Skip to content

Install OpenStack Client

How-to · Updated Jun 2026

Coming from another cloud?

▸DigitalOcean·Personal Access Tokens

Personal Access Tokens (PATs) and OAuth2 applicationshigh

  • DigitalOcean PATs are account-scoped (access all resources across all projects for that account) with a choice of read or read/write scope. OpenStack application credentials are project-scoped and tied to a specific set of roles.
  • DO supports OAuth2 for third-party app authorization (apps request access on behalf of a user). OpenStack Keystone supports OAuth1.0 for delegated token issuance; full OAuth2 support depends on the Keystone deployment.
  • DO PATs can be set to expire (custom expiry date) or be non-expiring. Keystone token TTL is server-configured, not per-credential.
  • DO does not support service accounts independent of a user identity. OpenStack application credentials survive user password changes and can be restricted to specific API operations via access rules.
DigitalOcean docs ↗
▸Hetzner·API Token

API Tokens (project-scoped Bearer tokens)high

  • Hetzner API tokens are project-scoped: each token is valid only for the project it was created in and must be separately generated per project. OpenStack Keystone application credentials are user-scoped and can be used across projects when the user has appropriate roles.
  • Hetzner has no OAuth2/OIDC integration for API access; all programmatic access requires a static bearer token. Keystone supports OIDC federation, LDAP backends, and federated identity (SAML2).
  • Hetzner tokens have no built-in expiry and must be manually rotated; there is no token TTL or refresh concept. Keystone tokens have configurable TTLs (default 1 hour) and support re-authentication.
  • Hetzner tokens are either read-only or read-write with no fine-grained scope. OpenStack roles (admin, member, reader) provide service-level access control per project.
Hetzner docs ↗

Install OpenStack Client

OpenStack client is a tool you can install on your local computer. Using the client, you'll be able to run commands on services in your Quake AI projects.

OpenStack Client runs in your terminal application as a command line tool.

If your local machine runs Windows, set up a Linux-compatible shell environment first. See Set up a Linux CLI environment on Windows.

This guide covers:

  • Install Python (if not already installed).
  • Install OpenStack client.

Note: Python is a programming language required to run OpenStack client. This example demonstrates one way to install and work with Python. You can decide to use other ways depending on your requirements and setup.

Install Python#

  1. Open the Terminal application.
  2. Use a package manager such as Homebrew to install Python3.
  3. If Homebrew is not already installed, type the following command into your terminal.
bash
/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)"
  1. Type the following command into your terminal.
bash
brew install python
  1. Verify your version.
bash
python3 --version

Install OpenStack command line tools client#

  1. Type the following command in your terminal:
bash
pip3 install python-openstackclient python-heatclient python-magnumclient

This installs the base OpenStack client along with service-specific plugins for Automation (Heat) and Kubernetes (Magnum). Without these plugins, commands for those services will not be recognized.

Next steps#

Set up an openrc.sh file After installing OpenStack client, you can use an openrc.sh file to authenticate into Quake AI. An openrc.sh file is a configuration file that stores authentication credentials and environment information. You can download this file from Quake AI.

See also#

Usage Guidelines

The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.

For the full policy, see Usage Guidelines.

Last validated: 03.06.2026

Was this page helpful?