Ansible deployment of the Kolla containers
Go to file
Ghanshyam Mann 283fa242ca Remove system scope token to access services
As per the RBAC new direction in Zed cycle, we have dropped the
system scope from API policies and all the policies are hardcoded
to project scoped so that any user accessing APIs using system scope
will get 403 error. It is dropped from all the OpenStack services
except for the Ironic service which will have system scope and to
support ironic only deployment, we are keeping system as well as project
scope in Keystone.

Complete discussion and direction can be found in the below gerrit
change and TC goal direction:

- https://review.opendev.org/c/openstack/governance/+/847418
- https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#the-issues-we-are-facing-with-scope-concept

As phase-2 of RBAC goal, services will start enabling the new
defaults and project scope by default. For example: Nova did in
- https://review.opendev.org/c/openstack/nova/+/866218

Kolla who start accessing the services using system scope token
- https://review.opendev.org/c/openstack/kolla-ansible/+/692179

This commit partially revert the above change except keeping
system scope usage for Keystone and Ironic. Rest all services are changed
to use the project scope token.

And enable the scope and new defaults for Nova which was disabled
by https://review.opendev.org/c/openstack/kolla-ansible/+/870804

Change-Id: I0adbe0a6c39e11d7c9542569085fc5d580f26c9d
2023-01-26 17:52:00 -06:00
ansible Remove system scope token to access services 2023-01-26 17:52:00 -06:00
contrib Update docs for Ubuntu 20.04 2020-11-20 08:40:36 +00:00
deploy-guide/source [docs] Unify project's naming convention 2021-01-27 20:08:41 +01:00
doc Remove system scope token to access services 2023-01-26 17:52:00 -06:00
etc/kolla Drop skydive 2023-01-05 14:55:53 +01:00
kolla_ansible Fix Hashi login method for approles 2022-09-02 16:42:15 +01:00
releasenotes Remove system scope token to access services 2023-01-26 17:52:00 -06:00
roles CI: Use nodepool.public_ipv4 if nodepool.private_ipv4 is empty 2023-01-13 13:03:31 +00:00
specs [docs] Unify project's naming convention 2021-01-27 20:08:41 +01:00
tests Merge "Drop skydive" 2023-01-19 10:26:01 +00:00
tools Merge "Integrate oslo-config-validator" 2023-01-03 17:40:00 +00:00
zuul.d Drop remnants of install_type 2023-01-12 15:15:08 +01:00
.ansible-lint Skip ansible-lint fqcn for module actions and role-name 2022-10-12 10:02:52 +02:00
.gitignore Ignore .vscode/ in Git 2020-04-10 15:55:42 +02:00
.gitreview OpenDev Migration Patch 2019-04-19 19:29:02 +00:00
.stestr.conf Add custom filters for checking services 2019-09-16 12:48:52 +00:00
.yamllint Fix CI failures 2019-10-15 13:27:55 +01:00
CONTRIBUTING.rst [Community goal] Update the contributor guide 2020-05-20 17:55:57 +02:00
LICENSE Add ASL license 2014-09-20 17:29:35 -07:00
lint-requirements.txt Bump ansible-lint version to 6.* 2022-04-12 08:56:25 +02:00
README.rst Remove kafka, storm, zookeeper 2022-12-08 06:50:15 +00:00
requirements.txt Use jinja2.pass_context instead of contextfilter 2022-03-24 16:29:26 +00:00
requirements.yml Install openstack.kolla collection 2022-02-21 14:26:48 +00:00
setup.cfg ovs-dpdk: add ovs-dpdkctl.sh to the role itself 2022-04-13 15:42:57 +00:00
setup.py Cleanup py27 support 2020-04-26 12:16:44 +02:00
test-requirements.txt Move lint requirements to dedicated file 2022-04-12 08:45:16 +02:00
tox.ini CI: Support tox4 2022-12-28 10:13:03 +00:00

Kolla Ansible

image

The Kolla Ansible is a deliverable project separated from Kolla project.

Kolla Ansible deploys OpenStack services and infrastructure components in Docker containers.

Kolla's mission statement is:

To provide production-ready containers and deployment tools for operating
OpenStack clouds.

Kolla is highly opinionated out of the box, but allows for complete customization. This permits operators with little experience to deploy OpenStack quickly and as experience grows modify the OpenStack configuration to suit the operator's exact requirements.

Getting Started

Learn about Kolla Ansible by reading the documentation online Kolla Ansible.

Get started by reading the Developer Quickstart.

OpenStack services

Kolla Ansible deploys containers for the following OpenStack projects:

Infrastructure components

Kolla Ansible deploys containers for the following infrastructure components:

Directories

  • ansible - Contains Ansible playbooks to deploy OpenStack services and infrastructure components in Docker containers.
  • contrib - Contains demos scenarios for Heat, Magnum and Tacker and a development environment for Vagrant
  • doc - Contains documentation.
  • etc - Contains a reference etc directory structure which requires configuration of a small number of configuration variables to achieve a working All-in-One (AIO) deployment.
  • kolla_ansible - Contains password generation script.
  • releasenotes - Contains releasenote of all features added in Kolla Ansible.
  • specs - Contains the Kolla Ansible communities key arguments about architectural shifts in the code base.
  • tests - Contains functional testing tools.
  • tools - Contains tools for interacting with Kolla Ansible.
  • zuul.d - Contains project gate job definitions.

Getting Involved

Need a feature? Find a bug? Let us know! Contributions are much appreciated and should follow the standard Gerrit workflow.

  • We communicate using the #openstack-kolla irc channel.
  • File bugs, blueprints, track releases, etc on Launchpad.
  • Attend weekly meetings.
  • Contribute code.

Contributors

Check out who's contributing code and contributing reviews.

Notices

Docker and the Docker logo are trademarks or registered trademarks of Docker, Inc. in the United States and/or other countries. Docker, Inc. and other parties may also have trademark rights in other terms used herein.