Sean Dague | e263c82 | 2014-12-05 14:25:28 -0500 | [diff] [blame] | 1 | #!/bin/bash |
| 2 | # |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 3 | # lib/swift |
Dean Troyer | 6d04fd7 | 2012-12-21 11:03:37 -0600 | [diff] [blame] | 4 | # Functions to control the configuration and operation of the **Swift** service |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 5 | |
| 6 | # Dependencies: |
Adam Spiers | 6a5aa7c | 2013-10-24 11:27:02 +0100 | [diff] [blame] | 7 | # |
| 8 | # - ``functions`` file |
| 9 | # - ``apache`` file |
| 10 | # - ``DEST``, ``SCREEN_NAME``, `SWIFT_HASH` must be defined |
| 11 | # - ``STACK_USER`` must be defined |
| 12 | # - ``SWIFT_DATA_DIR`` or ``DATA_DIR`` must be defined |
| 13 | # - ``lib/keystone`` file |
| 14 | # |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 15 | # ``stack.sh`` calls the entry points in this order: |
| 16 | # |
Adam Spiers | 6a5aa7c | 2013-10-24 11:27:02 +0100 | [diff] [blame] | 17 | # - install_swift |
| 18 | # - _config_swift_apache_wsgi |
| 19 | # - configure_swift |
| 20 | # - init_swift |
| 21 | # - start_swift |
| 22 | # - stop_swift |
| 23 | # - cleanup_swift |
| 24 | # - _cleanup_swift_apache_wsgi |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 25 | |
| 26 | # Save trace setting |
Ian Wienand | 523f488 | 2015-10-13 11:03:03 +1100 | [diff] [blame] | 27 | _XTRACE_LIB_SWIFT=$(set +o | grep xtrace) |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 28 | set +o xtrace |
| 29 | |
| 30 | |
| 31 | # Defaults |
| 32 | # -------- |
| 33 | |
Rob Crittenden | 18d4778 | 2014-03-19 17:47:42 -0400 | [diff] [blame] | 34 | if is_ssl_enabled_service "s-proxy" || is_service_enabled tls-proxy; then |
| 35 | SWIFT_SERVICE_PROTOCOL="https" |
| 36 | fi |
| 37 | |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 38 | # Set up default directories |
Sean Dague | e08ab10 | 2014-11-13 17:09:28 -0500 | [diff] [blame] | 39 | GITDIR["python-swiftclient"]=$DEST/python-swiftclient |
Sean Dague | 5cb1906 | 2014-11-01 01:37:45 +0100 | [diff] [blame] | 40 | |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 41 | SWIFT_DIR=$DEST/swift |
Dean Troyer | 64ab774 | 2012-12-28 15:38:28 -0600 | [diff] [blame] | 42 | SWIFT_AUTH_CACHE_DIR=${SWIFT_AUTH_CACHE_DIR:-/var/cache/swift} |
zhang-hare | d98a5d0 | 2013-06-21 18:18:02 +0800 | [diff] [blame] | 43 | SWIFT_APACHE_WSGI_DIR=${SWIFT_APACHE_WSGI_DIR:-/var/www/swift} |
Dean Troyer | b7490da | 2013-03-18 16:07:56 -0500 | [diff] [blame] | 44 | SWIFT3_DIR=$DEST/swift3 |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 45 | |
Rob Crittenden | 18d4778 | 2014-03-19 17:47:42 -0400 | [diff] [blame] | 46 | SWIFT_SERVICE_PROTOCOL=${SWIFT_SERVICE_PROTOCOL:-$SERVICE_PROTOCOL} |
Falk Reimann | 22f747b | 2015-08-28 12:40:19 +0200 | [diff] [blame] | 47 | SWIFT_DEFAULT_BIND_PORT=${SWIFT_DEFAULT_BIND_PORT:-8080} |
Rob Crittenden | 18d4778 | 2014-03-19 17:47:42 -0400 | [diff] [blame] | 48 | SWIFT_DEFAULT_BIND_PORT_INT=${SWIFT_DEFAULT_BIND_PORT_INT:-8081} |
Brian Haley | 180f5eb | 2015-06-16 13:14:31 -0400 | [diff] [blame] | 49 | SWIFT_SERVICE_LOCAL_HOST=${SWIFT_SERVICE_LOCAL_HOST:-$SERVICE_LOCAL_HOST} |
Rawlin Peters | 92ad152 | 2015-07-20 13:33:33 -0600 | [diff] [blame] | 50 | SWIFT_SERVICE_LISTEN_ADDRESS=${SWIFT_SERVICE_LISTEN_ADDRESS:-$SERVICE_LISTEN_ADDRESS} |
Rob Crittenden | 18d4778 | 2014-03-19 17:47:42 -0400 | [diff] [blame] | 51 | |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 52 | # TODO: add logging to different location. |
| 53 | |
| 54 | # Set ``SWIFT_DATA_DIR`` to the location of swift drives and objects. |
| 55 | # Default is the common DevStack data directory. |
| 56 | SWIFT_DATA_DIR=${SWIFT_DATA_DIR:-${DATA_DIR}/swift} |
Attila Fazekas | e602441 | 2013-09-15 18:38:48 +0200 | [diff] [blame] | 57 | SWIFT_DISK_IMAGE=${SWIFT_DATA_DIR}/drives/images/swift.img |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 58 | |
Dean Troyer | 6ec72fa | 2013-03-13 11:44:53 -0500 | [diff] [blame] | 59 | # Set ``SWIFT_CONF_DIR`` to the location of the configuration files. |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 60 | # Default is ``/etc/swift``. |
JordanP | a6dfe81 | 2014-11-20 18:06:23 +0100 | [diff] [blame] | 61 | SWIFT_CONF_DIR=${SWIFT_CONF_DIR:-/etc/swift} |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 62 | |
Dean Troyer | b7490da | 2013-03-18 16:07:56 -0500 | [diff] [blame] | 63 | if is_service_enabled s-proxy && is_service_enabled swift3; then |
Dean Troyer | dc97cb7 | 2015-03-28 08:20:50 -0500 | [diff] [blame] | 64 | # If we are using ``swift3``, we can default the S3 port to swift instead |
Dean Troyer | b7490da | 2013-03-18 16:07:56 -0500 | [diff] [blame] | 65 | # of nova-objectstore |
Falk Reimann | 22f747b | 2015-08-28 12:40:19 +0200 | [diff] [blame] | 66 | S3_SERVICE_PORT=${S3_SERVICE_PORT:-$SWIFT_DEFAULT_BIND_PORT} |
Dean Troyer | b7490da | 2013-03-18 16:07:56 -0500 | [diff] [blame] | 67 | fi |
| 68 | |
Ivan Kolodyazhny | 9ebd65b | 2015-03-08 23:51:55 +0200 | [diff] [blame] | 69 | if is_service_enabled g-api; then |
| 70 | # Minimum Cinder volume size is 1G so if Swift backend for Glance is |
| 71 | # only 1G we can not upload volume to image. |
| 72 | # Increase Swift disk size up to 2G |
| 73 | SWIFT_LOOPBACK_DISK_SIZE_DEFAULT=2G |
Matthew Oliver | 7b85723 | 2016-03-07 18:21:29 +1100 | [diff] [blame^] | 74 | SWIFT_MAX_FILE_SIZE_DEFAULT=1073741824 # 1G |
Ivan Kolodyazhny | 9ebd65b | 2015-03-08 23:51:55 +0200 | [diff] [blame] | 75 | else |
| 76 | # DevStack will create a loop-back disk formatted as XFS to store the |
| 77 | # swift data. Set ``SWIFT_LOOPBACK_DISK_SIZE`` to the disk size in |
| 78 | # kilobytes. |
| 79 | # Default is 1 gigabyte. |
| 80 | SWIFT_LOOPBACK_DISK_SIZE_DEFAULT=1G |
Matthew Oliver | 7b85723 | 2016-03-07 18:21:29 +1100 | [diff] [blame^] | 81 | SWIFT_MAX_FILE_SIZE_DEFAULT=536870912 # 512M |
Ivan Kolodyazhny | 9ebd65b | 2015-03-08 23:51:55 +0200 | [diff] [blame] | 82 | fi |
| 83 | |
Joe Gordon | 66c5424 | 2013-11-12 16:24:14 -0800 | [diff] [blame] | 84 | # if tempest enabled the default size is 6 Gigabyte. |
Attila Fazekas | 3418c1c | 2013-09-16 18:35:49 +0200 | [diff] [blame] | 85 | if is_service_enabled tempest; then |
Joe Gordon | 66c5424 | 2013-11-12 16:24:14 -0800 | [diff] [blame] | 86 | SWIFT_LOOPBACK_DISK_SIZE_DEFAULT=${SWIFT_LOOPBACK_DISK_SIZE:-6G} |
Matthew Oliver | 7b85723 | 2016-03-07 18:21:29 +1100 | [diff] [blame^] | 87 | SWIFT_MAX_FILE_SIZE_DEFAULT=5368709122 # Swift default 5G |
Attila Fazekas | 3418c1c | 2013-09-16 18:35:49 +0200 | [diff] [blame] | 88 | fi |
| 89 | |
| 90 | SWIFT_LOOPBACK_DISK_SIZE=${SWIFT_LOOPBACK_DISK_SIZE:-$SWIFT_LOOPBACK_DISK_SIZE_DEFAULT} |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 91 | |
Chmouel Boudjnah | bc3a339 | 2013-02-23 04:00:51 +0100 | [diff] [blame] | 92 | # Set ``SWIFT_EXTRAS_MIDDLEWARE`` to extras middlewares. |
Samuel Merritt | f19ccb6 | 2014-03-08 07:54:05 -0800 | [diff] [blame] | 93 | # Default is ``staticweb, formpost`` |
| 94 | SWIFT_EXTRAS_MIDDLEWARE=${SWIFT_EXTRAS_MIDDLEWARE:-formpost staticweb} |
Chmouel Boudjnah | bc3a339 | 2013-02-23 04:00:51 +0100 | [diff] [blame] | 95 | |
Cyril Roelandt | d988340 | 2013-09-27 15:16:51 +0000 | [diff] [blame] | 96 | # Set ``SWIFT_EXTRAS_MIDDLEWARE_LAST`` to extras middlewares that need to be at |
| 97 | # the end of the pipeline. |
Sean Dague | 5375329 | 2014-12-04 19:38:15 -0500 | [diff] [blame] | 98 | SWIFT_EXTRAS_MIDDLEWARE_LAST=${SWIFT_EXTRAS_MIDDLEWARE_LAST:-} |
Cyril Roelandt | d988340 | 2013-09-27 15:16:51 +0000 | [diff] [blame] | 99 | |
Joe H. Rahme | 1ce2ffd | 2013-10-22 15:19:09 +0200 | [diff] [blame] | 100 | # Set ``SWIFT_EXTRAS_MIDDLEWARE_NO_AUTH`` to extras middlewares that need to be at |
| 101 | # the beginning of the pipeline, before authentication middlewares. |
| 102 | SWIFT_EXTRAS_MIDDLEWARE_NO_AUTH=${SWIFT_EXTRAS_MIDDLEWARE_NO_AUTH:-crossdomain} |
| 103 | |
Marian Horban | ea21eb4 | 2015-08-18 06:57:18 -0400 | [diff] [blame] | 104 | # The ring uses a configurable number of bits from a path's MD5 hash as |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 105 | # a partition index that designates a device. The number of bits kept |
| 106 | # from the hash is known as the partition power, and 2 to the partition |
| 107 | # power indicates the partition count. Partitioning the full MD5 hash |
| 108 | # ring allows other parts of the cluster to work in batches of items at |
| 109 | # once which ends up either more efficient or at least less complex than |
