---
title: Charmhub | Deploy Charmed OSM using Charmhub - The Open Operator Collection
description: Deploy the latest version of Charmed OSM as a Kubernetes Operator on
  any cloud.
url: https://charmhub.io/osm/configurations/osm-keystone
---

##### We've discontinued the registration of new Bundles

New Bundle registrations are no longer accepted. Existing bundles remain functional. We recommend using the Juju Terraform Provider for new deployments.

[Learn more](https://discourse.charmhub.io/t/discontinuing-new-charmhub-bundle-registrations/15344)

# Charmed OSM

[Charmed Distribution of OSM](https://charmhub.io/publisher/charmed-osm "View all packages from Charmed Distribution of OSM")
| bundle

* [Charmed Distribution of OSM](https://charmhub.io/publisher/charmed-osm "View all packages from Charmed Distribution of OSM")
  | bundle

Platform:

stable 249

```
juju deploy osm
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

* [Osm Grafana](https://charmhub.io/osm/configurations/osm-grafana)
* [Nginx Ingress Integrator](https://charmhub.io/osm/configurations/nginx-ingress-integrator)
* [Kafka K8S](https://charmhub.io/osm/configurations/kafka-k8s)
* [Osm Keystone](https://charmhub.io/osm/configurations/osm-keystone)
* [Osm Lcm](https://charmhub.io/osm/configurations/osm-lcm)
* [Charmed Osm Mariadb K8S](https://charmhub.io/osm/configurations/charmed-osm-mariadb-k8s)
* [Osm Mon](https://charmhub.io/osm/configurations/osm-mon)
* [Mongodb K8S](https://charmhub.io/osm/configurations/mongodb-k8s)
* [Osm Nbi](https://charmhub.io/osm/configurations/osm-nbi)
* [Osm Ng Ui](https://charmhub.io/osm/configurations/osm-ng-ui)
* [Osm Pol](https://charmhub.io/osm/configurations/osm-pol)
* [Osm Prometheus](https://charmhub.io/osm/configurations/osm-prometheus)
* [Osm Ro](https://charmhub.io/osm/configurations/osm-ro)
* [Osm Vca Integrator](https://charmhub.io/osm/configurations/osm-vca-integrator)
* [Zookeeper K8S](https://charmhub.io/osm/configurations/zookeeper-k8s)

[Learn about configurations >](https://juju.is/docs/juju/configuration#heading--application-configuration)

* admin-password | string

  Default: admin

  Admin password to be created when starting the service
* admin-project | string

  Default: admin

  Admin project to be created when starting the service
* admin-username | string

  Default: admin

  Admin username to be created when starting the service
* keystone-db-password | string

  Default: admin

  Keystone DB Password
* ldap-authentication-domain-name | string

  Name of the domain which use LDAP authentication
* ldap-bind-password | string

  Password to bind and search for users
* ldap-bind-user | string

  User to bind and search for users
* ldap-chase-referrals | string

  Sets keystone’s referral chasing behavior across directory partitions.
  If left unset, the system’s default behavior will be used.
* ldap-enabled | boolean

  Boolean to enable/disable LDAP authentication
* ldap-group-objectclass | string

  Default: groupOfNames

  The LDAP object class to use for groups.
* ldap-group-tree-dn | string

  The search base to use for groups.
* ldap-page-size | int

  Defines the maximum number of results per page that keystone should
  request from the LDAP server when listing objects. A value of zero (0)
  disables paging.
* ldap-tls-cacert-base64 | string

  CA certificate in Base64 format (if you have the PEM file, text inside
  "-----BEGIN CERTIFICATE-----"/"-----END CERTIFICATE-----" tags).
* ldap-tls-req-cert | string

  Default: demand

  Defines how the certificates are checked for validity in the client
  (i.e., Keystone end) of the secure connection (this doesn’t affect what
  level of checking the server is doing on the certificates it receives
  from Keystone). Possible values are "demand", "never", and "allow". The
  default of demand means the client always checks the certificate and
  will drop the connection if it is not provided or invalid. never is the
  opposite—it never checks it, nor requires it to be provided. allow means
  that if it is not provided then the connection is allowed to continue,
  but if it is provided it will be checked—and if invalid, the connection
  will be dropped.
* ldap-url | string

  Default: ldap://localhost

  URL of the LDAP server
* ldap-use-starttls | boolean

  Enable Transport Layer Security (TLS) for providing a secure connection
