blob: f88f1d3504b6f057a5dd644a9a33330b792eab18 [file] [log] [blame]
Sean Daguee263c822014-12-05 14:25:28 -05001#!/bin/bash
2#
zhang-hared98a5d02013-06-21 18:18:02 +08003# lib/apache
4# Functions to control configuration and operation of apache web server
5
6# Dependencies:
Adam Spiers6a5aa7c2013-10-24 11:27:02 +01007#
8# - ``functions`` file
Dean Troyerd8864fe2014-02-17 11:00:42 -06009# - ``STACK_USER`` must be defined
10#
Stephan Renatuse578eff2013-11-19 13:31:04 +010011# lib/apache exports the following functions:
12#
Adam Spiers6a5aa7c2013-10-24 11:27:02 +010013# - install_apache_wsgi
Gabriel Assis Bezerraa688bc62014-05-27 20:58:22 +000014# - apache_site_config_for
Adam Spiers6a5aa7c2013-10-24 11:27:02 +010015# - enable_apache_site
16# - disable_apache_site
17# - start_apache_server
18# - stop_apache_server
19# - restart_apache_server
zhang-hared98a5d02013-06-21 18:18:02 +080020
21# Save trace setting
Ian Wienand523f4882015-10-13 11:03:03 +110022_XTRACE_LIB_APACHE=$(set +o | grep xtrace)
zhang-hared98a5d02013-06-21 18:18:02 +080023set +o xtrace
24
25# Allow overriding the default Apache user and group, default to
26# current user and his default group.
Stephan Renatuse578eff2013-11-19 13:31:04 +010027APACHE_USER=${APACHE_USER:-$STACK_USER}
zhang-hared98a5d02013-06-21 18:18:02 +080028APACHE_GROUP=${APACHE_GROUP:-$(id -gn $APACHE_USER)}
29
30
31# Set up apache name and configuration directory
Clark Boylancfb9f052016-11-29 10:43:05 -080032# Note that APACHE_CONF_DIR is really more accurately apache's vhost
33# configuration dir but we can't just change this because public interfaces.
zhang-hared98a5d02013-06-21 18:18:02 +080034if is_ubuntu; then
35 APACHE_NAME=apache2
Dean Troyer444a8d52014-06-06 16:36:52 -050036 APACHE_CONF_DIR=${APACHE_CONF_DIR:-/etc/$APACHE_NAME/sites-available}
Clark Boylancfb9f052016-11-29 10:43:05 -080037 APACHE_SETTINGS_DIR=${APACHE_SETTINGS_DIR:-/etc/$APACHE_NAME/conf-enabled}
zhang-hared98a5d02013-06-21 18:18:02 +080038elif is_fedora; then
39 APACHE_NAME=httpd
Dean Troyer444a8d52014-06-06 16:36:52 -050040 APACHE_CONF_DIR=${APACHE_CONF_DIR:-/etc/$APACHE_NAME/conf.d}
Clark Boylancfb9f052016-11-29 10:43:05 -080041 APACHE_SETTINGS_DIR=${APACHE_SETTINGS_DIR:-/etc/$APACHE_NAME/conf.d}
zhang-hared98a5d02013-06-21 18:18:02 +080042elif is_suse; then
43 APACHE_NAME=apache2
Dean Troyer444a8d52014-06-06 16:36:52 -050044 APACHE_CONF_DIR=${APACHE_CONF_DIR:-/etc/$APACHE_NAME/vhosts.d}
Clark Boylancfb9f052016-11-29 10:43:05 -080045 APACHE_SETTINGS_DIR=${APACHE_SETTINGS_DIR:-/etc/$APACHE_NAME/conf.d}
zhang-hared98a5d02013-06-21 18:18:02 +080046fi
Clark Boylan66ce5c22016-10-05 12:11:05 -070047APACHE_LOG_DIR="/var/log/${APACHE_NAME}"
zhang-hared98a5d02013-06-21 18:18:02 +080048
49# Functions
50# ---------
Gregory Haynes4b49e402016-08-31 18:19:51 -070051
52# Enable apache mod and restart apache if it isn't already enabled.
