Configuration Reference

Complete listing of all configuration options for the Shared File Systems service (manila), auto-generated from the source code.

DEFAULT

osapi_max_limit
Type:

integer

Default:

1000

The maximum number of items returned in a single response from a collection resource.

osapi_share_base_URL
Type:

string

Default:

<None>

Base URL to be presented to users in links to the Share API

use_forwarded_for
Type:

boolean

Default:

False

Treat X-Forwarded-For as the canonical remote address. Only enable this if you have a sanitizing proxy.

Warning

This option is deprecated for removal since Zed. Its value may be silently ignored in the future.

Reason:

This feature is duplicate of the HTTPProxyToWSGI middleware of oslo.middleware.

state_path
Type:

string

Default:

/var/lib/manila

Top-level directory for maintaining manila’s state.

my_ip
Type:

host address

Default:

<your_ip>

This option has a sample default set, which means that its actual default value may vary from the one documented above.

IP address of this host.

scheduler_topic
Type:

string

Default:

manila-scheduler

The topic scheduler nodes listen on.

share_topic
Type:

string

Default:

manila-share

The topic share nodes listen on.

data_topic
Type:

string

Default:

manila-data

The topic data nodes listen on.

api_rate_limit
Type:

boolean

Default:

True

Whether to rate limit the API.

osapi_share_ext_list
Type:

list

Default:

[]

Specify list of extensions to load when using osapi_share_extension option with manila.api.contrib.select_extensions.

osapi_share_extension
Type:

list

Default:

['manila.api.contrib.standard_extensions']

The osapi share extensions to load.

scheduler_manager
Type:

string

Default:

manila.scheduler.manager.SchedulerManager

Full class name for the scheduler manager.

share_manager
Type:

string

Default:

manila.share.manager.ShareManager

Full class name for the share manager.

data_manager
Type:

string

Default:

manila.data.manager.DataManager

Full class name for the data manager.

host
Type:

host address

Default:

<your_hostname>

This option has a sample default set, which means that its actual default value may vary from the one documented above.

Name of this node. This can be an opaque identifier. It is not necessarily a hostname, FQDN, or IP address.

storage_availability_zone
Type:

string

Default:

nova

Availability zone of this node.

default_share_type
Type:

string

Default:

<None>

Default share type to use.

default_share_group_type
Type:

string

Default:

<None>

Default share group type to use.

rootwrap_config
Type:

string

Default:

<None>

Path to the rootwrap configuration file to use for running commands as root.

monkey_patch
Type:

boolean

Default:

False

Whether to log monkey patching.

monkey_patch_modules
Type:

list

Default:

[]

List of modules or decorators to monkey patch.

service_down_time
Type:

integer

Default:

60

Maximum time since last check-in for up service.

share_api_class
Type:

string

Default:

manila.share.api.API

The full class name of the share API class to use.

auth_strategy
Type:

string

Default:

keystone

Valid Values:

noauth, noauthv2, keystone

The strategy to use for auth.

enabled_share_backends
Type:

list

Default:

<None>

A list of share backend names to use. These backend names should be backed by a unique [CONFIG] group with its options.

enabled_share_protocols
Type:

list

Default:

['NFS', 'CIFS']

Specify list of protocols to be allowed for share creation.

soft_deleted_share_retention_time
Type:

integer

Default:

604800

Maximum time (in seconds) to keep a share in the recycle bin, it will be deleted automatically after this amount of time has elapsed.

transfer_retention_time
Type:

integer

Default:

300

Maximum time (in seconds) to keep a share in awaiting_transfer state, after timeout, the share will automatically be rolled back to the available state

admin_only_metadata
Type:

list

Default:

['__affinity_same_host', '__affinity_different_host', '__managed_at']

Metadata keys that should only be manipulated by administrators.

driver_updatable_metadata
Type:

list

Default:

[]

Metadata keys that will decide which share metadata (element of the list is <driver_updatable_key>, i.e max_files) can be passed to share drivers as part of metadata create/update operations.

driver_updatable_subnet_metadata
Type:

list

Default:

[]

Metadata keys that will decide which share network subnet metadata (element of the list is <driver_updatable_key>, e.g. pnfs) can be passed to share drivers as part of metadata create/update operations.

update_shares_status_on_ensure
Type:

boolean

Default:

True

Whether Manila should update the status of all shares within a backend during ongoing ensure_shares run.

admin_only_el_metadata
Type:

list

Default:

['preferred']

Metadata keys for export locations that should only be manipulated by administrators.

data_manager_backup_supported_share_protocols
Type:

list

Default:

['NFS']

Specify list of protocols to be allowed for share backup creation when using either the data manager generic backup approach, or another backup driver that makes use of the data manager service.

compute_api_class
Type:

string

Default:

manila.compute.nova.API

The full class name of the Compute API class to use.

backend_url
Type:

string

Default:

file://$state_path

The back end URL to use for distributed coordination.

backup_mount_template
Type:

string

Default:

mount -vt %(proto)s %(options)s %(export)s %(path)s

The template for mounting NFS shares.

backup_unmount_template
Type:

string

Default:

umount -v %(path)s

The template for unmounting NFS shares.

backup_mount_export
Type:

string

Default:

<None>

NFS backup export location in hostname:path, ipv4addr:path, or “[ipv6addr]:path” format.

backup_mount_proto
Type:

string

Default:

nfs

Mount Protocol for mounting NFS shares

backup_mount_options
Type:

string

Default:

''

Mount options passed to the NFS client. See NFS man page for details.

data_access_wait_access_rules_timeout
Type:

integer

Default:

180

Time to wait for access rules to be allowed/denied on backends when migrating a share (seconds).

data_node_access_ips
Type:

list

Default:

[]

A list of the IPs of the node interface connected to the admin network. Used for allowing access to the mounting shares. Default is [].

data_node_access_cert
Type:

string

Default:

<None>

The certificate installed in the data node in order to allow access to certificate authentication-based shares.

data_node_access_admin_user
Type:

string

Default:

<None>

The admin user name registered in the security service in order to allow access to user authentication-based shares.

data_node_mount_options
Type:

dict

Default:

{}

Mount options to be included in the mount command for share protocols. Use dictionary format, example: {‘nfs’: ‘-o nfsvers=3’, ‘cifs’: ‘-o user=foo,pass=bar’}

backup_driver
Type:

string

Default:

manila.data.drivers.nfs.NFSBackupDriver

Driver to use for backups.

backup_share_mount_template
Type:

string

Default:

mount -vt %(proto)s %(options)s %(export)s %(path)s

The template for mounting shares during backup. Must specify the executable with all necessary parameters for the protocol supported. ‘proto’ template element may not be required if included in the command. ‘export’ and ‘path’ template elements are required. It is advisable to separate different commands per backend.

backup_share_unmount_template
Type:

string

Default:

umount -v %(path)s

The template for unmounting shares during backup. Must specify the executable with all necessary parameters for the protocol supported. ‘path’ template element is required. It is advisable to separate different commands per backend.

backup_ignore_files
Type:

list

Default:

['lost+found']

List of files and folders to be ignored when backing up shares. Items should be names (not including any path).

backup_protocol_access_mapping
Type:

dict value

Default:

{'ip': ['nfs']}

Protocol access mapping for backup. Should be a dictionary comprised of {‘access_type1’: [‘share_proto1’, ‘share_proto2’], ‘access_type2’: [‘share_proto2’, ‘share_proto3’]}.

mount_tmp_location
Type:

string

Default:

/tmp/

Temporary path to create and mount shares during migration.

backup_mount_tmp_location
Type:

string

Default:

/tmp/

Temporary path to create and mount backup during share backup.

check_hash
Type:

boolean

Default:

False

Chooses whether hash of each file should be checked on data copying.

backup_continue_update_interval
Type:

integer

Default:

10

This value, specified in seconds, determines how often the data manager will poll to perform the next steps of backup such as fetch the progress of backup.

restore_continue_update_interval
Type:

integer

Default:

10

This value, specified in seconds, determines how often the data manager will poll to perform the next steps of restore such as fetch the progress of restore.

db_backend
Type:

string

Default:

sqlalchemy

The backend to use for database.

enable_new_services
Type:

boolean

Default:

True

Services to be added to the available pool on create.

share_name_template
Type:

string

Default:

share-%s

Template string to be used to generate share names.

share_snapshot_name_template
Type:

string

Default:

share-snapshot-%s

Template string to be used to generate share snapshot names.

share_backup_name_template
Type:

string

Default:

share-backup-%s

Template string to be used to generate backup names.

db_driver
Type:

string

Default:

manila.db

Driver to use for database access.

fatal_exception_format_errors
Type:

boolean

Default:

False

Whether to make exception message format errors fatal.

image_api_class
Type:

string

Default:

manila.image.glance.API

The full class name of the Glance API class to use.

message_ttl
Type:

integer

Default:

2592000

Message minimum life in seconds.

message_reap_interval
Type:

integer

Default:

86400

Interval between periodic task runs to clean expired messages in seconds.

ovs_integration_bridge
Type:

string

Default:

br-int

Name of Open vSwitch bridge to use.

network_api_class
Type:

string

Default:

manila.network.neutron.neutron_network_plugin.NeutronNetworkPlugin

The full class name of the Networking API class to use.

network_plugin_ipv4_enabled
Type:

boolean

Default:

True

Whether to support IPv4 network resource, Default=True.

network_plugin_ipv6_enabled
Type:

boolean

Default:

False

Whether to support IPv6 network resource, Default=False. If this option is True, the value of ‘network_plugin_ipv4_enabled’ will be ignored.

neutron_physical_net_name
Type:

string

Default:

<None>

The name of the physical network to determine which net segment is used. This opt is optional and will only be used for networks configured with multiple segments.

neutron_net_id
Type:

string

Default:

<None>

Default Neutron network that will be used for share server creation. This opt is used only with class ‘NeutronSingleNetworkPlugin’.

neutron_subnet_id
Type:

string

Default:

<None>

Default Neutron subnet that will be used for share server creation. Should be assigned to network defined in opt ‘neutron_net_id’. This opt is used only with class ‘NeutronSingleNetworkPlugin’.

neutron_vnic_type
Type:

string

Default:

baremetal

Valid Values:

baremetal, normal, direct, direct-physical, macvtap

vNIC type used for binding.

neutron_host_id
Type:

string

Default:

<HOSTNAME>

This option has a sample default set, which means that its actual default value may vary from the one documented above.

Host ID to be used when creating neutron port. If not set host is set to manila-share host by default.

neutron_binding_profiles
Type:

list

Default:

<None>

A list of binding profiles to be used during port binding. This option can be used with the NeutronBindNetworkPlugin. The value for this option has to be a comma separated list of names that correspond to each binding profile. Each binding profile needs to be specified as an individual configuration section using the binding profile name as the section name.

neutron_switch_id
Type:

string

Default:

<None>

Switch ID for binding profile.

neutron_port_id
Type:

string

Default:

<None>

Port ID on the given switch.

neutron_switch_info
Type:

dict

Default:

<None>

Switch label. For example: ‘switch_ip: 10.4.30.5’. Multiple key-value pairs separated by commas are accepted.

standalone_network_plugin_gateway
Type:

string

Default:

<None>

Gateway address that should be used. Required.

standalone_network_plugin_mask
Type:

string

Default:

<None>

Network mask that will be used. Can be either decimal like ‘24’ or binary like ‘255.255.255.0’. Required.

standalone_network_plugin_network_type
Type:

string

Default:

<None>

Valid Values:

flat, vlan, vxlan, gre

Network type, such as ‘flat’, ‘vlan’, ‘vxlan’ or ‘gre’. Empty value is alias for ‘flat’. It will be assigned to share-network and share drivers will be able to use this for network interfaces within provisioned share servers. Optional.

standalone_network_plugin_segmentation_id
Type:

integer

Default:

<None>

Set it if network has segmentation (VLAN, VXLAN, etc…). It will be assigned to share-network and share drivers will be able to use this for network interfaces within provisioned share servers. Optional. Example: 1001

standalone_network_plugin_allowed_ip_ranges
Type:

list

Default:

<None>

Can be IP address, range of IP addresses or list of addresses or ranges. Contains addresses from IP network that are allowed to be used. If empty, then will be assumed that all host addresses from network can be used. Optional. Examples: 10.0.0.10 or 10.0.0.10-10.0.0.20 or 10.0.0.10-10.0.0.20,10.0.0.30-10.0.0.40,10.0.0.50

standalone_network_plugin_mtu
Type:

integer

Default:

1500

Maximum Transmission Unit (MTU) value of the network. Default value is 1500.

scheduler_host_manager
Type:

string

Default:

manila.scheduler.host_manager.HostManager

The scheduler host manager class to use.

scheduler_max_attempts
Type:

integer

Default:

3

Maximum number of attempts to schedule a share.

scheduler_default_filters
Type:

list

Default:

['OnlyHostFilter', 'AvailabilityZoneFilter', 'CapacityFilter', 'CapabilitiesFilter', 'DriverFilter', 'ShareReplicationFilter', 'CreateFromSnapshotFilter', 'AffinityFilter', 'AntiAffinityFilter']

Which filter class names to use for filtering hosts when not specified in the request.

scheduler_default_weighers
Type:

list

Default:

['CapacityWeigher', 'GoodnessWeigher', 'HostAffinityWeigher']

Which weigher class names to use for weighing hosts.

scheduler_default_share_group_filters
Type:

list

Default:

['AvailabilityZoneFilter', 'ConsistentSnapshotFilter']

Which filter class names to use for filtering hosts creating share group when not specified in the request.

scheduler_default_extend_filters
Type:

list

Default:

['CapacityFilter', 'DriverFilter']

Which filter class names to use for filtering hosts extending share when not specified in the request.

scheduler_driver
Type:

string

Default:

manila.scheduler.drivers.filter.FilterScheduler

Default scheduler driver to use.

scheduler_json_config_location
Type:

string

Default:

''

Absolute path to scheduler configuration JSON file.

max_gigabytes
Type:

integer

Default:

10000

Maximum number of volume gigabytes to allow per host.

capacity_weight_multiplier
Type:

floating point

Default:

1.0

Multiplier used for weighing share capacity. Negative numbers mean to stack vs spread.

pool_weight_multiplier
Type:

floating point

Default:

1.0

Multiplier used for weighing pools which have existing share servers. Negative numbers mean to spread vs stack.

report_interval
Type:

integer

Default:

10

Seconds between nodes reporting state to datastore.

cleanup_interval
Type:

integer

Default:

1800

Minimum Value:

300

Seconds between cleaning up the stopped nodes.

periodic_interval
Type:

integer

Default:

60

Seconds between running periodic tasks.

periodic_fuzzy_delay
Type:

integer

Default:

60

Range of seconds to randomly delay when starting the periodic task scheduler to reduce stampeding. (Disable by setting to 0)

osapi_share_listen
Type:

host address

Default:

::

IP address for OpenStack Share API to listen on.

osapi_share_listen_port
Type:

port number

Default:

8786

Minimum Value:

0

Maximum Value:

65535

Port for OpenStack Share API to listen on.

osapi_share_workers
Type:

integer

Default:

1

Number of workers for OpenStack Share API service.

osapi_share_use_ssl
Type:

boolean

Default:

False

Wraps the socket in a SSL context if True is set. A certificate file and key file must be specified.

use_scheduler_creating_share_from_snapshot
Type:

boolean

Default:

False

If set to False, then share creation from snapshot will be performed on the same host. If set to True, then scheduler will be used.When enabling this option make sure that filter CreateFromSnapshotFilter is enabled and to have hosts reporting replication_domain option.

default_mount_point_prefix
Type:

string

Default:

{project_id}_

Default prefix that will be used if none is providedthrough share_type extra specs. Prefix will only beused if share_type support mount_point_name.

is_deferred_deletion_enabled
Type:

boolean

Default:

False

Whether to delete shares and share snapshots in a deferred manner. Setting this option to True will cause quotas to be released immediately if a deletion request is accepted. Deletions may eventually fail, and rectifying them will require manual intervention.

ganesha_config_dir
Type:

string

Default:

/etc/ganesha

Directory where Ganesha config files are stored.

ganesha_config_path
Type:

string

Default:

$ganesha_config_dir/ganesha.conf

Path to main Ganesha config file.

ganesha_service_name
Type:

string

Default:

ganesha.nfsd

Name of the ganesha nfs service.

ganesha_db_path
Type:

string

Default:

$state_path/manila-ganesha.db

Location of Ganesha database file. (Ganesha module only.)

ganesha_export_dir
Type:

string

Default:

$ganesha_config_dir/export.d

Path to directory containing Ganesha export configuration. (Ganesha module only.)

ganesha_export_template_dir
Type:

string

Default:

/etc/manila/ganesha-export-templ.d

Path to directory containing Ganesha export block templates. (Ganesha module only.)

ganesha_rados_store_enable
Type:

boolean

Default:

False

Persist Ganesha exports and export counter in Ceph RADOS objects, highly available storage.

ganesha_rados_store_pool_name
Type:

string

Default:

<None>

Name of the Ceph RADOS pool to store Ganesha exports and export counter.

ganesha_rados_export_counter
Type:

string

Default:

ganesha-export-counter

Name of the Ceph RADOS object used as the Ganesha export counter.

ganesha_rados_export_index
Type:

string

Default:

ganesha-export-index

Name of the Ceph RADOS object used to store a list of the export RADOS object URLS.

num_shell_tries
Type:

integer

Default:

3

Number of times to attempt to run flakey shell commands.

reserved_share_percentage
Type:

integer

Default:

0

The percentage of backend capacity reserved. Used for shares which are not created from the snapshot.

reserved_share_from_snapshot_percentage
Type:

integer

Default:

0

The percentage of backend capacity reserved. Used for shares created from the snapshot. On some platforms, shares can only be created from the snapshot on the host where snapshot was taken, so we can set a lower value in this option compared to reserved_share_percentage, and allow to create shares from the snapshot on the same host up to a higher threshold.

