Name: keystone-api Namespace: openstack CreationTimestamp: Tue, 07 Apr 2026 15:29:44 +0000 Labels: app.kubernetes.io/managed-by=Helm application=keystone component=api release_group=keystone Annotations: deployment.kubernetes.io/revision: 1 meta.helm.sh/release-name: keystone meta.helm.sh/release-namespace: openstack openstackhelm.openstack.org/release_uuid: Selector: application=keystone,component=api,release_group=keystone Replicas: 1 desired | 1 updated | 1 total | 1 available | 0 unavailable StrategyType: RollingUpdate MinReadySeconds: 0 RollingUpdateStrategy: 1 max unavailable, 3 max surge Pod Template: Labels: application=keystone component=api release_group=keystone Annotations: configmap-bin-hash: 0fa826d4d7a09702781edd1dea99271bec84830f0fb47c323ca6697719e1dc71 configmap-etc-hash: 4b3b64310a1f40177b4197dd18db4119df827e22b606c9a8c99a118cc6e242ec openstackhelm.openstack.org/release_uuid: Service Account: keystone-api Init Containers: init: Image: harbor.atmosphere.dev/ghcr.io/vexxhost/kubernetes-entrypoint:edge@sha256:8921b64b87af184a1421dd856b2703bcf3cff9f50863cd0d18371cf964a87bd3 Port: Host Port: Command: kubernetes-entrypoint Environment: POD_NAME: (v1:metadata.name) NAMESPACE: (v1:metadata.namespace) INTERFACE_NAME: eth0 PATH: /usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/ DEPENDENCY_SERVICE: openstack:memcached,openstack:percona-xtradb-haproxy DEPENDENCY_JOBS: keystone-db-sync,keystone-credential-setup,keystone-fernet-setup DEPENDENCY_DAEMONSET: DEPENDENCY_CONTAINER: DEPENDENCY_POD_JSON: DEPENDENCY_CUSTOM_RESOURCE: Mounts: Containers: keystone-api: Image: harbor.atmosphere.dev/ghcr.io/vexxhost/keystone:2025.1@sha256:4007777530b15f1b1b69807ddaa05f9f896f48e41d030c0317b4ca49e4c65cb1 Port: 5000/TCP Host Port: 0/TCP Command: /tmp/keystone-api.sh start Liveness: http-get http://:5000/v3/ delay=50s timeout=15s period=60s #success=1 #failure=3 Readiness: http-get http://:5000/v3/ delay=15s timeout=15s period=60s #success=1 #failure=3 Environment: Mounts: /etc/apache2/conf-enabled/security.conf from keystone-etc (ro,path="security.conf") /etc/apache2/conf-enabled/wsgi-keystone.conf from keystone-etc (ro,path="wsgi-keystone.conf") /etc/apache2/mods-available/mpm_event.conf from keystone-etc (ro,path="mpm_event.conf") /etc/apache2/ports.conf from keystone-etc (ro,path="ports.conf") /etc/keystone from etckeystone (rw) /etc/keystone/access_rules.json from keystone-etc (ro,path="access_rules.json") /etc/keystone/credential-keys/ from keystone-credential-keys (rw) /etc/keystone/domains/keystone.atmosphere.conf from keystone-etc (ro,path="keystone.atmosphere.conf") /etc/keystone/fernet-keys/ from keystone-fernet-keys (rw) /etc/keystone/keystone.conf from keystone-etc (ro,path="keystone.conf") /etc/keystone/policy.yaml from keystone-etc (ro,path="policy.yaml") /etc/keystone/sso_callback_template.html from keystone-etc (ro,path="sso_callback_template.html") /etc/ssl/certs/ca-certificates.crt from ca-certificates (ro) /tmp from pod-tmp (rw) /tmp/keystone-api.sh from keystone-bin (ro,path="keystone-api.sh") /var/lib/apache2/oidc/keycloak.199-204-45-156.nip.io%2Frealms%2Fatmosphere.client from keystone-openid-metadata (rw,path="atmosphere-oidc-client") /var/lib/apache2/oidc/keycloak.199-204-45-156.nip.io%2Frealms%2Fatmosphere.conf from keystone-openid-metadata (rw,path="atmosphere-oidc-conf") /var/lib/apache2/oidc/keycloak.199-204-45-156.nip.io%2Frealms%2Fatmosphere.provider from keystone-openid-metadata (rw,path="atmosphere-oidc-provider") /var/log/apache2 from logs-apache (rw) /var/run/apache2 from run-apache (rw) /var/www/cgi-bin/keystone from wsgi-keystone (rw) Volumes: pod-tmp: Type: EmptyDir (a temporary directory that shares a pod's lifetime) Medium: SizeLimit: etckeystone: Type: EmptyDir (a temporary directory that shares a pod's lifetime) Medium: SizeLimit: wsgi-keystone: Type: EmptyDir (a temporary directory that shares a pod's lifetime) Medium: SizeLimit: logs-apache: Type: EmptyDir (a temporary directory that shares a pod's lifetime) Medium: SizeLimit: run-apache: Type: EmptyDir (a temporary directory that shares a pod's lifetime) Medium: SizeLimit: keystone-etc: Type: Secret (a volume populated by a Secret) SecretName: keystone-etc Optional: false keystone-bin: Type: ConfigMap (a volume populated by a ConfigMap) Name: keystone-bin Optional: false keystone-fernet-keys: Type: Secret (a volume populated by a Secret) SecretName: keystone-fernet-keys Optional: false keystone-credential-keys: Type: Secret (a volume populated by a Secret) SecretName: keystone-credential-keys Optional: false keystone-openid-metadata: Type: ConfigMap (a volume populated by a ConfigMap) Name: keystone-openid-metadata Optional: false ca-certificates: Type: HostPath (bare host directory volume) Path: /etc/ssl/certs/ca-certificates.crt HostPathType: Conditions: Type Status Reason ---- ------ ------ Available True MinimumReplicasAvailable Progressing True NewReplicaSetAvailable OldReplicaSets: NewReplicaSet: keystone-api-f8996f4f4 (1/1 replicas created) Events: Type Reason Age From Message ---- ------ ---- ---- ------- Normal ScalingReplicaSet 6m32s deployment-controller Scaled up replica set keystone-api-f8996f4f4 to 1