Skip to main content
Connect your OpenStack cloud to let CloudThinker agents inspect servers, volumes, networks, images, flavors, and quotas in one project, and make changes after you approve them. OpenStack authenticates with a Keystone user name and password, scoped to one project and one region.

Prerequisites

  • An OpenStack cloud whose Keystone (Identity) v3 address CloudThinker can reach. Use an https address.
  • A dedicated Keystone user with a role on the project you want inspected. See Required permissions.
  • The project name, the domain names of the user and the project, and the region.
CloudThinker supports one OpenStack connection per workspace, and each connection covers one project in one region. Federated sign-in and application credentials are not supported; the connection uses a user name and password.

Setup

1

Find your sign-in values

OpenStack’s own documentation says that before you issue client commands you “must download and source the openrc file” for your project. Open that file, or ask your cloud administrator, for the authentication URL, project name, user name, domain names, and region.
2

Create or choose a Keystone user

Use a dedicated user and give it a role on the project. A reader role is the least-privilege start.
3

Add the connection in CloudThinker

Navigate to Connections → OpenStack and enter the fields in Connection details. Leave the five optional endpoint fields blank unless your catalog is incomplete.Click Connect. CloudThinker requests a token from Keystone and shows a Connected status.

Connection details

Five optional fields let you bypass the Keystone catalog for one service: OS_IMAGE_ENDPOINT_OVERRIDE, OS_COMPUTE_ENDPOINT_OVERRIDE, OS_NETWORK_ENDPOINT_OVERRIDE, OS_VOLUMEV3_ENDPOINT_OVERRIDE, and OS_PLACEMENT_ENDPOINT_OVERRIDE. Each takes a full http(s) URL.
There is no field for a custom certificate authority. For a cloud with a self-signed certificate, Skip SSL verification is the only way to connect, and it removes protection against someone impersonating your cloud. Use it for lab clouds only. Internal endpoint works only if CloudThinker can reach your control-plane network.

Required permissions

Keystone ships three default roles, admin, member, and reader. OpenStack documents reader as read-only access to resources within a project, and the roles are nested, so member includes reader.
  • Start with reader on the project for inspection.
  • Which role each service accepts depends on your cloud’s policies. If a service refuses a request, grant the narrowest role that it accepts.
  • Every request is scoped to the project. Questions across all projects usually need the admin role; without it OpenStack can answer 403 Forbidden.
OpenStack’s documentation cautions that the reader role is the lowest level of authorization and that default policies may not expose sensitive information to it. Check what your cloud returns before you rely on it for audits.

Agent capabilities

See Approval for how gated changes work.

Verify the connection

Example prompts

Troubleshooting

Keystone did not issue a token. Check the user name, password, project name, and domain names, that the address is reachable from CloudThinker, and that the user has a role on the project. A certificate CloudThinker does not trust also fails here unless Skip SSL verification is selected.
The address is not a Keystone v3 URL, or it contains credentials, a query string, or a fragment. Use the address from your openrc file, which ends in /v3.
The region has a space or another character. Copy the region name exactly as it appears in your service catalog.
An optional endpoint field holds something other than a full URL; the same message names whichever override field is wrong. Enter a URL such as https://image.example.com, or clear the field.
The authentication address is empty. Enter your Keystone v3 address and connect again.
This workspace already has an OpenStack connection. Edit the existing one or disconnect it first.
Questions across all projects usually need the admin role. Ask about your own project, or grant the user that role.

Security

  • Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
  • Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
  • Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
  • Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
  • Use an https address — CloudThinker accepts an http Keystone address, but your password would then travel unencrypted.
  • Keep certificate checks on — Skip SSL verification is for lab clouds with self-signed certificates.

Kubernetes Connection

Workload analysis, resource optimization, and cluster operations

Approval

How approval-gated actions work