aboutsummaryrefslogtreecommitdiffstats
path: root/keystone.yaml
blob: 4fc635daba39ce5e58d5ed83173a7d3e46675b99 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
HeatTemplateFormatVersion: '2012-12-12'
Description: 'Keystone'
Parameters:
  KeyName: 
    Description: Name of an existing EC2 KeyPair to enable SSH access to the instances
    Type: String
    Default: default
  InstanceType:
    Description: Use this flavor
    Type: String
    Default: bm.small
  KeystoneDSN:
    Description: DSN for connecting to keystone
    Type: String
  KeystoneImage:
    Type: String
  AdminToken:
    Type: String
Resources:
  ApiAccessPolicy:
    Type: OS::Heat::AccessPolicy
    Properties:
      AllowedResources: [ KeystoneLaunch, Keystone ]
  ApiUser:
    Type: AWS::IAM::User
    Properties:
      Policies: [ { Ref: ApiAccessPolicy } ]
  ApiKey:
    Type: AWS::IAM::AccessKey
    Properties:
      UserName:
        Ref: ApiUser
  Keystone:
    Type: AWS::EC2::Instance
    Properties:
      ImageId:
        {Ref: KeystoneImage}
      InstanceType: {Ref: InstanceType}
      KeyName: {Ref: KeyName}
    Metadata:
      OpenStack::Role: stateless
      OpenStack::ImageBuilder::Elements: [ keystone ]
      heat: 
        access_key_id:
          Ref: ApiKey
        secret_key:
          Fn::GetAtt: [ ApiKey, SecretAccessKey ]
        stack:
          name: {Ref: 'AWS::StackName'}
          region: {Ref: 'AWS::Region'}
        refresh:
          - resource: Keystone
      admin-token: {Ref: AdminToken}
      keystone:
        db: {Ref: KeystoneDSN}