# yum install -y openstack-keystone httpd mod_wsgi

# mysql -u root -p -e "CREATE DATABASE keystone "

MariaDB [(none)]> CREATE DATABASE keystone;

Query OK, 1 row affected (0.03 sec)

MariaDB [(none)]> GRANT ALL PRIVILEGES ON keystone.* TO 'keystone'@'localhost' \

IDENTIFIED BY 'zoomtech';

MariaDB [(none)]> GRANT ALL PRIVILEGES ON keystone.* TO 'keystone'@'%' \

->   IDENTIFIED BY 'zoomtech';

Query OK, 0 rows affected (0.01 sec)

MariaDB [(none)]> exit

Bye

[root@controller1 ~]# mysql -uroot -p -e "CREATE DATABASE keystone"

[root@controller1 ~]# mysql -uroot -p -e "GRANT ALL PRIVILEGES ON keystone.* TO 'keystone'@'%'  IDENTIFIED BY 'zoomtech'"

[root@controller1 ~]# mysql -uroot -p -e "GRANT ALL PRIVILEGES ON keystone.* TO 'keystone'@'localhost'  IDENTIFIED BY 'zoomtech'"

[root@controller1 ~]# openssl rand -hex 10

d68d8a32a75bdbfdb004

配置/etc/keystone/keystone.conf文件

[DEFAULT]

verbose = true

admin_token = 745faaa51f7c62f8a2a7

public_bind_host = 192.168.17.132

admin_bind_host = 192.168.17.132

bind_host = controller1

[database]

connection = mysql+pymysql://keystone:zoomtech@demo.open-stack.cn/keystone

[token]

provider = keystone.token.providers.uuid.Provider

dirver = keystone.token.persistence.backends.memcach.Token

caching = true

token = keystone.auth.plugins.token.Token

[revoke]

driver = keystone.contrib.revoke.backends.sql.Revoke

[identity]

driver = sql

#driver = keystone.identity.backends.sql.identity

[catalog]

driver = sql

#driver = keystone.catalog.backends.sql.Catalog

[memcache]

servers = controller1:11211,controller2:11211,controller3:11211

[root@controller1 ~]# openstack-config --set /etc/keystone/keystone.conf DEFAULT admin_token d68d8a32a75bdbfdb004

[root@controller1 ~]# openstack-config --set /etc/keystone/keystone.conf database connection mysql+pymysql://keystone:zoomtech@demo.open-stack.cn/keystone

[root@controller1 ~]# openstack-config --set /etc/keystone/keystone.conf token provider fernet

[root@controller1 ~]# openstack-config --set /etc/keystone/keystone.conf memcache servers controller1:11211,controller2:11211,controller3:11211

[root@controller1 ~]# scp /etc/keystone/keystone.conf controller2:/etc/keystone/

keystone.conf                                                          100%   72KB  71.9KB/s   00:00

[root@controller1 ~]# scp /etc/keystone/keystone.conf controller3:/etc/keystone/

[root@controller2 ~]# vim /etc/keystone/keystone.conf

admin_token = 745faaa51f7c62f8a2a7

public_bind_host = 192.168.17.151

bind_host = controller2

admin_bind_host = 192.168.17.151

[root@controller3 ~]# vim /etc/keystone/keystone.conf

[default]

public_bind_host = 192.168.17.138

bind_host = controller3

admin_bind_host = 192.168.17.138

确认权限

[root@controller1 ~]# ll /etc/keystone/keystone.conf

-rw-r----- 1 root keystone 73642 Feb 21 15:42 /etc/keystone/keystone.conf

[root@controller1 ~]# chown root:keystone /etc/keystone/keystone.conf

[root@controller1 ~]# chmod 640 /etc/keystone/keystone.conf

同步Keystone数据库

[root@controller1 ~]# su -s /bin/sh -c "keystone-manage db_sync" keystone

初始化Fernet keys

[root@controller1 ~]# keystone-manage fernet_setup --keystone-user keystone --keystone-group keystone

配置Apache Http服务

1、三个节点配置 /etc/httpd/conf/httpd.conf

[root@controller1 ~] # vim /etc/httpd/conf/httpd.conf

ServerName controller1

Listen 8080

[root@controller2 ~]# vim /etc/httpd/conf/httpd.conf

ServerName controller2

Listen 8080

[root@controller3 ~]# vim /etc/httpd/conf/httpd.conf

ServerName controller3

Listen 8080

2、[root@controller1 ~]# vim /etc/httpd/conf.d/wsgi-keystone.conf

<VirtualHost *:5000>

WSGIDaemonProcess keystone-public processes=5 threads=1 user=keystone group=keystone display-name=%{GROUP}

