Skip to content
Snippets Groups Projects
wsgi-keystone.conf.j2 2.85 KiB
Newer Older
Carlos Cesario's avatar
Carlos Cesario committed
{% set keystone_log_dir = '/var/log/kolla/keystone' %}
{% set binary_path = '/usr/bin' if keystone_install_type == 'binary' else '/var/lib/kolla/venv/bin' %}
{% if keystone_enable_tls_backend | bool %}
{% if kolla_base_distro in ['centos']  %}
LoadModule ssl_module /usr/lib64/httpd/modules/mod_ssl.so
{% else %}
LoadModule ssl_module /usr/lib/apache2/modules/mod_ssl.so
{% endif %}
{% endif %}
Listen {{ api_interface_address | put_address_in_context('url') }}:{{ keystone_public_listen_port }}
Listen {{ api_interface_address | put_address_in_context('url') }}:{{ keystone_admin_listen_port }}
ServerSignature Off
ServerTokens Prod
KeepAliveTimeout {{ kolla_httpd_keep_alive }}
Michal Nasiadka's avatar
Michal Nasiadka committed
ErrorLog "{{ keystone_log_dir }}/apache-error.log"
<IfModule log_config_module>
    CustomLog "{{ keystone_log_dir }}/apache-access.log" common
</IfModule>

{% if keystone_logging_debug | bool %}
LogLevel info
{% endif %}

<Directory "{{ binary_path }}">
    <FilesMatch "^keystone-wsgi-(public|admin)$">
        AllowOverride None
        Options None
        Require all granted
    </FilesMatch>
</Directory>


<VirtualHost *:{{ keystone_public_listen_port }}>
    WSGIDaemonProcess keystone-public processes={{ openstack_service_workers }} threads=1 user=keystone group=keystone display-name=keystone-public
    WSGIProcessGroup keystone-public
    WSGIScriptAlias / {{ binary_path }}/keystone-wsgi-public
    WSGIApplicationGroup %{GLOBAL}
    WSGIPassAuthorization On
    <IfVersion >= 2.4>
      ErrorLogFormat "%{cu}t %M"
    </IfVersion>
Carlos Cesario's avatar
Carlos Cesario committed
    ErrorLog "{{ keystone_log_dir }}/keystone-apache-public-error.log"
    LogFormat "%{X-Forwarded-For}i %l %u %t \"%r\" %>s %b %D \"%{Referer}i\" \"%{User-Agent}i\"" logformat
Carlos Cesario's avatar
Carlos Cesario committed
    CustomLog "{{ keystone_log_dir }}/keystone-apache-public-access.log" logformat

{% if keystone_enable_tls_backend | bool %}
    SSLEngine on
    SSLCertificateFile /etc/keystone/certs/keystone-cert.pem
    SSLCertificateKeyFile /etc/keystone/certs/keystone-key.pem
{% endif %}
<VirtualHost *:{{ keystone_admin_listen_port }}>
    WSGIDaemonProcess keystone-admin processes={{ openstack_service_workers }} threads=1 user=keystone group=keystone display-name=keystone-admin
    WSGIProcessGroup keystone-admin
    WSGIScriptAlias / {{ binary_path }}/keystone-wsgi-admin
    WSGIApplicationGroup %{GLOBAL}
    WSGIPassAuthorization On
    <IfVersion >= 2.4>
      ErrorLogFormat "%{cu}t %M"
    </IfVersion>
Carlos Cesario's avatar
Carlos Cesario committed
    ErrorLog "{{ keystone_log_dir }}/keystone-apache-admin-error.log"
    LogFormat "%{X-Forwarded-For}i %l %u %t \"%r\" %>s %b %D \"%{Referer}i\" \"%{User-Agent}i\"" logformat
Carlos Cesario's avatar
Carlos Cesario committed
    CustomLog "{{ keystone_log_dir }}/keystone-apache-admin-access.log" logformat

{% if keystone_enable_tls_backend | bool %}
    SSLEngine on
    SSLCertificateFile /etc/keystone/certs/keystone-cert.pem
    SSLCertificateKeyFile /etc/keystone/certs/keystone-key.pem
{% endif %}
</VirtualHost>