glance: deploy services with Keystone v3 endpoints
authorEmilien Macchi <emilien@redhat.com>
Tue, 7 Mar 2017 21:47:34 +0000 (16:47 -0500)
committerJuan Antonio Osorio Robles <jaosorior@redhat.com>
Thu, 20 Apr 2017 07:15:21 +0000 (07:15 +0000)
* Switch auth_uri to point to Keystone versionless endpoint.
* Switch Swift auth url to use Keystone versionless endpoint and
  Keystone v3 API.

Co-Authored-By: Juan Antonio Osorio Robles <jaosorior@redhat.com>
Change-Id: I78cdd2286b5a5094f36d4f3c7c58340745664449
Partial-blueprint: keystone-v3

puppet/services/glance-api.yaml
releasenotes/notes/glance-keystonev3-d35182ba9a3778eb.yaml [new file with mode: 0644]

index f61e615..68b16cf 100644 (file)
@@ -153,7 +153,7 @@ outputs:
                   - '/glance'
                   - '?read_default_file=/etc/my.cnf.d/tripleo.cnf&read_default_group=tripleo'
             glance::api::bind_port: {get_param: [EndpointMap, GlanceInternal, port]}
-            glance::api::authtoken::auth_uri: {get_param: [EndpointMap, KeystoneInternal, uri] }
+            glance::api::authtoken::auth_uri: {get_param: [EndpointMap, KeystoneInternal, uri_no_suffix] }
             glance::api::authtoken::auth_url: { get_param: [EndpointMap, KeystoneInternal, uri_no_suffix] }
             glance::api::enable_v1_api: false
             glance::api::enable_v2_api: true
@@ -168,6 +168,8 @@ outputs:
                   - 9292
                   - 13292
             glance::api::authtoken::project_name: 'service'
+            glance::keystone::authtoken::user_domain_name: 'Default'
+            glance::keystone::authtoken::project_domain_name: 'Default'
             glance::api::pipeline: 'keystone'
             glance::api::show_image_direct_url: true
             # NOTE: bind IP is found in Heat replacing the network name with the
@@ -195,10 +197,11 @@ outputs:
               - {get_param: [ServiceNetMap, GlanceApiNetwork]}
             glance_notifier_strategy: {get_param: GlanceNotifierStrategy}
             glance_log_file: {get_param: GlanceLogFile}
-            glance::backend::swift::swift_store_auth_address: {get_param: [EndpointMap, KeystoneInternal, uri] }
+            glance::backend::swift::swift_store_auth_address: {get_param: [EndpointMap, KeystoneV3Internal, uri] }
             glance::backend::swift::swift_store_user: service:glance
             glance::backend::swift::swift_store_key: {get_param: GlancePassword}
             glance::backend::swift::swift_store_create_container_on_put: true
+            glance::backend::swift::swift_store_auth_version: 3
             glance::backend::rbd::rbd_store_pool: {get_param: GlanceRbdPoolName}
             glance::backend::rbd::rbd_store_user: {get_param: CephClientUserName}
             glance_backend: {get_param: GlanceBackend}
diff --git a/releasenotes/notes/glance-keystonev3-d35182ba9a3778eb.yaml b/releasenotes/notes/glance-keystonev3-d35182ba9a3778eb.yaml
new file mode 100644 (file)
index 0000000..072e85a
--- /dev/null
@@ -0,0 +1,4 @@
+---
+features:
+  - Deploy Glance with Keystone v3 endpoints and make
+    sure it doesn't rely on Keystone v2 anymore.