blob: ef1ad3d26a390be114d546212c6e14800d934b27 [file] [log] [blame]
Jesse Andrewsba23cc72011-09-11 03:22:13 -07001#!/usr/bin/env bash
2
Dean Troyerc6c1d432012-03-27 20:59:22 -05003# ``stack.sh`` is an opinionated OpenStack developer installation. It
Chris Dente9a47502015-06-27 11:29:09 +00004# installs and configures various combinations of **Cinder**, **Glance**,
Sean Dague3336b4b2017-05-02 08:45:34 -04005# **Horizon**, **Keystone**, **Nova**, **Neutron**, and **Swift**
Jesse Andrewsba23cc72011-09-11 03:22:13 -07006
Brett Campbell27f29442014-02-19 18:23:16 -08007# This script's options can be changed by setting appropriate environment
8# variables. You can configure things like which git repositories to use,
9# services to enable, OS images to use, etc. Default values are located in the
10# ``stackrc`` file. If you are crafty you can run the script on multiple nodes
11# using shared settings for common resources (eg., mysql or rabbitmq) and build
12# a multi-node developer install.
Jesse Andrews782b9912011-10-02 16:53:21 -040013
Dean Troyer4a43b7b2012-08-28 17:43:40 -050014# To keep this script simple we assume you are running on a recent **Ubuntu**
Ian Wienand2e667782019-11-20 10:41:34 +110015# (Bionic or newer), **Fedora** (F24 or newer), or **CentOS/RHEL**
Martin Falatic5bee0cd2015-01-23 14:10:33 -080016# (7 or newer) machine. (It may work on other platforms but support for those
17# platforms is left to those who added them to DevStack.) It should work in
Dean Troyerdc97cb72015-03-28 08:20:50 -050018# a VM or physical server. Additionally, we maintain a list of ``deb`` and
Martin Falatic5bee0cd2015-01-23 14:10:33 -080019# ``rpm`` dependencies and other configuration files in this repo.
Jesse Andrews24859062011-09-15 21:28:23 -070020
Jesse Andrews0e7e8972011-10-02 16:36:54 -040021# Learn more and get the most recent version at http://devstack.org
Jesse Andrews6edd17f2011-09-15 22:19:42 -070022
Ian Wienandf0247ed2015-07-09 15:49:16 +100023# Print the commands being run so that we can see the command that triggers
24# an error. It is also useful for following along as the install occurs.
25set -o xtrace
26
Jason Dunsmore4e971112013-04-10 10:17:40 -050027# Make sure custom grep options don't get in the way
28unset GREP_OPTIONS
29
Clark Boyland095e972017-06-13 10:18:36 -070030# NOTE(sdague): why do we explicitly set locale when running stack.sh?
31#
32# Devstack is written in bash, and many functions used throughout
zhangbailin32608da2017-08-09 01:43:00 -070033# devstack process text coming off a command (like the ip command)
Clark Boyland095e972017-06-13 10:18:36 -070034# and do transforms using grep, sed, cut, awk on the strings that are
Harald Jensasf0636ba2017-12-20 12:07:40 +010035# returned. Many of these programs are internationalized, which is
Clark Boyland095e972017-06-13 10:18:36 -070036# great for end users, but means that the strings that devstack
37# functions depend upon might not be there in other locales. We thus
38# need to pin the world to an english basis during the runs.
39#
40# Previously we used the C locale for this, every system has it, and
41# it gives us a stable sort order. It does however mean that we
42# effectively drop unicode support.... boo! :(
43#
44# With python3 being more unicode aware by default, that's not the
45# right option. While there is a C.utf8 locale, some distros are
46# shipping it as C.UTF8 for extra confusingness. And it's support
47# isn't super clear across distros. This is made more challenging when
48# trying to support both out of the box distros, and the gate which
49# uses diskimage builder to build disk images in a different way than
50# the distros do.
51#
52# So... en_US.utf8 it is. That's existed for a very long time. It is a
53# compromise position, but it is the least worse idea at the time of
54# this comment.
55#
56# We also have to unset other variables that might impact LC_ALL
57# taking effect.
Ian Wienand91626082016-08-04 15:17:38 +100058unset LANG
59unset LANGUAGE
Clark Boyland095e972017-06-13 10:18:36 -070060LC_ALL=en_US.utf8
Ian Wienand91626082016-08-04 15:17:38 +100061export LC_ALL
62
Akihiro Motoki1348ac92019-04-04 22:30:24 +090063# Clear all OpenStack related envvars
64unset `env | grep -E '^OS_' | cut -d = -f 1`
65
Brett Campbell27f29442014-02-19 18:23:16 -080066# Make sure umask is sane
67umask 022
68
Angus Lees7df9d1b2014-07-21 15:35:34 +100069# Not all distros have sbin in PATH for regular users.
