Application Credentials
Application Credentials
It is strongly recommended to create an OpenStack application credential and avoid storing your personal credentials on disk.
An OpenStack application credential has at most:
- the permissions of the account for which it was created,
- only within the scope of the project in which it was created.
Using application credentials is therefore important for restricting the scope of our actions.
Creation
usage: openstack application credential create
[-h] [-f {json,shell,table,value,yaml}] [-c COLUMN] [--noindent]
[--prefix PREFIX] [--max-width <integer>] [--fit-width] [--print-empty]
[--secret <secret>] [--role <role>] [--expiration <expiration>]
[--description <description>] [--unrestricted] [--restricted]
[--access-rules <access-rules>]
<name>Configuration
As a best practice, name your entries in the OpenStack configuration file taking into account: the application, the project, the domain used for authentication (default, stratuslab…),
the OpenStack instance (test, production…),
and the site operating that instance (virtualdata, gricad…).
the OpenStack instance (test, production…),
and the site operating that instance (virtualdata, gricad…).
clouds:
...
<APPLICATION>.<PROJECT>@<DOMAIN>.<INSTANCE>.<SITE>:
...clouds:
...
<APPLICATION>.<PROJECT>@<DOMAIN>.<INSTANCE>.<SITE>:
auth_type: v3applicationcredential
auth:
auth_url: <AUTH_URL>
application_credential_id: <APPLICATION_CREDENTIAL_ID>
application_credential_secret: <APPLICATION_CREDENTIAL_SECRET>
...Example
clouds:
...
continuous-integration.resinfo-discotech@stratuslab.production.virtualdata:
auth_type: v3applicationcredential
auth:
auth_url: https://keystone.lal.in2p3.fr:5000/v3
application_credential_id: abcdef01234567890abcdef0123456789
application_credential_secret: p868jk_HM_UjtApyp3iuBXkXc8DlmNxK1o7ViC8WEcCKNTFz2FUIZxNybSy3UsV-Iwq6JLC1X0IR45hxkdUdnA
...