OpenStack与Pulumi集成异常:YAML含DomainName仍认证失败
解决Pulumi部署OpenStack实例时的Domain认证错误
问题重现
部署代码:
import pulumi from pulumi_openstack import compute instance = compute.Instance('VMTEST', flavor_id='small', image_name='image-in-openstack')
配置文件(Pulumi.yaml):
config: openstack:authUrl: https://10.1.1.10:5000/v3/auth openstack:domainName: Customer001 openstack:userName: user001 openstack:password: secure: AAAB********** OMISSIS ***********eTrT openstack:insecure: true pulumi:template: openstack-python
报错信息:
openstack:compute:Instance (test): error: 1 error occurred: * Error creating OpenStack compute client: You must provide exactly one of DomainID or DomainName to authenticate by Username
可能的解决方案
1. 修正配置参数的命名格式
Pulumi的OpenStack Provider底层沿用Terraform的参数命名规则,需使用蛇形小写格式(snake_case)而非驼峰式。将配置中的参数名称修改为:
config: openstack:auth_url: https://10.1.1.10:5000/v3/auth openstack:domain_name: Customer001 openstack:user_name: user001 openstack:password: secure: AAAB********** OMISSIS ***********eTrT openstack:insecure: true pulumi:template: openstack-python
2. 验证配置是否正确加载
通过命令行确认配置已被Pulumi读取:
pulumi config get openstack:domain_name pulumi config get openstack:user_name
若未返回对应值,检查配置文件是否在项目根目录,或改用pulumi config set命令手动设置参数(推荐用命令行处理敏感配置,避免手动编辑YAML出错)。
3. 补充项目级域名配置(若环境要求)
如果你的OpenStack环境需要同时指定用户域和项目域,添加以下配置项:
config: # 保留原有配置... openstack:project_domain_name: Customer001 openstack:project_name: 你的项目名称
4. 检查认证端点路径
确认auth_url格式是否正确,标准v3认证端点应为https://<认证地址>:5000/v3,移除末尾的/auth后缀,部分环境会因路径错误导致认证失败。
内容的提问来源于stack exchange,提问作者mejdanek
相关产品推荐
相关产品推荐