70PATH=$PATH:/usr/local/sbin:/usr/sbin:/sbin
71
Dean Troyerdc97cb72015-03-28 08:20:50 -050072# Keep track of the DevStack directory
Jesse Andrews51fb22e2011-10-19 09:24:17 -070073TOP_DIR=$(cd $(dirname "$0") && pwd)
74
Sean Dague53753292014-12-04 19:38:15 -050075# Check for uninitialized variables, a big cause of bugs
76NOUNSET=${NOUNSET:-}
77if [[ -n "$NOUNSET" ]]; then
78 set -o nounset
79fi
80
Matthew Treinish4af2afc2015-10-13 09:51:17 -040081# Set start of devstack timestamp
82DEVSTACK_START_TIME=$(date +%s)
Dean Troyerdc97cb72015-03-28 08:20:50 -050083
84# Configuration
85# =============
86
Dean Troyerd3bf9bd2014-07-25 10:20:19 -050087# Sanity Checks
88# -------------
89
90# Clean up last environment var cache
91if [[ -r $TOP_DIR/.stackenv ]]; then
92 rm $TOP_DIR/.stackenv
93fi
94
Dean Troyerdc97cb72015-03-28 08:20:50 -050095# ``stack.sh`` keeps the list of ``deb`` and ``rpm`` dependencies, config
Dean Troyerd3bf9bd2014-07-25 10:20:19 -050096# templates and other useful files in the ``files`` subdirectory
97FILES=$TOP_DIR/files
98if [ ! -d $FILES ]; then
Vanou Ishiieef2a0d2021-01-20 14:15:57 +090099 set +o xtrace
100 echo "missing devstack/files"
101 exit 1
Dean Troyerd3bf9bd2014-07-25 10:20:19 -0500102fi
103
104# ``stack.sh`` keeps function libraries here
Dean Troyerdc97cb72015-03-28 08:20:50 -0500105# Make sure ``$TOP_DIR/inc`` directory is present
106if [ ! -d $TOP_DIR/inc ]; then
Vanou Ishiieef2a0d2021-01-20 14:15:57 +0900107 set +o xtrace
108 echo "missing devstack/inc"
109 exit 1
Dean Troyerdc97cb72015-03-28 08:20:50 -0500110fi
111
112# ``stack.sh`` keeps project libraries here
Dean Troyerd3bf9bd2014-07-25 10:20:19 -0500113# Make sure ``$TOP_DIR/lib`` directory is present
114if [ ! -d $TOP_DIR/lib ]; then
Vanou Ishiieef2a0d2021-01-20 14:15:57 +0900115 set +o xtrace
116 echo "missing devstack/lib"
117 exit 1
Dean Troyerd3bf9bd2014-07-25 10:20:19 -0500118fi
119
Dean Troyerdc97cb72015-03-28 08:20:50 -0500120# Check if run in POSIX shell
121if [[ "${POSIXLY_CORRECT}" == "y" ]]; then
Ian Wienand1afc28b2015-11-27 14:15:56 +1100122 set +o xtrace
Dean Troyerdc97cb72015-03-28 08:20:50 -0500123 echo "You are running POSIX compatibility mode, DevStack requires bash 4.2 or newer."
124 exit 1
125fi
126
Dean Troyerd3bf9bd2014-07-25 10:20:19 -0500127# OpenStack is designed to be run as a non-root user; Horizon will fail to run
128# as **root** since Apache will not serve content from **root** user).
129# ``stack.sh`` must not be run as **root**. It aborts and suggests one course of
130# action to create a suitable user account.
131
132if [[ $EUID -eq 0 ]]; then
Ian Wienand1afc28b2015-11-27 14:15:56 +1100133 set +o xtrace
134 echo "DevStack should be run as a user with sudo permissions, "
135 echo "not root."
136 echo "A \"stack\" user configured correctly can be created with:"
137 echo " $TOP_DIR/tools/create-stack-user.sh"
Dean Troyerd3bf9bd2014-07-25 10:20:19 -0500138 exit 1
139fi
140
Sean Dague90dd2622015-11-10 12:22:03 -0500141# OpenStack is designed to run at a system level, with system level
142# installation of python packages. It does not support running under a
143# virtual env, and will fail in really odd ways if you do this. Make
144# this explicit as it has come up on the mailing list.
145if [[ -n "$VIRTUAL_ENV" ]]; then
Ian Wienand1afc28b2015-11-27 14:15:56 +1100146 set +o xtrace
Sean Dague90dd2622015-11-10 12:22:03 -0500147 echo "You appear to be running under a python virtualenv."
Jordan Pittierc1750402015-11-12 11:03:20 +0100148 echo "DevStack does not support this, as we may break the"
Sean Dague90dd2622015-11-10 12:22:03 -0500149 echo "virtualenv you are currently in by modifying "
150 echo "external system-level components the virtualenv relies on."