WSGIProcessGroup keystone-public

WSGIScriptAlias / /usr/bin/keystone-wsgi-public

WSGIApplicationGroup %{GLOBAL}

WSGIPassAuthorization On

ErrorLogFormat "%{cu}t %M"

ErrorLog /var/log/httpd/keystone-error.log

CustomLog /var/log/httpd/keystone-access.log combined

<Directory /usr/bin>

Require all granted

</Directory>

</VirtualHost>

<VirtualHost *:35357>

WSGIDaemonProcess keystone-admin processes=5 threads=1 user=keystone group=keystone display-name=%{GROUP}

WSGIProcessGroup keystone-admin

WSGIScriptAlias / /usr/bin/keystone-wsgi-admin

WSGIApplicationGroup %{GLOBAL}

WSGIPassAuthorization On

ErrorLogFormat "%{cu}t %M"

ErrorLog /var/log/httpd/keystone-error.log

CustomLog /var/log/httpd/keystone-access.log combined

<Directory /usr/bin>

Require all granted

</Directory>

</VirtualHost>

将wsgi-keystone.conf复制到 controller2和controller3

3、启动apache

# systemctl enable httpd.service

# systemctl start httpd.service

[root@controller1 ~]# export OS_TOKEN=d68d8a32a75bdbfdb004

[root@controller1 ~]# export OS_URL=http://demo.open-stack.cn:35357/v3

[root@controller1 ~]# export OS_IDENTITY_API_VERSION=3

创建服务实体和身份认证服务:

[root@controller1 ~]# openstack service create   --name keystone --description "OpenStack Identity" identity

+-------------+----------------------------------+

| Field       | Value                            |

+-------------+----------------------------------+

| description | OpenStack Identity               |

| enabled     | True                             |

| id          | 5fe30200d9464aa384b5ddc1864b0244 |

| name        | keystone                         |

| type        | identity                         |

+-------------+----------------------------------+

error:

Unable to establish connection to http://demo.open-stack.cn:35357/v3/services

创建认证服务的 API 端点:

[root@controller1 ~]# openstack endpoint create --region RegionOne \

identity public http://demo.open-stack.cn:5000/v3

+--------------+-----------------------------------+

| Field        | Value                             |

+--------------+-----------------------------------+

| enabled      | True                              |

| id           | 527cfe77e4d64668ae4c5a92f5841607  |

| interface    | public                            |

| region       | RegionOne                         |

| region_id    | RegionOne                         |

| service_id   | 5fe30200d9464aa384b5ddc1864b0244  |

| service_name | keystone                          |

| service_type | identity                          |

| url          | http://demo.open-stack.cn:5000/v3 |

+--------------+-----------------------------------+

[root@controller1 ~]# openstack endpoint create --region RegionOne   identity internal http://demo.open-stack.cn:5000/v3

+--------------+-----------------------------------+

| Field        | Value                             |

+--------------+-----------------------------------+

| enabled      | True                              |

| id           | 9ecf73dab7c9481b9bb6976be271e93c  |

| interface    | internal                          |

| region       | RegionOne                         |

| region_id    | RegionOne                         |

| service_id   | 5fe30200d9464aa384b5ddc1864b0244  |

| service_name | keystone                          |

| service_type | identity                          |

| url          | http://demo.open-stack.cn:5000/v3 |

+--------------+-----------------------------------+

[root@controller1 ~]# openstack endpoint create --region RegionOne   identity admin http://demo.open-stack.cn:35357/v3

+--------------+------------------------------------+

| Field        | Value                              |

+--------------+------------------------------------+

| enabled      | True                               |

| id           | 4606f3b199a14167a9ebe76a0bda45f3   |

| interface    | admin                              |

| region       | RegionOne                          |

| region_id    | RegionOne                          |

| service_id   | 5fe30200d9464aa384b5ddc1864b0244   |

| service_name | keystone                           |

| service_type | identity                           |

| url          | http://demo.open-stack.cn:35357/v3 |

+--------------+------------------------------------+

[root@controller1 ~]# openstack domain create --description "Default Domain" default

