blob: 54e34804b3d2ecde0f253ac1c6969531822a8465 [file] [log] [blame]
Filip Pytloun943d6882015-10-06 16:28:32 +02001==================
2OpenStack Keystone
3==================
4
Jakub Pavlikffc280d2016-05-20 11:19:14 +02005Keystone provides authentication, authorization and service discovery
6mechanisms via HTTP primarily for use by projects in the OpenStack family. It
7is most commonly deployed as an HTTP interface to existing identity systems,
8such as LDAP.
Filip Pytloun943d6882015-10-06 16:28:32 +02009
10From Kilo release Keystone v3 endpoint has definition without version in url
11
12.. code-block:: bash
13
14 +----------------------------------+-----------+--------------------------+--------------------------+---------------------------+----------------------------------+
15 | id | region | publicurl | internalurl | adminurl | service_id |
16 +----------------------------------+-----------+--------------------------+--------------------------+---------------------------+----------------------------------+
17 | 91663a8db11c487c9253c8c456863494 | RegionOne | http://10.0.150.37:5000/ | http://10.0.150.37:5000/ | http://10.0.150.37:35357/ | 0fd2dba3153d45a1ba7f709cfc2d69c9 |
18 +----------------------------------+-----------+--------------------------+--------------------------+---------------------------+----------------------------------+
19
20
21Sample pillars
22==============
23
Adam Tengler7c66c882016-03-14 19:35:49 +010024.. caution::
25
Jakub Pavlikffc280d2016-05-20 11:19:14 +020026 When you use localhost as your database host (keystone:server:
27 atabase:host), sqlalchemy will try to connect to /var/run/mysql/
28 mysqld.sock, may cause issues if you located your mysql socket elsewhere
Adam Tengler7c66c882016-03-14 19:35:49 +010029
Filip Pytloun943d6882015-10-06 16:28:32 +020030Full stacked keystone
31
32.. code-block:: yaml
33
34 keystone:
35 server:
36 enabled: true
37 version: juno
38 service_token: 'service_tokeen'
39 service_tenant: service
40 service_password: 'servicepwd'
41 admin_tenant: admin
42 admin_name: admin
43 admin_password: 'adminpwd'
44 admin_email: stackmaster@domain.com
45 roles:
46 - admin
47 - Member
48 - image_manager
49 bind:
50 address: 0.0.0.0
51 private_address: 127.0.0.1
52 private_port: 35357
53 public_address: 127.0.0.1
54 public_port: 5000
55 api_version: 2.0
56 region: RegionOne
57 database:
58 engine: mysql
59 host: '127.0.0.1'
60 name: 'keystone'
61 password: 'LfTno5mYdZmRfoPV'
62 user: 'keystone'
63
64Keystone public HTTPS API
65
66.. code-block:: yaml
67
68 keystone:
69 server:
70 enabled: true
71 version: juno
72 ...
73 services:
74 - name: nova
75 type: compute
76 description: OpenStack Compute Service
77 user:
78 name: nova
79 password: password
80 bind:
81 public_address: cloud.domain.com
82 public_protocol: https
83 public_port: 8774
84 internal_address: 10.0.0.20
85 internal_port: 8774
86 admin_address: 10.0.0.20
87 admin_port: 8774
88
89Keystone memcached storage for tokens
90
91.. code-block:: yaml
92
93 keystone:
94 server:
95 enabled: true
96 version: juno
97 ...
98 token_store: cache
99 cache:
100 engine: memcached
101 host: 127.0.0.1
102 port: 11211
103 services:
104 ...
105
106Keystone clustered memcached storage for tokens
107
108.. code-block:: yaml
109
110 keystone:
111 server:
112 enabled: true
113 version: juno
114 ...
115 token_store: cache
116 cache:
117 engine: memcached
118 members:
119 - host: 192.160.0.1
120 port: 11211
121 - host: 192.160.0.2
122 port: 11211
123 services:
124 ...
125
126Keystone client
127
128.. code-block:: yaml
129
130 keystone:
131 client:
132 enabled: true
133 server:
134 host: 10.0.0.2
135 public_port: 5000
136 private_port: 35357
137 service_token: 'token'
138 admin_tenant: admin
139 admin_name: admin
140 admin_password: 'passwd'
141
142Keystone cluster
143
144.. code-block:: yaml
145
146 keystone:
147 control:
148 enabled: true
149 provider:
150 os15_token:
151 host: 10.0.0.2
152 port: 35357
153 token: token
154 os15_tcp_core_stg:
155 host: 10.0.0.5
156 port: 5000
157 tenant: admin
158 name: admin
159 password: password
160
161Keystone fernet tokens for OpenStack Kilo release
162
163.. code-block:: yaml
164
165 keystone:
166 server:
167 ...
168 tokens:
169 engine: fernet
Jakub Pavlik6b0b74a2016-09-01 10:49:14 +0200170 max_active_keys: 3
Filip Pytloun943d6882015-10-06 16:28:32 +0200171 ...
