2013-08-27 01:02:03 -04:00
|
|
|
---
|
2015-07-22 22:31:00 -04:00
|
|
|
layout: docs
|
2017-03-25 18:13:52 -04:00
|
|
|
sidebar_current: docs-builders-openstack
|
|
|
|
page_title: OpenStack - Builders
|
|
|
|
description: |-
|
|
|
|
The openstack Packer builder is able to create new images for use with
|
|
|
|
OpenStack. The builder takes a source image, runs any provisioning necessary
|
|
|
|
on the image after launching it, then creates a new reusable image. This
|
|
|
|
reusable image can then be used as the foundation of new servers that are
|
|
|
|
launched within OpenStack.
|
|
|
|
---
|
2013-08-27 01:02:03 -04:00
|
|
|
|
|
|
|
# OpenStack Builder
|
|
|
|
|
|
|
|
Type: `openstack`
|
|
|
|
|
2014-10-20 16:47:30 -04:00
|
|
|
The `openstack` Packer builder is able to create new images for use with
|
2015-07-22 22:31:00 -04:00
|
|
|
[OpenStack](http://www.openstack.org). The builder takes a source image, runs
|
|
|
|
any provisioning necessary on the image after launching it, then creates a new
|
|
|
|
reusable image. This reusable image can then be used as the foundation of new
|
|
|
|
servers that are launched within OpenStack. The builder will create temporary
|
|
|
|
keypairs that provide temporary access to the server while the image is being
|
|
|
|
created. This simplifies configuration quite a bit.
|
2013-08-27 01:02:03 -04:00
|
|
|
|
2015-07-22 22:31:00 -04:00
|
|
|
The builder does *not* manage images. Once it creates an image, it is up to you
|
|
|
|
to use it or delete it.
|
2013-08-27 01:02:03 -04:00
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
~> **OpenStack Liberty or later requires OpenSSL!** To use the OpenStack
|
2016-01-31 14:03:59 -05:00
|
|
|
builder with OpenStack Liberty (Oct 2015) or later you need to have OpenSSL
|
2016-09-20 04:36:15 -04:00
|
|
|
installed _if you are using temporary key pairs_, i.e. don't use
|
2016-01-31 14:03:59 -05:00
|
|
|
[`ssh_keypair_name`](openstack.html#ssh_keypair_name) nor
|
|
|
|
[`ssh_password`](/docs/templates/communicator.html#ssh_password). All major
|
|
|
|
OS'es have OpenSSL installed by default except Windows.
|
|
|
|
|
2013-08-27 01:02:03 -04:00
|
|
|
## Configuration Reference
|
|
|
|
|
|
|
|
There are many configuration options available for the builder. They are
|
|
|
|
segmented below into two categories: required and optional parameters. Within
|
|
|
|
each category, the available configuration keys are alphabetized.
|
|
|
|
|
2015-06-23 17:44:57 -04:00
|
|
|
In addition to the options listed here, a
|
2015-07-22 22:31:00 -04:00
|
|
|
[communicator](/docs/templates/communicator.html) can be configured for this
|
|
|
|
builder.
|
2015-06-23 17:44:57 -04:00
|
|
|
|
2014-05-04 13:47:40 -04:00
|
|
|
### Required:
|
2013-08-27 01:02:03 -04:00
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `flavor` (string) - The ID, name, or full URL for the desired flavor for the
|
2015-07-22 23:25:58 -04:00
|
|
|
server to be created.
|
2013-08-27 01:02:03 -04:00
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `image_name` (string) - The name of the resulting image.
|
2013-08-27 01:02:03 -04:00
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `identity_endpoint` (string) - The URL to the OpenStack Identity service.
|
2016-01-31 13:56:48 -05:00
|
|
|
If not specified, Packer will use the environment variables `OS_AUTH_URL`,
|
|
|
|
if set.
|
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `source_image` (string) - The ID or full URL to the base image to use. This
|
2015-07-22 23:25:58 -04:00
|
|
|
is the image that will be used to launch a new server and provision it.
|
|
|
|
Unless you specify completely custom SSH settings, the source image must
|
|
|
|
have `cloud-init` installed so that the keypair gets assigned properly.
|
2013-08-27 01:02:03 -04:00
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `source_image_name` (string) - The name of the base image to use. This
|
2015-08-10 09:43:15 -04:00
|
|
|
is an alternative way of providing `source_image` and only either of them
|
2015-08-10 09:35:56 -04:00
|
|
|
can be specified.
|
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `username` or `user_id` (string) - The username or id used to connect to
|
2016-01-31 13:56:48 -05:00
|
|
|
the OpenStack service. If not specified, Packer will use the environment
|
|
|
|
variable `OS_USERNAME` or `OS_USERID`, if set.
|
2015-06-12 00:33:52 -04:00
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `password` (string) - The password used to connect to the OpenStack service.