53function enable_apache_mod {
54 local mod=$1
55 # Apache installation, because we mark it NOPRIME
56 if is_ubuntu || is_suse ; then
57 if ! a2query -m $mod ; then
58 sudo a2enmod $mod
59 restart_apache_server
60 fi
61 elif is_fedora; then
62 # pass
63 true
64 else
65 exit_distro_not_supported "apache enable mod"
66 fi
67}
68
Sean Dague604e5982017-04-13 13:28:12 -040069# NOTE(sdague): Install uwsgi including apache module, we need to get
70# to 2.0.6+ to get a working mod_proxy_uwsgi. We can probably build a
71# check for that and do it differently for different platforms.
72function install_apache_uwsgi {
73 local apxs="apxs2"
74 if is_fedora; then
75 apxs="apxs"
76 fi
77
78 # Ubuntu xenial is back level on uwsgi so the proxy doesn't
79 # actually work. Hence we have to build from source for now.
80 #
81 # Centos 7 actually has the module in epel, but there was a big
82 # push to disable epel by default. As such, compile from source
83 # there as well.
84
85 local dir
86 dir=$(mktemp -d)
87 pushd $dir
88 pip_install uwsgi
89 pip download uwsgi -c $REQUIREMENTS_DIR/upper-constraints.txt
90 local uwsgi
91 uwsgi=$(ls uwsgi*)
92 tar xvf $uwsgi
93 cd uwsgi*/apache2
94 sudo $apxs -i -c mod_proxy_uwsgi.c
95 popd
96 # delete the temp directory
97 sudo rm -rf $dir
98
99 if is_ubuntu; then
100 # we've got to enable proxy and proxy_uwsgi for this to work
101 sudo a2enmod proxy
102 sudo a2enmod proxy_uwsgi
103 elif is_fedora; then
104 # redhat is missing a nice way to turn on/off modules
105 echo "LoadModule proxy_uwsgi_module modules/mod_proxy_uwsgi.so" \
106 | sudo tee /etc/httpd/conf.modules.d/02-proxy-uwsgi.conf
107 fi
108 restart_apache_server
109}
110
zhang-hared98a5d02013-06-21 18:18:02 +0800111# install_apache_wsgi() - Install Apache server and wsgi module
Ian Wienandaee18c72014-02-21 15:35:08 +1100112function install_apache_wsgi {
zhang-hared98a5d02013-06-21 18:18:02 +0800113 # Apache installation, because we mark it NOPRIME
114 if is_ubuntu; then
115 # Install apache2, which is NOPRIME'd
Davanum Srinivasafa8a002016-12-19 09:51:01 -0500116 install_package apache2
117 if python3_enabled; then
118 if is_package_installed libapache2-mod-wsgi; then
119 uninstall_package libapache2-mod-wsgi
120 fi
121 install_package libapache2-mod-wsgi-py3
122 else
123 install_package libapache2-mod-wsgi
124 fi
zhang-hared98a5d02013-06-21 18:18:02 +0800125 elif is_fedora; then
126 sudo rm -f /etc/httpd/conf.d/000-*
127 install_package httpd mod_wsgi
128 elif is_suse; then
129 install_package apache2 apache2-mod_wsgi
130 else
Gregory Haynes4b49e402016-08-31 18:19:51 -0700131 exit_distro_not_supported "apache wsgi installation"
zhang-hared98a5d02013-06-21 18:18:02 +0800132 fi
Gregory Haynes4b49e402016-08-31 18:19:51 -0700133 # WSGI isn't enabled by default, enable it
134 enable_apache_mod wsgi
Morgan Fainbergd074dc72014-06-24 21:33:39 -0700135}
136
Gabriel Assis Bezerraa688bc62014-05-27 20:58:22 +0000137# apache_site_config_for() - The filename of the site's configuration file.
138# This function uses the global variables APACHE_NAME and APACHE_CONF_DIR.
139#
Sean Dague8f8b2742017-04-13 09:34:12 -0400140# On Ubuntu 14.04+, the site configuration file must have a .conf suffix for a2ensite and a2dissite to
Gabriel Assis Bezerraa688bc62014-05-27 20:58:22 +0000141# recognise it. a2ensite and a2dissite ignore the .conf suffix used as parameter. The default sites'
142# files are 000-default.conf and default-ssl.conf.
