---
title: Charmhub | Deploy Magnum using Charmhub - The Open Operator Collection
description: Deploy the latest version of Magnum on any cloud.
url: https://charmhub.io/magnum/configurations
---

# Magnum

[OpenStack Charmers](https://charmhub.io/publisher/openstack-charmers "View all packages from OpenStack Charmers")

* [OpenStack Charmers](https://charmhub.io/publisher/openstack-charmers "View all packages from OpenStack Charmers")
* [Cloud](https://charmhub.io/?filter=cloud)

Platform:

24.04

23.10

23.04

22.10

22.04

20.04

18.04

yoga/stable f7bf027

```
juju deploy magnum --channel yoga/stable
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

* [action-managed-upgrade](https://charmhub.io/magnum/configurations#action-managed-upgrade)
* [cert-manager-type](https://charmhub.io/magnum/configurations#cert-manager-type)
* [cluster-user-trust](https://charmhub.io/magnum/configurations#cluster-user-trust)
* [database](https://charmhub.io/magnum/configurations#database)
* [database-user](https://charmhub.io/magnum/configurations#database-user)
* [debug](https://charmhub.io/magnum/configurations#debug)
* [dns-ha](https://charmhub.io/magnum/configurations#dns-ha)
* [haproxy-client-timeout](https://charmhub.io/magnum/configurations#haproxy-client-timeout)
* [haproxy-connect-timeout](https://charmhub.io/magnum/configurations#haproxy-connect-timeout)
* [haproxy-queue-timeout](https://charmhub.io/magnum/configurations#haproxy-queue-timeout)
* [haproxy-server-timeout](https://charmhub.io/magnum/configurations#haproxy-server-timeout)
* [openstack-origin](https://charmhub.io/magnum/configurations#openstack-origin)
* [os-admin-hostname](https://charmhub.io/magnum/configurations#os-admin-hostname)
* [os-admin-network](https://charmhub.io/magnum/configurations#os-admin-network)
* [os-internal-hostname](https://charmhub.io/magnum/configurations#os-internal-hostname)
* [os-internal-network](https://charmhub.io/magnum/configurations#os-internal-network)
* [os-public-hostname](https://charmhub.io/magnum/configurations#os-public-hostname)
* [os-public-network](https://charmhub.io/magnum/configurations#os-public-network)
* [rabbit-user](https://charmhub.io/magnum/configurations#rabbit-user)
* [rabbit-vhost](https://charmhub.io/magnum/configurations#rabbit-vhost)
* [region](https://charmhub.io/magnum/configurations#region)
* [ssl\_ca](https://charmhub.io/magnum/configurations#ssl_ca)
* [ssl\_cert](https://charmhub.io/magnum/configurations#ssl_cert)
* [ssl\_key](https://charmhub.io/magnum/configurations#ssl_key)
* [trustee-admin](https://charmhub.io/magnum/configurations#trustee-admin)
* [trustee-domain](https://charmhub.io/magnum/configurations#trustee-domain)
* [use-internal-endpoints](https://charmhub.io/magnum/configurations#use-internal-endpoints)
* [use-syslog](https://charmhub.io/magnum/configurations#use-syslog)
* [verbose](https://charmhub.io/magnum/configurations#verbose)
* [vip](https://charmhub.io/magnum/configurations#vip)
* [vip\_cidr](https://charmhub.io/magnum/configurations#vip_cidr)
* [vip\_iface](https://charmhub.io/magnum/configurations#vip_iface)
* [worker-multiplier](https://charmhub.io/magnum/configurations#worker-multiplier)

[Learn about configurations >](https://juju.is/docs/juju/configuration#heading--application-configuration)

* action-managed-upgrade | boolean

  If True enables openstack upgrades for this charm via juju actions.
  You will still need to set openstack-origin to the new repository but
  instead of an upgrade running automatically across all units, it will
  wait for you to execute the openstack-upgrade action for this charm on
  each unit. If False it will revert to existing behavior of upgrading
  all units on config change.
* cert-manager-type | string

  Default: barbican

  Certificate Manager plugin. Use barbican in production. Requires barbican
  to be present in your OpenStack deployment. Choices are:

  + x509keypair
  + barbican
* cluster-user-trust | boolean

  Controls whether to assign a trust to the cluster user or not. You will
  need to set it to True for clusters with volume\_driver=cinder or
  registry\_enabled=true in the underlying cluster template to work. This is
  a potential security risk since the trust gives instances OpenStack API
  access to the cluster's project. Note that this setting does not affect
  per-cluster trusts assigned to the Magnum service user.
* database | string

  Default: magnum

  Database name for Magnum
* database-user | string

  Default: magnum

  Username for Magnum database access
* debug | boolean

  Enable debug logging
* dns-ha | boolean

  Use DNS HA with MAAS 2.0. Note if this is set do not set vip settings
  below.
* haproxy-client-timeout | int

  Client timeout configuration in ms for haproxy, used in HA
