Ubuntu 12.04
Sponsored Link

OpenStack Havana - Keystone 設定#22013/11/22

 
Keystone に ユーザやロール、OpenStack 各コンポーネントが利用するサービスを登録しておきます。
[1] 環境変数を事前に読み込んでおく
「SERVICE_TOKEN」はkeystone.conf で「admin_token」に設定した値
「SERVICE_ENDPOINT」は Keystoneサーバーのホスト名またはIPアドレス
root@dlp:~#
export SERVICE_TOKEN=admintoken

root@dlp:~#
export SERVICE_ENDPOINT=http://10.0.0.30:35357/v2.0/

[2] テナント(グループ)を作成する
# admin テナント作成

root@dlp:~#
keystone tenant-create --name admin --description "Admin Tenant" --enabled true

+-------------+----------------------------------+
|   Property  |              Value               |
+-------------+----------------------------------+
| description |           Admin Tenant           |
|   enabled   |               True               |
|      id     | 3d7997a116ac48a4b72ff63327418e42 |
|     name    |              admin               |
+-------------+----------------------------------+

# service テナント作成

root@dlp:~#
keystone tenant-create --name service --description "Service Tenant" --enabled true

+-------------+----------------------------------+
|   Property  |              Value               |
+-------------+----------------------------------+
| description |          Service Tenant          |
|   enabled   |               True               |
|      id     | 17cfbcf053e745cfa0c4cf5cc6e80a32 |
|     name    |             service              |
+-------------+----------------------------------+

# 設定確認

root@dlp:~#
keystone tenant-list

+----------------------------------+---------+---------+
|                id                |   name  | enabled |
+----------------------------------+---------+---------+
| 3d7997a116ac48a4b72ff63327418e42 |  admin  |   True  |
| 17cfbcf053e745cfa0c4cf5cc6e80a32 | service |   True  |
+----------------------------------+---------+---------+
[3] ロールを作成する
# admin ロール作成

root@dlp:~#
keystone role-create --name admin

+----------+----------------------------------+
| Property |              Value               |
+----------+----------------------------------+
|    id    | 07e67314dfd74fc99b277953e65dc958 |
|   name   |              admin               |
+----------+----------------------------------+

# Member ロール作成

root@dlp:~#
keystone role-create --name Member

+----------+----------------------------------+
| Property |              Value               |
+----------+----------------------------------+
|    id    | e1001aae2627436f805467e9355c8a0d |
|   name   |              Member              |
+----------+----------------------------------+

# 設定確認

root@dlp:~#
keystone role-list

+----------------------------------+----------+
|                id                |   name   |
+----------------------------------+----------+
| e1001aae2627436f805467e9355c8a0d |  Member  |
| 9fe2ff9ee4384b1894a90878d3e92bab | _member_ |
| 07e67314dfd74fc99b277953e65dc958 |  admin   |
+----------------------------------+----------+
[4] ユーザーを作成する
# admin ユーザー作成 (admin テナント所属)

root@dlp:~#
keystone user-create --tenant admin --name admin --pass adminpassword --enabled true

+----------+----------------------------------+
| Property |              Value               |
+----------+----------------------------------+
|  email   |                                  |
| enabled  |               True               |
|    id    | befdaad20ff642ba851f58b7f9662cfd |
|   name   |              admin               |
| tenantId | 3d7997a116ac48a4b72ff63327418e42 |
+----------+----------------------------------+

# admin ユーザーを adminロール に加える

root@dlp:~#
keystone user-role-add --user admin --tenant admin --role admin
# glance ユーザー作成 (service テナント所属)

root@dlp:~#
keystone user-create --tenant service --name glance --pass servicepassword --enabled true

+----------+----------------------------------+
| Property |              Value               |
+----------+----------------------------------+
|  email   |                                  |
| enabled  |               True               |
|    id    | 95ad564fbb4f41d290d3128c9507e39a |
|   name   |              glance              |
| tenantId | 17cfbcf053e745cfa0c4cf5cc6e80a32 |
+----------+----------------------------------+

