Vasyl Saienko | eaf4fc4 | 2017-12-12 11:49:43 +0200 | [diff] [blame] | 1 | {%- from "keystone/map.jinja" import server with context %} |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 2 | {%- if server.enabled %} |
| 3 | |
| 4 | keystone_packages: |
| 5 | pkg.installed: |
| 6 | - names: {{ server.pkgs }} |
| 7 | |
Filip Pytloun | 54c4566 | 2017-09-07 16:43:54 +0200 | [diff] [blame] | 8 | {%- set ldap = {'enabled': False} %} |
| 9 | {%- if server.get('backend') == 'ldap' %} |
| 10 | {%- do ldap.update({'enabled': True}) %} |
| 11 | {%- else %} |
| 12 | {%- for domain in server.get('domain', {}).itervalues() %} |
| 13 | {%- if domain.get('ldap') %} |
| 14 | {%- do ldap.update({'enabled': True}) %} |
| 15 | {%- endif %} |
| 16 | {%- endfor %} |
| 17 | {%- endif %} |
| 18 | |
| 19 | {%- if ldap.enabled %} |
Ramon Melero | 96ff912 | 2017-08-15 11:02:50 -0500 | [diff] [blame] | 20 | keystone_ldap_packages: |
| 21 | pkg.installed: |
| 22 | - names: |
| 23 | - python-ldap |
| 24 | - python-ldappool |
| 25 | {% endif %} |
| 26 | |
Alexander Noskov | 78b81e0 | 2016-12-05 16:20:50 +0400 | [diff] [blame] | 27 | {%- if server.service_name in ['apache2', 'httpd'] %} |
Filip Pytloun | 2d5ff4a | 2017-05-19 12:00:59 +0200 | [diff] [blame] | 28 | {%- set keystone_service = 'apache_service' %} |
| 29 | |
Tatyana Leontovich | d06855c | 2017-04-24 21:03:22 +0300 | [diff] [blame] | 30 | purge_not_needed_configs: |
Marek Celoud | 073eb68 | 2017-04-11 10:48:48 +0200 | [diff] [blame] | 31 | file.absent: |
Tatyana Leontovich | d06855c | 2017-04-24 21:03:22 +0300 | [diff] [blame] | 32 | - names: ['/etc/apache2/sites-enabled/keystone.conf', '/etc/apache2/sites-enabled/wsgi-keystone.conf'] |
Marek Celoud | 073eb68 | 2017-04-11 10:48:48 +0200 | [diff] [blame] | 33 | - watch_in: |
Filip Pytloun | 2d5ff4a | 2017-05-19 12:00:59 +0200 | [diff] [blame] | 34 | - service: {{ keystone_service }} |
Marek Celoud | 073eb68 | 2017-04-11 10:48:48 +0200 | [diff] [blame] | 35 | |
Alexander Noskov | 78b81e0 | 2016-12-05 16:20:50 +0400 | [diff] [blame] | 36 | include: |
| 37 | - apache |
| 38 | |
| 39 | {%- if grains.os_family == "Debian" %} |
| 40 | keystone: |
| 41 | {%- endif %} |
| 42 | {%- if grains.os_family == "RedHat" %} |
| 43 | openstack-keystone: |
| 44 | {%- endif %} |
| 45 | service.dead: |
| 46 | - enable: False |
| 47 | - watch: |
| 48 | - pkg: keystone_packages |
| 49 | |
Filip Pytloun | 2d5ff4a | 2017-05-19 12:00:59 +0200 | [diff] [blame] | 50 | {%- else %} |
| 51 | |
| 52 | {%- set keystone_service = 'keystone_service' %} |
| 53 | |
Alexander Noskov | 78b81e0 | 2016-12-05 16:20:50 +0400 | [diff] [blame] | 54 | {%- endif %} |
| 55 | |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 56 | {%- if not salt['user.info']('keystone') %} |
| 57 | |
| 58 | keystone_user: |
| 59 | user.present: |
| 60 | - name: keystone |
| 61 | - home: /var/lib/keystone |
| 62 | - uid: 301 |
| 63 | - gid: 301 |
| 64 | - shell: /bin/false |
| 65 | - system: True |
| 66 | - require_in: |
| 67 | - pkg: keystone_packages |
| 68 | |
| 69 | keystone_group: |
| 70 | group.present: |
| 71 | - name: keystone |
| 72 | - gid: 301 |
| 73 | - system: True |
| 74 | - require_in: |
| 75 | - pkg: keystone_packages |
| 76 | - user: keystone_user |
| 77 | |
| 78 | {%- endif %} |
| 79 | |
| 80 | /etc/keystone/keystone.conf: |
| 81 | file.managed: |
| 82 | - source: salt://keystone/files/{{ server.version }}/keystone.conf.{{ grains.os_family }} |
| 83 | - template: jinja |
| 84 | - require: |
| 85 | - pkg: keystone_packages |
Alexander Noskov | 78b81e0 | 2016-12-05 16:20:50 +0400 | [diff] [blame] | 86 | - watch_in: |
Filip Pytloun | 2d5ff4a | 2017-05-19 12:00:59 +0200 | [diff] [blame] | 87 | - service: {{ keystone_service }} |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 88 | |
Oleksii Chupryn | ebe09a5 | 2017-04-21 11:08:14 +0300 | [diff] [blame] | 89 | {% if server.federation is defined %} |
