Define services and API endpoints The Identity Service also tracks what OpenStack services are installed and where to locate them on the network. Run these commands for each service in your OpenStack installation: keystone service-create. Describes the service. keystone endpoint-create. Associates API endpoints with the service. For now, create a service for the Identity Service itself that uses normal authentication instead of the authorization token when you run the keystone command in the future. Create a service entry for the Identity Service: # keystone service-create --name=keystone --type=identity \ --description="Keystone Identity Service" +-------------+----------------------------------+ | Property | Value | +-------------+----------------------------------+ | description | Keystone Identity Service | | id | 15c11a23667e427e91bc31335b45f4bd | | name | keystone | | type | identity | +-------------+----------------------------------+ The service ID is randomly generated and is different from the one shown here. Specify an API endpoint for the Identity Service by using the returned service ID. When you specify an endpoint, you provide URLs for the public API, internal API, and admin API. In this guide, the controller host name is used. Note that the Identity Service uses a different port for the admin API. # keystone endpoint-create \ --service-id=the_service_id_above \ --publicurl=http://controller:5000/v2.0 \ --internalurl=http://controller:5000/v2.0 \ --adminurl=http://controller:35357/v2.0 +-------------+-----------------------------------+ | Property | Value | +-------------+-----------------------------------+ | adminurl | http://controller:35357/v2.0 | | id | 11f9c625a3b94a3f8e66bf4e5de2679f | | internalurl | http://controller:5000/v2.0 | | publicurl | http://controller:5000/v2.0 | | region | regionOne | | service_id | 15c11a23667e427e91bc31335b45f4bd | +-------------+-----------------------------------+ As you add other services to your OpenStack installation, call these commands to register the services with the Identity Service.