Configuration Reference¶
Complete listing of all configuration options for the Shared File Systems service (manila), auto-generated from the source code.
DEFAULT¶
- osapi_max_limit¶
- Type:
integer
- Default:
1000
The maximum number of items returned in a single response from a collection resource.
- Type:
string
- Default:
<None>
Base URL to be presented to users in links to the Share API
- use_forwarded_for¶
- Type:
boolean
- Default:
False
Treat X-Forwarded-For as the canonical remote address. Only enable this if you have a sanitizing proxy.
Warning
This option is deprecated for removal since Zed. Its value may be silently ignored in the future.
- Reason:
This feature is duplicate of the HTTPProxyToWSGI middleware of oslo.middleware.
- state_path¶
- Type:
string
- Default:
/var/lib/manila
Top-level directory for maintaining manila’s state.
- my_ip¶
- Type:
host address
- Default:
<your_ip>
This option has a sample default set, which means that its actual default value may vary from the one documented above.
IP address of this host.
- scheduler_topic¶
- Type:
string
- Default:
manila-scheduler
The topic scheduler nodes listen on.
- Type:
string
- Default:
manila-share
The topic share nodes listen on.
- data_topic¶
- Type:
string
- Default:
manila-data
The topic data nodes listen on.
- api_rate_limit¶
- Type:
boolean
- Default:
True
Whether to rate limit the API.
- Type:
list
- Default:
[]
Specify list of extensions to load when using osapi_share_extension option with manila.api.contrib.select_extensions.
- Type:
list
- Default:
['manila.api.contrib.standard_extensions']
The osapi share extensions to load.
- scheduler_manager¶
- Type:
string
- Default:
manila.scheduler.manager.SchedulerManager
Full class name for the scheduler manager.
- Type:
string
- Default:
manila.share.manager.ShareManager
Full class name for the share manager.
- data_manager¶
- Type:
string
- Default:
manila.data.manager.DataManager
Full class name for the data manager.
- host¶
- Type:
host address
- Default:
<your_hostname>
This option has a sample default set, which means that its actual default value may vary from the one documented above.
Name of this node. This can be an opaque identifier. It is not necessarily a hostname, FQDN, or IP address.
- storage_availability_zone¶
- Type:
string
- Default:
nova
Availability zone of this node.
- Type:
string
- Default:
<None>
Default share type to use.
- Type:
string
- Default:
<None>
Default share group type to use.
- rootwrap_config¶
- Type:
string
- Default:
<None>
Path to the rootwrap configuration file to use for running commands as root.
- monkey_patch¶
- Type:
boolean
- Default:
False
Whether to log monkey patching.
- monkey_patch_modules¶
- Type:
list
- Default:
[]
List of modules or decorators to monkey patch.
- service_down_time¶
- Type:
integer
- Default:
60
Maximum time since last check-in for up service.
- Type:
string
- Default:
manila.share.api.API
The full class name of the share API class to use.
- auth_strategy¶
- Type:
string
- Default:
keystone- Valid Values:
noauth, noauthv2, keystone
The strategy to use for auth.
- Type:
list
- Default:
<None>
A list of share backend names to use. These backend names should be backed by a unique [CONFIG] group with its options.
- Type:
list
- Default:
['NFS', 'CIFS']
Specify list of protocols to be allowed for share creation.
- Type:
integer
- Default:
604800
Maximum time (in seconds) to keep a share in the recycle bin, it will be deleted automatically after this amount of time has elapsed.
- transfer_retention_time¶
- Type:
integer
- Default:
300
Maximum time (in seconds) to keep a share in awaiting_transfer state, after timeout, the share will automatically be rolled back to the available state
- admin_only_metadata¶
- Type:
list
- Default:
['__affinity_same_host', '__affinity_different_host', '__managed_at']
Metadata keys that should only be manipulated by administrators.
- driver_updatable_metadata¶
- Type:
list
- Default:
[]
Metadata keys that will decide which share metadata (element of the list is <driver_updatable_key>, i.e max_files) can be passed to share drivers as part of metadata create/update operations.
- driver_updatable_subnet_metadata¶
- Type:
list
- Default:
[]
Metadata keys that will decide which share network subnet metadata (element of the list is <driver_updatable_key>, e.g. pnfs) can be passed to share drivers as part of metadata create/update operations.
- Type:
boolean
- Default:
True
Whether Manila should update the status of all shares within a backend during ongoing ensure_shares run.
- admin_only_el_metadata¶
- Type:
list
- Default:
['preferred']
Metadata keys for export locations that should only be manipulated by administrators.
- Type:
list
- Default:
['NFS']
Specify list of protocols to be allowed for share backup creation when using either the data manager generic backup approach, or another backup driver that makes use of the data manager service.
- compute_api_class¶
- Type:
string
- Default:
manila.compute.nova.API
The full class name of the Compute API class to use.
- backend_url¶
- Type:
string
- Default:
file://$state_path
The back end URL to use for distributed coordination.
- backup_mount_template¶
- Type:
string
- Default:
mount -vt %(proto)s %(options)s %(export)s %(path)s
The template for mounting NFS shares.
- backup_unmount_template¶
- Type:
string
- Default:
umount -v %(path)s
The template for unmounting NFS shares.
- backup_mount_export¶
- Type:
string
- Default:
<None>
NFS backup export location in hostname:path, ipv4addr:path, or “[ipv6addr]:path” format.
- backup_mount_proto¶
- Type:
string
- Default:
nfs
Mount Protocol for mounting NFS shares
- backup_mount_options¶
- Type:
string
- Default:
''
Mount options passed to the NFS client. See NFS man page for details.
- data_access_wait_access_rules_timeout¶
- Type:
integer
- Default:
180
Time to wait for access rules to be allowed/denied on backends when migrating a share (seconds).
- data_node_access_ips¶
- Type:
list
- Default:
[]
A list of the IPs of the node interface connected to the admin network. Used for allowing access to the mounting shares. Default is [].
- data_node_access_cert¶
- Type:
string
- Default:
<None>
The certificate installed in the data node in order to allow access to certificate authentication-based shares.
- data_node_access_admin_user¶
- Type:
string
- Default:
<None>
The admin user name registered in the security service in order to allow access to user authentication-based shares.
- data_node_mount_options¶
- Type:
dict
- Default:
{}
Mount options to be included in the mount command for share protocols. Use dictionary format, example: {‘nfs’: ‘-o nfsvers=3’, ‘cifs’: ‘-o user=foo,pass=bar’}
- backup_driver¶
- Type:
string
- Default:
manila.data.drivers.nfs.NFSBackupDriver
Driver to use for backups.
- Type:
string
- Default:
mount -vt %(proto)s %(options)s %(export)s %(path)s
The template for mounting shares during backup. Must specify the executable with all necessary parameters for the protocol supported. ‘proto’ template element may not be required if included in the command. ‘export’ and ‘path’ template elements are required. It is advisable to separate different commands per backend.
- Type:
string
- Default:
umount -v %(path)s
The template for unmounting shares during backup. Must specify the executable with all necessary parameters for the protocol supported. ‘path’ template element is required. It is advisable to separate different commands per backend.
- backup_ignore_files¶
- Type:
list
- Default:
['lost+found']
List of files and folders to be ignored when backing up shares. Items should be names (not including any path).
- backup_protocol_access_mapping¶
- Type:
dict value
- Default:
{'ip': ['nfs']}
Protocol access mapping for backup. Should be a dictionary comprised of {‘access_type1’: [‘share_proto1’, ‘share_proto2’], ‘access_type2’: [‘share_proto2’, ‘share_proto3’]}.
- mount_tmp_location¶
- Type:
string
- Default:
/tmp/
Temporary path to create and mount shares during migration.
- backup_mount_tmp_location¶
- Type:
string
- Default:
/tmp/
Temporary path to create and mount backup during share backup.
- check_hash¶
- Type:
boolean
- Default:
False
Chooses whether hash of each file should be checked on data copying.
- backup_continue_update_interval¶
- Type:
integer
- Default:
10
This value, specified in seconds, determines how often the data manager will poll to perform the next steps of backup such as fetch the progress of backup.
- restore_continue_update_interval¶
- Type:
integer
- Default:
10
This value, specified in seconds, determines how often the data manager will poll to perform the next steps of restore such as fetch the progress of restore.
- db_backend¶
- Type:
string
- Default:
sqlalchemy
The backend to use for database.
- enable_new_services¶
- Type:
boolean
- Default:
True
Services to be added to the available pool on create.
- Type:
string
- Default:
share-%s
Template string to be used to generate share names.
- Type:
string
- Default:
share-snapshot-%s
Template string to be used to generate share snapshot names.
- Type:
string
- Default:
share-backup-%s
Template string to be used to generate backup names.
- db_driver¶
- Type:
string
- Default:
manila.db
Driver to use for database access.
- fatal_exception_format_errors¶
- Type:
boolean
- Default:
False
Whether to make exception message format errors fatal.
- image_api_class¶
- Type:
string
- Default:
manila.image.glance.API
The full class name of the Glance API class to use.
- message_ttl¶
- Type:
integer
- Default:
2592000
Message minimum life in seconds.
- message_reap_interval¶
- Type:
integer
- Default:
86400
Interval between periodic task runs to clean expired messages in seconds.
- ovs_integration_bridge¶
- Type:
string
- Default:
br-int
Name of Open vSwitch bridge to use.
- network_api_class¶
- Type:
string
- Default:
manila.network.neutron.neutron_network_plugin.NeutronNetworkPlugin
The full class name of the Networking API class to use.
- network_plugin_ipv4_enabled¶
- Type:
boolean
- Default:
True
Whether to support IPv4 network resource, Default=True.
- network_plugin_ipv6_enabled¶
- Type:
boolean
- Default:
False
Whether to support IPv6 network resource, Default=False. If this option is True, the value of ‘network_plugin_ipv4_enabled’ will be ignored.
- neutron_physical_net_name¶
- Type:
string
- Default:
<None>
The name of the physical network to determine which net segment is used. This opt is optional and will only be used for networks configured with multiple segments.
- neutron_net_id¶
- Type:
string
- Default:
<None>
Default Neutron network that will be used for share server creation. This opt is used only with class ‘NeutronSingleNetworkPlugin’.
- neutron_subnet_id¶
- Type:
string
- Default:
<None>
Default Neutron subnet that will be used for share server creation. Should be assigned to network defined in opt ‘neutron_net_id’. This opt is used only with class ‘NeutronSingleNetworkPlugin’.
- neutron_vnic_type¶
- Type:
string
- Default:
baremetal- Valid Values:
baremetal, normal, direct, direct-physical, macvtap
vNIC type used for binding.
- neutron_host_id¶
- Type:
string
- Default:
<HOSTNAME>
This option has a sample default set, which means that its actual default value may vary from the one documented above.
Host ID to be used when creating neutron port. If not set host is set to manila-share host by default.
- neutron_binding_profiles¶
- Type:
list
- Default:
<None>
A list of binding profiles to be used during port binding. This option can be used with the NeutronBindNetworkPlugin. The value for this option has to be a comma separated list of names that correspond to each binding profile. Each binding profile needs to be specified as an individual configuration section using the binding profile name as the section name.
- neutron_switch_id¶
- Type:
string
- Default:
<None>
Switch ID for binding profile.
- neutron_port_id¶
- Type:
string
- Default:
<None>
Port ID on the given switch.
- neutron_switch_info¶
- Type:
dict
- Default:
<None>
Switch label. For example: ‘switch_ip: 10.4.30.5’. Multiple key-value pairs separated by commas are accepted.
- standalone_network_plugin_gateway¶
- Type:
string
- Default:
<None>
Gateway address that should be used. Required.
- standalone_network_plugin_mask¶
- Type:
string
- Default:
<None>
Network mask that will be used. Can be either decimal like ‘24’ or binary like ‘255.255.255.0’. Required.
- standalone_network_plugin_network_type¶
- Type:
string
- Default:
<None>- Valid Values:
flat, vlan, vxlan, gre
Network type, such as ‘flat’, ‘vlan’, ‘vxlan’ or ‘gre’. Empty value is alias for ‘flat’. It will be assigned to share-network and share drivers will be able to use this for network interfaces within provisioned share servers. Optional.
- standalone_network_plugin_segmentation_id¶
- Type:
integer
- Default:
<None>
Set it if network has segmentation (VLAN, VXLAN, etc…). It will be assigned to share-network and share drivers will be able to use this for network interfaces within provisioned share servers. Optional. Example: 1001
- standalone_network_plugin_allowed_ip_ranges¶
- Type:
list
- Default:
<None>
Can be IP address, range of IP addresses or list of addresses or ranges. Contains addresses from IP network that are allowed to be used. If empty, then will be assumed that all host addresses from network can be used. Optional. Examples: 10.0.0.10 or 10.0.0.10-10.0.0.20 or 10.0.0.10-10.0.0.20,10.0.0.30-10.0.0.40,10.0.0.50
- standalone_network_plugin_mtu¶
- Type:
integer
- Default:
1500
Maximum Transmission Unit (MTU) value of the network. Default value is 1500.
- scheduler_host_manager¶
- Type:
string
- Default:
manila.scheduler.host_manager.HostManager
The scheduler host manager class to use.
- scheduler_max_attempts¶
- Type:
integer
- Default:
3
Maximum number of attempts to schedule a share.
- scheduler_default_filters¶
- Type:
list
- Default:
['OnlyHostFilter', 'AvailabilityZoneFilter', 'CapacityFilter', 'CapabilitiesFilter', 'DriverFilter', 'ShareReplicationFilter', 'CreateFromSnapshotFilter', 'AffinityFilter', 'AntiAffinityFilter']
Which filter class names to use for filtering hosts when not specified in the request.
- scheduler_default_weighers¶
- Type:
list
- Default:
['CapacityWeigher', 'GoodnessWeigher', 'HostAffinityWeigher']
Which weigher class names to use for weighing hosts.
- Type:
list
- Default:
['AvailabilityZoneFilter', 'ConsistentSnapshotFilter']
Which filter class names to use for filtering hosts creating share group when not specified in the request.
- scheduler_default_extend_filters¶
- Type:
list
- Default:
['CapacityFilter', 'DriverFilter']
Which filter class names to use for filtering hosts extending share when not specified in the request.
- scheduler_driver¶
- Type:
string
- Default:
manila.scheduler.drivers.filter.FilterScheduler
Default scheduler driver to use.
- scheduler_json_config_location¶
- Type:
string
- Default:
''
Absolute path to scheduler configuration JSON file.
- max_gigabytes¶
- Type:
integer
- Default:
10000
Maximum number of volume gigabytes to allow per host.
- capacity_weight_multiplier¶
- Type:
floating point
- Default:
1.0
Multiplier used for weighing share capacity. Negative numbers mean to stack vs spread.
- pool_weight_multiplier¶
- Type:
floating point
- Default:
1.0
Multiplier used for weighing pools which have existing share servers. Negative numbers mean to spread vs stack.
- report_interval¶
- Type:
integer
- Default:
10
Seconds between nodes reporting state to datastore.
- cleanup_interval¶
- Type:
integer
- Default:
1800- Minimum Value:
300
Seconds between cleaning up the stopped nodes.
- periodic_interval¶
- Type:
integer
- Default:
60
Seconds between running periodic tasks.
- periodic_fuzzy_delay¶
- Type:
integer
- Default:
60
Range of seconds to randomly delay when starting the periodic task scheduler to reduce stampeding. (Disable by setting to 0)
- Type:
host address
- Default:
::
IP address for OpenStack Share API to listen on.
- Type:
port number
- Default:
8786- Minimum Value:
0
- Maximum Value:
65535
Port for OpenStack Share API to listen on.
- Type:
integer
- Default:
1
Number of workers for OpenStack Share API service.
- Type:
boolean
- Default:
False
Wraps the socket in a SSL context if True is set. A certificate file and key file must be specified.
- Type:
boolean
- Default:
False
If set to False, then share creation from snapshot will be performed on the same host. If set to True, then scheduler will be used.When enabling this option make sure that filter CreateFromSnapshotFilter is enabled and to have hosts reporting replication_domain option.
- default_mount_point_prefix¶
- Type:
string
- Default:
{project_id}_
Default prefix that will be used if none is providedthrough share_type extra specs. Prefix will only beused if share_type support mount_point_name.
- is_deferred_deletion_enabled¶
- Type:
boolean
- Default:
False
Whether to delete shares and share snapshots in a deferred manner. Setting this option to True will cause quotas to be released immediately if a deletion request is accepted. Deletions may eventually fail, and rectifying them will require manual intervention.
- ganesha_config_dir¶
- Type:
string
- Default:
/etc/ganesha
Directory where Ganesha config files are stored.
- ganesha_config_path¶
- Type:
string
- Default:
$ganesha_config_dir/ganesha.conf
Path to main Ganesha config file.
- ganesha_service_name¶
- Type:
string
- Default:
ganesha.nfsd
Name of the ganesha nfs service.
- ganesha_db_path¶
- Type:
string
- Default:
$state_path/manila-ganesha.db
Location of Ganesha database file. (Ganesha module only.)
- ganesha_export_dir¶
- Type:
string
- Default:
$ganesha_config_dir/export.d
Path to directory containing Ganesha export configuration. (Ganesha module only.)
- ganesha_export_template_dir¶
- Type:
string
- Default:
/etc/manila/ganesha-export-templ.d
Path to directory containing Ganesha export block templates. (Ganesha module only.)
- ganesha_rados_store_enable¶
- Type:
boolean
- Default:
False
Persist Ganesha exports and export counter in Ceph RADOS objects, highly available storage.
- ganesha_rados_store_pool_name¶
- Type:
string
- Default:
<None>
Name of the Ceph RADOS pool to store Ganesha exports and export counter.
- ganesha_rados_export_counter¶
- Type:
string
- Default:
ganesha-export-counter
Name of the Ceph RADOS object used as the Ganesha export counter.
- ganesha_rados_export_index¶
- Type:
string
- Default:
ganesha-export-index
Name of the Ceph RADOS object used to store a list of the export RADOS object URLS.
- num_shell_tries¶
- Type:
integer
- Default:
3
Number of times to attempt to run flakey shell commands.
- Type:
integer
- Default:
0
The percentage of backend capacity reserved. Used for shares which are not created from the snapshot.
- Type:
integer
- Default:
0
The percentage of backend capacity reserved. Used for shares created from the snapshot. On some platforms, shares can only be created from the snapshot on the host where snapshot was taken, so we can set a lower value in this option compared to reserved_share_percentage, and allow to create shares from the snapshot on the same host up to a higher threshold.
- Type:
integer
- Default:
0
The percentage of backend capacity reserved for share extend operation. When existing limit of ‘reserved_share_percentage’ is hit, we do not want user to create a new share but existing shares can be extended based on value of this parameter.
- Type:
string
- Default:
<None>
The backend name for a given driver implementation.
- network_config_group¶
- Type:
string
- Default:
<None>
Name of the configuration group in the Manila conf file to look for network config options.If not set, the share backend’s config group will be used.If an option is not found within provided group, then ‘DEFAULT’ group will be used for search of option.