| 110 | # working with each item separately or the entire cluster all at once. |
| 111 | # By default we define 9 for the partition count (which mean 512). |
| 112 | SWIFT_PARTITION_POWER_SIZE=${SWIFT_PARTITION_POWER_SIZE:-9} |
| 113 | |
| 114 | # Set ``SWIFT_REPLICAS`` to configure how many replicas are to be |
Chmouel Boudjnah | 0c3a558 | 2013-03-06 10:58:33 +0100 | [diff] [blame] | 115 | # configured for your Swift cluster. By default we are configuring |
| 116 | # only one replica since this is way less CPU and memory intensive. If |
| 117 | # you are planning to test swift replication you may want to set this |
| 118 | # up to 3. |
| 119 | SWIFT_REPLICAS=${SWIFT_REPLICAS:-1} |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 120 | SWIFT_REPLICAS_SEQ=$(seq ${SWIFT_REPLICAS}) |
| 121 | |
Peter Portante | cee4b3b | 2013-11-20 14:33:16 -0500 | [diff] [blame] | 122 | # Set ``SWIFT_LOG_TOKEN_LENGTH`` to configure how many characters of an auth |
| 123 | # token should be placed in the logs. When keystone is used with PKI tokens, |
| 124 | # the token values can be huge, seemingly larger the 2K, at the least. We |
| 125 | # restrict it here to a default of 12 characters, which should be enough to |
| 126 | # trace through the logs when looking for its use. |
| 127 | SWIFT_LOG_TOKEN_LENGTH=${SWIFT_LOG_TOKEN_LENGTH:-12} |
| 128 | |
Atsushi SAKAI | fe7b56c | 2015-11-13 17:06:16 +0900 | [diff] [blame] | 129 | # Set ``SWIFT_MAX_HEADER_SIZE`` to configure the maximum length of headers in |
Julien Vey | 63024d9 | 2014-05-06 15:10:07 +0200 | [diff] [blame] | 130 | # Swift API |
| 131 | SWIFT_MAX_HEADER_SIZE=${SWIFT_MAX_HEADER_SIZE:-16384} |
| 132 | |
Matthew Oliver | 7b85723 | 2016-03-07 18:21:29 +1100 | [diff] [blame^] | 133 | # Set ``SWIFT_MAX_FILE_SIZE`` to configure the maximum file size in Swift API |
| 134 | # Default 500MB because the loopback file used for swift could be 1 or 2 GB |
| 135 | SWIFT_MAX_FILE_SIZE=${SWIFT_MAX_FILE_SIZE:-$SWIFT_MAX_FILE_SIZE_DEFAULT} |
| 136 | |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 137 | # Set ``OBJECT_PORT_BASE``, ``CONTAINER_PORT_BASE``, ``ACCOUNT_PORT_BASE`` |
Atsushi SAKAI | fe7b56c | 2015-11-13 17:06:16 +0900 | [diff] [blame] | 138 | # Port bases used in port number calculation for the service "nodes" |
| 139 | # The specified port number will be used, the additional ports calculated by |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 140 | # base_port + node_num * 10 |
Denis Afonso | dbe0868 | 2015-10-02 23:51:41 -0400 | [diff] [blame] | 141 | OBJECT_PORT_BASE=${OBJECT_PORT_BASE:-6613} |
| 142 | CONTAINER_PORT_BASE=${CONTAINER_PORT_BASE:-6611} |
| 143 | ACCOUNT_PORT_BASE=${ACCOUNT_PORT_BASE:-6612} |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 144 | |
Jim Rollenhagen | abbb0e9 | 2014-08-05 18:01:48 +0000 | [diff] [blame] | 145 | # Enable tempurl feature |
| 146 | SWIFT_ENABLE_TEMPURLS=${SWIFT_ENABLE_TEMPURLS:-False} |
Sean Dague | 5375329 | 2014-12-04 19:38:15 -0500 | [diff] [blame] | 147 | SWIFT_TEMPURL_KEY=${SWIFT_TEMPURL_KEY:-} |
Jim Rollenhagen | abbb0e9 | 2014-08-05 18:01:48 +0000 | [diff] [blame] | 148 | |
Dean Troyer | dc97cb7 | 2015-03-28 08:20:50 -0500 | [diff] [blame] | 149 | # Toggle for deploying Swift under HTTPD + mod_wsgi |
| 150 | SWIFT_USE_MOD_WSGI=${SWIFT_USE_MOD_WSGI:-False} |
| 151 | |
Dean Troyer | cc6b443 | 2013-04-08 15:38:03 -0500 | [diff] [blame] | 152 | # Functions |
| 153 | # --------- |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 154 | |
Dean Troyer | e4fa721 | 2014-01-15 15:04:49 -0600 | [diff] [blame] | 155 | # Test if any Swift services are enabled |
| 156 | # is_swift_enabled |
| 157 | function is_swift_enabled { |
| 158 | [[ ,${ENABLED_SERVICES} =~ ,"s-" ]] && return 0 |
| 159 | return 1 |
| 160 | } |
| 161 | |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 162 | # cleanup_swift() - Remove residual data files |
Ian Wienand | aee18c7 | 2014-02-21 15:35:08 +1100 | [diff] [blame] | 163 | function cleanup_swift { |
Sean Dague | 101b424 | 2013-10-22 08:47:11 -0400 | [diff] [blame] | 164 | rm -f ${SWIFT_CONF_DIR}{*.builder,*.ring.gz,backups/*.builder,backups/*.ring.gz} |
| 165 | if egrep -q ${SWIFT_DATA_DIR}/drives/sdb1 /proc/mounts; then |
| 166 | sudo umount ${SWIFT_DATA_DIR}/drives/sdb1 |
| 167 | fi |
| 168 | if [[ -e ${SWIFT_DISK_IMAGE} ]]; then |
| 169 | rm ${SWIFT_DISK_IMAGE} |
| 170 | fi |
| 171 | rm -rf ${SWIFT_DATA_DIR}/run/ |
Morgan Fainberg | 46455a3 | 2014-06-20 10:37:18 -0700 | [diff] [blame] | 172 | if [ "$SWIFT_USE_MOD_WSGI" == "True" ]; then |
Sean Dague | 101b424 | 2013-10-22 08:47:11 -0400 | [diff] [blame] | 173 | _cleanup_swift_apache_wsgi |
| 174 | fi |
zhang-hare | d98a5d0 | 2013-06-21 18:18:02 +0800 | [diff] [blame] | 175 | } |
| 176 | |
| 177 | # _cleanup_swift_apache_wsgi() - Remove wsgi files, disable and remove apache vhost file |
Ian Wienand | aee18c7 | 2014-02-21 15:35:08 +1100 | [diff] [blame] | 178 | function _cleanup_swift_apache_wsgi { |
zhang-hare | d98a5d0 | 2013-06-21 18:18:02 +0800 | [diff] [blame] | 179 | sudo rm -f $SWIFT_APACHE_WSGI_DIR/*.wsgi |
Jamie Lennox | 5470701 | 2013-09-17 12:07:48 +1000 | [diff] [blame] | 180 | disable_apache_site proxy-server |
Dean Troyer | 084f51f | 2014-07-25 15:08:52 -0500 | [diff] [blame] | 181 | local node_number type |
zhang-hare | d98a5d0 | 2013-06-21 18:18:02 +0800 | [diff] [blame] | 182 | for node_number in ${SWIFT_REPLICAS_SEQ}; do |
| 183 | for type in object container account; do |
Dean Troyer | 084f51f | 2014-07-25 15:08:52 -0500 | [diff] [blame] | 184 | local site_name=${type}-server-${node_number} |
Jamie Lennox | 5470701 | 2013-09-17 12:07:48 +1000 | [diff] [blame] | 185 | disable_apache_site ${site_name} |
Gabriel Assis Bezerra | a688bc6 | 2014-05-27 20:58:22 +0000 | [diff] [blame] | 186 | sudo rm -f $(apache_site_config_for ${site_name}) |
zhang-hare | d98a5d0 | 2013-06-21 18:18:02 +0800 | [diff] [blame] | 187 | done |
| 188 | done |
| 189 | } |
| 190 | |
| 191 | # _config_swift_apache_wsgi() - Set WSGI config files of Swift |
Ian Wienand | aee18c7 | 2014-02-21 15:35:08 +1100 | [diff] [blame] | 192 | function _config_swift_apache_wsgi { |
zhang-hare | d98a5d0 | 2013-06-21 18:18:02 +0800 | [diff] [blame] | 193 | sudo mkdir -p ${SWIFT_APACHE_WSGI_DIR} |
Falk Reimann | 22f747b | 2015-08-28 12:40:19 +0200 | [diff] [blame] | 194 | local proxy_port=${SWIFT_DEFAULT_BIND_PORT} |
zhang-hare | d98a5d0 | 2013-06-21 18:18:02 +0800 | [diff] [blame] | 195 | |
| 196 | # copy proxy vhost and wsgi file |
Gabriel Assis Bezerra | a688bc6 | 2014-05-27 20:58:22 +0000 | [diff] [blame] | 197 | sudo cp ${SWIFT_DIR}/examples/apache2/proxy-server.template $(apache_site_config_for proxy-server) |
zhang-hare | d98a5d0 | 2013-06-21 18:18:02 +0800 | [diff] [blame] | 198 | sudo sed -e " |
| 199 | /^#/d;/^$/d; |
| 200 | s/%PORT%/$proxy_port/g; |
| 201 | s/%SERVICENAME%/proxy-server/g; |
| 202 | s/%APACHE_NAME%/${APACHE_NAME}/g; |
Jamie Lennox | d582460 | 2013-09-17 11:44:37 +1000 | [diff] [blame] | 203 | s/%USER%/${STACK_USER}/g; |
Gabriel Assis Bezerra | a688bc6 | 2014-05-27 20:58:22 +0000 | [diff] [blame] | 204 | " -i $(apache_site_config_for proxy-server) |
Jamie Lennox | 5470701 | 2013-09-17 12:07:48 +1000 | [diff] [blame] | 205 | enable_apache_site proxy-server |
zhang-hare | d98a5d0 | 2013-06-21 18:18:02 +0800 | [diff] [blame] | 206 | |
| 207 | sudo cp ${SWIFT_DIR}/examples/wsgi/proxy-server.wsgi.template ${SWIFT_APACHE_WSGI_DIR}/proxy-server.wsgi |
| 208 | sudo sed -e " |
| 209 | /^#/d;/^$/d; |
| 210 | s/%SERVICECONF%/proxy-server.conf/g; |
| 211 | " -i ${SWIFT_APACHE_WSGI_DIR}/proxy-server.wsgi |
zhang-hare | d98a5d0 | 2013-06-21 18:18:02 +0800 | [diff] [blame] | 212 | |
| 213 | # copy apache vhost file and set name and port |
Dean Troyer | 084f51f | 2014-07-25 15:08:52 -0500 | [diff] [blame] | 214 | local node_number |
zhang-hare | d98a5d0 | 2013-06-21 18:18:02 +0800 | [diff] [blame] | 215 | for node_number in ${SWIFT_REPLICAS_SEQ}; do |
Ian Wienand | ada886d | 2015-10-07 14:06:26 +1100 | [diff] [blame] | 216 | local object_port |
| 217 | object_port=$(( OBJECT_PORT_BASE + 10 * (node_number - 1) )) |
| 218 | local container_port |
| 219 | container_port=$(( CONTAINER_PORT_BASE + 10 * (node_number - 1) )) |
| 220 | local account_port |
| 221 | account_port=$(( ACCOUNT_PORT_BASE + 10 * (node_number - 1) )) |
zhang-hare | d98a5d0 | 2013-06-21 18:18:02 +0800 | [diff] [blame] | 222 | |
Gabriel Assis Bezerra | a688bc6 | 2014-05-27 20:58:22 +0000 | [diff] [blame] | 223 | sudo cp ${SWIFT_DIR}/examples/apache2/object-server.template $(apache_site_config_for object-server-${node_number}) |
