컨트롤러 노드에 Keystone 을 설치하고 Apache 아래에서 서비스한다. 데이터베이스 설정을 먼저 끝낸다. KEYSTONE_DBPASS · ADMIN_PASS 는 미리 정한 값으로 바꾼다.
Ubuntu 24.04
apt install keystone
CentOS Stream 9 · RHEL 9
dnf install openstack-keystone httpd uwsgi-plugin-python3
/etc/keystone/keystone.conf 의 다음 절에 값을 넣는다.
[database]
connection = mysql+pymysql://keystone:KEYSTONE_DBPASS@controller/keystone
[token]
provider = fernet
[database] 절의 다른 connection 항목은 주석 처리한다.
su -s /bin/sh -c "keystone-manage db_sync" keystone
keystone-manage fernet_setup --keystone-user keystone --keystone-group keystone
keystone-manage credential_setup --keystone-user keystone --keystone-group keystone
admin 사용자 · admin 프로젝트 · RegionOne 리전 · identity 서비스 엔드포인트를 한 번에 만든다.
keystone-manage bootstrap --bootstrap-password ADMIN_PASS \
--bootstrap-admin-url http://controller:5000/v3/ \
--bootstrap-internal-url http://controller:5000/v3/ \
--bootstrap-public-url http://controller:5000/v3/ \
--bootstrap-region-id RegionOne
Ubuntu 24.04 — /etc/apache2/apache2.conf 에 ServerName 을 추가한다.
ServerName controller
systemctl restart apache2
CentOS Stream 9 · RHEL 9 — /etc/httpd/conf/httpd.conf 에 ServerName 을 추가하고 uwsgi 설정을 링크한다.
ServerName controller
ln -s /usr/share/keystone/uwsgi-keystone.conf /etc/httpd/conf.d/
systemctl enable httpd.service
systemctl start httpd.service
RHEL 계열에서 firewalld 를 쓰면 5000/tcp 를 연다.
firewall-cmd --permanent --add-port=5000/tcp
firewall-cmd --reload
export OS_USERNAME=admin
export OS_PASSWORD=ADMIN_PASS
export OS_PROJECT_NAME=admin
export OS_USER_DOMAIN_NAME=Default
export OS_PROJECT_DOMAIN_NAME=Default
export OS_AUTH_URL=http://controller:5000/v3
export OS_IDENTITY_API_VERSION=3
openstack token issue
openstack endpoint list
토큰이 발급되고 identity 서비스의 엔드포인트 세 개가 보이면 다음 단계인 도메인 · 프로젝트 · 사용자 생성으로 넘어간다.
CentOS Stream 8 은 mod_wsgi 를 썼다.
yum install -y openstack-keystone httpd python3-mod_wsgi
ln -s /usr/share/keystone/wsgi-keystone.conf /etc/httpd/conf.d/
CentOS 7 은 mod_wsgi 패키지를 쓴다.