- Type:
boolean
- Default:
<None>
There are two possible approaches for share drivers in Manila. First is when share driver is able to handle share-servers and second when not. Drivers can support either both or only one of these approaches. So, set this opt to True if share driver is able to handle share servers and it is desired mode else set False. It is set to None by default to make this choice intentional.
- max_over_subscription_ratio¶
- Type:
floating point
- Default:
20.0- Minimum Value:
1.0
Float representation of the over subscription ratio when thin provisioning is involved. Default ratio is 20.0, meaning provisioned capacity can be 20 times the total physical capacity. If the ratio is 10.5, it means provisioned capacity can be 10.5 times the total physical capacity. A ratio of 1.0 means provisioned capacity cannot exceed the total physical capacity. A ratio lower than 1.0 is invalid.
- migration_ignore_files¶
- Type:
list
- Default:
['lost+found']
List of files and folders to be ignored when migrating shares. Items should be names (not including any path).
- Type:
string
- Default:
mount -vt %(proto)s %(options)s %(export)s %(path)s
The template for mounting shares for this backend. Must specify the executable with all necessary parameters for the protocol supported. ‘proto’ template element may not be required if included in the command. ‘export’ and ‘path’ template elements are required. It is advisable to separate different commands per backend.
- Type:
string
- Default:
umount -v %(path)s
The template for unmounting shares for this backend. Must specify the executable with all necessary parameters for the protocol supported. ‘path’ template element is required. It is advisable to separate different commands per backend.
- protocol_access_mapping¶
- Type:
dict value
- Default:
{'ip': ['nfs'], 'user': ['cifs']}
Protocol access mapping for this backend. Should be a dictionary comprised of {‘access_type1’: [‘share_proto1’, ‘share_proto2’], ‘access_type2’: [‘share_proto2’, ‘share_proto3’]}.
- admin_network_config_group¶
- Type:
string
- Default:
<None>
If share driver requires to setup admin network for share, then define network plugin config options in some separate config group and set its name here. Used only with another option ‘driver_handles_share_servers’ set to ‘True’.
- replication_domain¶
- Type:
string
- Default:
<None>
A string specifying the replication domain that the backend belongs to. This option needs to be specified the same in the configuration sections of all backends that support replication between each other. If this option is not specified in the group, it means that replication is not enabled on the backend.
- backend_availability_zone¶
- Type:
string
- Default:
<None>
Availability zone for this share backend. If not set, the
storage_availability_zoneoption from the[DEFAULT]section is used.
- filter_function¶
- Type:
string
- Default:
<None>
String representation for an equation that will be used to filter hosts.
- goodness_function¶
- Type:
string
- Default:
<None>
String representation for an equation that will be used to determine the goodness of a host.
- Type:
integer
- Default:
-1
Maximum number of share instances created in a share server.
- Type:
integer
- Default:
-1
Maximum sum of gigabytes a share server can have considering all its share instances and snapshots.
- ssh_conn_timeout¶
- Type:
integer
- Default:
60
Backend server SSH connection timeout.
- ssh_min_pool_conn¶
- Type:
integer
- Default:
1
Minimum number of connections in the SSH pool.
- ssh_max_pool_conn¶
- Type:
integer
- Default:
10
Maximum number of connections in the SSH pool.
- drivers_private_storage_class¶
- Type:
string
- Default:
manila.share.drivers_private_data.SqlStorageDriver
The full class name of the Private Data Driver class to use.
- cephfs_conf_path¶
- Type:
string
- Default:
''
Fully qualified path to the ceph.conf file.
- cephfs_cluster_name¶
- Type:
string
- Default:
<None>
The name of the cluster in use, if it is not the default (‘ceph’).
- cephfs_auth_id¶
- Type:
string
- Default:
manila
The name of the ceph auth identity to use.
- cephfs_protocol_helper_type¶
- Type:
string
- Default:
CEPHFS- Valid Values:
CEPHFS, NFS
The type of protocol helper to use. Default is CEPHFS.
- cephfs_ganesha_server_is_remote¶
- Type:
boolean
- Default:
False
Whether the NFS-Ganesha server is remote to the driver.
Warning
This option is deprecated for removal since 2025.1. Its value may be silently ignored in the future.
- Reason:
This option is used by the deprecated NFSProtocolHelper
- cephfs_ganesha_server_ip¶
- Type:
host address
- Default:
<None>
The IP address of the NFS-Ganesha server.
- cephfs_ganesha_server_username¶
- Type:
string
- Default:
root
The username to authenticate as in the remote NFS-Ganesha server host.
Warning
This option is deprecated for removal since 2025.1. Its value may be silently ignored in the future.
- Reason:
This option is used by the deprecated NFSProtocolHelper
- cephfs_ganesha_path_to_private_key¶
- Type:
string
- Default:
<None>
The path of the driver host’s private SSH key file.
Warning
This option is deprecated for removal since 2025.1. Its value may be silently ignored in the future.
- Reason:
This option is used by the deprecated NFSProtocolHelper
- cephfs_ganesha_server_password¶
- Type:
string
- Default:
<None>
The password to authenticate as the user in the remote Ganesha server host. This is not required if ‘cephfs_ganesha_path_to_private_key’ is configured.
Warning
This option is deprecated for removal since 2025.1. Its value may be silently ignored in the future.
- Reason:
This option is used by the deprecated NFSProtocolHelper
- cephfs_ganesha_export_ips¶
- Type:
list
- Default:
[]
List of IPs to export shares. If not supplied, then the value of ‘cephfs_ganesha_server_ip’ will be used to construct share export locations.
- cephfs_volume_mode¶
- Type:
string
- Default:
755
The read/write/execute permissions mode for CephFS volumes, snapshots, and snapshot groups expressed in Octal as with linux ‘chmod’ or ‘umask’ commands.
- cephfs_filesystem_name¶
- Type:
string
- Default:
<None>
The name of the filesystem to use, if there are multiple filesystems in the cluster.
- Type:
string
- Default:
manila_cephfs_reef_caracal
Provide a unique string value to make the driver ensure all of the shares it has created during startup. Ensuring would re-export shares and this action isn’t always required, unless something has been administratively modified on CephFS.
- cephfs_cached_allocated_capacity_update_interval¶
- Type:
integer
- Default:
60- Minimum Value:
0
The maximum time in seconds that the cached pool data will be considered updated. If it is expired when trying to read the pool data, it must be refreshed.
- container_linux_bridge_name¶
- Type:
string
- Default:
docker0
Linux bridge used by container hypervisor to plug host-side veth to. It will be unplugged from here by the driver.
- container_ovs_bridge_name¶
- Type:
string
- Default:
br-int
OVS bridge to use to plug a container to.
- container_cifs_guest_ok¶
- Type:
boolean
- Default:
True
Determines whether to allow guest access to CIFS share or not.
- container_image_name¶
- Type:
string
- Default:
manila-docker-container
Image to be used for a container-based share server.
- container_helper¶
- Type:
string
- Default:
manila.share.drivers.container.container_helper.DockerExecHelper
Container helper which provides container-related operations to the driver.
- container_protocol_helper¶
- Type:
string
- Default:
manila.share.drivers.container.protocol_helper.DockerCIFSHelper
Helper which facilitates interaction with share server.
- container_security_service_helper¶
- Type:
string
- Default:
manila.share.drivers.container.security_service_helper.SecurityServiceHelper
Helper which facilitates interaction with security services.
- container_storage_helper¶
- Type:
string
- Default:
manila.share.drivers.container.storage_helper.LVMHelper
Helper which facilitates interaction with storage solution used to actually store data. By default LVM is used to provide storage for a share.
- container_volume_mount_path¶
- Type:
string
- Default:
/tmp/shares
Folder name in host to which logical volume will be mounted prior to providing access to it from a container.
- container_volume_group¶
- Type:
string
- Default:
manila_docker_volumes
LVM volume group to use for volumes. This volume group must be created by the cloud administrator independently from manila operations.
- emc_nas_login¶
- Type:
string
- Default:
<None>
User name for the EMC server.
- emc_nas_password¶
- Type:
string
- Default:
<None>
Password for the EMC server.
- emc_nas_server¶
- Type:
host address
- Default:
<None>
EMC server hostname or IP address.
- emc_nas_server_port¶
- Type:
port number
- Default:
8080- Minimum Value:
0
- Maximum Value:
65535
Port number for the EMC server.
- emc_nas_server_secure¶
- Type:
boolean
- Default:
True
Use secure connection to server.
- Type:
string
- Default:
<None>- Valid Values:
powerscale, isilon, vnx, unity, powermax, powerstore, powerflex
Share backend.
- emc_nas_root_dir¶
- Type:
string
- Default:
<None>
The root directory where shares will be located.
- emc_ssl_cert_verify¶
- Type:
boolean
- Default:
True
If set to False the https client will not validate the SSL certificate of the backend endpoint.
- emc_ssl_cert_path¶
- Type:
string
- Default:
<None>
Can be used to specify a non default path to a CA_BUNDLE file or directory with certificates of trusted CAs, which will be used to validate the backend.
- powermax_server_container¶
- Type:
string
- Default:
<None>
Data mover to host the NAS server.
- Type:
list
- Default:
<None>
Comma separated list of pools that can be used to persist share data.
- powermax_ethernet_ports¶
- Type:
list
- Default:
<None>
Comma separated list of ports that can be used for share server interfaces. Members of the list can be Unix-style glob expressions.
- smb_template_config_path¶
- Type:
string
- Default:
$state_path/smb.conf
Path to smb config.
- volume_name_template¶
- Type:
string
- Default:
manila-share-%s
Volume name template.
- volume_snapshot_name_template¶
- Type:
string
- Default:
manila-snapshot-%s
Volume snapshot name template.
- Type:
string
- Default:
/shares
Parent path in service instance where shares will be mounted.
- max_time_to_create_volume¶
- Type:
integer
- Default:
180
Maximum time to wait for creating cinder volume.
- max_time_to_extend_volume¶
- Type:
integer
- Default:
180
Maximum time to wait for extending cinder volume.
- max_time_to_attach¶
- Type:
integer
- Default:
120
Maximum time to wait for attaching cinder volume.
- service_instance_smb_config_path¶
- Type:
string
- Default:
$share_mount_path/smb.conf
Path to SMB config in service instance.
- Type:
dict value
- Default:
{'CIFS': 'manila.share.drivers.helpers.CIFSHelperIPAccess', 'NFS': 'manila.share.drivers.helpers.NFSHelper'}
Specify list of share export helpers.
- Type:
string
- Default:
ext4- Valid Values:
ext4, ext3
Filesystem type of the share volume.
- cinder_volume_type¶
- Type:
string
- Default:
<None>
Name or id of cinder volume type which will be used for all volumes created by driver.
- set_zero_reserved_blocks¶
- Type:
boolean
- Default:
True
If True, sets reserved blocks to 0 on formatted ext volumes to ensure full capacity is available to the share.
- glusterfs_server_password¶
- Type:
string
- Default:
<None>
Remote GlusterFS server node’s login password. This is not required if ‘glusterfs_path_to_private_key’ is configured.
- glusterfs_path_to_private_key¶
- Type:
string
- Default:
<None>
Path of Manila host’s private SSH key file.
- glusterfs_nfs_server_type¶
- Type:
string
- Default:
Gluster
Type of NFS server that mediate access to the Gluster volumes (Gluster or Ganesha).
- glusterfs_ganesha_server_ip¶
- Type:
host address
- Default:
<None>
Remote Ganesha server node’s IP address.
- glusterfs_ganesha_server_username¶
- Type:
string
- Default:
root
Remote Ganesha server node’s username.
- glusterfs_ganesha_server_password¶
- Type:
string
- Default:
<None>
Remote Ganesha server node’s login password. This is not required if ‘glusterfs_path_to_private_key’ is configured.
- Type:
string
- Default:
<None>
Specifies GlusterFS share layout, that is, the method of associating backing GlusterFS resources to shares.
- glusterfs_target¶
- Type:
string
- Default:
<None>
Specifies the GlusterFS volume to be mounted on the Manila host. It is of the form [remoteuser@]<volserver>:<volid>.
- glusterfs_mount_point_base¶
- Type:
string
- Default:
$state_path/mnt
Base directory containing mount points for Gluster volumes.
- glusterfs_servers¶
- Type:
list
- Default:
[]
List of GlusterFS servers that can be used to create shares. Each GlusterFS server should be of the form [remoteuser@]<volserver>, and they are assumed to belong to distinct Gluster clusters.
- glusterfs_volume_pattern¶
- Type:
string
- Default:
<None>
Regular expression template used to filter GlusterFS volumes for share creation. The regex template can optionally (ie. with support of the GlusterFS backend) contain the #{size} parameter which matches an integer (sequence of digits) in which case the value shall be interpreted as size of the volume in GB. Examples: “manila-share-volume-d+$”, “manila-share-volume-#{size}G-d+$”; with matching volume names, respectively: “manila-share-volume-12”, “manila-share-volume-3G-13”. In latter example, the number that matches “#{size}”, that is, 3, is an indication that the size of volume is 3G.
- hdfs_namenode_ip¶
- Type:
host address
- Default:
<None>
The IP of the HDFS namenode.
- hdfs_namenode_port¶
- Type:
port number
- Default:
9000- Minimum Value:
0
- Maximum Value:
65535
The port of HDFS namenode service.
- hdfs_ssh_port¶
- Type:
port number
- Default:
22- Minimum Value:
0
- Maximum Value:
65535
HDFS namenode SSH port.
- hdfs_ssh_name¶
- Type:
string
- Default:
<None>
HDFS namenode ssh login name.
- hdfs_ssh_pw¶
- Type:
string
- Default:
<None>
HDFS namenode SSH login password, This parameter is not necessary, if ‘hdfs_ssh_private_key’ is configured.
- hdfs_ssh_private_key¶
- Type:
string
- Default:
<None>
Path to HDFS namenode SSH private key for login.
- hitachi_hnas_ip¶
- Type:
host address
- Default:
<None>
HNAS management interface IP for communication between Manila controller and HNAS.
- hitachi_hnas_user¶
- Type:
string
- Default:
<None>
HNAS username Base64 String in order to perform tasks such as create file-systems and network interfaces.
- hitachi_hnas_password¶
- Type:
string
- Default:
<None>
HNAS user password. Required only if private key is not provided.
- hitachi_hnas_evs_id¶
- Type:
integer
- Default:
<None>
Specify which EVS this backend is assigned to.
- hitachi_hnas_evs_ip¶
- Type:
host address
- Default:
<None>
Specify IP for mounting shares.
- hitachi_hnas_admin_network_ip¶
- Type:
host address
- Default:
<None>
Specify IP for mounting shares in the Admin network.
- hitachi_hnas_file_system_name¶
- Type:
string
- Default:
<None>
Specify file-system name for creating shares.
- hitachi_hnas_ssh_private_key¶
- Type:
string
- Default:
<None>
RSA/DSA private key value used to connect into HNAS. Required only if password is not provided.
- hitachi_hnas_cluster_admin_ip0¶
- Type:
host address
- Default:
<None>
The IP of the clusters admin node. Only set in HNAS multinode clusters.
- hitachi_hnas_stalled_job_timeout¶
- Type:
integer
- Default:
30
The time (in seconds) to wait for stalled HNAS jobs before aborting.
- hitachi_hnas_driver_helper¶
- Type:
string
- Default:
manila.share.drivers.hitachi.hnas.ssh.HNASSSHBackend
Python class to be used for driver helper.
- hitachi_hnas_allow_cifs_snapshot_while_mounted¶
- Type:
boolean
- Default:
False
By default, CIFS snapshots are not allowed to be taken when the share has clients connected because consistent point-in-time replica cannot be guaranteed for all files. Enabling this might cause inconsistent snapshots on CIFS shares.
- hitachi_hsp_host¶
- Type:
host address
- Default:
<None>
HSP management host for communication between Manila controller and HSP.
- hitachi_hsp_username¶
- Type:
string
- Default:
<None>
HSP username to perform tasks such as create filesystems and shares.
- hitachi_hsp_password¶
- Type:
string
- Default:
<None>
HSP password for the username provided.
- hitachi_hsp_ssl_cert_verify¶
- Type:
boolean
- Default:
True
If set to False the https client will not validate the SSL certificate of the backend endpoint.
- hitachi_hsp_ssl_cert_path¶
- Type:
string
- Default:
<None>
Can be used to specify a non default path to a CA_BUNDLE file or directory with certificates of trusted CAs, which will be used to validate the backend.
- hpealletra_wsapi_url¶
- Type:
string
- Default:
''
Alletra WSAPI V3 Server Url like https://<alletra ip>:8080/api/v3
- hpealletra_username¶
- Type:
string
- Default:
''
Alletra username with the ‘edit’ role
- hpealletra_password¶
- Type:
string
- Default:
''
Alletra password for the user specified in hpealletra_username
- hpealletra_debug¶
- Type:
boolean
- Default:
False
Enable HTTP debugging to Alletra
- hpe3par_username¶
- Type:
string
- Default:
''
3PAR username with the ‘edit’ role
- hpe3par_password¶
- Type:
string
- Default:
''
3PAR password for the user specified in hpe3par_username
- hpe3par_san_ip¶
- Type:
host address
- Default:
<None>
IP address of SAN controller
- hpe3par_san_login¶
- Type:
string
- Default:
''
Username for SAN controller
- hpe3par_san_password¶
- Type:
string
- Default:
''
Password for SAN controller
- hpe3par_san_ssh_port¶
- Type:
port number
- Default:
22- Minimum Value:
0
- Maximum Value:
65535
SSH port to use with SAN
- hpe3par_fpg¶
- Type:
FPG
- Default:
<None>
The File Provisioning Group (FPG) to use
- Type:
boolean
- Default:
False
Use one filestore per share
- hpe3par_require_cifs_ip¶
- Type:
boolean
- Default:
False
Require IP access rules for CIFS (in addition to user)
- hpe3par_debug¶
- Type:
boolean
- Default:
False
Enable HTTP debugging to 3PAR
- hpe3par_cifs_admin_access_username¶
- Type:
string
- Default:
''
File system admin user name for CIFS.
- hpe3par_cifs_admin_access_password¶
- Type:
string
- Default:
''
File system admin password for CIFS.
- hpe3par_cifs_admin_access_domain¶
- Type:
string
- Default:
LOCAL_CLUSTER
File system domain for the CIFS admin user.
- Type:
string
- Default:
/mnt/
The path where shares will be mounted when deleting nested file trees.
- manila_huawei_conf_file¶
- Type:
string
- Default:
/etc/manila/manila_huawei_conf.xml
The configuration file for the Manila Huawei driver.
- Type:
host address
- Default:
<None>
IP to be added to GPFS export string.
- gpfs_mount_point_base¶
- Type:
string
- Default:
$state_path/mnt
Base folder where exported shares are located.
- gpfs_nfs_server_type¶
- Type:
string
- Default:
CES
NFS Server type. Valid choices are “CES” (Ganesha NFS) or “KNFS” (Kernel NFS).