zhang-hare | d98a5d0 | 2013-06-21 18:18:02 +0800 | [diff] [blame] | 224 | sudo sed -e " |
| 225 | s/%PORT%/$object_port/g; |
| 226 | s/%SERVICENAME%/object-server-${node_number}/g; |
| 227 | s/%APACHE_NAME%/${APACHE_NAME}/g; |
Jamie Lennox | d582460 | 2013-09-17 11:44:37 +1000 | [diff] [blame] | 228 | s/%USER%/${STACK_USER}/g; |
Gabriel Assis Bezerra | a688bc6 | 2014-05-27 20:58:22 +0000 | [diff] [blame] | 229 | " -i $(apache_site_config_for object-server-${node_number}) |
Jamie Lennox | 5470701 | 2013-09-17 12:07:48 +1000 | [diff] [blame] | 230 | enable_apache_site object-server-${node_number} |
zhang-hare | d98a5d0 | 2013-06-21 18:18:02 +0800 | [diff] [blame] | 231 | |
| 232 | sudo cp ${SWIFT_DIR}/examples/wsgi/object-server.wsgi.template ${SWIFT_APACHE_WSGI_DIR}/object-server-${node_number}.wsgi |
| 233 | sudo sed -e " |
| 234 | /^#/d;/^$/d; |
| 235 | s/%SERVICECONF%/object-server\/${node_number}.conf/g; |
| 236 | " -i ${SWIFT_APACHE_WSGI_DIR}/object-server-${node_number}.wsgi |
| 237 | |
Gabriel Assis Bezerra | a688bc6 | 2014-05-27 20:58:22 +0000 | [diff] [blame] | 238 | sudo cp ${SWIFT_DIR}/examples/apache2/container-server.template $(apache_site_config_for container-server-${node_number}) |
zhang-hare | d98a5d0 | 2013-06-21 18:18:02 +0800 | [diff] [blame] | 239 | sudo sed -e " |
| 240 | /^#/d;/^$/d; |
| 241 | s/%PORT%/$container_port/g; |
| 242 | s/%SERVICENAME%/container-server-${node_number}/g; |
| 243 | s/%APACHE_NAME%/${APACHE_NAME}/g; |
Jamie Lennox | d582460 | 2013-09-17 11:44:37 +1000 | [diff] [blame] | 244 | s/%USER%/${STACK_USER}/g; |
Gabriel Assis Bezerra | a688bc6 | 2014-05-27 20:58:22 +0000 | [diff] [blame] | 245 | " -i $(apache_site_config_for container-server-${node_number}) |
Jamie Lennox | 5470701 | 2013-09-17 12:07:48 +1000 | [diff] [blame] | 246 | enable_apache_site container-server-${node_number} |
zhang-hare | d98a5d0 | 2013-06-21 18:18:02 +0800 | [diff] [blame] | 247 | |
| 248 | sudo cp ${SWIFT_DIR}/examples/wsgi/container-server.wsgi.template ${SWIFT_APACHE_WSGI_DIR}/container-server-${node_number}.wsgi |
| 249 | sudo sed -e " |
| 250 | /^#/d;/^$/d; |
| 251 | s/%SERVICECONF%/container-server\/${node_number}.conf/g; |
| 252 | " -i ${SWIFT_APACHE_WSGI_DIR}/container-server-${node_number}.wsgi |
| 253 | |
Gabriel Assis Bezerra | a688bc6 | 2014-05-27 20:58:22 +0000 | [diff] [blame] | 254 | sudo cp ${SWIFT_DIR}/examples/apache2/account-server.template $(apache_site_config_for account-server-${node_number}) |
zhang-hare | d98a5d0 | 2013-06-21 18:18:02 +0800 | [diff] [blame] | 255 | sudo sed -e " |
Sean Dague | 101b424 | 2013-10-22 08:47:11 -0400 | [diff] [blame] | 256 | /^#/d;/^$/d; |
zhang-hare | d98a5d0 | 2013-06-21 18:18:02 +0800 | [diff] [blame] | 257 | s/%PORT%/$account_port/g; |
| 258 | s/%SERVICENAME%/account-server-${node_number}/g; |
| 259 | s/%APACHE_NAME%/${APACHE_NAME}/g; |
Jamie Lennox | d582460 | 2013-09-17 11:44:37 +1000 | [diff] [blame] | 260 | s/%USER%/${STACK_USER}/g; |
Gabriel Assis Bezerra | a688bc6 | 2014-05-27 20:58:22 +0000 | [diff] [blame] | 261 | " -i $(apache_site_config_for account-server-${node_number}) |
Jamie Lennox | 5470701 | 2013-09-17 12:07:48 +1000 | [diff] [blame] | 262 | enable_apache_site account-server-${node_number} |
zhang-hare | d98a5d0 | 2013-06-21 18:18:02 +0800 | [diff] [blame] | 263 | |
| 264 | sudo cp ${SWIFT_DIR}/examples/wsgi/account-server.wsgi.template ${SWIFT_APACHE_WSGI_DIR}/account-server-${node_number}.wsgi |
| 265 | sudo sed -e " |
Sean Dague | 101b424 | 2013-10-22 08:47:11 -0400 | [diff] [blame] | 266 | /^#/d;/^$/d; |
zhang-hare | d98a5d0 | 2013-06-21 18:18:02 +0800 | [diff] [blame] | 267 | s/%SERVICECONF%/account-server\/${node_number}.conf/g; |
| 268 | " -i ${SWIFT_APACHE_WSGI_DIR}/account-server-${node_number}.wsgi |
zhang-hare | d98a5d0 | 2013-06-21 18:18:02 +0800 | [diff] [blame] | 269 | done |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 270 | } |
| 271 | |
Ian Wienand | f8e86bb | 2014-02-21 15:16:31 +1100 | [diff] [blame] | 272 | # This function generates an object/container/account configuration |
| 273 | # emulating 4 nodes on different ports |
Chmouel Boudjnah | 6c585d7 | 2014-10-04 08:14:30 +0200 | [diff] [blame] | 274 | function generate_swift_config_services { |
Ian Wienand | f8e86bb | 2014-02-21 15:16:31 +1100 | [diff] [blame] | 275 | local swift_node_config=$1 |
| 276 | local node_id=$2 |
| 277 | local bind_port=$3 |
| 278 | local server_type=$4 |
| 279 | |
Ian Wienand | 761c456 | 2014-10-21 11:41:37 +1100 | [diff] [blame] | 280 | log_facility=$(( node_id - 1 )) |
Dean Troyer | 084f51f | 2014-07-25 15:08:52 -0500 | [diff] [blame] | 281 | local node_path=${SWIFT_DATA_DIR}/${node_number} |
Ian Wienand | f8e86bb | 2014-02-21 15:16:31 +1100 | [diff] [blame] | 282 | |
| 283 | iniuncomment ${swift_node_config} DEFAULT user |
| 284 | iniset ${swift_node_config} DEFAULT user ${STACK_USER} |
| 285 | |
| 286 | iniuncomment ${swift_node_config} DEFAULT bind_port |
| 287 | iniset ${swift_node_config} DEFAULT bind_port ${bind_port} |
| 288 | |
| 289 | iniuncomment ${swift_node_config} DEFAULT swift_dir |
| 290 | iniset ${swift_node_config} DEFAULT swift_dir ${SWIFT_CONF_DIR} |
| 291 | |
| 292 | iniuncomment ${swift_node_config} DEFAULT devices |
| 293 | iniset ${swift_node_config} DEFAULT devices ${node_path} |
| 294 | |
| 295 | iniuncomment ${swift_node_config} DEFAULT log_facility |
| 296 | iniset ${swift_node_config} DEFAULT log_facility LOG_LOCAL${log_facility} |
| 297 | |
| 298 | iniuncomment ${swift_node_config} DEFAULT workers |
Chmouel Boudjnah | 55dc2c2 | 2014-09-12 09:34:20 +0200 | [diff] [blame] | 299 | iniset ${swift_node_config} DEFAULT workers ${API_WORKERS:-1} |
Ian Wienand | f8e86bb | 2014-02-21 15:16:31 +1100 | [diff] [blame] | 300 | |
| 301 | iniuncomment ${swift_node_config} DEFAULT disable_fallocate |
| 302 | iniset ${swift_node_config} DEFAULT disable_fallocate true |
| 303 | |
| 304 | iniuncomment ${swift_node_config} DEFAULT mount_check |
| 305 | iniset ${swift_node_config} DEFAULT mount_check false |
| 306 | |
| 307 | iniuncomment ${swift_node_config} ${server_type}-replicator vm_test_mode |
| 308 | iniset ${swift_node_config} ${server_type}-replicator vm_test_mode yes |
Chmouel Boudjnah | 6c585d7 | 2014-10-04 08:14:30 +0200 | [diff] [blame] | 309 | |
| 310 | # Using a sed and not iniset/iniuncomment because we want to a global |
| 311 | # modification and make sure it works for new sections. |
| 312 | sed -i -e "s,#[ ]*recon_cache_path .*,recon_cache_path = ${SWIFT_DATA_DIR}/cache," ${swift_node_config} |
Ian Wienand | f8e86bb | 2014-02-21 15:16:31 +1100 | [diff] [blame] | 313 | } |
| 314 | |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 315 | # configure_swift() - Set config files, create data dirs and loop image |
Ian Wienand | aee18c7 | 2014-02-21 15:35:08 +1100 | [diff] [blame] | 316 | function configure_swift { |
Joe H. Rahme | 1ce2ffd | 2013-10-22 15:19:09 +0200 | [diff] [blame] | 317 | local swift_pipeline="${SWIFT_EXTRAS_MIDDLEWARE_NO_AUTH}" |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 318 | local node_number |
| 319 | local swift_node_config |
| 320 | local swift_log_dir |
Geronimo Orozco | 2f6576b | 2015-03-19 12:08:23 -0600 | [diff] [blame] | 321 | local user_group |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 322 | |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 323 | # Make sure to kill all swift processes first |
Chmouel Boudjnah | ad8b276 | 2013-01-10 15:40:01 +0100 | [diff] [blame] | 324 | swift-init --run-dir=${SWIFT_DATA_DIR}/run all stop || true |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 325 | |
Dean Troyer | 8421c2b | 2015-03-16 13:52:19 -0500 | [diff] [blame] | 326 | sudo install -d -o ${STACK_USER} ${SWIFT_CONF_DIR} |
| 327 | sudo install -d -o ${STACK_USER} ${SWIFT_CONF_DIR}/{object,container,account}-server |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 328 | |
Dean Troyer | 6ec72fa | 2013-03-13 11:44:53 -0500 | [diff] [blame] | 329 | if [[ "$SWIFT_CONF_DIR" != "/etc/swift" ]]; then |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 330 | # Some swift tools are hard-coded to use ``/etc/swift`` and are apparently not going to be fixed. |
| 331 | # Create a symlink if the config dir is moved |
Dean Troyer | 6ec72fa | 2013-03-13 11:44:53 -0500 | [diff] [blame] | 332 | sudo ln -sf ${SWIFT_CONF_DIR} /etc/swift |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 333 | fi |
| 334 | |
| 335 | # Swift use rsync to synchronize between all the different |
