# rocky ############################################################################### # [ WARNING ] # Configuration file maintained by Juju. Local changes may be overwritten. ############################################################################### [DEFAULT] admin_token = {{ token }} use_syslog = {{ use_syslog }} log_config_append = {{ log_config }} debug = {{ debug }} public_endpoint = {{ public_endpoint }} admin_endpoint = {{ admin_endpoint }} [database] {% if database_host -%} connection = {{ database_type }}://{{ database_user }}:{{ database_password }}@{{ database_host }}/{{ database }}{% if database_ssl_ca %}?ssl_ca={{ database_ssl_ca }}{% if database_ssl_cert %}&ssl_cert={{ database_ssl_cert }}&ssl_key={{ database_ssl_key }}{% endif %}{% endif %} {% else -%} connection = sqlite:////var/lib/keystone/keystone.db {% endif -%} idle_timeout = 200 [identity] driver = {{ identity_backend }} {% if default_domain_id -%} default_domain_id = {{ default_domain_id }} {% endif -%} {% if api_version == 3 -%} domain_specific_drivers_enabled = True domain_config_dir = {{ domain_config_dir }} {% endif -%} [credential] driver = sql [trust] driver = sql [catalog] driver = sql [endpoint_filter] [token] expiration = {{ token_expiration }} {% include "parts/section-signing" %} {% include "section-oslo-cache" %} [policy] driver = sql [assignment] driver = {{ assignment_backend }} [auth] methods = external,password,token,oauth1,mapped,openid,totp [paste_deploy] config_file = {{ paste_config_file }} [extra_headers] Distribution = Ubuntu [ldap] {% if identity_backend == 'ldap' -%} url = {{ ldap_server }} user = {{ ldap_user }} password = {{ ldap_password }} suffix = {{ ldap_suffix }} {% if ldap_config_flags -%} {% for key, value in ldap_config_flags.iteritems() -%} {{ key }} = {{ value }} {% endfor -%} {% endif -%} {% if ldap_readonly -%} user_allow_create = False user_allow_update = False user_allow_delete = False tenant_allow_create = False tenant_allow_update = False tenant_allow_delete = False role_allow_create = False role_allow_update = False role_allow_delete = False group_allow_create = False group_allow_update = False group_allow_delete = False {% endif -%} {% endif -%} {% if api_version == 3 -%} [resource] admin_project_domain_name = {{ admin_domain_name }} admin_project_name = admin {% endif -%} {% include "parts/section-federation" %} {% include "section-oslo-middleware" %}