|
2015-07-22 23:25:58 -04:00
|
|
|
If not specified, Packer will use the environment variables `OS_PASSWORD`,
|
|
|
|
if set.
|
2013-08-27 01:02:03 -04:00
|
|
|
|
2014-05-04 13:47:40 -04:00
|
|
|
### Optional:
|
2013-08-27 01:02:03 -04:00
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `availability_zone` (string) - The availability zone to launch the
|
2015-07-22 23:25:58 -04:00
|
|
|
server in. If this isn't specified, the default enforced by your OpenStack
|
|
|
|
cluster will be used. This may be required for some OpenStack clusters.
|
2015-06-12 11:10:10 -04:00
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `config_drive` (boolean) - Whether or not nova should use ConfigDrive for
|
2016-02-18 00:45:14 -05:00
|
|
|
cloud-init metadata.
|
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `domain_name` or `domain_id` (string) - The Domain name or ID you are
|
2016-02-18 00:45:14 -05:00
|
|
|
authenticating with. OpenStack installations require this if identity v3 is used.
|
|
|
|
Packer will use the environment variable `OS_DOMAIN_NAME` or `OS_DOMAIN_ID`, if set.
|
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `endpoint_type` (string) - The endpoint type to use. Can be any of "internal",
|
2016-01-31 13:56:48 -05:00
|
|
|
"internalURL", "admin", "adminURL", "public", and "publicURL". By default
|
|
|
|
this is "public".
|
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `floating_ip` (string) - A specific floating IP to assign to this instance.
|
2014-04-30 19:55:50 -04:00
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `floating_ip_pool` (string) - The name of the floating IP pool to use to
|
2016-01-31 13:56:48 -05:00
|
|
|
allocate a floating IP.
|
2014-04-30 19:55:50 -04:00
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `image_members` (array of strings) - List of members to add to the image
|
2016-12-14 19:00:29 -05:00
|
|
|
after creation. An image member is usually a project (also called the
|
|
|
|
“tenant”) with whom the image is shared.
|
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `image_visibility` (string) - One of "public", "private", "shared", or
|
2016-12-14 19:00:29 -05:00
|
|
|
"community".
|
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `insecure` (boolean) - Whether or not the connection to OpenStack can be
|
2015-07-22 23:25:58 -04:00
|
|
|
done over an insecure connection. By default this is false.
|
2014-05-05 12:44:25 -04:00
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `metadata` (object of key/value strings) - Glance metadata that will be
|
2016-02-18 00:45:14 -05:00
|
|
|
applied to the image.
|
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `instance_metadata` (object of key/value strings) - Metadata that is
|
2017-01-04 21:15:16 -05:00
|
|
|
applied to the server instance created by Packer. Also called server
|
|
|
|
properties in some documentation. The strings have a max size of 255 bytes
|
|
|
|
each.
|
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `networks` (array of strings) - A list of networks by UUID to attach to
|
2015-07-22 23:25:58 -04:00
|
|
|
this instance.
|
2014-06-15 19:46:02 -04:00
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `rackconnect_wait` (boolean) - For rackspace, whether or not to wait for
|
2016-02-18 00:45:14 -05:00
|
|
|
Rackconnect to assign the machine an IP address before connecting via SSH.
|
|
|
|
Defaults to false.
|
2014-05-01 23:26:07 -04:00
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `region` (string) - The name of the region, such as "DFW", in which to
|
2015-07-22 23:25:58 -04:00
|
|
|
launch the server to create the AMI. If not specified, Packer will use the
|
|
|
|
environment variable `OS_REGION_NAME`, if set.
|
2014-09-04 21:51:00 -04:00
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `reuse_ips` (boolean) - Whether or not to attempt to reuse existing
|
2017-02-16 07:35:27 -05:00
|
|
|
unassigned floating ips in the project before allocating a new one. Note
|
|
|
|
that it is not possible to safely do this concurrently, so if you are
|
|
|
|
running multiple openstack builds concurrently, or if other processes are
|
|
|
|
assigning and using floating IPs in the same openstack project while packer
|
|
|
|
is running, you should not set this to true. Defaults to false.
|
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `security_groups` (array of strings) - A list of security groups by name to
|
2016-02-18 00:45:14 -05:00
|
|
|
add to this instance.
|
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `ssh_interface` (string) - The type of interface to connect via SSH. Values
|
2015-07-22 23:25:58 -04:00
|
|
|
useful for Rackspace are "public" or "private", and the default behavior is
|
|
|
|
to connect via whichever is returned first from the OpenStack API.
|
2015-02-17 16:44:21 -05:00
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `ssh_ip_version` (string) - The IP version to use for SSH connections, valid
|
2016-02-14 15:23:56 -05:00
|
|
|
values are `4` and `6`. Useful on dual stacked instances where the default
|
2016-12-14 15:50:26 -05:00
|
|
|
behavior is to connect via whichever IP address is returned first from the
|
2016-02-14 15:23:56 -05:00
|
|
|
OpenStack API.
