Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1152644

Summary: QPID to rabbitmq migration guide - Access to vhost cinder refused for user cinder
Product: Red Hat OpenStack Reporter: Tzach Shefi <tshefi>
Component: doc-UpgradeAssignee: Don Domingo <ddomingo>
Status: CLOSED CURRENTRELEASE QA Contact: RHOS Documentation Team <rhos-docs>
Severity: high Docs Contact:
Priority: unspecified    
Version: 5.0 (RHEL 6)CC: ddomingo, tshefi, yeylon
Target Milestone: ---Keywords: Documentation
Target Release: 5.0 (RHEL 7)   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2014-10-22 11:06:56 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1141688    

Description Tzach Shefi 2014-10-14 15:20:05 UTC
Description of problem: While checking qpid to rabbitmq migration guide https://access.redhat.com/articles/1167113, Cinder service doesn't work, errors are logged on rabbitmq log. 

Tip -> access to vhost 'cinder' refused for user 'cinder'". 
So it turns out on deployments with rabbitmq as default amqp all services user vhost "/" and same user guest. 

When I compered this to guide, I noticed we create separate users per each service, as well as a vhost but only for Cinder called "cinder".

This too is fine, the only problem is the when we set permissions
 Step 4, procedure 2 sub step 3 -> 
Next, grant each of these RabbitMQ users read/write permissions to all resources:

The result is that all the users get permissions but to vhost "/", Cinder doesn't get permission to vhost "cinder" explaines rabbitmq log errors. 

Notice permissions:
[root@cougar01 ~]# rabbitmqctl list_permissions
Listing permissions in vhost "/" ...
cinder	.*	.*	.*
guest	.*	.*	.*
heat	.*	.*	.*
neutron	.*	.*	.*
nova	.*	.*	.*
...done.

No mention of Cinder vhost or setting permissions on it on migration guide. 

As a workaround: 
deleted vhost cinder # rabbitmqctl delete_vhost cinder
Changed cinder.conf to use vhost "/" rather then "cinder" 
# openstack-config --set /etc/cinder/cinder.conf DEFAULT rabbit_virtual_host /

Restarted Cinder and all working, plus clean rabbitmq logs. 


Version-Release number of selected component (if applicable):
RHEL 6.5 
rabbitmq-server-3.1.5-6.0.el6ost.noarch

How reproducible:
Every time, on three separate deployments. 

Steps to Reproduce:
1. AIO RHOS5 using packstack amqp=>qpid 
2. Follow qpid to rabbitmq migration guide
3. Check rabbitmq logs /var/log/rabbitmq/rabbit..log errors

=ERROR REPORT==== 14-Oct-2014::15:30:10 ===
closing AMQP connection <0.11721.0> (10.35.160.91:59798 -> 10.35.160.91:5672):
{handshake_error,opening,0,
                 {amqp_error,access_refused,
                             "access to vhost 'cinder' refused for user 'cinder'",
                             'connection.open'}}



Actual results:
Cinder service doesn't work, looking at rabbitmq logs I can see why

Expected results:
Cinder service should start up without errors on rabbitmq logs. 

Additional info: 
I find it confusing that as with the default rabbitmq deployment sets all services with vhost "/" and user guest. While on migration guide we decide that we should separate users per each group, plus a dedicated vhost for Cinder.

One last thing settings rabbitmq password in clear text on service config files is IMHO is a security risk. It might be a modest or low risk yet still a risk, not up to me to decide just bringing it up.

Comment 2 Don Domingo 2014-10-15 05:51:47 UTC
I corrected the step for assigning the cinder user's permissions to specify the 'cinder' vhost. 

FYI We added the step for creating the 'cinder' vhost as a result of https://access.redhat.com/support/cases/01190030 in BZ#1141688.

Comment 8 Tzach Shefi 2014-10-22 07:19:23 UTC
Great work. 
New guide for specific vhost per each service is a nice touch, went over it looks rock solid.