My Experiment yesterday left me with a broken IPA install. I aim to fix that.
Continue reading
De-conflicting Swift-Proxy with FreeIPA
Port 8080 is a popular port. Tomcat uses it as the default port for unencrypted traffic. FreeIA, installs Dogtag which runs in Tomcat. Swift proxy also chose that port number for its traffic. This means that if one is run on that port, the other cannot. Of the two, it is easier to change FreeIPA, as the port is only used for internal traffic, where as Swift’s port is in the service catalog and the documentation.
Continue reading
Launching a Centos VM in Tripleo Overcloud
My Overcloud deploy does not have any VM images associates with it. I want to test launching a VM.
Continue reading
Clearing the Keystone Environment
If you spend a lot of time switching between different cloud, different users, or even different projects for the same user when working with openstack, you’ve come across the problem where one environment variable from an old sourceing pollutes the current environment. I’ve been hit by that enough times that I wrote a small script to clear the environment.
I call it clear_os_env
Continue reading
Keystone Auth Entry Points
OpenStack libraries now use Authenication plugins from the keystoneauth1 library. One othe the plugins has disappered? Kerbersop. This used to be in the python-keystoneclient-kerberos package, but that is not shipped with Mitaka. What happened?
Continue reading
The difference between auth_uri and auth_url in auth_token
Dramatis Personae:
Adam Young, Jamie Lennox: Keystone core.
Scene: #openstack-keystone chat room.
Learning about the Overcloud Deploy Process
The process of deploying the overcloud goes through several technologies. Here’s what I’ve learned about tracing it.
Continue reading
Custom Overcloud Deploys
I’ve been using Tripleo Quickstart. I need custom deploys. Start with modifying the heat templates. I’m doing a mitaka deploy
SAML Federated Auth Plugin
SAML is usually thought of as a WebSSO mechanism, but it can be made to work for command line operations if you use the Extended Client Protocol (ECP). When we did the Rippowam demo last year, we were successful in getting an Unscoped token by using ECP, but that was not sufficient to perform operations on other services that need a scoped token.
Continue reading
Reviews for RDO packages
We are in the process of getting the docs straightened out for reviewing RDO packages. As we do, I want to record what I have working.