---
title: Charmhub | Deploy Keystone K8s Authentication Operator using Charmhub - The
  Open Operator Collection
description: Deploy the latest version of Keystone K8s Authentication Operator on
  any cloud. Runs the Keystone Kubernetes Authenticator in the cluster.
url: https://charmhub.io/keystone-k8s-auth
---

# Keystone K8s Authentication Operator

[Canonical Kubernetes](https://charmhub.io/publisher/containers "View all packages from Canonical Kubernetes")

* [Canonical Kubernetes](https://charmhub.io/publisher/containers "View all packages from Canonical Kubernetes")

Platform:

24.04

22.04

20.04

stable 910b822

```
juju deploy keystone-k8s-auth
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

---

#### Relevant links

* [Contact](https://launchpad.net/~containers)

---

#### Contacts

##### Maintainers

* [Submit a bug](https://bugs.launchpad.net/keystone-k8s-auth-operator)

---

Share your thoughts on this charm with the community on discourse.

[Join the discussion](https://discourse.charmhub.io/)

# keystone-k8s-auth

## [Description](https://charmhub.io/keystone-k8s-auth#p-32282-description)

This charmed operator manages the Keystone K8s Auth component of the OpenStack
Cloud Provider.

## [Usage](https://charmhub.io/keystone-k8s-auth#p-32282-usage)

The charm requires keystone credentials and connection information, which
can be provided via the `keystone` relation from the [Keystone charm](https://charmhub.io/keystone).

## [Deployment](https://charmhub.io/keystone-k8s-auth#p-32282-deployment)

### [The full process](https://charmhub.io/keystone-k8s-auth#p-32282-the-full-process)

```
juju deploy charmed-kubernetes
juju config kubernetes-control-plane allow-privileged=true
juju deploy keystone-k8s-auth
juju integrate keystone-k8s-auth:certificates easyrsa:client
juju integrate keystone-k8s-auth:kube-control kubernetes-control-plane:kube-control
juju integrate keystone-k8s-auth:keystone     keystone:identity-credentials
juju integrate keystone-k8s-auth:juju-info    kubernetes-control-plane:juju-info
```

You must also tell the cluster on which it is deployed that it will be
acting as an authentication and authorization provider.
For Charmed Kubernetes, you’ll need to configure the auth settings

### [Optional Configuration](https://charmhub.io/keystone-k8s-auth#p-32282-optional-configuration)

**release**

This charm comes packed with support for multiple versions of the keystone-k8s-auth deployment.
By default it will choose the latest if unspecified, but can be specifically tuned if desired
to an existing known release at the time of the charm build.

One can list which release are available in the charm using the action:

```
juju run keystone-k8s-auth list-versions
```

**keystone-ssl-ca**

This charm by default will pick up the root ca from the `certificates` relation in order to
contact keystone if it is using https. If keystone exists in another model, one may override
the keystone CA certificate using this configuration.

```
juju config keystone-k8s-auth keystone-ssl-ca=$(cat /path/to/ca.cert)
```

**replicas**

This charm by default will install 2 replica pods in the deployment, but this be changed for less or
more pods are required.

```
juju config keystone-k8s-auth replicas=1
```

### [Authentication or Authorization](https://charmhub.io/keystone-k8s-auth#p-32282-authentication-or-authorization)

```
# find the service ip in the cluster, apply as the authn webhook
service_url=$(juju run keystone-k8s-auth/leader get-service-url | yq '.service-url')
juju config kubernetes-control-plane authn-webhook-endpoint="${service_url}"
```

### [Authorization](https://charmhub.io/keystone-k8s-auth#p-32282-authorization)

For authorization, you’ll need to build a [webhook\_config](https://github.com/kubernetes/cloud-provider-openstack/blob/master/examples/webhook/keystone-apiserver-webhook.yaml) file.

```
juju run keystone-k8s-auth/leader generate-webhook-config | yq '.webhook-config' > webhook
juju config kubernetes-control-plane authorization-webhook-config-file="$(cat webhook)"
juju config kubernetes-control-plane authorization-mode="Node,RBAC,Webhook"
```

### [Removing](https://charmhub.io/keystone-k8s-auth#p-32282-removing)

Before removing, ensure the control-plane is ignoring the service

```
juju config kubernetes-control-plane \
    --reset authorization-webhook-config-file \
    --reset authorization-mode \
    --reset authn-webhook-endpoint
juju remove-application keystone-k8s-auth
```

## [Contributing](https://charmhub.io/keystone-k8s-auth#p-32282-contributing)

Please see the [Juju SDK docs](https://juju.is/docs/sdk) for guidelines
on enhancements to this charm following best practice guidelines, and
[CONTRIBUTING.md](https://github.com/canonical/keystone-k8s-auth-operator/blob/main/CONTRIBUTING.md)
for developer guidance.

---

[Help improve this document in the forum](https://discourse.charmhub.io/t/keystone-k8s-auth/14554) ([guidelines](https://discourse.charmhub.io/t/how-to-write-docs-our-documentation-guidelines-for-contributors/1245)). Last updated 1 year, 9 months ago.
