blob: 0c0d0e26d35ee3959eff44d1246bbb43cf20d406 [file] [log] [blame]
Anthony Young3a093122011-09-13 19:01:45 +00001[DEFAULT]
2# Show more verbose log output (sets INFO log level output)
3verbose = False
4
5# Show debugging output in logs (sets DEBUG log level output)
6debug = False
7
8# Which backend store should Keystone use by default.
9# Default: 'sqlite'
10# Available choices are 'sqlite' [future will include LDAP, PAM, etc]
11default_store = sqlite
12
13# Log to this file. Make sure you do not set the same log
14# file for both the API and registry servers!
Anthony Younge8fed482011-09-26 19:50:43 -070015log_file = %DEST%/keystone/keystone.log
Anthony Young3a093122011-09-13 19:01:45 +000016
17# List of backends to be configured
18backends = keystone.backends.sqlalchemy
19#For LDAP support, add: ,keystone.backends.ldap
20
21# Dictionary Maps every service to a header.Missing services would get header
22# X_(SERVICE_NAME) Key => Service Name, Value => Header Name
23service-header-mappings = {
24 'nova' : 'X-Server-Management-Url',
25 'swift' : 'X-Storage-Url',
26 'cdn' : 'X-CDN-Management-Url'}
27
Jesse Andrews9c7c9082011-11-23 10:10:53 -080028#List of extensions currently supported
29extensions= osksadm,oskscatalog
30
Anthony Young3a093122011-09-13 19:01:45 +000031# Address to bind the API server
32# TODO Properties defined within app not available via pipeline.
33service_host = 0.0.0.0
34
35# Port the bind the API server to
36service_port = 5000
37
Jesse Andrews9c7c9082011-11-23 10:10:53 -080038# SSL for API server
39service_ssl = False
40
Anthony Young3a093122011-09-13 19:01:45 +000041# Address to bind the Admin API server
42admin_host = 0.0.0.0
43
44# Port the bind the Admin API server to
Anthony Younga449dd82011-09-30 15:52:18 -070045admin_port = 35357
Anthony Young3a093122011-09-13 19:01:45 +000046
Jesse Andrews9c7c9082011-11-23 10:10:53 -080047# SSL for API Admin server
48admin_ssl = False
49
50# Keystone certificate file (modify as needed)
51# Only required if *_ssl is set to True
52certfile = /etc/keystone/ssl/certs/keystone.pem
53
54# Keystone private key file (modify as needed)
55# Only required if *_ssl is set to True
56keyfile = /etc/keystone/ssl/private/keystonekey.pem
57
58# Keystone trusted CA certificates (modify as needed)
59# Only required if *_ssl is set to True
60ca_certs = /etc/keystone/ssl/certs/ca.pem
61
62# Client certificate required
63# Only relevant if *_ssl is set to True
64cert_required = True
65
Anthony Young3a093122011-09-13 19:01:45 +000066#Role that allows to perform admin operations.
Jesse Andrews9c7c9082011-11-23 10:10:53 -080067keystone-admin-role = Admin
Anthony Young3a093122011-09-13 19:01:45 +000068
69#Role that allows to perform service admin operations.
Anthony Youngea884c32011-09-23 03:24:27 +000070keystone-service-admin-role = KeystoneServiceAdmin
Anthony Young3a093122011-09-13 19:01:45 +000071
Jesse Andrews9c7c9082011-11-23 10:10:53 -080072#Tells whether password user need to be hashed in the backend
73hash-password = True
74
Anthony Young3a093122011-09-13 19:01:45 +000075[keystone.backends.sqlalchemy]
76# SQLAlchemy connection string for the reference implementation registry
77# server. Any valid SQLAlchemy connection string is fine.
78# See: http://bit.ly/ideIpI
Anthony Younga8416442011-09-13 20:07:44 -070079sql_connection = %SQL_CONN%
Anthony Young3a093122011-09-13 19:01:45 +000080backend_entities = ['UserRoleAssociation', 'Endpoints', 'Role', 'Tenant',
81 'User', 'Credentials', 'EndpointTemplates', 'Token',
82 'Service']
83
84# Period in seconds after which SQLAlchemy should reestablish its connection
85# to the database.
86sql_idle_timeout = 30
87
88[pipeline:admin]
89pipeline =
Jesse Andrews9c7c9082011-11-23 10:10:53 -080090 urlrewritefilter
91 admin_api
Anthony Young3a093122011-09-13 19:01:45 +000092
93[pipeline:keystone-legacy-auth]
94pipeline =
Jesse Andrews9c7c9082011-11-23 10:10:53 -080095 urlrewritefilter
Anthony Young3a093122011-09-13 19:01:45 +000096 legacy_auth
97 RAX-KEY-extension
98 service_api
99
100[app:service_api]
101paste.app_factory = keystone.server:service_app_factory
102
103[app:admin_api]
104paste.app_factory = keystone.server:admin_app_factory
105
106[filter:urlrewritefilter]
107paste.filter_factory = keystone.middleware.url:filter_factory
108
109[filter:legacy_auth]
110paste.filter_factory = keystone.frontends.legacy_token_auth:filter_factory
111
112[filter:RAX-KEY-extension]
113paste.filter_factory = keystone.contrib.extensions.service.raxkey.frontend:filter_factory
Jesse Andrews9c7c9082011-11-23 10:10:53 -0800114
115[filter:debug]
116paste.filter_factory = keystone.common.wsgi:debug_filter_factory