summaryrefslogtreecommitdiffstats
path: root/heat.yaml
blob: d4c3eefc3ec90609f78788976881689fb3842b62 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
HeatTemplateFormatVersion: '2012-12-12'
Description: 'Heat Engine and API'
Parameters:
  KeyName: 
    Description: Name of an existing EC2 KeyPair to enable SSH access to the instances
    Type: String
    Default: default
  InstanceType:
    Description: Use this flavor
    Type: String
    Default: bm.small
  HeatUser:
    Description: Heat database username.
    Type: String
    Default: heat
  HeatEngineImage:
    Type: String
  HeatApiImage:
    Type: String
  RabbitMQHost:
    Description: Host for RabbitMQ
    Type: String
  RabbitMQPassword:
    Description: Password for RabbitMQ
    Type: String
  ApiGroupSize:
    Description: How many API nodes to run
    Type: Integer
    Default: 1
  AvailabilityZones:
    Type: List
    Default: [ 1 ]
Resources:
  EngineAccessPolicy:
    Type: OS::Heat::AccessPolicy
    Properties:
      AllowedResources: [ HeatEngine ]
  EngineUser:
    Type: AWS::IAM::User
    Properties:
      Policies: [ { Ref: EngineAccessPolicy } ]
  EngineKey:
    Type: AWS::IAM::AccessKey
    Properties:
      UserName:
        Ref: EngineUser
  ApiAccessPolicy:
    Type: OS::Heat::AccessPolicy
    Properties:
      AllowedResources: [ HeatAPI, HeatAPILaunch ]
  ApiUser:
    Type: AWS::IAM::User
    Properties:
      Policies: [ { Ref: ApiAccessPolicy } ]
  ApiKey:
    Type: AWS::IAM::AccessKey
    Properties:
      UserName:
        Ref: ApiUser
  HeatAPILaunch:
    Type: AWS::AutoScaling::LaunchConfiguration
    Metadata:
      OpenStack::ImageBuilder::Elements: [ heat-api ]
      heat:
        rpc_backend: heat.openstack.common.rpc.impl_kombu
        rabbit:
          host: {Ref: RabbitMQHost}
          password: {Ref: RabbitMQPassword}
        access_key_id:
          Ref: ApiKey
        secret_key:
          Fn::GetAtt: [ ApiKey, SecretAccessKey ]
        stack:
          name: {Ref: 'AWS::StackName'}
          region: {Ref: 'AWS::Region'}
        refresh:
          - resource: HeatAPILaunch
    Properties:
      ImageId:
        {Ref: HeatApiImage}
      InstanceType: {Ref: InstanceType}
      KeyName: {Ref: KeyName}
  HeatAPI:
    Type: OS::Heat::InstanceGroup
    Properties:
      LaunchConfiguration: {Ref: HeatApiLaunch}
      Size: {Ref: ApiGroupSize}
      AvailabilityZones: {Ref: AvailabilityZones}
  HeatEngine:
    Type: AWS::EC2::Instance
    Properties:
      ImageId:
        {Ref: HeatEngineImage}
    Metadata:
      OpenStack::Role: stateful
      OpenStack::ImageBuilder::Elements: [ heat-engine ]
      heat:
        rpc_backend: heat.openstack.common.rpc.impl_kombu
        rabbit:
          host: {Ref: RabbitMQHost}
          password: {Ref: RabbitMQPassword}
        access_key_id:
          Ref: EngineKey
        secret_key:
          Fn::GetAtt: [ EngineKey, SecretAccessKey ]
        stack:
          name: {Ref: 'AWS::StackName'}
          region: {Ref: 'AWS::Region'}
        refresh:
          - resource: HeatEngine