OpenStack Identity (Keystone)
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

4.1 KiB

Installing Keystone

This document describes how to install Keystone in order to use it. If you are intending to develop on or with Keystone, please read developing and setup.

Installing from Source

The source install instructions specifically avoid using platform specific packages, instead using the source for the code and the Python Package Index (PyPi).

It's expected that your system already has python, pip, and git available.

Clone the Keystone repository:

$ git clone
$ cd keystone

Install the Keystone web service:

$ python install

You should have all the pieces you need to run Keystone installed on your system. The following commands should be available on the command-line path:

  • keystone the Keystone client, used to interact with Keystone
  • keystone-manage used to bootstrap Keystone data
  • keystone-all used to run the Keystone services

You will find sample configuration files in etc/:

  • keystone.conf
  • keystone-paste.ini
  • logging.conf
  • policy.json
  • default_catalog.templates

From here, refer to configuration to choose which backend drivers to enable and use. Once configured, you should be able to run Keystone by issuing the command:

$ keystone-all

By default, this will show logging on the console from which it was started. Once started, you can initialize data in Keystone for use with the rest of OpenStack, as described in configuringservices.

An excellent reference implementation of setting up Keystone is DEVSTACK, most commonly used for development and testing setup of not only Keystone, but all of the core OpenStack projects.

The script with the latest examples of initializing data in Keystone is a bash script called lib/keystone

Installing from packages: Ubuntu

Ubuntu is providing packages for Keystone for Precise. To install keystone on Ubuntu:

$ sudo apt-get install keystone

In using Ubuntu's packages, the packages will set up a user account for the Keystone service (keystone), and place default configurations in /etc/keystone. The Debian installer will also ask you about configuration options for setting up and running Keystone. As of this writing, the defaults for Keystone backends are all SQL based, stored locally in a SQLite.

Once installed, you still need to initialize data in Keystone, which you can find described in configuringservices.

Installing from packages: Fedora

To install Keystone on Fedora refer to the steps found in the OpenStack Install Guide.

To install the packages:

$ sudo yum install openstack-keystone

Once installed, you still need to initialize data in Keystone, which you can find described in configuringservices.