| 336 | # partitions (which make more sense when you have a multi-node |
| 337 | # setup) we configure it with our version of rsync. |
| 338 | sed -e " |
| 339 | s/%GROUP%/${USER_GROUP}/; |
Stephan Renatus | e578eff | 2013-11-19 13:31:04 +0100 | [diff] [blame] | 340 | s/%USER%/${STACK_USER}/; |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 341 | s,%SWIFT_DATA_DIR%,$SWIFT_DATA_DIR,; |
| 342 | " $FILES/swift/rsyncd.conf | sudo tee /etc/rsyncd.conf |
| 343 | # rsyncd.conf just prepared for 4 nodes |
Vincent Untz | c18b965 | 2012-12-04 12:36:34 +0100 | [diff] [blame] | 344 | if is_ubuntu; then |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 345 | sudo sed -i '/^RSYNC_ENABLE=false/ { s/false/true/ }' /etc/default/rsync |
Attila Fazekas | 0e57b96 | 2014-02-28 09:09:52 +0100 | [diff] [blame] | 346 | elif [ -e /etc/xinetd.d/rsync ]; then |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 347 | sudo sed -i '/disable *= *yes/ { s/yes/no/ }' /etc/xinetd.d/rsync |
| 348 | fi |
| 349 | |
Dean Troyer | 6ec72fa | 2013-03-13 11:44:53 -0500 | [diff] [blame] | 350 | SWIFT_CONFIG_PROXY_SERVER=${SWIFT_CONF_DIR}/proxy-server.conf |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 351 | cp ${SWIFT_DIR}/etc/proxy-server.conf-sample ${SWIFT_CONFIG_PROXY_SERVER} |
| 352 | |
Daisuke Morita | d03915f | 2014-10-08 06:52:21 +0000 | [diff] [blame] | 353 | # To run container sync feature introduced in Swift ver 1.12.0, |
| 354 | # container sync "realm" is added in container-sync-realms.conf |
| 355 | local csyncfile=${SWIFT_CONF_DIR}/container-sync-realms.conf |
| 356 | cp ${SWIFT_DIR}/etc/container-sync-realms.conf-sample ${csyncfile} |
| 357 | iniset ${csyncfile} realm1 key realm1key |
Falk Reimann | 22f747b | 2015-08-28 12:40:19 +0200 | [diff] [blame] | 358 | iniset ${csyncfile} realm1 cluster_name1 "$SWIFT_SERVICE_PROTOCOL://$SERVICE_HOST:$SWIFT_DEFAULT_BIND_PORT/v1/" |
Chmouel Boudjnah | f2c1a71 | 2014-01-29 21:38:14 +0000 | [diff] [blame] | 359 | |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 360 | iniuncomment ${SWIFT_CONFIG_PROXY_SERVER} DEFAULT user |
Stephan Renatus | e578eff | 2013-11-19 13:31:04 +0100 | [diff] [blame] | 361 | iniset ${SWIFT_CONFIG_PROXY_SERVER} DEFAULT user ${STACK_USER} |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 362 | |
| 363 | iniuncomment ${SWIFT_CONFIG_PROXY_SERVER} DEFAULT swift_dir |
Dean Troyer | 6ec72fa | 2013-03-13 11:44:53 -0500 | [diff] [blame] | 364 | iniset ${SWIFT_CONFIG_PROXY_SERVER} DEFAULT swift_dir ${SWIFT_CONF_DIR} |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 365 | |
| 366 | iniuncomment ${SWIFT_CONFIG_PROXY_SERVER} DEFAULT workers |
| 367 | iniset ${SWIFT_CONFIG_PROXY_SERVER} DEFAULT workers 1 |
| 368 | |
| 369 | iniuncomment ${SWIFT_CONFIG_PROXY_SERVER} DEFAULT log_level |
| 370 | iniset ${SWIFT_CONFIG_PROXY_SERVER} DEFAULT log_level DEBUG |
| 371 | |
Rawlin Peters | 92ad152 | 2015-07-20 13:33:33 -0600 | [diff] [blame] | 372 | iniuncomment ${SWIFT_CONFIG_PROXY_SERVER} DEFAULT bind_ip |
| 373 | iniset ${SWIFT_CONFIG_PROXY_SERVER} DEFAULT bind_ip ${SWIFT_SERVICE_LISTEN_ADDRESS} |
| 374 | |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 375 | iniuncomment ${SWIFT_CONFIG_PROXY_SERVER} DEFAULT bind_port |
Rob Crittenden | 18d4778 | 2014-03-19 17:47:42 -0400 | [diff] [blame] | 376 | if is_service_enabled tls-proxy; then |
| 377 | iniset ${SWIFT_CONFIG_PROXY_SERVER} DEFAULT bind_port ${SWIFT_DEFAULT_BIND_PORT_INT} |
| 378 | else |
Falk Reimann | 22f747b | 2015-08-28 12:40:19 +0200 | [diff] [blame] | 379 | iniset ${SWIFT_CONFIG_PROXY_SERVER} DEFAULT bind_port ${SWIFT_DEFAULT_BIND_PORT} |
Rob Crittenden | 18d4778 | 2014-03-19 17:47:42 -0400 | [diff] [blame] | 380 | fi |
| 381 | |
| 382 | if is_ssl_enabled_service s-proxy; then |
| 383 | ensure_certificates SWIFT |
| 384 | |
| 385 | iniset ${SWIFT_CONFIG_PROXY_SERVER} DEFAULT cert_file "$SWIFT_SSL_CERT" |
| 386 | iniset ${SWIFT_CONFIG_PROXY_SERVER} DEFAULT key_file "$SWIFT_SSL_KEY" |
| 387 | fi |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 388 | |
Dean Troyer | dc97cb7 | 2015-03-28 08:20:50 -0500 | [diff] [blame] | 389 | # DevStack is commonly run in a small slow environment, so bump the timeouts up. |
| 390 | # ``node_timeout`` is the node read operation response time to the proxy server |
| 391 | # ``conn_timeout`` is how long it takes a connect() system call to return |
Joe Gordon | d254da5 | 2013-11-19 21:06:29 -0800 | [diff] [blame] | 392 | iniset ${SWIFT_CONFIG_PROXY_SERVER} app:proxy-server node_timeout 120 |
| 393 | iniset ${SWIFT_CONFIG_PROXY_SERVER} app:proxy-server conn_timeout 20 |
| 394 | |
Dina Belova | eedfdee | 2014-06-24 16:52:46 +0400 | [diff] [blame] | 395 | # Configure Ceilometer |
| 396 | if is_service_enabled ceilometer; then |
| 397 | iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:ceilometer "set log_level" "WARN" |
gordon chung | b6197e6 | 2015-02-12 15:33:35 -0500 | [diff] [blame] | 398 | iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:ceilometer paste.filter_factory "ceilometermiddleware.swift:filter_factory" |
| 399 | iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:ceilometer control_exchange "swift" |
| 400 | iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:ceilometer url $(get_transport_url) |
| 401 | iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:ceilometer driver "messaging" |
| 402 | iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:ceilometer topic "notifications" |
Dina Belova | eedfdee | 2014-06-24 16:52:46 +0400 | [diff] [blame] | 403 | SWIFT_EXTRAS_MIDDLEWARE_LAST="${SWIFT_EXTRAS_MIDDLEWARE_LAST} ceilometer" |
| 404 | fi |
Cyril Roelandt | d988340 | 2013-09-27 15:16:51 +0000 | [diff] [blame] | 405 | |
Dean Troyer | dc97cb7 | 2015-03-28 08:20:50 -0500 | [diff] [blame] | 406 | # Restrict the length of auth tokens in the Swift ``proxy-server`` logs. |
Peter Portante | cee4b3b | 2013-11-20 14:33:16 -0500 | [diff] [blame] | 407 | iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:proxy-logging reveal_sensitive_prefix ${SWIFT_LOG_TOKEN_LENGTH} |
| 408 | |
Dean Troyer | dc97cb7 | 2015-03-28 08:20:50 -0500 | [diff] [blame] | 409 | # By default Swift will be installed with Keystone and tempauth middleware |
Chmouel Boudjnah | 5cac378 | 2013-07-17 15:13:44 +0000 | [diff] [blame] | 410 | # and add the swift3 middleware if its configured for it. The token for |
Adam Spiers | cb96159 | 2013-10-05 12:11:07 +0100 | [diff] [blame] | 411 | # tempauth would be prefixed with the reseller_prefix setting `TEMPAUTH_` the |
| 412 | # token for keystoneauth would have the standard reseller_prefix `AUTH_` |
Chmouel Boudjnah | 5cac378 | 2013-07-17 15:13:44 +0000 | [diff] [blame] | 413 | if is_service_enabled swift3;then |
Joe H. Rahme | 1ce2ffd | 2013-10-22 15:19:09 +0200 | [diff] [blame] | 414 | swift_pipeline+=" swift3 s3token " |
Chmouel Boudjnah | bc3a339 | 2013-02-23 04:00:51 +0100 | [diff] [blame] | 415 | fi |
Chmouel Boudjnah | 254fd55 | 2014-06-30 12:22:59 +0000 | [diff] [blame] | 416 | |
Dean Troyer | 5ce44cd | 2015-02-12 22:18:33 -0600 | [diff] [blame] | 417 | if is_service_enabled keystone; then |
Chmouel Boudjnah | 254fd55 | 2014-06-30 12:22:59 +0000 | [diff] [blame] | 418 | swift_pipeline+=" authtoken keystoneauth" |
| 419 | fi |
| 420 | swift_pipeline+=" tempauth " |
| 421 | |
Chmouel Boudjnah | bc3a339 | 2013-02-23 04:00:51 +0100 | [diff] [blame] | 422 | sed -i "/^pipeline/ { s/tempauth/${swift_pipeline} ${SWIFT_EXTRAS_MIDDLEWARE}/ ;}" ${SWIFT_CONFIG_PROXY_SERVER} |
Cyril Roelandt | d988340 | 2013-09-27 15:16:51 +0000 | [diff] [blame] | 423 | sed -i "/^pipeline/ { s/proxy-server/${SWIFT_EXTRAS_MIDDLEWARE_LAST} proxy-server/ ; }" ${SWIFT_CONFIG_PROXY_SERVER} |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 424 | |
| 425 | iniset ${SWIFT_CONFIG_PROXY_SERVER} app:proxy-server account_autocreate true |
| 426 | |
Joe H. Rahme | 1ce2ffd | 2013-10-22 15:19:09 +0200 | [diff] [blame] | 427 | # Configure Crossdomain |
| 428 | iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:crossdomain use "egg:swift#crossdomain" |
| 429 | |
Dean Troyer | dc97cb7 | 2015-03-28 08:20:50 -0500 | [diff] [blame] | 430 | # Configure authtoken middleware to use the same Python logging |
| 431 | # adapter provided by the Swift ``proxy-server``, so that request transaction |
Peter Portante | 8afc893 | 2013-11-20 17:34:39 -0500 | [diff] [blame] | 432 | # IDs will included in all of its log messages. |