Alexander Noskov | 78b81e0 | 2016-12-05 16:20:50 +0400 | [diff] [blame] | 90 | |
| 91 | /etc/keystone/sso_callback_template.html: |
| 92 | file.managed: |
| 93 | - source: salt://keystone/files/sso_callback_template.html |
| 94 | - require: |
| 95 | - pkg: keystone_packages |
| 96 | - watch_in: |
Filip Pytloun | 2d5ff4a | 2017-05-19 12:00:59 +0200 | [diff] [blame] | 97 | - service: {{ keystone_service }} |
Alexander Noskov | 78b81e0 | 2016-12-05 16:20:50 +0400 | [diff] [blame] | 98 | |
| 99 | {%- endif %} |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 100 | |
| 101 | /etc/keystone/keystone-paste.ini: |
| 102 | file.managed: |
| 103 | - source: salt://keystone/files/{{ server.version }}/keystone-paste.ini.{{ grains.os_family }} |
Jiri Broulik | bd21be6 | 2017-08-14 15:31:29 +0200 | [diff] [blame] | 104 | - user: keystone |
| 105 | - group: keystone |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 106 | - template: jinja |
| 107 | - require: |
| 108 | - pkg: keystone_packages |
| 109 | - watch_in: |
Filip Pytloun | 2d5ff4a | 2017-05-19 12:00:59 +0200 | [diff] [blame] | 110 | - service: {{ keystone_service }} |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 111 | |
Dmitry Kalashnik | 494a17d | 2017-12-06 16:55:55 +0400 | [diff] [blame] | 112 | {%- if server.logging.log_appender %} |
| 113 | |
| 114 | {%- if server.logging.log_handlers.get('fluentd', {}).get('enabled', False) %} |
| 115 | keystone_fluentd_logger_package: |
| 116 | pkg.installed: |
| 117 | - name: python-fluent-logger |
| 118 | {%- endif %} |
Jiri Broulik | bd21be6 | 2017-08-14 15:31:29 +0200 | [diff] [blame] | 119 | |
| 120 | /etc/keystone/logging.conf: |
| 121 | file.managed: |
Dmitry Kalashnik | 494a17d | 2017-12-06 16:55:55 +0400 | [diff] [blame] | 122 | - user: keystone |
| 123 | - group: keystone |
| 124 | - source: salt://keystone/files/logging.conf |
| 125 | - template: jinja |
| 126 | - defaults: |
| 127 | values: {{ server }} |
| 128 | - require: |
| 129 | - pkg: keystone_packages |
| 130 | {%- if server.logging.log_handlers.get('fluentd', {}).get('enabled', False) %} |
| 131 | - pkg: keystone_fluentd_logger_package |
| 132 | {%- endif %} |
| 133 | - watch_in: |
| 134 | - service: {{ keystone_service }} |
| 135 | |
| 136 | /var/log/keystone/keystone.log: |
| 137 | file.managed: |
| 138 | - user: keystone |
| 139 | - group: keystone |
| 140 | - watch_in: |
| 141 | - service: {{ keystone_service }} |
| 142 | |
| 143 | {%- endif %} |
| 144 | |
| 145 | /etc/keystone/policy.json: |
| 146 | file.managed: |
Jiri Broulik | bd21be6 | 2017-08-14 15:31:29 +0200 | [diff] [blame] | 147 | - user: keystone |
| 148 | - group: keystone |
| 149 | - require: |
| 150 | - pkg: keystone_packages |
| 151 | - watch_in: |
| 152 | - service: {{ keystone_service }} |
| 153 | |
Benjamin Drung | 5fe8041 | 2018-02-14 23:55:54 +0100 | [diff] [blame] | 154 | {%- for name, rule in server.get('policy', {}).items() %} |
Adam Tengler | b1ebaca | 2017-05-04 21:06:08 +0000 | [diff] [blame] | 155 | |
| 156 | {%- if rule != None %} |
| 157 | |
| 158 | rule_{{ name }}_present: |
| 159 | keystone_policy.rule_present: |
| 160 | - path: /etc/keystone/policy.json |
| 161 | - name: {{ name }} |
| 162 | - rule: {{ rule }} |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 163 | - require: |
| 164 | - pkg: keystone_packages |
| 165 | - watch_in: |
Filip Pytloun | 2d5ff4a | 2017-05-19 12:00:59 +0200 | [diff] [blame] | 166 | - service: {{ keystone_service }} |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 167 | |
Adam Tengler | b1ebaca | 2017-05-04 21:06:08 +0000 | [diff] [blame] | 168 | {%- else %} |
| 169 | |
| 170 | rule_{{ name }}_absent: |
| 171 | keystone_policy.rule_absent: |
| 172 | - path: /etc/keystone/policy.json |
| 173 | - name: {{ name }} |
| 174 | - require: |