Jordan Pittierc1750402015-11-12 11:03:20 +0100151 echo "We recommend you use a separate virtual-machine if "
Sean Dague90dd2622015-11-10 12:22:03 -0500152 echo "you are worried about DevStack taking over your system."
153 exit 1
154fi
155
Sean Dague56037e92015-10-08 12:27:07 -0400156# Provide a safety switch for devstack. If you do a lot of devstack,
157# on a lot of different environments, you sometimes run it on the
158# wrong box. This makes there be a way to prevent that.
159if [[ -e $HOME/.no-devstack ]]; then
Ian Wienand1afc28b2015-11-27 14:15:56 +1100160 set +o xtrace
Sean Dague56037e92015-10-08 12:27:07 -0400161 echo "You've marked this host as a no-devstack host, to save yourself from"
162 echo "running devstack accidentally. If this is in error, please remove the"
163 echo "~/.no-devstack file"
164 exit 1
165fi
Attila Fazekasd9de1192015-03-26 09:25:02 +0100166
Dean Troyerd3bf9bd2014-07-25 10:20:19 -0500167# Prepare the environment
168# -----------------------
169
Sean Dague53753292014-12-04 19:38:15 -0500170# Initialize variables:
171LAST_SPINNER_PID=""
172
Dean Troyer6563a3c2012-01-31 12:11:56 -0600173# Import common functions
Dean Troyerc6c1d432012-03-27 20:59:22 -0500174source $TOP_DIR/functions
Dean Troyer6563a3c2012-01-31 12:11:56 -0600175
Dean Troyer8c2ce6e2015-02-18 14:47:54 -0600176# Import 'public' stack.sh functions
177source $TOP_DIR/lib/stack
178
Dean Troyerc6c1d432012-03-27 20:59:22 -0500179# Determine what system we are running on. This provides ``os_VENDOR``,
Ian Wienand7710e7f2014-08-27 16:15:32 +1000180# ``os_RELEASE``, ``os_PACKAGE``, ``os_CODENAME``
Dean Troyera9e0a482012-07-09 14:07:23 -0500181# and ``DISTRO``
182GetDistro
Jesse Andrews6edd17f2011-09-15 22:19:42 -0700183
Dean Troyerdc97cb72015-03-28 08:20:50 -0500184
Dean Troyer48352ee2012-12-12 12:50:38 -0600185# Global Settings
Dean Troyer0e8dced2014-07-25 10:33:21 -0500186# ---------------
Scott Moserf9da5082011-10-07 21:28:00 -0400187
Dean Troyer893e6632013-09-13 15:05:51 -0500188# Check for a ``localrc`` section embedded in ``local.conf`` and extract if
189# ``localrc`` does not already exist
190
191# Phase: local
192rm -f $TOP_DIR/.localrc.auto
Huan Xiecc6af3f2015-12-23 02:17:01 +0000193extract_localrc_section $TOP_DIR/local.conf $TOP_DIR/localrc $TOP_DIR/.localrc.auto
Dean Troyer893e6632013-09-13 15:05:51 -0500194
Dean Troyer1a6d4492013-06-03 16:47:36 -0500195# ``stack.sh`` is customizable by setting environment variables. Override a
Leticia Wanderley7f806492017-04-06 20:40:19 -0300196# default setting via export:
Scott Moserf9da5082011-10-07 21:28:00 -0400197#
Terry Wilson428af5a2012-11-01 16:12:39 -0400198# export DATABASE_PASSWORD=anothersecret
Scott Moserf9da5082011-10-07 21:28:00 -0400199# ./stack.sh
200#
Leticia Wanderley7f806492017-04-06 20:40:19 -0300201# or by setting the variable on the command line:
Scott Moserf9da5082011-10-07 21:28:00 -0400202#
Dean Troyer1a6d4492013-06-03 16:47:36 -0500203# DATABASE_PASSWORD=simple ./stack.sh
204#
Leticia Wanderley7f806492017-04-06 20:40:19 -0300205# Persistent variables can be placed in a ``local.conf`` file:
Scott Moserf9da5082011-10-07 21:28:00 -0400206#
Dean Troyerdc97cb72015-03-28 08:20:50 -0500207# [[local|localrc]]
Terry Wilson428af5a2012-11-01 16:12:39 -0400208# DATABASE_PASSWORD=anothersecret
209# DATABASE_USER=hellaroot
Scott Moserf9da5082011-10-07 21:28:00 -0400210#
211# We try to have sensible defaults, so you should be able to run ``./stack.sh``
Dean Troyerdc97cb72015-03-28 08:20:50 -0500212# in most cases. ``local.conf`` is not distributed with DevStack and will never
Dean Troyer4a43b7b2012-08-28 17:43:40 -0500213# be overwritten by a DevStack update.