| 433 | iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:authtoken log_name swift |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 434 | |
Jamie Lennox | 38c95b8 | 2015-01-30 02:15:42 +0000 | [diff] [blame] | 435 | iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:authtoken paste.filter_factory keystonemiddleware.auth_token:filter_factory |
Jamie Lennox | 6ac97de | 2015-03-12 09:03:28 +1100 | [diff] [blame] | 436 | configure_auth_token_middleware $SWIFT_CONFIG_PROXY_SERVER swift $SWIFT_AUTH_CACHE_DIR filter:authtoken |
Jamie Lennox | 38c95b8 | 2015-01-30 02:15:42 +0000 | [diff] [blame] | 437 | iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:authtoken delay_auth_decision 1 |
| 438 | iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:authtoken cache swift.cache |
| 439 | iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:authtoken include_service_catalog False |
| 440 | |
| 441 | iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:keystoneauth use "egg:swift#keystoneauth" |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 442 | iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:keystoneauth operator_roles "Member, admin" |
| 443 | |
Dean Troyer | dc97cb7 | 2015-03-28 08:20:50 -0500 | [diff] [blame] | 444 | # Configure Tempauth. In the sample config file Keystoneauth is commented |
Donagh McCabe | 7faceb6 | 2014-12-19 13:20:45 +0000 | [diff] [blame] | 445 | # out. Make sure we uncomment Tempauth after we uncomment Keystoneauth |
| 446 | # otherwise, this code also sets the reseller_prefix for Keystoneauth. |
| 447 | iniuncomment ${SWIFT_CONFIG_PROXY_SERVER} filter:tempauth account_autocreate |
| 448 | iniuncomment ${SWIFT_CONFIG_PROXY_SERVER} filter:tempauth reseller_prefix |
| 449 | iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:tempauth reseller_prefix "TEMPAUTH" |
| 450 | |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 451 | if is_service_enabled swift3; then |
| 452 | cat <<EOF >>${SWIFT_CONFIG_PROXY_SERVER} |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 453 | [filter:s3token] |
Cyril Roelandt | e8a2fa4 | 2015-05-06 17:30:48 +0200 | [diff] [blame] | 454 | paste.filter_factory = keystonemiddleware.s3_token:filter_factory |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 455 | auth_port = ${KEYSTONE_AUTH_PORT} |
| 456 | auth_host = ${KEYSTONE_AUTH_HOST} |
| 457 | auth_protocol = ${KEYSTONE_AUTH_PROTOCOL} |
Rob Crittenden | 18d4778 | 2014-03-19 17:47:42 -0400 | [diff] [blame] | 458 | cafile = ${SSL_BUNDLE_FILE} |
Attila Fazekas | fbb3e77 | 2015-03-03 15:08:28 +0100 | [diff] [blame] | 459 | admin_user = swift |
Sean Dague | 7580a0c | 2016-02-17 06:23:36 -0500 | [diff] [blame] | 460 | admin_tenant_name = ${SERVICE_PROJECT_NAME} |
Attila Fazekas | fbb3e77 | 2015-03-03 15:08:28 +0100 | [diff] [blame] | 461 | admin_password = ${SERVICE_PASSWORD} |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 462 | |
| 463 | [filter:swift3] |
| 464 | use = egg:swift3#swift3 |
Andrey Pavlov | 9b21f98 | 2015-08-20 23:37:04 +0300 | [diff] [blame] | 465 | location = ${REGION_NAME} |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 466 | EOF |
| 467 | fi |
| 468 | |
Dean Troyer | 6ec72fa | 2013-03-13 11:44:53 -0500 | [diff] [blame] | 469 | cp ${SWIFT_DIR}/etc/swift.conf-sample ${SWIFT_CONF_DIR}/swift.conf |
| 470 | iniset ${SWIFT_CONF_DIR}/swift.conf swift-hash swift_hash_path_suffix ${SWIFT_HASH} |
Julien Vey | 63024d9 | 2014-05-06 15:10:07 +0200 | [diff] [blame] | 471 | iniset ${SWIFT_CONF_DIR}/swift.conf swift-constraints max_header_size ${SWIFT_MAX_HEADER_SIZE} |
Matthew Oliver | 7b85723 | 2016-03-07 18:21:29 +1100 | [diff] [blame^] | 472 | iniset ${SWIFT_CONF_DIR}/swift.conf swift-constraints max_file_size ${SWIFT_MAX_FILE_SIZE} |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 473 | |
Dean Troyer | 084f51f | 2014-07-25 15:08:52 -0500 | [diff] [blame] | 474 | local node_number |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 475 | for node_number in ${SWIFT_REPLICAS_SEQ}; do |
Dean Troyer | 084f51f | 2014-07-25 15:08:52 -0500 | [diff] [blame] | 476 | local swift_node_config=${SWIFT_CONF_DIR}/object-server/${node_number}.conf |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 477 | cp ${SWIFT_DIR}/etc/object-server.conf-sample ${swift_node_config} |
Chmouel Boudjnah | 6c585d7 | 2014-10-04 08:14:30 +0200 | [diff] [blame] | 478 | generate_swift_config_services ${swift_node_config} ${node_number} $(( OBJECT_PORT_BASE + 10 * (node_number - 1) )) object |
Rawlin Peters | 92ad152 | 2015-07-20 13:33:33 -0600 | [diff] [blame] | 479 | iniuncomment ${swift_node_config} DEFAULT bind_ip |
| 480 | iniset ${swift_node_config} DEFAULT bind_ip ${SWIFT_SERVICE_LISTEN_ADDRESS} |
Chmouel Boudjnah | 8e5d2f0 | 2012-12-20 13:11:43 +0000 | [diff] [blame] | 481 | iniset ${swift_node_config} filter:recon recon_cache_path ${SWIFT_DATA_DIR}/cache |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 482 | |
Dean Troyer | 6ec72fa | 2013-03-13 11:44:53 -0500 | [diff] [blame] | 483 | swift_node_config=${SWIFT_CONF_DIR}/container-server/${node_number}.conf |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 484 | cp ${SWIFT_DIR}/etc/container-server.conf-sample ${swift_node_config} |
Chmouel Boudjnah | 6c585d7 | 2014-10-04 08:14:30 +0200 | [diff] [blame] | 485 | generate_swift_config_services ${swift_node_config} ${node_number} $(( CONTAINER_PORT_BASE + 10 * (node_number - 1) )) container |
Rawlin Peters | 92ad152 | 2015-07-20 13:33:33 -0600 | [diff] [blame] | 486 | iniuncomment ${swift_node_config} DEFAULT bind_ip |
| 487 | iniset ${swift_node_config} DEFAULT bind_ip ${SWIFT_SERVICE_LISTEN_ADDRESS} |
Attila Fazekas | 83e1095 | 2012-11-30 23:28:07 +0100 | [diff] [blame] | 488 | iniuncomment ${swift_node_config} app:container-server allow_versions |
| 489 | iniset ${swift_node_config} app:container-server allow_versions "true" |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 490 | |
Dean Troyer | 6ec72fa | 2013-03-13 11:44:53 -0500 | [diff] [blame] | 491 | swift_node_config=${SWIFT_CONF_DIR}/account-server/${node_number}.conf |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 492 | cp ${SWIFT_DIR}/etc/account-server.conf-sample ${swift_node_config} |
Chmouel Boudjnah | 6c585d7 | 2014-10-04 08:14:30 +0200 | [diff] [blame] | 493 | generate_swift_config_services ${swift_node_config} ${node_number} $(( ACCOUNT_PORT_BASE + 10 * (node_number - 1) )) account |
Rawlin Peters | 92ad152 | 2015-07-20 13:33:33 -0600 | [diff] [blame] | 494 | iniuncomment ${swift_node_config} DEFAULT bind_ip |
| 495 | iniset ${swift_node_config} DEFAULT bind_ip ${SWIFT_SERVICE_LISTEN_ADDRESS} |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 496 | done |
| 497 | |
Chmouel Boudjnah | 0ce91a5 | 2013-07-05 11:59:24 +0000 | [diff] [blame] | 498 | # Set new accounts in tempauth to match keystone tenant/user (to make testing easier) |
| 499 | iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:tempauth user_swifttenanttest1_swiftusertest1 "testing .admin" |
| 500 | iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:tempauth user_swifttenanttest2_swiftusertest2 "testing2 .admin" |
| 501 | iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:tempauth user_swifttenanttest1_swiftusertest3 "testing3 .admin" |
| 502 | |
| 503 | testfile=${SWIFT_CONF_DIR}/test.conf |
| 504 | cp ${SWIFT_DIR}/test/sample.conf ${testfile} |
| 505 | |
| 506 | # Set accounts for functional tests |
| 507 | iniset ${testfile} func_test account swifttenanttest1 |
| 508 | iniset ${testfile} func_test username swiftusertest1 |
| 509 | iniset ${testfile} func_test username3 swiftusertest3 |
| 510 | iniset ${testfile} func_test account2 swifttenanttest2 |
| 511 | iniset ${testfile} func_test username2 swiftusertest2 |
Alistair Coles | 24779f6 | 2014-10-15 18:57:59 +0100 | [diff] [blame] | 512 | iniset ${testfile} func_test account4 swifttenanttest4 |
| 513 | iniset ${testfile} func_test username4 swiftusertest4 |
| 514 | iniset ${testfile} func_test password4 testing4 |
| 515 | iniset ${testfile} func_test domain4 swift_test |
Chmouel Boudjnah | 0ce91a5 | 2013-07-05 11:59:24 +0000 | [diff] [blame] | 516 | |
Dean Troyer | 5ce44cd | 2015-02-12 22:18:33 -0600 | [diff] [blame] | 517 | if is_service_enabled keystone; then |
Chmouel Boudjnah | 0ce91a5 | 2013-07-05 11:59:24 +0000 | [diff] [blame] | 518 | iniuncomment ${testfile} func_test auth_version |
Ian Wienand | ada886d | 2015-10-07 14:06:26 +1100 | [diff] [blame] | 519 | local auth_vers |
| 520 | auth_vers=$(iniget ${testfile} func_test auth_version) |
