Merge "Make keystone_user module fully shade"
This commit is contained in:
commit
1ef8a4895e
@ -14,14 +14,6 @@
|
|||||||
# See the License for the specific language governing permissions and
|
# See the License for the specific language governing permissions and
|
||||||
# limitations under the License.
|
# limitations under the License.
|
||||||
|
|
||||||
# This file is a barebones file needed to file a gap until Ansible 2.0. No
|
|
||||||
# error checking, no deletions, no updates. Idempotent creation only.
|
|
||||||
|
|
||||||
# If you look closely, you will see we arent _really_ using the shade module
|
|
||||||
# we just use it to slightly abstract the authentication model. As patches land
|
|
||||||
# in upstream shade we will be able to use more of the shade module. Until then
|
|
||||||
# if we want to be 'stable' we really need to be using it as a passthrough
|
|
||||||
|
|
||||||
import traceback
|
import traceback
|
||||||
|
|
||||||
import shade
|
import shade
|
||||||
@ -47,35 +39,36 @@ def main():
|
|||||||
role = None
|
role = None
|
||||||
user = None
|
user = None
|
||||||
|
|
||||||
cloud = shade.operator_cloud(**module.params)
|
cloud = shade.OperatorCloud(**module.params)
|
||||||
|
|
||||||
for _project in cloud.keystone_client.projects.list():
|
for _project in cloud.search_projects():
|
||||||
if _project.name == project_name:
|
if _project.name == project_name:
|
||||||
project = _project
|
project = _project
|
||||||
|
|
||||||
for _role in cloud.keystone_client.roles.list():
|
for _role in cloud.search_roles():
|
||||||
if _role.name == role_name:
|
if _role.name == role_name:
|
||||||
role = _role
|
role = _role
|
||||||
|
|
||||||
for _user in cloud.keystone_client.users.list():
|
for _user in cloud.search_users():
|
||||||
if _user.name == user_name:
|
if _user.name == user_name:
|
||||||
user = _user
|
user = _user
|
||||||
|
|
||||||
if not project:
|
if not project:
|
||||||
changed = True
|
changed = True
|
||||||
project = cloud.keystone_client.projects.create(
|
project = cloud.create_project(project_name,
|
||||||
name=project_name, domain='default')
|
domain_id='default')
|
||||||
|
|
||||||
if not role:
|
if not role:
|
||||||
changed = True
|
changed = True
|
||||||
role = cloud.keystone_client.roles.create(name=role_name)
|
role = cloud.create_role(role_name)
|
||||||
|
|
||||||
if not user:
|
if not user:
|
||||||
changed = True
|
changed = True
|
||||||
user = cloud.keystone_client.users.create(name=user_name,
|
user = cloud.create_user(user_name,
|
||||||
password=password,
|
password=password,
|
||||||
project=project)
|
default_project=project,
|
||||||
cloud.keystone_client.roles.grant(role=role,
|
domain_id='default')
|
||||||
|
cloud.grant_role(role,
|
||||||
user=user,
|
user=user,
|
||||||
project=project)
|
project=project)
|
||||||
|
|
||||||
|
Loading…
Reference in New Issue
Block a user