172
Filip Pytloun6b9ec2b2016-01-12 13:52:01 +0100173Keystone domain with LDAP backend, using SQL for role/project assignment
174
175.. code-block:: yaml
176
177 keystone:
178 server:
179 domain:
Filip Pytlounaf25d8d2016-01-12 14:21:39 +0100180 description: "Testing domain"
Filip Pytloun6b9ec2b2016-01-12 13:52:01 +0100181 backend: ldap
182 assignment:
183 backend: sql
184 ldap:
Ales Komarekaabbda62016-03-15 08:38:35 +0100185 url: "ldaps://idm.domain.com"
186 suffix: "dc=cloud,dc=domain,dc=com"
187 # Will bind as uid=keystone,cn=users,cn=accounts,dc=cloud,dc=domain,dc=com
Filip Pytloun6b9ec2b2016-01-12 13:52:01 +0100188 uid: keystone
Ales Komarekaabbda62016-03-15 08:38:35 +0100189 password: password
Filip Pytloun6b9ec2b2016-01-12 13:52:01 +0100190
Filip Pytloun1abfdd72016-01-18 11:35:17 +0100191Using LDAP backend for default domain
192
193.. code-block:: yaml
194
195 keystone:
196 server:
197 backend: ldap
198 assignment:
199 backend: sql
200 ldap:
Ales Komarekaabbda62016-03-15 08:38:35 +0100201 url: "ldaps://idm.domain.com"
202 suffix: "dc=cloud,dc=domain,dc=com"
203 # Will bind as uid=keystone,cn=users,cn=accounts,dc=cloud,dc=domain,dc=com
Filip Pytloun1abfdd72016-01-18 11:35:17 +0100204 uid: keystone
Ales Komarekaabbda62016-03-15 08:38:35 +0100205 password: password
206
207Simple service endpoint definition (defaults to RegionOne)
208
209.. code-block:: yaml
210
211 keystone:
212 server:
213 service:
214 ceilometer:
215 type: metering
216 description: OpenStack Telemetry Service
217 user:
218 name: ceilometer
219 password: password
220 bind:
221 ...
222
223Region-aware service endpoints definition
224
225.. code-block:: yaml
226
227 keystone:
228 server:
229 service:
230 ceilometer_region01:
231 service: ceilometer
232 type: metering
233 region: region01
234 description: OpenStack Telemetry Service
235 user:
236 name: ceilometer
237 password: password
238 bind:
239 ...
240 ceilometer_region02:
241 service: ceilometer
242 type: metering
243 region: region02
244 description: OpenStack Telemetry Service
245 bind:
246 ...
247
Jakub Pavlik72e31d62016-04-08 16:26:57 +0200248Enable ceilometer notifications
249
250.. code-block:: yaml
251
252 keystone:
253 server:
254 notification: true
255 message_queue:
256 engine: rabbitmq
257 host: 127.0.0.1
258 port: 5672
259 user: openstack
260 password: password
261 virtual_host: '/openstack'
262 ha_queues: true
Filip Pytloun1abfdd72016-01-18 11:35:17 +0100263
Petr Michalec98fc6d62016-12-03 11:30:35 +0100264Enable CADF audit notification
265
266.. code-block:: yaml
267
268 keystone:
269 server:
270 notification: true
271 notification_format: cadf
272
Ales Komarek74a3ba62016-10-05 12:16:52 +0200273
274Keystone client
275---------------
276
277Service endpoints enforcement with service token
278
279.. code-block:: yaml
280
281 keystone:
282 client:
283 enabled: true
284 server:
285 keystone01:
286 admin:
287 host: 10.0.0.2
288 port: 35357
289 token: 'service_token'
290 service:
291 nova:
292 type: compute
293 description: OpenStack Compute Service
294 endpoints:
295 - region: region01
296 public_address: 172.16.10.1
297 public_port: 8773
298 public_path: '/v2'
299 internal_address: 172.16.10.1
300 internal_port: 8773
301 internal_path: '/v2'
302 admin_address: 172.16.10.1
303 admin_port: 8773
304 admin_path: '/v2'
305
306Project, users, roles enforcement with admin user
307
308.. code-block:: yaml
309
310 keystone:
311 client:
312 enabled: true
313 server:
314 keystone01:
315 admin:
316 host: 10.0.0.2
317 port: 5000
318 project: 'token'
319 user: admin
320 password: 'passwd'
321 roles:
322 - admin
323 - member
324 project:
325 tenant01:
326 description: "test env"
327 user:
328 user01:
329 email: jdoe@domain.com
330 is_admin: true
331 password: some
332 user02:
333 email: jdoe2@domain.com
334 password: some
335 roles:
336 - custom-roles
337
Jakub Pavlikffc280d2016-05-20 11:19:14 +0200338Documentation and Bugs
Ales Komarek74a3ba62016-10-05 12:16:52 +0200339======================
Filip Pytloun943d6882015-10-06 16:28:32 +0200340
Jakub Pavlikffc280d2016-05-20 11:19:14 +0200341To learn how to deploy OpenStack Salt, consult the documentation available
342online at:
343
344 https://wiki.openstack.org/wiki/OpenStackSalt
345
346In the unfortunate event that bugs are discovered, they should be reported to
347the appropriate bug tracker. If you obtained the software from a 3rd party
348operating system vendor, it is often wise to use their own bug tracker for
349reporting problems. In all other cases use the master OpenStack bug tracker,
350available at:
351
352 http://bugs.launchpad.net/openstack-salt
353
354Developers wishing to work on the OpenStack Salt project should always base
355their work on the latest formulas code, available from the master GIT
356repository at:
357
358 https://git.openstack.org/cgit/openstack/salt-formula-keystone
359
360Developers should also join the discussion on the IRC list, at:
361
362 https://wiki.openstack.org/wiki/Meetings/openstack-salt