+-------------+----------------------------------+

| Field       | Value                            |

+-------------+----------------------------------+

| description | Default Domain                   |

| enabled     | True                             |

| id          | 6fb0271bda4d459ab05a752b7708dee3 |

| name        | default                          |

+-------------+----------------------------------+

[root@controller1 ~]# openstack project create --domain default \

--description "Admin Project" admin

+-------------+----------------------------------+

| Field       | Value                            |

+-------------+----------------------------------+

| description | Admin Project                    |

| domain_id   | 6fb0271bda4d459ab05a752b7708dee3 |

| enabled     | True                             |

| id          | b81fade4255149c29aa53b87312f60de |

| is_domain   | False                            |

| name        | admin                            |

| parent_id   | 6fb0271bda4d459ab05a752b7708dee3 |

+-------------+----------------------------------+

[root@controller1 ~]# openstack user create --domain default \

--password-prompt admin

User Password:

Repeat User Password:

+-----------+----------------------------------+

| Field     | Value                            |

+-----------+----------------------------------+

| domain_id | 6fb0271bda4d459ab05a752b7708dee3 |

| enabled   | True                             |

| id        | e88caafd2c874b6ab4bc23d8b5fbf422 |

| name      | admin                            |

+-----------+----------------------------------+

[root@controller1 ~]# openstack role create admin

+-----------+----------------------------------+

| Field     | Value                            |

+-----------+----------------------------------+

| domain_id | None                             |

| id        | cb618462ef4a4479a7c0b611d3ead7ed |

| name      | admin                            |

+-----------+----------------------------------+

[root@controller1 ~]# openstack role add --project admin --user admin admin

创建Service

[root@controller1 ~]# openstack project create --domain default \

--description "Service Project" service

+-------------+----------------------------------+

| Field       | Value                            |

+-------------+----------------------------------+

| description | Service Project                  |

| domain_id   | 6fb0271bda4d459ab05a752b7708dee3 |

| enabled     | True                             |

| id          | b581d85c3bd642d88909f36a1ebb6387 |

| is_domain   | False                            |

| name        | service                          |

| parent_id   | 6fb0271bda4d459ab05a752b7708dee3 |

+-------------+----------------------------------+

创建``demo`` 项目:

[root@controller1 ~]# openstack project create --domain default \

--description "Demo Project" demo

+-------------+----------------------------------+

| Field       | Value                            |

+-------------+----------------------------------+

| description | Demo Project                     |

| domain_id   | 6fb0271bda4d459ab05a752b7708dee3 |

| enabled     | True                             |

| id          | da951d38bfd24ecc9d7384d3b8760dd6 |

| is_domain   | False                            |

| name        | demo                             |

| parent_id   | 6fb0271bda4d459ab05a752b7708dee3 |

+-------------+----------------------------------+

[root@controller1 ~]# openstack user create --domain default \

--password-prompt demo

User Password:

Repeat User Password:

+-----------+----------------------------------+

| Field     | Value                            |

+-----------+----------------------------------+

| domain_id | 6fb0271bda4d459ab05a752b7708dee3 |

| enabled   | True                             |

| id        | f113613d853342dba7b9636b571208bf |

| name      | demo                             |

+-----------+----------------------------------+

创建 user 角色:

[root@controller1 ~]# openstack role create user

+-----------+----------------------------------+

| Field     | Value                            |

+-----------+----------------------------------+

| domain_id | None                             |

| id        | 1c0bcc0e6ffe46d7b0366ead1d55908f |

| name      | user                             |

+-----------+----------------------------------+

[root@controller1 ~]# openstack role add --project demo --user demo user

编辑 /etc/keystone/keystone-paste.ini 文件,从``[pipeline:public_api]``,[pipeline:admin_api]``和``[pipeline:api_v3]``部分删除``admin_token_auth

[root@controller1 ~]# vim /etc/keystone/keystone-paste.ini

[root@controller1 ~]#

[root@controller1 ~]# unset OS_TOKEN OS_URL

[root@controller1 ~]# openstack --os-auth-url http://demo.open-stack.cn:35357/v3   --os-project-domain-name default --os-user-domain-name default   --os-project-name admin --os-username admin token issue

Password:

