blob: 84cec732342b21134e1d708738f91728c7b8ca50 [file] [log] [blame]
Sean Daguee263c822014-12-05 14:25:28 -05001#!/bin/bash
2#
zhang-hared98a5d02013-06-21 18:18:02 +08003# lib/apache
4# Functions to control configuration and operation of apache web server
5
6# Dependencies:
Adam Spiers6a5aa7c2013-10-24 11:27:02 +01007#
8# - ``functions`` file
Dean Troyerd8864fe2014-02-17 11:00:42 -06009# - ``STACK_USER`` must be defined
10#
Stephan Renatuse578eff2013-11-19 13:31:04 +010011# lib/apache exports the following functions:
12#
Adam Spiers6a5aa7c2013-10-24 11:27:02 +010013# - install_apache_wsgi
Gabriel Assis Bezerraa688bc62014-05-27 20:58:22 +000014# - apache_site_config_for
Adam Spiers6a5aa7c2013-10-24 11:27:02 +010015# - enable_apache_site
16# - disable_apache_site
17# - start_apache_server
18# - stop_apache_server
19# - restart_apache_server
zhang-hared98a5d02013-06-21 18:18:02 +080020
21# Save trace setting
Ian Wienand523f4882015-10-13 11:03:03 +110022_XTRACE_LIB_APACHE=$(set +o | grep xtrace)
zhang-hared98a5d02013-06-21 18:18:02 +080023set +o xtrace
24
25# Allow overriding the default Apache user and group, default to
26# current user and his default group.
Stephan Renatuse578eff2013-11-19 13:31:04 +010027APACHE_USER=${APACHE_USER:-$STACK_USER}
zhang-hared98a5d02013-06-21 18:18:02 +080028APACHE_GROUP=${APACHE_GROUP:-$(id -gn $APACHE_USER)}
29
30
31# Set up apache name and configuration directory
Clark Boylancfb9f052016-11-29 10:43:05 -080032# Note that APACHE_CONF_DIR is really more accurately apache's vhost
33# configuration dir but we can't just change this because public interfaces.
zhang-hared98a5d02013-06-21 18:18:02 +080034if is_ubuntu; then
35 APACHE_NAME=apache2
Dean Troyer444a8d52014-06-06 16:36:52 -050036 APACHE_CONF_DIR=${APACHE_CONF_DIR:-/etc/$APACHE_NAME/sites-available}
Clark Boylancfb9f052016-11-29 10:43:05 -080037 APACHE_SETTINGS_DIR=${APACHE_SETTINGS_DIR:-/etc/$APACHE_NAME/conf-enabled}
zhang-hared98a5d02013-06-21 18:18:02 +080038elif is_fedora; then
39 APACHE_NAME=httpd
Dean Troyer444a8d52014-06-06 16:36:52 -050040 APACHE_CONF_DIR=${APACHE_CONF_DIR:-/etc/$APACHE_NAME/conf.d}
Clark Boylancfb9f052016-11-29 10:43:05 -080041 APACHE_SETTINGS_DIR=${APACHE_SETTINGS_DIR:-/etc/$APACHE_NAME/conf.d}
zhang-hared98a5d02013-06-21 18:18:02 +080042elif is_suse; then
43 APACHE_NAME=apache2
Dean Troyer444a8d52014-06-06 16:36:52 -050044 APACHE_CONF_DIR=${APACHE_CONF_DIR:-/etc/$APACHE_NAME/vhosts.d}
Clark Boylancfb9f052016-11-29 10:43:05 -080045 APACHE_SETTINGS_DIR=${APACHE_SETTINGS_DIR:-/etc/$APACHE_NAME/conf.d}
zhang-hared98a5d02013-06-21 18:18:02 +080046fi
Clark Boylan66ce5c22016-10-05 12:11:05 -070047APACHE_LOG_DIR="/var/log/${APACHE_NAME}"
zhang-hared98a5d02013-06-21 18:18:02 +080048
49# Functions
50# ---------
Gregory Haynes4b49e402016-08-31 18:19:51 -070051
52# Enable apache mod and restart apache if it isn't already enabled.
