Sign inSign up

denbicloud/perunkeystoneadapter

By denbicloud

•Updated over 7 years ago

Image
0

446

denbicloud/perunkeystoneadapter repository overview

Documentation Status

⁠Perun Keystone Adapter

The Perun Keystone Adapter is a library written in Python that parses data propagated by Perun⁠ and modifies a connected Openstack⁠ Keystone⁠.

⁠Features

  • abstract keystone to simplify often used tasks (create/delete/update/list users and projects)
  • parse SCIM or de.NBI portal compute center propagation data for users and projects
  • modify Keystone according the propagated data:
  • creates items (users or projects) in Keystone if they not exists but propagated
  • modify items properties if they changed
  • mark items as deleted and disable them in Keystone if they are not propagated any more
  • deleting (marked and disabled) items functionality is available but not integrated in the normal workflow.
  • set/modify project quotas (needs a full openstack installation like DevStack⁠ for testing)
  • compatible with python 2.7.x and python 3

⁠Preparation

Before installing Perun Keystone Adapter you must be sure that used openstack domain for propagation is empty or all existing projects and users that also exists in perun must be tagged to avoid naming conflicts and the project names must have the same names as the groups in perun. By default everything created by the library is tagged as perun_propagation. This can be overwritten in the constructor of the KeyStone class.

As a help there are two scripts included in the assets directory of this repository that set a flag of your choice for a user and for a project.

  1. First install all necessary dependencies (maybe in your virtual environment) by running

    $ pip install -r requirements.txt
    
  2. The scripts expect that you sourced your OpenStack rc file:

    $ source env.rc
    
  3. Run the python script

    $ python set_project_flag.py  project_id flag_name
    

    or

    $ python set_user_flag.py  user_id flag_name
    

    where

    • user_id and project_id are OpenStack specific IDs
    • flag_name can be any value which is set for the flag attribute. If you do not modify the perunKeystoneAdapter, it expects perun_propagation as the value.

⁠Installation

Install a specific version of this library by providing a tag of the releases page⁠:

E.g: for version 0.1.1:

pip install git+https://github.com/deNBI/[email protected]

⁠Usage

⁠Commandline client

The perun propagation service transfers a zipped tar file containing a users and groups file in scim format. The following script unzips and untars the propagated information and adds it to the keystone database. Keystone is addressed by environment variables (sourcing the openstack rc file) or directly by passing an environemt map (not used in the example). The Openstack user needs at least permission to modify entries in Keystone

$ perun_propagation perun_upload.tar.gz
⁠WSGI script

The python module also contains a built-in server version of the perun_propagation script. The script uses flask⁠ to provide an upload function and run library functions in a separate thread. It can be simply tested starting the flask built-in webserver.

$ perun_propagation_service
 * Serving Flask app "denbi.scripts.perun_propagation_service" (lazy loading)
 * Environment: production
   WARNING: Do not use the development server in a production environment.
   Use a production WSGI server instead.
 * Debug mode: off
 * Running on http://127.0.0.1:5000/ (Press CTRL+C to quit)

For running this in production it is easy to use gunicorn as follows:

$ gunicorn --workers 1 --bind 127.0.0.1:5000 denbi.scripts.perun_propagation_service:app

There are additional deployment options available⁠ if you prefer to run WSGI applications with Apache, or other setups.

⁠Development

⁠Unit tests

The library comes with a set of unit tests - a full functional keystone is required to perfom all tests.

For testing the user/project management only a running keystone is enough. The Makefile included with the project runs a docker container for providing a keystone server.

In every case it is not recommended to use your production keystone/setup .

⁠Linting
$ make lint

will run flake8 on the source code directories.

Tag summary

Content type

Image

Digest

Size

141.9 MB

Last updated

over 7 years ago

docker pull denbicloud/perunkeystoneadapter