Jump to: navigation, search

Difference between revisions of "UnifiedCLI/Mapping"

(ec2-credentials)
(Redirected page to OpenStackClient/Commands)
 
(46 intermediate revisions by 2 users not shown)
Line 1: Line 1:
 +
#REDIRECT [[OpenStackClient/Commands]]
 +
 +
'''''Note: this page is being deprecated in favor of a new [[OpenStackClient/Commands|OpenStackClient Commands]] page with the correct name.'''''
 +
 
__TOC__
 
__TOC__
  
Line 15: Line 19:
 
  <code>openstack [<global-options>] <object> <verb> [<second-object>] [<command-local-arguments>]</code>
 
  <code>openstack [<global-options>] <object> <verb> [<second-object>] [<command-local-arguments>]</code>
 
'''''Note: The command format change was committed on 13May2013.  This is the new format.'''''
 
'''''Note: The command format change was committed on 13May2013.  This is the new format.'''''
 +
  
 
== Command Arguments ==
 
== Command Arguments ==
Line 25: Line 30:
 
   * <object-1> <verb> <object-2>
 
   * <object-1> <verb> <object-2>
 
     * group add user
 
     * group add user
     * compute service list  (here, 'access token' is a two-work single object)
+
     * access token list  (here, 'access token' is a two-word single object)
 
     * user list role (needs more thinking)
 
     * user list role (needs more thinking)
 +
 +
== Other ==
 +
 +
* Arguments that normally require an ID in the OS-API may also use the name or other short identifier where reasonable to support
 +
* Optional machine-parsable format is available with list and show commands.  List has an option for CSV-formatted output (see --format, --quote options for a list command) while show has an option for shell-assignment formatted output (see --format option for a show command).
  
 
== Verbs ==
 
== Verbs ==
Line 57: Line 67:
 
* <code><nowiki>unrescue</nowiki></code> (<code><nowiki>rescue</nowiki></code>) - return a server to normal boot mode
 
* <code><nowiki>unrescue</nowiki></code> (<code><nowiki>rescue</nowiki></code>) - return a server to normal boot mode
 
* <code><nowiki>unset</nowiki></code> (<code><nowiki>set</nowiki></code>) - remove an attribute of the object
 
* <code><nowiki>unset</nowiki></code> (<code><nowiki>set</nowiki></code>) - remove an attribute of the object
 +
  
 
== Objects ==
 
== Objects ==
Line 105: Line 116:
 
* <code>volume</code> - [[#Volume|Volume]] - [[#volume|volume]]
 
* <code>volume</code> - [[#Volume|Volume]] - [[#volume|volume]]
 
* <code>volume-type</code> - [[#Volume|Volume]] - [[#volume-type|volume-type]]
 
* <code>volume-type</code> - [[#Volume|Volume]] - [[#volume-type|volume-type]]
 +
  
 
== Global Options ==
 
== Global Options ==
Line 144: Line 156:
 
| --os-use-keyring ||  || ||  ||
 
| --os-use-keyring ||  || ||  ||
 
|}
 
|}
 +
  
 
== Common Options ==
 
== Common Options ==
Line 159: Line 172:
 
| --disable || Used for setting the enabled state for an object || n/a
 
| --disable || Used for setting the enabled state for an object || n/a
 
|}
 
|}
 +
  
 
= Command Mapping Summary =
 
= Command Mapping Summary =
Line 177: Line 191:
  
  
== Identity ==
+
== Cross API ==
  
 +
Object names that appear in multiple APIs, like quota, are handled by putting their command handler classes in openstackclient.common.  If the number of these becomes large they should be moved into a subdirectory.
  
{| class="wikitable"
+
==== credentials ====
|-
 
! OSC Option !!  Environment Variable !!  !!  Keystone Option !!  Environment Variable
 
|-
 
| --os-identity-api-version <ver> || OS_IDENTITY_API_VERSION ||  || --os-identity-api-version <ver> || OS_IDENTITY_API_VERSION
 
|-
 
| --os-token <token> || OS_TOKEN || || --os-token <token> || OS_SERVICE_TOKEN
 
|-
 
| --os-url <url> || OS_URL || || --os-endpoint <url> || OS_SERVICE_ENDPOINT
 
|-
 
|  ||  || || --os-cert <file> || OS_CERT
 
|-
 
|  ||  || || --os-key <key-file> || OS_KEY
 
|-
 
|  ||  || || --os-cache || OS_CACHE
 
|-
 
|  ||  || || --force-new-token ||
 
|-
 
|  ||  || || --stale-duration <seconds> ||
 
|-
 
|}
 
 
 
 
 
=== API v2.0 ===
 
  
==== catalog ====
+
''[consider rolling the ec2 creds into this too]''
  
 
{| class="wikitable"
 
{| class="wikitable"
Line 213: Line 205:
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os catalog show
+
os credentials create
     [--service <service>]
+
    --x509
 +
     [<private-key-file>]
 +
    [<certificate-file>]
 
</source>
 
</source>
 
|| no
 
|| no
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone catalog
+
nova x509-create-cert
     [--service <service-type>]
+
     [<pk-file>]
 +
    [<x509-cert>]
 +
</source>
 +
|-
 +
|
 +
<source lang="bash">
 +
os credentials show
 +
    [--token]
 +
    [--user]
 +
    [--x509 [--root]]
 +
</source>
 +
|| no
 +
|| ||
 +
<source lang="bash">
 +
nova credentials
 +
    [--wrap <integer>]
 +
 
 +
nova x509-get-root-cert
 +
    [<filename>]
 
</source>
 
</source>
 
|}
 
|}
  
==== ec2-credentials ====
+
==== limits ====
  
 
{| class="wikitable"
 
{| class="wikitable"
Line 232: Line 244:
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os ec2 credentials create
+
os limits show
     [--project <project>]
+
     --absolute [--reserved] | --rate
    [--user <user>]
 
 
</source>
 
</source>
|| in progress
+
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone ec2-credentials-create
+
nova absolute-limits
     [--user <user-id>]  
+
     [--reserved]
    [--tenant_id <tenant-id>]
+
 
 +
nova rate-limits
 +
 
 +
cinder absolute-limits
 +
 
 +
cinder rate-limits
 
</source>
 
</source>
 +
|}
 +
 +
==== quota ====
 +
 +
{| class="wikitable"
 
|-
 
|-
 +
! OSC Command !! Implemented !! !! Keystone command
 +
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os ec2 credentials delete
+
os quota set
     [--user <user>]
+
    # Compute settings
     <access-key>
+
    [--cores <num-cores>]
 +
    [--fixed-ips <num-fixed-ips>]
 +
     [--floating-ips <num-floating-ips>]
 +
     [--injected-file-size <injected-file-bytes>]
 +
    [--injected-files <num-injected-files>]
 +
    [--instances <num-instances>]
 +
    [--key-pairs <num-key-pairs>]
 +
    [--properties <num-properties>]
 +
    [--ram <ram-mb>]
 +
 
 +
    # Volume settings
 +
    [--gigabytes <new-gigabytes>]
 +
    [--snapshots <new-snapshots>]
 +
    [--volumes <new-volumes>]
 +
 
 +
    <project>
 
</source>
 
</source>
|| in progress
+
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone ec2-credentials-delete
+
nova quota-update
     [--user <user-id>]  
+
    [--instances <instances>]
     --access <access-key>
+
    [--cores <cores>]
 +
    [--ram <ram>]
 +
    [--volumes <volumes>]
 +
    [--gigabytes <gigabytes>]
 +
    [--floating-ips <floating_ips>]
 +
    [--metadata-items <metadata_items>]
 +
    [--injected-files <injected_files>]
 +
     [--injected-file-content-bytes <injected_file_content_bytes>]
 +
    <tenant_id>
 +
 
 +
cinder quota-update
 +
    [--volumes <volumes>]
 +
     [--snapshots <snapshots>]
 +
    [--gigabytes <gigabytes>]
 +
    <tenant_id>
 
</source>
 
</source>
|-
+
|-  
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os ec2 credentials list
+
os quota set
     [--user <user>]
+
    --class
 +
    # Compute settings
 +
    [--cores <num-cores>]
 +
    [--fixed-ips <num-fixed-ips>]
 +
     [--floating-ips <num-floating-ips>]
 +
    [--injected-file-size <injected-file-bytes>]
 +
    [--injected-files <num-injected-files>]
 +
    [--instances <num-instances>]
 +
    [--key-pairs <num-key-pairs>]
 +
    [--properties <num-properties>]
 +
    [--ram <ram-mb>]
 +
 
 +
    # Volume settings
 +
    [--gigabytes <new-gigabytes>]
 +
    [--snapshots <new-snapshots>]
 +
    [--volumes <new-volumes>]
 +
 
 +
    <class>
 
</source>
 
</source>
|| in progress
+
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone ec2-credentials-list
+
nova quota-class-update
     [--user <user-id>]
+
     [--instances <instances>]
</source>
+
    [--cores <cores>]
 +
    [--ram <ram>]
 +
    [--volumes <volumes>]
 +
    [--gigabytes <gigabytes>]
 +
    [--floating-ips <floating_ips>]
 +
    [--metadata-items <metadata_items>]
 +
    [--injected-files <injected_files>]
 +
    [--injected-file-content-bytes <injected_file_content_bytes>]
 +
    <class>
 +
 
 +
cinder quota-class-update
 +
    [--volumes <volumes>]
 +
    [--snapshots <snapshots>]
 +
    [--gigabytes <gigabytes>]
 +
    <tenant_id>
 +
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os ec2 credentials show
+
os quota show
     [--user <user>]
+
     [--default]
     <access-key>
+
     <project>
 
</source>
 
</source>
|| in progress
+
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone ec2-credentials-get
+
nova quota-show
     [--user <user-id>]  
+
     [--tenant <tenant-id>]
    --access <access-key>
+
 
</source>
+
cinder quota-show
|}
+
    <tenant_id>
  
==== endpoint ====
+
nova quota-defaults
 +
    <tenant_id>
  
{| class="wikitable"
+
cinder quota-defaults
|-
+
    <tenant_id>
! OSC Command !! Implemented !! !! Keystone command
+
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os endpoint create
+
os quota show
     --publicurl <public-url>
+
     --class
    [--adminurl <admin-url>]
+
     <class>
    [--internalurl <internal-url>]
 
    [--region <endpoint-region>]
 
     <service>
 
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone endpoint-create
+
nova quota-class-show
    [--region <endpoint-region>]
+
     <class>
    [--service_id <service-id>]
+
 
    [--publicurl <public-url>]
+
cinder quota-class-show
    [--adminurl <admin-url>]
+
     <class>
     [--internalurl <internal-url>]
 
</source>
 
|-
 
|
 
<source lang="bash">
 
os endpoint delete
 
    <endpoint-id>
 
</source>
 
|| yes
 
|| ||
 
<source lang="bash">
 
keystone endpoint-delete
 
     <endpoint-id>
 
 
</source>
 
</source>
 +
|}
 +
 +
== Identity ==
 +
 +
{| class="wikitable"
 +
|-
 +
! OSC Option !!  Environment Variable !!  !!  Keystone Option !!  Environment Variable
 +
|-
 +
| --os-identity-api-version <ver> || OS_IDENTITY_API_VERSION ||  || --os-identity-api-version <ver> || OS_IDENTITY_API_VERSION
 +
|-
 +
| --os-token <token> || OS_TOKEN || || --os-token <token> || OS_SERVICE_TOKEN
 +
|-
 +
| --os-url <url> || OS_URL || || --os-endpoint <url> || OS_SERVICE_ENDPOINT
 +
|-
 +
|  ||  || || --os-cert <file> || OS_CERT
 +
|-
 +
|  ||  || || --os-key <key-file> || OS_KEY
 +
|-
 +
|  ||  || || --os-cache || OS_CACHE
 +
|-
 +
|  ||  || || --force-new-token ||
 +
|-
 +
|  ||  || || --stale-duration <seconds> ||
 +
|-
 +
|}
 +
 +
=== API v2.0 ===
 +
 +
==== catalog ====
 +
 +
{| class="wikitable"
 +
|-
 +
! OSC Command !! Implemented !! !! Keystone command
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os endpoint list
+
os catalog show
     [--long]
+
     [--service <service>]
 
</source>
 
</source>
|| yes
+
|| no
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone endpoint-list
+
keystone catalog
 +
    [--service <service-type>]
 
</source>
 
</source>
 +
|}
 +
 +
==== ec2 credentials ====
 +
 +
{| class="wikitable"
 +
|-
 +
! OSC Command !! Implemented !! !! Keystone command
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os endpoint show
+
os ec2 credentials create
     [--type <endpoint-type>]
+
     [--project <project>]
     [--attr <endpoint-attribute>]
+
     [--user <user>]
    [--value <endpoint-value>]
 
    [--all]
 
    <service-type>
 
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone endpoint-get
+
keystone ec2-credentials-create
    --service <service-type>
+
     [--user <user-id>]  
     [--endpoint_type <endpoint-type>]
+
     [--tenant_id <tenant-id>]
     [--attr <service-attribute>]
 
    [--value <value>]
 
 
</source>
 
</source>
|}
 
 
==== role ====
 
 
{| class="wikitable"
 
|-
 
! OSC Command !! Implemented !! !! Keystone command
 
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os role create
+
os ec2 credentials delete
     <role-name>
+
    [--user <user>]
 +
     <access-key>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone role-create --name
+
keystone ec2-credentials-delete
     <role-name>
+
    [--user <user-id>]
 +
     --access <access-key>
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os role delete
+
os ec2 credentials list
     <role>
+
     [--user <user>]
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone role-delete
+
keystone ec2-credentials-list
     <role-id>
+
     [--user <user-id>]
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os role list
+
os ec2 credentials show
 +
    [--user <user>]
 +
    <access-key>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone role-list
+
keystone ec2-credentials-get
</source>
+
    [--user <user-id>]
|-
+
     --access <access-key>
|
 
<source lang="bash">
 
os role show
 
     <role>
 
</source>
 
|| yes
 
|| ||
 
<source lang="bash">
 
keystone role-get
 
    <role-id>
 
 
</source>
 
</source>
 
|}
 
|}
  
==== service ====
+
==== endpoint ====
  
 
{| class="wikitable"
 
{| class="wikitable"
Line 415: Line 507:
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os service create
+
os endpoint create
     [--type <service-type>]
+
    --publicurl <public-url>
     [--description <service-description>]
+
    [--adminurl <admin-url>]
     <service-name>
+
     [--internalurl <internal-url>]
 +
     [--region <endpoint-region>]
 +
     <service>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone service-create
+
keystone endpoint-create
     --name <name>  
+
    [--region <endpoint-region>]
     --type <type>
+
    [--service_id <service-id>]
     [--description <service-description>]
+
     [--publicurl <public-url>]
 +
     [--adminurl <admin-url>]
 +
     [--internalurl <internal-url>]
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os service delete
+
os endpoint delete
     <service>
+
     <endpoint-id>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone service-delete
+
keystone endpoint-delete
     <service-id>
+
     <endpoint-id>
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os service list
+
os endpoint list
 
     [--long]
 
     [--long]
 
</source>
 
</source>
Line 449: Line 545:
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone service-list
+
keystone endpoint-list
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os service show
+
os endpoint show
     <service>
+
    [--type <endpoint-type>]
 +
    [--attr <endpoint-attribute>]
 +
    [--value <endpoint-value>]
 +
    [--all]
 +
     <service-type>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone service-get
+
keystone endpoint-get
     <service-id>
+
    --service <service-type>
 +
    [--endpoint_type <endpoint-type>]
 +
     [--attr <service-attribute>]
 +
    [--value <value>]
 
</source>
 
</source>
 
|}
 
|}
  
==== tenant ====
+
==== role ====
  
 
{| class="wikitable"
 
{| class="wikitable"
Line 473: Line 576:
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os tenant create
+
os role create
     [--description <description>]
+
     <role-name>
    [--enable | --disable]
 
    <tenant-name>
 
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone tenant-create
+
keystone role-create --name
    --name <tenant-name>
+
     <role-name>
     [--description <tenant-description>]
+
</source>
    [--enabled <true|false>]
 
</source>
 
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os tenant delete
+
os role delete
     <tenant>
+
     <role>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone tenant-delete
+
keystone role-delete
     <tenant>
+
     <role-id>
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os tenant list
+
os role list
    [--long]
 
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone tenant-list
+
keystone role-list
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os tenant set
+
os role show
     [--name <new-tenant-name>]
+
     <role>
    [--description <new-tenant-description>]
 
    [--enable | --disable]
 
    <tenant>
 
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone tenant-update
+
keystone role-get
    [--name <tenant_name>]
+
     <role-id>
    [--description <tenant-description>]
 
    [--enabled <true|false>]
 
     <tenant-id>
 
 
</source>
 
</source>
 +
|}
 +
 +
==== service ====
 +
 +
{| class="wikitable"
 +
|-
 +
! OSC Command !! Implemented !! !! Keystone command
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os tenant show
+
os service create
     <tenant>
+
     [--type <service-type>]
 +
    [--description <service-description>]
 +
    <service-name>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone tenant-get
+
keystone service-create
     <tenant-id>
+
     --name <name>
 +
    --type <type>
 +
    [--description <service-description>]
 
</source>
 
</source>
|}
 
 
==== token ====
 
 
{| class="wikitable"
 
|-
 
! OSC Command !! Implemented !! !! Keystone command
 
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os token show
+
os service delete
     [--width <token-display-width>]
+
     <service>
 
</source>
 
</source>
|| ??
+
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone token-get [--wrap <integer>]
+
keystone service-delete
 +
    <service-id>
 
</source>
 
</source>
|}
 
 
==== user ====
 
 
{| class="wikitable"
 
|-
 
! OSC Command !! Implemented !! !! Keystone command
 
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os user create
+
os service list
     [--password <user-password>]
+
     [--long]
    [--email <user-email>]
 
    [--tenant <tenant>]
 
    [--enable | --disable]
 
    <user-name>
 
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone user-create
+
keystone service-list
    --name <user-name>
 
    [--tenant_id <tenant-id>]
 
    [--pass <pass>]
 
    [--email <email>]
 
    [--enabled <true|false>]
 
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os user delete
+
os service show
     <user>
+
    [--catalog]
 +
     <service>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone user-delete
+
keystone service-get
     <user-id>
+
     <service-id>
 
</source>
 
</source>
 +
|}
 +
 +
==== tenant ====
 +
 +
{| class="wikitable"
 +
|-
 +
! OSC Command !! Implemented !! !! Keystone command
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os user list
+
os tenant create
     [--tenant <tenant>]
+
     [--description <description>]
     [--long]
+
     [--enable | --disable]
 +
    <tenant-name>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone user-list
+
keystone tenant-create
     [<tenant-id>]
+
    --name <tenant-name>
 +
     [--description <tenant-description>]
 +
    [--enabled <true|false>]
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os user set
+
os tenant delete
    [--name <new-user-name>]
+
     <tenant>
    [--password <user-password>]
+
</source>
    [--email <user-email>]
 
     [--tenant <tenant>]
 
    [--enable|--disable]
 
    <user>
 
</source>
 
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone user-password-update
+
keystone tenant-delete
     --pass <password>
+
     <tenant>
    <user-id>
 
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os user show
+
os tenant list
     <user>
+
     [--long]
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone user-get
+
keystone tenant-list
    <user-id>
 
 
</source>
 
</source>
|}
 
 
==== user role ====
 
 
{| class="wikitable"
 
|-
 
! OSC Command !! Implemented !! !! Keystone command
 
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os user role add
+
os tenant set
     [--tenant <tenant>]
+
     [--name <new-tenant-name>]
     <user>
+
     [--description <new-tenant-description>]
     <role>
+
    [--enable | --disable]
 +
     <tenant>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone user-role-add
+
keystone tenant-update
     --user <user-id>
+
     [--name <tenant_name>]
     --role <role-id>
+
     [--description <tenant-description>]
     [--tenant_id <tenant-id>]
+
     [--enabled <true|false>]
 +
    <tenant-id>
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os user role list
+
os tenant show
     [--tenant <tenant>]
+
     <tenant>
    [<user>]
 
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone user-role-list
+
keystone tenant-get
    [--user <user-id>]
+
     <tenant-id>
     [--tenant_id <tenant-id>]
 
 
</source>
 
</source>
 +
|}
 +
 +
==== token ====
 +
 +
{| class="wikitable"
 +
|-
 +
! OSC Command !! Implemented !! !! Keystone command
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os user role remove
+
os token show
     [--tenant <tenant>]
+
     [--width <token-display-width>]
    <user>
 
    <role>
 
 
</source>
 
</source>
|| yes
+
|| ??
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone user-role-remove
+
keystone token-get [--wrap <integer>]
    --user <user-id>
 
    --role <role-id>
 
    [--tenant_id <tenant-id>]
 
 
</source>
 
</source>
 
|}
 
|}
  
====<other>====
+
==== user ====
  
 +
{| class="wikitable"
 +
|-
 +
! OSC Command !! Implemented !! !! Keystone command
 +
|-
 +
|
 
<source lang="bash">
 
<source lang="bash">
keystone bootstrap
+
os user create
        --pass <password>
+
    [--password <user-password>]
        [--user-name <user-name>]
+
    [--email <user-email>]
        [--role-name <role-name>]
+
    [--tenant <tenant>]
        [--tenant-name <tenant-name>]
+
    [--enable | --disable]
 
+
    <user-name>
## do not create in openstackclient, since it is in contribute
 
 
</source>
 
</source>
 
+
|| yes
 +
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone discover
+
keystone user-create
 
+
    --name <user-name>
## do not create in openstackclient, obsolete.
+
    [--tenant_id <tenant-id>]
 +
    [--pass <pass>]
 +
    [--email <email>]
 +
    [--enabled <true|false>]
 
</source>
 
</source>
 
=== API v3 ===
 
 
==== access token ====
 
 
{| class="wikitable"
 
|-
 
! OSC Command !! Implemented !! !! Keystone command
 
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os access token create
+
os user delete
     --consumer-key <consumer-key>
+
     <user>
    --consumer-secret <consumer-secret>
 
    --request-key <request-key>
 
    --request-secret <request-secret>
 
    --verifier <pin>
 
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
n/a
+
keystone user-delete
 +
    <user-id>
 
</source>
 
</source>
|}
 
 
==== credential ====
 
 
{| class="wikitable"
 
|-
 
! OSC Command !! Implemented !! !! Keystone command
 
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os credential create
+
os user list
     [--project <project>]
+
     [--tenant <tenant>]
     [--type ec2|cert]
+
     [--long]
    <user>
 
    <data>
 
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone credential-create
+
keystone user-list
    --user_id <user-id>
+
     [<tenant-id>]
    --type <credential-type>
 
    --data <credential-data>
 
     [--project_id <project-id>]
 
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os credential delete
+
os user set
     <credential-id>
+
     [--name <new-user-name>]
 +
    [--password <user-password>]
 +
    [--email <user-email>]
 +
    [--tenant <tenant>]
 +
    [--enable|--disable]
 +
    <user>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone credential-delete
+
keystone user-password-update
     <credential-id>
+
    --pass <password>
 +
     <user-id>
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os credential list
+
os user show
 +
    <user>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone credential-list
+
keystone user-get
 +
    <user-id>
 
</source>
 
</source>
 +
|}
 +
 +
==== user role ====
 +
 +
{| class="wikitable"
 +
|-
 +
! OSC Command !! Implemented !! !! Keystone command
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os credential set
+
os user role add
    [--user <user>]
+
     [--tenant <tenant>]
     [--type ec2|cert]
+
     <user>
    [--data <data>]
+
     <role>
     [--project <project>]
 
     <credential-id>
 
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone credential-update
+
keystone user-role-add
     [--user <user>]
+
     --user <user-id>
     [--type <type>]
+
     --role <role-id>
    [--data <data>]
+
     [--tenant_id <tenant-id>]
     [--project <project>]
 
    <credential-id>
 
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os credential show
+
os user role list
     <credential-id>
+
     [--tenant <tenant>]
 +
    [<user>]
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone credential-get
+
keystone user-role-list
     <credential-id>
+
    [--user <user-id>]
 +
    [--tenant_id <tenant-id>]
 +
</source>
 +
|-
 +
|
 +
<source lang="bash">
 +
os user role remove
 +
    [--tenant <tenant>]
 +
    <user>
 +
    <role>
 +
</source>
 +
|| yes
 +
|| ||
 +
<source lang="bash">
 +
keystone user-role-remove
 +
     --user <user-id>
 +
    --role <role-id>
 +
    [--tenant_id <tenant-id>]
 
</source>
 
</source>
 
|}
 
|}
  
==== domain ====
+
==== <other> ====
 +
 
 +
These keystone commands are not planned for re-implementation in OpenStackClient
 +
 
 +
<source lang="bash">
 +
keystone bootstrap
 +
        --pass <password>
 +
        [--user-name <user-name>]
 +
        [--role-name <role-name>]
 +
        [--tenant-name <tenant-name>]
 +
</source>
 +
 
 +
<source lang="bash">
 +
keystone discover
 +
</source>
 +
 
 +
=== API v3 ===
 +
 
 +
==== credential ====
  
 
{| class="wikitable"
 
{| class="wikitable"
Line 823: Line 935:
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os domain create
+
os credential create
     [--description <domain-description>]
+
     [--project <project>]
     [--enable | --disable]
+
     [--type ec2|cert]
     <domain-name>
+
     <user>
 +
    <data>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone domain-create
+
keystone credential-create
     --name <domain-name>
+
     --user_id <user-id>
     [--description <domain-description>]
+
     --type <credential-type>
     [--enabled <true|false>]
+
     --data <credential-data>
     [--private_project_names <true|false>]
+
     [--project_id <project-id>]
    [--private_user_names <true|false>]
 
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os domain delete
+
os credential delete
     <domain>
+
     <credential-id>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone domain-delete
+
keystone credential-delete
     <domain-id>
+
     <credential-id>
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os domain list
+
os credential list
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone domain-list
+
keystone credential-list
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os domain set
+
os credential set
     [--name <new-domain-name>]
+
     [--user <user>]
     [--description <new-domain-description>]
+
    [--type ec2|cert]
     [--enable | --disable]
+
     [--data <data>]
     <domain>
+
     [--project <project>]
 +
     <credential-id>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone domain-update
+
keystone credential-update
     [--name <domain_name>]
+
     [--user <user>]
     [--description <domain-description>]
+
     [--type <type>]
    [--enabled <true|false>]
+
     [--data <data>]
     [--private_project_names <true|false>]
+
     [--project <project>]
     [--private_user_names <true|false>]
+
     <credential-id>
     <domain-id>
 
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os domain show
+
os credential show
     <domain>
+
     <credential-id>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone domain-get
+
keystone credential-get
     <domain-id>
+
     <credential-id>
 
</source>
 
</source>
 
|}
 
|}
  
==== endpoint ====
+
==== domain ====
  
 
{| class="wikitable"
 
{| class="wikitable"
Line 902: Line 1,014:
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os endpoint create
+
os domain create
     [--region <endpoint-region>
+
     [--description <domain-description>]
 
     [--enable | --disable]
 
     [--enable | --disable]
     <service>
+
     <domain-name>
    <interface admin|public|internal>
 
    <url>
 
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone endpoint-create  
+
keystone domain-create
     [--region <endpoint-region>
+
     --name <domain-name>
     [--enable | --disable]
+
     [--description <domain-description>]
     <service_id>
+
     [--enabled <true|false>]
     <interface admin|public|internal>
+
     [--private_project_names <true|false>]
     <url>
+
     [--private_user_names <true|false>]
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os endpoint delete
+
os domain delete
     <endpoint-id>
+
     <domain>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
 +
keystone domain-delete
 +
    <domain-id>
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os endpoint list
+
os domain list
    [--long]
 
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone endpoint-list
+
keystone domain-list
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os endpoint set
+
os domain set
     [--interface <endpoint-interface>]
+
     [--name <new-domain-name>]
    [--url <endpoint-url>]
+
     [--description <new-domain-description>]
     [--service <service-id>]
 
    [--region <endpoint-region>]
 
 
     [--enable | --disable]
 
     [--enable | --disable]
     <endpoint>
+
     <domain>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone endpoint-set
+
keystone domain-update
     [--interface <endpoint-interface>]
+
     [--name <domain_name>]
     [--url <endpoint-url>]
+
     [--description <domain-description>]
     [--service <service-id>]
+
     [--enabled <true|false>]
     [--region <endpoint-region>]
+
     [--private_project_names <true|false>]
     [--enable | --disable]
+
     [--private_user_names <true|false>]
     <endpoint>
+
     <domain-id>
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os endpoint show
+
os domain show
     <endpoint>
+
     <domain>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone endpoint-get  
+
keystone domain-get
     <endpoint>
+
     <domain-id>
 
</source>
 
</source>
 
|}
 
|}
  
==== group ====
+
==== endpoint ====
  
 
{| class="wikitable"
 
{| class="wikitable"
Line 984: Line 1,093:
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os group create
+
os endpoint create
     [--domain <domain>]
+
     [--region <endpoint-region>
     [--description <group-description>]
+
     [--enable | --disable]
     <group-name>
+
    <service>
 +
    <interface admin|public|internal>
 +
     <url>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone group-create
+
keystone endpoint-create  
     --name <group-name>
+
     [--region <endpoint-region>
     [--domain_id <domain-id>]
+
     [--enable | --disable]
     [--description <group-description>]
+
    <service_id>
 +
    <interface admin|public|internal>
 +
     <url>
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os group delete
+
os endpoint delete
     <group>
+
     <endpoint-id>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone group-delete
 
    <group-id>
 
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os group list
+
os endpoint list
 
     [--long]
 
     [--long]
 
</source>
 
</source>
Line 1,018: Line 1,129:
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone group-list
+
keystone endpoint-list
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os group set
+
os endpoint set
     [--name <new-group-name>]
+
     [--interface <endpoint-interface>]
     [--domain <domain>]
+
    [--url <endpoint-url>]
     [--description <new-group-description>]
+
     [--service <service-id>]
     <group>
+
     [--region <endpoint-region>]
 +
    [--enable | --disable]
 +
     <endpoint>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone group-update
+
keystone endpoint-set
     [--name <group_name>]
+
     [--interface <endpoint-interface>]
     [--domain_id <domain-id>]
+
    [--url <endpoint-url>]
     [--description <group-description>]
+
     [--service <service-id>]
     <group-id>
+
     [--region <endpoint-region>]
 +
    [--enable | --disable]
 +
     <endpoint>
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os group show
+
os endpoint show
     <group>
+
     <endpoint>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone group-get
+
keystone endpoint-get  
     <group-id>
+
     <endpoint>
 
</source>
 
</source>
 
|}
 
|}
  
==== policy ====
+
==== group ====
  
 
{| class="wikitable"
 
{| class="wikitable"
Line 1,060: Line 1,175:
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os policy create
+
os group create
     [--type <policy-type>]
+
     [--domain <domain>]
     --blob-file <blob-file>
+
     [--description <group-description>]
 +
    <group-name>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone policy-create
+
keystone group-create
     --type <policy-type>
+
     --name <group-name>
     --blob <policy-blob>
+
     [--domain_id <domain-id>]
 +
    [--description <group-description>]
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os policy delete
+
os group delete
     <policy-id>
+
     <group>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone policy-delete
+
keystone group-delete
     <policy-id>
+
     <group-id>
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os policy list
+
os group list
     [--include-blob]
+
     [--long]
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone policy-list
+
keystone group-list
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os policy set
+
os group set
     [--type <policy-type>]
+
     [--name <new-group-name>]
     [--blob-file<blob-file>]
+
     [--domain <domain>]
     <policy-id>
+
    [--description <new-group-description>]
 +
     <group>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone policy-update
+
keystone group-update
     [--type <policy-type>]
+
     [--name <group_name>]
     [--blob <policy-blob>]
+
    [--domain_id <domain-id>]
     <policy-id>
+
     [--description <group-description>]
 +
     <group-id>
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os policy show
+
os group show
     <policy-id>
+
     <group>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone policy-get
+
keystone group-get
     <policy-id>
+
     <group-id>
 
</source>
 
</source>
 
|}
 
|}
  
==== project ====
+
==== oauth ====
  
 
{| class="wikitable"
 
{| class="wikitable"
Line 1,132: Line 1,251:
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os project create
+
os access token create
     [--domain <project-domain>]
+
     --consumer-key <consumer-key>
     [--description <project-description>]
+
     --consumer-secret <consumer-secret>
     [--enable | --disable]
+
     --request-key <request-key>
     <project-name>
+
     --request-secret <request-secret>
 +
    --verifier <pin>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone project-create
+
n/a
    [--domain_id <domain_id>]
 
    [--description <description>]
 
    [--enable | --disable]
 
    <name>
 
 
</source>
 
</source>
 
|-
 
|-
|
+
| look at some alternatives: || || ||
<source lang="bash">
 
os project delete
 
    <project>
 
</source>
 
|| yes
 
|| ||
 
<source lang="bash">
 
os project-delete
 
    <project_id>
 
</source>
 
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os project list
+
os oauth token create
     [--long]
+
     --consumer-key <consumer-key>
 +
    --consumer-secret <consumer-secret>
 +
    --request-key <request-key>
 +
    --request-secret <request-secret>
 +
    --verifier <pin>
 
</source>
 
</source>
|| yes
+
|| nyet
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone project-list
+
* makes the token specific to oauth
 +
* add [--oauth-ver X] if versioning for oauth2 is an issue?
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os project set
+
os oauth token create
     [--name <new-project-name>]
+
     --access
     [--domain <project-domain>]
+
     --consumer-key <consumer-key>
     [--description <new-project-description>]
+
     --consumer-secret <consumer-secret>
     [--enable | --disable]
+
     --request-key <request-key>
     <project>
+
     --request-secret <request-secret>
</source>
+
     --verifier <pin>
|| yes
+
 
|| ||
+
os oauth token create
<source lang="bash">
+
     --request
keystone project-set
+
     --consumer-key <consumer-key>
    [--name <new-project-name>]
+
     --roles <roles>
     [--domain <project-domain>]
 
     [--description <new-project-description>]
 
     [--enable | --disable]
 
    <project_id>
 
</source>
 
|-
 
|
 
<source lang="bash">
 
os project show
 
     <project>
 
 
</source>
 
</source>
|| yes
+
|| nyet
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone project-get
+
* collapse 'access token' and 'request token' into 'oauth token'?
    <project_id>
 
 
</source>
 
</source>
 
|}
 
|}
  
==== request token ====
+
==== policy ====
  
 
{| class="wikitable"
 
{| class="wikitable"
Line 1,212: Line 1,312:
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os request token authorize
+
os policy create
     --consumer-key <consumer-key>
+
     [--type <policy-type>]
    --consumer-secret <consumer-secret>
+
     --blob-file <blob-file>
    --request-key <request-key>
 
     --request-secret <request-secret>
 
    --user-token <token>
 
    --roles <roles>
 
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
n/a
+
keystone policy-create
 +
    --type <policy-type>
 +
    --blob <policy-blob>
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os request token create
+
os policy delete
     --consumer-key <consumer-key>
+
     <policy-id>
    --consumer-secret <consumer-secret>
 
    [--roles <roles>]
 
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
n/a
+
keystone policy-delete
 +
    <policy-id>
 
</source>
 
</source>
|}
 
 
==== role ====
 
 
{| class="wikitable"
 
|-
 
! OSC Command !! Implemented !! !! Keystone command
 
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os role add
+
os policy list
     [--user <user> | --group <group>]
+
     [--include-blob]
    [--domain <domain> | --project <project>]
 
    <role>
 
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
 +
keystone policy-list
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os role create
+
os policy set
     <role-name>
+
    [--type <policy-type>]
 +
    [--blob-file<blob-file>]
 +
     <policy-id>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
 +
keystone policy-update
 +
    [--type <policy-type>]
 +
    [--blob <policy-blob>]
 +
    <policy-id>
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os role delete
+
os policy show
     <role>
+
     <policy-id>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
 +
keystone policy-get
 +
    <policy-id>
 
</source>
 
</source>
 +
|}
 +
 +
==== project ====
 +
 +
{| class="wikitable"
 +
|-
 +
! OSC Command !! Implemented !! !! Keystone command
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os role list
+
os project create
 +
    [--domain <project-domain>]
 +
    [--description <project-description>]
 +
    [--enable | --disable]
 +
    <project-name>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
 +
keystone project-create
 +
    [--domain_id <domain_id>]
 +
    [--description <description>]
 +
    [--enable | --disable]
 +
    <name>
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os role remove
+
os project delete
    [--user <user> | --group <group>]
+
     <project>
     [--domain <domain> | --project <project>]
 
    <role>
 
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
 +
os project-delete
 +
    <project_id>
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os role set
+
os project list
     [--name <new-role-name>]
+
     [--long]
    <role>
 
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
 +
keystone project-list
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os role show
+
os project set
     <role>
+
    [--name <new-project-name>]
 +
    [--domain <project-domain>]
 +
    [--description <new-project-description>]
 +
    [--enable | --disable]
 +
    <project>
 +
</source>
 +
|| yes
 +
|| ||
 +
<source lang="bash">
 +
keystone project-set
 +
    [--name <new-project-name>]
 +
    [--domain <project-domain>]
 +
    [--description <new-project-description>]
 +
    [--enable | --disable]
 +
    <project_id>
 +
</source>
 +
|-
 +
|
 +
<source lang="bash">
 +
os project show
 +
     <project>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
 +
keystone project-get
 +
    <project_id>
 
</source>
 
</source>
 
|}
 
|}
  
==== service ====
+
==== role ====
  
 
{| class="wikitable"
 
{| class="wikitable"
Line 1,329: Line 1,464:
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os service create
+
os role add
[--name <name>]
+
    [--user <user> | --group <group>]
        [--enabled <true|false>]
+
    [--domain <domain> | --project <project>]
        <type>
+
    <role>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone service-create
 
[--name <name>]
 
        [--enabled <true|false>]
 
        <type>
 
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os service delete
+
os role create
     <service>
+
     <role-name>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone service-delete
+
</source>
    <service_id>
 
</source>
 
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os list service
+
os role delete
 +
    <role>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone service-list
 
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os service set
+
os role list
    [--type <service-type>]
 
    [--name <new-name>]
 
    [--enable | --disable]
 
    <service>
 
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone service-set
 
    [--type <service-type>]
 
    [--name <new-name>]
 
    [--enable | --disable]
 
    <service>
 
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os service show
+
os role remove
     <service>
+
     [--user <user> | --group <group>]
 +
    [--domain <domain> | --project <project>]
 +
    <role>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone service-get
 
    <service_id>
 
 
</source>
 
</source>
|}
 
 
==== user ====
 
 
{| class="wikitable"
 
|-
 
! OSC Command !! Implemented !! !! Keystone command
 
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os user create
+
os role set
     [--password <password>]
+
     [--name <new-role-name>]
    [--project <project>]
+
     <role>
    [--email <user-email>]
+
</source>
    [--enable | --disable]
 
     <name>
 
</source>
 
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone user-create
 
    --name <user-name>
 
    [--domain_id <domain-id>]
 
    [--default_project_id <project-id>]
 
    [--description <description>]
 
    [--enabled <true|false>]
 
    [--password <password>]
 
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os user delete
+
os role show
     <user>
+
     <role>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone user-delete
 
    <user-id>
 
 
</source>
 
</source>
 +
|}
 +
 +
==== service ====
 +
 +
{| class="wikitable"
 +
|-
 +
! OSC Command !! Implemented !! !! Keystone command
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os user list
+
os service create
    [--project <project>]
+
[--name <name>]
    [--long]
+
        [--enabled <true|false>]
 +
        <type>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone user-list
+
keystone service-create
 +
[--name <name>]
 +
        [--enabled <true|false>]
 +
        <type>
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os user set
+
os service delete
     [--name <new-name>]
+
     <service>
    [--password <password>]
 
    [--project <project>]
 
    [--email <user-email>]
 
    [--enable | --disable]
 
    <user>
 
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone user-update
+
keystone service-delete
     --user_id <user-id>
+
     <service_id>
    [--name <user-name>]
 
    [--domain_id <domain-id>]
 
    [--default_project_id <project-id>]
 
    [--description <description>]
 
    [--enabled <true|false>]
 
    [--password <password>]
 
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os user show
+
os list service
    <user>
 
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
keystone user-get
+
keystone service-list
     <user-id>
+
</source>
 +
|-
 +
|
 +
<source lang="bash">
 +
os service set
 +
    [--type <service-type>]
 +
    [--name <new-name>]
 +
    [--enable | --disable]
 +
    <service>
 +
</source>
 +
|| yes
 +
|| ||
 +
<source lang="bash">
 +
keystone service-set
 +
    [--type <service-type>]
 +
    [--name <new-name>]
 +
    [--enable | --disable]
 +
    <service>
 +
</source>
 +
|-
 +
|
 +
<source lang="bash">
 +
os service show
 +
    <service>
 +
</source>
 +
|| yes
 +
|| ||
 +
<source lang="bash">
 +
keystone service-get  
 +
     <service_id>
 
</source>
 
</source>
 
|}
 
|}
  
== Compute ==
+
==== user ====
 
 
 
 
{| class="wikitable"
 
|-
 
! OSC Option !! Environment Variable !! !! Nova Option !! Environment Variable
 
|-
 
| || || || --os-auth-system <auth-system> || OS_AUTH_SYSTEM
 
|-
 
| || || || --service-type <type> ||
 
|-
 
| || || || --service-name <name> || NOVA_SERVICE_NAME
 
|-
 
| || || || --volume-service-name <name> || NOVA_VOLUME_SERVICE_NAME
 
|-
 
| || || || --endpoint-type <type> || NOVA_ENDPOINT_TYPE
 
|-
 
| --os-compute-api-version <ver> || OS_COMPUTE_API_VERSION || || --os-compute-api-version <ver> || OS_COMPUTE_API_VERSION
 
|-
 
| || || || --bypass-url <bypass-url> ||
 
|}
 
 
 
 
 
=== API v2 (1.1) ===
 
 
 
==== agent ====
 
  
 
{| class="wikitable"
 
{| class="wikitable"
 
|-
 
|-
! OSC Command !! Implemented !! !! Nova command
+
! OSC Command !! Implemented !! !! Keystone command
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os agent create
+
os user create
     <os>
+
     [--password <password>]
     <architecture>
+
     [--project <project>]
     <version>
+
     [--email <user-email>]
     <url>
+
     [--enable | --disable]
    <md5hash>
+
     <name>
     <hypervisor>
 
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 +
<source lang="bash">
 +
keystone user-create
 +
    --name <user-name>
 +
    [--domain_id <domain-id>]
 +
    [--default_project_id <project-id>]
 +
    [--description <description>]
 +
    [--enabled <true|false>]
 +
    [--password <password>]
 +
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os agent delete
+
os user delete
     <id>
+
     <user>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 +
<source lang="bash">
 +
keystone user-delete
 +
    <user-id>
 +
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os agent list  
+
os user list
     [--hypervisor <hypervisor>]
+
     [--project <project>]
 +
    [--long]
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 +
<source lang="bash">
 +
keystone user-list
 +
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os agent set
+
os user set
     <id>
+
     [--name <new-name>]
     <version>
+
     [--password <password>]
     <url>
+
     [--project <project>]
     <md5hash>
+
     [--email <user-email>]
 +
    [--enable | --disable]
 +
    <user>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
|}
+
<source lang="bash">
 
+
keystone user-update
 
+
    --user_id <user-id>
==== aggregate ====
+
    [--name <user-name>]
 
+
    [--domain_id <domain-id>]
{| class="wikitable"
+
    [--default_project_id <project-id>]
|-
+
    [--description <description>]
! OSC Command !! Implemented !! !! Nova command
+
    [--enabled <true|false>]
 +
    [--password <password>]
 +
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os aggregate host add
+
os user show
     <aggregate>
+
     <user>
    <host>
 
 
</source>
 
</source>
|| no
+
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
nova aggregate-add-host
+
keystone user-get
     <id>
+
     <user-id>
    <host>
 
 
</source>
 
</source>
 +
|}
 +
 +
== Compute ==
 +
 +
 +
{| class="wikitable"
 +
|-
 +
! OSC Option !! Environment Variable !! !! Nova Option !! Environment Variable
 +
|-
 +
| || || || --os-auth-system <auth-system> || OS_AUTH_SYSTEM
 +
|-
 +
| || || || --service-type <type> ||
 +
|-
 +
| || || || --service-name <name> || NOVA_SERVICE_NAME
 +
|-
 +
| || || || --volume-service-name <name> || NOVA_VOLUME_SERVICE_NAME
 +
|-
 +
| || || || --endpoint-type <type> || NOVA_ENDPOINT_TYPE
 +
|-
 +
| --os-compute-api-version <ver> || OS_COMPUTE_API_VERSION || || --os-compute-api-version <ver> || OS_COMPUTE_API_VERSION
 +
|-
 +
| || || || --bypass-url <bypass-url> ||
 +
|}
 +
 +
 +
=== API v2 (1.1) ===
 +
 +
==== agent ====
 +
 +
{| class="wikitable"
 +
|-
 +
! OSC Command !! Implemented !! !! Nova command
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os aggregate create
+
os agent create
     <name>
+
     <os>
     <availability_zone>
+
     <architecture>
 +
    <version>
 +
    <url>
 +
    <md5hash>
 +
    <hypervisor>
 
</source>
 
</source>
|| no
+
|| yes
 
|| ||
 
|| ||
 +
|-
 +
|
 
<source lang="bash">
 
<source lang="bash">
nova aggregate-create
+
os agent delete
     <name>
+
     <id>
    <availability_zone>
 
 
</source>
 
</source>
 +
|| yes
 +
|| ||
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os aggregate delete
+
os agent list
     <aggregate>
+
     [--hypervisor <hypervisor>]
 
</source>
 
</source>
|| no
+
|| yes
 
|| ||
 
|| ||
<source lang="bash">
 
nova aggregate-delete
 
    <id>
 
</source>
 
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os aggregate list
+
os agent set
 +
    <id>
 +
    <version>
 +
    <url>
 +
    <md5hash>
 
</source>
 
</source>
|| no
+
|| yes
 
|| ||
 
|| ||
<source lang="bash">
+
|}
nova aggregate-list
+
 
</source>
+
 
 +
==== aggregate ====
 +
 
 +
{| class="wikitable"
 +
|-
 +
! OSC Command !! Implemented !! !! Nova command
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os aggregate host remove
+
os aggregate add host
 
     <aggregate>
 
     <aggregate>
 
     <host>
 
     <host>
 
</source>
 
</source>
|| no
+
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
nova aggregate-remove-host
+
nova aggregate-add-host
 
     <id>
 
     <id>
 
     <host>
 
     <host>
Line 1,628: Line 1,794:
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os aggregate set
+
os aggregate create
    [--name <new-name>]
 
 
     [--zone <availability-zone>]
 
     [--zone <availability-zone>]
 
     [--property <key=value>]
 
     [--property <key=value>]
     <aggregate>
+
     <name>
 
</source>
 
</source>
|| no
+
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
nova aggregate-update
+
nova aggregate-create
    <id>
 
 
     <name>
 
     <name>
 
     [<availability_zone>]
 
     [<availability_zone>]
 
nova aggregate-set-metadata
 
    <id>
 
    <key=value>
 
    [<key=value> ...]
 
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os aggregate show
+
os aggregate delete
 
     <aggregate>
 
     <aggregate>
 
</source>
 
</source>
|| no
+
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
nova aggregate-details
+
nova aggregate-delete
 
     <id>
 
     <id>
 
</source>
 
</source>
|}
 
 
 
==== bash-completion ====
 
 
{| class="wikitable"
 
|-
 
! OSC Command !! Implemented !! !! Nova command
 
 
|-
 
|-
 
|
 
|
TBD
 
|| no
 
|| ||
 
 
<source lang="bash">
 
<source lang="bash">
nova bash-completion
+
os aggregate list
 +
    [--long]
 +
</source>
 +
|| yes
 +
|| ||
 +
<source lang="bash">
 +
nova aggregate-list
 
</source>
 
</source>
|}
 
 
==== cloudpipe ====
 
 
{| class="wikitable"
 
|-
 
! OSC Command !! Implemented !! !! Nova command
 
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os create cloudpipe
+
os aggregate remove host
     <project>
+
     <aggregate>
 +
    <host>
 
</source>
 
</source>
|| no
+
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
nova cloudpipe-create
+
nova aggregate-remove-host
     <project>
+
    <id>
 +
     <host>
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os list cloudpipe
+
os aggregate set
 +
    [--name <new-name>]
 +
    [--zone <availability-zone>]
 +
    [--property <key=value>]
 +
    <aggregate>
 
</source>
 
</source>
|| no
+
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
nova cloudpipe-list
+
nova aggregate-update
</source>
+
    <id>
|}
+
    <name>
 +
    [<availability_zone>]
  
==== console ====
+
nova aggregate-set-metadata
 
+
     <id>
{| class="wikitable"
+
     <key=value>
|-
+
     [<key=value> ...]
! OSC Command !! Implemented !! !! Nova command
 
|-
 
|
 
<source lang="bash">
 
os console log show
 
     [--lines <num-lines>]
 
     <server>
 
</source>
 
|| yes
 
|| ||
 
<source lang="bash">
 
nova console-log
 
     [--length <length>]
 
    <server>
 
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os console url show
+
os aggregate show
    [--novnc | --xvpvnc | --spice]
+
     <aggregate>
     <server>
 
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
nova get-vnc-console
+
nova aggregate-details
    <server>
+
     <id>
     <console_type>
 
 
</source>
 
</source>
 
|}
 
|}
  
==== credentials ====
+
==== bash-completion ====
  
''This may be better handled as part of the Identity API''
 
 
{| class="wikitable"
 
{| class="wikitable"
 
|-
 
|-
Line 1,749: Line 1,886:
 
|-
 
|-
 
|
 
|
<source lang="bash">
 
 
TBD
 
TBD
</source>
 
 
|| no
 
|| no
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
nova credentials
+
nova bash-completion
 
</source>
 
</source>
 
|}
 
|}
  
==== diagnostics ====
+
==== cloudpipe ====
  
''Consider implementing this as: show server --diagnostics <server>''
 
 
{| class="wikitable"
 
{| class="wikitable"
 
|-
 
|-
Line 1,768: Line 1,902:
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os diagnostics show
+
os create cloudpipe
     <server>
+
     <project>
 +
</source>
 +
|| no
 +
|| ||
 +
<source lang="bash">
 +
nova cloudpipe-create
 +
    <project>
 +
</source>
 +
|-
 +
|
 +
<source lang="bash">
 +
os list cloudpipe
 
</source>
 
</source>
 
|| no
 
|| no
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
nova diagnostics
+
nova cloudpipe-list
    <server>
 
 
</source>
 
</source>
 
|}
 
|}
  
==== dns ====
+
==== console ====
  
''These commands need some attention...an IP shouldn't be required for all record types.  They need to be more DNS-y.  Zone anyone?''
 
 
{| class="wikitable"
 
{| class="wikitable"
 
|-
 
|-
Line 1,788: Line 1,931:
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os create dns
+
os console log show
     [--type <type>]
+
     [--lines <num-lines>]
     <ip>
+
     <server>
    <name>
 
    <domain>
 
 
</source>
 
</source>
|| no
+
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
nova dns-create
+
nova console-log
     [--type <type>]
+
     [--length <length>]
     <ip>
+
     <server>
    <name>
 
    <domain>
 
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os delete dns
+
os console url show
     <domain>
+
     [--novnc | --xvpvnc | --spice]
     <name>
+
     <server>
 
</source>
 
</source>
|| no
+
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
nova dns-delete
+
nova get-vnc-console
     <domain>
+
     <server>
     <name>
+
     <console_type>
 
</source>
 
</source>
 +
|}
 +
 +
==== credentials ====
 +
 +
See [[#credentials|credentials]] in the [[#Cross_API|cross API section]].
 +
 +
==== diagnostics ====
 +
 +
''Consider implementing this as: show server --diagnostics <server>''
 +
{| class="wikitable"
 +
|-
 +
! OSC Command !! Implemented !! !! Nova command
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os list dns
+
os diagnostics show
     [--ip <ip>]
+
     <server>
    [--name <name>]
 
    <domain>
 
 
</source>
 
</source>
 
|| no
 
|| no
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
nova dns-list
+
nova diagnostics
     [--ip <ip>]
+
     <server>
    [--name <name>]
 
    <domain>
 
 
</source>
 
</source>
 +
|}
 +
 +
==== dns ====
 +
 +
''These commands need some attention...an IP shouldn't be required for all record types.  They need to be more DNS-y.  Zone anyone?''
 +
{| class="wikitable"
 +
|-
 +
! OSC Command !! Implemented !! !! Nova command
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os create dns-domain
+
os create dns
     [--project <project>]
+
     [--type <type>]
     [--availability-zone <availability-zone>]
+
     <ip>
     [--public | --private]
+
     <name>
 
     <domain>
 
     <domain>
 
</source>
 
</source>
Line 1,845: Line 2,000:
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
nova dns-create-private-domain
+
nova dns-create
     [--availability_zone <availability_zone>]
+
     [--type <type>]
     <domain>
+
     <ip>
 
+
     <name>
nova dns-create-public-domain
 
     [--project <project>]
 
 
     <domain>
 
     <domain>
 
</source>
 
</source>
Line 1,856: Line 2,009:
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os delete dns-domain
+
os delete dns
 
     <domain>
 
     <domain>
 +
    <name>
 
</source>
 
</source>
 
|| no
 
|| no
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
nova dns-delete-domain
+
nova dns-delete
 
     <domain>
 
     <domain>
 +
    <name>
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os list dns-domains
+
os list dns
 +
    [--ip <ip>]
 +
    [--name <name>]
 +
    <domain>
 
</source>
 
</source>
 
|| no
 
|| no
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
nova dns-domains
+
nova dns-list
 +
    [--ip <ip>]
 +
    [--name <name>]
 +
    <domain>
 
</source>
 
</source>
|}
+
|-
 
+
|
==== endpoints ====
+
<source lang="bash">
 +
os create dns-domain
 +
    [--project <project>]
 +
    [--availability-zone <availability-zone>]
 +
    [--public | --private]
 +
    <domain>
 +
</source>
 +
|| no
 +
|| ||
 +
<source lang="bash">
 +
nova dns-create-private-domain
 +
    [--availability_zone <availability_zone>]
 +
    <domain>
  
''Totally duplicates Identity catalog command''
+
nova dns-create-public-domain
{| class="wikitable"
+
    [--project <project>]
 +
    <domain>
 +
</source>
 
|-
 
|-
! OSC Command !! Implemented !! !! Nova command
+
|
 +
<source lang="bash">
 +
os delete dns-domain
 +
    <domain>
 +
</source>
 +
|| no
 +
|| ||
 +
<source lang="bash">
 +
nova dns-delete-domain
 +
    <domain>
 +
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os endpoint list
+
os list dns-domains
 
</source>
 
</source>
 
|| no
 
|| no
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
nova endpoints
+
nova dns-domains
 
</source>
 
</source>
 
|}
 
|}
  
==== fixed-ip ====
+
==== endpoints ====
  
 +
''Totally duplicates Identity catalog command''
 
{| class="wikitable"
 
{| class="wikitable"
 
|-
 
|-
Line 1,903: Line 2,089:
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os ip fixed add
+
os endpoint list
 +
</source>
 +
|| no
 +
|| ||
 +
<source lang="bash">
 +
nova endpoints
 +
</source>
 +
|}
 +
 
 +
==== fixed-ip ====
 +
 
 +
{| class="wikitable"
 +
|-
 +
! OSC Command !! Implemented !! !! Nova command
 +
|-
 +
|
 +
<source lang="bash">
 +
os ip fixed add
 
     <network>
 
     <network>
 
     <server>
 
     <server>
Line 2,218: Line 2,421:
  
 
==== limits ====
 
==== limits ====
 +
 +
See [[#limits|limits]] in the [[#Cross_API|cross API section]].
 +
 +
==== quota ====
 +
 +
See [[#quota|quota]] in the [[#Cross_API|cross API section]].
 +
 +
 +
==== resource ====
  
 
{| class="wikitable"
 
{| class="wikitable"
Line 2,225: Line 2,437:
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os limits show
+
os show resource
     --absolute [--reserved] | --rate
+
     <hostname>
 
</source>
 
</source>
 
|| no
 
|| no
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
nova absolute-limits
+
nova describe-resource
 
+
    <hostname>
nova rate-limits
 
 
</source>
 
</source>
 
|}
 
|}
  
==== quota ====
+
==== secgroup ====
  
 
{| class="wikitable"
 
{| class="wikitable"
Line 2,245: Line 2,456:
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os quota set
+
os secgroup add
    [--instances <instances>]
+
 
    [--cores <cores>]
+
(see server add secgroup)
    [--ram <ram>]
+
</source>
    [--volumes <volumes>]
+
|| no
    [--gigabytes <gigabytes>]
 
    [--floating-ips <floating-ips>]
 
    [--property-items <property-items>]
 
    [--injected-files <injected-files>]
 
    [--injected-file-content-bytes <injected-file-content-bytes>]
 
    <project>
 
</source>
 
|| no
 
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
nova quota-update
+
nova add-secgroup
     [--instances <instances>]
+
     <server>
    [--cores <cores>]
+
     <secgroup>
    [--ram <ram>]
 
    [--volumes <volumes>]
 
    [--gigabytes <gigabytes>]
 
    [--floating-ips <floating_ips>]
 
    [--metadata-items <metadata_items>]
 
    [--injected-files <injected_files>]
 
    [--injected-file-content-bytes <injected_file_content_bytes>]
 
     <tenant_id>
 
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os quota set
+
os secgroup create
    --class
+
     [--description <description>]
    [--instances <instances>]
+
     <name>
    [--cores <cores>]
 
    [--ram <ram>]
 
    [--volumes <volumes>]
 
    [--gigabytes <gigabytes>]
 
    [--floating-ips <floating-ips>]
 
    [--property-items <property-items>]
 
    [--injected-files <injected-files>]
 
     [--injected-file-content-bytes <injected-file-content-bytes>]
 
     <class>
 
 
</source>
 
</source>
|| no
+
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
nova quota-class-update
+
nova secgroup-create
    [--instances <instances>]
+
     <name>
     [--cores <cores>]
+
     <description>
    [--ram <ram>]
+
</source>
    [--volumes <volumes>]
 
    [--gigabytes <gigabytes>]
 
    [--floating-ips <floating_ips>]
 
    [--metadata-items <metadata_items>]
 
    [--injected-files <injected_files>]
 
    [--injected-file-content-bytes <injected_file_content_bytes>]
 
     <class>
 
</source>
 
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os quota show
+
os secgroup delete
    [--defaults]
+
     <group>
     <project>
 
 
</source>
 
</source>
|| no
+
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
nova quota-defaults
+
nova secgroup-delete
     <tenant_id>
+
     <secgroup>
 
 
nova quota-show
 
    <tenant_id>
 
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os quota show
+
os secgroup list
     --class
+
     [--all-projects]
    <class>
 
 
</source>
 
</source>
|| no
+
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
nova quota-class-show
+
nova secgroup-list
    <class>
+
    [--all-tenants [<0|1>]]
 
</source>
 
</source>
|}
+
|-
 
+
|
 
 
 
 
'''resource'''
 
 
 
 
<source lang="bash">
 
<source lang="bash">
nova describe-resource <hostname>
+
os secgroup remove
  
os show resource ...
+
(see server remove secgroup)
 
</source>
 
</source>
 
+
|| no
==== secgroup ====
 
 
 
{| class="wikitable"
 
|-
 
! OSC Command !! Implemented !! !! Nova command
 
|-
 
|
 
<source lang="bash">
 
os secgroup add
 
    <secgroup>
 
    <server>
 
</source>
 
|| no
 
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
nova add-secgroup
+
nova remove-secgroup
 
     <server>
 
     <server>
 
     <secgroup>
 
     <secgroup>
Line 2,366: Line 2,522:
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os secgroup create
+
os secgroup set
     [--description <description>]
+
    [--name <new-name>]
     <name>
+
     [--description [<new-description>]
 +
     <group>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
nova secgroup-create
+
nova secgroup-update
 +
    <secgroup>
 
     <name>
 
     <name>
 
     <description>
 
     <description>
Line 2,380: Line 2,538:
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os secgroup delete
+
os secgroup show
     <secgroup>
+
     <group>
 
</source>
 
</source>
 
|| yes
 
|| yes
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
nova secgroup-delete
+
n/a
    <secgroup>
 
 
</source>
 
</source>
 +
|}
 +
 +
==== secgroup-group-rule ====
 +
 +
{| class="wikitable"
 +
|-
 +
! OSC Command !! Implemented !! !! Nova command
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os secgroup list
+
os secgroup group rule create
    [--all-tenants]
+
     [--proto <protocol>]
</source>
 
|| yes
 
|| ||
 
<source lang="bash">
 
nova secgroup-list
 
    [--all-tenants [<0|1>]]
 
</source>
 
|-
 
|
 
<source lang="bash">
 
os secgroup remove
 
    <secgroup>
 
    <server>
 
</source>
 
|| no
 
|| ||
 
<source lang="bash">
 
nova remove-secgroup
 
    <server>
 
    <secgroup>
 
</source>
 
|}
 
 
 
==== secgroup-group-rule ====
 
 
 
{| class="wikitable"
 
|-
 
! OSC Command !! Implemented !! !! Nova command
 
|-
 
|
 
<source lang="bash">
 
os secgroup group rule create
 
     [--proto <protocol>]
 
 
     [--port <port>:<port>]
 
     [--port <port>:<port>]
 
     <source-group>
 
     <source-group>
Line 2,473: Line 2,604:
 
     [--proto <proto>]
 
     [--proto <proto>]
 
     [--src-ip <ip-address>]
 
     [--src-ip <ip-address>]
     [--src-port <port>]
+
     [--dst-port <port-range>]
    [--dst-port <port>]
+
     <group>
     <secgroup>
 
 
</source>
 
</source>
 
|| no
 
|| no
Line 2,493: Line 2,623:
 
     [--proto <proto>]
 
     [--proto <proto>]
 
     [--src-ip <ip-address>]
 
     [--src-ip <ip-address>]
     [--src-port <port>]
+
     [--dst-port <port-range>]
    [--dst-port <port>]
+
     <group>
     <secgroup>
 
 
</source>
 
</source>
 
|| no
 
|| no
Line 2,511: Line 2,640:
 
<source lang="bash">
 
<source lang="bash">
 
os secgroup rule list
 
os secgroup rule list
     <secgroup>
+
     <group>
 
</source>
 
</source>
 
|| no
 
|| no
Line 2,526: Line 2,655:
 
|-
 
|-
 
! OSC Command !! Implemented !! !! Nova command
 
! OSC Command !! Implemented !! !! Nova command
 +
|-
 +
|
 +
<source lang="bash">
 +
os server add secgroup
 +
    <server>
 +
    <group>
 +
</source>
 +
|| no
 +
|| ||
 +
<source lang="bash">
 +
nova add-secgroup
 +
    <server>
 +
    <secgroup>
 +
</source>
 
|-
 
|-
 
|
 
|
Line 2,691: Line 2,834:
 
     <server>
 
     <server>
 
     <image>
 
     <image>
 +
</source>
 +
|-
 +
|
 +
<source lang="bash">
 +
os server remove secgroup
 +
    <server>
 +
    <group>
 +
</source>
 +
|| no
 +
|| ||
 +
<source lang="bash">
 +
nova remove-secgroup
 +
    <server>
 +
    <secgroup>
 
</source>
 
</source>
 
|-
 
|-
Line 2,874: Line 3,031:
 
</source>
 
</source>
 
|}
 
|}
 
  
 
==== usage ====
 
==== usage ====
Line 2,938: Line 3,094:
 
==== x509-cert ====
 
==== x509-cert ====
  
{| class="wikitable"
+
See [[#credentials|credentials]] in the [[#Cross_API|cross API section]].
|-
 
! OSC Command !! Implemented !! !! Keystone command
 
|-
 
|
 
<source lang="bash">
 
os x509 cert create
 
    [<private_key_file>]
 
    [<x509_cert>]
 
</source>
 
|| no
 
|| ||
 
<source lang="bash">
 
nova x509-create-cert
 
    [<private_key_file>]
 
    [<x509_cert>]
 
</source>
 
|}
 
  
 
==== x509-root-cert ====
 
==== x509-root-cert ====
  
{| class="wikitable"
+
See [[#credentials|credentials]] in the [[#Cross_API|cross API section]].
|-
+
 
! OSC Command !! Implemented !! !! Keystone command
 
|-
 
|
 
<source lang="bash">
 
os show x509-root-cert
 
</source>
 
|| no
 
|| ||
 
<source lang="bash">
 
nova x509-get-root-cert
 
    [<filename>]
 
</source>
 
|}
 
 
 
 
 
 
== Image ==
 
== Image ==
  
Line 3,051: Line 3,175:
 
     [--human-readable]
 
     [--human-readable]
 
</source>
 
</source>
|}
 
 
=== API v2 ===
 
 
==== image ====
 
 
{| class="wikitable"
 
|-
 
! OSC Command !! Implemented !! !! Glance command
 
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
 
os image delete
 
os image delete
     <id>
+
     <image>
 
</source>
 
</source>
 
|| yes
 
|| yes
Line 3,076: Line 3,191:
 
<source lang="bash">
 
<source lang="bash">
 
os image list
 
os image list
 +
    [--page-size <size>]
 
</source>
 
</source>
 
|| yes
 
|| yes
Line 3,085: Line 3,201:
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
os image show
+
os image save
 +
    [--file <filename>]
 
     <image>
 
     <image>
 
</source>
 
</source>
Line 3,091: Line 3,208:
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
glance image-show
+
glance image-download
     <IMAGE_ID>
+
     [--file <FILE>]
 +
    <IMAGE>
 
</source>
 
</source>
 
|-
 
|-
 
|
 
|
 
<source lang="bash">
 
<source lang="bash">
</source>
+
os image set
|| no
+
    [--name <name>]
|| ||
+
    [--owner <tenant>]
<source lang="bash">
+
    [--min-disk <disk-gb>]
glance member-images
+
    [--min-ram <ram-mg>]
     [options]
+
    [--protected | --unprotected]
     <MEMBER>
+
    [--public | --private]
 +
    [--property <key=value>]
 +
    <image>
 +
</source>
 +
|| yes
 +
|| ||
 +
<source lang="bash">
 +
glance image-update
 +
    [--name <NAME>]
 +
    [--disk-format <DISK_FORMAT>]
 +
    [--container-format <CONTAINER_FORMAT>]
 +
    [--owner <TENANT_ID>]
 +
    [--size <SIZE>]
 +
    [--min-disk <DISK_GB>]
 +
    [--min-ram <DISK_RAM>]
 +
    [--location <IMAGE_URL>]
 +
    [--file <FILE>]
 +
    [--checksum <CHECKSUM>]
 +
    [--copy-from <IMAGE_URL>]
 +
    [--is-public [True|False]]
 +
    [--is-protected [True|False]]
 +
    [--property <key=value>]
 +
    [--purge-props]
 +
    [--human-readable]
 +
    <IMAGE>
 +
</source>
 +
|-
 +
|
 +
<source lang="bash">
 +
os image show
 +
    <image>
 +
</source>
 +
|| yes
 +
|| ||
 +
<source lang="bash">
 +
glance image-show
 +
    [--human-readable]
 +
    <IMAGE>
 +
</source>
 +
|}
 +
 
 +
=== API v2 ===
 +
 
 +
==== image ====
 +
 
 +
{| class="wikitable"
 +
|-
 +
! OSC Command !! Implemented !! !! Glance command
 +
|-
 +
|
 +
<source lang="bash">
 +
os image delete
 +
    <image>
 +
</source>
 +
|| yes
 +
|| ||
 +
<source lang="bash">
 +
glance image-delete
 +
    <IMAGE_ID>
 +
</source>
 +
|-
 +
|
 +
<source lang="bash">
 +
os image list
 +
    [--page-size <size>]
 +
</source>
 +
|| yes
 +
|| ||
 +
<source lang="bash">
 +
glance image-list
 +
</source>
 +
|-
 +
|
 +
<source lang="bash">
 +
</source>
 +
|| no
 +
|| ||
 +
<source lang="bash">
 +
glance member-images
 +
     [options]
 +
     <MEMBER>
 +
</source>
 +
|-
 +
|
 +
<source lang="bash">
 +
os image save
 +
    [--file <filename>]
 +
    <image>
 +
</source>
 +
|| yes
 +
|| ||
 +
<source lang="bash">
 +
glance image-download
 +
    [--file <FILE>]
 +
    <IMAGE>
 +
</source>
 +
|-
 +
|
 +
<source lang="bash">
 +
os image set
 +
    [--id <id>]
 +
    [--store <store>]
 +
    [--container-format <format>]
 +
    [--disk-format <format>]
 +
    [--owner <tenant>]
 +
    [--size <size-bytes>]
 +
    [--min-disk <disk-gb>]
 +
    [--min-ram <ram-mg>]
 +
    [--location <image-url>]
 +
    [--copy-from <image-url>]
 +
    [--file <local-filename>]
 +
    [--checksum <checksum>]
 +
    [--protected | --unprotected]
 +
    [--public | --private]
 +
    [--property <key=value>]
 +
    <name>
 +
</source>
 +
|| no
 +
|| ||
 +
<source lang="bash">
 +
glance image-update
 +
    [--name <NAME>]
 +
    [--disk-format <DISK_FORMAT>]
 +
    [--container-format <CONTAINER_FORMAT>]
 +
    [--owner <TENANT_ID>]
 +
    [--size <SIZE>]
 +
    [--min-disk <DISK_GB>]
 +
    [--min-ram <DISK_RAM>]
 +
    [--location <IMAGE_URL>]
 +
    [--file <FILE>]
 +
    [--checksum <CHECKSUM>]
 +
    [--copy-from <IMAGE_URL>]
 +
    [--is-public [True|False]]
 +
    [--is-protected [True|False]]
 +
    [--property <key=value>]
 +
    [--purge-props]
 +
    [--human-readable]
 +
    <IMAGE>
 
</source>
 
</source>
 
|-
 
|-
Line 3,114: Line 3,369:
 
|| ||
 
|| ||
 
<source lang="bash">
 
<source lang="bash">
glance show
+
glance image-show
    [--human-readable]
 
    <IMAGE>
 
</source>
 
|-
 
|
 
<source lang="bash">
 
os image set
 
    [--id <id>]
 
    [--store <store>]
 
    [--container-format <format>]
 
    [--disk-format <format>]
 
    [--owner <tenant>]
 
    [--size <size-bytes>]
 
    [--min-disk <disk-gb>]
 
    [--min-ram <ram-mg>]
 
    [--location <image-url>]
 
    [--copy-from <image-url>]
 
    [--file <local-filename>]
 
    [--checksum <checksum>]
 
    [--protected | --unprotected]
 
    [--public | --private]
 
    [--property <key=value>]
 
    <name>
 
</source>
 
|| no
 
|| ||
 
<source lang="bash">
 
glance update
 
    [--name <NAME>]
 
    [--disk-format <DISK_FORMAT>]
 
    [--container-format <CONTAINER_FORMAT>]
 
    [--owner <TENANT_ID>]
 
    [--size <SIZE>]
 
    [--min-disk <DISK_GB>]
 
    [--min-ram <DISK_RAM>]
 
    [--location <IMAGE_URL>]
 
    [--file <FILE>]
 
    [--checksum <CHECKSUM>]
 
    [--copy-from <IMAGE_URL>]
 
    [--is-public [True|False]]
 
    [--is-protected [True|False]]
 
    [--property <key=value>]
 
    [--purge-props]
 
 
     [--human-readable]
 
     [--human-readable]
 
     <IMAGE>
 
     <IMAGE>
Line 3,165: Line 3,377:
  
 
==== image-member ====
 
==== image-member ====
 +
 +
Need to discuss the future of these commands with markwash...
  
 
<source lang="bash">
 
<source lang="bash">
Line 3,215: Line 3,429:
  
 
=== API v1.0 ===
 
=== API v1.0 ===
 +
 +
==== limits ====
 +
 +
See [[#limits|limits]] in the [[#Cross_API|cross API section]].
  
 
==== quota ====
 
==== quota ====
  
{| class="wikitable"
+
See [[#quota|quota]] in the [[#Cross_API|cross API section]].
|-
 
! OSC Command !! Implemented !! !! Cinder command
 
|-
 
|
 
<source lang="bash">
 
os quota list
 
    <tenant>
 
</source>
 
|| yes
 
|| ||
 
<source lang="bash">
 
</source>
 
|-
 
|
 
<source lang="bash">
 
os quota set
 
    [--volumes] <new-volumes>]
 
    [--gigabytes <new-gigabytes>]
 
    <tenant>
 
</source>
 
|| yes
 
|| ||
 
<source lang="bash">
 
cinder quota-update
 
    [--volumes <volumes>]
 
    [--snapshots <snapshots>]
 
    [--gigabytes <gigabytes>]
 
    <tenant_id>
 
</source>
 
|-
 
|
 
<source lang="bash">
 
os quota show
 
    <tenant>
 
</source>
 
|| yes
 
|| ||
 
<source lang="bash">
 
cinder quota-show
 
    <tenant_id>
 
</source>
 
|}
 
  
 
==== snapshot ====
 
==== snapshot ====
Line 3,533: Line 3,709:
 
== Network ==
 
== Network ==
  
'''quantum'''
+
The Network commands in <code>quantum</code> have been in a bit of flux and are currently out of scope for OpenStackClient.
  
 
{| class="wikitable"
 
{| class="wikitable"
Line 3,687: Line 3,863:
 
set port <tenant> <network> <port> <params>
 
set port <tenant> <network> <port> <params>
 
</source>
 
</source>
 
  
 
= Options =
 
= Options =

Latest revision as of 02:10, 19 July 2013

Note: this page is being deprecated in favor of a new OpenStackClient Commands page with the correct name.

