- dnsmasq service needs to be debootstrapped on the controller
- Public IP needs to be moved to br-ex. Note, if this is done on the command-line, instead of in /etc/network/interfaces, keep in mind that you'll lose your default gateway when you do it.
- openvswitch-datapath-dkms must be installed on all nodes.
- Replace %SERVICE_TENANT_NAME%, %SERVICE_USER% and %SERVICE_PASSWORD% in /etc/neutron/metadata_agent.ini with the real values from the keystone_authtoken section of /etc/neutron/neutron.conf. See this bug for more. By the way, that same bug makes me think neutron_admin_auth_url in /etc/nova/nova.conf should be http://controller:5000/v2.0 instead of http://controller:35357/v2.0. Indeed, someone on IRC with working neutron says he uses 5000, and 5000 works for me too.
- Set auth_region to regionOne (not RegionOne) in /etc/neutron/metadata_agent.ini.
- Set service_neutron_metadata_proxy=true in /etc/nova/nova.conf.
For the love of all things holy, whatever you do, DO NOT specify a tenant name instead of id to "neutron net-create --tenant-id". That argument is not validated, and so you'll create a network that breaks the metadata service! Which totally fucks your whole cloud. https://bugs.launchpad.net/nova/+bug/1246258