Chmouel Boudjnah | 0ce91a5 | 2013-07-05 11:59:24 +0000 | [diff] [blame] | 521 | iniset ${testfile} func_test auth_host ${KEYSTONE_SERVICE_HOST} |
| 522 | iniset ${testfile} func_test auth_port ${KEYSTONE_AUTH_PORT} |
Alistair Coles | 24779f6 | 2014-10-15 18:57:59 +0100 | [diff] [blame] | 523 | if [[ $auth_vers == "3" ]]; then |
| 524 | iniset ${testfile} func_test auth_prefix /v3/ |
| 525 | else |
| 526 | iniset ${testfile} func_test auth_prefix /v2.0/ |
| 527 | fi |
Chmouel Boudjnah | 0ce91a5 | 2013-07-05 11:59:24 +0000 | [diff] [blame] | 528 | fi |
| 529 | |
Ian Wienand | ada886d | 2015-10-07 14:06:26 +1100 | [diff] [blame] | 530 | local user_group |
| 531 | user_group=$(id -g ${STACK_USER}) |
Geronimo Orozco | 2f6576b | 2015-03-19 12:08:23 -0600 | [diff] [blame] | 532 | sudo install -d -o ${STACK_USER} -g ${user_group} ${SWIFT_DATA_DIR} |
| 533 | |
Dean Troyer | 084f51f | 2014-07-25 15:08:52 -0500 | [diff] [blame] | 534 | local swift_log_dir=${SWIFT_DATA_DIR}/logs |
Geronimo Orozco | 2f6576b | 2015-03-19 12:08:23 -0600 | [diff] [blame] | 535 | sudo rm -rf ${swift_log_dir} |
| 536 | sudo install -d -o ${STACK_USER} -g adm ${swift_log_dir}/hourly |
Yves-Gwenael Bourhis | f894c2a | 2014-04-16 13:37:46 +0200 | [diff] [blame] | 537 | |
| 538 | if [[ $SYSLOG != "False" ]]; then |
| 539 | sed "s,%SWIFT_LOGDIR%,${swift_log_dir}," $FILES/swift/rsyslog.conf | sudo \ |
| 540 | tee /etc/rsyslog.d/10-swift.conf |
| 541 | # restart syslog to take the changes |
| 542 | sudo killall -HUP rsyslogd |
| 543 | fi |
Sean Dague | ad7e8c6 | 2014-03-19 19:13:20 -0400 | [diff] [blame] | 544 | |
Morgan Fainberg | 46455a3 | 2014-06-20 10:37:18 -0700 | [diff] [blame] | 545 | if [ "$SWIFT_USE_MOD_WSGI" == "True" ]; then |
zhang-hare | d98a5d0 | 2013-06-21 18:18:02 +0800 | [diff] [blame] | 546 | _config_swift_apache_wsgi |
| 547 | fi |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 548 | } |
| 549 | |
Dean Troyer | 1c6c112 | 2013-03-27 17:40:53 -0500 | [diff] [blame] | 550 | # create_swift_disk - Create Swift backing disk |
Ian Wienand | aee18c7 | 2014-02-21 15:35:08 +1100 | [diff] [blame] | 551 | function create_swift_disk { |
Dean Troyer | 1c6c112 | 2013-03-27 17:40:53 -0500 | [diff] [blame] | 552 | local node_number |
| 553 | |
| 554 | # First do a bit of setup by creating the directories and |
| 555 | # changing the permissions so we can run it as our user. |
| 556 | |
Ian Wienand | ada886d | 2015-10-07 14:06:26 +1100 | [diff] [blame] | 557 | local user_group |
| 558 | user_group=$(id -g ${STACK_USER}) |
Dean Troyer | 8421c2b | 2015-03-16 13:52:19 -0500 | [diff] [blame] | 559 | sudo install -d -o ${STACK_USER} -g ${user_group} ${SWIFT_DATA_DIR}/{drives,cache,run,logs} |
Dean Troyer | 1c6c112 | 2013-03-27 17:40:53 -0500 | [diff] [blame] | 560 | |
| 561 | # Create a loopback disk and format it to XFS. |
Attila Fazekas | e602441 | 2013-09-15 18:38:48 +0200 | [diff] [blame] | 562 | if [[ -e ${SWIFT_DISK_IMAGE} ]]; then |
Dean Troyer | 1c6c112 | 2013-03-27 17:40:53 -0500 | [diff] [blame] | 563 | if egrep -q ${SWIFT_DATA_DIR}/drives/sdb1 /proc/mounts; then |
| 564 | sudo umount ${SWIFT_DATA_DIR}/drives/sdb1 |
Attila Fazekas | e602441 | 2013-09-15 18:38:48 +0200 | [diff] [blame] | 565 | sudo rm -f ${SWIFT_DISK_IMAGE} |
Dean Troyer | 1c6c112 | 2013-03-27 17:40:53 -0500 | [diff] [blame] | 566 | fi |
| 567 | fi |
| 568 | |
| 569 | mkdir -p ${SWIFT_DATA_DIR}/drives/images |
Attila Fazekas | e602441 | 2013-09-15 18:38:48 +0200 | [diff] [blame] | 570 | sudo touch ${SWIFT_DISK_IMAGE} |
Stephan Renatus | e578eff | 2013-11-19 13:31:04 +0100 | [diff] [blame] | 571 | sudo chown ${STACK_USER}: ${SWIFT_DISK_IMAGE} |
Dean Troyer | 1c6c112 | 2013-03-27 17:40:53 -0500 | [diff] [blame] | 572 | |
Attila Fazekas | e602441 | 2013-09-15 18:38:48 +0200 | [diff] [blame] | 573 | truncate -s ${SWIFT_LOOPBACK_DISK_SIZE} ${SWIFT_DISK_IMAGE} |
Dean Troyer | 1c6c112 | 2013-03-27 17:40:53 -0500 | [diff] [blame] | 574 | |
| 575 | # Make a fresh XFS filesystem |
Longgeek | fd034f0 | 2014-03-24 17:32:02 +0800 | [diff] [blame] | 576 | /sbin/mkfs.xfs -f -i size=1024 ${SWIFT_DISK_IMAGE} |
Dean Troyer | 1c6c112 | 2013-03-27 17:40:53 -0500 | [diff] [blame] | 577 | |
| 578 | # Mount the disk with mount options to make it as efficient as possible |
| 579 | mkdir -p ${SWIFT_DATA_DIR}/drives/sdb1 |
| 580 | if ! egrep -q ${SWIFT_DATA_DIR}/drives/sdb1 /proc/mounts; then |
| 581 | sudo mount -t xfs -o loop,noatime,nodiratime,nobarrier,logbufs=8 \ |
Attila Fazekas | e602441 | 2013-09-15 18:38:48 +0200 | [diff] [blame] | 582 | ${SWIFT_DISK_IMAGE} ${SWIFT_DATA_DIR}/drives/sdb1 |
Dean Troyer | 1c6c112 | 2013-03-27 17:40:53 -0500 | [diff] [blame] | 583 | fi |
| 584 | |
| 585 | # Create a link to the above mount and |
| 586 | # create all of the directories needed to emulate a few different servers |
Dean Troyer | 084f51f | 2014-07-25 15:08:52 -0500 | [diff] [blame] | 587 | local node_number |
Dean Troyer | 1c6c112 | 2013-03-27 17:40:53 -0500 | [diff] [blame] | 588 | for node_number in ${SWIFT_REPLICAS_SEQ}; do |
| 589 | sudo ln -sf ${SWIFT_DATA_DIR}/drives/sdb1/$node_number ${SWIFT_DATA_DIR}/$node_number; |
Dean Troyer | 084f51f | 2014-07-25 15:08:52 -0500 | [diff] [blame] | 590 | local drive=${SWIFT_DATA_DIR}/drives/sdb1/${node_number} |
| 591 | local node=${SWIFT_DATA_DIR}/${node_number}/node |
| 592 | local node_device=${node}/sdb1 |
Dean Troyer | 1c6c112 | 2013-03-27 17:40:53 -0500 | [diff] [blame] | 593 | [[ -d $node ]] && continue |
| 594 | [[ -d $drive ]] && continue |
Dean Troyer | 084f51f | 2014-07-25 15:08:52 -0500 | [diff] [blame] | 595 | sudo install -o ${STACK_USER} -g $user_group -d $drive |
| 596 | sudo install -o ${STACK_USER} -g $user_group -d $node_device |
Stephan Renatus | e578eff | 2013-11-19 13:31:04 +0100 | [diff] [blame] | 597 | sudo chown -R ${STACK_USER}: ${node} |
Dean Troyer | 1c6c112 | 2013-03-27 17:40:53 -0500 | [diff] [blame] | 598 | done |
| 599 | } |
Dean Troyer | dc97cb7 | 2015-03-28 08:20:50 -0500 | [diff] [blame] | 600 | |
| 601 | # create_swift_accounts() - Set up standard Swift accounts and extra |
Chmouel Boudjnah | ba31305 | 2013-07-10 21:03:43 +0200 | [diff] [blame] | 602 | # one for tests we do this by attaching all words in the account name |
| 603 | # since we want to make it compatible with tempauth which use |
| 604 | # underscores for separators. |
Chmouel Boudjnah | 0ce91a5 | 2013-07-05 11:59:24 +0000 | [diff] [blame] | 605 | |
Alistair Coles | 24779f6 | 2014-10-15 18:57:59 +0100 | [diff] [blame] | 606 | # Tenant User Roles Domain |
Chmouel Boudjnah | 0ce91a5 | 2013-07-05 11:59:24 +0000 | [diff] [blame] | 607 | # ------------------------------------------------------------------ |
Alistair Coles | 24779f6 | 2014-10-15 18:57:59 +0100 | [diff] [blame] | 608 | # service swift service default |
| 609 | # swifttenanttest1 swiftusertest1 admin default |
| 610 | # swifttenanttest1 swiftusertest3 anotherrole default |
| 611 | # swifttenanttest2 swiftusertest2 admin default |
| 612 | # swifttenanttest4 swiftusertest4 admin swift_test |
Chmouel Boudjnah | 0ce91a5 | 2013-07-05 11:59:24 +0000 | [diff] [blame] | 613 | |
Ian Wienand | aee18c7 | 2014-02-21 15:35:08 +1100 | [diff] [blame] | 614 | function create_swift_accounts { |
Dean Troyer | dc97cb7 | 2015-03-28 08:20:50 -0500 | [diff] [blame] | 615 | # Defines specific passwords used by ``tools/create_userrc.sh`` |
| 616 | # As these variables are used by ``create_userrc.sh,`` they must be exported |
| 617 | # The _password suffix is expected by ``create_userrc.sh``. |
JordanP | 7c6d005 | 2014-10-06 23:08:50 +0200 | [diff] [blame] | 618 | export swiftusertest1_password=testing |
| 619 | export swiftusertest2_password=testing2 |
| 620 | export swiftusertest3_password=testing3 |
Alistair Coles | 24779f6 | 2014-10-15 18:57:59 +0100 | [diff] [blame] | 621 | export swiftusertest4_password=testing4 |
Sahid Orentino Ferdjaoui | 1814e67 | 2014-02-11 17:56:07 +0100 | [diff] [blame] | 622 | |
Ian Wienand | ada886d | 2015-10-07 14:06:26 +1100 | [diff] [blame] | 623 | local another_role |
| 624 | another_role=$(get_or_create_role "anotherrole") |
Chmouel Boudjnah | ba31305 | 2013-07-10 21:03:43 +0200 | [diff] [blame] | 625 | |
Jim Rollenhagen | ae74ed7 | 2015-02-12 07:33:36 -0800 | [diff] [blame] | 626 | # NOTE(jroll): Swift doesn't need the admin role here, however Ironic uses |
| 627 | # temp urls, which break when uploaded by a non-admin role |
| 628 | create_service_user "swift" "admin" |
Chmouel Boudjnah | ba31305 | 2013-07-10 21:03:43 +0200 | [diff] [blame] | 629 | |