Scott Moserf9da5082011-10-07 21:28:00 -0400214#
Dean Troyerdf0972c2012-03-07 17:31:03 -0600215# DevStack distributes ``stackrc`` which contains locations for the OpenStack
Dean Troyercc6b4432013-04-08 15:38:03 -0500216# repositories, branches to configure, and other configuration defaults.
Dean Troyerdc97cb72015-03-28 08:20:50 -0500217# ``stackrc`` sources the ``localrc`` section of ``local.conf`` to allow you to
218# safely override those settings.
Dean Troyer4a43b7b2012-08-28 17:43:40 -0500219
Dean Troyerbbafb1b2012-06-11 16:51:39 -0500220if [[ ! -r $TOP_DIR/stackrc ]]; then
Dean Troyer14fd9792014-07-25 10:34:11 -0500221 die $LINENO "missing $TOP_DIR/stackrc - did you grab more than just stack.sh?"
Dean Troyerbbafb1b2012-06-11 16:51:39 -0500222fi
223source $TOP_DIR/stackrc
Dean Troyerdf0972c2012-03-07 17:31:03 -0600224
Ian Wienand07cbc442017-06-30 12:29:19 +1000225# write /etc/devstack-version
Sean Dague2c0faca2017-06-28 09:13:04 -0400226write_devstack_version
227
Ian Wienandc973e6c2014-11-05 09:52:27 +1100228# Warn users who aren't on an explicitly supported distro, but allow them to
229# override check and attempt installation with ``FORCE=yes ./stack``
Ghanshyam Mann7ad4cd02021-04-29 09:24:38 -0500230SUPPORTED_DISTROS="focal|f31|f32|opensuse-15.2|opensuse-tumbleweed|rhel8"
Riccardo Pittau8e74a612020-04-10 10:48:15 +0200231
232if [[ ! ${DISTRO} =~ $SUPPORTED_DISTROS ]]; then
Ian Wienandc973e6c2014-11-05 09:52:27 +1100233 echo "WARNING: this script has not been tested on $DISTRO"
234 if [[ "$FORCE" != "yes" ]]; then
235 die $LINENO "If you wish to run this script anyway run with FORCE=yes"
236 fi
237fi
238
Dean Troyer48352ee2012-12-12 12:50:38 -0600239# Local Settings
Dean Troyer4a43b7b2012-08-28 17:43:40 -0500240# --------------
241
Dean Troyer48352ee2012-12-12 12:50:38 -0600242# Make sure the proxy config is visible to sub-processes
243export_proxy_variables
Scott Moserf9da5082011-10-07 21:28:00 -0400244
Dean Troyerdc97cb72015-03-28 08:20:50 -0500245# Remove services which were negated in ``ENABLED_SERVICES``
Joe Gordon6fd28112012-11-13 16:55:41 -0800246# using the "-" prefix (e.g., "-rabbit") instead of
Doug Hellmannf04178f2012-07-05 17:10:03 -0400247# calling disable_service().
248disable_negated_services
Chmouel Boudjnahc4cd4142012-06-27 11:01:40 +0200249
Dean Troyera79617c2014-04-13 18:16:54 -0500250
Dean Troyerd3bf9bd2014-07-25 10:20:19 -0500251# Configure sudo
252# --------------
Dean Troyer9122e7b2011-10-17 14:07:11 -0500253
Dean Troyerdc97cb72015-03-28 08:20:50 -0500254# We're not as **root** so make sure ``sudo`` is available
Alex Monk5e2d0e02019-06-04 01:21:44 +0100255is_package_installed sudo || is_package_installed sudo-ldap || install_package sudo
Dean Troyer23f69d82013-10-04 12:35:24 -0500256
257# UEC images ``/etc/sudoers`` does not have a ``#includedir``, add one
258sudo grep -q "^#includedir.*/etc/sudoers.d" /etc/sudoers ||
259 echo "#includedir /etc/sudoers.d" | sudo tee -a /etc/sudoers
260
Sean Dagueb0160d02015-06-23 12:53:51 -0400261# Conditionally setup detailed logging for sudo
262if [[ -n "$LOG_SUDO" ]]; then
263 TEMPFILE=`mktemp`
264 echo "Defaults log_output" > $TEMPFILE
265 chmod 0440 $TEMPFILE
266 sudo chown root:root $TEMPFILE
267 sudo mv $TEMPFILE /etc/sudoers.d/00_logging
268fi
269
Dean Troyerdc97cb72015-03-28 08:20:50 -0500270# Set up DevStack sudoers
Dean Troyer23f69d82013-10-04 12:35:24 -0500271TEMPFILE=`mktemp`
272echo "$STACK_USER ALL=(root) NOPASSWD:ALL" >$TEMPFILE
Dean Troyerdc97cb72015-03-28 08:20:50 -0500273# Some binaries might be under ``/sbin`` or ``/usr/sbin``, so make sure sudo will
274# see them by forcing ``PATH``
Dean Troyer23f69d82013-10-04 12:35:24 -0500275echo "Defaults:$STACK_USER secure_path=/sbin:/usr/sbin:/usr/bin:/bin:/usr/local/sbin:/usr/local/bin" >> $TEMPFILE