- gpfs_nfs_server_list¶
- Type:
list
- Default:
<None>
A list of the fully qualified NFS server names that make up the OpenStack Manila configuration.
- is_gpfs_node¶
- Type:
boolean
- Default:
False
True:when Manila services are running on one of the Spectrum Scale node. False:when Manila services are not running on any of the Spectrum Scale node.
- gpfs_ssh_port¶
- Type:
port number
- Default:
22- Minimum Value:
0
- Maximum Value:
65535
GPFS server SSH port.
- gpfs_ssh_login¶
- Type:
string
- Default:
<None>
GPFS server SSH login name.
- gpfs_ssh_password¶
- Type:
string
- Default:
<None>
GPFS server SSH login password. The password is not needed, if ‘gpfs_ssh_private_key’ is configured.
- gpfs_ssh_private_key¶
- Type:
string
- Default:
<None>
Path to GPFS server SSH private key for login.
- Type:
dict value
- Default:
{'KNFS': 'manila.share.drivers.ibm.gpfs.KNFSHelper', 'CES': 'manila.share.drivers.ibm.gpfs.CESHelper'}
Specify list of share export helpers.
- infinibox_login¶
- Type:
string
- Default:
<None>
Administrative user account name used to access the INFINIDAT Infinibox storage system.
- infinibox_password¶
- Type:
string
- Default:
<None>
Password for the administrative user account specified in the infinibox_login option.
- infinibox_hostname¶
- Type:
host address
- Default:
<None>
The name (or IP address) for the INFINIDAT Infinibox storage system.
- infinidat_use_ssl¶
- Type:
boolean
- Default:
False
Use SSL to connect to the INFINIDAT Infinibox storage system.
- infinidat_suppress_ssl_warnings¶
- Type:
boolean
- Default:
False
Suppress requests library SSL certificate warnings.
- infinidat_pool_name¶
- Type:
string
- Default:
<None>
Name of the pool from which volumes are allocated.
- infinidat_nas_network_space_name¶
- Type:
string
- Default:
<None>
Name of the NAS network space on the INFINIDAT InfiniBox.
- infinidat_thin_provision¶
- Type:
boolean
- Default:
True
Use thin provisioning.
- infinidat_snapdir_accessible¶
- Type:
boolean
- Default:
True
Controls access to the .snapshot directory. By default, each share allows access to its own .snapshot directory, which contains files and directories of each snapshot taken. To restrict access to the .snapshot directory, this option should be set to False.
- infinidat_snapdir_visible¶
- Type:
boolean
- Default:
False
Controls visibility of the .snapshot directory. By default, each share contains the .snapshot directory, which is hidden on the client side. To make the .snapshot directory visible, this option should be set to True.
- infortrend_nas_ip¶
- Type:
host address
- Default:
<None>
Infortrend NAS IP for management.
- infortrend_nas_user¶
- Type:
string
- Default:
manila
User for the Infortrend NAS server.
- infortrend_nas_password¶
- Type:
string
- Default:
<None>
Password for the Infortrend NAS server. This is not necessary if infortrend_nas_ssh_key is set.
- infortrend_nas_ssh_key¶
- Type:
string
- Default:
<None>
SSH key for the Infortrend NAS server. This is not necessary if infortrend_nas_password is set.
- Type:
list
- Default:
<None>
Comma separated list of Infortrend NAS pools.
- Type:
list
- Default:
<None>
Comma separated list of Infortrend channels.
- infortrend_ssh_timeout¶
- Type:
integer
- Default:
30
SSH timeout in seconds.
- as13000_nas_ip¶
- Type:
host address
- Default:
<None>
IP address for the AS13000 storage.
- as13000_nas_port¶
- Type:
port number
- Default:
8088- Minimum Value:
0
- Maximum Value:
65535
Port number for the AS13000 storage.
- as13000_nas_login¶
- Type:
string
- Default:
<None>
Username for the AS13000 storage
- as13000_nas_password¶
- Type:
string
- Default:
<None>
Password for the AS13000 storage
- Type:
list
- Default:
<None>
The Storage Pools Manila should use, a comma separated list
- as13000_token_available_time¶
- Type:
integer
- Default:
3600
The effective time of token validity in seconds.
- instorage_nas_ip¶
- Type:
host address
- Default:
<None>
IP address for the InStorage.
- instorage_nas_port¶
- Type:
port number
- Default:
22- Minimum Value:
0
- Maximum Value:
65535
Port number for the InStorage.
- instorage_nas_login¶
- Type:
string
- Default:
<None>
Username for the InStorage.
- instorage_nas_password¶
- Type:
string
- Default:
<None>
Password for the InStorage.
- instorage_nas_pools¶
- Type:
list
- Default:
<None>
The Storage Pools Manila should use, a comma separated list.
- macrosan_nas_ip¶
- Type:
host address
- Default:
<None>
IP address for the Macrosan NAS server.
- macrosan_nas_port¶
- Type:
port number
- Default:
8443- Minimum Value:
0
- Maximum Value:
65535
Port number for the Macrosan NAS server.
- macrosan_nas_username¶
- Type:
string
- Default:
manila
Username for the Macrosan NAS server.
- macrosan_nas_password¶
- Type:
string
- Default:
<None>
Password for the Macrosan NAS server.
- macrosan_nas_http_protocol¶
- Type:
string
- Default:
https- Valid Values:
http, https
Http protocol for the Macrosan NAS server.
- macrosan_ssl_cert_verify¶
- Type:
boolean
- Default:
False
Defines whether the driver should check ssl cert.
- macrosan_nas_prefix¶
- Type:
string
- Default:
nas
Url prefix for the Macrosan NAS server.
- Type:
list
- Default:
<None>
Comma separated list of Macrosan NAS pools.
- macrosan_timeout¶
- Type:
integer
- Default:
60
request timeout in seconds.
- maprfs_clinode_ip¶
- Type:
list
- Default:
<None>
The list of IPs or hostnames of nodes where mapr-core is installed.
- maprfs_ssh_port¶
- Type:
port number
- Default:
22- Minimum Value:
0
- Maximum Value:
65535
CLDB node SSH port.
- maprfs_ssh_name¶
- Type:
string
- Default:
mapr
Cluster admin user ssh login name.
- maprfs_ssh_pw¶
- Type:
string
- Default:
<None>
Cluster node SSH login password, This parameter is not necessary, if ‘maprfs_ssh_private_key’ is configured.
- maprfs_ssh_private_key¶
- Type:
string
- Default:
<None>
Path to SSH private key for login.
- maprfs_base_volume_dir¶
- Type:
string
- Default:
/
Path in MapRFS where share volumes must be created.
- maprfs_zookeeper_ip¶
- Type:
list
- Default:
<None>
The list of IPs or hostnames of ZooKeeper nodes.
- maprfs_cldb_ip¶
- Type:
list
- Default:
<None>
The list of IPs or hostnames of CLDB nodes.
- maprfs_rename_managed_volume¶
- Type:
boolean
- Default:
True
Specify whether existing volume should be renamed when start managing.
- Type:
host address
- Default:
<None>
IP or hostname of the Lustre client mount point that is accessible to tenants. Used in export locations.
- lustre_mgs_ip¶
- Type:
host address
- Default:
<None>
IP or hostname of the Lustre MGS for SSH nodemap operations. If not set, nodemap commands run locally via oslo.privsep.
- lustre_mds_ip¶
- Type:
host address
- Default:
<None>
IP or hostname of the Lustre MDS for SSH quota operations. If not set, quota commands run locally via oslo.privsep.
- lustre_mount_point¶
- Type:
string
- Default:
/mnt/lustre
Local mount point of the Lustre filesystem on the manila-share host.
- lustre_mds_mount_point¶
- Type:
string
- Default:
<None>
Mount point of the Lustre filesystem on the MDS host. Only needed when lustre_mds_ip is set and the MDS mount path differs from lustre_mount_point. Defaults to lustre_mount_point.
- lustre_fs_name¶
- Type:
string
- Default:
<None>
Name of the Lustre filesystem.
- Type:
string
- Default:
manila_shares
Sub-directory under the mount point where Manila shares are created.
- lustre_project_id_start¶
- Type:
integer
- Default:
10000
Starting Lustre project ID for quota allocation.
- lustre_project_id_end¶
- Type:
integer
- Default:
60000
Maximum Lustre project ID for quota allocation.
- lustre_nid_type¶
- Type:
string
- Default:
tcp
Lustre NID type for client access (tcp, o2ib, etc).
- lustre_ssh_username¶
- Type:
string
- Default:
root
SSH username for connecting to Lustre MGS/MDS.
- lustre_ssh_private_key_path¶
- Type:
string
- Default:
<None>
Path to SSH private key for MGS/MDS access.
- lustre_reapply_access_on_startup¶
- Type:
boolean
- Default:
False
Reapply nodemap access rules for every share when the manila-share service starts. Nodemaps persist on the MGS, so this is not needed during normal operation. Enable temporarily to recover after a MGS rebuild or manual nodemap deletion.
- Type:
string
- Default:
$state_path/mnt
Base folder where exported shares are located.
- Type:
list
- Default:
<None>
List of IPs to export shares belonging to the LVM storage driver.
- Type:
integer
- Default:
0
If set, create LVMs with multiple mirrors. Note that this requires lvm_mirrors + 2 PVs with available space.
- Type:
string
- Default:
lvm-shares
Name for the VG that will contain exported shares.
- Type:
dict value
- Default:
{'CIFS': 'manila.share.drivers.helpers.CIFSHelperUserAccess', 'NFS': 'manila.share.drivers.helpers.NFSHelper'}
Specify list of share export helpers.
- netapp_storage_family¶
- Type:
string
- Default:
ontap_cluster
The storage family type used on the storage system; valid values include ontap_cluster for using clustered Data ONTAP.
- netapp_server_hostname¶
- Type:
host address
- Default:
<None>
The hostname (or IP address) for the storage system.
- netapp_server_port¶
- Type:
port number
- Default:
<None>- Minimum Value:
0
- Maximum Value:
65535
The TCP port to use for communication with the storage system or proxy server. If not specified, Data ONTAP drivers will use 80 for HTTP and 443 for HTTPS.
- netapp_use_legacy_client¶
- Type:
boolean
- Default:
True
The ONTAP client used for retrieving and modifying data on the storage. The legacy client relies mostly on ZAPI calls, only using REST calls for SVM migrate feature. If set to False, the new REST client is used, which runs REST calls if supported, otherwise falls back to the equivalent ZAPI call.
- netapp_transport_type¶
- Type:
string
- Default:
https
The transport protocol used when communicating with the storage system or proxy server. Valid values are http or https.
- netapp_ssl_cert_path¶
- Type:
string
- Default:
<None>
The path to a CA_BUNDLE file or directory with certificates of trusted CA. If set to a directory, it must have been processed using the c_rehash utility supplied with OpenSSL. When provided, this path is used as the trust anchor for HTTPS certificate verification. If not informed, the Mozilla Root Certificates are used by default. Applies to both REST and legacy ZAPI clients.
- netapp_ssl_cert_verify¶
- Type:
boolean
- Default:
True
If set to False, the SSL certificate of the storage system will not be verified. This is useful when the storage system uses a self-signed certificate. WARNING: disabling certificate verification is a security risk and should only be used in test and non-production environments. Applies to both the REST and legacy ZAPI clients.
- netapp_login¶
- Type:
string
- Default:
<None>
Administrative user account name used to access the storage system.
- netapp_password¶
- Type:
string
- Default:
<None>
Password for the administrative user account specified in the netapp_login option.
- netapp_private_key_file¶
- Type:
string
- Default:
/path/to/private_key.key,
This option has a sample default set, which means that its actual default value may vary from the one documented above.
For self signed certificate: This file contains the private key associated with the self-signed certificate. It is a sensitive file that should be kept secure and protected. The private key is used to sign the certificate and establish the authenticity and integrity of the certificate during the authentication process. For ca verified certificate: This file contains the private key associated with the certificate. It is generated when creating the certificate signing request (CSR) and should be kept secure and protected. The private key is used to sign the CSR and later used to establish secure connections and authenticate the entity.
- netapp_certificate_file¶
- Type:
string
- Default:
/path/to/certificate.pem
This option has a sample default set, which means that its actual default value may vary from the one documented above.
For self signed certificate: This file contains the self-signed digital certificate itself. It includes information about the entity such as the common name (e.g., domain name), organization details, validity period, and public key. The certificate file is generated based on the private key and is used by clients or systems to verify the entity identity during the authentication process. For ca verified certificate: This file contains the digital certificate issued by the trusted third-party certificate authority (CA). It includes information about the entity identity, public key, and the CA that issued the certificate. The certificate file is used by clients or systems to verify the authenticity and integrity of the entity during the authentication process.
- netapp_ca_certificate_file¶
- Type:
string
- Default:
/path/to/ca_certificate.crt
This option has a sample default set, which means that its actual default value may vary from the one documented above.
This is applicable only for ca verified certificate. This file contains the public key certificate of the trusted third-party certificate authority (CA) that issued the certificate. It is used by clients or systems to validate the authenticity of the certificate presented by the entity. The CA certificate file is typically pre-configured in the trust store of clients or systems to establish trust in certificates issued by that CA.
- netapp_certificate_host_validation¶
- Type:
boolean
- Default:
False
Enable certificate verification
- Type:
list
- Default:
['nfs3', 'nfs4.0']
The NFS protocol versions that will be enabled. Supported values include nfs3, nfs4.0, nfs4.1. This option only applies when the option driver_handles_share_servers is set to True.
- netapp_volume_name_template¶
- Type:
string
- Default:
share_%(share_id)s
NetApp volume name template.
- netapp_vserver_name_template¶
- Type:
string
- Default:
os_%s
Name template to use for new Vserver. When using CIFS protocol make sure to not configure characters illegal in DNS hostnames.
- netapp_qos_policy_group_name_template¶
- Type:
string
- Default:
qos_share_%(share_id)s
NetApp QoS policy group name template.
- netapp_port_name_search_pattern¶
- Type:
string
- Default:
(.*)
Pattern for overriding the selection of network ports on which to create Vserver LIFs.
- netapp_lif_name_template¶
- Type:
string
- Default:
os_%(net_allocation_id)s
Logical interface (LIF) name template
- netapp_identity_auth_token_path¶
- Type:
string
- Default:
''
Path to interact with auth tokens
- netapp_aggregate_name_search_pattern¶
- Type:
string
- Default:
(.*)
Pattern for searching available aggregates for provisioning.
- netapp_root_volume_aggregate¶
- Type:
string
- Default:
<None>
Name of aggregate to create Vserver root volumes on. This option only applies when the option driver_handles_share_servers is set to True.
- netapp_root_volume¶
- Type:
string
- Default:
root
Root volume name.
- netapp_delete_retention_hours¶
- Type:
integer
- Default:
12- Minimum Value:
0
The number of hours that a deleted volume should be retained before the delete is completed.
- netapp_volume_snapshot_reserve_percent¶
- Type:
integer
- Default:
5- Minimum Value:
0
- Maximum Value:
90
The percentage of share space set aside as reserve for snapshot usage; valid values range from 0 to 90.
- netapp_reset_snapdir_visibility¶
- Type:
string
- Default:
default- Valid Values:
visible, hidden, default
This option forces all existing shares to have their snapshot directory visibility set to either ‘visible’ or ‘hidden’ during driver startup. If set to ‘default’, nothing will be changed during startup. This will not affect new shares, which will have their snapshot directory always visible, unless toggled by the share type extra spec ‘netapp:hide_snapdir’.
- netapp_volume_snapshot_policy_exceptions¶
- Type:
list
- Default:
['ec2_backups']
NetApp volume Snapshot policy names which will not be overriden by extra-specs.
- netapp_snapmirror_policy_name_svm_template¶
- Type:
string
- Default:
snapmirror_policy_%(share_server_id)s
NetApp SnapMirror policy name template for Storage Virtual Machines (Vservers).
- netapp_fpolicy_default_file_operations¶
- Type:
list
- Default:
['create', 'write', 'rename']
NetApp FPolicy file operations to apply to a FPolicy event, when not provided by the user using “netapp:fpolicy_file_operations” extra-spec.
- netapp_fpolicy_policy_name_template¶
- Type:
string
- Default:
fpolicy_policy_%(share_id)s
NetApp FPolicy policy name template.
- netapp_fpolicy_event_name_template¶
- Type:
string
- Default:
fpolicy_event_%(protocol)s_%(share_id)s
NetApp FPolicy policy name template.
- netapp_cached_aggregates_status_lifetime¶
- Type:
integer
- Default:
60- Minimum Value:
0
The maximum time in seconds that the cached aggregates status will be considered valid. Trying to read the expired cache leads to refreshing it.
- netapp_enable_flexgroup¶
- Type:
boolean
- Default:
False
Specify if the FlexGroup pool is enabled. When it is enabled, the driver will report a single pool representing all aggregates (ONTAP chooses on which the share will be allocated). If you want to Manila control the aggregate selection, you can configure its custom FlexGroup pools through netapp_flexgroup_pools option. The FlexGroup placement is done either by ONTAP or Manila, not both.
- netapp_flexgroup_pools¶
- Type:
dict value
- Default:
{}
Multi opt of dict to represent the FlexGroup pools. A FlexGroup pool is configured with its name and its list of aggregates. Specify this option as many times as you have FlexGroup pools. Each entry takes the dict config form: netapp_flexgroup_pools = <pool_name>: <aggr_name1> <aggr_name2> ..
- netapp_flexgroup_pool_only¶
- Type:
boolean
- Default:
False
Specify if the FlexVol pools must not be reported when the netapp_enable_flexgroup is enabled.
- netapp_flexgroup_volume_online_timeout¶
- Type:
integer
- Default:
360- Minimum Value:
60
Sets time in seconds to wait for a FlexGroup volume create to complete and go online.
- netapp_flexgroup_aggregate_not_busy_timeout¶
- Type:
integer
- Default:
360- Minimum Value:
60
Provisioning FlexGroup share requires that all of its aggregates to not be busy deploying another volume. So, sets time in seconds to retry to create the FlexGroup share.
- netapp_delete_busy_flexgroup_snapshot_timeout¶
- Type:
integer
- Default:
360- Minimum Value:
60
Sets time in seconds to wait for a FlexGroup snapshot to not be busy with clones after splitting them.
- netapp_rest_operation_timeout¶
- Type:
integer
- Default:
60- Minimum Value:
60
Sets maximum amount of time in seconds to wait for a synchronous ONTAP REST API operation to be completed.
- netapp_zapi_fallback_enabled¶
- Type:
boolean
- Default:
True
This option allows ONTAP REST client methods to fallback to ZAPI when a REST method is not implemented.
- netapp_security_cert_expire_days¶
- Type:
integer
- Default:
365- Minimum Value:
1
- Maximum Value:
3652
Defines the expiration time (in days) for the certificate created during the vserver creation. This option only applies when the option driver_handles_share_servers is set to True.
- netapp_restrict_lif_creation_per_ha_pair¶
- Type:
boolean
- Default:
False
Prevent the creation of a share server if total number of data LIFs on one node of HA pair, including those that can be migrated in case of failure, exceeds the maximum data LIFs supported by the node. This option guarantees that, in the event of a node failure, the partner node will be able to takeover all data LIFs.
