Where Does OpenStack Store clouds.yaml?
OpenStack clients read clouds.yaml (plus secure.yaml for secrets) from ~/.config/openstack, with /etc/openstack as the system fallback.
Last updated
OpenStack clients resolve clouds from YAML files in a fixed search order, and the user file almost always wins. The clouds.yaml file names clouds with auth URLs, regions, and interfaces. The optional secure.yaml beside it carries passwords and tokens with strict permissions.
That split is the whole secrets story. Commit clouds.yaml freely; guard secure.yaml like a password file because it is one. Environment variables override both per session, which suits CI better than files on shared runners.
Where OpenStack stores this, by platform
~/.config/openstack/clouds.yaml
Cloud definitions plus optional secure.yaml for secrets. OS_CLOUD selects the entry; the SDK merges system then user files. Keep secure.yaml at 0600 permissions.
~/.config/openstack/clouds.yaml
Same XDG layout on macOS for the unified clients. Homebrew installs read the identical paths; only the tool binaries move.
Frequently asked questions
Which cloud does my command actually use?
List ~/.config/openstack for clouds.yaml and secure.yaml. The SDK merges system (/etc) then user files, so a user entry wins. OS_CLOUD picks the cloud; --os-cloud overrides per command.
Can I commit clouds.yaml to a shared repo?
Split them: public cloud definitions in clouds.yaml, secrets in secure.yaml with tight permissions. The SDK reads both and merges, so version-controlling clouds.yaml stays safe.
Notice an outdated path? Let us know.