reserved_share_extend_percentage
Type:

integer

Default:

0

The percentage of backend capacity reserved for share extend operation. When existing limit of ‘reserved_share_percentage’ is hit, we do not want user to create a new share but existing shares can be extended based on value of this parameter.

share_backend_name
Type:

string

Default:

<None>

The backend name for a given driver implementation.

network_config_group
Type:

string

Default:

<None>

Name of the configuration group in the Manila conf file to look for network config options.If not set, the share backend’s config group will be used.If an option is not found within provided group, then ‘DEFAULT’ group will be used for search of option.

driver_handles_share_servers
Type:

boolean

Default:

<None>

There are two possible approaches for share drivers in Manila. First is when share driver is able to handle share-servers and second when not. Drivers can support either both or only one of these approaches. So, set this opt to True if share driver is able to handle share servers and it is desired mode else set False. It is set to None by default to make this choice intentional.

max_over_subscription_ratio
Type:

floating point

Default:

20.0

Minimum Value:

1.0

Float representation of the over subscription ratio when thin provisioning is involved. Default ratio is 20.0, meaning provisioned capacity can be 20 times the total physical capacity. If the ratio is 10.5, it means provisioned capacity can be 10.5 times the total physical capacity. A ratio of 1.0 means provisioned capacity cannot exceed the total physical capacity. A ratio lower than 1.0 is invalid.

migration_ignore_files
Type:

list

Default:

['lost+found']

List of files and folders to be ignored when migrating shares. Items should be names (not including any path).

share_mount_template
Type:

string

Default:

mount -vt %(proto)s %(options)s %(export)s %(path)s

The template for mounting shares for this backend. Must specify the executable with all necessary parameters for the protocol supported. ‘proto’ template element may not be required if included in the command. ‘export’ and ‘path’ template elements are required. It is advisable to separate different commands per backend.

share_unmount_template
Type:

string

Default:

umount -v %(path)s

The template for unmounting shares for this backend. Must specify the executable with all necessary parameters for the protocol supported. ‘path’ template element is required. It is advisable to separate different commands per backend.

protocol_access_mapping
Type:

dict value

Default:

{'ip': ['nfs'], 'user': ['cifs']}

Protocol access mapping for this backend. Should be a dictionary comprised of {‘access_type1’: [‘share_proto1’, ‘share_proto2’], ‘access_type2’: [‘share_proto2’, ‘share_proto3’]}.

admin_network_config_group
Type:

string

Default:

<None>

If share driver requires to setup admin network for share, then define network plugin config options in some separate config group and set its name here. Used only with another option ‘driver_handles_share_servers’ set to ‘True’.

replication_domain
Type:

string

Default:

<None>

A string specifying the replication domain that the backend belongs to. This option needs to be specified the same in the configuration sections of all backends that support replication between each other. If this option is not specified in the group, it means that replication is not enabled on the backend.

backend_availability_zone
Type:

string

Default:

<None>

Availability zone for this share backend. If not set, the storage_availability_zone option from the [DEFAULT] section is used.

filter_function
Type:

string

Default:

<None>

String representation for an equation that will be used to filter hosts.

goodness_function
Type:

string

Default:

<None>

String representation for an equation that will be used to determine the goodness of a host.

max_shares_per_share_server
Type:

integer

Default:

-1

Maximum number of share instances created in a share server.

max_share_server_size
Type:

integer

Default:

-1

Maximum sum of gigabytes a share server can have considering all its share instances and snapshots.

ssh_conn_timeout
Type:

integer

Default:

60

Backend server SSH connection timeout.

ssh_min_pool_conn
Type:

integer

Default:

1

Minimum number of connections in the SSH pool.

ssh_max_pool_conn
Type:

integer

Default:

10

Maximum number of connections in the SSH pool.

drivers_private_storage_class
Type:

string

Default:

manila.share.drivers_private_data.SqlStorageDriver

The full class name of the Private Data Driver class to use.

cephfs_conf_path
Type:

string

Default:

''

Fully qualified path to the ceph.conf file.

cephfs_cluster_name
Type:

string

Default:

<None>

The name of the cluster in use, if it is not the default (‘ceph’).

cephfs_auth_id
Type:

string

Default:

manila

The name of the ceph auth identity to use.

cephfs_protocol_helper_type
Type:

string

Default:

CEPHFS

Valid Values:

CEPHFS, NFS

The type of protocol helper to use. Default is CEPHFS.

cephfs_ganesha_server_is_remote
Type:

boolean

Default:

False

Whether the NFS-Ganesha server is remote to the driver.

Warning

This option is deprecated for removal since 2025.1. Its value may be silently ignored in the future.

Reason:

This option is used by the deprecated NFSProtocolHelper

cephfs_ganesha_server_ip
Type:

host address

Default:

<None>

The IP address of the NFS-Ganesha server.

cephfs_ganesha_server_username
Type:

string

Default:

root

The username to authenticate as in the remote NFS-Ganesha server host.

Warning

This option is deprecated for removal since 2025.1. Its value may be silently ignored in the future.

Reason:

This option is used by the deprecated NFSProtocolHelper

cephfs_ganesha_path_to_private_key
Type:

string

Default:

<None>

The path of the driver host’s private SSH key file.

Warning

This option is deprecated for removal since 2025.1. Its value may be silently ignored in the future.

Reason:

This option is used by the deprecated NFSProtocolHelper

cephfs_ganesha_server_password
Type:

string

Default:

<None>

The password to authenticate as the user in the remote Ganesha server host. This is not required if ‘cephfs_ganesha_path_to_private_key’ is configured.

Warning

This option is deprecated for removal since 2025.1. Its value may be silently ignored in the future.

Reason:

This option is used by the deprecated NFSProtocolHelper

cephfs_ganesha_export_ips
Type:

list

Default:

[]

List of IPs to export shares. If not supplied, then the value of ‘cephfs_ganesha_server_ip’ will be used to construct share export locations.

cephfs_volume_mode
Type:

string

Default:

755

The read/write/execute permissions mode for CephFS volumes, snapshots, and snapshot groups expressed in Octal as with linux ‘chmod’ or ‘umask’ commands.

cephfs_filesystem_name
Type:

string

Default:

<None>

The name of the filesystem to use, if there are multiple filesystems in the cluster.

cephfs_ensure_all_shares_salt
Type:

string

Default:

manila_cephfs_reef_caracal

Provide a unique string value to make the driver ensure all of the shares it has created during startup. Ensuring would re-export shares and this action isn’t always required, unless something has been administratively modified on CephFS.

cephfs_cached_allocated_capacity_update_interval
Type:

integer

Default:

60

Minimum Value:

0

The maximum time in seconds that the cached pool data will be considered updated. If it is expired when trying to read the pool data, it must be refreshed.

container_linux_bridge_name
Type:

string

Default:

docker0

Linux bridge used by container hypervisor to plug host-side veth to. It will be unplugged from here by the driver.

container_ovs_bridge_name
Type:

string

Default:

br-int

OVS bridge to use to plug a container to.

container_cifs_guest_ok
Type:

boolean

Default:

True

Determines whether to allow guest access to CIFS share or not.

container_image_name
Type:

string

Default:

manila-docker-container

Image to be used for a container-based share server.

container_helper
Type:

string

Default:

manila.share.drivers.container.container_helper.DockerExecHelper

Container helper which provides container-related operations to the driver.

container_protocol_helper
Type:

string

Default:

manila.share.drivers.container.protocol_helper.DockerCIFSHelper

Helper which facilitates interaction with share server.

container_security_service_helper
Type:

string

Default:

manila.share.drivers.container.security_service_helper.SecurityServiceHelper

Helper which facilitates interaction with security services.

container_storage_helper
Type:

string

Default:

manila.share.drivers.container.storage_helper.LVMHelper

Helper which facilitates interaction with storage solution used to actually store data. By default LVM is used to provide storage for a share.

container_volume_mount_path
Type:

string

Default:

/tmp/shares

Folder name in host to which logical volume will be mounted prior to providing access to it from a container.

container_volume_group
Type:

string

Default:

manila_docker_volumes

LVM volume group to use for volumes. This volume group must be created by the cloud administrator independently from manila operations.

emc_nas_login
Type:

string

Default:

<None>

User name for the EMC server.

emc_nas_password
Type:

string

Default:

<None>

Password for the EMC server.

emc_nas_server
Type:

host address

Default:

<None>

EMC server hostname or IP address.

emc_nas_server_port
Type:

port number

Default:

8080

Minimum Value:

0

Maximum Value:

65535

Port number for the EMC server.

emc_nas_server_secure
Type:

boolean

Default:

True

Use secure connection to server.

emc_share_backend
Type:

string

Default:

<None>

Valid Values:

powerscale, isilon, vnx, unity, powermax, powerstore, powerflex

Share backend.

emc_nas_root_dir
Type:

string

Default:

<None>

The root directory where shares will be located.

emc_ssl_cert_verify
Type:

boolean

Default:

True

If set to False the https client will not validate the SSL certificate of the backend endpoint.

emc_ssl_cert_path
Type:

string

Default:

<None>

Can be used to specify a non default path to a CA_BUNDLE file or directory with certificates of trusted CAs, which will be used to validate the backend.

powermax_server_container
Type:

string

Default:

<None>

Data mover to host the NAS server.

powermax_share_data_pools
Type:

list

Default:

<None>

Comma separated list of pools that can be used to persist share data.

powermax_ethernet_ports
Type:

list

Default:

<None>

Comma separated list of ports that can be used for share server interfaces. Members of the list can be Unix-style glob expressions.

smb_template_config_path
Type:

string

Default:

$state_path/smb.conf

Path to smb config.

volume_name_template
Type:

string

Default:

manila-share-%s

Volume name template.

volume_snapshot_name_template
Type:

string

Default:

manila-snapshot-%s

Volume snapshot name template.

share_mount_path
Type:

string

Default:

/shares

Parent path in service instance where shares will be mounted.

max_time_to_create_volume
Type:

integer

Default:

180

Maximum time to wait for creating cinder volume.

max_time_to_extend_volume
Type:

integer

Default:

180

Maximum time to wait for extending cinder volume.

max_time_to_attach
Type:

integer

Default:

120

Maximum time to wait for attaching cinder volume.

service_instance_smb_config_path
Type:

string

Default:

$share_mount_path/smb.conf

Path to SMB config in service instance.

share_helpers
Type:

dict value

Default:

{'CIFS': 'manila.share.drivers.helpers.CIFSHelperIPAccess', 'NFS': 'manila.share.drivers.helpers.NFSHelper'}

Specify list of share export helpers.

share_volume_fstype
Type:

string

Default:

ext4

Valid Values:

ext4, ext3

Filesystem type of the share volume.

cinder_volume_type
Type:

string

Default:

<None>

Name or id of cinder volume type which will be used for all volumes created by driver.

set_zero_reserved_blocks
Type:

boolean

Default:

True

If True, sets reserved blocks to 0 on formatted ext volumes to ensure full capacity is available to the share.

glusterfs_server_password
Type:

string

Default:

<None>

Remote GlusterFS server node’s login password. This is not required if ‘glusterfs_path_to_private_key’ is configured.

glusterfs_path_to_private_key
Type:

string

Default:

<None>

Path of Manila host’s private SSH key file.

glusterfs_nfs_server_type
Type:

string

Default:

Gluster

Type of NFS server that mediate access to the Gluster volumes (Gluster or Ganesha).

glusterfs_ganesha_server_ip
Type:

host address

Default:

<None>

Remote Ganesha server node’s IP address.

glusterfs_ganesha_server_username
Type:

string

Default:

root

Remote Ganesha server node’s username.

glusterfs_ganesha_server_password
Type:

string

Default:

<None>

Remote Ganesha server node’s login password. This is not required if ‘glusterfs_path_to_private_key’ is configured.

glusterfs_share_layout
Type:

string

Default:

<None>

Specifies GlusterFS share layout, that is, the method of associating backing GlusterFS resources to shares.

glusterfs_target
Type:

string

Default:

<None>

Specifies the GlusterFS volume to be mounted on the Manila host. It is of the form [remoteuser@]<volserver>:<volid>.

glusterfs_mount_point_base
Type:

string

Default:

$state_path/mnt

Base directory containing mount points for Gluster volumes.

glusterfs_servers
Type:

list

Default:

[]

List of GlusterFS servers that can be used to create shares. Each GlusterFS server should be of the form [remoteuser@]<volserver>, and they are assumed to belong to distinct Gluster clusters.

glusterfs_volume_pattern
Type:

string

Default:

<None>

Regular expression template used to filter GlusterFS volumes for share creation. The regex template can optionally (ie. with support of the GlusterFS backend) contain the #{size} parameter which matches an integer (sequence of digits) in which case the value shall be interpreted as size of the volume in GB. Examples: “manila-share-volume-d+$”, “manila-share-volume-#{size}G-d+$”; with matching volume names, respectively: “manila-share-volume-12”, “manila-share-volume-3G-13”. In latter example, the number that matches “#{size}”, that is, 3, is an indication that the size of volume is 3G.

hdfs_namenode_ip
Type:

host address

Default:

<None>

The IP of the HDFS namenode.

hdfs_namenode_port
Type:

port number

Default:

9000

Minimum Value:

0

Maximum Value:

65535

The port of HDFS namenode service.

hdfs_ssh_port
Type:

port number

Default:

22

Minimum Value:

0

Maximum Value:

65535

HDFS namenode SSH port.

hdfs_ssh_name
Type:

string

Default:

<None>

HDFS namenode ssh login name.

hdfs_ssh_pw
Type:

string

Default:

<None>

HDFS namenode SSH login password, This parameter is not necessary, if ‘hdfs_ssh_private_key’ is configured.

hdfs_ssh_private_key
Type:

string

Default:

<None>

Path to HDFS namenode SSH private key for login.

hitachi_hnas_ip
Type:

host address

Default:

<None>

HNAS management interface IP for communication between Manila controller and HNAS.

hitachi_hnas_user
Type:

string

Default:

<None>

HNAS username Base64 String in order to perform tasks such as create file-systems and network interfaces.

hitachi_hnas_password
Type:

string

Default:

<None>

HNAS user password. Required only if private key is not provided.

hitachi_hnas_evs_id
Type:

integer

Default:

<None>

Specify which EVS this backend is assigned to.

hitachi_hnas_evs_ip
Type:

host address

Default:

<None>

Specify IP for mounting shares.

hitachi_hnas_admin_network_ip
Type:

host address

Default:

<None>

Specify IP for mounting shares in the Admin network.

hitachi_hnas_file_system_name
Type:

string

Default:

<None>

Specify file-system name for creating shares.

hitachi_hnas_ssh_private_key
Type:

string

Default:

<None>

RSA/DSA private key value used to connect into HNAS. Required only if password is not provided.

hitachi_hnas_cluster_admin_ip0
Type:

host address

Default:

<None>

The IP of the clusters admin node. Only set in HNAS multinode clusters.

hitachi_hnas_stalled_job_timeout
Type:

integer

Default:

30

The time (in seconds) to wait for stalled HNAS jobs before aborting.

hitachi_hnas_driver_helper
Type:

string

Default:

manila.share.drivers.hitachi.hnas.ssh.HNASSSHBackend

Python class to be used for driver helper.

hitachi_hnas_allow_cifs_snapshot_while_mounted
Type:

boolean

Default:

False

By default, CIFS snapshots are not allowed to be taken when the share has clients connected because consistent point-in-time replica cannot be guaranteed for all files. Enabling this might cause inconsistent snapshots on CIFS shares.

hitachi_hsp_host
Type:

host address

Default:

<None>

HSP management host for communication between Manila controller and HSP.

hitachi_hsp_username
Type:

string

Default:

<None>

HSP username to perform tasks such as create filesystems and shares.

hitachi_hsp_password
Type:

string

Default:

<None>

HSP password for the username provided.

hitachi_hsp_ssl_cert_verify
Type:

boolean

Default:

True

If set to False the https client will not validate the SSL certificate of the backend endpoint.

hitachi_hsp_ssl_cert_path
Type:

string

Default:

<None>

Can be used to specify a non default path to a CA_BUNDLE file or directory with certificates of trusted CAs, which will be used to validate the backend.

hpealletra_wsapi_url
Type:

string

Default:

''

Alletra WSAPI V3 Server Url like https://<alletra ip>:8080/api/v3

hpealletra_username
Type:

string

Default:

''

Alletra username with the ‘edit’ role

hpealletra_password
Type:

string

Default:

''

Alletra password for the user specified in hpealletra_username

hpealletra_debug
Type:

boolean

Default:

False

Enable HTTP debugging to Alletra

hpe3par_api_url
Type:

string

Default:

''

3PAR WSAPI Server Url like https://<3par ip>:8080/api/v1

hpe3par_username
Type:

string

Default:

''

3PAR username with the ‘edit’ role

hpe3par_password
Type:

string

Default:

''

3PAR password for the user specified in hpe3par_username

hpe3par_san_ip
Type:

host address

Default:

<None>

IP address of SAN controller

hpe3par_san_login
Type:

string

Default:

''

Username for SAN controller

hpe3par_san_password
Type:

string

Default:

''

Password for SAN controller

hpe3par_san_ssh_port
Type:

port number

Default:

22

Minimum Value:

0

Maximum Value:

65535

SSH port to use with SAN

hpe3par_fpg
Type:

FPG

Default:

<None>

The File Provisioning Group (FPG) to use

hpe3par_fstore_per_share
Type:

boolean

Default:

False

Use one filestore per share

hpe3par_require_cifs_ip
Type:

boolean

Default:

False

Require IP access rules for CIFS (in addition to user)

hpe3par_debug
Type:

boolean

Default:

False

Enable HTTP debugging to 3PAR

hpe3par_cifs_admin_access_username
Type:

string

Default:

''

File system admin user name for CIFS.

hpe3par_cifs_admin_access_password
Type:

string

Default:

''

File system admin password for CIFS.