|
2016-02-13 15:53:46 -05:00
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `ssh_keypair_name` (string) - If specified, this is the key that will be
|
2016-01-31 13:56:48 -05:00
|
|
|
used for SSH with the machine. By default, this is blank, and Packer will
|
|
|
|
generate a temporary keypair.
|
2017-03-13 15:18:05 -04:00
|
|
|
[`ssh_password`](/docs/templates/communicator.html#ssh_password) is used.
|
2016-03-04 01:56:39 -05:00
|
|
|
[`ssh_private_key_file`](/docs/templates/communicator.html#ssh_private_key_file)
|
2017-03-13 15:18:05 -04:00
|
|
|
or `ssh_agent_auth` must be specified when `ssh_keypair_name` is utilized.
|
2016-01-31 13:56:48 -05:00
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `ssh_agent_auth` (boolean) - If true, the local SSH agent will be used to
|
2017-03-13 15:18:05 -04:00
|
|
|
authenticate connections to the source instance. No temporary keypair will
|
|
|
|
be created, and the values of `ssh_password` and `ssh_private_key_file` will
|
|
|
|
be ignored. To use this option with a key pair already configured in the source
|
|
|
|
image, leave the `ssh_keypair_name` blank. To associate an existing key pair
|
|
|
|
with the source instance, set the `ssh_keypair_name` field to the name
|
|
|
|
of the key pair.
|
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `temporary_key_pair_name` (string) - The name of the temporary key pair
|
2017-03-13 15:18:05 -04:00
|
|
|
to generate. By default, Packer generates a name that looks like
|
|
|
|
`packer_<UUID>`, where \<UUID\> is a 36 character unique identifier.
|
2017-03-10 11:45:13 -05:00
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `tenant_id` or `tenant_name` (string) - The tenant ID or name to boot the
|
2016-02-18 00:45:14 -05:00
|
|
|
instance into. Some OpenStack installations require this. If not specified,
|
|
|
|
Packer will use the environment variable `OS_TENANT_NAME`, if set. Tenant
|
|
|
|
is also called Project in later versions of OpenStack.
|
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `use_floating_ip` (boolean) - _Deprecated_ use `floating_ip` or `floating_ip_pool`
|
2016-01-31 13:56:48 -05:00
|
|
|
instead.
|
2014-04-30 19:55:50 -04:00
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `user_data` (string) - User data to apply when launching the instance. Note
|
2016-01-31 13:56:48 -05:00
|
|
|
that you need to be careful about escaping characters due to the templates
|
|
|
|
being JSON. It is often more convenient to use `user_data_file`, instead.
|
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `user_data_file` (string) - Path to a file that will be used for the user
|
2016-01-31 13:56:48 -05:00
|
|
|
data when launching the instance.
|
|
|
|
|
|
|
|
## Basic Example: DevStack
|
|
|
|
|
|
|
|
Here is a basic example. This is a example to build on DevStack running in a VM.
|
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
```json
|
2016-01-31 13:56:48 -05:00
|
|
|
{
|
|
|
|
"type": "openstack",
|
|
|
|
"identity_endpoint": "http://<destack-ip>:5000/v3",
|
|
|
|
"tenant_name": "admin",
|
|
|
|
"domain_name": "Default",
|
|
|
|
"username": "admin",
|
|
|
|
"password": "<your admin password>",
|
|
|
|
"region": "RegionOne",
|
|
|
|
"ssh_username": "root",
|
|
|
|
"image_name": "Test image",
|
|
|
|
"source_image": "<image id>",
|
|
|
|
"flavor": "m1.tiny",
|
|
|
|
"insecure": "true"
|
|
|
|
}
|
|
|
|
|
|
|
|
```
|
|
|
|
|
2014-09-04 21:17:13 -04:00
|
|
|
## Basic Example: Rackspace public cloud
|
2013-08-27 01:02:03 -04:00
|
|
|
|
2015-07-22 22:31:00 -04:00
|
|
|
Here is a basic example. This is a working example to build a Ubuntu 12.04 LTS
|
|
|
|
(Precise Pangolin) on Rackspace OpenStack cloud offering.