OpenStackClient Commands

Part of the UnifiedCLI proposal

[Note that the use of the word object here is its generic meaning as the target of an action.]

Command Structure

The OpenStackClient has a consistent and predictable format for all of its commands.

  • The top level command name is openstack
  • Sub-commands take the form:
openstack [<global-options>] <object> <verb> [<second-object>] [<command-local-arguments>]

Note: The command format change was committed on 13May2013. This is the new format.


Command Arguments

  • All long options names shall use '-' as the interpolation character (--like-this)
  • Authentication options conform to a revised version of the original CLIAuth
  • Global arguments generally have a corresponding environment variable that may also be used to set the value. If both are present, the command-line option takes priority. The environment variable names can be derived from the option by dropping the leading '--', converting all embedded dashes ('-') to underscores ('_'), and converting to upper case.
  • Positional arguments trail command options.
  • Some commands require two objects be acted upon, both objects appear in the command and if both are positional arguments they appear in the same order as in the command. In words it can be expressed as "(given) object1 add object2 (to it)"
 * <object-1> <verb> <object-2>
   * group add user
   * access token list   (here, 'access token' is a two-word single object)
   * user list role (needs more thinking)

Other

  • Arguments that normally require an ID in the OS-API may also use the name or other short identifier where reasonable to support
  • Optional machine-parsable format is available with list and show commands. List has an option for CSV-formatted output (see --format, --quote options for a list command) while show has an option for shell-assignment formatted output (see --format option for a show command).

Verbs

The verbs used by the default OpenStack clients are defined below to provide a consistent meaning to each action. Many of them have logical opposite actions. Those verbs with an opposite action are noted in parens if applicable.

  • authorize - authorize a token (used in OAuth)
  • add (remove) - add some object to a container object; the command is built in the order of "container add object" (<container> <object>), the positional arguments appear in the same order
  • attach (detach) - connect two objects (is this different from add/remove? not really, use the same argument order as add)
  • create (delete) - create a new occurrance of the specified object
  • delete (create) - delete a specific occurrance of the specified object
  • detach (attach) - disconnect two objects (is this different from add/remove?)
  • list - display summary information about multiple objects
  • lock (unlock)
  • migrate - move a server to a different host; --live performs a live migration if possible
  • pause (unpause) - stop a server and leave it in memory
  • reboot - forcibly reboot a server
  • rebuild - rebuild a server using (most of) the same arguments as in the original create
  • remove (add) - remove an object from a group of objects
  • rescue (unrescue) - reboot a server in a special rescue mode allowing access to the original disks
  • resize - change a server's flavor
  • resume (suspend) - return a suspended server to running state
  • save - download an object locally
  • set (unset) - set an attribute of the object, often called metadata
  • show - display detailed information about the specifiec object
  • ssh
  • suspend (resume) - stop a server and save to disk freeing memory
  • unlock (lock)
  • unpause (pause) - return a paused server to running state
  • unrescue (rescue) - return a server to normal boot mode
  • unset (set) - remove an attribute of the object


Objects

Note: these need a review to sync up with the revised object names without dashes ('-') in them.


Global Options

The common global options from the default OpenStack clients have been mapped to the set of global options below.

OSC Option Environment Variable Option Environment Variable
--version --version
--help --help
--debug --debug
--quiet
--verbose
--log-file <filename>
--os-auth-url <url> OS_AUTH_URL --os-auth-url <url> OS_AUTH_URL
--os-tenant-name <name> OS_TENANT_NAME --os-tenant-name <name> OS_TENANT_NAME
--os-tenant-id <id> OS_TENANT_ID --os-tenant-id <id> OS_TENANT_ID
--os-username <name> OS_USERNAME --os-username <name> OS_USERNAME
--os-password <pw> OS_PASSWORD --os-password <pw> OS_PASSWORD
--os-region-name <region> OS_REGION_NAME --os-region-name <region> OS_REGION_NAME
--os-cacert <file> OS_CACERT --os-cacert <file> OS_CACERT
--insecure
--os-use-keyring


Common Options

A number of options will appear in many commands and should have the same form in all commands to the extent possible.

Option Description Usual Default
--description describes an object none
--enable Used for setting the enabled state for an object n/a
--disable Used for setting the enabled state for an object n/a


Command Mapping Summary

This is an example mapping of the existing commands from Keystone (Identity), Nova (Compute), Glance (Image) and Cinder (Volume) to the <verb> <object> form for the OpenStackClient cli tool. It reduces both the number of verbs and objects by handling some of the smaller differences with command line options.

Further consolidation could be achieved by additional options or by introduction secondary objects to the syntax. For example, the credentials and x509-cert (and x509-root-cert) objects could be combined:


nova x509-create-cert [<pk-file>] [<x509-cert>] os create credentials --x509 [<pk-file>] [<x509-cert>]
nova credentials os show credentials
nova x509-get-root-cert os show credentials --x509 --root


Cross API

Object names that appear in multiple APIs, like quota, are handled by putting their command handler classes in openstackclient.common. If the number of these becomes large they should be moved into a subdirectory.

credentials

[consider rolling the ec2 creds into this too]

OSC Command Implemented Keystone command
os credentials create
    --x509
    [<private-key-file>]
    [<certificate-file>]
no
nova x509-create-cert
    [<pk-file>]
    [<x509-cert>]
os credentials show
    [--token]
    [--user]
    [--x509 [--root]]
no
nova credentials
    [--wrap <integer>]

nova x509-get-root-cert
    [<filename>]

limits

OSC Command Implemented Keystone command
os limits show
    --absolute [--reserved] | --rate
yes
nova absolute-limits
    [--reserved]

nova rate-limits

cinder absolute-limits

cinder rate-limits

quota

OSC Command Implemented Keystone command
os quota set
    # Compute settings
    [--cores <num-cores>]
    [--fixed-ips <num-fixed-ips>]
    [--floating-ips <num-floating-ips>]
    [--injected-file-size <injected-file-bytes>]
    [--injected-files <num-injected-files>]
    [--instances <num-instances>] 
    [--key-pairs <num-key-pairs>]
    [--properties <num-properties>]
    [--ram <ram-mb>] 

    # Volume settings
    [--gigabytes <new-gigabytes>]
    [--snapshots <new-snapshots>]
    [--volumes <new-volumes>]

    <project>
yes
nova quota-update
    [--instances <instances>] 
    [--cores <cores>]
    [--ram <ram>] 
    [--volumes <volumes>]
    [--gigabytes <gigabytes>]
    [--floating-ips <floating_ips>]
    [--metadata-items <metadata_items>]
    [--injected-files <injected_files>]
    [--injected-file-content-bytes <injected_file_content_bytes>]
    <tenant_id>

cinder quota-update
    [--volumes <volumes>]
    [--snapshots <snapshots>]
    [--gigabytes <gigabytes>]
    <tenant_id>
os quota set
    --class
    # Compute settings
    [--cores <num-cores>]
    [--fixed-ips <num-fixed-ips>]
    [--floating-ips <num-floating-ips>]
    [--injected-file-size <injected-file-bytes>]
    [--injected-files <num-injected-files>]
    [--instances <num-instances>] 
    [--key-pairs <num-key-pairs>]
    [--properties <num-properties>]
    [--ram <ram-mb>] 

    # Volume settings
    [--gigabytes <new-gigabytes>]
    [--snapshots <new-snapshots>]
    [--volumes <new-volumes>]

    <class>
yes
nova quota-class-update 
    [--instances <instances>] 
    [--cores <cores>]
    [--ram <ram>] 
    [--volumes <volumes>]
    [--gigabytes <gigabytes>]
    [--floating-ips <floating_ips>]
    [--metadata-items <metadata_items>]
    [--injected-files <injected_files>]
    [--injected-file-content-bytes <injected_file_content_bytes>]
    <class>

cinder quota-class-update
    [--volumes <volumes>]
    [--snapshots <snapshots>]
    [--gigabytes <gigabytes>]
    <tenant_id>
os quota show
    [--default]
    <project>
yes
nova quota-show
    [--tenant <tenant-id>]

cinder quota-show
    <tenant_id>

nova quota-defaults
    <tenant_id>

cinder quota-defaults
    <tenant_id>
os quota show
    --class
    <class>
yes
nova quota-class-show
    <class>

cinder quota-class-show
    <class>

Identity

OSC Option Environment Variable Keystone Option Environment Variable
--os-identity-api-version <ver> OS_IDENTITY_API_VERSION --os-identity-api-version <ver> OS_IDENTITY_API_VERSION
--os-token <token> OS_TOKEN --os-token <token> OS_SERVICE_TOKEN
--os-url <url> OS_URL --os-endpoint <url> OS_SERVICE_ENDPOINT
--os-cert <file> OS_CERT
--os-key <key-file> OS_KEY
--os-cache OS_CACHE
--force-new-token
--stale-duration <seconds>

API v2.0

catalog

OSC Command Implemented Keystone command
os catalog show
    [--service <service>]
no
keystone catalog
    [--service <service-type>]

ec2 credentials

OSC Command Implemented Keystone command
os ec2 credentials create
    [--project <project>]
    [--user <user>]
yes
keystone ec2-credentials-create
    [--user <user-id>] 
    [--tenant_id <tenant-id>]
os ec2 credentials delete
    [--user <user>]
    <access-key>
yes
keystone ec2-credentials-delete
    [--user <user-id>] 
    --access <access-key>
os ec2 credentials list
    [--user <user>]
yes
keystone ec2-credentials-list
    [--user <user-id>]
os ec2 credentials show
    [--user <user>]
    <access-key>
yes
keystone ec2-credentials-get
    [--user <user-id>] 
    --access <access-key>

endpoint

OSC Command Implemented Keystone command
os endpoint create
    --publicurl <public-url>
    [--adminurl <admin-url>]
    [--internalurl <internal-url>]
    [--region <endpoint-region>]
    <service>
yes
keystone endpoint-create
    [--region <endpoint-region>]
    [--service_id <service-id>]
    [--publicurl <public-url>]
    [--adminurl <admin-url>]
    [--internalurl <internal-url>]
os endpoint delete
    <endpoint-id>
yes
keystone endpoint-delete
    <endpoint-id>
os endpoint list
    [--long]
yes
keystone endpoint-list
os endpoint show
    [--type <endpoint-type>]
    [--attr <endpoint-attribute>] 
    [--value <endpoint-value>]
    [--all]
    <service-type>
yes
keystone endpoint-get
    --service <service-type>
    [--endpoint_type <endpoint-type>]
    [--attr <service-attribute>] 
    [--value <value>]

role

OSC Command Implemented Keystone command
os role create
    <role-name>
yes
keystone role-create --name
    <role-name>
os role delete
    <role>
yes
keystone role-delete
    <role-id>
os role list
yes
keystone role-list
os role show
    <role>
yes
keystone role-get
    <role-id>

service

OSC Command Implemented Keystone command
os service create
    [--type <service-type>]
    [--description <service-description>]
    <service-name>
yes
keystone service-create
    --name <name> 
    --type <type>
    [--description <service-description>]
os service delete
    <service>
yes
keystone service-delete
    <service-id>
os service list
    [--long]
yes
keystone service-list
os service show
    [--catalog]
    <service>
yes
keystone service-get
    <service-id>

tenant

OSC Command Implemented Keystone command
os tenant create
    [--description <description>]
    [--enable | --disable]
    <tenant-name>
yes
keystone tenant-create
    --name <tenant-name>
    [--description <tenant-description>]
    [--enabled <true|false>]
os tenant delete
    <tenant>
yes
keystone tenant-delete
    <tenant>
os tenant list
    [--long]
yes
keystone tenant-list
os tenant set
    [--name <new-tenant-name>]
    [--description <new-tenant-description>]
    [--enable | --disable]
    <tenant>
yes
keystone tenant-update
    [--name <tenant_name>]
    [--description <tenant-description>]
    [--enabled <true|false>]
    <tenant-id>
os tenant show
    <tenant>
yes
keystone tenant-get
    <tenant-id>

token

OSC Command Implemented Keystone command
os token show
    [--width <token-display-width>]
 ??
keystone token-get [--wrap <integer>]

user

OSC Command Implemented Keystone command
os user create
    [--password <user-password>]
    [--email <user-email>]
    [--tenant <tenant>]
    [--enable | --disable]
    <user-name>
yes
keystone user-create
    --name <user-name> 
    [--tenant_id <tenant-id>]
    [--pass <pass>] 
    [--email <email>]
    [--enabled <true|false>]
os user delete
    <user>
yes
keystone user-delete
    <user-id>
os user list
    [--tenant <tenant>]
    [--long]
yes
keystone user-list
    [<tenant-id>]
os user set
    [--name <new-user-name>]
    [--password <user-password>]
    [--email <user-email>]
    [--tenant <tenant>]
    [--enable|--disable]
    <user>
yes
keystone user-password-update
    --pass <password>
    <user-id>
os user show
    <user>
yes
keystone user-get
    <user-id>

user role

OSC Command Implemented Keystone command
os user role add
    [--tenant <tenant>]
    <user>
    <role>
yes
keystone user-role-add
    --user <user-id>
    --role <role-id>
    [--tenant_id <tenant-id>]
os user role list
    [--tenant <tenant>]
    [<user>]
yes
keystone user-role-list
    [--user <user-id>]
    [--tenant_id <tenant-id>]
os user role remove
    [--tenant <tenant>]
    <user>
    <role>
yes
keystone user-role-remove
    --user <user-id>
    --role <role-id>
    [--tenant_id <tenant-id>]

<other>

These keystone commands are not planned for re-implementation in OpenStackClient

keystone bootstrap
        --pass <password>
        [--user-name <user-name>]
        [--role-name <role-name>]
        [--tenant-name <tenant-name>]
keystone discover