Adam Gandelmanea2fcb52014-03-17 16:37:56 -0700276echo "Defaults:$STACK_USER !requiretty" >> $TEMPFILE
Dean Troyer23f69d82013-10-04 12:35:24 -0500277chmod 0440 $TEMPFILE
278sudo chown root:root $TEMPFILE
279sudo mv $TEMPFILE /etc/sudoers.d/50_stack_sh
280
Dean Troyer0e8dced2014-07-25 10:33:21 -0500281
282# Configure Distro Repositories
283# -----------------------------
Ian Wienand531aeb72014-02-28 11:24:29 +1100284
Dean Troyerdc97cb72015-03-28 08:20:50 -0500285# For Debian/Ubuntu make apt attempt to retry network ops on it's own
Sean Daguee83f7782014-06-23 08:11:05 -0400286if is_ubuntu; then
Chmouel Boudjnah9246d962014-06-30 12:52:51 +0000287 echo 'APT::Acquire::Retries "20";' | sudo tee /etc/apt/apt.conf.d/80retry >/dev/null
Sean Daguee83f7782014-06-23 08:11:05 -0400288fi
289
Ian Wienand531aeb72014-02-28 11:24:29 +1100290# Some distros need to add repos beyond the defaults provided by the vendor
291# to pick up required packages.
292
Ian Wienanddc04b5a2017-12-04 11:32:36 +1100293function _install_epel {
Ian Wienand36705b52020-04-09 11:00:28 +0100294 # epel-release is in extras repo which is enabled by default
295 install_package epel-release
296
297 # RDO repos are not tested with epel and may have incompatibilities so
298 # let's limit the packages fetched from epel to the ones not in RDO repos.
Ian Wienand67fd81a2020-04-30 09:24:04 +1000299 sudo dnf config-manager --save --setopt=includepkgs=debootstrap,dpkg epel
Ian Wienanddc04b5a2017-12-04 11:32:36 +1100300}
Ian Wienand531aeb72014-02-28 11:24:29 +1100301
Ian Wienanddc04b5a2017-12-04 11:32:36 +1100302function _install_rdo {
Ian Wienand36705b52020-04-09 11:00:28 +0100303 # NOTE(ianw) 2020-04-30 : when we have future branches, we
304 # probably want to install the relevant branch RDO release as
305 # well. But for now it's all master.
306 sudo dnf -y install https://rdoproject.org/repos/rdo-release.el8.rpm
307 sudo dnf -y update
Ian Wienand95a9ff02015-11-12 14:49:20 +1100308}
Wiekus Beukesec47bc12015-03-19 08:20:38 -0700309
Dean Troyer0e8dced2014-07-25 10:33:21 -0500310
311# Configure Target Directories
312# ----------------------------
313
314# Destination path for installation ``DEST``
315DEST=${DEST:-/opt/stack}
Dean Troyer23f69d82013-10-04 12:35:24 -0500316
Dean Troyere26232b2012-06-27 17:55:15 -0500317# Create the destination directory and ensure it is writable by the user
Bob Ball376b6312013-07-29 13:10:25 +0100318# and read/executable by everybody for daemons (e.g. apache run for horizon)
Graham Hayes352d58a2015-07-20 16:28:52 +0100319# If directory exists do not modify the permissions.
320if [[ ! -d $DEST ]]; then
321 sudo mkdir -p $DEST
322 safe_chown -R $STACK_USER $DEST
323 safe_chmod 0755 $DEST
324fi
Dean Troyere26232b2012-06-27 17:55:15 -0500325
Ihar Hrachyshka09a3e712016-01-13 11:35:12 +0100326# Destination path for devstack logs
327if [[ -n ${LOGDIR:-} ]]; then
328 mkdir -p $LOGDIR
329fi
330
Dean Troyer0e8dced2014-07-25 10:33:21 -0500331# Destination path for service data
332DATA_DIR=${DATA_DIR:-${DEST}/data}
Graham Hayes352d58a2015-07-20 16:28:52 +0100333if [[ ! -d $DATA_DIR ]]; then
334 sudo mkdir -p $DATA_DIR
335 safe_chown -R $STACK_USER $DATA_DIR
336 safe_chmod 0755 $DATA_DIR
337fi
Dean Troyer0e8dced2014-07-25 10:33:21 -0500338
Dan Smith30d9bf92021-01-19 12:10:52 -0800339# Create and/or clean the async state directory
340async_init
341
Dean Troyer0e8dced2014-07-25 10:33:21 -0500342# Configure proper hostname
Ben Nemec3ee52c82013-12-12 19:26:12 +0000343# Certain services such as rabbitmq require that the local hostname resolves
344# correctly. Make sure it exists in /etc/hosts so that is always true.