|
2013-08-27 01:02:03 -04:00
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
```json
|
2013-08-27 01:02:03 -04:00
|
|
|
{
|
|
|
|
"type": "openstack",
|
2015-06-12 00:33:52 -04:00
|
|
|
"username": "foo",
|
|
|
|
"password": "foo",
|
2013-09-01 16:30:36 -04:00
|
|
|
"region": "DFW",
|
2013-08-27 01:02:03 -04:00
|
|
|
"ssh_username": "root",
|
|
|
|
"image_name": "Test image",
|
|
|
|
"source_image": "23b564c9-c3e6-49f9-bc68-86c7a9ab5018",
|
|
|
|
"flavor": "2"
|
|
|
|
}
|
2014-10-20 13:55:16 -04:00
|
|
|
```
|
2013-09-01 16:30:36 -04:00
|
|
|
|
2014-09-04 21:17:13 -04:00
|
|
|
## Basic Example: Private OpenStack cloud
|
|
|
|
|
2015-07-22 22:31:00 -04:00
|
|
|
This example builds an Ubuntu 14.04 image on a private OpenStack cloud, powered
|
|
|
|
by Metacloud.
|
2014-09-04 21:17:13 -04:00
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
```json
|
2014-09-04 21:17:13 -04:00
|
|
|
{
|
|
|
|
"type": "openstack",
|
2014-09-04 21:23:29 -04:00
|
|
|
"ssh_username": "root",
|
2014-09-04 21:17:13 -04:00
|
|
|
"image_name": "ubuntu1404_packer_test_1",
|
|
|
|
"source_image": "91d9c168-d1e5-49ca-a775-3bfdbb6c97f1",
|
|
|
|
"flavor": "2"
|
|
|
|
}
|
2014-10-20 13:55:16 -04:00
|
|
|
```
|
2014-09-04 21:17:13 -04:00
|
|
|
|
2015-07-22 22:31:00 -04:00
|
|
|
In this case, the connection information for connecting to OpenStack doesn't
|
|
|
|
appear in the template. That is because I source a standard OpenStack script
|
|
|
|
with environment variables set before I run this. This script is setting
|
|
|
|
environment variables like:
|
2014-09-04 21:17:13 -04:00
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `OS_AUTH_URL`
|
|
|
|
- `OS_TENANT_ID`
|
|
|
|
- `OS_USERNAME`
|
|
|
|
- `OS_PASSWORD`
|
2016-01-26 19:30:17 -05:00
|
|
|
|
|
|
|
This is slightly different when identity v3 is used:
|
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
- `OS_AUTH_URL`
|
|
|
|
- `OS_USERNAME`
|
|
|
|
- `OS_PASSWORD`
|
|
|
|
- `OS_DOMAIN_NAME`
|
|
|
|
- `OS_TENANT_NAME`
|
2016-01-26 19:30:17 -05:00
|
|
|
|
2016-01-31 13:56:48 -05:00
|
|
|
This will authenticate the user on the domain and scope you to the project.
|
|
|
|
A tenant is the same as a project. It's optional to use names or IDs in v3.
|
|
|
|
This means you can use `OS_USERNAME` or `OS_USERID`, `OS_TENANT_ID` or
|
2016-01-26 19:30:17 -05:00
|
|
|
`OS_TENANT_NAME` and `OS_DOMAIN_ID` or `OS_DOMAIN_NAME`.
|
|
|
|
|
|
|
|
The above example would be equivalent to an RC file looking like this :
|
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
```shell
|
|
|
|
export OS_AUTH_URL="https://identity.myprovider/v3"
|
|
|
|
export OS_USERNAME="myuser"
|
|
|
|
export OS_PASSWORD="password"
|
|
|
|
export OS_USER_DOMAIN_NAME="mydomain"
|
|
|
|
export OS_PROJECT_DOMAIN_NAME="mydomain"
|
|
|
|
```
|
2016-01-31 13:56:48 -05:00
|
|
|
|
|
|
|
## Notes on OpenStack Authorization
|
|
|
|
|
|
|
|
The simplest way to get all settings for authorization agains OpenStack is to
|
|
|
|
go into the OpenStack Dashboard (Horizon) select your _Project_ and navigate
|
|
|
|
_Project, Access & Security_, select _API Access_ and _Download OpenStack RC
|
|
|
|
File v3_. Source the file, and select your wanted region by setting
|
|
|
|
environment variable `OS_REGION_NAME` or `OS_REGION_ID` and `export
|
|
|
|
OS_TENANT_NAME=$OS_PROJECT_NAME` or `export OS_TENANT_ID=$OS_PROJECT_ID`.
|
|
|
|
|
2017-03-25 18:13:52 -04:00
|
|
|
~> `OS_TENANT_NAME` or `OS_TENANT_ID` must be used even with Identity v3,
|
2016-01-31 13:56:48 -05:00
|
|
|
`OS_PROJECT_NAME` and `OS_PROJECT_ID` has no effect in Packer.
|
|
|
|
|
|
|
|
To troubleshoot authorization issues test you environment variables with the
|
2016-03-09 06:29:31 -05:00
|
|
|
OpenStack cli. It can be installed with
|
2017-03-25 18:13:52 -04:00
|
|
|
|
|
|
|
```
|
|
|
|
$ pip install --user python-openstackclient
|
|
|
|
```
|