  configurations. If not provided, default value of 90000ms is used.
* haproxy-connect-timeout | int

  Connect timeout configuration in ms for haproxy, used in HA
  configurations. If not provided, default value of 9000ms is used.
* haproxy-queue-timeout | int

  Queue timeout configuration in ms for haproxy, used in HA
  configurations. If not provided, default value of 9000ms is used.
* haproxy-server-timeout | int

  Server timeout configuration in ms for haproxy, used in HA
  configurations. If not provided, default value of 90000ms is used.
* openstack-origin | string

  Default: yoga

  Repository from which to install. May be one of the following:
  distro (default), ppa:somecustom/ppa, a deb url sources entry,
  or a supported Cloud Archive release pocket.

  Supported Cloud Archive sources include: cloud:precise-folsom,
  cloud:precise-folsom/updates, cloud:precise-folsom/staging,
  cloud:precise-folsom/proposed.

  Note that updating this setting to a source that is known to
  provide a later version of OpenStack will trigger a software
  upgrade.
* os-admin-hostname | string

  The hostname or address of the admin endpoints created in the keystone
  identity provider.
  .
  This value will be used for admin endpoints. For example, an
  os-admin-hostname set to 'api-admin.example.com' with ssl enabled
  will create the following endpoint for neutron-api:
  .
  https://api-admin.example.com:9696/
* os-admin-network | string

  The IP address and netmask of the OpenStack Admin network (e.g.,
  192.168.0.0/24)
  .
  This network will be used for admin endpoints.
* os-internal-hostname | string

  The hostname or address of the internal endpoints created in the keystone
  identity provider.
  .
  This value will be used for internal endpoints. For example, an
  os-internal-hostname set to 'api-internal.example.com' with ssl enabled
  will create the following endpoint for neutron-api:
  .
  https://api-internal.example.com:9696/
* os-internal-network | string

  The IP address and netmask of the OpenStack Internal network (e.g.,
  192.168.0.0/24)
  .
  This network will be used for internal endpoints.
* os-public-hostname | string

  The hostname or address of the public endpoints created in the keystone
  identity provider.
  .
  This value will be used for public endpoints. For example, an
  os-public-hostname set to 'api-public.example.com' with ssl enabled
  will create the following endpoint for neutron-api:
  .
  https://api-public.example.com:9696/
* os-public-network | string

  The IP address and netmask of the OpenStack Public network (e.g.,
  192.168.0.0/24)
  .
  This network will be used for public endpoints.
* rabbit-user | string

  Default: magnum

  Username used to access rabbitmq queue
* rabbit-vhost | string

  Default: openstack

  Rabbitmq vhost
* region | string

  Default: RegionOne

  OpenStack Region
* ssl\_ca | string

  TLS CA to use to communicate with other components in a deployment.
  .
  **NOTE**: This configuration option will take precedence over any
  certificates received over the `certificates` relation.
* ssl\_cert | string

  TLS certificate to install and use for any listening services.
  .
  **NOTE**: This configuration option will take precedence over any
  certificates received over the `certificates` relation.
* ssl\_key | string

  TLS key to use with certificate specified as `ssl_cert`.
  .
  **NOTE**: This configuration option will take precedence over any
  certificates received over the `certificates` relation.
* trustee-admin | string

  Default: magnum\_domain\_admin

  Domain admin for the trustee-domain
* trustee-domain | string

  Default: magnum

  Domain used for COE
* use-internal-endpoints | boolean

  Openstack mostly defaults to using public endpoints for
  internal communication between services. If set to True this option
  will configure services to use internal endpoints where possible.
* use-syslog | boolean

  Setting this to True will allow supporting services to log to syslog.
* verbose | boolean

  Enable verbose logging
* vip | string

  Virtual IP(s) to use to front API services in HA configuration.

  If multiple networks are being used, a VIP should be provided for each
  network, separated by spaces.
* vip\_cidr | int

  Default: 24

  Default CIDR netmask to use for HA vip when it cannot be automatically
  determined.
* vip\_iface | string

  Default: eth0

  Default network interface to use for HA vip when it cannot be
  automatically determined.
* worker-multiplier | float

  The CPU core multiplier to use when configuring worker processes. By
  default, the number of workers for each daemon is set to twice the number
  of CPU cores a service unit has. This default value will be capped
  to 4 workers unless this configuration option is set.
