[Openstack] How should an instance learn what tenant it is in?

Andrew Bogott abogott at wikimedia.org
Wed Jun 17 01:46:13 UTC 2015


     I have many uses cases in which an instance needs to know what 
project it is in.  Right now I accomplish this through an intricate hack 
which involves hooking instance creation and writing the tenant name to 
an ldap record.

     I'm considering rewriting this hack to write the tenant name into 
the metadata directly, but that will still be a hack.  Is there an 
obvious, implemented solution to this that I'm missing?  If not, would a 
nova patch that adds tenant id and name to the metadata be welcome?  Or, 
are there security reasons for preventing an instance from knowing its 
tenant?

-Andrew




More information about the Openstack mailing list