summaryrefslogtreecommitdiffstats
path: root/puppet/services/nova-api.yaml
blob: c2bd395e8fdd7e68aa3c8461bdda4162592adf31 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
heat_template_version: 2016-04-08

description: >
  OpenStack Nova API service configured with Puppet

parameters:
  ServiceNetMap:
    default: {}
    description: Mapping of service_name -> network name. Typically set
                 via parameter_defaults in the resource registry.  This
                 mapping overrides those in ServiceNetMapDefaults.
    type: json
  DefaultPasswords:
    default: {}
    type: json
  EndpointMap:
    default: {}
    description: Mapping of service endpoint -> protocol. Typically set
                 via parameter_defaults in the resource registry.
    type: json
  NovaWorkers:
    default: 0
    description: Number of workers for Nova API service.
    type: number
  NovaPassword:
    description: The password for the nova service and db account, used by nova-api.
    type: string
    hidden: true
  KeystoneRegion:
    type: string
    default: 'regionOne'
    description: Keystone region for endpoint

resources:
  NovaBase:
    type: ./nova-base.yaml
    properties:
      ServiceNetMap: {get_param: ServiceNetMap}
      DefaultPasswords: {get_param: DefaultPasswords}
      EndpointMap: {get_param: EndpointMap}

outputs:
  role_data:
    description: Role data for the Nova API service.
    value:
      service_name: nova_api
      config_settings:
        map_merge:
          - get_attr: [NovaBase, role_data, config_settings]
          - nova::api::osapi_compute_workers: {get_param: NovaWorkers}
            nova::api::metadata_workers: {get_param: NovaWorkers}
            nova::cron::archive_deleted_rows::hour: '"*/12"'
            nova::cron::archive_deleted_rows::destination: '"/dev/null"'
            tripleo.nova_api.firewall_rules:
              '113 nova_api':
                dport:
                  - 6080
                  - 13080
                  - 8773
                  - 3773
                  - 8774
                  - 13774
                  - 8775
            nova::keystone::authtoken::project_name: 'service'
            nova::keystone::authtoken::password: {get_param: NovaPassword}
            nova::keystone::authtoken::auth_uri: {get_param: [EndpointMap, KeystoneInternal, uri] }
            nova::keystone::authtoken::auth_url: {get_param: [EndpointMap, KeystoneAdmin, uri_no_suffix]}
            nova::api::enabled: true
            nova::api::default_floating_pool: 'public'
            nova::api::sync_db_api: true
            nova::api::enable_proxy_headers_parsing: true
            nova::keystone::auth::tenant: 'service'
            nova::keystone::auth::public_url: {get_param: [EndpointMap, NovaPublic, uri]}
            nova::keystone::auth::internal_url: {get_param: [EndpointMap, NovaInternal, uri]}
            nova::keystone::auth::admin_url: {get_param: [EndpointMap, NovaAdmin, uri]}
            nova::keystone::auth::password: {get_param: NovaPassword}
            nova::keystone::auth::region: {get_param: KeystoneRegion}
      step_config: |
        include tripleo::profile::base::nova::api
pan>" == "apex" ]] ; then COMPUTE_USER=${COMPUTE_USER:-heat-admin} if [[ "$INSTALLER_IP" == "none" ]] ; then instack_mac=$(sudo virsh domiflist instack | awk '/default/{print $5}') INSTALLER_IP=$(/usr/sbin/arp -e | grep ${instack_mac} | awk '{print $1}') fi COMPUTE_IP=$(sudo ssh $ssh_opts $INSTALLER_IP \ "source stackrc; \ openstack server show $COMPUTE_HOST \ | awk '/ ctlplane network /{print \$5}'") elif [[ "$INSTALLER_TYPE" == "local" ]] ; then COMPUTE_USER=${COMPUTE_USER:-$(whoami)} COMPUTE_IP=$(getent hosts "$COMPUTE_HOST" | awk '{ print $1 }') if [[ -z "$COMPUTE_IP" ]]; then echo "ERROR: Could not resolve $COMPUTE_HOST. Either manually set COMPUTE_IP or enable DNS resolution." exit 1 fi fi # verify connectivity to target compute host ping -c 1 "$COMPUTE_IP" if [[ $? -ne 0 ]] ; then echo "ERROR: can not ping to computer host" exit 1 fi } prepare_compute_ssh() { ssh_opts_cpu="$ssh_opts" # get ssh key from installer node if [[ "$INSTALLER_TYPE" == "apex" ]] ; then sudo scp $ssh_opts root@"$INSTALLER_IP":/home/stack/.ssh/id_rsa instack_key elif [[ "$INSTALLER_TYPE" == "local" ]] ; then echo "INSTALLER_TYPE set to 'local'. Assuming SSH keys already exchanged with $COMPUTE_HOST" fi sudo chown $(whoami):$(whoami) instack_key chmod 400 instack_key ssh_opts_cpu+=" -i instack_key" # verify ssh to target compute host ssh $ssh_opts_cpu "$COMPUTE_USER@$COMPUTE_IP" 'exit' if [[ $? -ne 0 ]] ; then echo "ERROR: can not ssh to computer host" exit 1 fi } download_image() { [ -e "$IMAGE_FILE" ] && return 0 wget "$IMAGE_URL" -o "$IMAGE_FILE" } register_image() { openstack image list | grep -q " $IMAGE_NAME " && return 0 openstack image create "$IMAGE_NAME" \ --public \ --disk-format "$IMAGE_FORMAT" \ --container-format bare \ --file "$IMAGE_FILE" } create_test_user() { openstack user list | grep -q " $DOCTOR_USER " || { openstack user create "$DOCTOR_USER" --password "$DOCTOR_PW" } openstack project list | grep -q " $DOCTOR_PROJECT " || { openstack project create "$DOCTOR_PROJECT" } openstack user role list "$DOCTOR_USER" --project "$DOCTOR_PROJECT" \ | grep -q " $DOCTOR_ROLE " || { openstack role add "$DOCTOR_ROLE" --user "$DOCTOR_USER" \ --project "$DOCTOR_PROJECT" } } change_to_doctor_user() { export OS_USERNAME="$DOCTOR_USER" export OS_PASSWORD="$DOCTOR_PW" export OS_PROJECT_NAME="$DOCTOR_PROJECT" export OS_TENANT_NAME="$DOCTOR_PROJECT" } boot_vm() { ( # test VM done with test user, so can test non-admin change_to_doctor_user openstack server list | grep -q " $VM_NAME " && return 0 openstack server create --flavor "$VM_FLAVOR" \ --image "$IMAGE_NAME" \ "$VM_NAME" sleep 1 ) } create_alarm() { ( # get vm_id as test user change_to_doctor_user ceilometer alarm-list | grep -q " $ALARM_NAME " && return 0 vm_id=$(openstack server list | grep " $VM_NAME " | awk '{print $2}') ceilometer alarm-event-create --name "$ALARM_NAME" \ --alarm-action "http://localhost:$CONSUMER_PORT/failure" \ --description "VM failure" \ --enabled True \ --repeat-actions False \ --severity "moderate" \ --event-type compute.instance.update \ -q "traits.state=string::error; traits.instance_id=string::$vm_id" ) } start_monitor() { pgrep -f "python monitor.py" && return 0 sudo python monitor.py "$COMPUTE_HOST" "$COMPUTE_IP" \ "http://127.0.0.1:$INSPECTOR_PORT/events" > monitor.log 2>&1 & } stop_monitor() { pgrep -f "python monitor.py" || return 0 sudo kill $(pgrep -f "python monitor.py") cat monitor.log } start_inspector() { pgrep -f "python inspector.py" && return 0 python inspector.py "$INSPECTOR_PORT" > inspector.log 2>&1 & } stop_inspector() { pgrep -f "python inspector.py" || return 0 kill $(pgrep -f "python inspector.py") cat inspector.log } start_consumer() { pgrep -f "python consumer.py" && return 0 python consumer.py "$CONSUMER_PORT" > consumer.log 2>&1 & } stop_consumer() { pgrep -f "python consumer.py" || return 0 kill $(pgrep -f "python consumer.py") cat consumer.log } wait_for_vm_launch() { echo "waiting for vm launch..." ( # get VM state as test user change_to_doctor_user count=0 while [[ ${count} -lt 60 ]] do state=$(openstack server list | grep " $VM_NAME " | awk '{print $6}') [[ "$state" == "ACTIVE" ]] && return 0 [[ "$state" == "ERROR" ]] && echo "vm state is ERROR" && exit 1 count=$(($count+1)) sleep 1 done echo "ERROR: time out while waiting for vm launch" exit 1 ) } inject_failure() { echo "disabling network of compute host [$COMPUTE_HOST] for 3 mins..." cat > disable_network.sh << 'END_TXT' #!/bin/bash -x dev=$(sudo ip route | awk '/^default/{print $5}') sleep 1 sudo ip link set $dev down sleep 180 sudo ip link set $dev up sleep 1 END_TXT chmod +x disable_network.sh scp $ssh_opts_cpu disable_network.sh "$COMPUTE_USER@$COMPUTE_IP:" ssh $ssh_opts_cpu "$COMPUTE_USER@$COMPUTE_IP" 'nohup ./disable_network.sh > disable_network.log 2>&1 &' } calculate_notification_time() { detected=$(grep "doctor monitor detected at" monitor.log | awk '{print $5}') notified=$(grep "doctor consumer notified at" consumer.log | awk '{print $5}') echo "$notified $detected" | \ awk '{d = $1 - $2; if (d < 1 && d > 0) print d " OK"; else print d " NG"}' } check_host_status() { expect_state=$1 ( change_to_doctor_user host_status_line=$(openstack --os-compute-api-version 2.16 server show $VM_NAME | grep "host_status") if [[ $? -ne 0 ]] ; then echo "ERROR: host_status not configured for owner in Nova policy.json" exit 1 fi host_status=$(echo $host_status_line | awk '{print $4}') if [ -z "$host_status" ] ; then echo "ERROR: host_status not reported by: nova show $VM_NAME" exit 1 elif [[ "$host_status" != "$expect_state" ]] ; then echo "ERROR: host_status:$host_status not equal to expect_state: $expect_state" exit 1 else echo "$VM_NAME showing host_status: $host_status" fi ) } cleanup() { set +e echo "cleanup..." stop_monitor stop_inspector stop_consumer python ./nova_force_down.py "$COMPUTE_HOST" --unset sleep 1 ( change_to_doctor_user openstack server list | grep -q " $VM_NAME " && openstack server delete "$VM_NAME" sleep 1 alarm_id=$(ceilometer alarm-list | grep " $ALARM_NAME " | awk '{print $2}') sleep 1 [ -n "$alarm_id" ] && ceilometer alarm-delete "$alarm_id" sleep 1 ) image_id=$(openstack image list | grep " $IMAGE_NAME " | awk '{print $2}') sleep 1 [ -n "$image_id" ] && openstack image delete "$image_id" openstack role remove "$DOCTOR_ROLE" --user "$DOCTOR_USER" \ --project "$DOCTOR_PROJECT" openstack project delete "$DOCTOR_PROJECT" openstack user delete "$DOCTOR_USER" echo "waiting disabled compute host back to be enabled..." sleep 180 check_host_status "UP" ssh $ssh_opts_cpu "$COMPUTE_USER@$COMPUTE_IP" \ "[ -e disable_network.log ] && cat disable_network.log" } echo "Note: doctor/tests/run.sh has been executed." trap cleanup EXIT echo "preparing VM image..." download_image register_image echo "creating test user..." create_test_user echo "creating VM and alarm..." boot_vm wait_for_vm_launch create_alarm echo "get computer host info and prepare to ssh..." get_compute_host_info prepare_compute_ssh echo "starting doctor sample components..." start_monitor start_inspector start_consumer sleep 60 echo "injecting host failure..." inject_failure sleep 10 check_host_status "DOWN" calculate_notification_time echo "done"