The Image service’s middleware pipeline for its registry is found in the glance-registry-paste.ini file.

# Use this pipeline for no auth - DEFAULT
pipeline = healthcheck osprofiler unauthenticated-context registryapp

# Use this pipeline for keystone auth
pipeline = healthcheck osprofiler authtoken context registryapp

# Use this pipeline for authZ only. This means that the registry will treat a
# user as authenticated without making requests to keystone to reauthenticate
# the user.
pipeline = healthcheck osprofiler context registryapp

paste.app_factory = glance.registry.api:API.factory

paste.filter_factory = oslo_middleware:Healthcheck.factory
backends = disable_by_file
disable_by_file_path = /etc/glance/healthcheck_disable

paste.filter_factory = glance.api.middleware.context:ContextMiddleware.factory

paste.filter_factory = glance.api.middleware.context:UnauthenticatedContextMiddleware.factory

paste.filter_factory = keystonemiddleware.auth_token:filter_factory

paste.filter_factory = osprofiler.web:WsgiMiddleware.factory
enabled = yes  #DEPRECATED