| 175 | - pkg: keystone_packages |
Adam Tengler | b1ebaca | 2017-05-04 21:06:08 +0000 | [diff] [blame] | 176 | - watch_in: |
Filip Pytloun | 2d5ff4a | 2017-05-19 12:00:59 +0200 | [diff] [blame] | 177 | - service: {{ keystone_service }} |
Adam Tengler | b1ebaca | 2017-05-04 21:06:08 +0000 | [diff] [blame] | 178 | |
| 179 | {%- endif %} |
| 180 | |
| 181 | {%- endfor %} |
| 182 | |
Filip Pytloun | 6b9ec2b | 2016-01-12 13:52:01 +0100 | [diff] [blame] | 183 | {%- if server.get("domain", {}) %} |
| 184 | |
| 185 | /etc/keystone/domains: |
| 186 | file.directory: |
| 187 | - mode: 0755 |
| 188 | - require: |
| 189 | - pkg: keystone_packages |
| 190 | |
Benjamin Drung | 5fe8041 | 2018-02-14 23:55:54 +0100 | [diff] [blame] | 191 | {%- for domain_name, domain in server.domain.items() %} |
Ales Komarek | aabbda6 | 2016-03-15 08:38:35 +0100 | [diff] [blame] | 192 | |
Filip Pytloun | 6b9ec2b | 2016-01-12 13:52:01 +0100 | [diff] [blame] | 193 | /etc/keystone/domains/keystone.{{ domain_name }}.conf: |
| 194 | file.managed: |
| 195 | - source: salt://keystone/files/keystone.domain.conf |
Filip Pytloun | af25d8d | 2016-01-12 14:21:39 +0100 | [diff] [blame] | 196 | - template: jinja |
Filip Pytloun | 6b9ec2b | 2016-01-12 13:52:01 +0100 | [diff] [blame] | 197 | - require: |
| 198 | - file: /etc/keystone/domains |
| 199 | - watch_in: |
Filip Pytloun | 2d5ff4a | 2017-05-19 12:00:59 +0200 | [diff] [blame] | 200 | - service: {{ keystone_service }} |
Filip Pytloun | 5b50385 | 2016-01-12 14:02:07 +0100 | [diff] [blame] | 201 | - defaults: |
Filip Pytloun | af25d8d | 2016-01-12 14:21:39 +0100 | [diff] [blame] | 202 | domain_name: {{ domain_name }} |
Filip Pytloun | 5b50385 | 2016-01-12 14:02:07 +0100 | [diff] [blame] | 203 | |
Filip Pytloun | 19620f7 | 2016-01-19 16:27:00 +0100 | [diff] [blame] | 204 | {%- if domain.get('ldap', {}).get('tls', {}).get('cacert', False) %} |
Ales Komarek | aabbda6 | 2016-03-15 08:38:35 +0100 | [diff] [blame] | 205 | |
Filip Pytloun | 3e2555e | 2016-01-12 20:23:34 +0100 | [diff] [blame] | 206 | keystone_domain_{{ domain_name }}_cacert: |
| 207 | file.managed: |
| 208 | - name: /etc/keystone/domains/{{ domain_name }}.pem |
Filip Pytloun | c7e3b81 | 2016-01-12 20:52:10 +0100 | [diff] [blame] | 209 | - contents_pillar: keystone:server:domain:{{ domain_name }}:ldap:tls:cacert |
Filip Pytloun | 3e2555e | 2016-01-12 20:23:34 +0100 | [diff] [blame] | 210 | - require: |
| 211 | - file: /etc/keystone/domains |
Filip Pytloun | b96a0a4 | 2016-05-25 11:36:44 +0200 | [diff] [blame] | 212 | {%- if not grains.get('noservices', False) %} |
Filip Pytloun | 3e2555e | 2016-01-12 20:23:34 +0100 | [diff] [blame] | 213 | - watch_in: |
Filip Pytloun | 2d5ff4a | 2017-05-19 12:00:59 +0200 | [diff] [blame] | 214 | - service: {{ keystone_service }} |
Filip Pytloun | b96a0a4 | 2016-05-25 11:36:44 +0200 | [diff] [blame] | 215 | {%- endif %} |
Ales Komarek | aabbda6 | 2016-03-15 08:38:35 +0100 | [diff] [blame] | 216 | |
Filip Pytloun | 3e2555e | 2016-01-12 20:23:34 +0100 | [diff] [blame] | 217 | {%- endif %} |
| 218 | |
Vasyl Saienko | 75826ac | 2018-04-23 11:15:50 +0300 | [diff] [blame^] | 219 | {#- can't use RC file here as identity endpoint may not be present in keystone #} |
| 220 | {#- as we will add it later in keystone.client state. Use endpoint override here. #} |
| 221 | {#- will be fixed when switched to keystone bootstrap. #} |
| 222 | {#- TODO: move domain creation to keystone.client state. #} |
Filip Pytloun | 5b50385 | 2016-01-12 14:02:07 +0100 | [diff] [blame] | 223 | keystone_domain_{{ domain_name }}: |
| 224 | cmd.run: |
Vasyl Saienko | 75826ac | 2018-04-23 11:15:50 +0300 | [diff] [blame^] | 225 | - name: openstack --os-identity-api-version 3 |
| 226 | --os-endpoint {{ server.bind.get('private_protocol', 'http') }}://{{ server.bind.private_address }}:{{ server.bind.private_port }}/v3 |