- netapp_cifs_aes_encryption¶
- Type:
boolean
- Default:
False
This option enable/disable AES encryption for the share server based on the parameter value (True/False).
- netapp_enable_logical_space_reporting¶
- Type:
boolean
- Default:
False
This option enables the logical space reporting on a newly created vserver and logical space accounting on newly created volumes on this vserver.
- netapp_fixed_qos_policy_prefix¶
- Type:
string
- Default:
FIXED_QOS
This option enables user to configure the prefix of fixed QoS policies created on vserver.
- netapp_adaptive_qos_policy_prefix¶
- Type:
string
- Default:
ADAPTIVE_QOS
This option enables user to configure the prefix of adaptive QoS policies created on vserver.
- netapp_cifs_smb_signing¶
- Type:
boolean
- Default:
False
This option enable/disable SMB signing that protects the security of the data fabric by making sure that traffic between storage systems and clients is not compromised.
- netapp_dns_domains¶
- Type:
list
- Default:
[]
DNS search domains for SVMs (max 6, DHSS=True only). Must be paired with netapp_dns_nameservers.
- netapp_dns_nameservers¶
- Type:
list
- Default:
[]
DNS server IPs for SVMs (max 3, DHSS=True only). Must be paired with netapp_dns_domains.
- netapp_dns_hosts¶
- Type:
list
- Default:
[]
Static hostname:ip fallbacks for the SVM local-hosts table. Requires netapp_dns_domains and netapp_dns_nameservers. Supports “host1,host2:ip” shorthand for shared IPs.
- netapp_snapmirror_quiesce_timeout¶
- Type:
integer
- Default:
3600- Minimum Value:
0
The maximum time in seconds to wait for existing snapmirror transfers to complete before aborting when promoting a replica.
- netapp_snapmirror_release_timeout¶
- Type:
integer
- Default:
3600- Minimum Value:
0
The maximum time in seconds to wait for a snapmirror release when breaking snapmirror relationships.
- netapp_snapmirror_schedule¶
- Type:
string
- Default:
hourly
An interval in either minutes or hours used to update the SnapMirror relationship. Few valid values are: 5min, 10min, 30min, hourly etc. The schedule at the “destination” host will be the one that will be considered when creating a new replica, or promoting a replica
- netapp_volume_move_cutover_timeout¶
- Type:
integer
- Default:
3600- Minimum Value:
0
The maximum time in seconds to wait for the completion of a volume move operation after the cutover was triggered.
- netapp_start_volume_move_timeout¶
- Type:
integer
- Default:
3600- Minimum Value:
0
The maximum time in seconds to wait for the completion of a volume clone split operation in order to start a volume move.
- netapp_migration_cancel_timeout¶
- Type:
integer
- Default:
3600- Minimum Value:
0
The maximum time in seconds that migration cancel waits for all migration operations be completely aborted.
- netapp_server_migration_state_change_timeout¶
- Type:
integer
- Default:
3600- Minimum Value:
0
The maximum time in seconds that a share server migration waits for a vserver to change its internal states.
- netapp_server_migration_check_capacity¶
- Type:
boolean
- Default:
True
Specify if the capacity check must be made by the driver while performing a share server migration. If enabled, the driver will validate if the destination backend can hold all shares and snapshots capacities from the source share server.
- netapp_mount_replica_timeout¶
- Type:
integer
- Default:
3600- Minimum Value:
0
The maximum time in seconds to wait for mounting a replica.
- netapp_enabled_backup_types¶
- Type:
list
- Default:
[]
Specify compatible backup_types for backend to provision backup share for SnapVault relationship. Multiple backup_types can be provided. If multiple backup types are enabled, create separate config sections for each backup type specifying the “netapp_backup_vserver”, “netapp_backup_backend_section_name”, “netapp_backup_volume”, and “netapp_snapmirror_job_timeout” as appropriate. Example- netapp_enabled_backup_types = eng_backup, finance_backup
- netapp_backup_backend_section_name¶
- Type:
string
- Default:
<None>
Backend (ONTAP cluster) name where backup volume will be provisioned. This is one of the backend which is enabled in manila.conf file.
- netapp_backup_vserver¶
- Type:
string
- Default:
''
vserver name of backend that is use for backup the share. When user provide vserver value then backup volume will be created under this vserver
- netapp_backup_volume¶
- Type:
string
- Default:
''
Specify backup share name in case user wanted to backup the share. Some case user has dedicated volume for backup in this case use can provide dedicated volume. backup_share_server must be specified if backup_share is provided
- netapp_snapmirror_job_timeout¶
- Type:
integer
- Default:
1800- Minimum Value:
0
The maximum time in seconds to wait for a snapmirror related operation to backup to complete.
- nexenta_rest_addresses¶
- Type:
list
- Default:
<None>
One or more comma delimited IP addresses for management communication with NexentaStor appliance.
- nexenta_rest_port¶
- Type:
integer
- Default:
8443
Port to connect to Nexenta REST API server.
- nexenta_rest_protocol¶
- Type:
string
- Default:
auto- Valid Values:
http, https, auto
Use http or https for REST connection (default auto).
- nexenta_use_https¶
- Type:
boolean
- Default:
True
Use HTTP secure protocol for NexentaStor management REST API connections
- nexenta_user¶
- Type:
string
- Default:
admin
User name to connect to Nexenta SA.
- nexenta_password¶
- Type:
string
- Default:
<None>
Password to connect to Nexenta SA.
- nexenta_volume¶
- Type:
string
- Default:
volume1
Volume name on NexentaStor.
- nexenta_pool¶
- Type:
string
- Default:
pool1
Pool name on NexentaStor.
- nexenta_nfs¶
- Type:
boolean
- Default:
True
Defines whether share over NFS is enabled.
- nexenta_ssl_cert_verify¶
- Type:
boolean
- Default:
False
Defines whether the driver should check ssl cert.
- nexenta_rest_connect_timeout¶
- Type:
floating point
- Default:
30
Specifies the time limit (in seconds), within which the connection to NexentaStor management REST API server must be established
- nexenta_rest_read_timeout¶
- Type:
floating point
- Default:
300
Specifies the time limit (in seconds), within which NexentaStor management REST API server must send a response
- nexenta_rest_backoff_factor¶
- Type:
floating point
- Default:
1
Specifies the backoff factor to apply between connection attempts to NexentaStor management REST API server
- nexenta_rest_retry_count¶
- Type:
integer
- Default:
5
Specifies the number of times to repeat NexentaStor management REST API call in case of connection errors and NexentaStor appliance EBUSY or ENOENT errors
- Type:
string
- Default:
nfs_share
Parent filesystem where all the shares will be created. This parameter is only used by NexentaStor4 driver.
- Type:
string
- Default:
share-
Nexenta share name prefix.
- nexenta_folder¶
- Type:
string
- Default:
folder
Parent folder on NexentaStor.
- nexenta_dataset_compression¶
- Type:
string
- Default:
on- Valid Values:
on, off, gzip, gzip-1, gzip-2, gzip-3, gzip-4, gzip-5, gzip-6, gzip-7, gzip-8, gzip-9, lzjb, zle, lz4
Compression value for new ZFS folders.
- nexenta_dataset_dedupe¶
- Type:
string
- Default:
off- Valid Values:
on, off, sha256, verify
Deduplication value for new ZFS folders. Only used by NexentaStor4 driver.
- nexenta_thin_provisioning¶
- Type:
boolean
- Default:
True
If True shares will not be space guaranteed and overprovisioning will be enabled.
- nexenta_dataset_record_size¶
- Type:
integer
- Default:
131072
Specifies a suggested block size in for files in a file system. (bytes)
- nexenta_nas_host¶
- Type:
host address
- Default:
<None>
Data IP address of Nexenta storage appliance.
- nexenta_mount_point_base¶
- Type:
string
- Default:
$state_path/mnt
Base directory that contains NFS share mount points.
- flashblade_api¶
- Type:
string
- Default:
<None>
API token for an administrative user account
- flashblade_eradicate¶
- Type:
boolean
- Default:
True
When enabled, all FlashBlade file systems and snapshots will be eradicated at the time of deletion in Manila. Data will NOT be recoverable after a delete with this set to True! When disabled, file systems and snapshots will go into pending eradication state and can be recovered.)
- flashblade_mgmt_vip¶
- Type:
host address
- Default:
<None>
The name (or IP address) for the Pure Storage FlashBlade storage system management VIP.
- flashblade_data_vip¶
- Type:
list
- Default:
<None>
The names (or IP address) for the Pure Storage FlashBlade storage system data VIPs. The first listed name or IP address will be considered to be the preferred IP address, although is not enforced.
- flashblade_ssl_cert_verify¶
- Type:
boolean
- Default:
True
If set to True, the driver verifies the SSL certificate presented by the FlashBlade management interface. This is enabled by default. If the FlashBlade uses a self-signed or private CA certificate, supply the CA certificate bundle via flashblade_ca_cert_path. Setting this to False disables verification and is not recommended.
- flashblade_ca_cert_path¶
- Type:
string
- Default:
<None>
Path to a CA certificate bundle file (PEM format) used to verify the FlashBlade management interface’s SSL certificate. Only used when flashblade_ssl_cert_verify is True. If unset, the system default CA certificates are used.
- qnap_management_url¶
- Type:
string
- Default:
<None>
The URL to manage QNAP Storage.
- Type:
host address
- Default:
<None>
NAS share IP for mounting shares.
- qnap_nas_login¶
- Type:
string
- Default:
<None>
Username for QNAP storage.
- qnap_nas_password¶
- Type:
string
- Default:
<None>
Password for QNAP storage.
- qnap_poolname¶
- Type:
string
- Default:
<None>
Pool within which QNAP shares must be created.
- quobyte_api_url¶
- Type:
string
- Default:
<None>
URL of the Quobyte API server (http or https)
- quobyte_api_ca¶
- Type:
string
- Default:
<None>
The X.509 CA file to verify the server cert.
- Type:
boolean
- Default:
False
Actually deletes shares (vs. unexport)
- quobyte_api_username¶
- Type:
string
- Default:
admin
Username for Quobyte API server.
- quobyte_api_password¶
- Type:
string
- Default:
quobyte
Password for Quobyte API server
- quobyte_volume_configuration¶
- Type:
string
- Default:
BASE
Name of volume configuration used for new shares.
- quobyte_default_volume_user¶
- Type:
string
- Default:
root
Default owning user for new volumes.
- quobyte_default_volume_group¶
- Type:
string
- Default:
root
Default owning group for new volumes.
- quobyte_export_path¶
- Type:
string
- Default:
/quobyte
Export path for shares of this bacckend. This needs to match the quobyte-nfs services “Pseudo” option.
- service_instance_user¶
- Type:
string
- Default:
<None>
User in service instance that will be used for authentication.
- service_instance_password¶
- Type:
string
- Default:
<None>
Password for service instance user.
- path_to_private_key¶
- Type:
string
- Default:
<None>
Path to host’s private key.
- max_time_to_build_instance¶
- Type:
integer
- Default:
300
Maximum time in seconds to wait for creating service instance.
- limit_ssh_access¶
- Type:
boolean
- Default:
False
Block SSH connection to the service instance from other networks than service network.
- service_instance_name_or_id¶
- Type:
string
- Default:
<None>
Name or ID of service instance in Nova to use for share exports. Used only when share servers handling is disabled.
- service_net_name_or_ip¶
- Type:
host address
- Default:
<None>
Can be either name of network that is used by service instance within Nova to get IP address or IP address itself (either IPv4 or IPv6) for managing shares there. Used only when share servers handling is disabled.
- tenant_net_name_or_ip¶
- Type:
host address
- Default:
<None>
Can be either name of network that is used by service instance within Nova to get IP address or IP address itself (either IPv4 or IPv6) for exporting shares. Used only when share servers handling is disabled.
- service_image_name¶
- Type:
string
- Default:
manila-service-image
Name of image in Glance, that will be used for service instance creation. Only used if driver_handles_share_servers=True.
- service_instance_name_template¶
- Type:
string
- Default:
%s
Name of service instance. Only used if driver_handles_share_servers=True.
- manila_service_keypair_name¶
- Type:
string
- Default:
manila-service
Keypair name that will be created and used for service instances. Only used if driver_handles_share_servers=True.
- path_to_public_key¶
- Type:
string
- Default:
~/.ssh/id_rsa.pub
Path to hosts public key. Only used if driver_handles_share_servers=True.
- service_instance_security_group¶
- Type:
string
- Default:
manila-service
Security group name, that will be used for service instance creation. Only used if driver_handles_share_servers=True.
- service_instance_flavor_id¶
- Type:
string
- Default:
100
ID of flavor, that will be used for service instance creation. Only used if driver_handles_share_servers=True.
- service_network_name¶
- Type:
string
- Default:
manila_service_network
Name of manila service network. Used only with Neutron. Only used if driver_handles_share_servers=True.
- service_network_host¶
- Type:
host address
- Default:
<your_network_hostname>
This option has a sample default set, which means that its actual default value may vary from the one documented above.
Hostname to be used for service network binding. Used only with Neutron and if driver_handles_share_servers=True.
- service_network_cidr¶
- Type:
string
- Default:
10.254.0.0/16
CIDR of manila service network. Used only with Neutron and if driver_handles_share_servers=True.
- service_network_division_mask¶
- Type:
integer
- Default:
28
This mask is used for dividing service network into subnets, IP capacity of subnet with this mask directly defines possible amount of created service VMs per tenant’s subnet. Used only with Neutron and if driver_handles_share_servers=True.
- interface_driver¶
- Type:
string
- Default:
manila.network.linux.interface.OVSInterfaceDriver
Module path to the Virtual Interface (VIF) driver class. This option is used only by drivers operating in driver_handles_share_servers=True mode that provision OpenStack compute instances as share servers. This option is only supported with Neutron networking. Drivers provided in tree work with Linux Bridge (manila.network.linux.interface.BridgeInterfaceDriver) and OVS (manila.network.linux.interface.OVSInterfaceDriver). If the manila-share service is running on a host that is connected to the administrator network, a no-op driver (manila.network.linux.interface.NoopInterfaceDriver) may be used.
- Type:
boolean
- Default:
False
Attach share server directly to share network. Used only with Neutron and if driver_handles_share_servers=True.
- admin_network_id¶
- Type:
string
- Default:
<None>
ID of neutron network used to communicate with admin network, to create additional admin export locations on.
- admin_subnet_id¶
- Type:
string
- Default:
<None>
ID of neutron subnet used to communicate with admin network, to create additional admin export locations on. Related to ‘admin_network_id’.
- service_instance_boot_from_volume¶
- Type:
boolean
- Default:
False
Boot service instances (share servers) from a Cinder volume. If False, boot from the image as before. Only used if driver_handles_share_servers=True.
- service_instance_boot_volume_size¶
- Type:
integer
- Default:
10- Minimum Value:
1
Size (GiB) of the root volume when booting from volume. Only used if driver_handles_share_servers=True.
- service_instance_boot_volume_type¶
- Type:
string
- Default:
<None>
Name or id of cinder volume type which will be used for all boot volumes created by driver.
- service_instance_base_boot_volume_id¶
- Type:
string
- Default:
<None>
UUID of volume in Cinder, that will be used as base volume that bootable volume clone from during service instance creation. Only used if driver_handles_share_servers=True.
- service_instance_boot_volume_delete_on_termination¶
- Type:
boolean
- Default:
True
Whether the root volume is deleted when the service instance is terminated. Only used if driver_handles_share_servers=True.
- service_instance_boot_volume_name_template¶
- Type:
string
- Default:
manila-share-%s-boot
Boot volume name template.
- tegile_nas_server¶
- Type:
host address
- Default:
<None>
Tegile NAS server hostname or IP address.
- tegile_nas_login¶
- Type:
string
- Default:
<None>
User name for the Tegile NAS server.
- tegile_nas_password¶
- Type:
string
- Default:
<None>
Password for the Tegile NAS server.
- tegile_default_project¶
- Type:
string
- Default:
<None>
Create shares in this project
- winrm_cert_pem_path¶
- Type:
string
- Default:
~/.ssl/cert.pem
Path to the x509 certificate used for accessing the service instance.
- winrm_cert_key_pem_path¶
- Type:
string
- Default:
~/.ssl/key.pem
Path to the x509 certificate key.
- winrm_use_cert_based_auth¶
- Type:
boolean
- Default:
False
Use x509 certificates in order to authenticate to the service instance.
- winrm_conn_timeout¶
- Type:
integer
- Default:
60
WinRM connection timeout.
- winrm_operation_timeout¶
- Type:
integer
- Default:
60
WinRM operation timeout.
- winrm_retry_count¶
- Type:
integer
- Default:
3
WinRM retry count.
- winrm_retry_interval¶
- Type:
integer
- Default:
5
WinRM retry interval in seconds
- Type:
host address
- Default:
<None>
IP to be added to user-facing export location. Required.
- zfs_service_ip¶
- Type:
host address
- Default:
<None>
IP to be added to admin-facing export location. Required.
- zfs_zpool_list¶
- Type:
list
- Default:
<None>
Specify list of zpools that are allowed to be used by backend. Can contain nested datasets. Examples: Without nested dataset: ‘zpool_name’. With nested dataset: ‘zpool_name/nested_dataset_name’. Required.
- zfs_dataset_creation_options¶
- Type:
list
- Default:
<None>
Define here list of options that should be applied for each dataset creation if needed. Example: compression=gzip,dedup=off. Note that, for secondary replicas option ‘readonly’ will be set to ‘on’ and for active replicas to ‘off’ in any way. Also, ‘quota’ will be equal to share size. Optional.
- zfs_dataset_name_prefix¶
- Type:
string
- Default:
manila_share_
Prefix to be used in each dataset name. Optional.
- zfs_dataset_snapshot_name_prefix¶
- Type:
string
- Default:
manila_share_snapshot_
Prefix to be used in each dataset snapshot name. Optional.
- zfs_use_ssh¶
- Type:
boolean
- Default:
False
Remote ZFS storage hostname that should be used for SSH’ing. Optional.
- zfs_ssh_username¶
- Type:
string
- Default:
<None>
SSH user that will be used in 2 cases: 1) By manila-share service in case it is located on different host than its ZFS storage. 2) By manila-share services with other ZFS backends that perform replication. It is expected that SSH’ing will be key-based, passwordless. This user should be passwordless sudoer. Optional.
- zfs_ssh_user_password¶
- Type:
string
- Default:
<None>
Password for user that is used for SSH’ing ZFS storage host. Not used for replication operations. They require passwordless SSH access. Optional.
- zfs_ssh_private_key_path¶
- Type:
string
- Default:
<None>
Path to SSH private key that should be used for SSH’ing ZFS storage host. Not used for replication operations. Optional.
- Type:
dict value
- Default:
{'NFS': 'manila.share.drivers.zfsonlinux.utils.NFSviaZFSHelper'}
Specify list of share export helpers for ZFS storage. It should look like following: ‘FOO_protocol=foo.FooClass,BAR_protocol=bar.BarClass’. Required.