345LOCAL_HOSTNAME=`hostname -s`
Peter Penchev854cb672017-12-14 21:45:52 +0000346if ! fgrep -qwe "$LOCAL_HOSTNAME" /etc/hosts; then
Ben Nemec3ee52c82013-12-12 19:26:12 +0000347 sudo sed -i "s/\(^127.0.0.1.*\)/\1 $LOCAL_HOSTNAME/" /etc/hosts
348fi
349
Ihar Hrachyshka09a3e712016-01-13 11:35:12 +0100350# If you have all the repos installed above already setup (e.g. a CI
351# situation where they are on your image) you may choose to skip this
352# to speed things up
353SKIP_EPEL_INSTALL=$(trueorfalse False SKIP_EPEL_INSTALL)
354
Ian Wienand36705b52020-04-09 11:00:28 +0100355if [[ $DISTRO == "rhel8" ]]; then
Ian Wienanddc04b5a2017-12-04 11:32:36 +1100356 # If we have /etc/ci/mirror_info.sh assume we're on a OpenStack CI
357 # node, where EPEL is installed (but disabled) and already
358 # pointing at our internal mirror
359 if [[ -f /etc/ci/mirror_info.sh ]]; then
360 SKIP_EPEL_INSTALL=True
Ian Wienand36705b52020-04-09 11:00:28 +0100361 sudo dnf config-manager --set-enabled epel
Paul Belangerbc4b8eb2017-04-13 15:06:36 -0400362 fi
Ian Wienandbda194a2016-05-18 10:42:56 +1000363
Ian Wienand36705b52020-04-09 11:00:28 +0100364 # PowerTools repo provides libyaml-devel required by devstack itself and
365 # EPEL packages assume that the PowerTools repository is enable.
366 sudo dnf config-manager --set-enabled PowerTools
367
Pierre Riteauf3611222021-02-17 17:43:13 +0100368 # CentOS 8.3 changed the repository name to lower case.
369 sudo dnf config-manager --set-enabled powertools
370
Ian Wienanddc04b5a2017-12-04 11:32:36 +1100371 if [[ ${SKIP_EPEL_INSTALL} != True ]]; then
372 _install_epel
373 fi
374 # Along with EPEL, CentOS (and a-likes) require some packages only
375 # available in RDO repositories (e.g. OVS, or later versions of
376 # kvm) to run.
377 _install_rdo
Ian Wienand36705b52020-04-09 11:00:28 +0100378
379 # NOTE(cgoncalves): workaround RHBZ#1154272
380 # dnf fails for non-privileged users when expired_repos.json doesn't exist.
381 # RHBZ: https://bugzilla.redhat.com/show_bug.cgi?id=1154272
382 # Patch: https://github.com/rpm-software-management/dnf/pull/1448
383 echo "[]" | sudo tee /var/cache/dnf/expired_repos.json
Ihar Hrachyshka09a3e712016-01-13 11:35:12 +0100384fi
385
Attila Fazekasadcf40d2015-11-05 09:47:38 +0100386# Ensure python is installed
387# --------------------------
Federico Ressi21a10d32020-01-31 07:43:30 +0100388install_python
Attila Fazekasadcf40d2015-11-05 09:47:38 +0100389
Ian Wienand531aeb72014-02-28 11:24:29 +1100390
Dean Troyerffd17682014-08-02 16:07:03 -0500391# Configure Logging
392# -----------------
393
394# Set up logging level
Sean Dague53753292014-12-04 19:38:15 -0500395VERBOSE=$(trueorfalse True VERBOSE)
Ian Wienand83ecb972018-02-06 10:03:34 +1100396VERBOSE_NO_TIMESTAMP=$(trueorfalse False VERBOSE)
Dean Troyerffd17682014-08-02 16:07:03 -0500397
398# Draw a spinner so the user knows something is happening
399function spinner {
400 local delay=0.75
401 local spinstr='/-\|'
402 printf "..." >&3
403 while [ true ]; do
404 local temp=${spinstr#?}
405 printf "[%c]" "$spinstr" >&3
406 local spinstr=$temp${spinstr%"$temp"}
407 sleep $delay
408 printf "\b\b\b" >&3
409 done
410}
411
412function kill_spinner {
413 if [ ! -z "$LAST_SPINNER_PID" ]; then
414 kill >/dev/null 2>&1 $LAST_SPINNER_PID
415 printf "\b\b\bdone\n" >&3
416 fi
417}
418
419# Echo text to the log file, summary log file and stdout
420# echo_summary "something to say"