| 227 | --os-token {{ server.service_token }} |
| 228 | --os-auth-type admin_token |
| 229 | domain create --description "{{ domain.description }}" {{ domain_name }} |
| 230 | - unless: {% if grains.get('noservices') %}/bin/true{% else %} |
| 231 | openstack --os-identity-api-version 3 |
| 232 | --os-endpoint {{ server.bind.get('private_protocol', 'http') }}://{{ server.bind.private_address }}:{{ server.bind.private_port }}/v3 |
| 233 | --os-token {{ server.service_token }} |
| 234 | --os-auth-type admin_token |
| 235 | domain list | grep " {{ domain_name }}"{% endif %} |
Dmitry Stremkovskiy | 0ad884b | 2017-07-27 14:51:11 +0300 | [diff] [blame] | 236 | - shell: /bin/bash |
Filip Pytloun | 5b50385 | 2016-01-12 14:02:07 +0100 | [diff] [blame] | 237 | - require: |
| 238 | - file: /root/keystonercv3 |
Filip Pytloun | 2d5ff4a | 2017-05-19 12:00:59 +0200 | [diff] [blame] | 239 | - service: {{ keystone_service }} |
Ales Komarek | aabbda6 | 2016-03-15 08:38:35 +0100 | [diff] [blame] | 240 | |
Filip Pytloun | 6b9ec2b | 2016-01-12 13:52:01 +0100 | [diff] [blame] | 241 | {%- endfor %} |
| 242 | |
| 243 | {%- endif %} |
| 244 | |
Filip Pytloun | 19620f7 | 2016-01-19 16:27:00 +0100 | [diff] [blame] | 245 | {%- if server.get('ldap', {}).get('tls', {}).get('cacert', False) %} |
Ales Komarek | aabbda6 | 2016-03-15 08:38:35 +0100 | [diff] [blame] | 246 | |
Filip Pytloun | 19620f7 | 2016-01-19 16:27:00 +0100 | [diff] [blame] | 247 | keystone_ldap_default_cacert: |
| 248 | file.managed: |
| 249 | - name: {{ server.ldap.tls.cacertfile }} |
| 250 | - contents_pillar: keystone:server:ldap:tls:cacert |
| 251 | - require: |
| 252 | - pkg: keystone_packages |
| 253 | - watch_in: |
Filip Pytloun | 2d5ff4a | 2017-05-19 12:00:59 +0200 | [diff] [blame] | 254 | - service: {{ keystone_service }} |
Ales Komarek | aabbda6 | 2016-03-15 08:38:35 +0100 | [diff] [blame] | 255 | |
Filip Pytloun | 19620f7 | 2016-01-19 16:27:00 +0100 | [diff] [blame] | 256 | {%- endif %} |
| 257 | |
Martin Polreich | abe6a6b | 2017-06-02 16:56:56 +0200 | [diff] [blame] | 258 | {%- if server.service_name not in ['apache2', 'httpd'] %} |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 259 | keystone_service: |
| 260 | service.running: |
| 261 | - name: {{ server.service_name }} |
| 262 | - enable: True |
Martin Polreich | 962dfdd | 2017-06-08 14:04:14 +0200 | [diff] [blame] | 263 | {%- if grains.get('noservices') %} |
| 264 | - onlyif: /bin/false |
| 265 | {%- endif %} |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 266 | - watch: |
Kirill Bespalov | 0098445 | 2017-08-01 17:44:11 +0300 | [diff] [blame] | 267 | {%- if server.notification and server.message_queue.get('ssl',{}).get('enabled', False) %} |
Kirill Bespalov | 33272a8 | 2017-11-15 13:40:26 +0300 | [diff] [blame] | 268 | - file: rabbitmq_ca_keystone_server |
Kirill Bespalov | 0098445 | 2017-08-01 17:44:11 +0300 | [diff] [blame] | 269 | {%- endif %} |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 270 | - file: /etc/keystone/keystone.conf |
Filip Pytloun | b96a0a4 | 2016-05-25 11:36:44 +0200 | [diff] [blame] | 271 | {%- endif %} |
| 272 | |
| 273 | {%- if grains.get('virtual_subtype', None) == "Docker" %} |
| 274 | keystone_entrypoint: |
| 275 | file.managed: |
| 276 | - name: /entrypoint.sh |
| 277 | - template: jinja |
| 278 | - source: salt://keystone/files/entrypoint.sh |
| 279 | - mode: 755 |
| 280 | {%- endif %} |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 281 | |
| 282 | /root/keystonerc: |
| 283 | file.managed: |
| 284 | - source: salt://keystone/files/keystonerc |
| 285 | - template: jinja |
| 286 | - require: |
| 287 | - pkg: keystone_packages |
| 288 | |
| 289 | /root/keystonercv3: |
| 290 | file.managed: |
| 291 | - source: salt://keystone/files/keystonercv3 |
| 292 | - template: jinja |
| 293 | - require: |
| 294 | - pkg: keystone_packages |
| 295 | |