- zfs_replica_snapshot_prefix¶
- Type:
string
- Default:
tmp_snapshot_for_replication_
Set snapshot prefix for usage in ZFS replication. Required.
- zfs_migration_snapshot_prefix¶
- Type:
string
- Default:
tmp_snapshot_for_share_migration_
Set snapshot prefix for usage in ZFS migration. Required.
- zfssa_host¶
- Type:
host address
- Default:
<None>
ZFSSA management IP address.
- zfssa_data_ip¶
- Type:
host address
- Default:
<None>
IP address for data.
- zfssa_auth_user¶
- Type:
string
- Default:
<None>
ZFSSA management authorized username.
- zfssa_auth_password¶
- Type:
string
- Default:
<None>
ZFSSA management authorized user’s password.
- zfssa_pool¶
- Type:
string
- Default:
<None>
ZFSSA storage pool name.
- zfssa_project¶
- Type:
string
- Default:
<None>
ZFSSA project name.
- zfssa_nas_checksum¶
- Type:
string
- Default:
fletcher4
Controls checksum used for data blocks.
- zfssa_nas_compression¶
- Type:
string
- Default:
off
Data compression-off, lzjb, gzip-2, gzip, gzip-9.
- zfssa_nas_logbias¶
- Type:
string
- Default:
latency
Controls behavior when servicing synchronous writes.
- zfssa_nas_mountpoint¶
- Type:
string
- Default:
''
Location of project in ZFS/SA.
- zfssa_nas_quota_snap¶
- Type:
string
- Default:
true
Controls whether a share quota includes snapshot.
- zfssa_nas_rstchown¶
- Type:
string
- Default:
true
Controls whether file ownership can be changed.
- zfssa_nas_vscan¶
- Type:
string
- Default:
false
Controls whether the share is scanned for viruses.
- zfssa_rest_timeout¶
- Type:
string
- Default:
<None>
REST connection timeout (in seconds).
- zfssa_manage_policy¶
- Type:
string
- Default:
loose- Valid Values:
loose, strict
Driver policy for share manage. A strict policy checks for a schema named manila_managed, and makes sure its value is true. A loose policy does not check for the schema.
- enable_pre_hooks¶
- Type:
boolean
- Default:
False
Whether to enable pre hooks or not.
- enable_post_hooks¶
- Type:
boolean
- Default:
False
Whether to enable post hooks or not.
- enable_periodic_hooks¶
- Type:
boolean
- Default:
False
Whether to enable periodic hooks or not.
- suppress_pre_hooks_errors¶
- Type:
boolean
- Default:
False
Whether to suppress pre hook errors (allow driver perform actions) or not.
- suppress_post_hooks_errors¶
- Type:
boolean
- Default:
False
Whether to suppress post hook errors (allow driver’s results to pass through) or not.
- periodic_hooks_interval¶
- Type:
floating point
- Default:
300.0
Interval in seconds between execution of periodic hooks. Used when option ‘enable_periodic_hooks’ is set to True. Default is 300.
- Type:
string
- Default:
manila.share.drivers.generic.GenericShareDriver
Driver to use for share creation.
- hook_drivers¶
- Type:
list
- Default:
[]
Driver(s) to perform some additional actions before and after share driver actions and on a periodic basis. Default is [].
- Type:
boolean
- Default:
False
Whether share servers will be deleted on deletion of the last share.
- unmanage_remove_access_rules¶
- Type:
boolean
- Default:
False
If set to True, then manila will deny access and remove all access rules on share unmanage.If set to False - nothing will be changed.
- Type:
boolean
- Default:
True
If set to True, then Manila will delete all share servers which were unused more than specified time .If set to False - automatic deletion of share servers will be disabled.
- Type:
integer
- Default:
10- Minimum Value:
10
- Maximum Value:
720
Unallocated share servers reclamation time interval (minutes). Minimum value is 10 minutes, maximum is 720 minutes. The reclamation function is run every 10 minutes and delete share servers which were unused more than unused_share_server_cleanup_interval option defines. This value reflects the shortest time Manila will wait for a share server to go unutilized before deleting it.
- replica_state_update_interval¶
- Type:
integer
- Default:
300
This value, specified in seconds, determines how often the share manager will poll for the health (replica_state) of each replica instance.
- migration_driver_continue_update_interval¶
- Type:
integer
- Default:
60
This value, specified in seconds, determines how often the share manager will poll the driver to perform the next step of migration in the storage backend, for a migrating share.
- server_migration_driver_continue_update_interval¶
- Type:
integer
- Default:
900
This value, specified in seconds, determines how often the share manager will poll the driver to perform the next step of migration in the storage backend, for a migrating share server.
- server_migration_extend_neutron_network¶
- Type:
boolean
- Default:
False
If set to True, neutron network are extended to destination host during share server migration. This option should only be enabled if using NeutronNetworkPlugin or its derivatives and when multiple bindings of Manila ports are supported by Neutron ML2 plugin.
- Type:
integer
- Default:
300
This value, specified in seconds, determines how often the share manager will poll the driver to update the share usage size in the storage backend, for shares in that backend.
- Type:
boolean
- Default:
False
If set to True, share usage size will be polled for in the interval specified with “share_usage_size_update_interval”. Usage data can be consumed by telemetry integration. If telemetry is not configured, this option must be set to False. If set to False - gathering share usage size will be disabled.
- Type:
boolean
- Default:
False
Offload pending share ensure during share service startup
- Type:
integer
- Default:
3600
This value, specified in seconds, determines how often the share manager will check for expired shares and delete them from the Recycle bin.
- check_for_expired_transfers¶
- Type:
integer
- Default:
300
This value, specified in seconds, determines how often the share manager will check for expired transfers and destroy them and roll back share state.
- driver_backup_continue_update_interval¶
- Type:
integer
- Default:
60
This value, specified in seconds, determines how often the share manager will poll to perform the next steps of backup such as fetch the progress of backup.
- driver_restore_continue_update_interval¶
- Type:
integer
- Default:
60
This value, specified in seconds, determines how often the share manager will poll to perform the next steps of restore such as fetch the progress of restore.
- periodic_deferred_delete_interval¶
- Type:
integer
- Default:
300
This value, specified in seconds, determines how often the share manager will try to delete the share and share snapshots in backend driver.
- volume_api_class¶
- Type:
string
- Default:
manila.volume.cinder.API
The full class name of the Volume API class to use.
- tcp_keepalive¶
- Type:
boolean
- Default:
True
Sets the value of TCP_KEEPALIVE (True/False) for each server socket.
- tcp_keepalive_interval¶
- Type:
integer
- Default:
<None>
Sets the value of TCP_KEEPINTVL in seconds for each server socket. Not supported on OS X.
- tcp_keepalive_count¶
- Type:
integer
- Default:
<None>
Sets the value of TCP_KEEPCNT for each server socket. Not supported on OS X.
- vast_mgmt_host¶
- Type:
host address
- Default:
<None>
Hostname or IP address VAST storage system management VIP.
- vast_mgmt_port¶
- Type:
port number
- Default:
443- Minimum Value:
0
- Maximum Value:
65535
Port for VAST management
- vast_vippool_name¶
- Type:
string
- Default:
<None>
Name of Virtual IP pool
- vast_root_export¶
- Type:
string
- Default:
manila
Base path for shares
- vast_mgmt_user¶
- Type:
string
- Default:
<None>
Username for VAST management
- vast_mgmt_password¶
- Type:
string
- Default:
<None>
Password for VAST management
- vast_api_token¶
- Type:
string
- Default:
''
API token for accessing VAST mgmt. If provided, it will be used instead of ‘san_login’ and ‘san_password’.
- executor_thread_pool_size¶
- Type:
integer
- Default:
64
Size of executor thread pool when executor is threading or eventlet.
Deprecated Variations¶ Group
Name
DEFAULT
rpc_thread_pool_size
- rpc_response_timeout¶
- Type:
integer
- Default:
60
Seconds to wait for a response from a call.
- transport_url¶
- Type:
string
- Default:
rabbit://
The network address and optional user credentials for connecting to the messaging backend, in URL format. The expected format is:
driver://[user:pass@]host:port[,[userN:passN@]hostN:portN]/virtual_host?query
Example: rabbit://rabbitmq:password@127.0.0.1:5672//
For full details on the fields in the URL see the documentation of oslo_messaging.TransportURL at https://docs.openstack.org/oslo.messaging/latest/reference/transport.html
- control_exchange¶
- Type:
string
- Default:
openstack
The default exchange under which topics are scoped. May be overridden by an exchange name specified in the transport_url option.
- rpc_ping_enabled¶
- Type:
boolean
- Default:
False
Add an endpoint to answer to ping calls. Endpoint is named oslo_rpc_server_ping
- run_external_periodic_tasks¶
- Type:
boolean
- Default:
True
Some periodic tasks can be run in a separate process. Should we run them here?
- backdoor_port¶
- Type:
string
- Default:
<None>
Enable eventlet backdoor. Acceptable values are 0, <port>, and <start>:<end>, where 0 results in listening on a random tcp port number; <port> results in listening on the specified port number (and not enabling backdoor if that port is in use); and <start>:<end> results in listening on the smallest unused port number within the specified range of port numbers. The chosen port is displayed in the service’s log file.
Warning
This option is deprecated for removal. Its value may be silently ignored in the future.
- Reason:
The ‘backdoor_port’ option is deprecated and will be removed in a future release.
- backdoor_socket¶
- Type:
string
- Default:
<None>
Enable eventlet backdoor, using the provided path as a unix socket that can receive connections. This option is mutually exclusive with ‘backdoor_port’ in that only one should be provided. If both are provided then the existence of this option overrides the usage of that option. Inside the path {pid} will be replaced with the PID of the current process.
Warning
This option is deprecated for removal. Its value may be silently ignored in the future.
- Reason:
The ‘backdoor_socket’ option is deprecated and will be removed in a future release.
- log_options¶
- Type:
boolean
- Default:
True
Enables or disables logging values of all registered options when starting a service (at DEBUG level).
- graceful_shutdown_timeout¶
- Type:
integer
- Default:
60
Specify a timeout after which a gracefully shutdown server will exit. Zero value means endless wait.
- api_paste_config¶
- Type:
string
- Default:
api-paste.ini
File name for the paste.deploy config for api service
Warning
This option is deprecated for removal. Its value may be silently ignored in the future.
- Reason:
The ‘api_paste_config’ option is deprecated and will be removed in a future release.
- wsgi_log_format¶
- Type:
string
- Default:
%(client_ip)s "%(request_line)s" status: %(status_code)s len: %(body_length)s time: %(wall_seconds).7f
A python format string that is used as the template to generate log lines. The following values can beformatted into it: client_ip, date_time, request_line, status_code, body_length, wall_seconds.
Warning
This option is deprecated for removal. Its value may be silently ignored in the future.
- Reason:
The ‘wsgi_log_format’ option is deprecated and will be removed in a future release.
- tcp_keepidle¶
- Type:
integer
- Default:
600
Sets the value of TCP_KEEPIDLE in seconds for each server socket. Not supported on OS X.
Warning
This option is deprecated for removal. Its value may be silently ignored in the future.
- Reason:
The ‘tcp_keepidle’ option is deprecated and will be removed in a future release.
- wsgi_default_pool_size¶
- Type:
integer
- Default:
100
Size of the pool of greenthreads used by wsgi
Warning
This option is deprecated for removal. Its value may be silently ignored in the future.
- Reason:
The ‘wsgi_default_pool_size’ option is deprecated and will be removed in a future release.
- max_header_line¶
- Type:
integer
- Default:
16384
Maximum line size of message headers to be accepted. max_header_line may need to be increased when using large tokens (typically those generated when keystone is configured to use PKI tokens with big service catalogs).
Warning
This option is deprecated for removal. Its value may be silently ignored in the future.
- Reason:
The ‘max_header_line’ option is deprecated and will be removed in a future release.
- wsgi_keep_alive¶
- Type:
boolean
- Default:
True
If False, closes the client socket connection explicitly.
Warning
This option is deprecated for removal. Its value may be silently ignored in the future.
- Reason:
The ‘wsgi_keep_alive’ option is deprecated and will be removed in a future release.
- client_socket_timeout¶
- Type:
integer
- Default:
900
Timeout for client connections’ socket operations. If an incoming connection is idle for this number of seconds it will be closed. A value of ‘0’ means wait forever.
Warning
This option is deprecated for removal. Its value may be silently ignored in the future.
- Reason:
The ‘client_socket_timeout’ option is deprecated and will be removed in a future release.
- wsgi_server_debug¶
- Type:
boolean
- Default:
False
True if the server should send exception tracebacks to the clients on 500 errors. If False, the server will respond with empty bodies.
Warning
This option is deprecated for removal. Its value may be silently ignored in the future.
- Reason:
The ‘wsgi_server_debug’ option is deprecated and will be removed in a future release.
- debug¶
- Type:
boolean
- Default:
False- Mutable:
This option can be changed without restarting.
If set to true, the logging level will be set to DEBUG instead of the default INFO level.
- log_config_append¶
- Type:
string
- Default:
<None>- Mutable:
This option can be changed without restarting.
The name of a logging configuration file. This file is appended to any existing logging configuration files. For details about logging configuration files, see the Python logging module documentation. Note that when logging configuration files are used then all logging configuration is set in the configuration file and other logging configuration options are ignored (for example, log-date-format).
Deprecated Variations¶ Group
Name
DEFAULT
log-config
DEFAULT
log_config
- log_date_format¶
- Type:
string
- Default:
%Y-%m-%d %H:%M:%S
Defines the format string for %(asctime)s in log records. Default: the value above . This option is ignored if log_config_append is set.
- log_file¶
- Type:
string
- Default:
<None>
(Optional) Name of log file to send logging output to. If no default is set, logging will go to stderr as defined by use_stderr. This option is ignored if log_config_append is set.
Deprecated Variations¶ Group
Name
DEFAULT
logfile
- log_dir¶
- Type:
string
- Default:
<None>
(Optional) The base directory used for relative log_file paths. This option is ignored if log_config_append is set.
Deprecated Variations¶ Group
Name
DEFAULT
logdir
- use_syslog¶
- Type:
boolean
- Default:
False
Use syslog for logging. Existing syslog format is DEPRECATED and will be changed later to honor RFC5424. This option is ignored if log_config_append is set.
- use_journal¶
- Type:
boolean
- Default:
False
Enable journald for logging. If running in a systemd environment you may wish to enable journal support. Doing so will use the journal native protocol which includes structured metadata in addition to log messages.This option is ignored if log_config_append is set.
- syslog_log_facility¶
- Type:
string
- Default:
LOG_USER
Syslog facility to receive log lines. This option is ignored if log_config_append is set.
- use_json¶
- Type:
boolean
- Default:
False
Use JSON formatting for logging. This option is ignored if log_config_append is set.
- use_stderr¶
- Type:
boolean
- Default:
False
Log output to standard error. This option is ignored if log_config_append is set.
- log_color¶
- Type:
boolean
- Default:
False
(Optional) Set the ‘color’ key according to log levels. This option takes effect only when logging to stderr or stdout is used. This option is ignored if log_config_append is set.
- log_rotate_interval¶
- Type:
integer
- Default:
1
The amount of time before the log files are rotated. This option is ignored unless log_rotation_type is set to “interval”.
- log_rotate_interval_type¶
- Type:
string
- Default:
days- Valid Values:
Seconds, Minutes, Hours, Days, Weekday, Midnight
Rotation interval type. The time of the last file change (or the time when the service was started) is used when scheduling the next rotation.
- max_logfile_count¶
- Type:
integer
- Default:
30
Maximum number of rotated log files.
- max_logfile_size_mb¶
- Type:
integer
- Default:
200
Log file maximum size in MB. This option is ignored if “log_rotation_type” is not set to “size”.
- log_rotation_type¶
- Type:
string
- Default:
none- Valid Values:
interval, size, none
Log rotation type.
Possible values
- interval
Rotate logs at predefined time intervals.
- size
Rotate logs once they reach a predefined size.
- none
Do not rotate log files.
- logging_context_format_string¶
- Type:
string
- Default:
%(asctime)s.%(msecs)03d %(process)d %(levelname)s %(name)s [%(global_request_id)s %(request_id)s %(user_identity)s] %(instance)s%(message)s
Format string to use for log messages with context. Used by oslo_log.formatters.ContextFormatter
- logging_default_format_string¶
- Type:
string
- Default:
%(asctime)s.%(msecs)03d %(process)d %(levelname)s %(name)s [-] %(instance)s%(message)s
Format string to use for log messages when context is undefined. Used by oslo_log.formatters.ContextFormatter
- logging_debug_format_suffix¶
- Type:
string
- Default:
%(funcName)s %(pathname)s:%(lineno)d
Additional data to append to log message when logging level for the message is DEBUG. Used by oslo_log.formatters.ContextFormatter
- logging_exception_prefix¶
- Type:
string
- Default:
%(asctime)s.%(msecs)03d %(process)d ERROR %(name)s %(instance)s
Prefix each line of exception output with this format. Used by oslo_log.formatters.ContextFormatter
- logging_user_identity_format¶
- Type:
string
- Default:
%(user)s %(project)s %(domain)s %(system_scope)s %(user_domain)s %(project_domain)s
Defines the format string for %(user_identity)s that is used in logging_context_format_string. Used by oslo_log.formatters.ContextFormatter
- default_log_levels¶
- Type:
list
- Default:
['amqp=WARN', 'boto=WARN', 'sqlalchemy=WARN', 'suds=INFO', 'oslo.messaging=INFO', 'oslo_messaging=INFO', 'iso8601=WARN', 'requests.packages.urllib3.connectionpool=WARN', 'urllib3.connectionpool=WARN', 'websocket=WARN', 'requests.packages.urllib3.util.retry=WARN', 'urllib3.util.retry=WARN', 'keystonemiddleware=WARN', 'routes.middleware=WARN', 'stevedore=WARN', 'taskflow=WARN', 'keystoneauth=WARN', 'oslo.cache=INFO', 'oslo_policy=INFO', 'dogpile.core.dogpile=INFO']
List of package logging levels in logger=LEVEL pairs. This option is ignored if log_config_append is set.
- publish_errors¶
- Type:
boolean
- Default:
False
Enables or disables publication of error events.
- instance_format¶
- Type:
string
- Default:
"[instance: %(uuid)s] "
The format for an instance that is passed with the log message.
- instance_uuid_format¶
- Type:
string
- Default:
"[instance: %(uuid)s] "
The format for an instance UUID that is passed with the log message.
- rate_limit_interval¶
- Type:
integer
- Default:
0
Interval, number of seconds, of log rate limiting.
- rate_limit_burst¶
- Type:
integer
- Default:
0
Maximum number of logged messages per rate_limit_interval.
- rate_limit_except_level¶
- Type:
string
- Default:
CRITICAL- Valid Values:
CRITICAL, ERROR, INFO, WARNING, DEBUG, ‘’
Log level name used by rate limiting. Logs with level greater or equal to rate_limit_except_level are not filtered. An empty string means that all levels are filtered.