421function echo_summary {
422 if [[ -t 3 && "$VERBOSE" != "True" ]]; then
423 kill_spinner
424 echo -n -e $@ >&6
425 spinner &
426 LAST_SPINNER_PID=$!
427 else
428 echo -e $@ >&6
429 fi
430}
431
432# Echo text only to stdout, no log files
433# echo_nolog "something not for the logs"
434function echo_nolog {
435 echo $@ >&3
436}
437
Dean Troyerffd17682014-08-02 16:07:03 -0500438# Set up logging for ``stack.sh``
439# Set ``LOGFILE`` to turn on logging
440# Append '.xxxxxxxx' to the given name to maintain history
441# where 'xxxxxxxx' is a representation of the date the file was created
442TIMESTAMP_FORMAT=${TIMESTAMP_FORMAT:-"%F-%H%M%S"}
Dean Troyerdde41d02014-12-09 17:47:57 -0600443LOGDAYS=${LOGDAYS:-7}
444CURRENT_LOG_TIME=$(date "+$TIMESTAMP_FORMAT")
Dean Troyerffd17682014-08-02 16:07:03 -0500445
446if [[ -n "$LOGFILE" ]]; then
Dean Troyerad5cc982014-12-10 16:35:32 -0600447 # Clean up old log files. Append '.*' to the user-specified
448 # ``LOGFILE`` to match the date in the search template.
Mikhail S Medvedevfc9cc962015-01-20 11:04:48 -0600449 LOGFILE_DIR="${LOGFILE%/*}" # dirname
450 LOGFILE_NAME="${LOGFILE##*/}" # basename
451 mkdir -p $LOGFILE_DIR
452 find $LOGFILE_DIR -maxdepth 1 -name $LOGFILE_NAME.\* -mtime +$LOGDAYS -exec rm {} \;
Dean Troyerffd17682014-08-02 16:07:03 -0500453 LOGFILE=$LOGFILE.${CURRENT_LOG_TIME}
Dean Troyerad5cc982014-12-10 16:35:32 -0600454 SUMFILE=$LOGFILE.summary.${CURRENT_LOG_TIME}
Dean Troyerffd17682014-08-02 16:07:03 -0500455
456 # Redirect output according to config
457
458 # Set fd 3 to a copy of stdout. So we can set fd 1 without losing
459 # stdout later.
460 exec 3>&1
461 if [[ "$VERBOSE" == "True" ]]; then
Ian Wienand83ecb972018-02-06 10:03:34 +1100462 _of_args="-v"
463 if [[ "$VERBOSE_NO_TIMESTAMP" == "True" ]]; then
464 _of_args="$_of_args --no-timestamp"
465 fi
Dean Troyerffd17682014-08-02 16:07:03 -0500466 # Set fd 1 and 2 to write the log file
Federico Ressi21a10d32020-01-31 07:43:30 +0100467 exec 1> >( $PYTHON $TOP_DIR/tools/outfilter.py $_of_args -o "${LOGFILE}" ) 2>&1
Dean Troyerffd17682014-08-02 16:07:03 -0500468 # Set fd 6 to summary log file
Federico Ressi21a10d32020-01-31 07:43:30 +0100469 exec 6> >( $PYTHON $TOP_DIR/tools/outfilter.py -o "${SUMFILE}" )
Dean Troyerffd17682014-08-02 16:07:03 -0500470 else
471 # Set fd 1 and 2 to primary logfile
Federico Ressi21a10d32020-01-31 07:43:30 +0100472 exec 1> >( $PYTHON $TOP_DIR/tools/outfilter.py -o "${LOGFILE}" ) 2>&1
Dean Troyerffd17682014-08-02 16:07:03 -0500473 # Set fd 6 to summary logfile and stdout
Federico Ressi21a10d32020-01-31 07:43:30 +0100474 exec 6> >( $PYTHON $TOP_DIR/tools/outfilter.py -v -o "${SUMFILE}" >&3 )
Dean Troyerffd17682014-08-02 16:07:03 -0500475 fi
476
477 echo_summary "stack.sh log $LOGFILE"
478 # Specified logfile name always links to the most recent log
Mikhail S Medvedevfc9cc962015-01-20 11:04:48 -0600479 ln -sf $LOGFILE $LOGFILE_DIR/$LOGFILE_NAME
480 ln -sf $SUMFILE $LOGFILE_DIR/$LOGFILE_NAME.summary
Dean Troyerffd17682014-08-02 16:07:03 -0500481else
482 # Set up output redirection without log files
483 # Set fd 3 to a copy of stdout. So we can set fd 1 without losing
484 # stdout later.