143#
Ralf Haferkamp633a1292014-06-16 14:10:05 +0200144# On Fedora and openSUSE, any file in /etc/httpd/conf.d/ whose name ends with .conf is enabled.
Gabriel Assis Bezerraa688bc62014-05-27 20:58:22 +0000145#
146# On RHEL and CentOS, things should hopefully work as in Fedora.
147#
148# The table below summarizes what should happen on each distribution:
149# +----------------------+--------------------+--------------------------+--------------------------+
150# | Distribution | File name | Site enabling command | Site disabling command |
151# +----------------------+--------------------+--------------------------+--------------------------+
Gabriel Assis Bezerraa688bc62014-05-27 20:58:22 +0000152# | Ubuntu 14.04 | site.conf | a2ensite site | a2dissite site |
153# | Fedora, RHEL, CentOS | site.conf.disabled | mv site.conf{.disabled,} | mv site.conf{,.disabled} |
154# +----------------------+--------------------+--------------------------+--------------------------+
155function apache_site_config_for {
156 local site=$@
157 if is_ubuntu; then
Sean Dague8f8b2742017-04-13 09:34:12 -0400158 # Ubuntu 14.04 - Apache 2.4
159 echo $APACHE_CONF_DIR/${site}.conf
Ralf Haferkamp633a1292014-06-16 14:10:05 +0200160 elif is_fedora || is_suse; then
Gabriel Assis Bezerraa688bc62014-05-27 20:58:22 +0000161 # fedora conf.d is only imported if it ends with .conf so this is approx the same
Dean Troyer444a8d52014-06-06 16:36:52 -0500162 local enabled_site_file="$APACHE_CONF_DIR/${site}.conf"
Gabriel Assis Bezerraa688bc62014-05-27 20:58:22 +0000163 if [ -f $enabled_site_file ]; then
164 echo ${enabled_site_file}
165 else
166 echo ${enabled_site_file}.disabled
167 fi
168 fi
169}
170
Jamie Lennox54707012013-09-17 12:07:48 +1000171# enable_apache_site() - Enable a particular apache site
Ian Wienandaee18c72014-02-21 15:35:08 +1100172function enable_apache_site {
Jamie Lennox54707012013-09-17 12:07:48 +1000173 local site=$@
174 if is_ubuntu; then
175 sudo a2ensite ${site}
Ralf Haferkamp633a1292014-06-16 14:10:05 +0200176 elif is_fedora || is_suse; then
Dean Troyer444a8d52014-06-06 16:36:52 -0500177 local enabled_site_file="$APACHE_CONF_DIR/${site}.conf"
178 # Do nothing if site already enabled or no site config exists
179 if [[ -f ${enabled_site_file}.disabled ]] && [[ ! -f ${enabled_site_file} ]]; then
180 sudo mv ${enabled_site_file}.disabled ${enabled_site_file}
181 fi
Jamie Lennox54707012013-09-17 12:07:48 +1000182 fi
183}
184
185# disable_apache_site() - Disable a particular apache site
Ian Wienandaee18c72014-02-21 15:35:08 +1100186function disable_apache_site {
Jamie Lennox54707012013-09-17 12:07:48 +1000187 local site=$@
188 if is_ubuntu; then
Chris Dent2fcdaac2017-04-18 16:54:12 +0100189 sudo a2dissite ${site} || true
Ralf Haferkamp633a1292014-06-16 14:10:05 +0200190 elif is_fedora || is_suse; then
Dean Troyer444a8d52014-06-06 16:36:52 -0500191 local enabled_site_file="$APACHE_CONF_DIR/${site}.conf"
192 # Do nothing if no site config exists
193 if [[ -f ${enabled_site_file} ]]; then
194 sudo mv ${enabled_site_file} ${enabled_site_file}.disabled
195 fi
Jamie Lennox54707012013-09-17 12:07:48 +1000196 fi
197}
198
zhang-hared98a5d02013-06-21 18:18:02 +0800199# start_apache_server() - Start running apache server
Ian Wienandaee18c72014-02-21 15:35:08 +1100200function start_apache_server {
zhang-hared98a5d02013-06-21 18:18:02 +0800201 start_service $APACHE_NAME
202}
203
204# stop_apache_server() - Stop running apache server
Ian Wienandaee18c72014-02-21 15:35:08 +1100205function stop_apache_server {
zhang-hared98a5d02013-06-21 18:18:02 +0800206 if [ -n "$APACHE_NAME" ]; then
207 stop_service $APACHE_NAME
208 else
209 exit_distro_not_supported "apache configuration"
210 fi
211}
212
213# restart_apache_server
Ian Wienandaee18c72014-02-21 15:35:08 +1100214function restart_apache_server {
Morgan Fainberg2df00462014-07-15 11:06:36 -0700215 # Apache can be slow to stop, doing an explicit stop, sleep, start helps
216 # to mitigate issues where apache will claim a port it's listening on is
217 # still in use and fail to start.