Filip Pytloun | b96a0a4 | 2016-05-25 11:36:44 +0200 | [diff] [blame] | 296 | {%- if not grains.get('noservices', False) %} |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 297 | keystone_syncdb: |
| 298 | cmd.run: |
Igor Pukha | 3aa8e20 | 2017-05-03 15:42:50 +0300 | [diff] [blame] | 299 | - name: keystone-manage db_sync && sleep 1 |
Ruslan Usichenko | 64cd354 | 2017-01-30 15:59:44 +0200 | [diff] [blame] | 300 | - timeout: 120 |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 301 | - require: |
Filip Pytloun | 2d5ff4a | 2017-05-19 12:00:59 +0200 | [diff] [blame] | 302 | - service: {{ keystone_service }} |
Filip Pytloun | b96a0a4 | 2016-05-25 11:36:44 +0200 | [diff] [blame] | 303 | {%- endif %} |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 304 | |
| 305 | {% if server.tokens.engine == 'fernet' %} |
| 306 | |
Jakub Pavlik | 143338c | 2016-02-16 18:57:54 +0100 | [diff] [blame] | 307 | keystone_fernet_keys: |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 308 | file.directory: |
Jakub Pavlik | 143338c | 2016-02-16 18:57:54 +0100 | [diff] [blame] | 309 | - name: {{ server.tokens.location }} |
| 310 | - mode: 750 |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 311 | - user: keystone |
| 312 | - group: keystone |
| 313 | - require: |
| 314 | - pkg: keystone_packages |
| 315 | - require_in: |
| 316 | - service: keystone_fernet_setup |
| 317 | |
Filip Pytloun | b96a0a4 | 2016-05-25 11:36:44 +0200 | [diff] [blame] | 318 | {%- if not grains.get('noservices', False) %} |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 319 | keystone_fernet_setup: |
| 320 | cmd.run: |
| 321 | - name: keystone-manage fernet_setup --keystone-user keystone --keystone-group keystone |
| 322 | - require: |
Filip Pytloun | 2d5ff4a | 2017-05-19 12:00:59 +0200 | [diff] [blame] | 323 | - service: {{ keystone_service }} |
Jakub Pavlik | 143338c | 2016-02-16 18:57:54 +0100 | [diff] [blame] | 324 | - file: keystone_fernet_keys |
Andrey Shestakov | d256344 | 2017-06-15 17:08:46 +0300 | [diff] [blame] | 325 | {%- endif %} |
Jakub Pavlik | f61df54 | 2017-04-03 18:01:23 +0200 | [diff] [blame] | 326 | |
Andrey Shestakov | d256344 | 2017-06-15 17:08:46 +0300 | [diff] [blame] | 327 | {% endif %} |
| 328 | |
Oleh Hryhorov | 284f282 | 2017-10-26 10:58:10 +0300 | [diff] [blame] | 329 | {%- if server.version in ['newton', 'ocata', 'pike'] %} |
Andrey Shestakov | d256344 | 2017-06-15 17:08:46 +0300 | [diff] [blame] | 330 | keystone_credential_keys: |
| 331 | file.directory: |
| 332 | - name: {{ server.credential.location }} |
| 333 | - mode: 750 |
| 334 | - user: keystone |
| 335 | - group: keystone |
| 336 | - require: |
| 337 | - pkg: keystone_packages |
| 338 | |
| 339 | {%- if not grains.get('noservices', False) %} |
| 340 | keystone_credential_setup: |
Jakub Pavlik | f61df54 | 2017-04-03 18:01:23 +0200 | [diff] [blame] | 341 | cmd.run: |
| 342 | - name: keystone-manage credential_setup --keystone-user keystone --keystone-group keystone |
| 343 | - require: |
Filip Pytloun | 2d5ff4a | 2017-05-19 12:00:59 +0200 | [diff] [blame] | 344 | - service: {{ keystone_service }} |
Andrey Shestakov | d256344 | 2017-06-15 17:08:46 +0300 | [diff] [blame] | 345 | - file: keystone_credential_keys |
Jakub Pavlik | f61df54 | 2017-04-03 18:01:23 +0200 | [diff] [blame] | 346 | {%- endif %} |
Filip Pytloun | b96a0a4 | 2016-05-25 11:36:44 +0200 | [diff] [blame] | 347 | {%- endif %} |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 348 | |
Filip Pytloun | b96a0a4 | 2016-05-25 11:36:44 +0200 | [diff] [blame] | 349 | {%- if not grains.get('noservices', False) %} |
Ales Komarek | 95ceb4b | 2016-10-20 17:28:21 +0200 | [diff] [blame] | 350 | |
| 351 | {%- if not salt['pillar.get']('linux:system:repo:mirantis_openstack', False) %} |
| 352 | |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 353 | keystone_service_tenant: |
Oleg Iurchenko | 5b1e532 | 2017-10-20 00:29:20 +0300 | [diff] [blame] | 354 | keystoneng.tenant_present: |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 355 | - name: {{ server.service_tenant }} |
Andres Montalban | 06c3589 | 2016-09-23 12:24:38 -0300 | [diff] [blame] | 356 | - connection_token: {{ server.service_token }} |
| 357 | - connection_endpoint: 'http://{{ server.bind.address }}:{{ server.bind.private_port }}/v2.0' |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 358 | - require: |
| 359 | - cmd: keystone_syncdb |
| 360 | |
| 361 | keystone_admin_tenant: |
Oleg Iurchenko | 5b1e532 | 2017-10-20 00:29:20 +0300 | [diff] [blame] | 362 | keystoneng.tenant_present: |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 363 | - name: {{ server.admin_tenant }} |
Andres Montalban | 06c3589 | 2016-09-23 12:24:38 -0300 | [diff] [blame] | 364 | - connection_token: {{ server.service_token }} |
| 365 | - connection_endpoint: 'http://{{ server.bind.address }}:{{ server.bind.private_port }}/v2.0' |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 366 | - require: |
Oleg Iurchenko | 5b1e532 | 2017-10-20 00:29:20 +0300 | [diff] [blame] | 367 | - keystoneng: keystone_service_tenant |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 368 | |
| 369 | keystone_roles: |
Oleg Iurchenko | 5b1e532 | 2017-10-20 00:29:20 +0300 | [diff] [blame] | 370 | keystoneng.role_present: |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 371 | - names: {{ server.roles }} |
Andres Montalban | 06c3589 | 2016-09-23 12:24:38 -0300 | [diff] [blame] | 372 | - connection_token: {{ server.service_token }} |
| 373 | - connection_endpoint: 'http://{{ server.bind.address }}:{{ server.bind.private_port }}/v2.0' |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 374 | - require: |
Oleg Iurchenko | 5b1e532 | 2017-10-20 00:29:20 +0300 | [diff] [blame] | 375 | - keystoneng: keystone_service_tenant |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 376 | |
Adam Tengler | 43c8a18 | 2017-09-08 09:54:31 +0000 | [diff] [blame] | 377 | {%- if not server.get('ldap', {}).get('read_only', False) %} |
| 378 | |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 379 | keystone_admin_user: |
Oleg Iurchenko | 5b1e532 | 2017-10-20 00:29:20 +0300 | [diff] [blame] | 380 | keystoneng.user_present: |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 381 | - name: {{ server.admin_name }} |
| 382 | - password: {{ server.admin_password }} |
| 383 | - email: {{ server.admin_email }} |
| 384 | - tenant: {{ server.admin_tenant }} |
| 385 | - roles: |
| 386 | {{ server.admin_tenant }}: |
| 387 | - admin |
Andres Montalban | 06c3589 | 2016-09-23 12:24:38 -0300 | [diff] [blame] | 388 | - connection_token: {{ server.service_token }} |
| 389 | - connection_endpoint: 'http://{{ server.bind.address }}:{{ server.bind.private_port }}/v2.0' |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 390 | - require: |
Oleg Iurchenko | 5b1e532 | 2017-10-20 00:29:20 +0300 | [diff] [blame] | 391 | - keystoneng: keystone_admin_tenant |
| 392 | - keystoneng: keystone_roles |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 393 | |
Ales Komarek | 95ceb4b | 2016-10-20 17:28:21 +0200 | [diff] [blame] | 394 | {%- endif %} |
| 395 | |
Adam Tengler | 43c8a18 | 2017-09-08 09:54:31 +0000 | [diff] [blame] | 396 | {%- endif %} |
| 397 | |
Benjamin Drung | 5fe8041 | 2018-02-14 23:55:54 +0100 | [diff] [blame] | 398 | {%- for service_name, service in server.get('service', {}).items() %} |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 399 | |
| 400 | keystone_{{ service_name }}_service: |
Oleg Iurchenko | 5b1e532 | 2017-10-20 00:29:20 +0300 | [diff] [blame] | 401 | keystoneng.service_present: |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 402 | - name: {{ service_name }} |
| 403 | - service_type: {{ service.type }} |
| 404 | - description: {{ service.description }} |
Andres Montalban | 06c3589 | 2016-09-23 12:24:38 -0300 | [diff] [blame] | 405 | - connection_token: {{ server.service_token }} |
| 406 | - connection_endpoint: 'http://{{ server.bind.address }}:{{ server.bind.private_port }}/v2.0' |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 407 | - require: |
Oleg Iurchenko | 5b1e532 | 2017-10-20 00:29:20 +0300 | [diff] [blame] | 408 | - keystoneng: keystone_roles |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 409 | |
Petr Michalec | 685a219 | 2017-03-06 14:58:01 +0100 | [diff] [blame] | 410 | keystone_{{ service_name }}_{{ service.get('region', 'RegionOne') }}_endpoint: |
Oleg Iurchenko | 5b1e532 | 2017-10-20 00:29:20 +0300 | [diff] [blame] | 411 | keystoneng.endpoint_present: |
Ales Komarek | aabbda6 | 2016-03-15 08:38:35 +0100 | [diff] [blame] | 412 | - name: {{ service.get('service', service_name) }} |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 413 | - publicurl: '{{ service.bind.get('public_protocol', 'http') }}://{{ service.bind.public_address }}:{{ service.bind.public_port }}{{ service.bind.public_path }}' |
| 414 | - internalurl: '{{ service.bind.get('internal_protocol', 'http') }}://{{ service.bind.internal_address }}:{{ service.bind.internal_port }}{{ service.bind.internal_path }}' |
| 415 | - adminurl: '{{ service.bind.get('admin_protocol', 'http') }}://{{ service.bind.admin_address }}:{{ service.bind.admin_port }}{{ service.bind.admin_path }}' |
| 416 | - region: {{ service.get('region', 'RegionOne') }} |
Andres Montalban | 06c3589 | 2016-09-23 12:24:38 -0300 | [diff] [blame] | 417 | - connection_token: {{ server.service_token }} |
| 418 | - connection_endpoint: 'http://{{ server.bind.address }}:{{ server.bind.private_port }}/v2.0' |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 419 | - require: |
Oleg Iurchenko | 5b1e532 | 2017-10-20 00:29:20 +0300 | [diff] [blame] | 420 | - keystoneng: keystone_{{ service_name }}_service |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 421 | |
| 422 | {% if service.user is defined %} |
| 423 | |
| 424 | keystone_user_{{ service.user.name }}: |
Oleg Iurchenko | 5b1e532 | 2017-10-20 00:29:20 +0300 | [diff] [blame] | 425 | keystoneng.user_present: |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 426 | - name: {{ service.user.name }} |
| 427 | - password: {{ service.user.password }} |
| 428 | - email: {{ server.admin_email }} |
| 429 | - tenant: {{ server.service_tenant }} |
| 430 | - roles: |
| 431 | {{ server.service_tenant }}: |
| 432 | - admin |
Andres Montalban | 06c3589 | 2016-09-23 12:24:38 -0300 | [diff] [blame] | 433 | - connection_token: {{ server.service_token }} |
| 434 | - connection_endpoint: 'http://{{ server.bind.address }}:{{ server.bind.private_port }}/v2.0' |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 435 | - require: |
Oleg Iurchenko | 5b1e532 | 2017-10-20 00:29:20 +0300 | [diff] [blame] | 436 | - keystoneng: keystone_roles |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 437 | |
| 438 | {% endif %} |
| 439 | |
Ales Komarek | 95ceb4b | 2016-10-20 17:28:21 +0200 | [diff] [blame] | 440 | {%- endfor %} |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 441 | |
Benjamin Drung | 5fe8041 | 2018-02-14 23:55:54 +0100 | [diff] [blame] | 442 | {%- for tenant_name, tenant in server.get('tenant', {}).items() %} |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 443 | |
| 444 | keystone_tenant_{{ tenant_name }}: |
Oleg Iurchenko | 5b1e532 | 2017-10-20 00:29:20 +0300 | [diff] [blame] | 445 | keystoneng.tenant_present: |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 446 | - name: {{ tenant_name }} |
Andres Montalban | 06c3589 | 2016-09-23 12:24:38 -0300 | [diff] [blame] | 447 | - connection_token: {{ server.service_token }} |
| 448 | - connection_endpoint: 'http://{{ server.bind.address }}:{{ server.bind.private_port }}/v2.0' |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 449 | - require: |
Oleg Iurchenko | 5b1e532 | 2017-10-20 00:29:20 +0300 | [diff] [blame] | 450 | - keystoneng: keystone_roles |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 451 | |
Benjamin Drung | 5fe8041 | 2018-02-14 23:55:54 +0100 | [diff] [blame] | 452 | {%- for user_name, user in tenant.get('user', {}).items() %} |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 453 | |
| 454 | keystone_user_{{ user_name }}: |
Oleg Iurchenko | 5b1e532 | 2017-10-20 00:29:20 +0300 | [diff] [blame] | 455 | keystoneng.user_present: |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 456 | - name: {{ user_name }} |
| 457 | - password: {{ user.password }} |
| 458 | - email: {{ user.get('email', 'root@localhost') }} |
| 459 | - tenant: {{ tenant_name }} |
| 460 | - roles: |
| 461 | {{ tenant_name }}: |
| 462 | {%- if user.get('roles', False) %} |
| 463 | {{ user.roles }} |
| 464 | {%- else %} |
| 465 | - Member |
| 466 | {%- endif %} |
Andres Montalban | 06c3589 | 2016-09-23 12:24:38 -0300 | [diff] [blame] | 467 | - connection_token: {{ server.service_token }} |
| 468 | - connection_endpoint: 'http://{{ server.bind.address }}:{{ server.bind.private_port }}/v2.0' |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 469 | - require: |
Oleg Iurchenko | 5b1e532 | 2017-10-20 00:29:20 +0300 | [diff] [blame] | 470 | - keystoneng: keystone_tenant_{{ tenant_name }} |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 471 | |
| 472 | {%- endfor %} |
| 473 | |
| 474 | {%- endfor %} |
Filip Pytloun | b96a0a4 | 2016-05-25 11:36:44 +0200 | [diff] [blame] | 475 | {%- endif %} {# end noservices #} |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 476 | |
Kirill Bespalov | 357fc3c | 2017-08-30 14:18:19 +0300 | [diff] [blame] | 477 | {%- if server.database.get('ssl',{}).get('enabled',False) %} |
Kirill Bespalov | 33272a8 | 2017-11-15 13:40:26 +0300 | [diff] [blame] | 478 | mysql_ca_keystone_server: |
Kirill Bespalov | 357fc3c | 2017-08-30 14:18:19 +0300 | [diff] [blame] | 479 | {%- if server.database.ssl.cacert is defined %} |
| 480 | file.managed: |
| 481 | - name: {{ server.database.ssl.cacert_file }} |
| 482 | - contents_pillar: keystone:server:database:ssl:cacert |
| 483 | - mode: 0444 |
| 484 | - makedirs: true |
| 485 | - require_in: |
| 486 | - file: /etc/keystone/keystone.conf |
| 487 | {%- else %} |
| 488 | file.exists: |
Vasyl Saienko | eaf4fc4 | 2017-12-12 11:49:43 +0200 | [diff] [blame] | 489 | - name: {{ server.database.ssl.get('cacert_file', server.cacert_file) }} |
Kirill Bespalov | 357fc3c | 2017-08-30 14:18:19 +0300 | [diff] [blame] | 490 | - require_in: |
| 491 | - file: /etc/keystone/keystone.conf |
Kirill Bespalov | 0098445 | 2017-08-01 17:44:11 +0300 | [diff] [blame] | 492 | {% endif %} |
| 493 | {% endif %} |
| 494 | |
| 495 | |
| 496 | {%- if server.notification and server.message_queue.get('ssl',{}).get('enabled', False) %} |
Kirill Bespalov | 33272a8 | 2017-11-15 13:40:26 +0300 | [diff] [blame] | 497 | rabbitmq_ca_keystone_server: |
Kirill Bespalov | 0098445 | 2017-08-01 17:44:11 +0300 | [diff] [blame] | 498 | {%- if server.message_queue.ssl.cacert is defined %} |
| 499 | file.managed: |
| 500 | - name: {{ server.message_queue.ssl.cacert_file }} |
| 501 | - contents_pillar: keystone:server:message_queue:ssl:cacert |
| 502 | - mode: 0444 |
| 503 | - makedirs: true |
| 504 | {%- else %} |
| 505 | file.exists: |
Vasyl Saienko | eaf4fc4 | 2017-12-12 11:49:43 +0200 | [diff] [blame] | 506 | - name: {{ server.message_queue.ssl.get('cacert_file', server.cacert_file) }} |
Kirill Bespalov | 357fc3c | 2017-08-30 14:18:19 +0300 | [diff] [blame] | 507 | {%- endif %} |
| 508 | {%- endif %} |
| 509 | |
Filip Pytloun | 943d688 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 510 | {%- endif %} |