Name: keystone-api Namespace: openstack CreationTimestamp: Sun, 29 Mar 2026 02:03:57 +0000 Labels: app.kubernetes.io/managed-by=Helm application=keystone component=api release_group=keystone Annotations: deployment.kubernetes.io/revision: 1 meta.helm.sh/release-name: keystone meta.helm.sh/release-namespace: openstack openstackhelm.openstack.org/release_uuid: Selector: application=keystone,component=api,release_group=keystone Replicas: 1 desired | 1 updated | 1 total | 1 available | 0 unavailable StrategyType: RollingUpdate MinReadySeconds: 0 RollingUpdateStrategy: 1 max unavailable, 3 max surge Pod Template: Labels: application=keystone component=api release_group=keystone Annotations: configmap-bin-hash: 0fa826d4d7a09702781edd1dea99271bec84830f0fb47c323ca6697719e1dc71 configmap-etc-hash: c5bb6974b5ee05283172a952ea5f8a72490fea1bb6a9308b28e88ad5ad8c6297 openstackhelm.openstack.org/release_uuid: Service Account: keystone-api Init Containers: init: Image: harbor.atmosphere.dev/ghcr.io/vexxhost/kubernetes-entrypoint:edge@sha256:8921b64b87af184a1421dd856b2703bcf3cff9f50863cd0d18371cf964a87bd3 Port: Host Port: Command: kubernetes-entrypoint Environment: POD_NAME: (v1:metadata.name) NAMESPACE: (v1:metadata.namespace) INTERFACE_NAME: eth0 PATH: /usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/ DEPENDENCY_SERVICE: openstack:memcached,openstack:percona-xtradb-haproxy DEPENDENCY_JOBS: keystone-db-sync,keystone-credential-setup,keystone-fernet-setup DEPENDENCY_DAEMONSET: DEPENDENCY_CONTAINER: DEPENDENCY_POD_JSON: DEPENDENCY_CUSTOM_RESOURCE: Mounts: Containers: keystone-api: Image: harbor.atmosphere.dev/ghcr.io/vexxhost/keystone:2025.1@sha256:adfa098b5ac03326572cabd4b6750192024e9e04fa97815314ace33629398901 Port: 5000/TCP Host Port: 0/TCP Command: /tmp/keystone-api.sh start Liveness: http-get http://:5000/v3/ delay=50s timeout=15s period=60s #success=1 #failure=3 Readiness: http-get http://:5000/v3/ delay=15s timeout=15s period=60s #success=1 #failure=3 Environment: Mounts: /etc/apache2/conf-enabled/security.conf from keystone-etc (ro,path="security.conf") /etc/apache2/conf-enabled/wsgi-keystone.conf from keystone-etc (ro,path="wsgi-keystone.conf") /etc/apache2/mods-available/mpm_event.conf from keystone-etc (ro,path="mpm_event.conf") /etc/apache2/ports.conf from keystone-etc (ro,path="ports.conf") /etc/keystone from etckeystone (rw) /etc/keystone/access_rules.json from keystone-etc (ro,path="access_rules.json") /etc/keystone/credential-keys/ from keystone-credential-keys (rw) /etc/keystone/domains/keystone.atmosphere.conf from keystone-etc (ro,path="keystone.atmosphere.conf") /etc/keystone/fernet-keys/ from keystone-fernet-keys (rw) /etc/keystone/keystone.conf from keystone-etc (ro,path="keystone.conf") /etc/keystone/policy.yaml from keystone-etc (ro,path="policy.yaml") /etc/keystone/sso_callback_template.html from keystone-etc (ro,path="sso_callback_template.html") /etc/ssl/certs/ca-certificates.crt from ca-certificates (ro) /tmp from pod-tmp (rw) /tmp/keystone-api.sh from keystone-bin (ro,path="keystone-api.sh") /var/lib/apache2/oidc/keycloak.162-253-55-62.nip.io%2Frealms%2Fatmosphere.client from keystone-openid-metadata (rw,path="atmosphere-oidc-client") /var/lib/apache2/oidc/keycloak.162-253-55-62.nip.io%2Frealms%2Fatmosphere.conf from keystone-openid-metadata (rw,path="atmosphere-oidc-conf") /var/lib/apache2/oidc/keycloak.162-253-55-62.nip.io%2Frealms%2Fatmosphere.provider from keystone-openid-metadata (rw,path="atmosphere-oidc-provider") /var/log/apache2 from logs-apache (rw) /var/run/apache2 from run-apache (rw) /var/www/cgi-bin/keystone from wsgi-keystone (rw) Volumes: pod-tmp: Type: EmptyDir (a temporary directory that shares a pod's lifetime) Medium: SizeLimit: etckeystone: Type: EmptyDir (a temporary directory that shares a pod's lifetime) Medium: SizeLimit: wsgi-keystone: Type: EmptyDir (a temporary directory that shares a pod's lifetime) Medium: SizeLimit: logs-apache: Type: EmptyDir (a temporary directory that shares a pod's lifetime) Medium: SizeLimit: run-apache: Type: EmptyDir (a temporary directory that shares a pod's lifetime) Medium: SizeLimit: keystone-etc: Type: Secret (a volume populated by a Secret) SecretName: keystone-etc Optional: false keystone-bin: Type: ConfigMap (a volume populated by a ConfigMap) Name: keystone-bin Optional: false keystone-fernet-keys: Type: Secret (a volume populated by a Secret) SecretName: keystone-fernet-keys Optional: false keystone-credential-keys: Type: Secret (a volume populated by a Secret) SecretName: keystone-credential-keys Optional: false keystone-openid-metadata: Type: ConfigMap (a volume populated by a ConfigMap) Name: keystone-openid-metadata Optional: false ca-certificates: Type: HostPath (bare host directory volume) Path: /etc/ssl/certs/ca-certificates.crt HostPathType: Conditions: Type Status Reason ---- ------ ------ Available True MinimumReplicasAvailable Progressing True NewReplicaSetAvailable OldReplicaSets: NewReplicaSet: keystone-api-55d58fd749 (1/1 replicas created) Events: Type Reason Age From Message ---- ------ ---- ---- ------- Normal ScalingReplicaSet 16m deployment-controller Scaled up replica set keystone-api-55d58fd749 to 1