releases, every time hoping things will be different.
both requirements caused a lot of trouble, we run into a lot of documented but unfixed bugs. they were often closed with the comment: ldap subsystem will be rewritten.
i thing we tested three times, each time a new major version. each time there was a new ldap system, but it was still broken.