hpe3par_cifs_admin_access_domain
Type:

string

Default:

LOCAL_CLUSTER

File system domain for the CIFS admin user.

hpe3par_share_mount_path
Type:

string

Default:

/mnt/

The path where shares will be mounted when deleting nested file trees.

manila_huawei_conf_file
Type:

string

Default:

/etc/manila/manila_huawei_conf.xml

The configuration file for the Manila Huawei driver.

gpfs_share_export_ip
Type:

host address

Default:

<None>

IP to be added to GPFS export string.

gpfs_mount_point_base
Type:

string

Default:

$state_path/mnt

Base folder where exported shares are located.

gpfs_nfs_server_type
Type:

string

Default:

CES

NFS Server type. Valid choices are “CES” (Ganesha NFS) or “KNFS” (Kernel NFS).

gpfs_nfs_server_list
Type:

list

Default:

<None>

A list of the fully qualified NFS server names that make up the OpenStack Manila configuration.

is_gpfs_node
Type:

boolean

Default:

False

True:when Manila services are running on one of the Spectrum Scale node. False:when Manila services are not running on any of the Spectrum Scale node.

gpfs_ssh_port
Type:

port number

Default:

22

Minimum Value:

0

Maximum Value:

65535

GPFS server SSH port.

gpfs_ssh_login
Type:

string

Default:

<None>

GPFS server SSH login name.

gpfs_ssh_password
Type:

string

Default:

<None>

GPFS server SSH login password. The password is not needed, if ‘gpfs_ssh_private_key’ is configured.

gpfs_ssh_private_key
Type:

string

Default:

<None>

Path to GPFS server SSH private key for login.

gpfs_share_helpers
Type:

dict value

Default:

{'KNFS': 'manila.share.drivers.ibm.gpfs.KNFSHelper', 'CES': 'manila.share.drivers.ibm.gpfs.CESHelper'}

Specify list of share export helpers.

infinibox_login
Type:

string

Default:

<None>

Administrative user account name used to access the INFINIDAT Infinibox storage system.

infinibox_password
Type:

string

Default:

<None>

Password for the administrative user account specified in the infinibox_login option.

infinibox_hostname
Type:

host address

Default:

<None>

The name (or IP address) for the INFINIDAT Infinibox storage system.

infinidat_use_ssl
Type:

boolean

Default:

False

Use SSL to connect to the INFINIDAT Infinibox storage system.

infinidat_suppress_ssl_warnings
Type:

boolean

Default:

False

Suppress requests library SSL certificate warnings.

infinidat_pool_name
Type:

string

Default:

<None>

Name of the pool from which volumes are allocated.

infinidat_nas_network_space_name
Type:

string

Default:

<None>

Name of the NAS network space on the INFINIDAT InfiniBox.

infinidat_thin_provision
Type:

boolean

Default:

True

Use thin provisioning.

infinidat_snapdir_accessible
Type:

boolean

Default:

True

Controls access to the .snapshot directory. By default, each share allows access to its own .snapshot directory, which contains files and directories of each snapshot taken. To restrict access to the .snapshot directory, this option should be set to False.

infinidat_snapdir_visible
Type:

boolean

Default:

False

Controls visibility of the .snapshot directory. By default, each share contains the .snapshot directory, which is hidden on the client side. To make the .snapshot directory visible, this option should be set to True.

infortrend_nas_ip
Type:

host address

Default:

<None>

Infortrend NAS IP for management.

infortrend_nas_user
Type:

string

Default:

manila

User for the Infortrend NAS server.

infortrend_nas_password
Type:

string

Default:

<None>

Password for the Infortrend NAS server. This is not necessary if infortrend_nas_ssh_key is set.

infortrend_nas_ssh_key
Type:

string

Default:

<None>

SSH key for the Infortrend NAS server. This is not necessary if infortrend_nas_password is set.

infortrend_share_pools
Type:

list

Default:

<None>

Comma separated list of Infortrend NAS pools.

infortrend_share_channels
Type:

list

Default:

<None>

Comma separated list of Infortrend channels.

infortrend_ssh_timeout
Type:

integer

Default:

30

SSH timeout in seconds.

as13000_nas_ip
Type:

host address

Default:

<None>

IP address for the AS13000 storage.

as13000_nas_port
Type:

port number

Default:

8088

Minimum Value:

0

Maximum Value:

65535

Port number for the AS13000 storage.

as13000_nas_login
Type:

string

Default:

<None>

Username for the AS13000 storage

as13000_nas_password
Type:

string

Default:

<None>

Password for the AS13000 storage

as13000_share_pools
Type:

list

Default:

<None>

The Storage Pools Manila should use, a comma separated list

as13000_token_available_time
Type:

integer

Default:

3600

The effective time of token validity in seconds.

instorage_nas_ip
Type:

host address

Default:

<None>

IP address for the InStorage.

instorage_nas_port
Type:

port number

Default:

22

Minimum Value:

0

Maximum Value:

65535

Port number for the InStorage.

instorage_nas_login
Type:

string

Default:

<None>

Username for the InStorage.

instorage_nas_password
Type:

string

Default:

<None>

Password for the InStorage.

instorage_nas_pools
Type:

list

Default:

<None>

The Storage Pools Manila should use, a comma separated list.

macrosan_nas_ip
Type:

host address

Default:

<None>

IP address for the Macrosan NAS server.

macrosan_nas_port
Type:

port number

Default:

8443

Minimum Value:

0

Maximum Value:

65535

Port number for the Macrosan NAS server.

macrosan_nas_username
Type:

string

Default:

manila

Username for the Macrosan NAS server.

macrosan_nas_password
Type:

string

Default:

<None>

Password for the Macrosan NAS server.

macrosan_nas_http_protocol
Type:

string

Default:

https

Valid Values:

http, https

Http protocol for the Macrosan NAS server.

macrosan_ssl_cert_verify
Type:

boolean

Default:

False

Defines whether the driver should check ssl cert.

macrosan_nas_prefix
Type:

string

Default:

nas

Url prefix for the Macrosan NAS server.

macrosan_share_pools
Type:

list

Default:

<None>

Comma separated list of Macrosan NAS pools.

macrosan_timeout
Type:

integer

Default:

60

request timeout in seconds.

maprfs_clinode_ip
Type:

list

Default:

<None>

The list of IPs or hostnames of nodes where mapr-core is installed.

maprfs_ssh_port
Type:

port number

Default:

22

Minimum Value:

0

Maximum Value:

65535

CLDB node SSH port.

maprfs_ssh_name
Type:

string

Default:

mapr

Cluster admin user ssh login name.

maprfs_ssh_pw
Type:

string

Default:

<None>

Cluster node SSH login password, This parameter is not necessary, if ‘maprfs_ssh_private_key’ is configured.

maprfs_ssh_private_key
Type:

string

Default:

<None>

Path to SSH private key for login.

maprfs_base_volume_dir
Type:

string

Default:

/

Path in MapRFS where share volumes must be created.

maprfs_zookeeper_ip
Type:

list

Default:

<None>

The list of IPs or hostnames of ZooKeeper nodes.

maprfs_cldb_ip
Type:

list

Default:

<None>

The list of IPs or hostnames of CLDB nodes.

maprfs_rename_managed_volume
Type:

boolean

Default:

True

Specify whether existing volume should be renamed when start managing.

lustre_share_export_ip
Type:

host address

Default:

<None>

IP or hostname of the Lustre client mount point that is accessible to tenants. Used in export locations.

lustre_mgs_ip
Type:

host address

Default:

<None>

IP or hostname of the Lustre MGS for SSH nodemap operations. If not set, nodemap commands run locally via oslo.privsep.

lustre_mds_ip
Type:

host address

Default:

<None>

IP or hostname of the Lustre MDS for SSH quota operations. If not set, quota commands run locally via oslo.privsep.

lustre_mount_point
Type:

string

Default:

/mnt/lustre

Local mount point of the Lustre filesystem on the manila-share host.

lustre_mds_mount_point
Type:

string

Default:

<None>

Mount point of the Lustre filesystem on the MDS host. Only needed when lustre_mds_ip is set and the MDS mount path differs from lustre_mount_point. Defaults to lustre_mount_point.

lustre_fs_name
Type:

string

Default:

<None>

Name of the Lustre filesystem.

lustre_share_path_prefix
Type:

string

Default:

manila_shares

Sub-directory under the mount point where Manila shares are created.

lustre_project_id_start
Type:

integer

Default:

10000

Starting Lustre project ID for quota allocation.

lustre_project_id_end
Type:

integer

Default:

60000

Maximum Lustre project ID for quota allocation.

lustre_nid_type
Type:

string

Default:

tcp

Lustre NID type for client access (tcp, o2ib, etc).

lustre_ssh_username
Type:

string

Default:

root

SSH username for connecting to Lustre MGS/MDS.

lustre_ssh_private_key_path
Type:

string

Default:

<None>

Path to SSH private key for MGS/MDS access.

lustre_reapply_access_on_startup
Type:

boolean

Default:

False

Reapply nodemap access rules for every share when the manila-share service starts. Nodemaps persist on the MGS, so this is not needed during normal operation. Enable temporarily to recover after a MGS rebuild or manual nodemap deletion.

lvm_share_export_root
Type:

string

Default:

$state_path/mnt

Base folder where exported shares are located.

lvm_share_export_ips
Type:

list

Default:

<None>

List of IPs to export shares belonging to the LVM storage driver.

lvm_share_mirrors
Type:

integer

Default:

0

If set, create LVMs with multiple mirrors. Note that this requires lvm_mirrors + 2 PVs with available space.

lvm_share_volume_group
Type:

string

Default:

lvm-shares

Name for the VG that will contain exported shares.

lvm_share_helpers
Type:

dict value

Default:

{'CIFS': 'manila.share.drivers.helpers.CIFSHelperUserAccess', 'NFS': 'manila.share.drivers.helpers.NFSHelper'}

Specify list of share export helpers.

netapp_storage_family
Type:

string

Default:

ontap_cluster

The storage family type used on the storage system; valid values include ontap_cluster for using clustered Data ONTAP.

netapp_server_hostname
Type:

host address

Default:

<None>

The hostname (or IP address) for the storage system.

netapp_server_port
Type:

port number

Default:

<None>

Minimum Value:

0

Maximum Value:

65535

The TCP port to use for communication with the storage system or proxy server. If not specified, Data ONTAP drivers will use 80 for HTTP and 443 for HTTPS.

netapp_use_legacy_client
Type:

boolean

Default:

True

The ONTAP client used for retrieving and modifying data on the storage. The legacy client relies mostly on ZAPI calls, only using REST calls for SVM migrate feature. If set to False, the new REST client is used, which runs REST calls if supported, otherwise falls back to the equivalent ZAPI call.

netapp_transport_type
Type:

string

Default:

https

The transport protocol used when communicating with the storage system or proxy server. Valid values are http or https.

netapp_ssl_cert_path
Type:

string

Default:

<None>

The path to a CA_BUNDLE file or directory with certificates of trusted CA. If set to a directory, it must have been processed using the c_rehash utility supplied with OpenSSL. When provided, this path is used as the trust anchor for HTTPS certificate verification. If not informed, the Mozilla Root Certificates are used by default. Applies to both REST and legacy ZAPI clients.

netapp_ssl_cert_verify
Type:

boolean

Default:

True

If set to False, the SSL certificate of the storage system will not be verified. This is useful when the storage system uses a self-signed certificate. WARNING: disabling certificate verification is a security risk and should only be used in test and non-production environments. Applies to both the REST and legacy ZAPI clients.

netapp_login
Type:

string

Default:

<None>

Administrative user account name used to access the storage system.

netapp_password
Type:

string

Default:

<None>

Password for the administrative user account specified in the netapp_login option.

netapp_private_key_file
Type:

string

Default:

/path/to/private_key.key,

This option has a sample default set, which means that its actual default value may vary from the one documented above.

For self signed certificate: This file contains the private key associated with the self-signed certificate. It is a sensitive file that should be kept secure and protected. The private key is used to sign the certificate and establish the authenticity and integrity of the certificate during the authentication process. For ca verified certificate: This file contains the private key associated with the certificate. It is generated when creating the certificate signing request (CSR) and should be kept secure and protected. The private key is used to sign the CSR and later used to establish secure connections and authenticate the entity.

netapp_certificate_file
Type:

string

Default:

/path/to/certificate.pem

This option has a sample default set, which means that its actual default value may vary from the one documented above.

For self signed certificate: This file contains the self-signed digital certificate itself. It includes information about the entity such as the common name (e.g., domain name), organization details, validity period, and public key. The certificate file is generated based on the private key and is used by clients or systems to verify the entity identity during the authentication process. For ca verified certificate: This file contains the digital certificate issued by the trusted third-party certificate authority (CA). It includes information about the entity identity, public key, and the CA that issued the certificate. The certificate file is used by clients or systems to verify the authenticity and integrity of the entity during the authentication process.

netapp_ca_certificate_file
Type:

string

Default:

/path/to/ca_certificate.crt

This option has a sample default set, which means that its actual default value may vary from the one documented above.

This is applicable only for ca verified certificate. This file contains the public key certificate of the trusted third-party certificate authority (CA) that issued the certificate. It is used by clients or systems to validate the authenticity of the certificate presented by the entity. The CA certificate file is typically pre-configured in the trust store of clients or systems to establish trust in certificates issued by that CA.

netapp_certificate_host_validation
Type:

boolean

Default:

False

Enable certificate verification

netapp_enabled_share_protocols
Type:

list

Default:

['nfs3', 'nfs4.0']

The NFS protocol versions that will be enabled. Supported values include nfs3, nfs4.0, nfs4.1. This option only applies when the option driver_handles_share_servers is set to True.

netapp_volume_name_template
Type:

string

Default:

share_%(share_id)s

NetApp volume name template.

netapp_vserver_name_template
Type:

string

Default:

os_%s

Name template to use for new Vserver. When using CIFS protocol make sure to not configure characters illegal in DNS hostnames.

netapp_qos_policy_group_name_template
Type:

string

Default:

qos_share_%(share_id)s

NetApp QoS policy group name template.

netapp_port_name_search_pattern
Type:

string

Default:

(.*)

Pattern for overriding the selection of network ports on which to create Vserver LIFs.

netapp_lif_name_template
Type:

string

Default:

os_%(net_allocation_id)s

Logical interface (LIF) name template

netapp_identity_auth_token_path
Type:

string

Default:

''

Path to interact with auth tokens

netapp_aggregate_name_search_pattern
Type:

string

Default:

(.*)

Pattern for searching available aggregates for provisioning.

netapp_root_volume_aggregate
Type:

string

Default:

<None>

Name of aggregate to create Vserver root volumes on. This option only applies when the option driver_handles_share_servers is set to True.

netapp_root_volume
Type:

string

Default:

root

Root volume name.

netapp_delete_retention_hours
Type:

integer

Default:

12

Minimum Value:

0

The number of hours that a deleted volume should be retained before the delete is completed.

netapp_volume_snapshot_reserve_percent
Type:

integer

Default:

5

Minimum Value:

0

Maximum Value:

90

The percentage of share space set aside as reserve for snapshot usage; valid values range from 0 to 90.

netapp_reset_snapdir_visibility
Type:

string

Default:

default

Valid Values:

visible, hidden, default

This option forces all existing shares to have their snapshot directory visibility set to either ‘visible’ or ‘hidden’ during driver startup. If set to ‘default’, nothing will be changed during startup. This will not affect new shares, which will have their snapshot directory always visible, unless toggled by the share type extra spec ‘netapp:hide_snapdir’.

netapp_volume_snapshot_policy_exceptions
Type:

list

Default:

['ec2_backups']

NetApp volume Snapshot policy names which will not be overriden by extra-specs.

netapp_snapmirror_policy_name_svm_template
Type:

string

Default:

snapmirror_policy_%(share_server_id)s

NetApp SnapMirror policy name template for Storage Virtual Machines (Vservers).

netapp_fpolicy_default_file_operations
Type:

list

Default:

['create', 'write', 'rename']

NetApp FPolicy file operations to apply to a FPolicy event, when not provided by the user using “netapp:fpolicy_file_operations” extra-spec.

netapp_fpolicy_policy_name_template
Type:

string

Default:

fpolicy_policy_%(share_id)s

NetApp FPolicy policy name template.

netapp_fpolicy_event_name_template
Type:

string

Default:

fpolicy_event_%(protocol)s_%(share_id)s

NetApp FPolicy policy name template.

netapp_cached_aggregates_status_lifetime
Type:

integer

Default:

60

Minimum Value:

0

The maximum time in seconds that the cached aggregates status will be considered valid. Trying to read the expired cache leads to refreshing it.

netapp_enable_flexgroup
Type:

boolean

Default:

False

Specify if the FlexGroup pool is enabled. When it is enabled, the driver will report a single pool representing all aggregates (ONTAP chooses on which the share will be allocated). If you want to Manila control the aggregate selection, you can configure its custom FlexGroup pools through netapp_flexgroup_pools option. The FlexGroup placement is done either by ONTAP or Manila, not both.

netapp_flexgroup_pools
Type:

dict value

Default:

{}

Multi opt of dict to represent the FlexGroup pools. A FlexGroup pool is configured with its name and its list of aggregates. Specify this option as many times as you have FlexGroup pools. Each entry takes the dict config form: netapp_flexgroup_pools = <pool_name>: <aggr_name1> <aggr_name2> ..

netapp_flexgroup_pool_only
Type:

boolean

Default:

False

Specify if the FlexVol pools must not be reported when the netapp_enable_flexgroup is enabled.

netapp_flexgroup_volume_online_timeout
Type:

integer

Default:

360

Minimum Value:

60

Sets time in seconds to wait for a FlexGroup volume create to complete and go online.

netapp_flexgroup_aggregate_not_busy_timeout
Type:

integer

Default:

360

Minimum Value:

60

Provisioning FlexGroup share requires that all of its aggregates to not be busy deploying another volume. So, sets time in seconds to retry to create the FlexGroup share.

