Prerequisites
- An OpenStack cloud whose Keystone (Identity) v3 address CloudThinker can reach. Use an
httpsaddress. - A dedicated Keystone user with a role on the project you want inspected. See Required permissions.
- The project name, the domain names of the user and the project, and the region.
Setup
Find your sign-in values
Create or choose a Keystone user
reader role is the least-privilege start.Add the connection in CloudThinker
Connection details
http(s) URL.
Required permissions
Keystone ships three default roles,admin, member, and reader. OpenStack documents reader as read-only access to resources within a project, and the roles are nested, so member includes reader.
- Start with
readeron the project for inspection. - Which role each service accepts depends on your cloud’s policies. If a service refuses a request, grant the narrowest role that it accepts.
- Every request is scoped to the project. Questions across all projects usually need the
adminrole; without it OpenStack can answer403 Forbidden.
Agent capabilities
Verify the connection
Example prompts
Troubleshooting
Failed to connect to OpenStack
Failed to connect to OpenStack
OS_AUTH_URL must be a Keystone v3 URL (http(s)://host[:port]/[path/]v3)
OS_AUTH_URL must be a Keystone v3 URL (http(s)://host[:port]/[path/]v3)
/v3.OS_REGION_NAME must contain only letters, digits, '_', '-' (max 64 chars)
OS_REGION_NAME must contain only letters, digits, '_', '-' (max 64 chars)
OS_IMAGE_ENDPOINT_OVERRIDE must be an http(s) URL with a host
OS_IMAGE_ENDPOINT_OVERRIDE must be an http(s) URL with a host
https://image.example.com, or clear the field.Invalid OpenStack connection configuration
Invalid OpenStack connection configuration
Connection 'openstack' already exists. Only one instance is allowed.
Connection 'openstack' already exists. Only one instance is allowed.
403 Forbidden on a cross-project question
403 Forbidden on a cross-project question
admin role. Ask about your own project, or grant the user that role.Security
- Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
- Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
- Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
- Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
- Use an https address — CloudThinker accepts an
httpKeystone address, but your password would then travel unencrypted. - Keep certificate checks on — Skip SSL verification is for lab clouds with self-signed certificates.