+------------+----------------------------------+

| Field      | Value                            |

+------------+----------------------------------+

| expires    | 2017-02-22T06:28:10.845869Z      |

| id         | cff141923edc40d69ead04bcde8f01c4 |

| project_id | b81fade4255149c29aa53b87312f60de |

| user_id    | e88caafd2c874b6ab4bc23d8b5fbf422 |

+------------+----------------------------------+

[root@controller1 ~]# vim admin-openrc.sh

export OS_PROJECT_DOMAIN_NAME=default

export OS_USER_DOMAIN_NAME=default

export OS_PROJECT_NAME=admin

export OS_USERNAME=admin

export OS_PASSWORD=zoomtech

export OS_AUTH_URL=http://demo.open-stack.cn:35357/v3

export OS_IDENTITY_API_VERSION=3

export OS_IMAGE_API_VERSION=2

[root@controller1 ~]# source admin-openrc.sh

[root@controller1 ~]# openstack token issue

+------------+----------------------------------+

| Field      | Value                            |

+------------+----------------------------------+

| expires    | 2017-02-22T06:30:45.484675Z      |

| id         | de745b965ce2466a904f18ce0a187279 |

| project_id | b81fade4255149c29aa53b87312f60de |

| user_id    | e88caafd2c874b6ab4bc23d8b5fbf422 |

+------------+----------------------------------+

[root@controller1 ~]# openstack service list

+----------------------------------+----------+----------+

| ID                               | Name     | Type     |

+----------------------------------+----------+----------+

| 5fe30200d9464aa384b5ddc1864b0244 | keystone | identity |

+----------------------------------+----------+----------+

在 Controller2上验证Keystone

[root@controller2 ~]# source admin-openrc.sh

[root@controller2 ~]# openstack token issue

+------------+----------------------------------+

| Field      | Value                            |

+------------+----------------------------------+

| expires    | 2017-02-22T06:31:51.487910Z      |

| id         | e2ffc4461c604107ac9ba7386d493a09 |

| project_id | b81fade4255149c29aa53b87312f60de |

| user_id    | e88caafd2c874b6ab4bc23d8b5fbf422 |

+------------+----------------------------------+

[root@controller2 ~]# openstack service list

+----------------------------------+----------+----------+

| ID                               | Name     | Type     |

+----------------------------------+----------+----------+

| 5fe30200d9464aa384b5ddc1864b0244 | keystone | identity |

+----------------------------------+----------+----------+

在 Controller2上验证Keystone

[root@controller3 ~]# source admin-openrc.sh

[root@controller3 ~]# openstack token issue

+------------+----------------------------------+

| Field      | Value                            |

+------------+----------------------------------+

| expires    | 2017-02-22T06:32:19.618061Z      |

| id         | 3db2b1cec73d48b496ac8845e0842bea |

| project_id | b81fade4255149c29aa53b87312f60de |

| user_id    | e88caafd2c874b6ab4bc23d8b5fbf422 |

+------------+----------------------------------+

[root@controller3 ~]# openstack service list

+----------------------------------+----------+----------+

| ID                               | Name     | Type     |

+----------------------------------+----------+----------+

| 5fe30200d9464aa384b5ddc1864b0244 | keystone | identity |

+----------------------------------+----------+----------+

本文转自 OpenStack2015 51CTO博客,原文链接:http://blog.51cto.com/andyliu/1917399,如需转载请自行联系原作者

Openstack HA集群5-Keystone HA的更多相关文章

  1. OpenStack Swift集群与Keystone的整合使用说明

    之前已经介绍了OpenStack Swift集群和Keystone的安装部署,最后来讲一讲Swift集群与Keystone的整合使用吧. 1. 简介 本文档描述了Keystone与Swift集群的整合 ...

  2. HUE配置文件hue.ini 的hdfs_clusters模块详解(图文详解)(分HA集群和非HA集群)

    不多说,直接上干货! 我的集群机器情况是 bigdatamaster(192.168.80.10).bigdataslave1(192.168.80.11)和bigdataslave2(192.168 ...

  3. HUE配置文件hue.ini 的hive和beeswax模块详解(图文详解)(分HA集群和非HA集群)

    不多说,直接上干货! 我的集群机器情况是 bigdatamaster(192.168.80.10).bigdataslave1(192.168.80.11)和bigdataslave2(192.168 ...

  4. HUE配置文件hue.ini 的yarn_clusters模块详解(图文详解)(分HA集群和非HA集群)

    不多说,直接上干货! 我的集群机器情况是 bigdatamaster(192.168.80.10).bigdataslave1(192.168.80.11)和bigdataslave2(192.168 ...

  5. HUE配置文件hue.ini 的database模块详解(包含qlite、mysql、 psql、和oracle)(图文详解)(分HA集群和非HA集群)

    不多说,直接上干货! Hue配置文件里,提及到,提供有postgresql_psycopg2, mysql, sqlite3 or oracle. 注意:Hue本身用到的是sqlite3. 在哪里呢, ...