# glance ユーザーを adminロール に加える

root@dlp:~#
keystone user-role-add --user glance --tenant service --role admin
# nova ユーザー作成 (service テナント)

root@dlp:~#
keystone user-create --tenant service --name nova --pass servicepassword --enabled true

+----------+----------------------------------+
| Property |              Value               |
+----------+----------------------------------+
|  email   |                                  |
| enabled  |               True               |
|    id    | 6afd084e788b49089a1ea4c86f1de3e3 |
|   name   |               nova               |
| tenantId | 17cfbcf053e745cfa0c4cf5cc6e80a32 |
+----------+----------------------------------+

# nova ユーザーを adminロール に加える

root@dlp:~#
keystone user-role-add --user nova --tenant service --role admin
# 設定確認

root@dlp:~#
keystone user-list

+----------------------------------+--------+---------+-------+
|                id                |  name  | enabled | email |
+----------------------------------+--------+---------+-------+
| befdaad20ff642ba851f58b7f9662cfd | admin  |   True  |       |
| 95ad564fbb4f41d290d3128c9507e39a | glance |   True  |       |
| 6afd084e788b49089a1ea4c86f1de3e3 |  nova  |   True  |       |
+----------------------------------+--------+---------+-------+
[5] サービス用のエントリを作成する
# keystone用サービスエントリ作成

root@dlp:~#
keystone service-create --name=keystone --type=identity --description="Keystone Identity Service"

+-------------+----------------------------------+
|   Property  |              Value               |
+-------------+----------------------------------+
| description |    Keystone Identity Service     |
|      id     | 159031c5cba6430b9c4fbea4fbb582ab |
|     name    |             keystone             |
|     type    |             identity             |
+-------------+----------------------------------+

# glance用サービスエントリ作成

root@dlp:~#
keystone service-create --name=glance --type=image --description="Glance Image Service"

+-------------+----------------------------------+
|   Property  |              Value               |
+-------------+----------------------------------+
| description |       Glance Image Service       |
|      id     | 7eee3455b0084bd1b8728f9463d8d6e3 |
|     name    |              glance              |
|     type    |              image               |
+-------------+----------------------------------+

# nova用サービスエントリ作成

root@dlp:~#
keystone service-create --name=nova --type=compute --description="Nova Compute Service"

+-------------+----------------------------------+
|   Property  |              Value               |
+-------------+----------------------------------+
| description |       Nova Compute Service       |
|      id     | a9e6b1dce1b94701a655a9dcbe147250 |
|     name    |               nova               |
|     type    |             compute              |
+-------------+----------------------------------+

# 設定確認

root@dlp:~#
keystone service-list

+----------------------------------+----------+----------+---------------------------+
|                id                |   name   |   type   |        description        |
+----------------------------------+----------+----------+---------------------------+
| 7eee3455b0084bd1b8728f9463d8d6e3 |  glance  |  image   |    Glance Image Service   |
| 159031c5cba6430b9c4fbea4fbb582ab | keystone | identity | Keystone Identity Service |
| a9e6b1dce1b94701a655a9dcbe147250 |   nova   | compute  |    Nova Compute Service   |
+----------------------------------+----------+----------+---------------------------+
[6] エンドポイントを作成する
# 自ホストを定義しておく

root@dlp:~#
export my_host=10.0.0.30
# keystone 用エンドポイント作成

root@dlp:~#
keystone endpoint-create --region RegionOne \
--service keystone \
--publicurl "http://$my_host:\$(public_port)s/v2.0" \
--internalurl "http://$my_host:\$(public_port)s/v2.0" \
--adminurl "http://$my_host:\$(admin_port)s/v2.0"

