/
trusts.py
71 lines (59 loc) · 2.32 KB
/
trusts.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
# Copyright (c) 2013 Mirantis Inc.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
# implied.
# See the License for the specific language governing permissions and
# limitations under the License.
from oslo.config import cfg
from climate import context
from climate.utils.openstack import keystone
CONF = cfg.CONF
def create_trust():
"""Creates trust via Keystone API v3 to use in plugins."""
client = keystone.ClimateKeystoneClient()
trustee_id = keystone.ClimateKeystoneClient(
username=CONF.os_admin_username,
password=CONF.os_admin_password,
tenant_name=CONF.os_admin_tenant_name).user_id
ctx = context.current()
trust = client.trusts.create(trustor_user=ctx.user_id,
trustee_user=trustee_id,
impersonation=False,
role_names=ctx.roles,
project=ctx.tenant_id)
return trust
def delete_trust(lease):
"""Deletes trust for the specified lease."""
if lease.trust_id:
client = keystone.ClimateKeystoneClient(trust_id=lease.trust_id)
client.trusts.delete(lease.trust_id)
def create_ctx_from_trust(trust_id):
"""Return context built from given trust."""
ctx = context.ClimateContext(
user_name=CONF.os_admin_username,
tenant_name=CONF.os_admin_tenant_name,
)
auth_url = "%s://%s:%s/v3" % (CONF.os_auth_protocol,
CONF.os_auth_host,
CONF.os_auth_port)
client = keystone.ClimateKeystoneClient(
password=CONF.os_admin_password,
trust_id=trust_id,
auth_url=auth_url,
ctx=ctx,
)
# use 'with ctx' statement in the place you need context from trust
return context.ClimateContext(
ctx,
auth_token=client.auth_token,
service_catalog=client.service_catalog.catalog['catalog'],
tenant_id=client.tenant_id,
)