netapp_delete_busy_flexgroup_snapshot_timeout
Type:

integer

Default:

360

Minimum Value:

60

Sets time in seconds to wait for a FlexGroup snapshot to not be busy with clones after splitting them.

netapp_rest_operation_timeout
Type:

integer

Default:

60

Minimum Value:

60

Sets maximum amount of time in seconds to wait for a synchronous ONTAP REST API operation to be completed.

netapp_zapi_fallback_enabled
Type:

boolean

Default:

True

This option allows ONTAP REST client methods to fallback to ZAPI when a REST method is not implemented.

netapp_security_cert_expire_days
Type:

integer

Default:

365

Minimum Value:

1

Maximum Value:

3652

Defines the expiration time (in days) for the certificate created during the vserver creation. This option only applies when the option driver_handles_share_servers is set to True.

netapp_restrict_lif_creation_per_ha_pair
Type:

boolean

Default:

False

Prevent the creation of a share server if total number of data LIFs on one node of HA pair, including those that can be migrated in case of failure, exceeds the maximum data LIFs supported by the node. This option guarantees that, in the event of a node failure, the partner node will be able to takeover all data LIFs.

netapp_cifs_aes_encryption
Type:

boolean

Default:

False

This option enable/disable AES encryption for the share server based on the parameter value (True/False).

netapp_enable_logical_space_reporting
Type:

boolean

Default:

False

This option enables the logical space reporting on a newly created vserver and logical space accounting on newly created volumes on this vserver.

netapp_fixed_qos_policy_prefix
Type:

string

Default:

FIXED_QOS

This option enables user to configure the prefix of fixed QoS policies created on vserver.

netapp_adaptive_qos_policy_prefix
Type:

string

Default:

ADAPTIVE_QOS

This option enables user to configure the prefix of adaptive QoS policies created on vserver.

netapp_cifs_smb_signing
Type:

boolean

Default:

False

This option enable/disable SMB signing that protects the security of the data fabric by making sure that traffic between storage systems and clients is not compromised.

netapp_dns_domains
Type:

list

Default:

[]

DNS search domains for SVMs (max 6, DHSS=True only). Must be paired with netapp_dns_nameservers.

netapp_dns_nameservers
Type:

list

Default:

[]

DNS server IPs for SVMs (max 3, DHSS=True only). Must be paired with netapp_dns_domains.

netapp_dns_hosts
Type:

list

Default:

[]

Static hostname:ip fallbacks for the SVM local-hosts table. Requires netapp_dns_domains and netapp_dns_nameservers. Supports “host1,host2:ip” shorthand for shared IPs.

netapp_snapmirror_quiesce_timeout
Type:

integer

Default:

3600

Minimum Value:

0

The maximum time in seconds to wait for existing snapmirror transfers to complete before aborting when promoting a replica.

netapp_snapmirror_release_timeout
Type:

integer

Default:

3600

Minimum Value:

0

The maximum time in seconds to wait for a snapmirror release when breaking snapmirror relationships.

netapp_snapmirror_schedule
Type:

string

Default:

hourly

An interval in either minutes or hours used to update the SnapMirror relationship. Few valid values are: 5min, 10min, 30min, hourly etc. The schedule at the “destination” host will be the one that will be considered when creating a new replica, or promoting a replica

netapp_volume_move_cutover_timeout
Type:

integer

Default:

3600

Minimum Value:

0

The maximum time in seconds to wait for the completion of a volume move operation after the cutover was triggered.

netapp_start_volume_move_timeout
Type:

integer

Default:

3600

Minimum Value:

0

The maximum time in seconds to wait for the completion of a volume clone split operation in order to start a volume move.

netapp_migration_cancel_timeout
Type:

integer

Default:

3600

Minimum Value:

0

The maximum time in seconds that migration cancel waits for all migration operations be completely aborted.

netapp_server_migration_state_change_timeout
Type:

integer

Default:

3600

Minimum Value:

0

The maximum time in seconds that a share server migration waits for a vserver to change its internal states.

netapp_server_migration_check_capacity
Type:

boolean

Default:

True

Specify if the capacity check must be made by the driver while performing a share server migration. If enabled, the driver will validate if the destination backend can hold all shares and snapshots capacities from the source share server.

netapp_mount_replica_timeout
Type:

integer

Default:

3600

Minimum Value:

0

The maximum time in seconds to wait for mounting a replica.

netapp_enabled_backup_types
Type:

list

Default:

[]

Specify compatible backup_types for backend to provision backup share for SnapVault relationship. Multiple backup_types can be provided. If multiple backup types are enabled, create separate config sections for each backup type specifying the “netapp_backup_vserver”, “netapp_backup_backend_section_name”, “netapp_backup_volume”, and “netapp_snapmirror_job_timeout” as appropriate. Example- netapp_enabled_backup_types = eng_backup, finance_backup

netapp_backup_backend_section_name
Type:

string

Default:

<None>

Backend (ONTAP cluster) name where backup volume will be provisioned. This is one of the backend which is enabled in manila.conf file.

netapp_backup_vserver
Type:

string

Default:

''

vserver name of backend that is use for backup the share. When user provide vserver value then backup volume will be created under this vserver

netapp_backup_volume
Type:

string

Default:

''

Specify backup share name in case user wanted to backup the share. Some case user has dedicated volume for backup in this case use can provide dedicated volume. backup_share_server must be specified if backup_share is provided

netapp_snapmirror_job_timeout
Type:

integer

Default:

1800

Minimum Value:

0

The maximum time in seconds to wait for a snapmirror related operation to backup to complete.

nexenta_rest_addresses
Type:

list

Default:

<None>

One or more comma delimited IP addresses for management communication with NexentaStor appliance.

nexenta_rest_port
Type:

integer

Default:

8443

Port to connect to Nexenta REST API server.

nexenta_rest_protocol
Type:

string

Default:

auto

Valid Values:

http, https, auto

Use http or https for REST connection (default auto).

nexenta_use_https
Type:

boolean

Default:

True

Use HTTP secure protocol for NexentaStor management REST API connections

nexenta_user
Type:

string

Default:

admin

User name to connect to Nexenta SA.

nexenta_password
Type:

string

Default:

<None>

Password to connect to Nexenta SA.

nexenta_volume
Type:

string

Default:

volume1

Volume name on NexentaStor.

nexenta_pool
Type:

string

Default:

pool1

Pool name on NexentaStor.

nexenta_nfs
Type:

boolean

Default:

True

Defines whether share over NFS is enabled.

nexenta_ssl_cert_verify
Type:

boolean

Default:

False

Defines whether the driver should check ssl cert.

nexenta_rest_connect_timeout
Type:

floating point

Default:

30

Specifies the time limit (in seconds), within which the connection to NexentaStor management REST API server must be established

nexenta_rest_read_timeout
Type:

floating point

Default:

300

Specifies the time limit (in seconds), within which NexentaStor management REST API server must send a response

nexenta_rest_backoff_factor
Type:

floating point

Default:

1

Specifies the backoff factor to apply between connection attempts to NexentaStor management REST API server

nexenta_rest_retry_count
Type:

integer

Default:

5

Specifies the number of times to repeat NexentaStor management REST API call in case of connection errors and NexentaStor appliance EBUSY or ENOENT errors

nexenta_nfs_share
Type:

string

Default:

nfs_share

Parent filesystem where all the shares will be created. This parameter is only used by NexentaStor4 driver.

nexenta_share_name_prefix
Type:

string

Default:

share-

Nexenta share name prefix.

nexenta_folder
Type:

string

Default:

folder

Parent folder on NexentaStor.

nexenta_dataset_compression
Type:

string

Default:

on

Valid Values:

on, off, gzip, gzip-1, gzip-2, gzip-3, gzip-4, gzip-5, gzip-6, gzip-7, gzip-8, gzip-9, lzjb, zle, lz4

Compression value for new ZFS folders.

nexenta_dataset_dedupe
Type:

string

Default:

off

Valid Values:

on, off, sha256, verify

Deduplication value for new ZFS folders. Only used by NexentaStor4 driver.

nexenta_thin_provisioning
Type:

boolean

Default:

True

If True shares will not be space guaranteed and overprovisioning will be enabled.

nexenta_dataset_record_size
Type:

integer

Default:

131072

Specifies a suggested block size in for files in a file system. (bytes)

nexenta_nas_host
Type:

host address

Default:

<None>

Data IP address of Nexenta storage appliance.

nexenta_mount_point_base
Type:

string

Default:

$state_path/mnt

Base directory that contains NFS share mount points.

flashblade_api
Type:

string

Default:

<None>

API token for an administrative user account

flashblade_eradicate
Type:

boolean

Default:

True

When enabled, all FlashBlade file systems and snapshots will be eradicated at the time of deletion in Manila. Data will NOT be recoverable after a delete with this set to True! When disabled, file systems and snapshots will go into pending eradication state and can be recovered.)

flashblade_mgmt_vip
Type:

host address

Default:

<None>

The name (or IP address) for the Pure Storage FlashBlade storage system management VIP.

flashblade_data_vip
Type:

list

Default:

<None>

The names (or IP address) for the Pure Storage FlashBlade storage system data VIPs. The first listed name or IP address will be considered to be the preferred IP address, although is not enforced.

flashblade_ssl_cert_verify
Type:

boolean

Default:

True

If set to True, the driver verifies the SSL certificate presented by the FlashBlade management interface. This is enabled by default. If the FlashBlade uses a self-signed or private CA certificate, supply the CA certificate bundle via flashblade_ca_cert_path. Setting this to False disables verification and is not recommended.

flashblade_ca_cert_path
Type:

string

Default:

<None>

Path to a CA certificate bundle file (PEM format) used to verify the FlashBlade management interface’s SSL certificate. Only used when flashblade_ssl_cert_verify is True. If unset, the system default CA certificates are used.

qnap_management_url
Type:

string

Default:

<None>

The URL to manage QNAP Storage.

qnap_share_ip
Type:

host address

Default:

<None>

NAS share IP for mounting shares.

qnap_nas_login
Type:

string

Default:

<None>

Username for QNAP storage.

qnap_nas_password
Type:

string

Default:

<None>

Password for QNAP storage.

qnap_poolname
Type:

string

Default:

<None>

Pool within which QNAP shares must be created.

quobyte_api_url
Type:

string

Default:

<None>

URL of the Quobyte API server (http or https)

quobyte_api_ca
Type:

string

Default:

<None>

The X.509 CA file to verify the server cert.

quobyte_delete_shares
Type:

boolean

Default:

False

Actually deletes shares (vs. unexport)

quobyte_api_username
Type:

string

Default:

admin

Username for Quobyte API server.

quobyte_api_password
Type:

string

Default:

quobyte

Password for Quobyte API server

quobyte_volume_configuration
Type:

string

Default:

BASE

Name of volume configuration used for new shares.

quobyte_default_volume_user
Type:

string

Default:

root

Default owning user for new volumes.

quobyte_default_volume_group
Type:

string

Default:

root

Default owning group for new volumes.

quobyte_export_path
Type:

string

Default:

/quobyte

Export path for shares of this bacckend. This needs to match the quobyte-nfs services “Pseudo” option.

service_instance_user
Type:

string

Default:

<None>

User in service instance that will be used for authentication.

service_instance_password
Type:

string

Default:

<None>

Password for service instance user.

path_to_private_key
Type:

string

Default:

<None>

Path to host’s private key.

max_time_to_build_instance
Type:

integer

Default:

300

Maximum time in seconds to wait for creating service instance.

limit_ssh_access
Type:

boolean

Default:

False

Block SSH connection to the service instance from other networks than service network.

service_instance_name_or_id
Type:

string

Default:

<None>

Name or ID of service instance in Nova to use for share exports. Used only when share servers handling is disabled.

service_net_name_or_ip
Type:

host address

Default:

<None>

Can be either name of network that is used by service instance within Nova to get IP address or IP address itself (either IPv4 or IPv6) for managing shares there. Used only when share servers handling is disabled.

tenant_net_name_or_ip
Type:

host address

Default:

<None>

Can be either name of network that is used by service instance within Nova to get IP address or IP address itself (either IPv4 or IPv6) for exporting shares. Used only when share servers handling is disabled.

service_image_name
Type:

string

Default:

manila-service-image

Name of image in Glance, that will be used for service instance creation. Only used if driver_handles_share_servers=True.

service_instance_name_template
Type:

string

Default:

%s

Name of service instance. Only used if driver_handles_share_servers=True.

manila_service_keypair_name
Type:

string

Default:

manila-service

Keypair name that will be created and used for service instances. Only used if driver_handles_share_servers=True.

path_to_public_key
Type:

string

Default:

~/.ssh/id_rsa.pub

Path to hosts public key. Only used if driver_handles_share_servers=True.

service_instance_security_group
Type:

string

Default:

manila-service

Security group name, that will be used for service instance creation. Only used if driver_handles_share_servers=True.

service_instance_flavor_id
Type:

string

Default:

100

ID of flavor, that will be used for service instance creation. Only used if driver_handles_share_servers=True.

service_network_name
Type:

string

Default:

manila_service_network

Name of manila service network. Used only with Neutron. Only used if driver_handles_share_servers=True.

service_network_host
Type:

host address

Default:

<your_network_hostname>

This option has a sample default set, which means that its actual default value may vary from the one documented above.

Hostname to be used for service network binding. Used only with Neutron and if driver_handles_share_servers=True.

service_network_cidr
Type:

string

Default:

10.254.0.0/16

CIDR of manila service network. Used only with Neutron and if driver_handles_share_servers=True.

service_network_division_mask
Type:

integer

Default:

28

This mask is used for dividing service network into subnets, IP capacity of subnet with this mask directly defines possible amount of created service VMs per tenant’s subnet. Used only with Neutron and if driver_handles_share_servers=True.

interface_driver
Type:

string

Default:

manila.network.linux.interface.OVSInterfaceDriver

Module path to the Virtual Interface (VIF) driver class. This option is used only by drivers operating in driver_handles_share_servers=True mode that provision OpenStack compute instances as share servers. This option is only supported with Neutron networking. Drivers provided in tree work with Linux Bridge (manila.network.linux.interface.BridgeInterfaceDriver) and OVS (manila.network.linux.interface.OVSInterfaceDriver). If the manila-share service is running on a host that is connected to the administrator network, a no-op driver (manila.network.linux.interface.NoopInterfaceDriver) may be used.

connect_share_server_to_tenant_network
Type:

boolean

Default:

False

Attach share server directly to share network. Used only with Neutron and if driver_handles_share_servers=True.

admin_network_id
Type:

string

Default:

<None>

ID of neutron network used to communicate with admin network, to create additional admin export locations on.

admin_subnet_id
Type:

string

Default:

<None>

ID of neutron subnet used to communicate with admin network, to create additional admin export locations on. Related to ‘admin_network_id’.

service_instance_boot_from_volume
Type:

boolean

Default:

False

Boot service instances (share servers) from a Cinder volume. If False, boot from the image as before. Only used if driver_handles_share_servers=True.

service_instance_boot_volume_size
Type:

integer

Default:

10

Minimum Value:

1

Size (GiB) of the root volume when booting from volume. Only used if driver_handles_share_servers=True.

service_instance_boot_volume_type
Type:

string

Default:

<None>

Name or id of cinder volume type which will be used for all boot volumes created by driver.

service_instance_base_boot_volume_id
Type:

string

Default:

<None>

UUID of volume in Cinder, that will be used as base volume that bootable volume clone from during service instance creation. Only used if driver_handles_share_servers=True.

service_instance_boot_volume_delete_on_termination
Type:

boolean

Default:

True

Whether the root volume is deleted when the service instance is terminated. Only used if driver_handles_share_servers=True.

service_instance_boot_volume_name_template
Type:

string

Default:

manila-share-%s-boot

Boot volume name template.

tegile_nas_server
Type:

host address

Default:

<None>

Tegile NAS server hostname or IP address.

tegile_nas_login
Type:

string

Default:

<None>

User name for the Tegile NAS server.

tegile_nas_password
Type:

string

Default:

<None>

Password for the Tegile NAS server.

tegile_default_project
Type:

string

Default:

<None>

Create shares in this project

winrm_cert_pem_path
Type:

string

Default:

~/.ssl/cert.pem

Path to the x509 certificate used for accessing the service instance.

winrm_cert_key_pem_path
Type:

string

Default:

~/.ssl/key.pem

Path to the x509 certificate key.

winrm_use_cert_based_auth
Type:

boolean

Default:

False

Use x509 certificates in order to authenticate to the service instance.

winrm_conn_timeout
Type:

integer

Default:

60

WinRM connection timeout.

winrm_operation_timeout
Type:

integer

Default:

60

WinRM operation timeout.

winrm_retry_count
Type:

integer

Default:

3

WinRM retry count.

winrm_retry_interval
Type:

integer

Default:

5

WinRM retry interval in seconds

zfs_share_export_ip
Type:

host address

Default:

<None>

IP to be added to user-facing export location. Required.

zfs_service_ip
Type:

host address

Default:

<None>

IP to be added to admin-facing export location. Required.

zfs_zpool_list
Type:

list

Default:

<None>

Specify list of zpools that are allowed to be used by backend. Can contain nested datasets. Examples: Without nested dataset: ‘zpool_name’. With nested dataset: ‘zpool_name/nested_dataset_name’. Required.

zfs_dataset_creation_options
Type:

list

Default:

<None>

Define here list of options that should be applied for each dataset creation if needed. Example: compression=gzip,dedup=off. Note that, for secondary replicas option ‘readonly’ will be set to ‘on’ and for active replicas to ‘off’ in any way. Also, ‘quota’ will be equal to share size. Optional.

zfs_dataset_name_prefix
Type:

string

Default:

manila_share_

Prefix to be used in each dataset name. Optional.

zfs_dataset_snapshot_name_prefix
Type:

string

Default:

manila_share_snapshot_

Prefix to be used in each dataset snapshot name. Optional.