  6. HUE配置文件hue.ini 的hbase模块详解(图文详解)(分HA集群和非HA集群)

    不多说,直接上干货! 我的集群机器情况是 bigdatamaster(192.168.80.10).bigdataslave1(192.168.80.11)和bigdataslave2(192.168 ...

  7. HUE配置文件hue.ini 的pig模块详解(图文详解)(分HA集群和非HA集群)

    不多说,直接上干货! 一.默认的pig配置文件 ########################################################################### ...

  8. HUE配置文件hue.ini 的sqoop模块详解(图文详解)(分HA集群和非HA集群)

    不多说,直接上干货! 我的集群机器情况是 bigdatamaster(192.168.80.10).bigdataslave1(192.168.80.11)和bigdataslave2(192.168 ...

  9. HUE配置文件hue.ini 的filebrowser模块详解(图文详解)(分HA集群和非HA集群)

    不多说,直接上干货! 我的集群机器情况是 bigdatamaster(192.168.80.10).bigdataslave1(192.168.80.11)和bigdataslave2(192.168 ...

  10. HUE配置文件hue.ini 的mapred_clusters模块详解(图文详解)(分HA集群和非HA集群)

    不多说,直接上干货! 我的集群机器情况是 bigdatamaster(192.168.80.10).bigdataslave1(192.168.80.11)和bigdataslave2(192.168 ...

随机推荐

  1. LoadRunner从入门到实战学习路线(持续更新中...)

    写在前面        我是一个测试工程师,从土木工程行业转行到互联网行业,目前是工作的第三年.平时主要做功能测试,性能测试接触比较少,虽然以前培训的时候学习过一些性能相关的知识,但都是入门初级的知识 ...

  2. Java中String转int型的方法以及错误处理

    应要求,本周制作了一个判断一个年份是否是闰年的程序.逻辑很简单,这里就不贴代码了.可是,在这次程序编写中发现了一个问题. 在输入年份时,如果输入1)字母2)空3)超过Int上限时,就会抛excepti ...

  3. AJ学IOS(16)UI之XIB自定义Cell实现团购UI

    AJ分享,必须精品 先看效果图 自定义Cell 本次主要是自定义Cell的学习 实现自定义Cell主要有三种方法:按照使用的频繁度排序: XIB > 纯代码 > StoryBoard XI ...

  4. 使用malloc和free函数进行内存动态分配

    一.在学习c语言里面,内存分配这个话题非常有意思,因为我们平时在开发的时候,如果一不小心没注意内存释放的话,写的的程序很容易出错,所以今天就来回顾一下c语言里面的内存动态分配,下面我们先来看一个实例来 ...

  5. mvc传递json数据到view简单实例

    基于extjs4.2 controller //存储数据的类 public class DataLink { public string Name { get; set; } public strin ...

  6. 一篇文章快速搞懂Redis的慢查询分析

    什么是慢查询? 慢查询,顾名思义就是比较慢的查询,但是究竟是哪里慢呢?首先,我们了解一下Redis命令执行的整个过程: 发送命令 命令排队 命令执行 返回结果 在慢查询的定义中,统计比较慢的时间段指的 ...

  7. SpringBoot系列(九)单,多文件上传的正确姿势

    SpringBoot系列(九)分分钟解决文件上传 往期推荐 SpringBoot系列(一)idea新建Springboot项目 SpringBoot系列(二)入门知识 springBoot系列(三)配 ...

  8. @SessionAttributes 的使用

    @SessionAttributes 注解只用作用在 类 上,作用是将指定的 Model 的键值对保存在 session 中.可以让其他请求共用 session 中的键值对. 指定保存的属性名 作用是 ...

  9. React AntDesign 引入css

    React项目是用umi脚手架搭建的AntDesign,用到一个第三方表格组件Jexcel,npm install 之后组件的样式加载不上,犯了愁,翻阅各种资料,踏平两个小坑. 大家都知道,安装完成的 ...

  10. Suctf知识记录&&PHP代码审计,无字母数字webshell&&open_basedir绕过&&waf+idna+pythonssrf+nginx

    Checkin .user.ini构成php后门利用,设置auto_prepend_file=01.jpg,自动在文件前包含了01.jpg,利用.user.ini和图片马实现文件包含+图片马的利用. ...