- fatal_deprecations¶
- Type:
boolean
- Default:
False
Enables or disables fatal status of deprecations.
barbican¶
- endpoint_type¶
- Type:
string
- Default:
publicURL- Valid Values:
publicURL, internalURL, adminURL, public, internal, admin
Endpoint type to be used with keystone client calls.
- region_name¶
- Type:
string
- Default:
<None>
Region name for connecting to keystone for application credential management.
- auth_url¶
- Type:
unknown type
- Default:
<None>
Authentication URL
- auth_type¶
- Type:
unknown type
- Default:
<None>
Authentication type to load
Deprecated Variations¶ Group
Name
barbican
auth_plugin
- cafile¶
- Type:
string
- Default:
<None>
PEM encoded Certificate Authority to use when verifying HTTPs connections.
- certfile¶
- Type:
string
- Default:
<None>
PEM encoded client certificate cert file
- collect_timing¶
- Type:
boolean
- Default:
False
Collect per-API call timing information.
- default_domain_id¶
- Type:
unknown type
- Default:
<None>
Optional domain ID to use with v3 and v2 parameters. It will be used for both the user and project domain in v3 and ignored in v2 authentication.
- default_domain_name¶
- Type:
unknown type
- Default:
<None>
Optional domain name to use with v3 API and v2 parameters. It will be used for both the user and project domain in v3 and ignored in v2 authentication.
- domain_id¶
- Type:
unknown type
- Default:
<None>
Domain ID to scope to
- domain_name¶
- Type:
unknown type
- Default:
<None>
Domain name to scope to
- insecure¶
- Type:
boolean
- Default:
False
Verify HTTPS connections.
- keyfile¶
- Type:
string
- Default:
<None>
PEM encoded client certificate key file
- password¶
- Type:
unknown type
- Default:
<None>
User’s password
- project_domain_id¶
- Type:
unknown type
- Default:
<None>
Domain ID containing project
- project_domain_name¶
- Type:
unknown type
- Default:
<None>
Domain name containing project
- project_id¶
- Type:
unknown type
- Default:
<None>
Project ID to scope to
Deprecated Variations¶ Group
Name
barbican
tenant-id
barbican
tenant_id
- project_name¶
- Type:
unknown type
- Default:
<None>
Project name to scope to
Deprecated Variations¶ Group
Name
barbican
tenant-name
barbican
tenant_name
- split_loggers¶
- Type:
boolean
- Default:
False
Log requests to multiple loggers.
- system_scope¶
- Type:
unknown type
- Default:
<None>
Scope for system operations
- timeout¶
- Type:
floating point
- Default:
<None>
Timeout value for http requests
- trust_id¶
- Type:
unknown type
- Default:
<None>
ID of the trust to use as a trustee use
- user_domain_id¶
- Type:
unknown type
- Default:
<None>
User’s domain id
- user_domain_name¶
- Type:
unknown type
- Default:
<None>
User’s domain name
- user_id¶
- Type:
unknown type
- Default:
<None>
User id
- username¶
- Type:
unknown type
- Default:
<None>
Username
Deprecated Variations¶ Group
Name
barbican
user-name
barbican
user_name
- barbican_endpoint¶
- Type:
URI
- Default:
<None>
Use this endpoint to connect to Barbican, for example: “http://localhost:9311/”
- barbican_api_version¶
- Type:
string
- Default:
<None>
Version of the Barbican API, for example: “v1”
- auth_endpoint¶
- Type:
URI
- Default:
http://localhost/identity/v3
Use this endpoint to connect to Keystone
Deprecated Variations¶ Group
Name
key_manager
auth_url
- retry_delay¶
- Type:
integer
- Default:
1
Number of seconds to wait before retrying poll for key creation completion
- number_of_retries¶
- Type:
integer
- Default:
60
Number of times to retry poll for key creation completion
- verify_ssl¶
- Type:
boolean
- Default:
True
Specifies if insecure TLS (https) requests. If False, the server’s certificate will not be validated, if True, we can set the verify_ssl_path config meanwhile.
- verify_ssl_path¶
- Type:
string
- Default:
<None>
A path to a bundle or CA certs to check against, or None for requests to attempt to locate and use certificates which verify_ssh is True. If verify_ssl is False, this is ignored.
- barbican_endpoint_type¶
- Type:
string
- Default:
public- Valid Values:
public, internal, admin
Specifies the type of endpoint.
- barbican_region_name¶
- Type:
string
- Default:
<None>
Specifies the region of the chosen endpoint.
- send_service_user_token¶
- Type:
boolean
- Default:
False
When True, if sending a user token to a REST API, also send a service token.
Nova often reuses the user token provided to the nova-api to talk to other REST APIs, such as Cinder, Glance and Neutron. It is possible that while the user token was valid when the request was made to Nova, the token may expire before it reaches the other service. To avoid any failures, and to make it clear it is Nova calling the service on the user’s behalf, we include a service token along with the user token. Should the user’s token have expired, a valid service token ensures the REST API request will still be accepted by the keystone middleware.
- cafile¶
- Type:
string
- Default:
<None>
PEM encoded Certificate Authority to use when verifying HTTPs connections.
- certfile¶
- Type:
string
- Default:
<None>
PEM encoded client certificate cert file
- keyfile¶
- Type:
string
- Default:
<None>
PEM encoded client certificate key file
- insecure¶
- Type:
boolean
- Default:
False
Verify HTTPS connections.
- timeout¶
- Type:
floating point
- Default:
<None>
Timeout value for http requests
- collect_timing¶
- Type:
boolean
- Default:
False
Collect per-API call timing information.
- split_loggers¶
- Type:
boolean
- Default:
False
Log requests to multiple loggers.
barbican_service_user¶
- cafile¶
- Type:
string
- Default:
<None>
PEM encoded Certificate Authority to use when verifying HTTPs connections.
- certfile¶
- Type:
string
- Default:
<None>
PEM encoded client certificate cert file
- keyfile¶
- Type:
string
- Default:
<None>
PEM encoded client certificate key file
- insecure¶
- Type:
boolean
- Default:
False
Verify HTTPS connections.
- timeout¶
- Type:
floating point
- Default:
<None>
Timeout value for http requests
- collect_timing¶
- Type:
boolean
- Default:
False
Collect per-API call timing information.
- split_loggers¶
- Type:
boolean
- Default:
False
Log requests to multiple loggers.
- auth_type¶
- Type:
unknown type
- Default:
<None>
Authentication type to load
Deprecated Variations¶ Group
Name
barbican_service_user
auth_plugin
- auth_section¶
- Type:
unknown type
- Default:
<None>
Config Section from which to load plugin specific options
cinder¶
- cross_az_attach¶
- Type:
boolean
- Default:
True
Allow attaching between instances and volumes in different availability zones.
- http_retries¶
- Type:
integer
- Default:
3
Number of cinderclient retries on failed HTTP calls.
- endpoint_type¶
- Type:
string
- Default:
publicURL- Valid Values:
publicURL, internalURL, adminURL, public, internal, admin
Endpoint type to be used with cinder client calls.
- region_name¶
- Type:
string
- Default:
<None>
Region name for connecting to cinder.
- auth_url¶
- Type:
unknown type
- Default:
<None>
Authentication URL
- auth_type¶
- Type:
unknown type
- Default:
<None>
Authentication type to load
Deprecated Variations¶ Group
Name
cinder
auth_plugin
- cafile¶
- Type:
string
- Default:
<None>
PEM encoded Certificate Authority to use when verifying HTTPs connections.
- certfile¶
- Type:
string
- Default:
<None>
PEM encoded client certificate cert file
- collect_timing¶
- Type:
boolean
- Default:
False
Collect per-API call timing information.
- default_domain_id¶
- Type:
unknown type
- Default:
<None>
Optional domain ID to use with v3 and v2 parameters. It will be used for both the user and project domain in v3 and ignored in v2 authentication.
- default_domain_name¶
- Type:
unknown type
- Default:
<None>
Optional domain name to use with v3 API and v2 parameters. It will be used for both the user and project domain in v3 and ignored in v2 authentication.
- domain_id¶
- Type:
unknown type
- Default:
<None>
Domain ID to scope to
- domain_name¶
- Type:
unknown type
- Default:
<None>
Domain name to scope to
- insecure¶
- Type:
boolean
- Default:
False
Verify HTTPS connections.
- keyfile¶
- Type:
string
- Default:
<None>
PEM encoded client certificate key file
- password¶
- Type:
unknown type
- Default:
<None>
User’s password
- project_domain_id¶
- Type:
unknown type
- Default:
<None>
Domain ID containing project
- project_domain_name¶
- Type:
unknown type
- Default:
<None>
Domain name containing project
- project_id¶
- Type:
unknown type
- Default:
<None>
Project ID to scope to
Deprecated Variations¶ Group
Name
cinder
tenant-id
cinder
tenant_id
- project_name¶
- Type:
unknown type
- Default:
<None>
Project name to scope to
Deprecated Variations¶ Group
Name
cinder
tenant-name
cinder
tenant_name
- split_loggers¶
- Type:
boolean
- Default:
False
Log requests to multiple loggers.
- system_scope¶
- Type:
unknown type
- Default:
<None>
Scope for system operations
- timeout¶
- Type:
floating point
- Default:
<None>
Timeout value for http requests
- trust_id¶
- Type:
unknown type
- Default:
<None>
ID of the trust to use as a trustee use
- user_domain_id¶
- Type:
unknown type
- Default:
<None>
User’s domain id
- user_domain_name¶
- Type:
unknown type
- Default:
<None>
User’s domain name
- user_id¶
- Type:
unknown type
- Default:
<None>
User id
- username¶
- Type:
unknown type
- Default:
<None>
Username
Deprecated Variations¶ Group
Name
cinder
user-name
cinder
user_name
cors¶
- allowed_origin¶
- Type:
list
- Default:
<None>
Indicate whether this resource may be shared with the domain received in the requests “origin” header. Format: “<protocol>://<host>[:<port>]”, no trailing slash. Example: https://horizon.example.com
- allow_credentials¶
- Type:
boolean
- Default:
True
Indicate that the actual request can include user credentials
- expose_headers¶
- Type:
list
- Default:
['X-Auth-Token', 'X-OpenStack-Request-ID', 'X-Openstack-Manila-Api-Version', 'X-OpenStack-Manila-API-Experimental', 'X-Subject-Token', 'X-Service-Token']
Indicate which headers are safe to expose to the API. Defaults to HTTP Simple Headers.
- max_age¶
- Type:
integer
- Default:
3600
Maximum cache age of CORS preflight requests.
- allow_methods¶
- Type:
list
- Default:
['GET', 'PUT', 'POST', 'DELETE', 'PATCH']
Indicate which methods can be used during the actual request.
- allow_headers¶
- Type:
list
- Default:
['X-Auth-Token', 'X-OpenStack-Request-ID', 'X-Openstack-Manila-Api-Version', 'X-OpenStack-Manila-API-Experimental', 'X-Identity-Status', 'X-Roles', 'X-Service-Catalog', 'X-User-Id', 'X-Tenant-Id']
Indicate which header field names may be used during the actual request.
database¶
- sqlite_synchronous¶
- Type:
boolean
- Default:
True
If True, SQLite uses synchronous mode.
- backend¶
- Type:
string
- Default:
sqlalchemy
The back end to use for the database.
- connection¶
- Type:
string
- Default:
<None>
The SQLAlchemy connection string to use to connect to the database.
- slave_connection¶
- Type:
string
- Default:
<None>
The SQLAlchemy connection string to use to connect to the slave database.
- asyncio_connection¶
- Type:
string
- Default:
<None>
The SQLAlchemy asyncio connection string to use to connect to the database.
- asyncio_slave_connection¶
- Type:
string
- Default:
<None>
The SQLAlchemy asyncio connection string to use to connect to the slave database.
- synchronous_reader¶
- Type:
boolean
- Default:
True
Whether or not to assume a reader context needs to guarantee it can read data committed by a writer assuming replication lag is present; defaults to True. When False, a reader context works the same as async_reader and will select the slave database if present. When using a galera cluster, this can be set to False only if you set mysql_wsrep_sync_wait to 1 (this will guarantee that the reader will wait until writesets are committed).Note that this may incur a performance degradation within the galera cluster. Note also that this parameter has no effect if you do not set any slave_connection.
- mysql_sql_mode¶
- Type:
string
- Default:
TRADITIONAL
The SQL mode to be used for MySQL sessions. This option, including the default, overrides any server-set SQL mode. To use whatever SQL mode is set by the server configuration, set this to no value. Example: mysql_sql_mode=
- mysql_wsrep_sync_wait¶
- Type:
integer
- Default:
<None>
For Galera only, configure wsrep_sync_wait causality checks on new connections. Default is None, meaning don’t configure any setting.
- connection_recycle_time¶
- Type:
integer
- Default:
3600
Connections which have been present in the connection pool longer than this number of seconds will be replaced with a new one the next time they are checked out from the pool.
- max_pool_size¶
- Type:
integer
- Default:
5
Maximum number of SQL connections to keep open in a pool. Setting a value of 0 indicates no limit.
- max_retries¶
- Type:
integer
- Default:
10
Maximum number of database connection retries during startup. Set to -1 to specify an infinite retry count.
- retry_interval¶
- Type:
integer
- Default:
10
Interval between retries of opening a SQL connection.
- max_overflow¶
- Type:
integer
- Default:
50
If set, use this value for max_overflow with SQLAlchemy.
- connection_debug¶
- Type:
integer
- Default:
0- Minimum Value:
0
- Maximum Value:
100
Verbosity of SQL debugging information: 0=None, 100=Everything.
- connection_trace¶
- Type:
boolean
- Default:
False
Add Python stack traces to SQL as comment strings.
- pool_timeout¶
- Type:
integer
- Default:
<None>
If set, use this value for pool_timeout with SQLAlchemy.
- use_db_reconnect¶
- Type:
boolean
- Default:
False
Enable the experimental use of database reconnect on connection lost.
- db_retry_interval¶
- Type:
integer
- Default:
1
Seconds between retries of a database transaction.
- db_inc_retry_interval¶
- Type:
boolean
- Default:
True
If True, increases the interval between retries of a database operation up to db_max_retry_interval.
- db_max_retry_interval¶
- Type:
integer
- Default:
10
If db_inc_retry_interval is set, the maximum seconds between retries of a database operation.
- db_max_retries¶
- Type:
integer
- Default:
20
Maximum retries in case of connection error or deadlock error before error is raised. Set to -1 to specify an infinite retry count.
- connection_parameters¶
- Type:
string
- Default:
''
Optional URL parameters to append onto the connection URL at connect time; specify as param1=value1¶m2=value2&…
glance¶
- api_microversion¶
- Type:
string
- Default:
2
Version of Glance API to be used.
- region_name¶
- Type:
string
- Default:
RegionOne
Region name for connecting to glance.
- endpoint_type¶
- Type:
string
- Default:
publicURL- Valid Values:
publicURL, internalURL, adminURL, public, internal, admin
Endpoint type to be used with glance client calls.
- auth_url¶
- Type:
unknown type
- Default:
<None>
Authentication URL
- auth_type¶
- Type:
unknown type
- Default:
<None>
Authentication type to load
Deprecated Variations¶ Group
Name
glance
auth_plugin
- cafile¶
- Type:
string
- Default:
<None>
PEM encoded Certificate Authority to use when verifying HTTPs connections.
- certfile¶
- Type:
string
- Default:
<None>
PEM encoded client certificate cert file
- collect_timing¶
- Type:
boolean
- Default:
False
Collect per-API call timing information.
- default_domain_id¶
- Type:
unknown type
- Default:
<None>
Optional domain ID to use with v3 and v2 parameters. It will be used for both the user and project domain in v3 and ignored in v2 authentication.
- default_domain_name¶
- Type:
unknown type
- Default:
<None>
Optional domain name to use with v3 API and v2 parameters. It will be used for both the user and project domain in v3 and ignored in v2 authentication.
- domain_id¶
- Type:
unknown type
- Default:
<None>
Domain ID to scope to
- domain_name¶
- Type:
unknown type
- Default:
<None>
Domain name to scope to
- insecure¶
- Type:
boolean
- Default:
False
Verify HTTPS connections.
- keyfile¶
- Type:
string
- Default:
<None>
PEM encoded client certificate key file
- password¶
- Type:
unknown type
- Default:
<None>
User’s password
- project_domain_id¶
- Type:
unknown type
- Default:
<None>
Domain ID containing project
- project_domain_name¶
- Type:
unknown type
- Default:
<None>
Domain name containing project
- project_id¶
- Type:
unknown type
- Default:
<None>
Project ID to scope to
Deprecated Variations¶ Group
Name
glance
tenant-id
glance
tenant_id
- project_name¶
- Type:
unknown type
- Default:
<None>
Project name to scope to
Deprecated Variations¶ Group
Name
glance
tenant-name
glance
tenant_name
- split_loggers¶
- Type:
boolean
- Default:
False
Log requests to multiple loggers.
- system_scope¶
- Type:
unknown type
- Default:
<None>
Scope for system operations
- timeout¶
- Type:
floating point
- Default:
<None>
Timeout value for http requests
- trust_id¶
- Type:
unknown type
- Default:
<None>
ID of the trust to use as a trustee use
- user_domain_id¶
- Type:
unknown type
- Default:
<None>
User’s domain id
- user_domain_name¶
- Type:
unknown type
- Default:
<None>
User’s domain name
- user_id¶
- Type:
unknown type
- Default:
<None>
User id
- username¶
- Type:
unknown type
- Default:
<None>
Username
Deprecated Variations¶ Group
Name
glance
user-name
glance
user_name
healthcheck¶
- detailed¶
- Type:
boolean
- Default:
False
Show more detailed information as part of the response. Security note: Enabling this option may expose sensitive details about the service being monitored. Be sure to verify that it will not violate your security policies.
- backends¶
- Type:
list
- Default:
[]
Additional backends that can perform health checks and report that information back as part of a request.
- allowed_source_ranges¶
- Type:
list
- Default:
[]
A list of network addresses to limit source ip allowed to access healthcheck information. Any request from ip outside of these network addresses are ignored.
- ignore_proxied_requests¶
- Type:
boolean
- Default:
False
Ignore requests with proxy headers.
- disable_by_file_path¶
- Type:
string
- Default:
<None>
Check the presence of a file to determine if an application is running on a port. Used by DisableByFileHealthcheck plugin.
- disable_by_file_paths¶
- Type:
list
- Default:
[]
Check the presence of a file based on a port to determine if an application is running on a port. Expects a “port:path” list of strings. Used by DisableByFilesPortsHealthcheck plugin.
- enable_by_file_paths¶
- Type:
list
- Default:
[]
Check the presence of files. Used by EnableByFilesHealthcheck plugin.
key_manager¶
- backend¶
- Type:
string
- Default:
barbican
Specify the key manager implementation. Options are “barbican” and “vault”. Default is “barbican”. Will support the values earlier set using [key_manager]/api_class for some time.
