---
title: Charmhub | Deploy Keystone K8S using Charmhub - The Open Operator Collection
description: Deploy the latest version of Keystone K8S as a Kubernetes Operator on
  any cloud.
url: https://charmhub.io/keystone-k8s/configurations
---

# Keystone K8S

[OpenStack Charmers](https://charmhub.io/publisher/openstack-charmers "View all packages from OpenStack Charmers")

* [OpenStack Charmers](https://charmhub.io/publisher/openstack-charmers "View all packages from OpenStack Charmers")

Platform:

2024.1/stable 060d2288

```
juju deploy keystone-k8s --channel 2024.1/stable
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

* [catalog-cache-expiration](https://charmhub.io/keystone-k8s/configurations#catalog-cache-expiration)
* [debug](https://charmhub.io/keystone-k8s/configurations#debug)
* [dogpile-cache-expiration](https://charmhub.io/keystone-k8s/configurations#dogpile-cache-expiration)
* [enable-telemetry-notifications](https://charmhub.io/keystone-k8s/configurations#enable-telemetry-notifications)
* [identity-backend](https://charmhub.io/keystone-k8s/configurations#identity-backend)
* [log-level](https://charmhub.io/keystone-k8s/configurations#log-level)
* [region](https://charmhub.io/keystone-k8s/configurations#region)
* [saml-x509-keypair](https://charmhub.io/keystone-k8s/configurations#saml-x509-keypair)

[Learn about configurations >](https://juju.is/docs/juju/configuration#heading--application-configuration)

* catalog-cache-expiration | int

  Default: 60

  Amount of time (in seconds) the catalog should be cached for.
* debug | boolean

  Enable debug logging.
* dogpile-cache-expiration | int

  Default: 60

  Amount of time (in seconds) to cache items in the dogpile.cache. This only applies
  to cached methods that do not have an explicitly defined cache expiration time.
* enable-telemetry-notifications | boolean

  Enable notifications to send to telemetry.
* identity-backend | string

  Default: sql

  Keystone identity backend, valid options are sql and pam
* log-level | string

  Default: WARNING

  Log level (WARNING, INFO, DEBUG, ERROR)
* region | string

  Default: RegionOne

  Name of the OpenStack region
* saml-x509-keypair | secret

  The SAML2 x509 certificates. This certificate is used by SAML2 for two purposes:

  + Sign messages between the SP and the IDP
  + Encrypt messages. This is rarely used as in the majority of cases, SAML2 traffic is
    sent over https.
    This certificate will be part of the SAML2 metadata.
    The secret is expected to have two keys:

  {
  "certificate": "contents of the certificate",
  "key": "contents of the key"
  }

  You can upload the secrets by running:

  juju add-secret saml-secret
  certificate#file=/path/to/cert.pem
  key#file=/path/to/corresponding/key
  juju grant-secret saml-secret keystone