zfs_use_ssh
Type:

boolean

Default:

False

Remote ZFS storage hostname that should be used for SSH’ing. Optional.

zfs_ssh_username
Type:

string

Default:

<None>

SSH user that will be used in 2 cases: 1) By manila-share service in case it is located on different host than its ZFS storage. 2) By manila-share services with other ZFS backends that perform replication. It is expected that SSH’ing will be key-based, passwordless. This user should be passwordless sudoer. Optional.

zfs_ssh_user_password
Type:

string

Default:

<None>

Password for user that is used for SSH’ing ZFS storage host. Not used for replication operations. They require passwordless SSH access. Optional.

zfs_ssh_private_key_path
Type:

string

Default:

<None>

Path to SSH private key that should be used for SSH’ing ZFS storage host. Not used for replication operations. Optional.

zfs_share_helpers
Type:

dict value

Default:

{'NFS': 'manila.share.drivers.zfsonlinux.utils.NFSviaZFSHelper'}

Specify list of share export helpers for ZFS storage. It should look like following: ‘FOO_protocol=foo.FooClass,BAR_protocol=bar.BarClass’. Required.

zfs_replica_snapshot_prefix
Type:

string

Default:

tmp_snapshot_for_replication_

Set snapshot prefix for usage in ZFS replication. Required.

zfs_migration_snapshot_prefix
Type:

string

Default:

tmp_snapshot_for_share_migration_

Set snapshot prefix for usage in ZFS migration. Required.

zfssa_host
Type:

host address

Default:

<None>

ZFSSA management IP address.

zfssa_data_ip
Type:

host address

Default:

<None>

IP address for data.

zfssa_auth_user
Type:

string

Default:

<None>

ZFSSA management authorized username.

zfssa_auth_password
Type:

string

Default:

<None>

ZFSSA management authorized user’s password.

zfssa_pool
Type:

string

Default:

<None>

ZFSSA storage pool name.

zfssa_project
Type:

string

Default:

<None>

ZFSSA project name.

zfssa_nas_checksum
Type:

string

Default:

fletcher4

Controls checksum used for data blocks.

zfssa_nas_compression
Type:

string

Default:

off

Data compression-off, lzjb, gzip-2, gzip, gzip-9.

zfssa_nas_logbias
Type:

string

Default:

latency

Controls behavior when servicing synchronous writes.

zfssa_nas_mountpoint
Type:

string

Default:

''

Location of project in ZFS/SA.

zfssa_nas_quota_snap
Type:

string

Default:

true

Controls whether a share quota includes snapshot.

zfssa_nas_rstchown
Type:

string

Default:

true

Controls whether file ownership can be changed.

zfssa_nas_vscan
Type:

string

Default:

false

Controls whether the share is scanned for viruses.

zfssa_rest_timeout
Type:

string

Default:

<None>

REST connection timeout (in seconds).

zfssa_manage_policy
Type:

string

Default:

loose

Valid Values:

loose, strict

Driver policy for share manage. A strict policy checks for a schema named manila_managed, and makes sure its value is true. A loose policy does not check for the schema.

enable_pre_hooks
Type:

boolean

Default:

False

Whether to enable pre hooks or not.

enable_post_hooks
Type:

boolean

Default:

False

Whether to enable post hooks or not.

enable_periodic_hooks
Type:

boolean

Default:

False

Whether to enable periodic hooks or not.

suppress_pre_hooks_errors
Type:

boolean

Default:

False

Whether to suppress pre hook errors (allow driver perform actions) or not.

suppress_post_hooks_errors
Type:

boolean

Default:

False

Whether to suppress post hook errors (allow driver’s results to pass through) or not.

periodic_hooks_interval
Type:

floating point

Default:

300.0

Interval in seconds between execution of periodic hooks. Used when option ‘enable_periodic_hooks’ is set to True. Default is 300.

share_driver
Type:

string

Default:

manila.share.drivers.generic.GenericShareDriver

Driver to use for share creation.

hook_drivers
Type:

list

Default:

[]

Driver(s) to perform some additional actions before and after share driver actions and on a periodic basis. Default is [].

delete_share_server_with_last_share
Type:

boolean

Default:

False

Whether share servers will be deleted on deletion of the last share.

unmanage_remove_access_rules
Type:

boolean

Default:

False

If set to True, then manila will deny access and remove all access rules on share unmanage.If set to False - nothing will be changed.

automatic_share_server_cleanup
Type:

boolean

Default:

True

If set to True, then Manila will delete all share servers which were unused more than specified time .If set to False - automatic deletion of share servers will be disabled.

unused_share_server_cleanup_interval
Type:

integer

Default:

10

Minimum Value:

10

Maximum Value:

720

Unallocated share servers reclamation time interval (minutes). Minimum value is 10 minutes, maximum is 720 minutes. The reclamation function is run every 10 minutes and delete share servers which were unused more than unused_share_server_cleanup_interval option defines. This value reflects the shortest time Manila will wait for a share server to go unutilized before deleting it.

replica_state_update_interval
Type:

integer

Default:

300

This value, specified in seconds, determines how often the share manager will poll for the health (replica_state) of each replica instance.

migration_driver_continue_update_interval
Type:

integer

Default:

60

This value, specified in seconds, determines how often the share manager will poll the driver to perform the next step of migration in the storage backend, for a migrating share.

server_migration_driver_continue_update_interval
Type:

integer

Default:

900

This value, specified in seconds, determines how often the share manager will poll the driver to perform the next step of migration in the storage backend, for a migrating share server.

server_migration_extend_neutron_network
Type:

boolean

Default:

False

If set to True, neutron network are extended to destination host during share server migration. This option should only be enabled if using NeutronNetworkPlugin or its derivatives and when multiple bindings of Manila ports are supported by Neutron ML2 plugin.

share_usage_size_update_interval
Type:

integer

Default:

300

This value, specified in seconds, determines how often the share manager will poll the driver to update the share usage size in the storage backend, for shares in that backend.

enable_gathering_share_usage_size
Type:

boolean

Default:

False

If set to True, share usage size will be polled for in the interval specified with “share_usage_size_update_interval”. Usage data can be consumed by telemetry integration. If telemetry is not configured, this option must be set to False. If set to False - gathering share usage size will be disabled.

share_service_inithost_offload
Type:

boolean

Default:

False

Offload pending share ensure during share service startup

check_for_expired_shares_in_recycle_bin_interval
Type:

integer

Default:

3600

This value, specified in seconds, determines how often the share manager will check for expired shares and delete them from the Recycle bin.

check_for_expired_transfers
Type:

integer

Default:

300

This value, specified in seconds, determines how often the share manager will check for expired transfers and destroy them and roll back share state.

driver_backup_continue_update_interval
Type:

integer

Default:

60

This value, specified in seconds, determines how often the share manager will poll to perform the next steps of backup such as fetch the progress of backup.

driver_restore_continue_update_interval
Type:

integer

Default:

60

This value, specified in seconds, determines how often the share manager will poll to perform the next steps of restore such as fetch the progress of restore.

periodic_deferred_delete_interval
Type:

integer

Default:

300

This value, specified in seconds, determines how often the share manager will try to delete the share and share snapshots in backend driver.

volume_api_class
Type:

string

Default:

manila.volume.cinder.API

The full class name of the Volume API class to use.

tcp_keepalive
Type:

boolean

Default:

True

Sets the value of TCP_KEEPALIVE (True/False) for each server socket.

tcp_keepalive_interval
Type:

integer

Default:

<None>

Sets the value of TCP_KEEPINTVL in seconds for each server socket. Not supported on OS X.

tcp_keepalive_count
Type:

integer

Default:

<None>

Sets the value of TCP_KEEPCNT for each server socket. Not supported on OS X.

vast_mgmt_host
Type:

host address

Default:

<None>

Hostname or IP address VAST storage system management VIP.

vast_mgmt_port
Type:

port number

Default:

443

Minimum Value:

0

Maximum Value:

65535

Port for VAST management

vast_vippool_name
Type:

string

Default:

<None>

Name of Virtual IP pool

vast_root_export
Type:

string

Default:

manila

Base path for shares

vast_mgmt_user
Type:

string

Default:

<None>

Username for VAST management

vast_mgmt_password
Type:

string

Default:

<None>

Password for VAST management

vast_api_token
Type:

string

Default:

''

API token for accessing VAST mgmt. If provided, it will be used instead of ‘san_login’ and ‘san_password’.

executor_thread_pool_size
Type:

integer

Default:

64

Size of executor thread pool when executor is threading or eventlet.

Deprecated Variations

Group

Name

DEFAULT

rpc_thread_pool_size

rpc_response_timeout
Type:

integer

Default:

60

Seconds to wait for a response from a call.

transport_url
Type:

string

Default:

rabbit://

The network address and optional user credentials for connecting to the messaging backend, in URL format. The expected format is:

driver://[user:pass@]host:port[,[userN:passN@]hostN:portN]/virtual_host?query

Example: rabbit://rabbitmq:password@127.0.0.1:5672//

For full details on the fields in the URL see the documentation of oslo_messaging.TransportURL at https://docs.openstack.org/oslo.messaging/latest/reference/transport.html

control_exchange
Type:

string

Default:

openstack

The default exchange under which topics are scoped. May be overridden by an exchange name specified in the transport_url option.

rpc_ping_enabled
Type:

boolean

Default:

False

Add an endpoint to answer to ping calls. Endpoint is named oslo_rpc_server_ping

run_external_periodic_tasks
Type:

boolean

Default:

True

Some periodic tasks can be run in a separate process. Should we run them here?

backdoor_port
Type:

string

Default:

<None>

Enable eventlet backdoor. Acceptable values are 0, <port>, and <start>:<end>, where 0 results in listening on a random tcp port number; <port> results in listening on the specified port number (and not enabling backdoor if that port is in use); and <start>:<end> results in listening on the smallest unused port number within the specified range of port numbers. The chosen port is displayed in the service’s log file.

Warning

This option is deprecated for removal. Its value may be silently ignored in the future.

Reason:

The ‘backdoor_port’ option is deprecated and will be removed in a future release.

backdoor_socket
Type:

string

Default:

<None>

Enable eventlet backdoor, using the provided path as a unix socket that can receive connections. This option is mutually exclusive with ‘backdoor_port’ in that only one should be provided. If both are provided then the existence of this option overrides the usage of that option. Inside the path {pid} will be replaced with the PID of the current process.

Warning

This option is deprecated for removal. Its value may be silently ignored in the future.

Reason:

The ‘backdoor_socket’ option is deprecated and will be removed in a future release.

log_options
Type:

boolean

Default:

True

Enables or disables logging values of all registered options when starting a service (at DEBUG level).

graceful_shutdown_timeout
Type:

integer

Default:

60

Specify a timeout after which a gracefully shutdown server will exit. Zero value means endless wait.

api_paste_config
Type:

string

Default:

api-paste.ini

File name for the paste.deploy config for api service

Warning

This option is deprecated for removal. Its value may be silently ignored in the future.

Reason:

The ‘api_paste_config’ option is deprecated and will be removed in a future release.

wsgi_log_format
Type:

string

Default:

%(client_ip)s "%(request_line)s" status: %(status_code)s  len: %(body_length)s time: %(wall_seconds).7f

A python format string that is used as the template to generate log lines. The following values can beformatted into it: client_ip, date_time, request_line, status_code, body_length, wall_seconds.

Warning

This option is deprecated for removal. Its value may be silently ignored in the future.

Reason:

The ‘wsgi_log_format’ option is deprecated and will be removed in a future release.

tcp_keepidle
Type:

integer

Default:

600

Sets the value of TCP_KEEPIDLE in seconds for each server socket. Not supported on OS X.

Warning

This option is deprecated for removal. Its value may be silently ignored in the future.

Reason:

The ‘tcp_keepidle’ option is deprecated and will be removed in a future release.

wsgi_default_pool_size
Type:

integer

Default:

100

Size of the pool of greenthreads used by wsgi

Warning

This option is deprecated for removal. Its value may be silently ignored in the future.

Reason:

The ‘wsgi_default_pool_size’ option is deprecated and will be removed in a future release.

max_header_line
Type:

integer

Default:

16384

Maximum line size of message headers to be accepted. max_header_line may need to be increased when using large tokens (typically those generated when keystone is configured to use PKI tokens with big service catalogs).

Warning

This option is deprecated for removal. Its value may be silently ignored in the future.

Reason:

The ‘max_header_line’ option is deprecated and will be removed in a future release.

wsgi_keep_alive
Type:

boolean

Default:

True

If False, closes the client socket connection explicitly.

Warning

This option is deprecated for removal. Its value may be silently ignored in the future.

Reason:

The ‘wsgi_keep_alive’ option is deprecated and will be removed in a future release.

client_socket_timeout
Type:

integer

Default:

900

Timeout for client connections’ socket operations. If an incoming connection is idle for this number of seconds it will be closed. A value of ‘0’ means wait forever.

Warning

This option is deprecated for removal. Its value may be silently ignored in the future.

Reason:

The ‘client_socket_timeout’ option is deprecated and will be removed in a future release.

wsgi_server_debug
Type:

boolean

Default:

False

True if the server should send exception tracebacks to the clients on 500 errors. If False, the server will respond with empty bodies.

Warning

This option is deprecated for removal. Its value may be silently ignored in the future.

Reason:

The ‘wsgi_server_debug’ option is deprecated and will be removed in a future release.

debug
Type:

boolean

Default:

False

Mutable:

This option can be changed without restarting.

If set to true, the logging level will be set to DEBUG instead of the default INFO level.

log_config_append
Type:

string

Default:

<None>

Mutable:

This option can be changed without restarting.

The name of a logging configuration file. This file is appended to any existing logging configuration files. For details about logging configuration files, see the Python logging module documentation. Note that when logging configuration files are used then all logging configuration is set in the configuration file and other logging configuration options are ignored (for example, log-date-format).

Deprecated Variations

Group

Name

DEFAULT

log-config

DEFAULT

log_config

log_date_format
Type:

string

Default:

%Y-%m-%d %H:%M:%S

Defines the format string for %(asctime)s in log records. Default: the value above . This option is ignored if log_config_append is set.

log_file
Type:

string

Default:

<None>

(Optional) Name of log file to send logging output to. If no default is set, logging will go to stderr as defined by use_stderr. This option is ignored if log_config_append is set.

Deprecated Variations

Group

Name

DEFAULT

logfile

log_dir
Type:

string

Default:

<None>

(Optional) The base directory used for relative log_file paths. This option is ignored if log_config_append is set.

Deprecated Variations

Group

Name

DEFAULT

logdir

use_syslog
Type:

boolean

Default:

False

Use syslog for logging. Existing syslog format is DEPRECATED and will be changed later to honor RFC5424. This option is ignored if log_config_append is set.

use_journal
Type:

boolean

Default:

False

Enable journald for logging. If running in a systemd environment you may wish to enable journal support. Doing so will use the journal native protocol which includes structured metadata in addition to log messages.This option is ignored if log_config_append is set.

syslog_log_facility
Type:

string

Default:

LOG_USER

Syslog facility to receive log lines. This option is ignored if log_config_append is set.

use_json
Type:

boolean

Default:

False

Use JSON formatting for logging. This option is ignored if log_config_append is set.

use_stderr
Type:

boolean

Default:

False

Log output to standard error. This option is ignored if log_config_append is set.

log_color
Type:

boolean

Default:

False

(Optional) Set the ‘color’ key according to log levels. This option takes effect only when logging to stderr or stdout is used. This option is ignored if log_config_append is set.

log_rotate_interval
Type:

integer

Default:

1

The amount of time before the log files are rotated. This option is ignored unless log_rotation_type is set to “interval”.

log_rotate_interval_type
Type:

string

Default:

days

Valid Values:

Seconds, Minutes, Hours, Days, Weekday, Midnight

Rotation interval type. The time of the last file change (or the time when the service was started) is used when scheduling the next rotation.

max_logfile_count
Type:

integer

Default:

30

Maximum number of rotated log files.

max_logfile_size_mb
Type:

integer

Default:

200

Log file maximum size in MB. This option is ignored if “log_rotation_type” is not set to “size”.

log_rotation_type
Type:

string

Default:

none

Valid Values:

interval, size, none

Log rotation type.

