Skip to content
Application Credentials

Application Credentials

It is strongly recommended to create an OpenStack application credential and avoid storing your personal credentials on disk.
An OpenStack application credential has at most:

  • the permissions of the account for which it was created,
  • only within the scope of the project in which it was created.
    Using application credentials is therefore important for restricting the scope of our actions.

Creation

usage: openstack application credential create
  [-h] [-f {json,shell,table,value,yaml}] [-c COLUMN] [--noindent]
  [--prefix PREFIX] [--max-width <integer>] [--fit-width] [--print-empty]
  [--secret <secret>] [--role <role>] [--expiration <expiration>]
  [--description <description>] [--unrestricted] [--restricted]
  [--access-rules <access-rules>]
  <name>

Configuration

As a best practice, name your entries in the OpenStack configuration file taking into account: the application, the project, the domain used for authentication (default, stratuslab…),
the OpenStack instance (test, production…),
and the site operating that instance (virtualdata, gricad…).
clouds:
...
  <APPLICATION>.<PROJECT>@<DOMAIN>.<INSTANCE>.<SITE>:
...
clouds:
...
  <APPLICATION>.<PROJECT>@<DOMAIN>.<INSTANCE>.<SITE>:
    auth_type: v3applicationcredential
    auth:
       auth_url: <AUTH_URL>
       application_credential_id: <APPLICATION_CREDENTIAL_ID>
       application_credential_secret: <APPLICATION_CREDENTIAL_SECRET>
...

Example

clouds:
...
  continuous-integration.resinfo-discotech@stratuslab.production.virtualdata:
    auth_type: v3applicationcredential
    auth:
      auth_url: https://keystone.lal.in2p3.fr:5000/v3
      application_credential_id: abcdef01234567890abcdef0123456789
      application_credential_secret: p868jk_HM_UjtApyp3iuBXkXc8DlmNxK1o7ViC8WEcCKNTFz2FUIZxNybSy3UsV-Iwq6JLC1X0IR45hxkdUdnA
...