openstack-ansible/playbooks/roles
Jesse Pretorius 54808a7802 Implement multi-domain LDAP configuration for Keystone
This patch changes the keystone_ldap configuration to allow multiple
LDAP identity back-end configurations to be implemented.

Example implementation in user_variables.yml:

keystone_ldap:
  Users:
    url: "ldap://10.10.10.10"
    user: "root"
    password: "secrete"
    ...
  Admins:
    url: "ldap://20.20.20.20"
    user: "root"
    password: "secrete"
    ...

This will place two configuration files into /etc/keystone/domains/,
both of which will be configured to use the LDAP driver.

 - keystone.Users.conf
 - keystone.Admins.conf

Each first level key entry is a domain name. Each entry below that
are key-value pairs for the 'ldap' section in the configuration
file.

Note that the reason why only LDAP is catered for is due to the fact
that LDAP is the only supported driver in OpenStack for
Domain-specific configuration files.

Also the reason that only the identity back-end is catered for is that
the LDAP driver for the role, resource and assignment back-ends have
been deprecated and are scheduled for removal in Mitaka.

UpgradeImpact:

- keystone_ldap's first key tier is now the domain name.
  An existing keystone_ldap configuration entry can be converted by
  renaming the 'ldap' key to the domain name 'Default'.
  **Note** that the domain name entry is case-sensitive.

- keystone_ldap_identity_driver has been removed, as the driver
  for ldap is now simply 'ldap' and there are no other back-end
  options for Keystone at this time.

Change-Id: Ifa4c42f7dbcc40a256a3156f74f0150384f9ab87
2016-01-26 13:08:57 +00:00
..
ceph_client Update ceph repo 2016-01-21 21:47:57 +08:00
haproxy_server Allow sourcing apt_key from ansible host 2016-01-14 12:46:57 -06:00
openstack_openrc Implement OpenStack client clouds.yml configuration file 2015-12-15 20:47:43 -06:00
os_aodh Update Master SHAs - 17 Jan 2016 2016-01-18 23:58:48 +00:00
os_ceilometer Update Ceilometer paste file 2016-01-22 09:44:18 +00:00
os_cinder Use http request to check cinder api availability 2016-01-25 11:04:03 +00:00
os_glance Update Master SHAs - 17 Jan 2016 2016-01-18 23:58:48 +00:00
os_heat Update Master SHAs - 17 Jan 2016 2016-01-18 23:58:48 +00:00
os_horizon Re-deploy the Horizon venv if it mismatches the repo 2016-01-19 16:53:39 +00:00
os_keystone Implement multi-domain LDAP configuration for Keystone 2016-01-26 13:08:57 +00:00
os_neutron Add ECMP support config for PGLib 2016-01-25 15:14:30 +00:00
os_nova Use slurp to collect the nova ssh keys 2016-01-26 09:36:38 +00:00
os_swift Merge "Add statsd configuration for swift" 2016-01-15 08:11:21 +00:00
os_swift_sync Fix os_swift_sync role's set_weight 2016-01-08 14:18:51 +00:00
os_tempest Update Master SHAs - 17 Jan 2016 2016-01-18 23:58:48 +00:00
repo_build Re-deploy the Horizon venv if it mismatches the repo 2016-01-19 16:53:39 +00:00
system_crontab_coordination Add role system-crontab-coordination 2015-06-30 10:06:11 +01:00