Sean Dague | 985e958 | 2016-02-10 07:25:24 -0500 | [diff] [blame] | 630 | get_or_create_service "swift" "object-store" "Swift Service" |
| 631 | get_or_create_endpoint \ |
| 632 | "object-store" \ |
| 633 | "$REGION_NAME" \ |
| 634 | "$SWIFT_SERVICE_PROTOCOL://$SERVICE_HOST:$SWIFT_DEFAULT_BIND_PORT/v1/AUTH_\$(tenant_id)s" \ |
| 635 | "$SWIFT_SERVICE_PROTOCOL://$SERVICE_HOST:$SWIFT_DEFAULT_BIND_PORT" \ |
| 636 | "$SWIFT_SERVICE_PROTOCOL://$SERVICE_HOST:$SWIFT_DEFAULT_BIND_PORT/v1/AUTH_\$(tenant_id)s" |
Chmouel Boudjnah | ba31305 | 2013-07-10 21:03:43 +0200 | [diff] [blame] | 637 | |
Ian Wienand | ada886d | 2015-10-07 14:06:26 +1100 | [diff] [blame] | 638 | local swift_tenant_test1 |
| 639 | swift_tenant_test1=$(get_or_create_project swifttenanttest1 default) |
Dean Troyer | 084f51f | 2014-07-25 15:08:52 -0500 | [diff] [blame] | 640 | die_if_not_set $LINENO swift_tenant_test1 "Failure creating swift_tenant_test1" |
Jamie Lennox | 9d7e776 | 2015-05-29 01:08:53 +0000 | [diff] [blame] | 641 | SWIFT_USER_TEST1=$(get_or_create_user swiftusertest1 $swiftusertest1_password \ |
| 642 | "default" "test@example.com") |
DennyZhang | 23178a9 | 2013-10-22 17:07:32 -0500 | [diff] [blame] | 643 | die_if_not_set $LINENO SWIFT_USER_TEST1 "Failure creating SWIFT_USER_TEST1" |
Jamie Lennox | 9b215db | 2015-02-10 18:19:57 +1100 | [diff] [blame] | 644 | get_or_add_user_project_role admin $SWIFT_USER_TEST1 $swift_tenant_test1 |
Chmouel Boudjnah | 0ce91a5 | 2013-07-05 11:59:24 +0000 | [diff] [blame] | 645 | |
Ian Wienand | ada886d | 2015-10-07 14:06:26 +1100 | [diff] [blame] | 646 | local swift_user_test3 |
| 647 | swift_user_test3=$(get_or_create_user swiftusertest3 $swiftusertest3_password \ |
Jamie Lennox | 9d7e776 | 2015-05-29 01:08:53 +0000 | [diff] [blame] | 648 | "default" "test3@example.com") |
Dean Troyer | 084f51f | 2014-07-25 15:08:52 -0500 | [diff] [blame] | 649 | die_if_not_set $LINENO swift_user_test3 "Failure creating swift_user_test3" |
Jamie Lennox | 9b215db | 2015-02-10 18:19:57 +1100 | [diff] [blame] | 650 | get_or_add_user_project_role $another_role $swift_user_test3 $swift_tenant_test1 |
Chmouel Boudjnah | 0ce91a5 | 2013-07-05 11:59:24 +0000 | [diff] [blame] | 651 | |
Ian Wienand | ada886d | 2015-10-07 14:06:26 +1100 | [diff] [blame] | 652 | local swift_tenant_test2 |
| 653 | swift_tenant_test2=$(get_or_create_project swifttenanttest2 default) |
Dean Troyer | 084f51f | 2014-07-25 15:08:52 -0500 | [diff] [blame] | 654 | die_if_not_set $LINENO swift_tenant_test2 "Failure creating swift_tenant_test2" |
Steve Martinelli | 1968542 | 2014-01-24 13:02:26 -0600 | [diff] [blame] | 655 | |
Ian Wienand | ada886d | 2015-10-07 14:06:26 +1100 | [diff] [blame] | 656 | local swift_user_test2 |
| 657 | swift_user_test2=$(get_or_create_user swiftusertest2 $swiftusertest2_password \ |
Jamie Lennox | 9d7e776 | 2015-05-29 01:08:53 +0000 | [diff] [blame] | 658 | "default" "test2@example.com") |
Dean Troyer | 084f51f | 2014-07-25 15:08:52 -0500 | [diff] [blame] | 659 | die_if_not_set $LINENO swift_user_test2 "Failure creating swift_user_test2" |
Jamie Lennox | 9b215db | 2015-02-10 18:19:57 +1100 | [diff] [blame] | 660 | get_or_add_user_project_role admin $swift_user_test2 $swift_tenant_test2 |
Alistair Coles | 24779f6 | 2014-10-15 18:57:59 +0100 | [diff] [blame] | 661 | |
Ian Wienand | ada886d | 2015-10-07 14:06:26 +1100 | [diff] [blame] | 662 | local swift_domain |
| 663 | swift_domain=$(get_or_create_domain swift_test 'Used for swift functional testing') |
Alistair Coles | 24779f6 | 2014-10-15 18:57:59 +0100 | [diff] [blame] | 664 | die_if_not_set $LINENO swift_domain "Failure creating swift_test domain" |
| 665 | |
Ian Wienand | ada886d | 2015-10-07 14:06:26 +1100 | [diff] [blame] | 666 | local swift_tenant_test4 |
| 667 | swift_tenant_test4=$(get_or_create_project swifttenanttest4 $swift_domain) |
Alistair Coles | 24779f6 | 2014-10-15 18:57:59 +0100 | [diff] [blame] | 668 | die_if_not_set $LINENO swift_tenant_test4 "Failure creating swift_tenant_test4" |
Jamie Lennox | 18f39bf | 2015-01-28 13:38:32 +1000 | [diff] [blame] | 669 | |
Ian Wienand | ada886d | 2015-10-07 14:06:26 +1100 | [diff] [blame] | 670 | local swift_user_test4 |
| 671 | swift_user_test4=$(get_or_create_user swiftusertest4 $swiftusertest4_password \ |
Jamie Lennox | 9d7e776 | 2015-05-29 01:08:53 +0000 | [diff] [blame] | 672 | $swift_domain "test4@example.com") |
Alistair Coles | 24779f6 | 2014-10-15 18:57:59 +0100 | [diff] [blame] | 673 | die_if_not_set $LINENO swift_user_test4 "Failure creating swift_user_test4" |
Jamie Lennox | 9b215db | 2015-02-10 18:19:57 +1100 | [diff] [blame] | 674 | get_or_add_user_project_role admin $swift_user_test4 $swift_tenant_test4 |
Chmouel Boudjnah | 0ce91a5 | 2013-07-05 11:59:24 +0000 | [diff] [blame] | 675 | } |
Dean Troyer | 1c6c112 | 2013-03-27 17:40:53 -0500 | [diff] [blame] | 676 | |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 677 | # init_swift() - Initialize rings |
Ian Wienand | aee18c7 | 2014-02-21 15:35:08 +1100 | [diff] [blame] | 678 | function init_swift { |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 679 | local node_number |
| 680 | # Make sure to kill all swift processes first |
Chmouel Boudjnah | ad8b276 | 2013-01-10 15:40:01 +0100 | [diff] [blame] | 681 | swift-init --run-dir=${SWIFT_DATA_DIR}/run all stop || true |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 682 | |
Dean Troyer | 1c6c112 | 2013-03-27 17:40:53 -0500 | [diff] [blame] | 683 | # Forcibly re-create the backing filesystem |
| 684 | create_swift_disk |
| 685 | |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 686 | # This is where we create three different rings for swift with |
| 687 | # different object servers binding on different ports. |
Dean Troyer | 6ec72fa | 2013-03-13 11:44:53 -0500 | [diff] [blame] | 688 | pushd ${SWIFT_CONF_DIR} >/dev/null && { |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 689 | |
| 690 | rm -f *.builder *.ring.gz backups/*.builder backups/*.ring.gz |
| 691 | |
| 692 | swift-ring-builder object.builder create ${SWIFT_PARTITION_POWER_SIZE} ${SWIFT_REPLICAS} 1 |
| 693 | swift-ring-builder container.builder create ${SWIFT_PARTITION_POWER_SIZE} ${SWIFT_REPLICAS} 1 |
| 694 | swift-ring-builder account.builder create ${SWIFT_PARTITION_POWER_SIZE} ${SWIFT_REPLICAS} 1 |
| 695 | |
| 696 | for node_number in ${SWIFT_REPLICAS_SEQ}; do |
Brian Haley | 180f5eb | 2015-06-16 13:14:31 -0400 | [diff] [blame] | 697 | swift-ring-builder object.builder add z${node_number}-${SWIFT_SERVICE_LOCAL_HOST}:$(( OBJECT_PORT_BASE + 10 * (node_number - 1) ))/sdb1 1 |
| 698 | swift-ring-builder container.builder add z${node_number}-${SWIFT_SERVICE_LOCAL_HOST}:$(( CONTAINER_PORT_BASE + 10 * (node_number - 1) ))/sdb1 1 |
| 699 | swift-ring-builder account.builder add z${node_number}-${SWIFT_SERVICE_LOCAL_HOST}:$(( ACCOUNT_PORT_BASE + 10 * (node_number - 1) ))/sdb1 1 |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 700 | done |
| 701 | swift-ring-builder object.builder rebalance |
| 702 | swift-ring-builder container.builder rebalance |
| 703 | swift-ring-builder account.builder rebalance |
| 704 | } && popd >/dev/null |
| 705 | |
Dean Troyer | 64ab774 | 2012-12-28 15:38:28 -0600 | [diff] [blame] | 706 | # Create cache dir |
Dean Troyer | 8421c2b | 2015-03-16 13:52:19 -0500 | [diff] [blame] | 707 | sudo install -d -o ${STACK_USER} $SWIFT_AUTH_CACHE_DIR |
Dean Troyer | 64ab774 | 2012-12-28 15:38:28 -0600 | [diff] [blame] | 708 | rm -f $SWIFT_AUTH_CACHE_DIR/* |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 709 | } |
| 710 | |
Ian Wienand | aee18c7 | 2014-02-21 15:35:08 +1100 | [diff] [blame] | 711 | function install_swift { |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 712 | git_clone $SWIFT_REPO $SWIFT_DIR $SWIFT_BRANCH |
Dean Troyer | 253a1a3 | 2013-04-01 18:23:22 -0500 | [diff] [blame] | 713 | setup_develop $SWIFT_DIR |
Morgan Fainberg | 46455a3 | 2014-06-20 10:37:18 -0700 | [diff] [blame] | 714 | if [ "$SWIFT_USE_MOD_WSGI" == "True" ]; then |
zhang-hare | d98a5d0 | 2013-06-21 18:18:02 +0800 | [diff] [blame] | 715 | install_apache_wsgi |
| 716 | fi |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 717 | } |
| 718 | |
Ian Wienand | aee18c7 | 2014-02-21 15:35:08 +1100 | [diff] [blame] | 719 | function install_swiftclient { |
Sean Dague | e08ab10 | 2014-11-13 17:09:28 -0500 | [diff] [blame] | 720 | if use_library_from_git "python-swiftclient"; then |
| 721 | git_clone_by_name "python-swiftclient" |
| 722 | setup_dev_lib "python-swiftclient" |
