# Openstack driver privatekeyFile location and safety

**URL:** <https://forums.suse.com/t/openstack-driver-privatekeyfile-location-and-safety/10950>\
**Category:** SUSE Rancher Prime\
**Created:** [June 29, 2018, 5:38am UTC](https://forums.suse.com/t/openstack-driver-privatekeyfile-location-and-safety/10950 "2018-06-29T05:38:55Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![divyangjp](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/divyangjp/32/4241_2.png) [@divyangjp](https://forums.suse.com/u/divyangjp)\
**Post date:** [June 29, 2018, 5:38am UTC](https://forums.suse.com/t/openstack-driver-privatekeyfile-location-and-safety/10950/1 "2018-06-29T05:38:55Z")

</div>

Hi,  
I’ve setup Rancher-2.0 in HA mode with 3 nodes.  
Openstack driver needs absolute path to SSH private key file.  
Where exactly I need to put this file in.  
Does it also mean that, user will have to share their Private Keys with Admins to put them on Rancher servers?

-Regards,  
Divyang

---

<div class="post-metadata">

**Author:** ![amioranza](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/amioranza/32/3053_2.png) [@amioranza](https://forums.suse.com/u/amioranza)\
**Post date:** [June 29, 2018, 5:18pm UTC](https://forums.suse.com/t/openstack-driver-privatekeyfile-location-and-safety/10950/2 "2018-06-29T17:18:48Z")

</div>

Hi @divyangjp,

It needs to be inside the Rancher container, anywhere inside where you can specify the path.

Using Rancher in 3 node setup you have K8s cluster running, you can do it using secrets and mounting it as a file inside Rancher container.

Att,

---

<div class="post-metadata">

**Author:** ![divyangjp](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/divyangjp/32/4241_2.png) [@divyangjp](https://forums.suse.com/u/divyangjp)\
**Post date:** [July 2, 2018, 1:53am UTC](https://forums.suse.com/t/openstack-driver-privatekeyfile-location-and-safety/10950/3 "2018-07-02T01:53:22Z")

</div>

Hi @amioranza  
Thanks for replying.  
But can you be more technically specific about the steps?

-Divyang

---

<div class="post-metadata">

**Author:** ![amioranza](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/amioranza/32/3053_2.png) [@amioranza](https://forums.suse.com/u/amioranza)\
**Post date:** [July 3, 2018, 7:46pm UTC](https://forums.suse.com/t/openstack-driver-privatekeyfile-location-and-safety/10950/4 "2018-07-03T19:46:13Z")

</div>

For sure,

First you need to create a new secret on cattle-system namespace with this command:

`kubectl create secret generic my-private-key --from-file=ssh-privatekey=~/.ssh/id_rsa`

With the secret OK in your cattle-system namespace you have to update the rancher deployment. You can get the current yaml of your deployment with this command:

`kubectl get deployment cattle -n cattle-system -o yaml`

Now with the yaml you need to do some cleanup to remove the fields that k8s api create automatically and add two new sessions, first the mount of the key on some path and second the volume based on the created secret:  
Volume mount:

> ```
> volumeMounts:
> ...
> - mountPath: /tmp/ssh/id_rsa
> name: my-private-key
> readOnly: true
> 
> ```

Volumes:

> ```
> volumes:
> - name: my-private-key-volume
> secret:
> defaultMode: 420
> secretName: my-private-key
> 
> ```

With all ready apply the deployment again:

`kubectl apply -f rancher-deployment.yaml -n cattle-system`

Now you need to test the deploy specifying the private key of you Openstack template as /tmp/ssh/id\_rsa.