53function enable_apache_mod {
54 local mod=$1
55 # Apache installation, because we mark it NOPRIME
Clark Boylan35649ae2017-05-27 17:52:55 -070056 if is_ubuntu; then
57 # Skip mod_version as it is not a valid mod to enable
58 # on debuntu, instead it is built in.
59 if [[ "$mod" != "version" ]] && ! a2query -m $mod ; then
60 sudo a2enmod $mod
61 restart_apache_server
62 fi
63 elif is_suse; then
64 if ! a2enmod -q $mod ; then
Gregory Haynes4b49e402016-08-31 18:19:51 -070065 sudo a2enmod $mod
66 restart_apache_server
67 fi
68 elif is_fedora; then
69 # pass
70 true
71 else
72 exit_distro_not_supported "apache enable mod"
73 fi
74}
75
Sean Dague604e5982017-04-13 13:28:12 -040076# NOTE(sdague): Install uwsgi including apache module, we need to get
77# to 2.0.6+ to get a working mod_proxy_uwsgi. We can probably build a
78# check for that and do it differently for different platforms.
79function install_apache_uwsgi {
80 local apxs="apxs2"
81 if is_fedora; then
82 apxs="apxs"
83 fi
84
85 # Ubuntu xenial is back level on uwsgi so the proxy doesn't
86 # actually work. Hence we have to build from source for now.
87 #
88 # Centos 7 actually has the module in epel, but there was a big
89 # push to disable epel by default. As such, compile from source
90 # there as well.
91
92 local dir
93 dir=$(mktemp -d)
94 pushd $dir
95 pip_install uwsgi
96 pip download uwsgi -c $REQUIREMENTS_DIR/upper-constraints.txt
97 local uwsgi
98 uwsgi=$(ls uwsgi*)
99 tar xvf $uwsgi
100 cd uwsgi*/apache2
101 sudo $apxs -i -c mod_proxy_uwsgi.c
102 popd
103 # delete the temp directory
104 sudo rm -rf $dir
105
Clark Boylan35649ae2017-05-27 17:52:55 -0700106 if is_ubuntu || is_suse ; then
Sean Dague604e5982017-04-13 13:28:12 -0400107 # we've got to enable proxy and proxy_uwsgi for this to work
108 sudo a2enmod proxy
109 sudo a2enmod proxy_uwsgi
110 elif is_fedora; then
111 # redhat is missing a nice way to turn on/off modules
112 echo "LoadModule proxy_uwsgi_module modules/mod_proxy_uwsgi.so" \
113 | sudo tee /etc/httpd/conf.modules.d/02-proxy-uwsgi.conf
114 fi
115 restart_apache_server
116}
117
zhang-hared98a5d02013-06-21 18:18:02 +0800118# install_apache_wsgi() - Install Apache server and wsgi module
Ian Wienandaee18c72014-02-21 15:35:08 +1100119function install_apache_wsgi {
zhang-hared98a5d02013-06-21 18:18:02 +0800120 # Apache installation, because we mark it NOPRIME
121 if is_ubuntu; then
122 # Install apache2, which is NOPRIME'd
Davanum Srinivasafa8a002016-12-19 09:51:01 -0500123 install_package apache2
124 if python3_enabled; then
125 if is_package_installed libapache2-mod-wsgi; then
126 uninstall_package libapache2-mod-wsgi
127 fi
128 install_package libapache2-mod-wsgi-py3
129 else
130 install_package libapache2-mod-wsgi
131 fi
zhang-hared98a5d02013-06-21 18:18:02 +0800132 elif is_fedora; then
133 sudo rm -f /etc/httpd/conf.d/000-*
134 install_package httpd mod_wsgi
Ian Wienand41e6e122017-08-08 15:06:26 +1000135 # For consistency with Ubuntu, switch to the worker mpm, as
Attila Fazekas9fd38e72017-12-11 12:20:25 +0100136 # the default is event
Ian Wienand41e6e122017-08-08 15:06:26 +1000137 sudo sed -i '/mod_mpm_prefork.so/s/^/#/g' /etc/httpd/conf.modules.d/00-mpm.conf