API v3

credential

OSC Command Implemented Keystone command
os credential create
    [--project <project>]
    [--type ec2|cert]
    <user>
    <data>
yes
keystone credential-create
    --user_id <user-id>
    --type <credential-type>
    --data <credential-data>
    [--project_id <project-id>]
os credential delete
    <credential-id>
yes
keystone credential-delete
    <credential-id>
os credential list
yes
keystone credential-list
os credential set
    [--user <user>]
    [--type ec2|cert]
    [--data <data>]
    [--project <project>]
    <credential-id>
yes
keystone credential-update
    [--user <user>]
    [--type <type>]
    [--data <data>]
    [--project <project>]
    <credential-id>
os credential show
    <credential-id>
yes
keystone credential-get
    <credential-id>

domain

OSC Command Implemented Keystone command
os domain create
    [--description <domain-description>]
    [--enable | --disable]
    <domain-name>
yes
keystone domain-create
    --name <domain-name>
    [--description <domain-description>]
    [--enabled <true|false>]
    [--private_project_names <true|false>]
    [--private_user_names <true|false>]
os domain delete
    <domain>
yes
keystone domain-delete
    <domain-id>
os domain list
yes
keystone domain-list
os domain set
    [--name <new-domain-name>]
    [--description <new-domain-description>]
    [--enable | --disable]
    <domain>
yes
keystone domain-update
    [--name <domain_name>]
    [--description <domain-description>]
    [--enabled <true|false>]
    [--private_project_names <true|false>]
    [--private_user_names <true|false>]
    <domain-id>
os domain show
    <domain>
yes
keystone domain-get
    <domain-id>

endpoint

OSC Command Implemented Keystone command
os endpoint create
    [--region <endpoint-region>
    [--enable | --disable]
    <service>
    <interface admin|public|internal>
    <url>
yes
keystone endpoint-create 
    [--region <endpoint-region>
    [--enable | --disable]
    <service_id>
    <interface admin|public|internal>
    <url>
os endpoint delete
    <endpoint-id>
yes
os endpoint list
    [--long]
yes
keystone endpoint-list
os endpoint set
    [--interface <endpoint-interface>]
    [--url <endpoint-url>]
    [--service <service-id>]
    [--region <endpoint-region>]
    [--enable | --disable]
    <endpoint>
yes
keystone endpoint-set
    [--interface <endpoint-interface>]
    [--url <endpoint-url>]
    [--service <service-id>]
    [--region <endpoint-region>]
    [--enable | --disable]
    <endpoint>
os endpoint show
    <endpoint>
yes
keystone endpoint-get 
    <endpoint>

group

OSC Command Implemented Keystone command
os group create
    [--domain <domain>]
    [--description <group-description>]
    <group-name>
yes
keystone group-create
    --name <group-name>
    [--domain_id <domain-id>]
    [--description <group-description>]
os group delete
    <group>
yes
keystone group-delete
    <group-id>
os group list
    [--long]
yes
keystone group-list
os group set
    [--name <new-group-name>]
    [--domain <domain>]
    [--description <new-group-description>]
    <group>
yes
keystone group-update
    [--name <group_name>]
    [--domain_id <domain-id>]
    [--description <group-description>]
    <group-id>
os group show
    <group>
yes
keystone group-get
    <group-id>

oauth

OSC Command Implemented Keystone command
os access token create
    --consumer-key <consumer-key>
    --consumer-secret <consumer-secret>
    --request-key <request-key>
    --request-secret <request-secret>
    --verifier <pin>
yes
n/a
look at some alternatives:
os oauth token create
    --consumer-key <consumer-key>
    --consumer-secret <consumer-secret>
    --request-key <request-key>
    --request-secret <request-secret>
    --verifier <pin>
nyet
* makes the token specific to oauth
* add [--oauth-ver X] if versioning for oauth2 is an issue?
os oauth token create
    --access
    --consumer-key <consumer-key>
    --consumer-secret <consumer-secret>
    --request-key <request-key>
    --request-secret <request-secret>
    --verifier <pin>

os oauth token create
    --request
    --consumer-key <consumer-key>
    --roles <roles>
nyet
* collapse 'access token' and 'request token' into 'oauth token'?

policy

OSC Command Implemented Keystone command
os policy create
    [--type <policy-type>]
    --blob-file <blob-file>
yes
keystone policy-create
    --type <policy-type>
    --blob <policy-blob>
os policy delete
    <policy-id>
yes
keystone policy-delete
    <policy-id>
os policy list
    [--include-blob]
yes
keystone policy-list
os policy set
    [--type <policy-type>]
    [--blob-file<blob-file>]
    <policy-id>
yes
keystone policy-update
    [--type <policy-type>]
    [--blob <policy-blob>]
    <policy-id>
os policy show
    <policy-id>
yes
keystone policy-get
    <policy-id>

project

OSC Command Implemented Keystone command
os project create
    [--domain <project-domain>]
    [--description <project-description>]
    [--enable | --disable]
    <project-name>
yes
keystone project-create
    [--domain_id <domain_id>]
    [--description <description>]
    [--enable | --disable]
    <name>
os project delete
    <project>
yes
os project-delete
    <project_id>
os project list
    [--long]
yes
keystone project-list
os project set
    [--name <new-project-name>]
    [--domain <project-domain>]
    [--description <new-project-description>]
    [--enable | --disable]
    <project>
yes
keystone project-set
    [--name <new-project-name>]
    [--domain <project-domain>]
    [--description <new-project-description>]
    [--enable | --disable]
    <project_id>
os project show
    <project>
yes
keystone project-get
    <project_id>

role

OSC Command Implemented Keystone command
os role add
    [--user <user> | --group <group>]
    [--domain <domain> | --project <project>]
    <role>
yes
os role create
    <role-name>
yes
os role delete
    <role>
yes
os role list
yes
os role remove
    [--user <user> | --group <group>]
    [--domain <domain> | --project <project>]
    <role>
yes
os role set
    [--name <new-role-name>]
    <role>
yes
os role show
    <role>
yes

service

OSC Command Implemented Keystone command
os service create
	[--name <name>]
        [--enabled <true|false>]
        <type>
yes
keystone service-create
	[--name <name>]
        [--enabled <true|false>]
        <type>
os service delete
    <service>
yes
keystone service-delete
    <service_id>
os list service
yes
keystone service-list
os service set
    [--type <service-type>]
    [--name <new-name>]
    [--enable | --disable]
    <service>
yes
keystone service-set
    [--type <service-type>]
    [--name <new-name>]
    [--enable | --disable]
    <service>
os service show
    <service>
yes
keystone service-get 
    <service_id>

user

OSC Command Implemented Keystone command
os user create
    [--password <password>] 
    [--project <project>]
    [--email <user-email>]
    [--enable | --disable]
    <name>
yes
keystone user-create
    --name <user-name> 
    [--domain_id <domain-id>]
    [--default_project_id <project-id>]
    [--description <description>]
    [--enabled <true|false>]
    [--password <password>]
os user delete
    <user>
yes
keystone user-delete
    <user-id>
os user list
    [--project <project>]
    [--long]
yes
keystone user-list
os user set
    [--name <new-name>]
    [--password <password>] 
    [--project <project>]
    [--email <user-email>]
    [--enable | --disable]
    <user>
yes
keystone user-update
    --user_id <user-id>
    [--name <user-name>]
    [--domain_id <domain-id>]
    [--default_project_id <project-id>]
    [--description <description>]
    [--enabled <true|false>]
    [--password <password>]
os user show
    <user>
yes
keystone user-get
    <user-id>

Compute

OSC Option Environment Variable Nova Option Environment Variable
--os-auth-system <auth-system> OS_AUTH_SYSTEM
--service-type <type>
--service-name <name> NOVA_SERVICE_NAME
--volume-service-name <name> NOVA_VOLUME_SERVICE_NAME
--endpoint-type <type> NOVA_ENDPOINT_TYPE
--os-compute-api-version <ver> OS_COMPUTE_API_VERSION --os-compute-api-version <ver> OS_COMPUTE_API_VERSION
--bypass-url <bypass-url>


API v2 (1.1)

agent

OSC Command Implemented Nova command
os agent create
    <os>
    <architecture>
    <version>
    <url>
    <md5hash>
    <hypervisor>
yes
os agent delete
    <id>
yes
os agent list 
    [--hypervisor <hypervisor>]
yes
os agent set
    <id>
    <version>
    <url>
    <md5hash>
yes


aggregate

OSC Command Implemented Nova command
os aggregate add host
    <aggregate>
    <host>
yes
nova aggregate-add-host
    <id>
    <host>
os aggregate create
    [--zone <availability-zone>]
    [--property <key=value>]
    <name>
yes
nova aggregate-create
    <name>
    [<availability_zone>]
os aggregate delete
    <aggregate>
yes
nova aggregate-delete
    <id>
os aggregate list
    [--long]
yes
nova aggregate-list
os aggregate remove host
    <aggregate>
    <host>
yes
nova aggregate-remove-host
    <id>
    <host>
os aggregate set
    [--name <new-name>]
    [--zone <availability-zone>]
    [--property <key=value>]
    <aggregate>
yes
nova aggregate-update
    <id>
    <name>
    [<availability_zone>]

nova aggregate-set-metadata
    <id>
    <key=value>
    [<key=value> ...]
os aggregate show
    <aggregate>
yes
nova aggregate-details
    <id>

bash-completion

OSC Command Implemented Nova command

TBD

no
nova bash-completion

cloudpipe

OSC Command Implemented Nova command
os create cloudpipe
    <project>
no
nova cloudpipe-create
    <project>
os list cloudpipe
no
nova cloudpipe-list

console

OSC Command Implemented Nova command
os console log show
    [--lines <num-lines>]
    <server>
yes
nova console-log
    [--length <length>]
    <server>
os console url show
    [--novnc | --xvpvnc | --spice]
    <server>
yes
nova get-vnc-console
    <server>
    <console_type>

credentials

See credentials in the cross API section.

diagnostics

Consider implementing this as: show server --diagnostics <server>

OSC Command Implemented Nova command
os diagnostics show
    <server>
no
nova diagnostics
    <server>

dns

These commands need some attention...an IP shouldn't be required for all record types. They need to be more DNS-y. Zone anyone?

OSC Command Implemented Nova command
os create dns
    [--type <type>]
    <ip>
    <name>
    <domain>
no
nova dns-create
    [--type <type>]
    <ip>
    <name>
    <domain>
os delete dns
    <domain>
    <name>
no
nova dns-delete
    <domain>
    <name>
os list dns
    [--ip <ip>]
    [--name <name>]
    <domain>
no
nova dns-list
    [--ip <ip>]
    [--name <name>]
    <domain>
os create dns-domain
    [--project <project>]
    [--availability-zone <availability-zone>]
    [--public | --private]
    <domain>
no
nova dns-create-private-domain
    [--availability_zone <availability_zone>]
    <domain>

nova dns-create-public-domain
    [--project <project>]
    <domain>
os delete dns-domain
    <domain>
no
nova dns-delete-domain
    <domain>
os list dns-domains
no
nova dns-domains

endpoints

Totally duplicates Identity catalog command

OSC Command Implemented Nova command
os endpoint list
no
nova endpoints

fixed-ip

OSC Command Implemented Nova command
os ip fixed add
    <network>
    <server>
yes
nova add-fixed-ip
    <server>
    <network_id>
os ip fixed remove
    <ip-address>
    <server>
yes
nova remove-fixed-ip
    <server>
    <address>


flavor

OSC Command Implemented Nova command
os flavor create
    [--id <id>]
    [--ram <size-mb>]
    [--disk <size-gb>]
    [--ephemeral-disk <size-gb>]
    [--swap <size-mb>]
    [--vcpus <num-cpu>]
    [--rxtx-factor <factor>]
    [--public | --private]
    <name>
(partial)
default: auto
default: 256M
default: 0G
default: 0G
default: 0G
default: 1
default: 1
default: public
nova flavor-create
    [--ephemeral <ephemeral>] 
    [--swap <swap>]
    [--rxtx-factor <factor>]
    <name>
    <id>
    <ram>
    <disk>
    <vcpus>
os flavor delete
    <flavor>
yes
nova flavor-delete 
    <id>
os flavor list
yes
nova flavor-list
os flavor show
    <flavor>
yes


floating-ip

OSC Command Implemented Nova command
os ip floating add
    <ip-address>
    <server>
yes
nova add-floating-ip
    <server>
    <address>
os ip floating create
    [<pool>]
yes
nova floating-ip-create
    [<floating_ip_pool>]
os ip floating delete
    <ip-address>
yes
nova floating-ip-delete
    <address>
os ip floating list
yes
nova floating-ip-list
os ip floating remove
    <ip-address>
    <server>
yes
nova remove-floating-ip
    <server>
    <address>


floating-ip-pool

OSC Command Implemented Nova command
os ip floating pool list
yes
nova floating-ip-pool-list


host

OSC Command Implemented Nova command
os host list
    [--zone <availability-zone>]
yes
nova host-action
    [--action <action>]
    <hostname>
os host set
    ...
no
nova host-update
    [--status <status>] 
    [--maintenance <maintenance_mode>]
    <hostname>
os host show
    <host>
yes


hypervisor

OSC Command Implemented Nova command
os hypervisor list
    [--matching <hostname>]
yes
os hypervisor show
    <id>
yes


keypair

OSC Command Implemented Nova command
os keypair create
    [--public-key <file>]
    <name>
yes
nova keypair-add
    [--pub_key <pub_key>]
    <name>
os keypair delete
    <name>
yes
nova keypair-delete
    <name>
os keypair list
yes
nova keypair-list
os keypair show
    [--public-key]
    <name>
yes


limits

See limits in the cross API section.

quota

See quota in the cross API section.


resource

OSC Command Implemented Nova command
os show resource
    <hostname>
no
nova describe-resource
    <hostname>

secgroup

OSC Command Implemented Nova command
os secgroup add

(see server add secgroup)
no
nova add-secgroup
    <server>
    <secgroup>
os secgroup create
    [--description <description>]
    <name>
yes
nova secgroup-create
    <name>
    <description>
os secgroup delete
    <group>
yes
nova secgroup-delete
    <secgroup>
os secgroup list
    [--all-projects]
yes
nova secgroup-list
     [--all-tenants [<0|1>]]
os secgroup remove