Att,

---

<div class="post-metadata">

**Author:** ![divyangjp](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/divyangjp/32/4241_2.png) [@divyangjp](https://forums.suse.com/u/divyangjp)\
**Post date:** [July 4, 2018, 12:24am UTC](https://forums.suse.com/t/openstack-driver-privatekeyfile-location-and-safety/10950/5 "2018-07-04T00:24:33Z")

</div>

@amioranza Perfect. Thanks for taking time to give complete example. 🙂

---

<div class="post-metadata">

**Author:** ![Ian\_Zhang](https://avatars.discourse-cdn.com/v4/letter/i/74df32/32.png) [@Ian\_Zhang](https://forums.suse.com/u/Ian_Zhang)\
**Post date:** [August 5, 2018, 6:40am UTC](https://forums.suse.com/t/openstack-driver-privatekeyfile-location-and-safety/10950/6 "2018-08-05T06:40:16Z")

</div>

Thanks @amioranza, unfortunately, i tried your approach and i got below errors, first, i got validation error saying “defaultMode” and “secretName” are unknown fields.  
_error: error validating “rancher-deployment.yaml”: error validating data: [ValidationError(Deployment.spec.template.spec.volumes[0]): unknown field “defaultMode” in io.k8s.api.core.v1.Volume, ValidationError(Deployment.spec.template.spec.volumes[0]): unknown field “secretName” in io.k8s.api.core.v1.Volume]; if you choose to ignore these errors, turn validation off with --validate=false_

after i removed those fields and re-apply again. i got  
_The Deployment “cattle” is invalid: spec.template.spec.containers[0].volumeMounts[0].name: Not found: “my-private-key”_

seems like cattle-system can not support volume mount well, any further instructions?  
Thanks a lot!

Rancher version **v2.0.6**

---

<div class="post-metadata">

**Author:** ![DJAyth](https://avatars.discourse-cdn.com/v4/letter/d/bcef8e/32.png) [@DJAyth](https://forums.suse.com/u/DJAyth)\
**Post date:** [April 23, 2019, 2:24pm UTC](https://forums.suse.com/t/openstack-driver-privatekeyfile-location-and-safety/10950/7 "2019-04-23T14:24:09Z")

</div>

Just ran into this issue myself when working with 2.2 as a test case.

I setup the environment via the HA Install, and tried to deploy a cluster via Openstack. I found a way around it via the GUI. You can get a shell in the cattle pod via the GUI and from there you can put in the file. I had to install the nano text editor to be able to create the file, but from there I was able to get it created and provision the cluster.

Outside of the GUI I tried many different ways to get into the thing but with no luck.

---

<div class="post-metadata">

**Author:** ![anthony](https://avatars.discourse-cdn.com/v4/letter/a/49beb7/32.png) [@anthony](https://forums.suse.com/u/anthony)\
**Post date:** [April 30, 2019, 7:37pm UTC](https://forums.suse.com/t/openstack-driver-privatekeyfile-location-and-safety/10950/8 "2019-04-30T19:37:51Z")

</div>

Actually, you don’t need to go all the way that far.

Easier way is to NOT specify privateKeyFile at all. In this case Rancher would generate its own security key, one per node, upload the public part of it into Openstack and use it to provision the VMs. Magic.

---

<div class="post-metadata">

**Author:** ![schuhm](https://avatars.discourse-cdn.com/v4/letter/s/a88e4f/32.png) [@schuhm](https://forums.suse.com/u/schuhm)\
**Post date:** [May 22, 2019, 8:37am UTC](https://forums.suse.com/t/openstack-driver-privatekeyfile-location-and-safety/10950/9 "2019-05-22T08:37:39Z")

</div>

A hybrid model is NOT to specify privateKeyFile at all, like @anthony says, so that Rancher creates a dedicated key for sshUser for each server. But then nevertheless, adding a user-data file and create an account with ssh\_authorized\_keys, so that you can still access all nodes without downloading a dedicated key for each host.

---

<div class="post-metadata">

**Author:** ![11120](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/11120/32/7029_2.png) [@11120](https://forums.suse.com/u/11120)\
**Post date:** [December 26, 2020, 11:06am UTC](https://forums.suse.com/t/openstack-driver-privatekeyfile-location-and-safety/10950/10 "2020-12-26T11:06:12Z")

</div>

@anthony good job, but create secret should be in the cattle-system.
