# Service Endpoints

Source: https://docs.quake.ai/docs/tools/service-endpoints
Markdown: https://docs.quake.ai/docs/tools/service-endpoints.md

---

# Service endpoints

Quake AI exposes supported OpenStack services at dedicated hostnames following the pattern `{service}.{region}.rumble.cloud`. This page lists the public service endpoint base URLs and explains how to configure them for CLI, SDK, and Terraform use.

Quake AI runs OpenStack {OPENSTACK_RELEASE}. When referencing upstream OpenStack documentation, use the Antelope release notes and API guides.

## Regions

Quake AI operates in three production regions:

| Region ID | Location | Console URL |
|---|---|---|
| `us-east-1` | US East | `https://sky.us-east-1.rumble.cloud` |
| `us-east-2` | US East | `https://sky.us-east-2.rumble.cloud` |
| `us-west-1` | US West | `https://sky.us-west-1.rumble.cloud` |

Each region is an independent OpenStack deployment with its own service catalog and data residency. Resources created in one region are not visible in another. Identity is the exception: a single non-regional Keystone endpoint (`https://keystone.rumble.cloud`) issues tokens for all three regions.

## Endpoint reference

Replace `{region}` with your region ID (e.g., `us-east-1`). The examples below use `us-east-1`; substitute your region as needed.

| Quake AI service | OpenStack project | Base URL | Notes |
|---|---|---|---|
| Compute | Nova | `https://compute.{region}.rumble.cloud/v2.1` | Microversion ceiling 2.93 |
| Network | Neutron | `https://network.{region}.rumble.cloud` | |
| Block Storage | Cinder v3 | `https://volume.{region}.rumble.cloud/v3/{PROJECT_ID}` | Project-scoped path |
| Images | Glance | `https://image.{region}.rumble.cloud` | |
| Object Storage (Swift) | Swift | `https://object.{region}.rumble.cloud/swift/v1/AUTH_{PROJECT_ID}` | Native Swift protocol |
| Object Storage (S3) | S3 gateway | `https://object.{region}.rumble.cloud` | S3-compatible API on the same host |
| Identity | Keystone | `https://keystone.rumble.cloud` | Auth URL: `https://keystone.rumble.cloud/v3`. The Keystone hostname has no `{region}` segment. |
| Orchestration | Heat | `https://orchestration.{region}.rumble.cloud/v1/{PROJECT_ID}` | Project-scoped path |
| CloudFormation | Heat CFN | `https://cloudformation.{region}.rumble.cloud/v1` | AWS CloudFormation-compatible API |
| Container Infrastructure | Magnum | `https://container-infra.{region}.rumble.cloud/v1` | Kubernetes cluster management |

Replace `{PROJECT_ID}` with your OpenStack project ID. You can find it in the console under **API** > **API Endpoints**, or by running `openstack project show -f value -c id`.

## Hostname pattern

All service endpoints use the convention:

```text
https://{service-name}.{region}.rumble.cloud
```

Where:
- `{service-name}` is the OpenStack service hostname (e.g., `compute`, `network`, `volume`)
- `{region}` is one of `us-east-1`, `us-east-2`, or `us-west-1`

This differs from many OpenStack deployments that use a single endpoint with path-based routing. Quake AI's per-service hostnames simplify firewall rules and certificate management.

## S3 and Swift dual-protocol access

Object storage at `object.{region}.rumble.cloud` serves both protocols:

- **Swift**: native OpenStack protocol at `/swift/v1/AUTH_{PROJECT_ID}`. Used by the `openstack` CLI and Swift SDKs. Supports Swift-native ACLs and container metadata.
- **S3**: compatible API at the root path. Used by AWS SDKs, `s3cmd`, `rclone`, and any S3-compatible tooling. Requires [S3 credentials](/docs/tools/s3-credentials) (separate from OpenStack application credentials).

Both protocols access the same underlying storage. Objects created via Swift are visible via S3 and vice versa.

## Endpoint discovery

Most users do not need to configure individual endpoints. The OpenStack CLI and SDKs auto-discover service URLs via the **Keystone service catalog**:

1. You authenticate against the Keystone auth URL (`https://keystone.rumble.cloud/v3`)
2. Keystone returns a token that includes a service catalog
3. The CLI/SDK reads the catalog to find each service's public endpoint

This means your `clouds.yaml` or `openrc.sh` only needs the auth URL; the CLI resolves everything else automatically.

The endpoint table above is for users who need explicit URLs: Terraform provider configuration, custom HTTP clients, firewall allowlists, or debugging.

## `clouds.yaml` configuration

Drop this file into `~/.config/openstack/clouds.yaml` to configure the OpenStack CLI and Python SDKs:

```yaml
clouds:
  quakeai:
    auth:
      auth_url: https://keystone.rumble.cloud/v3
      application_credential_id: YOUR_CREDENTIAL_ID
      application_credential_secret: YOUR_CREDENTIAL_SECRET
    auth_type: v3applicationcredential
    region_name: us-east-1  # us-east-1 | us-east-2 | us-west-1
    interface: public
    identity_api_version: 3
```

Then select the cloud in your shell:

```bash
export OS_CLOUD=quakeai
openstack server list
```

Generate your application credential ID and secret at [Application credentials](/docs/tools/generate-app-credentials). The CLI discovers all other service endpoints from the Keystone catalog; you do not need to list them individually in `clouds.yaml`.



Store `clouds.yaml` securely. It contains your application credential secret. Do not commit it to version control. Add `clouds.yaml` to your `.gitignore`.



## Viewing endpoints in the console

The cloud console displays your project's service catalog at **API** > **API Endpoints** (`{CONSOLE_REGION_URL}/papi/endpoints`). This view shows the same endpoints listed above, resolved for your specific project. See [API Endpoints console](/docs/tools/api-endpoints) for the console reference.

## Related

- [API access console reference](/docs/tools/api-access-console): overview of all 4 views in the API console section
- [API Endpoints console](/docs/tools/api-endpoints): view endpoints in the cloud console
- [How Quake AI uses OpenStack](/resources/migration/openstack): service-to-project mapping and migration guidance
- [How to create application credentials](/docs/tools/generate-app-credentials): create credentials for CLI and API access
- [How to create S3 credentials](/docs/object/how-to/create-s3-credentials): create S3 access keys for object storage
- [How to get an API token](/docs/tools/api-tokens): generate project-scoped tokens
- [API Reference](/reference): full API documentation with curl examples
