Authentication considerations for multi-region object deployment

In a multi-region object deployment environment, all regions must use the same Keystone service.

The keystone service can be a local keystone installed with the object deployment or it can be an independent service. Subsequent clusters that join the environment must specify an external keystone server during installation.

The following two methods can be used for object authentication configuration with a multi-region setup:

Note: The installer can automatically create these endpoints if the option to configure the remote keystone is used during installation and –configure-remote-keystone is specified.