You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Juju添加DevStack部署的OpenStack云时无法验证Keystone端点

Juju添加DevStack OpenStack云端点校验失败解决

问题现象

使用DevStack部署OpenStack后,执行juju add-cloud交互式添加OpenStack云时,输入所有可能的Keystone端点地址均返回Can't validate endpoint: No Openstack server running报错。
已完成的前置验证:

  • curl可正常访问Keystone端点获取版本信息
  • nc测试5000端口连通性正常
  • 已配置no_proxy环境变量排除代理影响
  • 同节点上OpenStack-Ansible部署的标准路径OpenStack云可正常添加,该DevStack环境Keystone带/identity路径前缀

相关配置参考:

DevStack local.conf核心配置

$ cat local.conf | grep -v "#" | grep -v "^$"
[[local|localrc]]
ADMIN_PASSWORD=admin
DATABASE_PASSWORD=$ADMIN_PASSWORD
RABBIT_PASSWORD=$ADMIN_PASSWORD
SERVICE_PASSWORD=$ADMIN_PASSWORD
HOST_IP=172.29.21.181
FLOATING_RANGE=172.29.20.1/22
Q_FLOATING_ALLOCATION_POOL=start=172.29.21.182,end=172.29.21.184
PUBLIC_NETWORK_GATEWAY=172.29.21.181
ENABLED_SERVICES+=,tls-proxy
ENABLED_SERVICES+=,g-api,g-reg
LOGFILE=$DEST/logs/stack.sh.log
LOGDAYS=2
SWIFT_HASH=66a3d6b56c1f479c8b4e70ab5c2000f5
SWIFT_REPLICAS=1
SWIFT_DATA_DIR=$DEST/data

OpenStack服务端点列表

$ openstack endpoint list
+----------------------------------+-----------+--------------+----------------+---------+-----------+-------------------------------------------------+
| ID                               | Region    | Service Name | Service Type   | Enabled | Interface | URL                                             |
+----------------------------------+-----------+--------------+----------------+---------+-----------+-------------------------------------------------+
| 0b489b8a683d4be489448230437e39ca | RegionOne | cinder       | block-storage  | True    | public    | https://172.29.21.181/volume/v3/$(project_id)s  |
| 0b9e96cfe0b440b781171ac0b082de3a | RegionOne | keystone     | identity       | True    | admin     | https://172.29.21.181/identity                  |
| 29ce5b2061dd474492f3aebda164acd0 | RegionOne | cinderv2     | volumev2       | True    | public    | https://172.29.21.181/volume/v2/$(project_id)s  |
| 45e10e75eb6848f5a934674373962e11 | RegionOne | glance       | image          | True    | public    | https://172.29.21.181/image                     |
| 8c35460b8c0d4c21ac9b7dd27bc92c48 | RegionOne | keystone     | identity       | True    | public    | https://172.29.21.181/identity                  |
| af451150c3094497936fd6877380d877 | RegionOne | placement    | placement      | True    | public    | https://172.29.21.181/placement                 |
| b3907f627f684ada8526b89c2c9683f9 | RegionOne | neutron      | network        | True    | public    | https://172.29.21.181:9696/                     |
| c642b07700b54be39e1dd537e8c0f8be | RegionOne | nova         | compute        | True    | public    | https://172.29.21.181/compute/v2.1              |
| dbb94215bc89457383a390a0490a89f6 | RegionOne | nova_legacy  | compute_legacy | True    | public    | https://172.29.21.181/compute/v2/$(project_id)s |
| e1037ed336d541b080e365caa0020e78 | RegionOne | cinderv3     | volumev3       | True    | public    | https://172.29.21.181/volume/v3/$(project_id)s  |
+----------------------------------+-----------+--------------+----------------+---------+-----------+-------------------------------------------------+

交互式添加报错信息

$ juju add-cloud openstack
This operation can be applied to both a copy on this client and to the one on a controller.
No current controller was detected and there are no registered controllers on this client: either bootstrap one or register one.
Cloud Types
  lxd
  maas
  manual
  openstack
  vsphere

Select cloud type: openstack

Enter the API endpoint url for the cloud [https://172.29.21.181/identity]: https://172.29.21.181/identity
Can't validate endpoint: No Openstack server running at https://172.29.21.181/identity

Enter the API endpoint url for the cloud [https://172.29.21.181/identity]: https://172.29.21.181/identity/v3
Can't validate endpoint: No Openstack server running at https://172.29.21.181/identity/v3

Enter the API endpoint url for the cloud [https://172.29.21.181/identity]: http://172.29.21.181/identity
Can't validate endpoint: No Openstack server running at http://172.29.21.181/identity

Enter the API endpoint url for the cloud [https://172.29.21.181/identity]: https://172.29.21.181:5000/v3
Can't validate endpoint: No Openstack server running at https://172.29.21.181:5000/v3

根因说明

报错来自两个叠加问题:

  1. Juju交互式添加时的端点探测逻辑是为标准OpenStack部署设计的,默认预期Keystone v3端点直接暴露在/v3路径下,对DevStack启用tls-proxy后带的/identity路径前缀适配有问题,会出现路径拼接错误
  2. DevStack启用tls-proxy时使用自签TLS证书,Juju基于Go语言实现的HTTP客户端默认严格校验证书信任链,自签证书不被信任时会直接中断连接,返回泛化的"服务不存在"报错,不会明确提示证书错误;curl能正常访问是因为curl对TLS错误的容忍度更高,返回结果时才会提示证书问题,不会直接断开连接

解决步骤

  • 跳过交互式添加流程,手动编写云配置文件绕过错误的探测逻辑。新建~/devstack-juju-cloud.yaml,写入以下配置:
    clouds:
      devstack:
        type: openstack
        auth-types: [userpass]
        endpoint: https://172.29.21.181/identity/v3
        insecure: true
        regions:
          RegionOne:
            endpoint: https://172.29.21.181/identity/v3
    
    配置中insecure: true用于跳过TLS证书校验,适配DevStack自签证书场景。
  • 执行命令从本地配置文件导入云定义,跳过交互式校验:
    juju add-cloud --client -f ~/devstack-juju-cloud.yaml devstack
    
    加--client参数是因为当前未引导任何控制器,配置直接保存在本地客户端即可。
  • 导入完成后执行juju clouds确认devstack云出现在列表中,后续通过juju add-credential devstack填入OpenStack账号信息(DevStack默认用户域、项目域均为Default),即可正常执行bootstrap操作。

补充排查项

如果上述操作后仍报错,按以下顺序检查:

  • 确认Juju版本≥2.9.0,2.8及更早版本不支持带路径前缀的Keystone端点,会强制拼接端口和路径导致访问失败
  • 临时取消所有代理环境变量再执行操作:unset HTTP_PROXY HTTPS_PROXY http_proxy https_proxy,Go语言的代理逻辑对no_proxy的CIDR、单IP配置存在已知兼容问题,直接取消代理最稳妥
  • 检查DevStack主机的防火墙规则,确认放行了172.29.21.181地址上5000、8774、9696等OpenStack服务端口的入方向访问

内容的提问来源于stack exchange,提问作者Silviu Sofrone

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.02 01:30:27