  from Keystone to LDAP (StartTLS, not LDAPS).
* ldap-user-enabled-attribute | string

  Default: enabled

  In Keystone, a user entity can be either enabled or disabled. Setting
  the above option will give a mapping to an equivalent attribute in LDAP,
  allowing your LDAP management tools to disable a user.
* ldap-user-enabled-default | string

  Default: true

  Most LDAP servers use a boolean or bit in a control field to indicate
  enablement. However, some schemas might use an integer value in an
  attribute. In this situation, set user\_enabled\_default to the integer
  value that represents a user being enabled.
* ldap-user-enabled-invert | boolean

  Some LDAP schemas have an “account locked” attribute, which is the
  equivalent to account being “disabled.” In order to map this to the
  Keystone enabled attribute, you can utilize the user\_enabled\_invert
  setting in conjunction with user\_enabled\_attribute to map the lock
  status to disabled in Keystone.
* ldap-user-enabled-mask | int

  Some LDAP schemas, rather than having a dedicated attribute for user
  enablement, use a bit within a general control attribute (such as
  userAccountControl) to indicate this. Setting user\_enabled\_mask will
  cause Keystone to look at only the status of this bit in the attribute
  specified by user\_enabled\_attribute, with the bit set indicating the
  user is enabled.
* ldap-user-filter | string

  This filter option allow additional filter (over and above
  user\_objectclass) to be included into the search of user. One common use
  of this is to provide more efficient searching, where the recommended
  search for user objects is (&(objectCategory=person)(objectClass=user)).
  By specifying user\_objectclass as user and user\_filter as
  objectCategory=person in the Keystone configuration file, this can be
  achieved.
* ldap-user-id-attribute | string

  Default: cn

  This set of options define the mapping to LDAP attributes for the three
  key user attributes supported by Keystone. The LDAP attribute chosen for
  user\_id must be something that is immutable for a user and no more than
  64 characters in length. Notice that Distinguished Name (DN) may be
  longer than 64 characters and thus is not suitable. An uid, or mail may
  be appropriate.
* ldap-user-name-attribute | string

  Default: sn

  This set of options define the mapping to LDAP attributes for the three
  key user attributes supported by Keystone. The LDAP attribute chosen for
  user\_id must be something that is immutable for a user and no more than
  64 characters in length. Notice that Distinguished Name (DN) may be
  longer than 64 characters and thus is not suitable. An uid, or mail may
  be appropriate.
* ldap-user-objectclass | string

  Default: inetOrgPerson

  LDAP object class that Keystone will filter on within user\_tree\_dn to
  find user objects. Any objects of other classes will be ignored.
* ldap-user-pass-attribute | string

  Default: userPassword

  This set of options define the mapping to LDAP attributes for the three
  key user attributes supported by Keystone. The LDAP attribute chosen for
  user\_id must be something that is immutable for a user and no more than
  64 characters in length. Notice that Distinguished Name (DN) may be
  longer than 64 characters and thus is not suitable. An uid, or mail may
  be appropriate.
* ldap-user-tree-dn | string

  Root of the tree in LDAP server in which Keystone will search for users
* mysql-uri | string

  Mysql URI with the following format:
  mysql://<user>:<password>@<mysql\_host>:<mysql\_port>/<database>
* project-domain-name | string

  Default: default

  Project domain name (Hardcoded in the container start.sh script)
* region-id | string

  Default: RegionOne

  Region ID to be created when starting the service
* service-password | string

  Default: nbi

  Service Password to be created when starting the service
* service-project | string

  Default: service

  Service Project to be created when starting the service
* service-username | string

  Default: nbi

  Service Username to be created when starting the service
* token-expiration | int

  Default: 3600

  Token keys expiration in seconds
* user-domain-name | string

  Default: default

  User domain name (Hardcoded in the container start.sh script)
