Name: keystone-api Namespace: openstack CreationTimestamp: Sat, 25 Apr 2026 09:38:14 +0000 Labels: app.kubernetes.io/managed-by=Helm application=keystone component=api release_group=keystone Annotations: deployment.kubernetes.io/revision: 1 meta.helm.sh/release-name: keystone meta.helm.sh/release-namespace: openstack openstackhelm.openstack.org/release_uuid: Selector: application=keystone,component=api,release_group=keystone Replicas: 1 desired | 1 updated | 1 total | 1 available | 0 unavailable StrategyType: RollingUpdate MinReadySeconds: 0 RollingUpdateStrategy: 1 max unavailable, 3 max surge Pod Template: Labels: application=keystone component=api release_group=keystone Annotations: configmap-bin-hash: 0fa826d4d7a09702781edd1dea99271bec84830f0fb47c323ca6697719e1dc71 configmap-etc-hash: 25277531cca2d1203618c09ba60dfd82197736133a7789e2e05df619abbcbfec openstackhelm.openstack.org/release_uuid: Service Account: keystone-api Init Containers: init: Image: harbor.atmosphere.dev/ghcr.io/vexxhost/kubernetes-entrypoint:edge Port: Host Port: Command: kubernetes-entrypoint Environment: POD_NAME: (v1:metadata.name) NAMESPACE: (v1:metadata.namespace) INTERFACE_NAME: eth0 PATH: /usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/ DEPENDENCY_SERVICE: openstack:memcached,openstack:percona-xtradb-haproxy DEPENDENCY_JOBS: keystone-db-sync,keystone-credential-setup,keystone-fernet-setup DEPENDENCY_DAEMONSET: DEPENDENCY_CONTAINER: DEPENDENCY_POD_JSON: DEPENDENCY_CUSTOM_RESOURCE: Mounts: Containers: keystone-api: Image: harbor.atmosphere.dev/ghcr.io/vexxhost/keystone:main@sha256:d82122679914bcf9121e951e754da7f4c93cb02c79414694547aa6314530cddb Port: 5000/TCP Host Port: 0/TCP Command: /tmp/keystone-api.sh start Liveness: http-get http://:5000/v3/ delay=50s timeout=15s period=60s #success=1 #failure=3 Readiness: http-get http://:5000/v3/ delay=15s timeout=15s period=60s #success=1 #failure=3 Environment: Mounts: /etc/apache2/conf-enabled/security.conf from keystone-etc (ro,path="security.conf") /etc/apache2/conf-enabled/wsgi-keystone.conf from keystone-etc (ro,path="wsgi-keystone.conf") /etc/apache2/mods-available/mpm_event.conf from keystone-etc (ro,path="mpm_event.conf") /etc/apache2/ports.conf from keystone-etc (ro,path="ports.conf") /etc/keystone from etckeystone (rw) /etc/keystone/access_rules.json from keystone-etc (ro,path="access_rules.json") /etc/keystone/credential-keys/ from keystone-credential-keys (rw) /etc/keystone/domains/keystone.atmosphere.conf from keystone-etc (ro,path="keystone.atmosphere.conf") /etc/keystone/fernet-keys/ from keystone-fernet-keys (rw) /etc/keystone/keystone.conf from keystone-etc (ro,path="keystone.conf") /etc/keystone/policy.yaml from keystone-etc (ro,path="policy.yaml") /etc/keystone/sso_callback_template.html from keystone-etc (ro,path="sso_callback_template.html") /etc/ssl/certs/ca-certificates.crt from ca-certificates (ro) /tmp from pod-tmp (rw) /tmp/keystone-api.sh from keystone-bin (ro,path="keystone-api.sh") /var/lib/apache2/oidc/keycloak.199-204-45-109.nip.io%2Frealms%2Fatmosphere.client from keystone-openid-metadata (rw,path="atmosphere-oidc-client") /var/lib/apache2/oidc/keycloak.199-204-45-109.nip.io%2Frealms%2Fatmosphere.conf from keystone-openid-metadata (rw,path="atmosphere-oidc-conf") /var/lib/apache2/oidc/keycloak.199-204-45-109.nip.io%2Frealms%2Fatmosphere.provider from keystone-openid-metadata (rw,path="atmosphere-oidc-provider") /var/log/apache2 from logs-apache (rw) /var/run/apache2 from run-apache (rw) /var/www/cgi-bin/keystone from wsgi-keystone (rw) Volumes: pod-tmp: Type: EmptyDir (a temporary directory that shares a pod's lifetime) Medium: SizeLimit: etckeystone: Type: EmptyDir (a temporary directory that shares a pod's lifetime) Medium: SizeLimit: wsgi-keystone: Type: EmptyDir (a temporary directory that shares a pod's lifetime) Medium: SizeLimit: logs-apache: Type: EmptyDir (a temporary directory that shares a pod's lifetime) Medium: SizeLimit: run-apache: Type: EmptyDir (a temporary directory that shares a pod's lifetime) Medium: SizeLimit: keystone-etc: Type: Secret (a volume populated by a Secret) SecretName: keystone-etc Optional: false keystone-bin: Type: ConfigMap (a volume populated by a ConfigMap) Name: keystone-bin Optional: false keystone-fernet-keys: Type: Secret (a volume populated by a Secret) SecretName: keystone-fernet-keys Optional: false keystone-credential-keys: Type: Secret (a volume populated by a Secret) SecretName: keystone-credential-keys Optional: false keystone-openid-metadata: Type: ConfigMap (a volume populated by a ConfigMap) Name: keystone-openid-metadata Optional: false ca-certificates: Type: HostPath (bare host directory volume) Path: /etc/ssl/certs/ca-certificates.crt HostPathType: Conditions: Type Status Reason ---- ------ ------ Available True MinimumReplicasAvailable Progressing True NewReplicaSetAvailable OldReplicaSets: NewReplicaSet: keystone-api-688cb87dc4 (1/1 replicas created) Events: Type Reason Age From Message ---- ------ ---- ---- ------- Normal ScalingReplicaSet 7m24s deployment-controller Scaled up replica set keystone-api-688cb87dc4 to 1