(see server remove secgroup)
no
nova remove-secgroup
    <server>
    <secgroup>
os secgroup set
    [--name <new-name>]
    [--description [<new-description>]
    <group>
yes
nova secgroup-update
    <secgroup>
    <name>
    <description>
os secgroup show
    <group>
yes
n/a

secgroup-group-rule

OSC Command Implemented Nova command
os secgroup group rule create
    [--proto <protocol>]
    [--port <port>:<port>]
    <source-group>
    <secgroup>
no
nova secgroup-add-group-rule
    [--ip_proto <ip_proto>]
    [--from_port <from_port>]
    [--to_port <to_port>]
    <secgroup>
    <source_group>
os secgroup group rule delete
    [--proto <protocol>]
    [--port <port>:<port>]
    <source-group>
    <secgroup>
no
nova secgroup-delete-group-rule
    [--ip_proto <ip_proto>]
    [--from_port <from_port>]
    [--to_port <to_port>]
    <secgroup>
    <source_group>

secgroup-rule

OSC Command Implemented Nova command
os secgroup rule create
    [--proto <proto>]
    [--src-ip <ip-address>]
    [--dst-port <port-range>]
    <group>
no
nova secgroup-add-rule
    <secgroup>
    <ip_proto>
    <from_port>
    <to_port>
    <cidr>
os secgroup rule delete
    [--proto <proto>]
    [--src-ip <ip-address>]
    [--dst-port <port-range>]
    <group>
no
nova secgroup-delete-rule
    <secgroup>
    <ip_proto>
    <from_port>
    <to_port>
    <cidr>
os secgroup rule list
    <group>
no
nova secgroup-list-rules
    <secgroup>

server

OSC Command Implemented Nova command
os server add secgroup
    <server>
    <group>
no
nova add-secgroup
    <server>
    <secgroup>
os server create
    --image <image>
    --flavor <flavor>
    [--security-group <security-group-list> [...] ]
    [--key-name <key-name>]
    [--meta-data <key=value> [...] ]
    [--file <dest-filename=source-filename>] [...] ]
    [--user-data <user-data>]
    [--availability-zone <zone-name>]
    [--block-device-mapping <dev-name=mapping> [...] ]
    [--nic <net-id=net-uuid,v4-fixed-ip=ip-addr> [...] ]
    [--hint <key=value> [...] ]
    [--config-drive <value>|True ]
    [--min <count>]
    [--max <count>]
    [--wait]
    <server-name>
yes
nova boot
    [--flavor <flavor>]
    [--image <image>]
    [--meta <key=value>]
    [--file <dst-path=src-path>]
    [--key_name <key_name>]
    [--user_data <user-data>]
    [--availability_zone <availability-zone>]
    [--security_groups <security_groups>]
    [--block_device_mapping <dev_name=mapping>]
    [--hint <key=value>]
    [--nic <net-id=net-uuid,v4-fixed-ip=ip-addr>]
    [--config-drive <value>]
    [--poll]
    <name>
os server delete
    <server>
yes
nova delete
    <server>
os server list
    [--reservation-id <reservation-id>] 
    [--ip <ip-regex>]
    [--ip6 <ip6-regex>] 
    [--name <name-regex>]
    [--instance-name <instance-name-regex>] 
    [--status <status>]
    [--flavor <flavor>]
    [--image <image>] 
    [--host <hostname>]
    [--all-tenants]
yes
nova list
    [--reservation_id <reservation_id>] 
    [--ip <ip_regexp>]
    [--ip6 <ip6_regexp>] 
    [--name <name_regexp>]
    [--instance_name <name_regexp>] 
    [--status <status>]
    [--flavor <flavor>] [--image <image>] 
    [--host <hostname>]
    [--all_tenants [<0|1>]]
os server lock
    <server>
no
nova lock
    <server>
os server migrate
    --live
    [--block_migrate]
    [--disk_over_commit]
    <server>
    <host>

os server migrate
    [--wait]
    <server>
no
nova live-migration
    [--block_migrate] 
    [--disk_over_commit]
    <server>
<host>

nova migrate
    [--poll]
    <server>
os server pause
    <server>
yes
nova pause
    <server>
os server reboot
    [--hard | --soft]
    [--wait]
    <server>
yes
nova reboot
    [--hard]
    [--poll]
    <server>
os server rebuild
    --image <image>
    [--password <password>] 
    [--wait]
    <server>
yes
nova rebuild
    [--rebuild_password <rebuild_password>] 
    [--poll]
    <server>
    <image>
os server remove secgroup
    <server>
    <group>
no
nova remove-secgroup
    <server>
    <secgroup>
os server rename
    <server>
    <new-name>
no
nova rename
    <server>
    <name>
os server rescue
    <server>
no
nova rescue
    <server>
os server resize
    --flavor <flavor>
    [--wait]
    <server>
no
nova resize
    [--poll]
    <server>
    <flavor>
os server resize
    --confirm
    <server>
no
nova resize-confirm
    <server>
os server resume
    <server>
yes
nova resume
    <server>
os server set
    --meta-data <key=value>
    [--meta-data <key=value>] ...
    <server>
os unset server
    --meta-data <key>
    [--meta-data <key>] ...
    <server>
no
nova meta
    <server>
    <action>
    <key=value>
    [<key=value> ...]
os server set
    --root-password
    <server>
no
nova root-password
    <server>
os server show
    <server>
yes
nova show
    <server>
os server ssh
    [--port PORT]
    --private]
    [--ipv6]
    [--login <login>]
    <server>
no
nova ssh
    [--port PORT]
    [--private]
    [--ipv6]
    [--login <login>]
    <server>
os server suspend
    <server>
yes
nova suspend
    <server>
os server unlock
    <server>
no
nova unlock
    <server>
os server unpause
    <server>
yes
nova unpause
    <server>
os server unrescue
    <server>
no
nova unrescue
    <server>

usage

OSC Command Implemented Keystone command
os usage list
    [--start <start>]
    [--end <end>]
no
nova usage-list
    [--start <start>]
    [--end <end>]


volume

OSC Command Implemented Keystone command
os volume attach
    <volume>
    <server>
    <device>
no
nova volume-attach
    <server>
    <volume>
    <device>
os volume detach
    <server>
    <volume>
no
nova volume-detach
    <server>
    <volume>


x509-cert

See credentials in the cross API section.

x509-root-cert

See credentials in the cross API section.

Image

OSC Option Environment Variable Glance Option Environment Variable
--os-image-api-version <ver> OS_IMAGE_API_VERSION --os-image-api-version <ver> OS_IMAGE_API_VERSION
--os-service-type <type> OS_SERVICE_TYPE
--os-endpoint-type <type> OS_ENDPOINT_TYPE
--os-token <token> OS_TOKEN --os-auth-token <token> OS_AUTH_TOKEN
--os-url <url> OS_URL --os-image-url <url> OS_IMAGE_URL
--os-cacert <file> OS_CACERT
--cert-file <file> CERT_FILE
--key-file <key-file> KEY_FILE
--no-ssl-compression


API v1

image

OSC Command Implemented Glance command
os image create
    [--id <id>]
    [--store <store>]
    [--container-format <format>]
    [--disk-format <format>]
    [--owner <tenant>]
    [--size <size-bytes>]
    [--min-disk <disk-gb>]
    [--min-ram <ram-mg>]
    [--location <image-url>]
    [--copy-from <image-url>]
    [--file <local-filename>]
    [--checksum <checksum>]
    [--protected | --unprotected]
    [--public | --private]
    [--property <key=value>]
    <name>
yes
glance image-create
    [--id <IMAGE_ID>]
    [--name <NAME>]
    [--disk-format <DISK_FORMAT>]
    [--container-format <CONTAINER_FORMAT>]
    [--owner <TENANT_ID>]
    [--size <SIZE>]
    [--min-disk <DISK_GB>]
    [--min-ram <DISK_RAM>]
    [--location <IMAGE_URL>]
    [--checksum <CHECKSUM>]
    [--copy-from <IMAGE_URL>]
    [--is-public [True|False]]
    [--is-protected [True|False]]
    [--property <key=value>]
    [--human-readable]
os image delete
    <image>
yes
glance image-delete
    <IMAGE_ID>
os image list
    [--page-size <size>]
yes
glance image-list
os image save
    [--file <filename>]
    <image>
yes
glance image-download
    [--file <FILE>]
    <IMAGE>
os image set
    [--name <name>]
    [--owner <tenant>]
    [--min-disk <disk-gb>]
    [--min-ram <ram-mg>]
    [--protected | --unprotected]
    [--public | --private]
    [--property <key=value>]
    <image>
yes
glance image-update
    [--name <NAME>]
    [--disk-format <DISK_FORMAT>]
    [--container-format <CONTAINER_FORMAT>]
    [--owner <TENANT_ID>]
    [--size <SIZE>]
    [--min-disk <DISK_GB>]
    [--min-ram <DISK_RAM>]
    [--location <IMAGE_URL>]
    [--file <FILE>]
    [--checksum <CHECKSUM>]
    [--copy-from <IMAGE_URL>]
    [--is-public [True|False]]
    [--is-protected [True|False]]
    [--property <key=value>]
    [--purge-props]
    [--human-readable]
    <IMAGE>
os image show
    <image>
yes
glance image-show
    [--human-readable]
    <IMAGE>

API v2

image

OSC Command Implemented Glance command
os image delete
    <image>
yes
glance image-delete
    <IMAGE_ID>
os image list
    [--page-size <size>]
yes
glance image-list
no
glance member-images
    [options]
    <MEMBER>
os image save
    [--file <filename>]
    <image>
yes
glance image-download
    [--file <FILE>]
    <IMAGE>
os image set
    [--id <id>]
    [--store <store>]
    [--container-format <format>]
    [--disk-format <format>]
    [--owner <tenant>]
    [--size <size-bytes>]
    [--min-disk <disk-gb>]
    [--min-ram <ram-mg>]
    [--location <image-url>]
    [--copy-from <image-url>]
    [--file <local-filename>]
    [--checksum <checksum>]
    [--protected | --unprotected]
    [--public | --private]
    [--property <key=value>]
    <name>
no
glance image-update
    [--name <NAME>]
    [--disk-format <DISK_FORMAT>]
    [--container-format <CONTAINER_FORMAT>]
    [--owner <TENANT_ID>]
    [--size <SIZE>]
    [--min-disk <DISK_GB>]
    [--min-ram <DISK_RAM>]
    [--location <IMAGE_URL>]
    [--file <FILE>]
    [--checksum <CHECKSUM>]
    [--copy-from <IMAGE_URL>]
    [--is-public [True|False]]
    [--is-protected [True|False]]
    [--property <key=value>]
    [--purge-props]
    [--human-readable]
    <IMAGE>
os image show
    <image>
yes
glance image-show
    [--human-readable]
    <IMAGE>


image-member

Need to discuss the future of these commands with markwash...

glance member-create [--can-share] <IMAGE_ID> <TENANT_ID>

os create image-member ...


glance member-delete <IMAGE_ID> <TENANT_ID>

os list image-member <image> [options]


glance member-delete [options] <ID> <MEMBER>

os delete image-member ...


glance member-list [--image-id <IMAGE_ID>] [--tenant-id <TENANT_ID>]

os list image-member ...

Volume

Cinder Option Environment Variable OSC Option Environment Variable
--os-volume-api-version <ver> OS_VOLUME_API_VERSION --os-volume-api-version <ver> OS_VOLUME_API_VERSION
--service-type <type>
--service-name <name> CINDER_SERVICE_NAME
--volume-service-name <name> CINDER_VOLUME_SERVICE_NAME
--endpoint-type <type> CINDER_ENDPOINT_TYPE
--retries <int>


API v1.0

limits

See limits in the cross API section.

quota

See quota in the cross API section.

snapshot

OSC Command Implemented Cinder command
os snapshot create
    --name <name>
    [--description <description>]
    [--force]
    <volume>
yes
cinder snapshot-create
    --force <True|False>
    --display-name <display-name>
    --display-description <display-description>
    <volume-id>
os snapshot delete
    <snapshot>
yes
cinder snapshot-delete
    <snapshot-id>
os snapshot list
yes (no opts yet)
cinder snapshot-list 
    --all-tenants [<0|1>]
    --display-name <display-name>
    --status <status>
    --volume-id <volume-id>
os snapshot set
    [--name <new-name>]
    [--description <new-description>]
    <snapshot>
yes
cinder snapshot-rename
    --display-description <display-description>
    --display-name <display-name>
    <snapshot-id>
os snapshot show
    <snapshot>
yes
cinder snapshot-show
    <snapshot-id>

volume

OSC Command Implemented Cinder command
os volume create
    --size <size>
    [--description <description>]
    [--volume-type <volume-type>]
    [--snapshot-id <snapshot-id>]
    [--source <volid>]
    [--image <image-id>]
    [--availability-zone <availability-zone>]
    [--property <key=value>]
    [--user <user>]           # admin only
    [--project <project>]     # admin only
    <name>
yes
cinder create
    [--snapshot-id <snapshot-id>]
    [--source-volid <source-volid>]
    [--image-id <image-id>]
    [--display-name <display-name>]
    [--display-description <display-description>]
    [--volume-type <volume-type>]
    [--availability-zone <availability-zone>]
    [--metadata <key=value>]
    <size>
os volume delete
    [--force]
    <volume>
yes
cinder delete
    <volume-id>

cinder force-delete
    <volume-id>
os volume list
    [--name <name>]
    [--status <status>]
    [--long]
    [--all-tenants]           # admin only
yes
cinder list 
    --all-tenants [<0|1>]
    --display-name <display-name>
    --status <status>
os volume set
    [--name <new-name>]
    [--description <new-description>]
    [--property <key=value>]
    <volume>
yes
cinder metadata
    <volume-id>
    <action>
    <key=value>

cinder rename
    --display-description <display-description>
    <volume-id>
    <display-name>
os volume show
    <volume>
yes
cinder show
    <volume-id>
os volume unset
    [--property <key=value>]
    <volume>
yes

volume-type

OSC Command Implemented Cinder command
os volume type create
    [--property <key=value>]
    <name>
yes
cinder type-create
    <type-name>
os volume type delete
    <volume-type>
yes
cinder type-delete
    <type-id>
os volume type list
    [--long]
yes
cinder type-list 

cinder extra-specs-list
os volume type set
    [--property <key=value>]
    <volume-type>
yes
cinder type-key
    <type-id>
    <set>
    <key=value>
os volume type unset
    [--property <key>]
    <volume-type>
yes
cinder type-key
    <type-id>
    <unset>
    <key>

Network

The Network commands in quantum have been in a bit of flux and are currently out of scope for OpenStackClient.

Command-line Option Environment Variable
--host=HOST
--port=PORT
--ssl
--verbose
--logfile=LOGFILE
--token=TOKEN
--version=VERSION QUANTUM_VERSION


API v2.0

  • Verbs:
    • quantum: create, delete, list, plug, show, update, unplug
    • os: add, create, delete, list, remove, set, show
  • Objects:
    • quantum: iface, net, port
    • os: interface, network, port

iface

plug_iface <tenant-id> <net-id> <port-id> <iface-id>

add interface <tenant> <network> <port> <interface>


show_iface <tenant-id> <net-id> <port-id>

show interface <tenant> <network> <port>


unplug_iface <tenant-id> <net-id> <port-id>

remove interface <tenant> <network> <port>


net

create_net <tenant-id> <net-name>

create network <tenant> <network-name>


delete_net <tenant-id> <net-id>

delete <tenant> <network>


list_nets <tenant-id>

list network <tenant>


list_nets_detail <tenant-id>

list network --detail <tenant>


show_net <tenant-id> <net-id>

show network <tenant> <network>


show_net_detail <tenant-id> <net-id>

show network --detail <tenant> <network>


update_net <tenant-id> <net-id> <new-name>

set network <tenant> <network> --name <name>


port

create_port <tenant-id> <net-id>

create port <tenant> <network>


delete_port <tenant-id> <net-id> <port-id>

delete port <tenant> <network> <port>


list_ports <tenant-id> <net-id>

list port <tenant> <network>


list_ports_detail <tenant-id> <net-id>

list port --detail <tenant> <network>


show_port <tenant-id> <net-id> <port-id>

show port <tenant> <network> <port>


show_port_detail <tenant-id> <net-id> <port-id>

show port --detail <tenant> <network> <port>


update_port <tenant-id> <net-id> <port-id> <params>

set port <tenant> <network> <port> <params>

Options

In general, options will be transformed into more UNIX-like usage

  • --enable true|false becomes --enable|--disable

(dhellmann) Not all boolean options have natural antonyms like enable/disable. It may be more consistent to use a --flag --no-flag style naming convention to indicate the opposites of flags.

"(dtroyer) Yup, except i really don't like --no-enable. I'm going to work through the switch mapping to see how many others we really have to deal with."