Possible values

interval

Rotate logs at predefined time intervals.

size

Rotate logs once they reach a predefined size.

none

Do not rotate log files.

logging_context_format_string
Type:

string

Default:

%(asctime)s.%(msecs)03d %(process)d %(levelname)s %(name)s [%(global_request_id)s %(request_id)s %(user_identity)s] %(instance)s%(message)s

Format string to use for log messages with context. Used by oslo_log.formatters.ContextFormatter

logging_default_format_string
Type:

string

Default:

%(asctime)s.%(msecs)03d %(process)d %(levelname)s %(name)s [-] %(instance)s%(message)s

Format string to use for log messages when context is undefined. Used by oslo_log.formatters.ContextFormatter

logging_debug_format_suffix
Type:

string

Default:

%(funcName)s %(pathname)s:%(lineno)d

Additional data to append to log message when logging level for the message is DEBUG. Used by oslo_log.formatters.ContextFormatter

logging_exception_prefix
Type:

string

Default:

%(asctime)s.%(msecs)03d %(process)d ERROR %(name)s %(instance)s

Prefix each line of exception output with this format. Used by oslo_log.formatters.ContextFormatter

logging_user_identity_format
Type:

string

Default:

%(user)s %(project)s %(domain)s %(system_scope)s %(user_domain)s %(project_domain)s

Defines the format string for %(user_identity)s that is used in logging_context_format_string. Used by oslo_log.formatters.ContextFormatter

default_log_levels
Type:

list

Default:

['amqp=WARN', 'boto=WARN', 'sqlalchemy=WARN', 'suds=INFO', 'oslo.messaging=INFO', 'oslo_messaging=INFO', 'iso8601=WARN', 'requests.packages.urllib3.connectionpool=WARN', 'urllib3.connectionpool=WARN', 'websocket=WARN', 'requests.packages.urllib3.util.retry=WARN', 'urllib3.util.retry=WARN', 'keystonemiddleware=WARN', 'routes.middleware=WARN', 'stevedore=WARN', 'taskflow=WARN', 'keystoneauth=WARN', 'oslo.cache=INFO', 'oslo_policy=INFO', 'dogpile.core.dogpile=INFO']

List of package logging levels in logger=LEVEL pairs. This option is ignored if log_config_append is set.

publish_errors
Type:

boolean

Default:

False

Enables or disables publication of error events.

instance_format
Type:

string

Default:

"[instance: %(uuid)s] "

The format for an instance that is passed with the log message.

instance_uuid_format
Type:

string

Default:

"[instance: %(uuid)s] "

The format for an instance UUID that is passed with the log message.

rate_limit_interval
Type:

integer

Default:

0

Interval, number of seconds, of log rate limiting.

rate_limit_burst
Type:

integer

Default:

0

Maximum number of logged messages per rate_limit_interval.

rate_limit_except_level
Type:

string

Default:

CRITICAL

Valid Values:

CRITICAL, ERROR, INFO, WARNING, DEBUG, ‘’

Log level name used by rate limiting. Logs with level greater or equal to rate_limit_except_level are not filtered. An empty string means that all levels are filtered.

fatal_deprecations
Type:

boolean

Default:

False

Enables or disables fatal status of deprecations.

barbican

endpoint_type
Type:

string

Default:

publicURL

Valid Values:

publicURL, internalURL, adminURL, public, internal, admin

Endpoint type to be used with keystone client calls.

region_name
Type:

string

Default:

<None>

Region name for connecting to keystone for application credential management.

auth_url
Type:

unknown type

Default:

<None>

Authentication URL

auth_type
Type:

unknown type

Default:

<None>

Authentication type to load

Deprecated Variations

Group

Name

barbican

auth_plugin

cafile
Type:

string

Default:

<None>

PEM encoded Certificate Authority to use when verifying HTTPs connections.

certfile
Type:

string

Default:

<None>

PEM encoded client certificate cert file

collect_timing
Type:

boolean

Default:

False

Collect per-API call timing information.

default_domain_id
Type:

unknown type

Default:

<None>

Optional domain ID to use with v3 and v2 parameters. It will be used for both the user and project domain in v3 and ignored in v2 authentication.

default_domain_name
Type:

unknown type

Default:

<None>

Optional domain name to use with v3 API and v2 parameters. It will be used for both the user and project domain in v3 and ignored in v2 authentication.

domain_id
Type:

unknown type

Default:

<None>

Domain ID to scope to

domain_name
Type:

unknown type

Default:

<None>

Domain name to scope to

insecure
Type:

boolean

Default:

False

Verify HTTPS connections.

keyfile
Type:

string

Default:

<None>

PEM encoded client certificate key file

password
Type:

unknown type

Default:

<None>

User’s password

project_domain_id
Type:

unknown type

Default:

<None>

Domain ID containing project

project_domain_name
Type:

unknown type

Default:

<None>

Domain name containing project

project_id
Type:

unknown type

Default:

<None>

Project ID to scope to

Deprecated Variations

Group

Name

barbican

tenant-id

barbican

tenant_id

project_name
Type:

unknown type

Default:

<None>

Project name to scope to

Deprecated Variations

Group

Name

barbican

tenant-name

barbican

tenant_name

split_loggers
Type:

boolean

Default:

False

Log requests to multiple loggers.

system_scope
Type:

unknown type

Default:

<None>

Scope for system operations

timeout
Type:

floating point

Default:

<None>

Timeout value for http requests

trust_id
Type:

unknown type

Default:

<None>

ID of the trust to use as a trustee use

user_domain_id
Type:

unknown type

Default:

<None>

User’s domain id

user_domain_name
Type:

unknown type

Default:

<None>

User’s domain name

user_id
Type:

unknown type

Default:

<None>

User id

username
Type:

unknown type

Default:

<None>

Username

Deprecated Variations

Group

Name

barbican

user-name

barbican

user_name

barbican_endpoint
Type:

URI

Default:

<None>

Use this endpoint to connect to Barbican, for example: “http://localhost:9311/

barbican_api_version
Type:

string

Default:

<None>

Version of the Barbican API, for example: “v1”

auth_endpoint
Type:

URI

Default:

http://localhost/identity/v3

Use this endpoint to connect to Keystone

Deprecated Variations

Group

Name

key_manager

auth_url

retry_delay
Type:

integer

Default:

1

Number of seconds to wait before retrying poll for key creation completion

number_of_retries
Type:

integer

Default:

60

Number of times to retry poll for key creation completion

verify_ssl
Type:

boolean

Default:

True

Specifies if insecure TLS (https) requests. If False, the server’s certificate will not be validated, if True, we can set the verify_ssl_path config meanwhile.

verify_ssl_path
Type:

string

Default:

<None>

A path to a bundle or CA certs to check against, or None for requests to attempt to locate and use certificates which verify_ssh is True. If verify_ssl is False, this is ignored.

barbican_endpoint_type
Type:

string

Default:

public

Valid Values:

public, internal, admin

Specifies the type of endpoint.

barbican_region_name
Type:

string

Default:

<None>

Specifies the region of the chosen endpoint.

send_service_user_token
Type:

boolean

Default:

False

When True, if sending a user token to a REST API, also send a service token.

Nova often reuses the user token provided to the nova-api to talk to other REST APIs, such as Cinder, Glance and Neutron. It is possible that while the user token was valid when the request was made to Nova, the token may expire before it reaches the other service. To avoid any failures, and to make it clear it is Nova calling the service on the user’s behalf, we include a service token along with the user token. Should the user’s token have expired, a valid service token ensures the REST API request will still be accepted by the keystone middleware.

cafile
Type:

string

Default:

<None>

PEM encoded Certificate Authority to use when verifying HTTPs connections.

certfile
Type:

string

Default:

<None>

PEM encoded client certificate cert file

keyfile
Type:

string

Default:

<None>

PEM encoded client certificate key file

insecure
Type:

boolean

Default:

False

Verify HTTPS connections.

timeout
Type:

floating point

Default:

<None>

Timeout value for http requests

collect_timing
Type:

boolean

Default:

False

Collect per-API call timing information.

split_loggers
Type:

boolean

Default:

False

Log requests to multiple loggers.

barbican_service_user

cafile
Type:

string

Default:

<None>

PEM encoded Certificate Authority to use when verifying HTTPs connections.

certfile
Type:

string

Default:

<None>

PEM encoded client certificate cert file

keyfile
Type:

string

Default:

<None>

PEM encoded client certificate key file

insecure
Type:

boolean

Default:

False

Verify HTTPS connections.

timeout
Type:

floating point

Default:

<None>

Timeout value for http requests

collect_timing
Type:

boolean

Default:

False

Collect per-API call timing information.

split_loggers
Type:

boolean

Default:

False

Log requests to multiple loggers.

auth_type
Type:

unknown type

Default:

<None>

Authentication type to load

Deprecated Variations

Group

Name

barbican_service_user

auth_plugin

auth_section
Type:

unknown type

Default:

<None>

Config Section from which to load plugin specific options

cinder

cross_az_attach
Type:

boolean

Default:

True

Allow attaching between instances and volumes in different availability zones.

http_retries
Type:

integer

Default:

3

Number of cinderclient retries on failed HTTP calls.

endpoint_type
Type:

string

Default:

publicURL

Valid Values:

publicURL, internalURL, adminURL, public, internal, admin

Endpoint type to be used with cinder client calls.

region_name
Type:

string

Default:

<None>

Region name for connecting to cinder.

auth_url
Type:

unknown type

Default:

<None>

Authentication URL

auth_type
Type:

unknown type

Default:

<None>

Authentication type to load

Deprecated Variations

Group

Name

cinder

auth_plugin

cafile
Type:

string

Default:

<None>

PEM encoded Certificate Authority to use when verifying HTTPs connections.

certfile
Type:

string

Default:

<None>

PEM encoded client certificate cert file

collect_timing
Type:

boolean

Default:

False

Collect per-API call timing information.

default_domain_id
Type:

unknown type

Default:

<None>

Optional domain ID to use with v3 and v2 parameters. It will be used for both the user and project domain in v3 and ignored in v2 authentication.

default_domain_name
Type:

unknown type

Default:

<None>

Optional domain name to use with v3 API and v2 parameters. It will be used for both the user and project domain in v3 and ignored in v2 authentication.

domain_id
Type:

unknown type

Default:

<None>

Domain ID to scope to

domain_name
Type:

unknown type

Default:

<None>

Domain name to scope to

insecure
Type:

boolean

Default:

False

Verify HTTPS connections.

keyfile
Type:

string

Default:

<None>

PEM encoded client certificate key file

password
Type:

unknown type

Default:

<None>

User’s password

project_domain_id
Type:

unknown type

Default:

<None>

Domain ID containing project

project_domain_name
Type:

unknown type

Default:

<None>

Domain name containing project

project_id
Type:

unknown type

Default:

<None>

Project ID to scope to

Deprecated Variations

Group

Name

cinder

tenant-id

cinder

tenant_id

project_name
Type:

unknown type

Default:

<None>

Project name to scope to

Deprecated Variations

Group

Name

cinder

tenant-name

cinder

tenant_name

split_loggers
Type:

boolean

Default:

False

Log requests to multiple loggers.

system_scope
Type:

unknown type

Default:

<None>

Scope for system operations

timeout
Type:

floating point

Default:

<None>

Timeout value for http requests

trust_id
Type:

unknown type

Default:

<None>

ID of the trust to use as a trustee use

user_domain_id
Type:

unknown type

Default:

<None>

User’s domain id

user_domain_name
Type:

unknown type

Default:

<None>

User’s domain name

user_id
Type:

unknown type

Default:

<None>

User id

username
Type:

unknown type

Default:

<None>

Username

Deprecated Variations

Group

Name

cinder

user-name

cinder

user_name

cors

allowed_origin
Type:

list

Default:

<None>

Indicate whether this resource may be shared with the domain received in the requests “origin” header. Format: “<protocol>://<host>[:<port>]”, no trailing slash. Example: https://horizon.example.com

allow_credentials
Type:

boolean

Default:

True

Indicate that the actual request can include user credentials

expose_headers
Type:

list

Default:

['X-Auth-Token', 'X-OpenStack-Request-ID', 'X-Openstack-Manila-Api-Version', 'X-OpenStack-Manila-API-Experimental', 'X-Subject-Token', 'X-Service-Token']

Indicate which headers are safe to expose to the API. Defaults to HTTP Simple Headers.

max_age
Type:

integer

Default:

3600

Maximum cache age of CORS preflight requests.

allow_methods
Type:

list

Default:

['GET', 'PUT', 'POST', 'DELETE', 'PATCH']

Indicate which methods can be used during the actual request.

allow_headers
Type:

list

Default:

['X-Auth-Token', 'X-OpenStack-Request-ID', 'X-Openstack-Manila-Api-Version', 'X-OpenStack-Manila-API-Experimental', 'X-Identity-Status', 'X-Roles', 'X-Service-Catalog', 'X-User-Id', 'X-Tenant-Id']

Indicate which header field names may be used during the actual request.

database

sqlite_synchronous
Type:

boolean

Default:

True

If True, SQLite uses synchronous mode.

backend
Type:

string

Default:

sqlalchemy

The back end to use for the database.

connection
Type:

string

Default:

<None>

The SQLAlchemy connection string to use to connect to the database.

slave_connection
Type:

string

Default:

<None>

The SQLAlchemy connection string to use to connect to the slave database.

asyncio_connection
Type:

string

Default:

<None>

The SQLAlchemy asyncio connection string to use to connect to the database.

asyncio_slave_connection
Type:

string

Default:

<None>

The SQLAlchemy asyncio connection string to use to connect to the slave database.

synchronous_reader
Type:

boolean

Default:

True

Whether or not to assume a reader context needs to guarantee it can read data committed by a writer assuming replication lag is present; defaults to True. When False, a reader context works the same as async_reader and will select the slave database if present. When using a galera cluster, this can be set to False only if you set mysql_wsrep_sync_wait to 1 (this will guarantee that the reader will wait until writesets are committed).Note that this may incur a performance degradation within the galera cluster. Note also that this parameter has no effect if you do not set any slave_connection.

mysql_sql_mode
Type:

string

Default:

TRADITIONAL

The SQL mode to be used for MySQL sessions. This option, including the default, overrides any server-set SQL mode. To use whatever SQL mode is set by the server configuration, set this to no value. Example: mysql_sql_mode=

mysql_wsrep_sync_wait
Type:

integer

Default:

<None>

For Galera only, configure wsrep_sync_wait causality checks on new connections. Default is None, meaning don’t configure any setting.

connection_recycle_time
Type:

integer

Default:

3600

Connections which have been present in the connection pool longer than this number of seconds will be replaced with a new one the next time they are checked out from the pool.

max_pool_size
Type:

integer

Default:

5

Maximum number of SQL connections to keep open in a pool. Setting a value of 0 indicates no limit.

max_retries
Type:

integer

Default:

10

Maximum number of database connection retries during startup. Set to -1 to specify an infinite retry count.

retry_interval
Type:

integer

Default:

10

Interval between retries of opening a SQL connection.

max_overflow
Type:

integer

Default:

50

If set, use this value for max_overflow with SQLAlchemy.

connection_debug
Type:

integer

Default:

0

Minimum Value:

0

Maximum Value:

100

Verbosity of SQL debugging information: 0=None, 100=Everything.

connection_trace
Type:

boolean

Default:

False

Add Python stack traces to SQL as comment strings.

pool_timeout
Type:

integer

Default:

<None>

If set, use this value for pool_timeout with SQLAlchemy.

use_db_reconnect
Type:

boolean

Default:

False

Enable the experimental use of database reconnect on connection lost.

db_retry_interval
Type:

integer

Default:

1

Seconds between retries of a database transaction.

db_inc_retry_interval
Type:

boolean

Default:

True

If True, increases the interval between retries of a database operation up to db_max_retry_interval.

db_max_retry_interval
Type:

integer

Default:

10

If db_inc_retry_interval is set, the maximum seconds between retries of a database operation.

db_max_retries
Type:

integer

Default:

20

Maximum retries in case of connection error or deadlock error before error is raised. Set to -1 to specify an infinite retry count.

connection_parameters
Type:

string

Default:

''

Optional URL parameters to append onto the connection URL at connect time; specify as param1=value1&param2=value2&…

glance

api_microversion
Type:

string

Default:

2

Version of Glance API to be used.

region_name
Type:

string

Default:

RegionOne

Region name for connecting to glance.

endpoint_type
Type:

string

Default:

publicURL

Valid Values:

publicURL, internalURL, adminURL, public, internal, admin

Endpoint type to be used with glance client calls.

auth_url
Type:

unknown type

Default:

<None>

Authentication URL

auth_type
Type:

unknown type

Default:

<None>

Authentication type to load

Deprecated Variations

Group

Name

glance

auth_plugin

cafile
Type:

string

Default:

<None>

PEM encoded Certificate Authority to use when verifying HTTPs connections.

certfile
Type:

string

Default:

<None>

PEM encoded client certificate cert file

collect_timing
Type:

boolean

Default:

False

Collect per-API call timing information.

default_domain_id
Type:

unknown type

Default:

<None>

Optional domain ID to use with v3 and v2 parameters. It will be used for both the user and project domain in v3 and ignored in v2 authentication.

default_domain_name
Type:

unknown type

Default:

<None>

Optional domain name to use with v3 API and v2 parameters. It will be used for both the user and project domain in v3 and ignored in v2 authentication.

domain_id
Type:

unknown type

Default:

<None>

Domain ID to scope to

domain_name
Type:

unknown type

Default:

<None>

Domain name to scope to

insecure
Type:

boolean

Default:

False

Verify HTTPS connections.

keyfile
Type:

string

Default:

<None>

PEM encoded client certificate key file

password
Type:

unknown type

Default:

<None>

User’s password

project_domain_id
Type:

unknown type

Default:

<None>

Domain ID containing project

project_domain_name
Type:

unknown type

Default:

<None>

Domain name containing project

project_id
Type:

unknown type

Default:

<None>

Project ID to scope to

Deprecated Variations

Group

Name

glance

tenant-id

glance

tenant_id

project_name
Type:

unknown type

Default:

<None>

Project name to scope to

Deprecated Variations

Group

Name

glance

tenant-name

glance

tenant_name

split_loggers
Type:

boolean

Default:

False

Log requests to multiple loggers.

system_scope
Type:

unknown type

Default:

<None>

Scope for system operations

timeout
Type:

floating point

Default:

<None>

Timeout value for http requests

trust_id
Type:

unknown type

Default:

<None>

ID of the trust to use as a trustee use

user_domain_id
Type:

unknown type

Default:

<None>

User’s domain id

user_domain_name
Type:

unknown type

Default:

<None>

User’s domain name

user_id
Type:

unknown type

Default:

<None>

User id

username
Type:

unknown type

Default:

<None>

Username

Deprecated Variations

Group

Name

glance

user-name

glance

user_name

healthcheck

detailed
Type:

boolean

Default:

False

Show more detailed information as part of the response. Security note: Enabling this option may expose sensitive details about the service being monitored. Be sure to verify that it will not violate your security policies.

backends
Type:

list

Default:

[]

Additional backends that can perform health checks and report that information back as part of a request.

allowed_source_ranges
Type:

list

Default:

[]

A list of network addresses to limit source ip allowed to access healthcheck information. Any request from ip outside of these network addresses are ignored.

ignore_proxied_requests
Type:

boolean

Default:

False

Ignore requests with proxy headers.

disable_by_file_path
Type:

string

Default:

<None>

Check the presence of a file to determine if an application is running on a port. Used by DisableByFileHealthcheck plugin.

disable_by_file_paths
Type:

list

Default:

[]

Check the presence of a file based on a port to determine if an application is running on a port. Expects a “port:path” list of strings. Used by DisableByFilesPortsHealthcheck plugin.

enable_by_file_paths
Type:

list

Default:

[]

Check the presence of files. Used by EnableByFilesHealthcheck plugin.

key_manager

backend
Type:

string

Default:

barbican

Specify the key manager implementation. Options are “barbican” and “vault”. Default is “barbican”. Will support the values earlier set using [key_manager]/api_class for some time.