Sean Dague | 5cb1906 | 2014-11-01 01:37:45 +0100 | [diff] [blame] | 723 | fi |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 724 | } |
| 725 | |
Chris Dent | 1848b83 | 2015-06-27 15:05:17 +0100 | [diff] [blame] | 726 | # install_ceilometermiddleware() - Collect source and prepare |
| 727 | # note that this doesn't really have anything to do with ceilometer; |
| 728 | # though ceilometermiddleware has ceilometer in its name as an |
| 729 | # artifact of history, it is not a ceilometer specific tool. It |
| 730 | # simply generates pycadf-based notifications about requests and |
| 731 | # responses on the swift proxy |
| 732 | function install_ceilometermiddleware { |
| 733 | if use_library_from_git "ceilometermiddleware"; then |
| 734 | git_clone_by_name "ceilometermiddleware" |
| 735 | setup_dev_lib "ceilometermiddleware" |
| 736 | else |
| 737 | pip_install_gr ceilometermiddleware |
| 738 | fi |
| 739 | } |
| 740 | |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 741 | # start_swift() - Start running processes, including screen |
Ian Wienand | aee18c7 | 2014-02-21 15:35:08 +1100 | [diff] [blame] | 742 | function start_swift { |
Chmouel Boudjnah | 8ecbb38 | 2013-03-12 12:15:17 +0100 | [diff] [blame] | 743 | # (re)start memcached to make sure we have a clean memcache. |
| 744 | restart_service memcached |
| 745 | |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 746 | # Start rsync |
Vincent Untz | c18b965 | 2012-12-04 12:36:34 +0100 | [diff] [blame] | 747 | if is_ubuntu; then |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 748 | sudo /etc/init.d/rsync restart || : |
Attila Fazekas | 0e57b96 | 2014-02-28 09:09:52 +0100 | [diff] [blame] | 749 | elif [ -e /etc/xinetd.d/rsync ]; then |
| 750 | start_service xinetd |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 751 | else |
Attila Fazekas | 0e57b96 | 2014-02-28 09:09:52 +0100 | [diff] [blame] | 752 | start_service rsyncd |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 753 | fi |
| 754 | |
Morgan Fainberg | 46455a3 | 2014-06-20 10:37:18 -0700 | [diff] [blame] | 755 | if [ "$SWIFT_USE_MOD_WSGI" == "True" ]; then |
zhang-hare | d98a5d0 | 2013-06-21 18:18:02 +0800 | [diff] [blame] | 756 | restart_apache_server |
| 757 | swift-init --run-dir=${SWIFT_DATA_DIR}/run rest start |
Chris Dent | 2f27a0e | 2014-09-09 13:46:02 +0100 | [diff] [blame] | 758 | tail_log s-proxy /var/log/$APACHE_NAME/proxy-server |
zhang-hare | d98a5d0 | 2013-06-21 18:18:02 +0800 | [diff] [blame] | 759 | if [[ ${SWIFT_REPLICAS} == 1 ]]; then |
| 760 | for type in object container account; do |
Chris Dent | 2f27a0e | 2014-09-09 13:46:02 +0100 | [diff] [blame] | 761 | tail_log s-${type} /var/log/$APACHE_NAME/${type}-server-1 |
zhang-hare | d98a5d0 | 2013-06-21 18:18:02 +0800 | [diff] [blame] | 762 | done |
| 763 | fi |
| 764 | return 0 |
| 765 | fi |
| 766 | |
Sean Dague | 101b424 | 2013-10-22 08:47:11 -0400 | [diff] [blame] | 767 | # By default with only one replica we are launching the proxy, |
| 768 | # container, account and object server in screen in foreground and |
Dean Troyer | dc97cb7 | 2015-03-28 08:20:50 -0500 | [diff] [blame] | 769 | # other services in background. If we have ``SWIFT_REPLICAS`` set to something |
| 770 | # greater than one we first spawn all the Swift services then kill the proxy |
Sean Dague | 101b424 | 2013-10-22 08:47:11 -0400 | [diff] [blame] | 771 | # service so we can run it in foreground in screen. ``swift-init ... |
| 772 | # {stop|restart}`` exits with '1' if no servers are running, ignore it just |
| 773 | # in case |
Dean Troyer | 084f51f | 2014-07-25 15:08:52 -0500 | [diff] [blame] | 774 | local todo type |
Sean Dague | 101b424 | 2013-10-22 08:47:11 -0400 | [diff] [blame] | 775 | swift-init --run-dir=${SWIFT_DATA_DIR}/run all restart || true |
| 776 | if [[ ${SWIFT_REPLICAS} == 1 ]]; then |
Chmouel Boudjnah | 0c3a558 | 2013-03-06 10:58:33 +0100 | [diff] [blame] | 777 | todo="object container account" |
Sean Dague | 101b424 | 2013-10-22 08:47:11 -0400 | [diff] [blame] | 778 | fi |
| 779 | for type in proxy ${todo}; do |
| 780 | swift-init --run-dir=${SWIFT_DATA_DIR}/run ${type} stop || true |
| 781 | done |
Rob Crittenden | 18d4778 | 2014-03-19 17:47:42 -0400 | [diff] [blame] | 782 | if is_service_enabled tls-proxy; then |
Falk Reimann | 22f747b | 2015-08-28 12:40:19 +0200 | [diff] [blame] | 783 | local proxy_port=${SWIFT_DEFAULT_BIND_PORT} |
Rob Crittenden | 18d4778 | 2014-03-19 17:47:42 -0400 | [diff] [blame] | 784 | start_tls_proxy '*' $proxy_port $SERVICE_HOST $SWIFT_DEFAULT_BIND_PORT_INT & |
| 785 | fi |
Chris Dent | 2f27a0e | 2014-09-09 13:46:02 +0100 | [diff] [blame] | 786 | run_process s-proxy "$SWIFT_DIR/bin/swift-proxy-server ${SWIFT_CONF_DIR}/proxy-server.conf -v" |
Sean Dague | 101b424 | 2013-10-22 08:47:11 -0400 | [diff] [blame] | 787 | if [[ ${SWIFT_REPLICAS} == 1 ]]; then |
| 788 | for type in object container account; do |
Chris Dent | 2f27a0e | 2014-09-09 13:46:02 +0100 | [diff] [blame] | 789 | run_process s-${type} "$SWIFT_DIR/bin/swift-${type}-server ${SWIFT_CONF_DIR}/${type}-server/1.conf -v" |
Sean Dague | 101b424 | 2013-10-22 08:47:11 -0400 | [diff] [blame] | 790 | done |
| 791 | fi |
Jim Rollenhagen | abbb0e9 | 2014-08-05 18:01:48 +0000 | [diff] [blame] | 792 | |
| 793 | if [[ "$SWIFT_ENABLE_TEMPURLS" == "True" ]]; then |
| 794 | swift_configure_tempurls |
| 795 | fi |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 796 | } |
| 797 | |
| 798 | # stop_swift() - Stop running processes (non-screen) |
Ian Wienand | aee18c7 | 2014-02-21 15:35:08 +1100 | [diff] [blame] | 799 | function stop_swift { |
Dean Troyer | 084f51f | 2014-07-25 15:08:52 -0500 | [diff] [blame] | 800 | local type |
zhang-hare | d98a5d0 | 2013-06-21 18:18:02 +0800 | [diff] [blame] | 801 | |
Morgan Fainberg | 46455a3 | 2014-06-20 10:37:18 -0700 | [diff] [blame] | 802 | if [ "$SWIFT_USE_MOD_WSGI" == "True" ]; then |
zhang-hare | d98a5d0 | 2013-06-21 18:18:02 +0800 | [diff] [blame] | 803 | swift-init --run-dir=${SWIFT_DATA_DIR}/run rest stop && return 0 |
| 804 | fi |
| 805 | |
Dean Troyer | dc97cb7 | 2015-03-28 08:20:50 -0500 | [diff] [blame] | 806 | # screen normally killed by ``unstack.sh`` |
Dean Troyer | 995eb92 | 2013-03-07 16:11:40 -0600 | [diff] [blame] | 807 | if type -p swift-init >/dev/null; then |
Chmouel Boudjnah | 0c3a558 | 2013-03-06 10:58:33 +0100 | [diff] [blame] | 808 | swift-init --run-dir=${SWIFT_DATA_DIR}/run all stop || true |
| 809 | fi |
Chmouel Boudjnah | f36a9b2 | 2014-02-03 23:44:47 +0100 | [diff] [blame] | 810 | # Dump all of the servers |
Chris Dent | 2f27a0e | 2014-09-09 13:46:02 +0100 | [diff] [blame] | 811 | # Maintain the iteration as stop_process() has some desirable side-effects |
Dean Troyer | 1eae3e1 | 2014-03-06 11:49:22 -0600 | [diff] [blame] | 812 | for type in proxy object container account; do |
Chris Dent | 2f27a0e | 2014-09-09 13:46:02 +0100 | [diff] [blame] | 813 | stop_process s-${type} |
Dean Troyer | 1eae3e1 | 2014-03-06 11:49:22 -0600 | [diff] [blame] | 814 | done |
| 815 | # Blast out any stragglers |
Attila Fazekas | f750a6f | 2015-07-01 12:17:35 +0200 | [diff] [blame] | 816 | pkill -f swift- || true |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 817 | } |
| 818 | |
Jim Rollenhagen | abbb0e9 | 2014-08-05 18:01:48 +0000 | [diff] [blame] | 819 | function swift_configure_tempurls { |
Steve Martinelli | a91d455 | 2015-10-20 23:15:38 -0400 | [diff] [blame] | 820 | # note we are using swift credentials! |
Jim Rollenhagen | abbb0e9 | 2014-08-05 18:01:48 +0000 | [diff] [blame] | 821 | OS_USERNAME=swift \ |
Steve Martinelli | a91d455 | 2015-10-20 23:15:38 -0400 | [diff] [blame] | 822 | OS_PASSWORD=$SERVICE_PASSWORD \ |
Sean Dague | 7580a0c | 2016-02-17 06:23:36 -0500 | [diff] [blame] | 823 | OS_PROJECT_NAME=$SERVICE_PROJECT_NAME \ |
Steve Martinelli | a91d455 | 2015-10-20 23:15:38 -0400 | [diff] [blame] | 824 | openstack object store account \ |
| 825 | set --property "Temp-URL-Key=$SWIFT_TEMPURL_KEY" |
Jim Rollenhagen | abbb0e9 | 2014-08-05 18:01:48 +0000 | [diff] [blame] | 826 | } |
| 827 | |
Attila Fazekas | ece6a33 | 2012-11-29 14:19:41 +0100 | [diff] [blame] | 828 | # Restore xtrace |
Ian Wienand | 523f488 | 2015-10-13 11:03:03 +1100 | [diff] [blame] | 829 | $_XTRACE_LIB_SWIFT |
Sean Dague | 584d90e | 2013-03-29 14:34:53 -0400 | [diff] [blame] | 830 | |
Adam Spiers | 6a5aa7c | 2013-10-24 11:27:02 +0100 | [diff] [blame] | 831 | # Tell emacs to use shell-script-mode |
| 832 | ## Local variables: |
| 833 | ## mode: shell-script |
| 834 | ## End: |