Attila Fazekas9fd38e72017-12-11 12:20:25 +0100138 sudo sed -i '/mod_mpm_event.so/s/^/#/g' /etc/httpd/conf.modules.d/00-mpm.conf
Ian Wienand41e6e122017-08-08 15:06:26 +1000139 sudo sed -i '/mod_mpm_worker.so/s/^#//g' /etc/httpd/conf.modules.d/00-mpm.conf
zhang-hared98a5d02013-06-21 18:18:02 +0800140 elif is_suse; then
141 install_package apache2 apache2-mod_wsgi
142 else
Gregory Haynes4b49e402016-08-31 18:19:51 -0700143 exit_distro_not_supported "apache wsgi installation"
zhang-hared98a5d02013-06-21 18:18:02 +0800144 fi
Gregory Haynes4b49e402016-08-31 18:19:51 -0700145 # WSGI isn't enabled by default, enable it
146 enable_apache_mod wsgi
Morgan Fainbergd074dc72014-06-24 21:33:39 -0700147}
148
Gabriel Assis Bezerraa688bc62014-05-27 20:58:22 +0000149# apache_site_config_for() - The filename of the site's configuration file.
150# This function uses the global variables APACHE_NAME and APACHE_CONF_DIR.
151#
Sean Dague8f8b2742017-04-13 09:34:12 -0400152# On Ubuntu 14.04+, the site configuration file must have a .conf suffix for a2ensite and a2dissite to
Gabriel Assis Bezerraa688bc62014-05-27 20:58:22 +0000153# recognise it. a2ensite and a2dissite ignore the .conf suffix used as parameter. The default sites'
154# files are 000-default.conf and default-ssl.conf.
155#
Ralf Haferkamp633a1292014-06-16 14:10:05 +0200156# On Fedora and openSUSE, any file in /etc/httpd/conf.d/ whose name ends with .conf is enabled.
Gabriel Assis Bezerraa688bc62014-05-27 20:58:22 +0000157#
158# On RHEL and CentOS, things should hopefully work as in Fedora.
159#
160# The table below summarizes what should happen on each distribution:
161# +----------------------+--------------------+--------------------------+--------------------------+
162# | Distribution | File name | Site enabling command | Site disabling command |
163# +----------------------+--------------------+--------------------------+--------------------------+
Gabriel Assis Bezerraa688bc62014-05-27 20:58:22 +0000164# | Ubuntu 14.04 | site.conf | a2ensite site | a2dissite site |
165# | Fedora, RHEL, CentOS | site.conf.disabled | mv site.conf{.disabled,} | mv site.conf{,.disabled} |
166# +----------------------+--------------------+--------------------------+--------------------------+
167function apache_site_config_for {
168 local site=$@
169 if is_ubuntu; then
Sean Dague8f8b2742017-04-13 09:34:12 -0400170 # Ubuntu 14.04 - Apache 2.4
171 echo $APACHE_CONF_DIR/${site}.conf
Ralf Haferkamp633a1292014-06-16 14:10:05 +0200172 elif is_fedora || is_suse; then
Gabriel Assis Bezerraa688bc62014-05-27 20:58:22 +0000173 # fedora conf.d is only imported if it ends with .conf so this is approx the same
Dean Troyer444a8d52014-06-06 16:36:52 -0500174 local enabled_site_file="$APACHE_CONF_DIR/${site}.conf"
Gabriel Assis Bezerraa688bc62014-05-27 20:58:22 +0000175 if [ -f $enabled_site_file ]; then
176 echo ${enabled_site_file}
177 else
178 echo ${enabled_site_file}.disabled
179 fi
180 fi
181}
182
Jamie Lennox54707012013-09-17 12:07:48 +1000183# enable_apache_site() - Enable a particular apache site
Ian Wienandaee18c72014-02-21 15:35:08 +1100184function enable_apache_site {
Jamie Lennox54707012013-09-17 12:07:48 +1000185 local site=$@
Clark Boylan35649ae2017-05-27 17:52:55 -0700186 # Many of our sites use mod version. Just enable it.
187 enable_apache_mod version
Jamie Lennox54707012013-09-17 12:07:48 +1000188 if is_ubuntu; then
189 sudo a2ensite ${site}
Ralf Haferkamp633a1292014-06-16 14:10:05 +0200190 elif is_fedora || is_suse; then
Dean Troyer444a8d52014-06-06 16:36:52 -0500191 local enabled_site_file="$APACHE_CONF_DIR/${site}.conf"
192 # Do nothing if site already enabled or no site config exists
193 if [[ -f ${enabled_site_file}.disabled ]] && [[ ! -f ${enabled_site_file} ]]; then
194 sudo mv ${enabled_site_file}.disabled ${enabled_site_file}
195 fi
Jamie Lennox54707012013-09-17 12:07:48 +1000196 fi
197}
198
199# disable_apache_site() - Disable a particular apache site
Ian Wienandaee18c72014-02-21 15:35:08 +1100200function disable_apache_site {
Jamie Lennox54707012013-09-17 12:07:48 +1000201 local site=$@
202 if is_ubuntu; then
Chris Dent2fcdaac2017-04-18 16:54:12 +0100203 sudo a2dissite ${site} || true
Ralf Haferkamp633a1292014-06-16 14:10:05 +0200204 elif is_fedora || is_suse; then
Dean Troyer444a8d52014-06-06 16:36:52 -0500205 local enabled_site_file="$APACHE_CONF_DIR/${site}.conf"
206 # Do nothing if no site config exists
207 if [[ -f ${enabled_site_file} ]]; then
208 sudo mv ${enabled_site_file} ${enabled_site_file}.disabled
209 fi
Jamie Lennox54707012013-09-17 12:07:48 +1000210 fi
211}
212
zhang-hared98a5d02013-06-21 18:18:02 +0800213# start_apache_server() - Start running apache server
Ian Wienandaee18c72014-02-21 15:35:08 +1100214function start_apache_server {
zhang-hared98a5d02013-06-21 18:18:02 +0800215 start_service $APACHE_NAME
216}
217
218# stop_apache_server() - Stop running apache server
Ian Wienandaee18c72014-02-21 15:35:08 +1100219function stop_apache_server {
zhang-hared98a5d02013-06-21 18:18:02 +0800220 if [ -n "$APACHE_NAME" ]; then
221 stop_service $APACHE_NAME
222 else
223 exit_distro_not_supported "apache configuration"
224 fi
225}
226
227# restart_apache_server
Ian Wienandaee18c72014-02-21 15:35:08 +1100228function restart_apache_server {
Morgan Fainberg2df00462014-07-15 11:06:36 -0700229 # Apache can be slow to stop, doing an explicit stop, sleep, start helps
230 # to mitigate issues where apache will claim a port it's listening on is
231 # still in use and fail to start.
Sean Dague2b85cf02017-04-13 09:02:14 -0400232 restart_service $APACHE_NAME
zhang-hared98a5d02013-06-21 18:18:02 +0800233}
234
Sean Dague2f8c88e2017-04-13 09:08:39 -0400235function write_uwsgi_config {
236 local file=$1
237 local wsgi=$2
238 local url=$3
239 local http=$4
240 local name=""
241 name=$(basename $wsgi)
rabiaa26baa2017-04-20 10:55:16 +0530242
243 # create a home for the sockets; note don't use /tmp -- apache has
244 # a private view of it on some platforms.
245 local socket_dir='/var/run/uwsgi'
Kirill Zaitsevd0db62a2017-05-26 19:02:52 +0300246
247 # /var/run will be empty on ubuntu after reboot, so we can use systemd-temptiles
248 # to automatically create $socket_dir.
249 sudo mkdir -p /etc/tmpfiles.d/
250 echo "d $socket_dir 0755 $STACK_USER root" | sudo tee /etc/tmpfiles.d/uwsgi.conf
251 sudo systemd-tmpfiles --create /etc/tmpfiles.d/uwsgi.conf
252
rabiaa26baa2017-04-20 10:55:16 +0530253 local socket="$socket_dir/${name}.socket"
Sean Dague2f8c88e2017-04-13 09:08:39 -0400254
255 # always cleanup given that we are using iniset here
256 rm -rf $file
257 iniset "$file" uwsgi wsgi-file "$wsgi"
Sean Dague2f8c88e2017-04-13 09:08:39 -0400258 iniset "$file" uwsgi processes $API_WORKERS
259 # This is running standalone
260 iniset "$file" uwsgi master true
261 # Set die-on-term & exit-on-reload so that uwsgi shuts down
262 iniset "$file" uwsgi die-on-term true
Dinesh Bhoref60f2b2017-09-05 14:40:32 +0530263 iniset "$file" uwsgi exit-on-reload false
Matthew Treinish477a9622017-08-04 11:09:26 -0400264 # Set worker-reload-mercy so that worker will not exit till the time
265 # configured after graceful shutdown
266 iniset "$file" uwsgi worker-reload-mercy $WORKER_TIMEOUT
Sean Dague2f8c88e2017-04-13 09:08:39 -0400267 iniset "$file" uwsgi enable-threads true
268 iniset "$file" uwsgi plugins python
269 # uwsgi recommends this to prevent thundering herd on accept.
270 iniset "$file" uwsgi thunder-lock true
Matthew Treinish477a9622017-08-04 11:09:26 -0400271 # Set hook to trigger graceful shutdown on SIGTERM
272 iniset "$file" uwsgi hook-master-start "unix_signal:15 gracefully_kill_them_all"
Sean Dague2f8c88e2017-04-13 09:08:39 -0400273 # Override the default size for headers from the 4k default.
274 iniset "$file" uwsgi buffer-size 65535
275 # Make sure the client doesn't try to re-use the connection.
276 iniset "$file" uwsgi add-header "Connection: close"
277 # This ensures that file descriptors aren't shared between processes.
278 iniset "$file" uwsgi lazy-apps true
Sean Dague2f8c88e2017-04-13 09:08:39 -0400279
280 # If we said bind directly to http, then do that and don't start the apache proxy
281 if [[ -n "$http" ]]; then
282 iniset "$file" uwsgi http $http
283 else
284 local apache_conf=""
285 apache_conf=$(apache_site_config_for $name)
Chris Dentb90bb1a2017-04-18 16:30:14 +0000286 iniset "$file" uwsgi socket "$socket"
287 iniset "$file" uwsgi chmod-socket 666
Matthew Treinish1fa65362017-06-23 22:32:37 +0000288 echo "ProxyPass \"${url}\" \"unix:${socket}|uwsgi://uwsgi-uds-${name}/\" retry=0 " | sudo tee -a $apache_conf
Sean Dague2f8c88e2017-04-13 09:08:39 -0400289 enable_apache_site $name
Ian Wienandf6a2d2c2017-04-26 10:50:29 +1000290 restart_apache_server
Sean Dague2f8c88e2017-04-13 09:08:39 -0400291 fi
292}
293
Matthew Treinish1fa65362017-06-23 22:32:37 +0000294# For services using chunked encoding, the only services known to use this
295# currently are Glance and Swift, we need to use an http proxy instead of
296# mod_proxy_uwsgi because the chunked encoding gets dropped. See:
297# https://github.com/unbit/uwsgi/issues/1540 You can workaround this on python2
298# but that involves having apache buffer the request before sending it to
Jeremy Liu2f7df512017-07-12 10:09:48 +0800299# uwsgi.
Matthew Treinish1fa65362017-06-23 22:32:37 +0000300function write_local_uwsgi_http_config {
301 local file=$1
302 local wsgi=$2
303 local url=$3
304 name=$(basename $wsgi)
305
306 # create a home for the sockets; note don't use /tmp -- apache has
307 # a private view of it on some platforms.
308
309 # always cleanup given that we are using iniset here
310 rm -rf $file
311 iniset "$file" uwsgi wsgi-file "$wsgi"
312 port=$(get_random_port)
Matthew Treinish1560efe2017-06-30 12:15:26 -0400313 iniset "$file" uwsgi http-socket "127.0.0.1:$port"
Matthew Treinish1fa65362017-06-23 22:32:37 +0000314 iniset "$file" uwsgi processes $API_WORKERS
315 # This is running standalone
316 iniset "$file" uwsgi master true
317 # Set die-on-term & exit-on-reload so that uwsgi shuts down
318 iniset "$file" uwsgi die-on-term true
Dinesh Bhoref60f2b2017-09-05 14:40:32 +0530319 iniset "$file" uwsgi exit-on-reload false
Matthew Treinish1fa65362017-06-23 22:32:37 +0000320 iniset "$file" uwsgi enable-threads true
321 iniset "$file" uwsgi plugins python
322 # uwsgi recommends this to prevent thundering herd on accept.
323 iniset "$file" uwsgi thunder-lock true
Matthew Treinish477a9622017-08-04 11:09:26 -0400324 # Set hook to trigger graceful shutdown on SIGTERM
325 iniset "$file" uwsgi hook-master-start "unix_signal:15 gracefully_kill_them_all"
326 # Set worker-reload-mercy so that worker will not exit till the time
327 # configured after graceful shutdown
328 iniset "$file" uwsgi worker-reload-mercy $WORKER_TIMEOUT
Matthew Treinish1fa65362017-06-23 22:32:37 +0000329 # Override the default size for headers from the 4k default.
330 iniset "$file" uwsgi buffer-size 65535
331 # Make sure the client doesn't try to re-use the connection.
332 iniset "$file" uwsgi add-header "Connection: close"
333 # This ensures that file descriptors aren't shared between processes.
334 iniset "$file" uwsgi lazy-apps true
335 iniset "$file" uwsgi chmod-socket 666
336 iniset "$file" uwsgi http-raw-body true
337 iniset "$file" uwsgi http-chunked-input true
338 iniset "$file" uwsgi http-auto-chunked true
Matthew Treinish82d06102017-06-28 17:42:31 -0400339 iniset "$file" uwsgi http-keepalive false
Matthew Treinishb79531a2017-06-30 12:10:06 -0400340 # Increase socket timeout for slow chunked uploads
341 iniset "$file" uwsgi socket-timeout 30
Matthew Treinish1fa65362017-06-23 22:32:37 +0000342
343 enable_apache_mod proxy
344 enable_apache_mod proxy_http
345 local apache_conf=""
346 apache_conf=$(apache_site_config_for $name)
347 echo "KeepAlive Off" | sudo tee $apache_conf
Matthew Treinisha3488d52017-08-10 14:55:15 -0400348 echo "SetEnv proxy-sendchunked 1" | sudo tee -a $apache_conf
Matthew Treinish1fa65362017-06-23 22:32:37 +0000349 echo "ProxyPass \"${url}\" \"http://127.0.0.1:$port\" retry=0 " | sudo tee -a $apache_conf
350 enable_apache_site $name
351 restart_apache_server
352}
353
Sean Dague2f8c88e2017-04-13 09:08:39 -0400354function remove_uwsgi_config {
355 local file=$1
356 local wsgi=$2
357 local name=""
358 name=$(basename $wsgi)
359
360 rm -rf $file
361 disable_apache_site $name
362}
363
zhang-hared98a5d02013-06-21 18:18:02 +0800364# Restore xtrace
Ian Wienand523f4882015-10-13 11:03:03 +1100365$_XTRACE_LIB_APACHE
zhang-hared98a5d02013-06-21 18:18:02 +0800366
Adam Spiers6a5aa7c2013-10-24 11:27:02 +0100367# Tell emacs to use shell-script-mode
368## Local variables:
369## mode: shell-script
370## End: