[openstack-dev] [fuel] OS_SERVICE_TOKEN usage in Fuel

Oleksiy Molchanov omolchanov at mirantis.com
Tue Jul 28 15:26:47 UTC 2015


Hello all,

We need to discuss removal of OS_SERVICE_TOKEN usage in Fuel after
deployment. This came from https://bugs.launchpad.net/fuel/+bug/1430619. I
guess not all of us have an access to this bug, so to be short:

# A "shared secret" that can be used to bootstrap Keystone.
# This "token" does not represent a user, and carries no
# explicit authorization. To disable in production (highly
# recommended), remove AdminTokenAuthMiddleware from your
# paste application pipelines (for example, in keystone-
# paste.ini). (string value)

After removing this and testing we found out that OSTF fails because it
uses admin token.

What do you think if we create ostf user like for workloads, but with wider
permissions?

BR,
Oleksiy.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openstack.org/pipermail/openstack-dev/attachments/20150728/7a480e86/attachment.html>


More information about the OpenStack-dev mailing list