Deprecated Variations

Group

Name

key_manager

api_class

auth_type
Type:

string

Default:

<None>

Valid Values:

token, password, keystone_token, keystone_password

The type of authentication credential to create. Required if no context is passed to the credential factory.

token
Type:

string

Default:

<None>

Token for authentication. Required for ‘token’ and ‘keystone_token’ auth_type if no context is passed to the credential factory.

username
Type:

string

Default:

<None>

Username for authentication. Required for ‘password’ auth_type. Optional for the ‘keystone_password’ auth_type.

password
Type:

string

Default:

<None>

Password for authentication. Required for ‘password’ and ‘keystone_password’ auth_type.

auth_url
Type:

URI

Default:

<None>

Use this endpoint to connect to Keystone.

user_id
Type:

string

Default:

<None>

User ID for authentication. Optional for ‘keystone_token’ and ‘keystone_password’ auth_type.

user_domain_id
Type:

string

Default:

<None>

User’s domain ID for authentication. Optional for ‘keystone_token’ and ‘keystone_password’ auth_type.

user_domain_name
Type:

string

Default:

<None>

User’s domain name for authentication. Optional for ‘keystone_token’ and ‘keystone_password’ auth_type.

trust_id
Type:

string

Default:

<None>

Trust ID for trust scoping. Optional for ‘keystone_token’ and ‘keystone_password’ auth_type.

domain_id
Type:

string

Default:

<None>

Domain ID for domain scoping. Optional for ‘keystone_token’ and ‘keystone_password’ auth_type.

domain_name
Type:

string

Default:

<None>

Domain name for domain scoping. Optional for ‘keystone_token’ and ‘keystone_password’ auth_type.

project_id
Type:

string

Default:

<None>

Project ID for project scoping. Optional for ‘keystone_token’ and ‘keystone_password’ auth_type.

project_name
Type:

string

Default:

<None>

Project name for project scoping. Optional for ‘keystone_token’ and ‘keystone_password’ auth_type.

project_domain_id
Type:

string

Default:

<None>

Project’s domain ID for project. Optional for ‘keystone_token’ and ‘keystone_password’ auth_type.

project_domain_name
Type:

string

Default:

<None>

Project’s domain name for project. Optional for ‘keystone_token’ and ‘keystone_password’ auth_type.

reauthenticate
Type:

boolean

Default:

True

Allow fetching a new token if the current one is going to expire. Optional for ‘keystone_token’ and ‘keystone_password’ auth_type.

keystone_authtoken

www_authenticate_uri
Type:

string

Default:

<None>

Complete “public” Identity API endpoint. This endpoint should not be an “admin” endpoint, as it should be accessible by all end users. Unauthenticated clients are redirected to this endpoint to authenticate. Although this endpoint should ideally be unversioned, client support in the wild varies.

auth_version
Type:

string

Default:

<None>

API version of the Identity API endpoint.

interface
Type:

string

Default:

internal

Interface to use for the Identity API endpoint. Valid values are “public”, “internal” (default) or “admin”.

delay_auth_decision
Type:

boolean

Default:

False

Do not handle authorization requests within the middleware, but delegate the authorization decision to downstream WSGI components.

http_connect_timeout
Type:

integer

Default:

<None>

Request timeout value for communicating with Identity API server.

http_request_max_retries
Type:

integer

Default:

3

How many times are we trying to reconnect when communicating with Identity API Server.

cache
Type:

string

Default:

<None>

Request environment key where the Swift cache object is stored. When auth_token middleware is deployed with a Swift cache, use this option to have the middleware share a caching backend with swift. Otherwise, use the memcached_servers option instead.

certfile
Type:

string

Default:

<None>

Required if identity server requires client certificate

keyfile
Type:

string

Default:

<None>

Required if identity server requires client certificate

cafile
Type:

string

Default:

<None>

A PEM encoded Certificate Authority to use when verifying HTTPs connections. Defaults to system CAs.

insecure
Type:

boolean

Default:

False

Verify HTTPS connections.

region_name
Type:

string

Default:

<None>

The region in which the identity server can be found.

memcached_servers
Type:

list

Default:

<None>

Optionally specify a list of memcached server(s) to use for caching. If left undefined, tokens will instead be cached in-process.

Deprecated Variations

Group

Name

keystone_authtoken

memcache_servers

token_cache_time
Type:

integer

Default:

300

In order to prevent excessive effort spent validating tokens, the middleware caches previously-seen tokens for a configurable duration (in seconds). Set to -1 to disable caching completely.

memcache_security_strategy
Type:

string

Default:

None

Valid Values:

None, MAC, ENCRYPT

(Optional) If defined, indicate whether token data should be authenticated or authenticated and encrypted. If MAC, token data is authenticated (with HMAC) in the cache. If ENCRYPT, token data is encrypted and authenticated in the cache. If the value is not one of these options or empty, auth_token will raise an exception on initialization.

memcache_secret_key
Type:

string

Default:

<None>

(Optional, mandatory if memcache_security_strategy is defined) This string is used for key derivation.

memcache_tls_enabled
Type:

boolean

Default:

False

(Optional) Global toggle for TLS usage when comunicating with the caching servers.

memcache_tls_cafile
Type:

string

Default:

<None>

(Optional) Path to a file of concatenated CA certificates in PEM format necessary to establish the caching server’s authenticity. If tls_enabled is False, this option is ignored.

memcache_tls_certfile
Type:

string

Default:

<None>

(Optional) Path to a single file in PEM format containing the client’s certificate as well as any number of CA certificates needed to establish the certificate’s authenticity. This file is only required when client side authentication is necessary. If tls_enabled is False, this option is ignored.

memcache_tls_keyfile
Type:

string

Default:

<None>

(Optional) Path to a single file containing the client’s private key in. Otherwhise the private key will be taken from the file specified in tls_certfile. If tls_enabled is False, this option is ignored.

memcache_tls_allowed_ciphers
Type:

string

Default:

<None>

(Optional) Set the available ciphers for sockets created with the TLS context. It should be a string in the OpenSSL cipher list format. If not specified, all OpenSSL enabled ciphers will be available.

memcache_pool_dead_retry
Type:

integer

Default:

300

(Optional) Number of seconds memcached server is considered dead before it is tried again.

memcache_pool_maxsize
Type:

integer

Default:

10

(Optional) Maximum total number of open connections to every memcached server.

memcache_pool_socket_timeout
Type:

integer

Default:

3

(Optional) Socket timeout in seconds for communicating with a memcached server.

memcache_pool_unused_timeout
Type:

integer

Default:

60

(Optional) Number of seconds a connection to memcached is held unused in the pool before it is closed.

memcache_pool_conn_get_timeout
Type:

integer

Default:

10

(Optional) Number of seconds that an operation will wait to get a memcached client connection from the pool.

memcache_use_advanced_pool
Type:

boolean

Default:

True

(Optional) Use the advanced (eventlet safe) memcached client pool.

include_service_catalog
Type:

boolean

Default:

True

(Optional) Indicate whether to set the X-Service-Catalog header. If False, middleware will not ask for service catalog on token validation and will not set the X-Service-Catalog header.

enforce_token_bind
Type:

string

Default:

permissive

Used to control the use and type of token binding. Can be set to: “disabled” to not check token binding. “permissive” (default) to validate binding information if the bind type is of a form known to the server and ignore it if not. “strict” like “permissive” but if the bind type is unknown the token will be rejected. “required” any form of token binding is needed to be allowed. Finally the name of a binding method that must be present in tokens.

service_token_roles
Type:

list

Default:

['service']

A choice of roles that must be present in a service token. Service tokens are allowed to request that an expired token can be used and so this check should tightly control that only actual services should be sending this token. Roles here are applied as an ANY check so any role in this list must be present. For backwards compatibility reasons this currently only affects the allow_expired check.

service_token_roles_required
Type:

boolean

Default:

True

When set to True, service tokens must contain a role from the service_token_roles list to be considered valid. This prevents end-user tokens from being used as service tokens and ensures proper service-to-service authentication. Setting this to False is NOT RECOMMENDED as it allows any valid token to be used as a service token, which can bypass access-rule checks and weaken composite-auth protections.

service_type
Type:

string

Default:

<None>

The name or type of the service as it appears in the service catalog. This is used to validate tokens that have restricted access rules.

memcache_sasl_enabled
Type:

boolean

Default:

False

Enable the SASL(Simple Authentication and Security Layer) if the SASL_enable is true, else disable.

memcache_username
Type:

string

Default:

''

the user name for the SASL

memcache_password
Type:

string

Default:

''

the username password for SASL

auth_type
Type:

unknown type

Default:

<None>

Authentication type to load

Deprecated Variations

Group

Name

keystone_authtoken

auth_plugin

auth_section
Type:

unknown type

Default:

<None>

Config Section from which to load plugin specific options

neutron

url
Type:

string

Default:

<None>

URL for connecting to neutron.

url_timeout
Type:

integer

Default:

30

Timeout value for connecting to neutron in seconds.

Warning

This option is deprecated for removal since Yoga. Its value may be silently ignored in the future.

Reason:

This parameter has had no effect since 2.0.0. The timeout parameter should be used instead.

auth_strategy
Type:

string

Default:

keystone

Auth strategy for connecting to neutron in admin context.

Warning

This option is deprecated for removal since Yoga. Its value may be silently ignored in the future.

Reason:

This parameter has had no effect since 2.0.0. Use the auth_type parameter to select authentication type

endpoint_type
Type:

string

Default:

publicURL

Valid Values:

publicURL, internalURL, adminURL, public, internal, admin

Endpoint type to be used with neutron client calls.

region_name
Type:

string

Default:

<None>

Region name for connecting to neutron in admin context.

auth_url
Type:

unknown type

Default:

<None>

Authentication URL

auth_type
Type:

unknown type

Default:

<None>

Authentication type to load

Deprecated Variations

Group

Name

neutron

auth_plugin

cafile
Type:

string

Default:

<None>

PEM encoded Certificate Authority to use when verifying HTTPs connections.

certfile
Type:

string

Default:

<None>

PEM encoded client certificate cert file

collect_timing
Type:

boolean

Default:

False

Collect per-API call timing information.

default_domain_id
Type:

unknown type

Default:

<None>

Optional domain ID to use with v3 and v2 parameters. It will be used for both the user and project domain in v3 and ignored in v2 authentication.

default_domain_name
Type:

unknown type

Default:

<None>

Optional domain name to use with v3 API and v2 parameters. It will be used for both the user and project domain in v3 and ignored in v2 authentication.

domain_id
Type:

unknown type

Default:

<None>

Domain ID to scope to

domain_name
Type:

unknown type

Default:

<None>

Domain name to scope to

insecure
Type:

boolean

Default:

False

Verify HTTPS connections.

keyfile
Type:

string

Default:

<None>

PEM encoded client certificate key file

password
Type:

unknown type

Default:

<None>

User’s password

project_domain_id
Type:

unknown type

Default:

<None>

Domain ID containing project

project_domain_name
Type:

unknown type

Default:

<None>

Domain name containing project

project_id
Type:

unknown type

Default:

<None>

Project ID to scope to

Deprecated Variations

Group

Name

neutron

tenant-id

neutron

tenant_id

project_name
Type:

unknown type

Default:

<None>

Project name to scope to

Deprecated Variations

Group

Name

neutron

tenant-name

neutron

tenant_name

split_loggers
Type:

boolean

Default:

False

Log requests to multiple loggers.

system_scope
Type:

unknown type

Default:

<None>

Scope for system operations

timeout
Type:

floating point

Default:

<None>

Timeout value for http requests

trust_id
Type:

unknown type

Default:

<None>

ID of the trust to use as a trustee use

user_domain_id
Type:

unknown type

Default:

<None>

User’s domain id

user_domain_name
Type:

unknown type

Default:

<None>

User’s domain name

user_id
Type:

unknown type

Default:

<None>

User id

username
Type:

unknown type

Default:

<None>

Username

Deprecated Variations

Group

Name

neutron

user-name

neutron

user_name

nova

api_microversion
Type:

string

Default:

2.10

Version of Nova API to be used.

endpoint_type
Type:

string

Default:

publicURL

Valid Values:

publicURL, internalURL, adminURL, public, internal, admin

Endpoint type to be used with nova client calls.

region_name
Type:

string

Default:

<None>

Region name for connecting to nova.

auth_url
Type:

unknown type

Default:

<None>

Authentication URL

auth_type
Type:

unknown type

Default:

<None>

Authentication type to load

Deprecated Variations

Group

Name

nova

auth_plugin

cafile
Type:

string

Default:

<None>

PEM encoded Certificate Authority to use when verifying HTTPs connections.

certfile
Type:

string

Default:

<None>

PEM encoded client certificate cert file

collect_timing
Type:

boolean

Default:

False

Collect per-API call timing information.

default_domain_id
Type:

unknown type

Default:

<None>

Optional domain ID to use with v3 and v2 parameters. It will be used for both the user and project domain in v3 and ignored in v2 authentication.

default_domain_name
Type:

unknown type

Default:

<None>

Optional domain name to use with v3 API and v2 parameters. It will be used for both the user and project domain in v3 and ignored in v2 authentication.

domain_id
Type:

unknown type

Default:

<None>

Domain ID to scope to

domain_name
Type:

unknown type

Default:

<None>

Domain name to scope to

insecure
Type:

boolean

Default:

False

Verify HTTPS connections.

keyfile
Type:

string

Default:

<None>

PEM encoded client certificate key file

password
Type:

unknown type

Default:

<None>

User’s password

project_domain_id
Type:

unknown type

Default:

<None>

Domain ID containing project

project_domain_name
Type:

unknown type

Default:

<None>

Domain name containing project

project_id
Type:

unknown type

Default:

<None>

Project ID to scope to

Deprecated Variations

Group

Name

nova

tenant-id

nova

tenant_id

project_name
Type:

unknown type

Default:

<None>

Project name to scope to

Deprecated Variations

Group

Name

nova

tenant-name

nova

tenant_name

split_loggers
Type:

boolean

Default:

False

Log requests to multiple loggers.

system_scope
Type:

unknown type

Default:

<None>

Scope for system operations

timeout
Type:

floating point

Default:

<None>

Timeout value for http requests

trust_id
Type:

unknown type

Default:

<None>

ID of the trust to use as a trustee use

user_domain_id
Type:

unknown type

Default:

<None>

User’s domain id

user_domain_name
Type:

unknown type

Default:

<None>

User’s domain name

user_id
Type:

unknown type

Default:

<None>

User id

username
Type:

unknown type

Default:

<None>

Username

Deprecated Variations

Group

Name

nova

user-name

nova

user_name

oslo_concurrency

disable_process_locking
Type:

boolean

Default:

False

Enables or disables inter-process locks.

lock_path
Type:

string

Default:

<None>

Directory to use for lock files. For security, the specified directory should only be writable by the user running the processes that need locking. Defaults to environment variable OSLO_LOCK_PATH. If external locks are used, a lock path must be set.

oslo_messaging_kafka

kafka_max_fetch_bytes
Type:

integer

Default:

1048576

Max fetch bytes of Kafka consumer

kafka_consumer_timeout
Type:

floating point

Default:

1.0

Default timeout(s) for Kafka consumers

consumer_group
Type:

string

Default:

oslo_messaging_consumer

Group id for Kafka consumer. Consumers in one group will coordinate message consumption

producer_batch_timeout
Type:

floating point

Default:

0.0

Upper bound on the delay for KafkaProducer batching in seconds

producer_batch_size
Type:

integer

Default:

16384

Size of batch for the producer async send

compression_codec
Type:

string

Default:

none

Valid Values:

none, gzip, snappy, lz4, zstd

The compression codec for all data generated by the producer. If not set, compression will not be used. Note that the allowed values of this depend on the kafka version

enable_auto_commit
Type:

boolean

Default:

False

Enable asynchronous consumer commits

max_poll_records
Type:

integer

Default:

500

The maximum number of records returned in a poll call

security_protocol
Type:

string

Default:

PLAINTEXT

Valid Values:

PLAINTEXT, SASL_PLAINTEXT, SSL, SASL_SSL

Protocol used to communicate with brokers

sasl_mechanism
Type:

string

Default:

PLAIN

Mechanism when security protocol is SASL

ssl_cafile
Type:

string

Default:

''

CA certificate PEM file used to verify the server certificate

ssl_client_cert_file
Type:

string

Default:

''

Client certificate PEM file used for authentication.

ssl_client_key_file
Type:

string

Default:

''

Client key PEM file used for authentication.

ssl_client_key_password
Type:

string

Default:

''

Client key password file used for authentication.

oslo_messaging_notifications

driver
Type:

multi-valued

Default:

''

The Drivers(s) to handle sending notifications. Possible values are messaging, messagingv2, routing, log, test, noop

transport_url
Type:

string

Default:

<None>

A URL representing the messaging driver to use for notifications. If not set, we fall back to the same configuration used for RPC.

topics
Type:

list

Default:

['notifications']

AMQP topic used for OpenStack notifications.

retry
Type:

integer

Default:

-1

The maximum number of attempts to re-send a notification message which failed to be delivered due to a recoverable error. 0 - No retry, -1 - indefinite

oslo_messaging_rabbit

amqp_durable_queues
Type:

boolean

Default:

False

Use durable queues in AMQP. If rabbit_quorum_queue is enabled, queues will be durable and this value will be ignored.

amqp_auto_delete
Type:

boolean

Default:

False

Auto-delete queues in AMQP.

rpc_conn_pool_size
Type:

integer

Default:

30

Minimum Value:

1

Size of RPC connection pool.

conn_pool_min_size
Type:

integer

Default:

2

The pool size limit for connections expiration policy

conn_pool_ttl
Type:

integer

Default:

1200

The time-to-live in sec of idle connections in the pool

ssl
Type:

boolean

Default:

False

Connect over SSL.

ssl_version
Type:

string

Default:

''

SSL version to use (valid only if SSL enabled). Valid values are TLSv1 and SSLv23. SSLv2, SSLv3, TLSv1_1, and TLSv1_2 may be available on some distributions.

ssl_key_file
Type:

string

Default:

''

SSL key file (valid only if SSL enabled).

ssl_cert_file
Type:

string

Default:

''

SSL cert file (valid only if SSL enabled).

ssl_ca_file
Type:

string

Default:

''

SSL certification authority file (valid only if SSL enabled).

ssl_enforce_hostname_verification
Type:

boolean

Default:

True

When true, verify the broker hostname against the certificate when ssl_ca_file is set. When false, ssl with ssl_ca_file still validates the certificate chain but does not verify the broker hostname. ssl=true without ssl_ca_file never enables hostname verification.