Deprecated Variations¶ Group
Name
key_manager
api_class
- auth_type¶
- Type:
string
- Default:
<None>- Valid Values:
token, password, keystone_token, keystone_password
The type of authentication credential to create. Required if no context is passed to the credential factory.
- token¶
- Type:
string
- Default:
<None>
Token for authentication. Required for ‘token’ and ‘keystone_token’ auth_type if no context is passed to the credential factory.
- username¶
- Type:
string
- Default:
<None>
Username for authentication. Required for ‘password’ auth_type. Optional for the ‘keystone_password’ auth_type.
- password¶
- Type:
string
- Default:
<None>
Password for authentication. Required for ‘password’ and ‘keystone_password’ auth_type.
- auth_url¶
- Type:
URI
- Default:
<None>
Use this endpoint to connect to Keystone.
- user_id¶
- Type:
string
- Default:
<None>
User ID for authentication. Optional for ‘keystone_token’ and ‘keystone_password’ auth_type.
- user_domain_id¶
- Type:
string
- Default:
<None>
User’s domain ID for authentication. Optional for ‘keystone_token’ and ‘keystone_password’ auth_type.
- user_domain_name¶
- Type:
string
- Default:
<None>
User’s domain name for authentication. Optional for ‘keystone_token’ and ‘keystone_password’ auth_type.
- trust_id¶
- Type:
string
- Default:
<None>
Trust ID for trust scoping. Optional for ‘keystone_token’ and ‘keystone_password’ auth_type.
- domain_id¶
- Type:
string
- Default:
<None>
Domain ID for domain scoping. Optional for ‘keystone_token’ and ‘keystone_password’ auth_type.
- domain_name¶
- Type:
string
- Default:
<None>
Domain name for domain scoping. Optional for ‘keystone_token’ and ‘keystone_password’ auth_type.
- project_id¶
- Type:
string
- Default:
<None>
Project ID for project scoping. Optional for ‘keystone_token’ and ‘keystone_password’ auth_type.
- project_name¶
- Type:
string
- Default:
<None>
Project name for project scoping. Optional for ‘keystone_token’ and ‘keystone_password’ auth_type.
- project_domain_id¶
- Type:
string
- Default:
<None>
Project’s domain ID for project. Optional for ‘keystone_token’ and ‘keystone_password’ auth_type.
- project_domain_name¶
- Type:
string
- Default:
<None>
Project’s domain name for project. Optional for ‘keystone_token’ and ‘keystone_password’ auth_type.
- reauthenticate¶
- Type:
boolean
- Default:
True
Allow fetching a new token if the current one is going to expire. Optional for ‘keystone_token’ and ‘keystone_password’ auth_type.
keystone_authtoken¶
- www_authenticate_uri¶
- Type:
string
- Default:
<None>
Complete “public” Identity API endpoint. This endpoint should not be an “admin” endpoint, as it should be accessible by all end users. Unauthenticated clients are redirected to this endpoint to authenticate. Although this endpoint should ideally be unversioned, client support in the wild varies.
- auth_version¶
- Type:
string
- Default:
<None>
API version of the Identity API endpoint.
- interface¶
- Type:
string
- Default:
internal
Interface to use for the Identity API endpoint. Valid values are “public”, “internal” (default) or “admin”.
- delay_auth_decision¶
- Type:
boolean
- Default:
False
Do not handle authorization requests within the middleware, but delegate the authorization decision to downstream WSGI components.
- http_connect_timeout¶
- Type:
integer
- Default:
<None>
Request timeout value for communicating with Identity API server.
- http_request_max_retries¶
- Type:
integer
- Default:
3
How many times are we trying to reconnect when communicating with Identity API Server.
- cache¶
- Type:
string
- Default:
<None>
Request environment key where the Swift cache object is stored. When auth_token middleware is deployed with a Swift cache, use this option to have the middleware share a caching backend with swift. Otherwise, use the
memcached_serversoption instead.
- certfile¶
- Type:
string
- Default:
<None>
Required if identity server requires client certificate
- keyfile¶
- Type:
string
- Default:
<None>
Required if identity server requires client certificate
- cafile¶
- Type:
string
- Default:
<None>
A PEM encoded Certificate Authority to use when verifying HTTPs connections. Defaults to system CAs.
- insecure¶
- Type:
boolean
- Default:
False
Verify HTTPS connections.
- region_name¶
- Type:
string
- Default:
<None>
The region in which the identity server can be found.
- memcached_servers¶
- Type:
list
- Default:
<None>
Optionally specify a list of memcached server(s) to use for caching. If left undefined, tokens will instead be cached in-process.
Deprecated Variations¶ Group
Name
keystone_authtoken
memcache_servers
- token_cache_time¶
- Type:
integer
- Default:
300
In order to prevent excessive effort spent validating tokens, the middleware caches previously-seen tokens for a configurable duration (in seconds). Set to -1 to disable caching completely.
- memcache_security_strategy¶
- Type:
string
- Default:
None- Valid Values:
None, MAC, ENCRYPT
(Optional) If defined, indicate whether token data should be authenticated or authenticated and encrypted. If MAC, token data is authenticated (with HMAC) in the cache. If ENCRYPT, token data is encrypted and authenticated in the cache. If the value is not one of these options or empty, auth_token will raise an exception on initialization.
- memcache_secret_key¶
- Type:
string
- Default:
<None>
(Optional, mandatory if memcache_security_strategy is defined) This string is used for key derivation.
- memcache_tls_enabled¶
- Type:
boolean
- Default:
False
(Optional) Global toggle for TLS usage when comunicating with the caching servers.
- memcache_tls_cafile¶
- Type:
string
- Default:
<None>
(Optional) Path to a file of concatenated CA certificates in PEM format necessary to establish the caching server’s authenticity. If tls_enabled is False, this option is ignored.
- memcache_tls_certfile¶
- Type:
string
- Default:
<None>
(Optional) Path to a single file in PEM format containing the client’s certificate as well as any number of CA certificates needed to establish the certificate’s authenticity. This file is only required when client side authentication is necessary. If tls_enabled is False, this option is ignored.
- memcache_tls_keyfile¶
- Type:
string
- Default:
<None>
(Optional) Path to a single file containing the client’s private key in. Otherwhise the private key will be taken from the file specified in tls_certfile. If tls_enabled is False, this option is ignored.
- memcache_tls_allowed_ciphers¶
- Type:
string
- Default:
<None>
(Optional) Set the available ciphers for sockets created with the TLS context. It should be a string in the OpenSSL cipher list format. If not specified, all OpenSSL enabled ciphers will be available.
- memcache_pool_dead_retry¶
- Type:
integer
- Default:
300
(Optional) Number of seconds memcached server is considered dead before it is tried again.
- memcache_pool_maxsize¶
- Type:
integer
- Default:
10
(Optional) Maximum total number of open connections to every memcached server.
- memcache_pool_socket_timeout¶
- Type:
integer
- Default:
3
(Optional) Socket timeout in seconds for communicating with a memcached server.
- memcache_pool_unused_timeout¶
- Type:
integer
- Default:
60
(Optional) Number of seconds a connection to memcached is held unused in the pool before it is closed.
- memcache_pool_conn_get_timeout¶
- Type:
integer
- Default:
10
(Optional) Number of seconds that an operation will wait to get a memcached client connection from the pool.
- memcache_use_advanced_pool¶
- Type:
boolean
- Default:
True
(Optional) Use the advanced (eventlet safe) memcached client pool.
- include_service_catalog¶
- Type:
boolean
- Default:
True
(Optional) Indicate whether to set the X-Service-Catalog header. If False, middleware will not ask for service catalog on token validation and will not set the X-Service-Catalog header.
- enforce_token_bind¶
- Type:
string
- Default:
permissive
Used to control the use and type of token binding. Can be set to: “disabled” to not check token binding. “permissive” (default) to validate binding information if the bind type is of a form known to the server and ignore it if not. “strict” like “permissive” but if the bind type is unknown the token will be rejected. “required” any form of token binding is needed to be allowed. Finally the name of a binding method that must be present in tokens.
- service_token_roles¶
- Type:
list
- Default:
['service']
A choice of roles that must be present in a service token. Service tokens are allowed to request that an expired token can be used and so this check should tightly control that only actual services should be sending this token. Roles here are applied as an ANY check so any role in this list must be present. For backwards compatibility reasons this currently only affects the allow_expired check.
- service_token_roles_required¶
- Type:
boolean
- Default:
True
When set to True, service tokens must contain a role from the service_token_roles list to be considered valid. This prevents end-user tokens from being used as service tokens and ensures proper service-to-service authentication. Setting this to False is NOT RECOMMENDED as it allows any valid token to be used as a service token, which can bypass access-rule checks and weaken composite-auth protections.
- service_type¶
- Type:
string
- Default:
<None>
The name or type of the service as it appears in the service catalog. This is used to validate tokens that have restricted access rules.
- memcache_sasl_enabled¶
- Type:
boolean
- Default:
False
Enable the SASL(Simple Authentication and Security Layer) if the SASL_enable is true, else disable.
- memcache_username¶
- Type:
string
- Default:
''
the user name for the SASL
- memcache_password¶
- Type:
string
- Default:
''
the username password for SASL
- auth_type¶
- Type:
unknown type
- Default:
<None>
Authentication type to load
Deprecated Variations¶ Group
Name
keystone_authtoken
auth_plugin
- auth_section¶
- Type:
unknown type
- Default:
<None>
Config Section from which to load plugin specific options
neutron¶
- url¶
- Type:
string
- Default:
<None>
URL for connecting to neutron.
- url_timeout¶
- Type:
integer
- Default:
30
Timeout value for connecting to neutron in seconds.
Warning
This option is deprecated for removal since Yoga. Its value may be silently ignored in the future.
- Reason:
This parameter has had no effect since 2.0.0. The timeout parameter should be used instead.
- auth_strategy¶
- Type:
string
- Default:
keystone
Auth strategy for connecting to neutron in admin context.
Warning
This option is deprecated for removal since Yoga. Its value may be silently ignored in the future.
- Reason:
This parameter has had no effect since 2.0.0. Use the auth_type parameter to select authentication type
- endpoint_type¶
- Type:
string
- Default:
publicURL- Valid Values:
publicURL, internalURL, adminURL, public, internal, admin
Endpoint type to be used with neutron client calls.
- region_name¶
- Type:
string
- Default:
<None>
Region name for connecting to neutron in admin context.
- auth_url¶
- Type:
unknown type
- Default:
<None>
Authentication URL
- auth_type¶
- Type:
unknown type
- Default:
<None>
Authentication type to load
Deprecated Variations¶ Group
Name
neutron
auth_plugin
- cafile¶
- Type:
string
- Default:
<None>
PEM encoded Certificate Authority to use when verifying HTTPs connections.
- certfile¶
- Type:
string
- Default:
<None>
PEM encoded client certificate cert file
- collect_timing¶
- Type:
boolean
- Default:
False
Collect per-API call timing information.
- default_domain_id¶
- Type:
unknown type
- Default:
<None>
Optional domain ID to use with v3 and v2 parameters. It will be used for both the user and project domain in v3 and ignored in v2 authentication.
- default_domain_name¶
- Type:
unknown type
- Default:
<None>
Optional domain name to use with v3 API and v2 parameters. It will be used for both the user and project domain in v3 and ignored in v2 authentication.
- domain_id¶
- Type:
unknown type
- Default:
<None>
Domain ID to scope to
- domain_name¶
- Type:
unknown type
- Default:
<None>
Domain name to scope to
- insecure¶
- Type:
boolean
- Default:
False
Verify HTTPS connections.
- keyfile¶
- Type:
string
- Default:
<None>
PEM encoded client certificate key file
- password¶
- Type:
unknown type
- Default:
<None>
User’s password
- project_domain_id¶
- Type:
unknown type
- Default:
<None>
Domain ID containing project
- project_domain_name¶
- Type:
unknown type
- Default:
<None>
Domain name containing project
- project_id¶
- Type:
unknown type
- Default:
<None>
Project ID to scope to
Deprecated Variations¶ Group
Name
neutron
tenant-id
neutron
tenant_id
- project_name¶
- Type:
unknown type
- Default:
<None>
Project name to scope to
Deprecated Variations¶ Group
Name
neutron
tenant-name
neutron
tenant_name
- split_loggers¶
- Type:
boolean
- Default:
False
Log requests to multiple loggers.
- system_scope¶
- Type:
unknown type
- Default:
<None>
Scope for system operations
- timeout¶
- Type:
floating point
- Default:
<None>
Timeout value for http requests
- trust_id¶
- Type:
unknown type
- Default:
<None>
ID of the trust to use as a trustee use
- user_domain_id¶
- Type:
unknown type
- Default:
<None>
User’s domain id
- user_domain_name¶
- Type:
unknown type
- Default:
<None>
User’s domain name
- user_id¶
- Type:
unknown type
- Default:
<None>
User id
- username¶
- Type:
unknown type
- Default:
<None>
Username
Deprecated Variations¶ Group
Name
neutron
user-name
neutron
user_name
nova¶
- api_microversion¶
- Type:
string
- Default:
2.10
Version of Nova API to be used.
- endpoint_type¶
- Type:
string
- Default:
publicURL- Valid Values:
publicURL, internalURL, adminURL, public, internal, admin
Endpoint type to be used with nova client calls.
- region_name¶
- Type:
string
- Default:
<None>
Region name for connecting to nova.
- auth_url¶
- Type:
unknown type
- Default:
<None>
Authentication URL
- auth_type¶
- Type:
unknown type
- Default:
<None>
Authentication type to load
Deprecated Variations¶ Group
Name
nova
auth_plugin
- cafile¶
- Type:
string
- Default:
<None>
PEM encoded Certificate Authority to use when verifying HTTPs connections.
- certfile¶
- Type:
string
- Default:
<None>
PEM encoded client certificate cert file
- collect_timing¶
- Type:
boolean
- Default:
False
Collect per-API call timing information.
- default_domain_id¶
- Type:
unknown type
- Default:
<None>
Optional domain ID to use with v3 and v2 parameters. It will be used for both the user and project domain in v3 and ignored in v2 authentication.
- default_domain_name¶
- Type:
unknown type
- Default:
<None>
Optional domain name to use with v3 API and v2 parameters. It will be used for both the user and project domain in v3 and ignored in v2 authentication.
- domain_id¶
- Type:
unknown type
- Default:
<None>
Domain ID to scope to
- domain_name¶
- Type:
unknown type
- Default:
<None>
Domain name to scope to
- insecure¶
- Type:
boolean
- Default:
False
Verify HTTPS connections.
- keyfile¶
- Type:
string
- Default:
<None>
PEM encoded client certificate key file
- password¶
- Type:
unknown type
- Default:
<None>
User’s password
- project_domain_id¶
- Type:
unknown type
- Default:
<None>
Domain ID containing project
- project_domain_name¶
- Type:
unknown type
- Default:
<None>
Domain name containing project
- project_id¶
- Type:
unknown type
- Default:
<None>
Project ID to scope to
Deprecated Variations¶ Group
Name
nova
tenant-id
nova
tenant_id
- project_name¶
- Type:
unknown type
- Default:
<None>
Project name to scope to
Deprecated Variations¶ Group
Name
nova
tenant-name
nova
tenant_name
- split_loggers¶
- Type:
boolean
- Default:
False
Log requests to multiple loggers.
- system_scope¶
- Type:
unknown type
- Default:
<None>
Scope for system operations
- timeout¶
- Type:
floating point
- Default:
<None>
Timeout value for http requests
- trust_id¶
- Type:
unknown type
- Default:
<None>
ID of the trust to use as a trustee use
- user_domain_id¶
- Type:
unknown type
- Default:
<None>
User’s domain id
- user_domain_name¶
- Type:
unknown type
- Default:
<None>
User’s domain name
- user_id¶
- Type:
unknown type
- Default:
<None>
User id
- username¶
- Type:
unknown type
- Default:
<None>
Username
Deprecated Variations¶ Group
Name
nova
user-name
nova
user_name
oslo_concurrency¶
- disable_process_locking¶
- Type:
boolean
- Default:
False
Enables or disables inter-process locks.
- lock_path¶
- Type:
string
- Default:
<None>
Directory to use for lock files. For security, the specified directory should only be writable by the user running the processes that need locking. Defaults to environment variable OSLO_LOCK_PATH. If external locks are used, a lock path must be set.
oslo_messaging_kafka¶
- kafka_max_fetch_bytes¶
- Type:
integer
- Default:
1048576
Max fetch bytes of Kafka consumer
- kafka_consumer_timeout¶
- Type:
floating point
- Default:
1.0
Default timeout(s) for Kafka consumers
- consumer_group¶
- Type:
string
- Default:
oslo_messaging_consumer
Group id for Kafka consumer. Consumers in one group will coordinate message consumption
- producer_batch_timeout¶
- Type:
floating point
- Default:
0.0
Upper bound on the delay for KafkaProducer batching in seconds
- producer_batch_size¶
- Type:
integer
- Default:
16384
Size of batch for the producer async send
- compression_codec¶
- Type:
string
- Default:
none- Valid Values:
none, gzip, snappy, lz4, zstd
The compression codec for all data generated by the producer. If not set, compression will not be used. Note that the allowed values of this depend on the kafka version
- enable_auto_commit¶
- Type:
boolean
- Default:
False
Enable asynchronous consumer commits
- max_poll_records¶
- Type:
integer
- Default:
500
The maximum number of records returned in a poll call
- security_protocol¶
- Type:
string
- Default:
PLAINTEXT- Valid Values:
PLAINTEXT, SASL_PLAINTEXT, SSL, SASL_SSL
Protocol used to communicate with brokers
- sasl_mechanism¶
- Type:
string
- Default:
PLAIN
Mechanism when security protocol is SASL
- ssl_cafile¶
- Type:
string
- Default:
''
CA certificate PEM file used to verify the server certificate
- ssl_client_cert_file¶
- Type:
string
- Default:
''
Client certificate PEM file used for authentication.
- ssl_client_key_file¶
- Type:
string
- Default:
''
Client key PEM file used for authentication.
- ssl_client_key_password¶
- Type:
string
- Default:
''
Client key password file used for authentication.
oslo_messaging_notifications¶
- driver¶
- Type:
multi-valued
- Default:
''
The Drivers(s) to handle sending notifications. Possible values are messaging, messagingv2, routing, log, test, noop
- transport_url¶
- Type:
string
- Default:
<None>
A URL representing the messaging driver to use for notifications. If not set, we fall back to the same configuration used for RPC.
- topics¶
- Type:
list
- Default:
['notifications']
AMQP topic used for OpenStack notifications.
- retry¶
- Type:
integer
- Default:
-1
The maximum number of attempts to re-send a notification message which failed to be delivered due to a recoverable error. 0 - No retry, -1 - indefinite
oslo_messaging_rabbit¶
- amqp_durable_queues¶
- Type:
boolean
- Default:
False
Use durable queues in AMQP. If rabbit_quorum_queue is enabled, queues will be durable and this value will be ignored.
- amqp_auto_delete¶
- Type:
boolean
- Default:
False
Auto-delete queues in AMQP.
- rpc_conn_pool_size¶
- Type:
integer
- Default:
30- Minimum Value:
1
Size of RPC connection pool.
- conn_pool_min_size¶
- Type:
integer
- Default:
2
The pool size limit for connections expiration policy
- conn_pool_ttl¶
- Type:
integer
- Default:
1200
The time-to-live in sec of idle connections in the pool
- ssl¶
- Type:
boolean
- Default:
False
Connect over SSL.
- ssl_version¶
- Type:
string
- Default:
''
SSL version to use (valid only if SSL enabled). Valid values are TLSv1 and SSLv23. SSLv2, SSLv3, TLSv1_1, and TLSv1_2 may be available on some distributions.
- ssl_key_file¶
- Type:
string
- Default:
''
SSL key file (valid only if SSL enabled).
- ssl_cert_file¶
- Type:
string
- Default:
''
SSL cert file (valid only if SSL enabled).
- ssl_ca_file¶
- Type:
string
- Default:
''
SSL certification authority file (valid only if SSL enabled).
- ssl_enforce_hostname_verification¶
- Type:
boolean
- Default:
True
When true, verify the broker hostname against the certificate when
ssl_ca_fileis set. When false,sslwithssl_ca_filestill validates the certificate chain but does not verify the broker hostname.ssl=truewithoutssl_ca_filenever enables hostname verification.Warning
This option is deprecated for removal. Its value may be silently ignored in the future.
- Reason:
Verification is always enabled now
- ssl_enforce_fips_mode¶
- Type:
boolean
- Default:
False
Global toggle for enforcing the OpenSSL FIPS mode. This feature requires Python support. This is available in Python 3.9 in all environments and may have been backported to older Python versions on select environments. If the Python executable used does not support OpenSSL FIPS mode, an exception will be raised.
Warning
This option is deprecated for removal. Its value may be silently ignored in the future.
- Reason:
FIPS_mode_set API was removed in OpenSSL 3.0.0. This option has no effect now.
- kombu_reconnect_delay¶
- Type:
floating point
- Default:
1.0- Minimum Value:
0.0
- Maximum Value:
4.5
How long to wait (in seconds) before reconnecting in response to an AMQP consumer cancel notification.
- kombu_reconnect_splay¶
- Type:
floating point
- Default:
0.0- Minimum Value:
0.0
Random time to wait for when reconnecting in response to an AMQP consumer cancel notification.
- kombu_compression¶
- Type:
string
- Default:
<None>
EXPERIMENTAL: Possible values are: gzip, bz2. If not set compression will not be used. This option may not be available in future versions.
- kombu_missing_consumer_retry_timeout¶
- Type:
integer
- Default:
60
How long to wait a missing client before abandoning to send it its replies. This value should not be longer than rpc_response_timeout.
Deprecated Variations¶ Group
Name
oslo_messaging_rabbit
kombu_reconnect_timeout
- kombu_failover_strategy¶
- Type:
string
- Default:
round-robin- Valid Values:
round-robin, shuffle
Determines how the next RabbitMQ node is chosen in case the one we are currently connected to becomes unavailable. Takes effect only if more than one RabbitMQ node is provided in config.
- rabbit_login_method¶
- Type:
string
- Default:
AMQPLAIN- Valid Values:
PLAIN, AMQPLAIN, EXTERNAL, RABBIT-CR-DEMO
The RabbitMQ login method.
- rabbit_retry_interval¶
- Type:
integer
- Default:
1- Minimum Value:
1
How frequently to retry connecting with RabbitMQ.
- rabbit_retry_backoff¶
- Type:
integer
- Default:
2- Minimum Value:
0
How long to backoff for between retries when connecting to RabbitMQ.
- rabbit_interval_max¶
- Type:
integer
- Default:
30- Minimum Value:
1
Maximum interval of RabbitMQ connection retries.
- rabbit_ha_queues¶
- Type:
boolean
- Default:
False
Try to use HA queues in RabbitMQ (x-ha-policy: all). If you change this option, you must wipe the RabbitMQ database. In RabbitMQ 3.0, queue mirroring is no longer controlled by the x-ha-policy argument when declaring a queue. If you just want to make sure that all queues (except those with auto-generated names) are mirrored across all nodes, run: “rabbitmqctl set_policy HA ‘^(?!amq.).*’ ‘{“ha-mode”: “all”}’ “
- rabbit_quorum_queue¶
- Type:
boolean
- Default:
False
Use quorum queues in RabbitMQ (x-queue-type: quorum). The quorum queue is a modern queue type for RabbitMQ implementing a durable, replicated FIFO queue based on the Raft consensus algorithm. It is available as of RabbitMQ 3.8.0. If set this option will conflict with the HA queues (
rabbit_ha_queues) aka mirrored queues, in other words the HA queues should be disabled. Quorum queues are also durable by default so the amqp_durable_queues option is ignored when this option is enabled.
- rabbit_transient_quorum_queue¶
- Type:
boolean
- Default:
False
Use quorum queues for transients queues in RabbitMQ. Enabling this option will then make sure those queues are also using quorum kind of rabbit queues, which are HA by default.
- rabbit_quorum_delivery_limit¶
- Type:
integer
- Default:
0
Each time a message is redelivered to a consumer, a counter is incremented. Once the redelivery count exceeds the delivery limit the message gets dropped or dead-lettered (if a DLX exchange has been configured) Used only when rabbit_quorum_queue is enabled, Default 0 which means dont set a limit.
- rabbit_quorum_max_memory_length¶
- Type:
integer
- Default:
0
By default all messages are maintained in memory if a quorum queue grows in length it can put memory pressure on a cluster. This option can limit the number of messages in the quorum queue. Used only when rabbit_quorum_queue is enabled, Default 0 which means dont set a limit.
- rabbit_quorum_max_memory_bytes¶
- Type:
integer
- Default:
0
By default all messages are maintained in memory if a quorum queue grows in length it can put memory pressure on a cluster. This option can limit the number of memory bytes used by the quorum queue. Used only when rabbit_quorum_queue is enabled, Default 0 which means dont set a limit.
- rabbit_transient_queues_ttl¶
- Type:
integer
- Default:
1800- Minimum Value:
0
Positive integer representing duration in seconds for queue TTL (x-expires). Queues which are unused for the duration of the TTL are automatically deleted. The parameter affects only reply and fanout queues. Setting 0 as value will disable the x-expires. If doing so, make sure you have a rabbitmq policy to delete the queues or you deployment will create an infinite number of queue over time.In case rabbit_stream_fanout is set to True, this option will control data retention policy (x-max-age) for messages in the fanout queue rather then the queue duration itself. So the oldest data in the stream queue will be discarded from it once reaching TTL Setting to 0 will disable x-max-age for stream which make stream grow indefinitely filling up the diskspace
- rabbit_qos_prefetch_count¶
- Type:
integer
- Default:
0
Specifies the number of messages to prefetch. Setting to zero allows unlimited messages.
- heartbeat_timeout_threshold¶
- Type:
integer
- Default:
60
Number of seconds after which the Rabbit broker is considered down if heartbeat’s keep-alive fails (0 disables heartbeat).
- heartbeat_rate¶
- Type:
integer
- Default:
3
How often times during the heartbeat_timeout_threshold we check the heartbeat.
- direct_mandatory_flag¶
- Type:
boolean
- Default:
True
(DEPRECATED) Enable/Disable the RabbitMQ mandatory flag for direct send. The direct send is used as reply, so the MessageUndeliverable exception is raised in case the client queue does not exist.MessageUndeliverable exception will be used to loop for a timeout to lets a chance to sender to recover.This flag is deprecated and it will not be possible to deactivate this functionality anymore
Warning
This option is deprecated for removal. Its value may be silently ignored in the future.
- Reason:
Mandatory flag no longer deactivable.
- enable_cancel_on_failover¶
- Type:
boolean
- Default:
False
Enable x-cancel-on-ha-failover flag so that rabbitmq server will cancel and notify consumerswhen queue is down
- use_queue_manager¶
- Type:
boolean
- Default:
False
Should we use consistant queue names or random ones
- hostname¶
- Type:
string
- Default:
node1.example.com
This option has a sample default set, which means that its actual default value may vary from the one documented above.
Hostname used by queue manager. Defaults to the value returned by socket.gethostname().
- processname¶
- Type:
string
- Default:
nova-api
This option has a sample default set, which means that its actual default value may vary from the one documented above.
Process name used by queue manager
- rabbit_stream_fanout¶
- Type:
boolean
- Default:
False
Use stream queues in RabbitMQ (x-queue-type: stream). Streams are a new persistent and replicated data structure (“queue type”) in RabbitMQ which models an append-only log with non-destructive consumer semantics. It is available as of RabbitMQ 3.9.0. If set this option will replace all fanout queues with only one stream queue.
oslo_middleware¶
- max_request_body_size¶
- Type:
integer
- Default:
114688
The maximum body size for each request, in bytes.
- enable_proxy_headers_parsing¶
- Type:
boolean
- Default:
False
Whether the application is behind a proxy or not. This determines if the middleware should parse the headers or not.
- http_basic_auth_user_file¶
- Type:
string
- Default:
/etc/htpasswd
HTTP basic auth password file.
oslo_middleware_tracing¶
- enabled¶
- Type:
boolean
- Default:
False
Enable OpenTelemetry distributed tracing. When enabled, the service will export trace data via OTLP to a configured backend. This is the primary mechanism to control tracing for services that do not use paste deploy.
- otlp_endpoint¶
- Type:
URI
- Default:
http://localhost:4318
OTLP exporter endpoint URL. For HTTP/protobuf protocol, traces are sent to <endpoint>/v1/traces.
- otlp_protocol¶
- Type:
string
- Default:
http/protobuf- Valid Values:
http/protobuf, grpc
OTLP transport protocol.
Possible values
- http/protobuf
OTLP over HTTP with Protocol Buffers
- grpc
OTLP over gRPC
- service_name¶
- Type:
string
- Default:
<None>
OpenTelemetry service name reported in trace data. This must be set when tracing is enabled, either via set_defaults() or in the configuration file.
- sampling_rate¶
- Type:
floating point
- Default:
1.0- Minimum Value:
0.0
- Maximum Value:
1.0
Trace sampling rate as a float between 0.0 and 1.0. A value of 1.0 means all traces are sampled.
- insecure¶
- Type:
boolean
- Default:
False
Disable TLS verification for the OTLP endpoint. Set to True only in development environments without proper TLS certificates.
oslo_policy¶
- enforce_new_defaults¶
- Type:
boolean
- Default:
True
This option controls whether or not to use old deprecated defaults when evaluating policies. If
True, the old deprecated defaults are not going to be evaluated. This means if any existing token is allowed for old defaults but is disallowed for new defaults, it will be disallowed. IfFalse, the deprecated policy check string is logically OR’d with the new policy check string, allowing for a graceful upgrade experience between releases with new policies, which is the default behavior.
- policy_file¶
- Type:
string
- Default:
policy.yaml
The relative or absolute path of a file that maps roles to permissions for a given service. Relative paths must be specified in relation to the configuration file setting this option.
- policy_default_rule¶
- Type:
string
- Default:
default
Default rule. Enforced when a requested rule is not found.
- policy_dirs¶
- Type:
multi-valued
- Default:
policy.d
Directories where policy configuration files are stored. They can be relative to any directory in the search path defined by the config_dir option, or absolute paths. The file defined by policy_file must exist for these directories to be searched. Missing or empty directories are ignored.
- remote_content_type¶
- Type:
string
- Default:
application/x-www-form-urlencoded- Valid Values:
application/x-www-form-urlencoded, application/json
Content Type to send and receive data for REST based policy check
- remote_ssl_verify_server_crt¶
- Type:
boolean
- Default:
False
server identity verification for REST based policy check
- remote_ssl_ca_crt_file¶
- Type:
string
- Default:
<None>
Absolute path to ca cert file for REST based policy check
- remote_ssl_client_crt_file¶
- Type:
string
- Default:
<None>
Absolute path to client cert for REST based policy check
- remote_ssl_client_key_file¶
- Type:
string
- Default:
<None>
Absolute path client key file REST based policy check
- remote_timeout¶
- Type:
floating point
- Default:
60- Minimum Value:
0
Timeout in seconds for REST based policy check
oslo_reports¶
- log_dir¶
- Type:
string
- Default:
<None>
Path to a log directory where to create a file
- file_event_handler¶
- Type:
string
- Default:
<None>
The path to a file to watch for changes to trigger the reports, instead of signals. Setting this option disables the signal trigger for the reports. If application is running as a WSGI application it is recommended to use this instead of signals.
- file_event_handler_interval¶
- Type:
integer
- Default:
1
How many seconds to wait between polls when file_event_handler is set
quota¶
- Type:
integer
- Default:
50
Number of shares allowed per project.
Deprecated Variations¶ Group
Name
DEFAULT
quota_shares
- snapshots¶
- Type:
integer
- Default:
50
Number of share snapshots allowed per project.
Deprecated Variations¶ Group
Name
DEFAULT
quota_snapshots
- gigabytes¶
- Type:
integer
- Default:
1000
Number of share gigabytes allowed per project.
Deprecated Variations¶ Group
Name
DEFAULT
quota_gigabytes
- Type:
integer
- Default:
-1
Max size allowed per share, in gigabytes.
Deprecated Variations¶ Group
Name
DEFAULT
quota_per_share_gigabytes
- snapshot_gigabytes¶
- Type:
integer
- Default:
1000
Number of snapshot gigabytes allowed per project.
Deprecated Variations¶ Group
Name
DEFAULT
quota_snapshot_gigabytes
- Type:
integer
- Default:
10
Number of share-networks allowed per project.
Deprecated Variations¶ Group
Name
DEFAULT
quota_share_networks
- Type:
integer
- Default:
100
Number of share-replicas allowed per project.
Deprecated Variations¶ Group
Name
DEFAULT
quota_share_replicas
- replica_gigabytes¶
- Type:
integer
- Default:
1000
Number of replica gigabytes allowed per project.
Deprecated Variations¶ Group
Name
DEFAULT
quota_replica_gigabytes
- Type:
integer
- Default:
50
Number of share groups allowed.
Deprecated Variations¶ Group
Name
DEFAULT
quota_share_groups
- Type:
integer
- Default:
50
Number of share group snapshots allowed.
Deprecated Variations¶ Group
Name
DEFAULT
quota_share_group_snapshots
- reservation_expire¶
- Type:
integer
- Default:
86400
Number of seconds until a reservation expires.
Deprecated Variations¶ Group
Name
DEFAULT
reservation_expire
- until_refresh¶
- Type:
integer
- Default:
0
Count of reservations until usage is refreshed.
Deprecated Variations¶ Group
Name
DEFAULT
until_refresh
- max_age¶
- Type:
integer
- Default:
0
Number of seconds between subsequent usage refreshes.
Deprecated Variations¶ Group
Name
DEFAULT
max_age
- driver¶
- Type:
string
- Default:
manila.quota.DbQuotaDriver
Default driver to use for quota checks.
Deprecated Variations¶ Group
Name
DEFAULT
quota_driver
- backups¶
- Type:
integer
- Default:
10
Number of share backups allowed per project.
Deprecated Variations¶ Group
Name
DEFAULT
quota_backups
- backup_gigabytes¶
- Type:
integer
- Default:
1000
Total amount of storage, in gigabytes, allowed for backups per project.
Deprecated Variations¶ Group
Name
DEFAULT
quota_backup_gigabytes
- encryption_keys¶
- Type:
integer
- Default:
100
Number of encryption keys allowed per project.
ssl¶
- ca_file¶
- Type:
string
- Default:
<None>
CA certificate file to use to verify connecting clients.
Warning
This option is deprecated for removal. Its value may be silently ignored in the future.
- Reason:
The ‘ca_file’ option is deprecated and will be removed in a future release.
- cert_file¶
- Type:
string
- Default:
<None>
Certificate file to use when starting the server securely.
Warning
This option is deprecated for removal. Its value may be silently ignored in the future.
- Reason:
The ‘cert_file’ option is deprecated and will be removed in a future release.
- key_file¶
- Type:
string
- Default:
<None>
Private key file to use when starting the server securely.
Warning
This option is deprecated for removal. Its value may be silently ignored in the future.
- Reason:
The ‘key_file’ option is deprecated and will be removed in a future release.
- version¶
- Type:
string
- Default:
<None>
SSL version to use (valid only if SSL enabled). Valid values are TLSv1 and SSLv23. SSLv2, SSLv3, TLSv1_1, and TLSv1_2 may be available on some distributions.
Warning
This option is deprecated for removal. Its value may be silently ignored in the future.
- Reason:
The ‘version’ option is deprecated and will be removed in a future release.
- ciphers¶
- Type:
string
- Default:
<None>
Sets the list of available ciphers. value should be a string in the OpenSSL cipher list format.
Warning
This option is deprecated for removal. Its value may be silently ignored in the future.
- Reason:
The ‘ciphers’ option is deprecated and will be removed in a future release.
vault¶
- root_token_id¶
- Type:
string
- Default:
<None>
root token for vault
- auth_method¶
- Type:
string
- Default:
approle- Valid Values:
approle, jwt, kubernetes
Auth method to use when connecting to Vault. “approle” uses approle_role_id and approle_secret_id. “jwt” and “kubernetes” use token_role and token_file.
- approle_role_id¶
- Type:
string
- Default:
<None>
AppRole role_id for authentication with vault
- approle_secret_id¶
- Type:
string
- Default:
<None>
AppRole secret_id for authentication with vault
- token_role¶
- Type:
string
- Default:
<None>
Vault role name for token-based auth. Required when auth_method is jwt or kubernetes.
- token_file¶
- Type:
string
- Default:
<None>
Path to the token file used for Vault login. Required when auth_method is jwt or kubernetes.
- auth_path¶
- Type:
string
- Default:
<None>
Mount path of the Vault auth backend, used in the login URL /v1/auth/<auth_path>/login. Defaults to the value of auth_method when not set. Override this when the auth backend is mounted at a non-default path (e.g. “kubernetes-my-cluster” instead of “kubernetes”).
- kv_mountpoint¶
- Type:
string
- Default:
secret
Mountpoint of KV store in Vault to use
- kv_path¶
- Type:
string
- Default:
<None>
Path relative to root of KV store in Vault to use.
- kv_version¶
- Type:
integer
- Default:
2- Valid Values:
1, 2
Version of KV store in Vault to use.
- vault_url¶
- Type:
URI
- Default:
http://127.0.0.1:8200
Use this endpoint to connect to Vault
- ssl_ca_crt_file¶
- Type:
string
- Default:
<None>
Absolute path to ca cert file
- use_ssl¶
- Type:
boolean
- Default:
False
SSL Enabled/Disabled
Warning
This option is deprecated for removal. Its value may be silently ignored in the future.
- Reason:
This option has no effect.
- namespace¶
- Type:
string
- Default:
<None>
Vault Namespace to use for all requests to Vault. Vault Namespaces feature is available only in Vault Enterprise
- timeout¶
- Type:
floating point
- Default:
60
Timeout (in seconds) in each request to Vault