Heat scaling - are the scale up and down URLs authenticated?

asked 2015-01-08

dyasny

updated 2015-01-26

zaneb

When I use the standard template from github, two URLs are generated, one for up and one for down-scaling the stack. I can issue a POST call to each to trigger the scaling.

My question is, can those URLs be secured somehow, or can anyone just trigger them if they know the URL?


answered 2015-01-09

Everything in Openstack can be configured to use ssl:

Take a look at the sample heat.conf : heat.conf


# Options defined in heat.common.config

# Type of endpoint in Identity service catalog to use for
# communication with the OpenStack service. (string value)

# Optional CA cert file to use in SSL connections. (string
# value)

# Optional PEM-formatted certificate chain file. (string
# value)

# Optional PEM-formatted file that contains the private key.
# (string value)

# If set, then the server's certificate will not be verified.
# (boolean value)

It all depends on how you configure your Openstack installation.

SSL would have been my next question. What I am more interested in are credentials, htaccess or something of the sort, so that only the tenant will be able to POST to the up/down scale URLs

dyasny ( 2015-01-09 )

