Keystone-manage bootstrap can't bootstrap domains other than default
Bug #1593542 reported by
Shawn Berger
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Identity (keystone) |
Opinion
|
Undecided
|
Shawn Berger |
Bug Description
When using keystone-manage bootstrap, you can't define the domain that you want to bootstrap. It will always work with default. The problem is this doesn't help with a multi-domain environment. An admin user defined in the default domain doesn't have any permissions in other domains. Once a new domain is created a different admin user specific to that domain would need to be created in order to be able to act within it.
If the keystone-manage bootstrap utility could allow bootstrapping of non-default domains then it could facilitate the administration of larger, multi-domain cloud environments without the security concern that arises from the older admin_token method.
Changed in keystone: | |
assignee: | nobody → Shawn Berger (slberger) |
To post a comment you must log in.
Are you looking to put the admin project in a different domain or are you looking to have the bootstrap process grant the admin user a role on a domain?