Warning

This option is deprecated for removal. Its value may be silently ignored in the future.

Reason:

Verification is always enabled now

ssl_enforce_fips_mode
Type:

boolean

Default:

False

Global toggle for enforcing the OpenSSL FIPS mode. This feature requires Python support. This is available in Python 3.9 in all environments and may have been backported to older Python versions on select environments. If the Python executable used does not support OpenSSL FIPS mode, an exception will be raised.

Warning

This option is deprecated for removal. Its value may be silently ignored in the future.

Reason:

FIPS_mode_set API was removed in OpenSSL 3.0.0. This option has no effect now.

kombu_reconnect_delay
Type:

floating point

Default:

1.0

Minimum Value:

0.0

Maximum Value:

4.5

How long to wait (in seconds) before reconnecting in response to an AMQP consumer cancel notification.

kombu_reconnect_splay
Type:

floating point

Default:

0.0

Minimum Value:

0.0

Random time to wait for when reconnecting in response to an AMQP consumer cancel notification.

kombu_compression
Type:

string

Default:

<None>

EXPERIMENTAL: Possible values are: gzip, bz2. If not set compression will not be used. This option may not be available in future versions.

kombu_missing_consumer_retry_timeout
Type:

integer

Default:

60

How long to wait a missing client before abandoning to send it its replies. This value should not be longer than rpc_response_timeout.

Deprecated Variations

Group

Name

oslo_messaging_rabbit

kombu_reconnect_timeout

kombu_failover_strategy
Type:

string

Default:

round-robin

Valid Values:

round-robin, shuffle

Determines how the next RabbitMQ node is chosen in case the one we are currently connected to becomes unavailable. Takes effect only if more than one RabbitMQ node is provided in config.

rabbit_login_method
Type:

string

Default:

AMQPLAIN

Valid Values:

PLAIN, AMQPLAIN, EXTERNAL, RABBIT-CR-DEMO

The RabbitMQ login method.

rabbit_retry_interval
Type:

integer

Default:

1

Minimum Value:

1

How frequently to retry connecting with RabbitMQ.

rabbit_retry_backoff
Type:

integer

Default:

2

Minimum Value:

0

How long to backoff for between retries when connecting to RabbitMQ.

rabbit_interval_max
Type:

integer

Default:

30

Minimum Value:

1

Maximum interval of RabbitMQ connection retries.

rabbit_ha_queues
Type:

boolean

Default:

False

Try to use HA queues in RabbitMQ (x-ha-policy: all). If you change this option, you must wipe the RabbitMQ database. In RabbitMQ 3.0, queue mirroring is no longer controlled by the x-ha-policy argument when declaring a queue. If you just want to make sure that all queues (except those with auto-generated names) are mirrored across all nodes, run: “rabbitmqctl set_policy HA ‘^(?!amq.).*’ ‘{“ha-mode”: “all”}’ “

rabbit_quorum_queue
Type:

boolean

Default:

False

Use quorum queues in RabbitMQ (x-queue-type: quorum). The quorum queue is a modern queue type for RabbitMQ implementing a durable, replicated FIFO queue based on the Raft consensus algorithm. It is available as of RabbitMQ 3.8.0. If set this option will conflict with the HA queues (rabbit_ha_queues) aka mirrored queues, in other words the HA queues should be disabled. Quorum queues are also durable by default so the amqp_durable_queues option is ignored when this option is enabled.

rabbit_transient_quorum_queue
Type:

boolean

Default:

False

Use quorum queues for transients queues in RabbitMQ. Enabling this option will then make sure those queues are also using quorum kind of rabbit queues, which are HA by default.

rabbit_quorum_delivery_limit
Type:

integer

Default:

0

Each time a message is redelivered to a consumer, a counter is incremented. Once the redelivery count exceeds the delivery limit the message gets dropped or dead-lettered (if a DLX exchange has been configured) Used only when rabbit_quorum_queue is enabled, Default 0 which means dont set a limit.

rabbit_quorum_max_memory_length
Type:

integer

Default:

0

By default all messages are maintained in memory if a quorum queue grows in length it can put memory pressure on a cluster. This option can limit the number of messages in the quorum queue. Used only when rabbit_quorum_queue is enabled, Default 0 which means dont set a limit.

rabbit_quorum_max_memory_bytes
Type:

integer

Default:

0

By default all messages are maintained in memory if a quorum queue grows in length it can put memory pressure on a cluster. This option can limit the number of memory bytes used by the quorum queue. Used only when rabbit_quorum_queue is enabled, Default 0 which means dont set a limit.

rabbit_transient_queues_ttl
Type:

integer

Default:

1800

Minimum Value:

0

Positive integer representing duration in seconds for queue TTL (x-expires). Queues which are unused for the duration of the TTL are automatically deleted. The parameter affects only reply and fanout queues. Setting 0 as value will disable the x-expires. If doing so, make sure you have a rabbitmq policy to delete the queues or you deployment will create an infinite number of queue over time.In case rabbit_stream_fanout is set to True, this option will control data retention policy (x-max-age) for messages in the fanout queue rather then the queue duration itself. So the oldest data in the stream queue will be discarded from it once reaching TTL Setting to 0 will disable x-max-age for stream which make stream grow indefinitely filling up the diskspace

rabbit_qos_prefetch_count
Type:

integer

Default:

0

Specifies the number of messages to prefetch. Setting to zero allows unlimited messages.

heartbeat_timeout_threshold
Type:

integer

Default:

60

Number of seconds after which the Rabbit broker is considered down if heartbeat’s keep-alive fails (0 disables heartbeat).

heartbeat_rate
Type:

integer

Default:

3

How often times during the heartbeat_timeout_threshold we check the heartbeat.

direct_mandatory_flag
Type:

boolean

Default:

True

(DEPRECATED) Enable/Disable the RabbitMQ mandatory flag for direct send. The direct send is used as reply, so the MessageUndeliverable exception is raised in case the client queue does not exist.MessageUndeliverable exception will be used to loop for a timeout to lets a chance to sender to recover.This flag is deprecated and it will not be possible to deactivate this functionality anymore

Warning

This option is deprecated for removal. Its value may be silently ignored in the future.

Reason:

Mandatory flag no longer deactivable.

enable_cancel_on_failover
Type:

boolean

Default:

False

Enable x-cancel-on-ha-failover flag so that rabbitmq server will cancel and notify consumerswhen queue is down

use_queue_manager
Type:

boolean

Default:

False

Should we use consistant queue names or random ones

hostname
Type:

string

Default:

node1.example.com

This option has a sample default set, which means that its actual default value may vary from the one documented above.

Hostname used by queue manager. Defaults to the value returned by socket.gethostname().

processname
Type:

string

Default:

nova-api

This option has a sample default set, which means that its actual default value may vary from the one documented above.

Process name used by queue manager

rabbit_stream_fanout
Type:

boolean

Default:

False

Use stream queues in RabbitMQ (x-queue-type: stream). Streams are a new persistent and replicated data structure (“queue type”) in RabbitMQ which models an append-only log with non-destructive consumer semantics. It is available as of RabbitMQ 3.9.0. If set this option will replace all fanout queues with only one stream queue.

oslo_middleware

max_request_body_size
Type:

integer

Default:

114688

The maximum body size for each request, in bytes.

enable_proxy_headers_parsing
Type:

boolean

Default:

False

Whether the application is behind a proxy or not. This determines if the middleware should parse the headers or not.

http_basic_auth_user_file
Type:

string

Default:

/etc/htpasswd

HTTP basic auth password file.

oslo_middleware_tracing

enabled
Type:

boolean

Default:

False

Enable OpenTelemetry distributed tracing. When enabled, the service will export trace data via OTLP to a configured backend. This is the primary mechanism to control tracing for services that do not use paste deploy.

otlp_endpoint
Type:

URI

Default:

http://localhost:4318

OTLP exporter endpoint URL. For HTTP/protobuf protocol, traces are sent to <endpoint>/v1/traces.

otlp_protocol
Type:

string

Default:

http/protobuf

Valid Values:

http/protobuf, grpc

OTLP transport protocol.

Possible values

http/protobuf

OTLP over HTTP with Protocol Buffers

grpc

OTLP over gRPC

service_name
Type:

string

Default:

<None>

OpenTelemetry service name reported in trace data. This must be set when tracing is enabled, either via set_defaults() or in the configuration file.

sampling_rate
Type:

floating point

Default:

1.0

Minimum Value:

0.0

Maximum Value:

1.0

Trace sampling rate as a float between 0.0 and 1.0. A value of 1.0 means all traces are sampled.

insecure
Type:

boolean

Default:

False

Disable TLS verification for the OTLP endpoint. Set to True only in development environments without proper TLS certificates.

oslo_policy

enforce_new_defaults
Type:

boolean

Default:

True

This option controls whether or not to use old deprecated defaults when evaluating policies. If True, the old deprecated defaults are not going to be evaluated. This means if any existing token is allowed for old defaults but is disallowed for new defaults, it will be disallowed. If False, the deprecated policy check string is logically OR’d with the new policy check string, allowing for a graceful upgrade experience between releases with new policies, which is the default behavior.

policy_file
Type:

string

Default:

policy.yaml

The relative or absolute path of a file that maps roles to permissions for a given service. Relative paths must be specified in relation to the configuration file setting this option.

policy_default_rule
Type:

string

Default:

default

Default rule. Enforced when a requested rule is not found.

policy_dirs
Type:

multi-valued

Default:

policy.d

Directories where policy configuration files are stored. They can be relative to any directory in the search path defined by the config_dir option, or absolute paths. The file defined by policy_file must exist for these directories to be searched. Missing or empty directories are ignored.

remote_content_type
Type:

string

Default:

application/x-www-form-urlencoded

Valid Values:

application/x-www-form-urlencoded, application/json

Content Type to send and receive data for REST based policy check

remote_ssl_verify_server_crt
Type:

boolean

Default:

False

server identity verification for REST based policy check

remote_ssl_ca_crt_file
Type:

string

Default:

<None>

Absolute path to ca cert file for REST based policy check

remote_ssl_client_crt_file
Type:

string

Default:

<None>

Absolute path to client cert for REST based policy check

remote_ssl_client_key_file
Type:

string

Default:

<None>

Absolute path client key file REST based policy check

remote_timeout
Type:

floating point

Default:

60

Minimum Value:

0

Timeout in seconds for REST based policy check

oslo_reports

log_dir
Type:

string

Default:

<None>

Path to a log directory where to create a file

file_event_handler
Type:

string

Default:

<None>

The path to a file to watch for changes to trigger the reports, instead of signals. Setting this option disables the signal trigger for the reports. If application is running as a WSGI application it is recommended to use this instead of signals.

file_event_handler_interval
Type:

integer

Default:

1

How many seconds to wait between polls when file_event_handler is set

quota

shares
Type:

integer

Default:

50

Number of shares allowed per project.

Deprecated Variations

Group

Name

DEFAULT

quota_shares

snapshots
Type:

integer

Default:

50

Number of share snapshots allowed per project.

Deprecated Variations

Group

Name

DEFAULT

quota_snapshots

gigabytes
Type:

integer

Default:

1000

Number of share gigabytes allowed per project.

Deprecated Variations

Group

Name

DEFAULT

quota_gigabytes

per_share_gigabytes
Type:

integer

Default:

-1

Max size allowed per share, in gigabytes.

Deprecated Variations

Group

Name

DEFAULT

quota_per_share_gigabytes

snapshot_gigabytes
Type:

integer

Default:

1000

Number of snapshot gigabytes allowed per project.

Deprecated Variations

Group

Name

DEFAULT

quota_snapshot_gigabytes

share_networks
Type:

integer

Default:

10

Number of share-networks allowed per project.

Deprecated Variations

Group

Name

DEFAULT

quota_share_networks

share_replicas
Type:

integer

Default:

100

Number of share-replicas allowed per project.

Deprecated Variations

Group

Name

DEFAULT

quota_share_replicas

replica_gigabytes
Type:

integer

Default:

1000

Number of replica gigabytes allowed per project.

Deprecated Variations

Group

Name

DEFAULT

quota_replica_gigabytes

share_groups
Type:

integer

Default:

50

Number of share groups allowed.

Deprecated Variations

Group

Name

DEFAULT

quota_share_groups

share_group_snapshots
Type:

integer

Default:

50

Number of share group snapshots allowed.

Deprecated Variations

Group

Name

DEFAULT

quota_share_group_snapshots

reservation_expire
Type:

integer

Default:

86400

Number of seconds until a reservation expires.

Deprecated Variations

Group

Name

DEFAULT

reservation_expire

until_refresh
Type:

integer

Default:

0

Count of reservations until usage is refreshed.

Deprecated Variations

Group

Name

DEFAULT

until_refresh

max_age
Type:

integer

Default:

0

Number of seconds between subsequent usage refreshes.

Deprecated Variations

Group

Name

DEFAULT

max_age

driver
Type:

string

Default:

manila.quota.DbQuotaDriver

Default driver to use for quota checks.

Deprecated Variations

Group

Name

DEFAULT

quota_driver

backups
Type:

integer

Default:

10

Number of share backups allowed per project.

Deprecated Variations

Group

Name

DEFAULT

quota_backups

backup_gigabytes
Type:

integer

Default:

1000

Total amount of storage, in gigabytes, allowed for backups per project.

Deprecated Variations

Group

Name

DEFAULT

quota_backup_gigabytes

encryption_keys
Type:

integer

Default:

100

Number of encryption keys allowed per project.

ssl

ca_file
Type:

string

Default:

<None>

CA certificate file to use to verify connecting clients.

Warning

This option is deprecated for removal. Its value may be silently ignored in the future.

Reason:

The ‘ca_file’ option is deprecated and will be removed in a future release.

cert_file
Type:

string

Default:

<None>

Certificate file to use when starting the server securely.

Warning

This option is deprecated for removal. Its value may be silently ignored in the future.

Reason:

The ‘cert_file’ option is deprecated and will be removed in a future release.

key_file
Type:

string

Default:

<None>

Private key file to use when starting the server securely.

Warning

This option is deprecated for removal. Its value may be silently ignored in the future.

Reason:

The ‘key_file’ option is deprecated and will be removed in a future release.

version
Type:

string

Default:

<None>

SSL version to use (valid only if SSL enabled). Valid values are TLSv1 and SSLv23. SSLv2, SSLv3, TLSv1_1, and TLSv1_2 may be available on some distributions.

Warning

This option is deprecated for removal. Its value may be silently ignored in the future.

Reason:

The ‘version’ option is deprecated and will be removed in a future release.

ciphers
Type:

string

Default:

<None>

Sets the list of available ciphers. value should be a string in the OpenSSL cipher list format.

Warning

This option is deprecated for removal. Its value may be silently ignored in the future.

Reason:

The ‘ciphers’ option is deprecated and will be removed in a future release.

vault

root_token_id
Type:

string

Default:

<None>

root token for vault

auth_method
Type:

string

Default:

approle

Valid Values:

approle, jwt, kubernetes

Auth method to use when connecting to Vault. “approle” uses approle_role_id and approle_secret_id. “jwt” and “kubernetes” use token_role and token_file.

approle_role_id
Type:

string

Default:

<None>

AppRole role_id for authentication with vault

approle_secret_id
Type:

string

Default:

<None>

AppRole secret_id for authentication with vault

token_role
Type:

string

Default:

<None>

Vault role name for token-based auth. Required when auth_method is jwt or kubernetes.

token_file
Type:

string

Default:

<None>

Path to the token file used for Vault login. Required when auth_method is jwt or kubernetes.

auth_path
Type:

string

Default:

<None>

Mount path of the Vault auth backend, used in the login URL /v1/auth/<auth_path>/login. Defaults to the value of auth_method when not set. Override this when the auth backend is mounted at a non-default path (e.g. “kubernetes-my-cluster” instead of “kubernetes”).

kv_mountpoint
Type:

string

Default:

secret

Mountpoint of KV store in Vault to use

kv_path
Type:

string

Default:

<None>

Path relative to root of KV store in Vault to use.

kv_version
Type:

integer

Default:

2

Valid Values:

1, 2

Version of KV store in Vault to use.

vault_url
Type:

URI

Default:

http://127.0.0.1:8200

Use this endpoint to connect to Vault

ssl_ca_crt_file
Type:

string

Default:

<None>

Absolute path to ca cert file

use_ssl
Type:

boolean

Default:

False

SSL Enabled/Disabled

Warning

This option is deprecated for removal. Its value may be silently ignored in the future.

Reason:

This option has no effect.

namespace
Type:

string

Default:

<None>

Vault Namespace to use for all requests to Vault. Vault Namespaces feature is available only in Vault Enterprise

timeout
Type:

floating point

Default:

60

Timeout (in seconds) in each request to Vault