+-------------+---------------------------------------+
|   Property  |                 Value                 |
+-------------+---------------------------------------+
|   adminurl  |  http://10.0.0.30:$(admin_port)s/v2.0 |
|      id     |    b25c8f741b254435984095e8854d2b61   |
| internalurl | http://10.0.0.30:$(public_port)s/v2.0 |
|  publicurl  | http://10.0.0.30:$(public_port)s/v2.0 |
|    region   |               RegionOne               |
|  service_id |    159031c5cba6430b9c4fbea4fbb582ab   |
+-------------+---------------------------------------+

# glance 用エンドポイント作成

root@dlp:~#
keystone endpoint-create --region RegionOne \
--service glance \
--publicurl "http://$my_host:9292/v1" \
--internalurl "http://$my_host:9292/v1" \
--adminurl "http://$my_host:9292/v1"

+-------------+----------------------------------+
|   Property  |              Value               |
+-------------+----------------------------------+
|   adminurl  |     http://10.0.0.30:9292/v1     |
|      id     | d0ef1f8e906745538007ba84993808f2 |
| internalurl |     http://10.0.0.30:9292/v1     |
|  publicurl  |     http://10.0.0.30:9292/v1     |
|    region   |            RegionOne             |
|  service_id | 7eee3455b0084bd1b8728f9463d8d6e3 |
+-------------+----------------------------------+

# nova 用エンドポイント作成

root@dlp:~#
keystone endpoint-create --region RegionOne \
--service nova \
--publicurl "http://$my_host:\$(compute_port)s/v1.1/\$(tenant_id)s" \
--internalurl "http://$my_host:\$(compute_port)s/v1.1/\$(tenant_id)s" \
--adminurl "http://$my_host:\$(compute_port)s/v1.1/\$(tenant_id)s"

+-------------+------------------------------------------------------+
|   Property  |                        Value                         |
+-------------+------------------------------------------------------+
|   adminurl  | http://10.0.0.30:$(compute_port)s/v1.1/$(tenant_id)s |
|      id     |           17f792a981954dbb943ce11f9f88df42           |
| internalurl | http://10.0.0.30:$(compute_port)s/v1.1/$(tenant_id)s |
|  publicurl  | http://10.0.0.30:$(compute_port)s/v1.1/$(tenant_id)s |
|    region   |                      RegionOne                       |
|  service_id |           a9e6b1dce1b94701a655a9dcbe147250           |
+-------------+------------------------------------------------------+

# 設定確認

root@dlp:~#
keystone endpoint-list

+----------------------------------+-----------+------------------------------------------------------+
|                id                |   region  |                      publicurl                       |
+----------------------------------+-----------+------------------------------------------------------+
| 17f792a981954dbb943ce11f9f88df42 | RegionOne | http://10.0.0.30:$(compute_port)s/v1.1/$(tenant_id)s |
| b25c8f741b254435984095e8854d2b61 | RegionOne |        http://10.0.0.30:$(public_port)s/v2.0         |
| d0ef1f8e906745538007ba84993808f2 | RegionOne |               http://10.0.0.30:9292/v1               |
+----------------------------------+-----------+------------------------------------------------------+
+------------------------------------------------------+------------------------------------------------------+
|                     internalurl                      |                       adminurl                       |
+------------------------------------------------------+------------------------------------------------------+
| http://10.0.0.30:$(compute_port)s/v1.1/$(tenant_id)s | http://10.0.0.30:$(compute_port)s/v1.1/$(tenant_id)s |
|        http://10.0.0.30:$(public_port)s/v2.0         |         http://10.0.0.30:$(admin_port)s/v2.0         |
|               http://10.0.0.30:9292/v1               |               http://10.0.0.30:9292/v1               |
+------------------------------------------------------+------------------------------------------------------+
+----------------------------------+
|            service_id            |
+----------------------------------+
| a9e6b1dce1b94701a655a9dcbe147250 |
| 159031c5cba6430b9c4fbea4fbb582ab |
| 7eee3455b0084bd1b8728f9463d8d6e3 |
+----------------------------------+
関連コンテンツ