Sean Dague2b85cf02017-04-13 09:02:14 -0400218 restart_service $APACHE_NAME
zhang-hared98a5d02013-06-21 18:18:02 +0800219}
220
Gregory Haynes4b49e402016-08-31 18:19:51 -0700221# reload_apache_server
222function reload_apache_server {
223 reload_service $APACHE_NAME
224}
225
Sean Dague2f8c88e2017-04-13 09:08:39 -0400226function write_uwsgi_config {
227 local file=$1
228 local wsgi=$2
229 local url=$3
230 local http=$4
231 local name=""
232 name=$(basename $wsgi)
233 local socket="/tmp/${name}.socket"
234
235 # always cleanup given that we are using iniset here
236 rm -rf $file
237 iniset "$file" uwsgi wsgi-file "$wsgi"
238 iniset "$file" uwsgi socket "$socket"
239 iniset "$file" uwsgi processes $API_WORKERS
240 # This is running standalone
241 iniset "$file" uwsgi master true
242 # Set die-on-term & exit-on-reload so that uwsgi shuts down
243 iniset "$file" uwsgi die-on-term true
244 iniset "$file" uwsgi exit-on-reload true
245 iniset "$file" uwsgi enable-threads true
246 iniset "$file" uwsgi plugins python
247 # uwsgi recommends this to prevent thundering herd on accept.
248 iniset "$file" uwsgi thunder-lock true
249 # Override the default size for headers from the 4k default.
250 iniset "$file" uwsgi buffer-size 65535
251 # Make sure the client doesn't try to re-use the connection.
252 iniset "$file" uwsgi add-header "Connection: close"
253 # This ensures that file descriptors aren't shared between processes.
254 iniset "$file" uwsgi lazy-apps true
255 iniset "$file" uwsgi chmod-socket 666
256
257 # If we said bind directly to http, then do that and don't start the apache proxy
258 if [[ -n "$http" ]]; then
259 iniset "$file" uwsgi http $http
260 else
261 local apache_conf=""
262 apache_conf=$(apache_site_config_for $name)
Sean Dague6ed53152017-04-13 13:33:16 -0400263 echo "ProxyPass \"${url}\" \"unix:${socket}|uwsgi://uwsgi-uds-${name}/\" retry=0 " | sudo tee $apache_conf
Sean Dague2f8c88e2017-04-13 09:08:39 -0400264 enable_apache_site $name
265 reload_apache_server
266 fi
267}
268
269function remove_uwsgi_config {
270 local file=$1
271 local wsgi=$2
272 local name=""
273 name=$(basename $wsgi)
274
275 rm -rf $file
276 disable_apache_site $name
277}
278
zhang-hared98a5d02013-06-21 18:18:02 +0800279# Restore xtrace
Ian Wienand523f4882015-10-13 11:03:03 +1100280$_XTRACE_LIB_APACHE
zhang-hared98a5d02013-06-21 18:18:02 +0800281
Adam Spiers6a5aa7c2013-10-24 11:27:02 +0100282# Tell emacs to use shell-script-mode
283## Local variables:
284## mode: shell-script
285## End: