blob: bc6ce3d5c2bf68869785f596879c7b07b1b2df54 [file] [log] [blame]
Sean Daguee263c822014-12-05 14:25:28 -05001#!/bin/bash
2#
Dean Troyer6d04fd72012-12-21 11:03:37 -06003# lib/databases/mysql
4# Functions to control the configuration and operation of the **MySQL** database backend
Terry Wilson428af5a2012-11-01 16:12:39 -04005
6# Dependencies:
Adam Spiers6a5aa7c2013-10-24 11:27:02 +01007#
8# - DATABASE_{HOST,USER,PASSWORD} must be defined
Terry Wilson428af5a2012-11-01 16:12:39 -04009
10# Save trace setting
Ian Wienand523f4882015-10-13 11:03:03 +110011_XTRACE_DB_MYSQL=$(set +o | grep xtrace)
Terry Wilson428af5a2012-11-01 16:12:39 -040012set +o xtrace
13
armando-migliacciob3d88222015-06-12 07:54:03 -070014MYSQL_DRIVER=${MYSQL_DRIVER:-PyMySQL}
Carlos Camachocc6e20b2022-01-07 15:30:56 +010015INSTALL_DATABASE_SERVER_PACKAGES=$(trueorfalse True INSTALL_DATABASE_SERVER_PACKAGES)
Dean Troyercc6b4432013-04-08 15:38:03 -050016
Terry Wilson428af5a2012-11-01 16:12:39 -040017register_database mysql
18
Slawek Kaplonskid54a1c62019-09-10 12:05:06 +020019if [[ -z "$MYSQL_SERVICE_NAME" ]]; then
20 MYSQL_SERVICE_NAME=mysql
21 if is_fedora && ! is_oraclelinux; then
22 MYSQL_SERVICE_NAME=mariadb
23 elif is_suse && systemctl list-unit-files | grep -q 'mariadb\.service'; then
24 # Older mariadb packages on SLES 12 provided mysql.service. The
25 # newer ones on SLES 12 and 15 use mariadb.service; they also
26 # provide a mysql.service symlink for backwards-compatibility, but
27 # let's not rely on that.
28 MYSQL_SERVICE_NAME=mariadb
Jens Harbott959a7c22021-05-02 09:29:15 +020029 elif [[ "$DISTRO" == "bullseye" ]]; then
30 MYSQL_SERVICE_NAME=mariadb
Slawek Kaplonskid54a1c62019-09-10 12:05:06 +020031 fi
Sean Dague53753292014-12-04 19:38:15 -050032fi
Dean Troyercc6b4432013-04-08 15:38:03 -050033
34# Functions
35# ---------
36
Julien Danjou0eec4f82015-09-08 10:45:06 +000037function get_database_type_mysql {
38 if [[ "$MYSQL_DRIVER" == "PyMySQL" ]]; then
39 echo mysql+pymysql
40 else
41 echo mysql
42 fi
43}
44
Dean Troyer995eb922013-03-07 16:11:40 -060045# Get rid of everything enough to cleanly change database backends
46function cleanup_database_mysql {
Dirk Mueller1d968d72017-09-23 14:45:42 +020047 stop_service $MYSQL_SERVICE_NAME
Dean Troyer995eb922013-03-07 16:11:40 -060048 if is_ubuntu; then
49 # Get ruthless with mysql
Sean Dague8f90f762015-01-14 10:36:48 -050050 apt_get purge -y mysql* mariadb*
Dean Troyer995eb922013-03-07 16:11:40 -060051 sudo rm -rf /var/lib/mysql
Tiago Mello4376ae02014-03-14 10:48:56 -030052 sudo rm -rf /etc/mysql
Dean Troyer995eb922013-03-07 16:11:40 -060053 return
Dirk Mueller1d968d72017-09-23 14:45:42 +020054 elif is_oraclelinux; then
Wiekus Beukesec47bc12015-03-19 08:20:38 -070055 uninstall_package mysql-community-server
56 sudo rm -rf /var/lib/mysql
Dirk Mueller1d968d72017-09-23 14:45:42 +020057 elif is_suse || is_fedora; then
Attila Fazekas1f316be2015-01-26 16:39:57 +010058 uninstall_package mariadb-server
59 sudo rm -rf /var/lib/mysql
Dean Troyer995eb922013-03-07 16:11:40 -060060 else
61 return
62 fi
Dean Troyer995eb922013-03-07 16:11:40 -060063}
64
Terry Wilson428af5a2012-11-01 16:12:39 -040065function recreate_database_mysql {
66 local db=$1
zhhuabj2832f282013-05-08 18:43:26 +080067 mysql -u$DATABASE_USER -p$DATABASE_PASSWORD -h$MYSQL_HOST -e "DROP DATABASE IF EXISTS $db;"
Ihar Hrachyshka157c84b2014-10-06 13:29:39 +020068 mysql -u$DATABASE_USER -p$DATABASE_PASSWORD -h$MYSQL_HOST -e "CREATE DATABASE $db CHARACTER SET utf8;"
Terry Wilson428af5a2012-11-01 16:12:39 -040069}
70
71function configure_database_mysql {
Ade Lee15b2e422023-01-24 14:44:13 +010072 local my_conf mysql slow_log my_client_conf
Terry Wilson428af5a2012-11-01 16:12:39 -040073 echo_summary "Configuring and starting MySQL"
74
Vincent Untzc18b9652012-12-04 12:36:34 +010075 if is_ubuntu; then
Dean Troyer3ef23bc2014-07-25 14:56:22 -050076 my_conf=/etc/mysql/my.cnf
Wiekus Beukesec47bc12015-03-19 08:20:38 -070077 elif is_suse || is_oraclelinux; then
78 my_conf=/etc/my.cnf
Vincent Untz00011c02012-12-06 09:56:32 +010079 elif is_fedora; then
Dean Troyer3ef23bc2014-07-25 14:56:22 -050080 my_conf=/etc/my.cnf
Yuval Brik13e81ad2017-06-23 10:32:16 +030081 local cracklib_conf=/etc/my.cnf.d/cracklib_password_check.cnf
82 if [ -f "$cracklib_conf" ]; then
83 inicomment -sudo "$cracklib_conf" "mariadb" "plugin-load-add"
84 fi
Vincent Untz00011c02012-12-06 09:56:32 +010085 else
86 exit_distro_not_supported "mysql configuration"
Terry Wilson428af5a2012-11-01 16:12:39 -040087 fi
88
Ade Lee15b2e422023-01-24 14:44:13 +010089 # Set fips mode on
90 if is_ubuntu; then
91 if is_fips_enabled; then
92 my_client_conf=/etc/mysql/mysql.conf.d/mysql.cnf
93 iniset -sudo $my_client_conf mysql ssl-fips-mode "on"
94 iniset -sudo $my_conf mysqld ssl-fips-mode "on"
95 fi
96 fi
97
Brian Haley7943a922022-03-14 13:53:41 -040098 # Change bind-address from localhost (127.0.0.1) to any (::)
99 iniset -sudo $my_conf mysqld bind-address "$(ipv6_unquote $SERVICE_LISTEN_ADDRESS)"
100
101 # (Re)Start mysql-server
Vincent Untz00011c02012-12-06 09:56:32 +0100102 if is_fedora || is_suse; then
103 # service is not started by default
Dirk Mueller1d968d72017-09-23 14:45:42 +0200104 start_service $MYSQL_SERVICE_NAME
Brian Haley7943a922022-03-14 13:53:41 -0400105 elif is_ubuntu; then
106 # required since bind-address could have changed above
107 restart_service $MYSQL_SERVICE_NAME
Vincent Untz00011c02012-12-06 09:56:32 +0100108 fi
109
110 # Set the root password - only works the first time. For Ubuntu, we already
Jens Rosenboom9abb26d2016-12-07 21:12:55 +0100111 # did that with debconf before installing the package, but we still try,
Miguel Lavalle0a406482022-12-07 16:51:28 -0600112 # because the package might have been installed already. We don't do this
113 # for Ubuntu 22.04 (jammy) because the authorization model change in
114 # version 10.4 of mariadb. See
115 # https://mariadb.org/authentication-in-mariadb-10-4/
116 if ! (is_ubuntu && [[ "$DISTRO" == "jammy" ]] && [ "$MYSQL_SERVICE_NAME" == "mariadb" ]); then
117 sudo mysqladmin -u root password $DATABASE_PASSWORD || true
118 fi
Vincent Untz00011c02012-12-06 09:56:32 +0100119
Slawek Kaplonskid54a1c62019-09-10 12:05:06 +0200120 # In case of Mariadb, giving hostname in arguments causes permission
121 # problems as it expects connection through socket
122 if is_ubuntu && [ "$MYSQL_SERVICE_NAME" == "mariadb" ]; then
123 local cmd_args="-uroot -p$DATABASE_PASSWORD "
124 else
Brian Haley7943a922022-03-14 13:53:41 -0400125 local cmd_args="-uroot -p$DATABASE_PASSWORD -h$SERVICE_LOCAL_HOST "
Slawek Kaplonskid54a1c62019-09-10 12:05:06 +0200126 fi
127
128 # In mariadb e.g. on Ubuntu socket plugin is used for authentication
129 # as root so it works only as sudo. To restore old "mysql like" behaviour,
130 # we need to change auth plugin for root user
Jens Harbott959a7c22021-05-02 09:29:15 +0200131 if is_ubuntu && [[ "$DISTRO" != "bullseye" ]] && [ "$MYSQL_SERVICE_NAME" == "mariadb" ]; then
Miguel Lavalle0a406482022-12-07 16:51:28 -0600132 if [[ "$DISTRO" == "jammy" ]]; then
133 # For Ubuntu 22.04 (jammy) we follow the model outlined in
134 # https://mariadb.org/authentication-in-mariadb-10-4/
135 sudo mysql -e "ALTER USER $DATABASE_USER@localhost IDENTIFIED VIA mysql_native_password USING PASSWORD('$DATABASE_PASSWORD');"
136 else
137 sudo mysql $cmd_args -e "UPDATE mysql.user SET plugin='' WHERE user='$DATABASE_USER' AND host='localhost';"
138 sudo mysql $cmd_args -e "FLUSH PRIVILEGES;"
139 fi
Slawek Kaplonskid54a1c62019-09-10 12:05:06 +0200140 fi
Miguel Lavalle0a406482022-12-07 16:51:28 -0600141 if ! (is_ubuntu && [[ "$DISTRO" == "jammy" ]] && [ "$MYSQL_SERVICE_NAME" == "mariadb" ]); then
142 # Create DB user if it does not already exist
143 sudo mysql $cmd_args -e "CREATE USER IF NOT EXISTS '$DATABASE_USER'@'%' identified by '$DATABASE_PASSWORD';"
144 # Update the DB to give user '$DATABASE_USER'@'%' full control of the all databases:
145 sudo mysql $cmd_args -e "GRANT ALL PRIVILEGES ON *.* TO '$DATABASE_USER'@'%';"
146 fi
Terry Wilson428af5a2012-11-01 16:12:39 -0400147
148 # Now update ``my.cnf`` for some local needs and restart the mysql service
149
Brian Haley7943a922022-03-14 13:53:41 -0400150 # Set default db type to InnoDB
Roman Podoliaka88b84092017-02-07 13:34:12 +0200151 iniset -sudo $my_conf mysqld sql_mode TRADITIONAL
Ian Wienand9c0b9f32015-07-22 06:08:09 +1000152 iniset -sudo $my_conf mysqld default-storage-engine InnoDB
Jens Rosenboom4b59fbb2017-03-15 21:58:48 +0000153 iniset -sudo $my_conf mysqld max_connections 1024
Terry Wilson428af5a2012-11-01 16:12:39 -0400154
Jeremy Stanleyc4f47342014-01-25 01:10:31 +0000155 if [[ "$DATABASE_QUERY_LOGGING" == "True" ]]; then
156 echo_summary "Enabling MySQL query logging"
Attila Fazekas1f316be2015-01-26 16:39:57 +0100157 if is_fedora; then
Attila Fazekas3b53aeb2014-04-30 11:57:22 +0200158 slow_log=/var/log/mariadb/mariadb-slow.log
159 else
160 slow_log=/var/log/mysql/mysql-slow.log
161 fi
Ralf Haferkamp0526bb82014-04-03 08:27:33 +0200162 sudo sed -e '/log.slow.queries/d' \
163 -e '/long.query.time/d' \
164 -e '/log.queries.not.using.indexes/d' \
Dean Troyer3ef23bc2014-07-25 14:56:22 -0500165 -i $my_conf
Monty Taylor7c73e8d2013-01-07 08:17:01 +0000166
Ralf Haferkamp0526bb82014-04-03 08:27:33 +0200167 # Turn on slow query log, log all queries (any query taking longer than
168 # 0 seconds) and log all non-indexed queries
Ian Wienand9c0b9f32015-07-22 06:08:09 +1000169 iniset -sudo $my_conf mysqld slow-query-log 1
170 iniset -sudo $my_conf mysqld slow-query-log-file $slow_log
171 iniset -sudo $my_conf mysqld long-query-time 0
172 iniset -sudo $my_conf mysqld log-queries-not-using-indexes 1
Jeremy Stanleyc4f47342014-01-25 01:10:31 +0000173 fi
Monty Taylor7c73e8d2013-01-07 08:17:01 +0000174
Dan Smithc2772c22022-04-08 08:48:49 -0700175 if [[ "$MYSQL_GATHER_PERFORMANCE" == "True" ]]; then
Dan Smithfe52d7f2022-04-28 12:34:38 -0700176 echo "enabling MySQL performance counting"
177
178 # Install our sqlalchemy plugin
179 pip_install ${TOP_DIR}/tools/dbcounter
180
181 # Create our stats database for accounting
182 recreate_database stats
183 mysql -u $DATABASE_USER -p$DATABASE_PASSWORD -h $MYSQL_HOST -e \
184 "CREATE TABLE queries (db VARCHAR(32), op VARCHAR(32),
185 count INT, PRIMARY KEY (db, op)) ENGINE MEMORY" stats
Dan Smithc2772c22022-04-08 08:48:49 -0700186 fi
187
Dan Smith75673592023-02-13 14:41:40 +0000188 if [[ "$MYSQL_REDUCE_MEMORY" == "True" ]]; then
189 iniset -sudo $my_conf mysqld read_buffer_size 64K
190 iniset -sudo $my_conf mysqld innodb_buffer_pool_size 16M
191 iniset -sudo $my_conf mysqld thread_stack 192K
192 iniset -sudo $my_conf mysqld thread_cache_size 8
193 iniset -sudo $my_conf mysqld tmp_table_size 8M
194 iniset -sudo $my_conf mysqld sort_buffer_size 8M
195 iniset -sudo $my_conf mysqld max_allowed_packet 8M
196 fi
197
Dirk Mueller1d968d72017-09-23 14:45:42 +0200198 restart_service $MYSQL_SERVICE_NAME
Terry Wilson428af5a2012-11-01 16:12:39 -0400199}
200
201function install_database_mysql {
Vincent Untzc18b9652012-12-04 12:36:34 +0100202 if is_ubuntu; then
Terry Wilson428af5a2012-11-01 16:12:39 -0400203 # Seed configuration with mysql password so that apt-get install doesn't
204 # prompt us for a password upon install.
Bob Ball90333432015-01-19 10:56:42 +0000205 sudo debconf-set-selections <<MYSQL_PRESEED
206mysql-server mysql-server/root_password password $DATABASE_PASSWORD
207mysql-server mysql-server/root_password_again password $DATABASE_PASSWORD
208mysql-server mysql-server/start_on_boot boolean true
Terry Wilson428af5a2012-11-01 16:12:39 -0400209MYSQL_PRESEED
210 fi
211
212 # while ``.my.cnf`` is not needed for OpenStack to function, it is useful
213 # as it allows you to access the mysql databases via ``mysql nova`` instead
214 # of having to specify the username/password each time.
215 if [[ ! -e $HOME/.my.cnf ]]; then
216 cat <<EOF >$HOME/.my.cnf
217[client]
218user=$DATABASE_USER
219password=$DATABASE_PASSWORD
Terry Wilson428af5a2012-11-01 16:12:39 -0400220EOF
Slawek Kaplonskid54a1c62019-09-10 12:05:06 +0200221
222 if ! is_ubuntu || [ "$MYSQL_SERVICE_NAME" != "mariadb" ]; then
223 echo "host=$MYSQL_HOST" >> $HOME/.my.cnf
224 fi
Terry Wilson428af5a2012-11-01 16:12:39 -0400225 chmod 0600 $HOME/.my.cnf
226 fi
227 # Install mysql-server
Carlos Camachocc6e20b2022-01-07 15:30:56 +0100228 if [[ "$INSTALL_DATABASE_SERVER_PACKAGES" == "True" ]]; then
229 if is_oraclelinux; then
230 install_package mysql-community-server
231 elif is_fedora; then
232 install_package mariadb-server mariadb-devel mariadb
233 sudo systemctl enable $MYSQL_SERVICE_NAME
234 elif is_suse; then
235 install_package mariadb-server
236 sudo systemctl enable $MYSQL_SERVICE_NAME
237 elif is_ubuntu; then
238 install_package $MYSQL_SERVICE_NAME-server
239 else
240 exit_distro_not_supported "mysql installation"
241 fi
Vincent Untzca5c4712012-11-21 17:45:49 +0100242 fi
Dean Troyer5686dbc2015-03-09 14:27:51 -0500243}
Dean Troyerb1d8e8e2015-02-16 13:58:35 -0600244
Dean Troyer5686dbc2015-03-09 14:27:51 -0500245function install_database_python_mysql {
Dean Troyerb1d8e8e2015-02-16 13:58:35 -0600246 # Install Python client module
Sean Dague37421992015-05-20 06:37:11 -0700247 pip_install_gr $MYSQL_DRIVER
248 if [[ "$MYSQL_DRIVER" == "MySQL-python" ]]; then
249 ADDITIONAL_VENV_PACKAGES+=",MySQL-python"
Julien Danjou0f63eb32015-06-12 09:05:12 +0200250 elif [[ "$MYSQL_DRIVER" == "PyMySQL" ]]; then
251 ADDITIONAL_VENV_PACKAGES+=",PyMySQL"
Sean Dague37421992015-05-20 06:37:11 -0700252 fi
Terry Wilson428af5a2012-11-01 16:12:39 -0400253}
254
255function database_connection_url_mysql {
Attila Fazekas7e79d912013-03-03 12:23:04 +0100256 local db=$1
Dan Smithfe52d7f2022-04-28 12:34:38 -0700257 local plugin
258
259 # NOTE(danms): We don't enable perf on subnodes yet because the
260 # plugin is not installed there
261 if [[ "$MYSQL_GATHER_PERFORMANCE" == "True" ]]; then
262 if is_service_enabled mysql; then
263 plugin="&plugin=dbcounter"
264 fi
265 fi
266
267 echo "$BASE_SQL_CONN/$db?charset=utf8$plugin"
Terry Wilson428af5a2012-11-01 16:12:39 -0400268}
269
Dean Troyercc6b4432013-04-08 15:38:03 -0500270
Terry Wilson428af5a2012-11-01 16:12:39 -0400271# Restore xtrace
Ian Wienand523f4882015-10-13 11:03:03 +1100272$_XTRACE_DB_MYSQL
Sean Dague584d90e2013-03-29 14:34:53 -0400273
274# Local variables:
275# mode: shell-script
276# End: