Book Image

Extending OpenStack

By : Omar Khedher
Book Image

Extending OpenStack

By: Omar Khedher

Overview of this book

OpenStack is a very popular cloud computing platform that has enabled several organizations during the last few years to successfully implement their Infrastructure as a Service (IaaS) platforms. This book will guide you through new features of the latest OpenStack releases and how to bring them into production straightaway in an agile way. It starts by showing you how to expand your current OpenStack setup and how to approach your next OpenStack Data Center generation deployment. You will discover how to extend your storage and network capacity and also take advantage of containerization technology such as Docker and Kubernetes in OpenStack. Additionally, you'll explore the power of big data as a Service terminology implemented in OpenStack by integrating the Sahara project. This book will teach you how to build Hadoop clusters and launch jobs in a very simple way. Then you'll automate and deploy applications on top of OpenStack. You will discover how to write your own plugin in the Murano project. The final part of the book will go through best practices for security such as identity, access management, and authentication exposed by Keystone in OpenStack. By the end of this book, you will be ready to extend and customize your private cloud based on your requirements.
Table of Contents (12 chapters)

All in one authentication hub

The concept of the federation offers a way of bringing different parties under one centralized umbrella. Most enterprises prefer to expose a unified platform to internal users within different service providers. One of the most common federation use cases are identity and authentication federation systems. An organization might have different services around its IT infrastructure that require authentication and authorization for each privileged user.

Implementing many database back-ends for each service would potentially increase a security risk to map several accounts for each user service. That can easily result in losing track of each individual account for each service when off-boarding a user. Additionally, managing identity separately for each service by a different system can be very confusing for users as well as it presents an administrative...