settingsLogin | Registersettings


Recent questions tagged _member_

0 votes
2 responses 8 views

Hi list, As I understand, keystone only defined two roles: - admin - non-admin, but can be any role name you want, role1, role2, user, _member_, whatever say there are quite few people in the same project, so far, the users assigned with ...

asked Oct 21, 2017 in openstack by Chengwei_Yang (180 points)  
2 x  
0 votes
27 responses 23 views

In the past year or so, has there been anything that made you think “I wish the TC would do something about that!” ? If so, what was it, and what would you have wanted the TC to do about it? -- Ed Leafe ...

asked Oct 13, 2017 in openstack-dev by Ed_Leafe (11,720 points)   1 3 6
3 x  
0 votes
7 responses 599 views

Hi, I am running OpenStack Ocata that as originally provisioned using RDO Packstack. I currently have Keystone configured to use a single identity backend which is LDAP. Everything works great with this configuration except Heat and Magnum. ...

asked Jul 27, 2017 in openstack by Tristan_Evans (280 points)   1 1 1
0 votes
0 responses 561 views

Hello all, I'm currently having a issue whereby I'm unable to login with horizon even after logs show that authentication was successful. I am able to use the command line successfully without issue. In my troubleshooting I've tried to ...

asked Jul 12, 2017 in openstack by Casey_Richins (120 points)   1 1 1
0 votes
0 responses 56 views

Trying to figure out if this is a bug in ECP support within novaclient, or if I am misconfiguring something. Any feedback helps! We have keystone configured to use a separate Shibboleth server for auth (with an ECP endpoint). Federated ...

asked May 1, 2017 in openstack-operators by Evan_Bollig_PhD (400 points)   2
0 votes
3 responses 4 views

Hi, Apologies if this questions has been answered already, or is in some doc somewhere. Please point me in the right direction of so. I'm upgrading openstack from Juno to Mitaka, in steps. We role our own openstack using puppet, and have ...

asked Nov 9, 2016 in openstack-operators by Justin_Cattle (620 points)   1 2
0 votes
0 responses 339 views

We are delighted to announce the release of: kolla 3.0.0: Kolla OpenStack Deployment This release is part of the newton release series. Download the package from: For more details, please see below. ...

asked Oct 20, 2016 in openstack-announce by no-reply_at_openstac (33,960 points)   2 14 30
0 votes
0 responses 61 views

We are high-spirited to announce the release of: instack-undercloud 5.0.0: instack-undercloud This release is part of the newton release series. The source is available from: ...

asked Oct 20, 2016 in openstack-announce by no-reply_at_openstac (33,960 points)   2 14 30
0 votes
0 responses 19 views

Hello everyone, When trying to run the next test: TestNetworkBasicOps.test_connectivity_between_vms_on_different_networks, from the devstack server itself, it passes, but when trying to run it from another server. i.e. by changing the *uri ...

asked Oct 20, 2016 in openstack-dev by Yossi_Tamarov (180 points)  
0 votes
0 responses 21 views from keystoneclient.v2_0.client ...

asked Sep 14, 2016 in openstack-operators by Lee_Ho_Yeung (140 points)  
0 votes
0 responses 11 views

i have already set insecure but still got error >>> nc.quotas.update(, floating_ips=1) Traceback (most recent call last): File "", line 1, in File "/usr/lib/python2.7/dist-packages/novaclient/v1_1/", line 61, in update ...

asked Aug 29, 2016 in openstack-operators by Lee_Ho_Yeung (140 points)  
0 votes
2 responses 356 views

Has anyone been able to successfully integrate the S3 api with Swift? I'm working on this in my lab, and finding a number of issues: 1) I've found that when I enable the S3 API, my swift proxy doesn't bind to it's port. I'm guessing that ...

asked Aug 19, 2016 in openstack by John_van_Ommen (1,100 points)   1 1
0 votes
5 responses 564 views

Hi, I’m having a bit of fun try to use AD for identifying and authorising Users on Openstack . The idea is to use AD for read-only access to users/group definitions, but all authorisation data to be stored in SQL. What works: Users can be ...

asked Aug 2, 2016 in openstack by Sean.Boran_at_swissc (340 points)   1 1 1
0 votes
8 responses 2 views

Hey folks, In Kolla we have a significant bug in that Horizon can't be used because it requires a member user. We have a few approaches to fixing this problem in mind, but want to understand what Operators want. Devstack itself has switched ...

asked Jul 30, 2016 in openstack-operators by Steven_Dake_(stdake) (24,540 points)   2 10 23
0 votes
2 responses 22 views

Hi! As an OIDC user, tried to play with Heat and Murano recently. They usually fail with a trust creation error, noticing that keystone cannot find the _member_ role while creating the trust. Since a federated user is not really have a role ...

asked Jun 7, 2016 in openstack-dev by Gyorgy_Szombathelyi (1,580 points)   1 4
0 votes
5 responses 20 views

Hi testing Openstack Mitaka (deployed with Mirantis FUEL 8.0), when testing Heat Autoscaling, I get this error: /heat.engine.resource Forbidden: You are not authorized to perform the requested action./ Any ideas on what's going on? Thanks ...

asked May 10, 2016 in openstack by Ja._CA. (1,100 points)   3 5
0 votes
2 responses 24 views

Hi all, Is anyone using granular roles or groups, with fewer permissions granted than _member_ ? If so, have you found a nice, simple (within the context of OpenStack) method or scheme for:- a) modifying the default "admin_or_owner" rules, ...

asked Feb 3, 2016 in openstack-operators by Michael_Richardson (240 points)  
0 votes
0 responses 122 views

Hi all, I'm a total newbie to openstack, and I'm trying to install a testing environment to study it. I installed Openstack Juno on CentOS 7 following "Openstack Installation Guide for Red Hat 7, CentOS 7 and Fedora 20" - I'm working on ...

asked Oct 31, 2015 in openstack by Marco_Antonio_Carcan (120 points)   1 1
0 votes
4 responses 5 views 1. Add a config value ADMIN_PROJECT_ID 2. In token creation, if ADMIN_PROJECT_ID is not None: only add the admin role to the token if the id of the scoped project == ...

asked Oct 11, 2015 in openstack-dev by Adam_Young (19,940 points)   2 7 9
0 votes
1 response 282 views

i have a user whose role was "_member_ "later changed to "heat_stack_user" and again changed to "_member_" but now the user is not able to do any heat commands as it returns "ERROR: You are not authorized to complete this action". for heat ...

asked Aug 27, 2015 in openstack by kevin_parrikar (600 points)   4 9