485 exec 3>&1
486 if [[ "$VERBOSE" != "True" ]]; then
487 # Throw away stdout and stderr
488 exec 1>/dev/null 2>&1
489 fi
490 # Always send summary fd to original stdout
Federico Ressi21a10d32020-01-31 07:43:30 +0100491 exec 6> >( $PYTHON $TOP_DIR/tools/outfilter.py -v >&3 )
Dean Troyerffd17682014-08-02 16:07:03 -0500492fi
493
Einst Crazy9e11e092015-09-29 20:01:44 +0800494# Basic test for ``$DEST`` path permissions (fatal on error unless skipped)
495check_path_perm_sanity ${DEST}
Dean Troyerffd17682014-08-02 16:07:03 -0500496
497# Configure Error Traps
498# ---------------------
499
500# Kill background processes on exit
501trap exit_trap EXIT
502function exit_trap {
503 local r=$?
504 jobs=$(jobs -p)
505 # Only do the kill when we're logging through a process substitution,
506 # which currently is only to verbose logfile
507 if [[ -n $jobs && -n "$LOGFILE" && "$VERBOSE" == "True" ]]; then
508 echo "exit_trap: cleaning up child processes"
509 kill 2>&1 $jobs
510 fi
511
Sean Dague85cf2932017-03-27 15:35:13 -0400512 #Remove timing data file
513 if [ -f "$OSCWRAP_TIMER_FILE" ] ; then
514 rm "$OSCWRAP_TIMER_FILE"
515 fi
516
Dean Troyerffd17682014-08-02 16:07:03 -0500517 # Kill the last spinner process
518 kill_spinner
519
520 if [[ $r -ne 0 ]]; then
521 echo "Error on exit"
Monty Taylor03ae3c42017-09-19 14:22:19 -0500522 # If we error before we've installed os-testr, this will fail.
Monty Taylorcbd5f4e2017-09-10 15:00:29 -0600523 if type -p generate-subunit > /dev/null; then
524 generate-subunit $DEVSTACK_START_TIME $SECONDS 'fail' >> ${SUBUNIT_OUTPUT}
525 fi
Dean Troyerffd17682014-08-02 16:07:03 -0500526 if [[ -z $LOGDIR ]]; then
Federico Ressi21a10d32020-01-31 07:43:30 +0100527 ${PYTHON} $TOP_DIR/tools/worlddump.py
Dean Troyerffd17682014-08-02 16:07:03 -0500528 else
Federico Ressi21a10d32020-01-31 07:43:30 +0100529 ${PYTHON} $TOP_DIR/tools/worlddump.py -d $LOGDIR
Dean Troyerffd17682014-08-02 16:07:03 -0500530 fi
Matthew Treinish4af2afc2015-10-13 09:51:17 -0400531 else
Monty Taylor03ae3c42017-09-19 14:22:19 -0500532 # If we error before we've installed os-testr, this will fail.
Monty Taylorcbd5f4e2017-09-10 15:00:29 -0600533 if type -p generate-subunit > /dev/null; then
534 generate-subunit $DEVSTACK_START_TIME $SECONDS >> ${SUBUNIT_OUTPUT}
535 fi
Dean Troyerffd17682014-08-02 16:07:03 -0500536 fi
537
538 exit $r
539}
540
541# Exit on any errors so that errors don't compound
542trap err_trap ERR
543function err_trap {
544 local r=$?
545 set +o xtrace
546 if [[ -n "$LOGFILE" ]]; then
547 echo "${0##*/} failed: full log in $LOGFILE"
548 else
549 echo "${0##*/} failed"
550 fi
551 exit $r
552}
553
554# Begin trapping error exit codes
555set -o errexit
556
Dean Troyerdc97cb72015-03-28 08:20:50 -0500557# Print the kernel version
558uname -a
559
Jamie Lennoxbd24a8d2013-09-20 16:26:42 +1000560# Reset the bundle of CA certificates
561SSL_BUNDLE_FILE="$DATA_DIR/ca-bundle.pem"
562rm -f $SSL_BUNDLE_FILE
563
Dean Troyer0e8dced2014-07-25 10:33:21 -0500564# Import common services (database, message queue) configuration
565source $TOP_DIR/lib/database
566source $TOP_DIR/lib/rpc_backend
567
Dean Troyerd81a0272012-08-31 18:04:55 -0500568# Configure Projects
569# ==================
570
Bharat Kumar Kobagana7b9341e2015-03-30 11:58:10 +0530571# Clone all external plugins
572fetch_plugins
573
Wei Jiangang2af69152015-09-08 18:03:22 +0800574# Plugin Phase 0: override_defaults - allow plugins to override
Sean Dague6e275e12015-03-26 05:54:28 -0400575# defaults before other services are run
576run_phase override_defaults
577
Dean Troyerdc97cb72015-03-28 08:20:50 -0500578# Import Apache functions
zhang-hared98a5d02013-06-21 18:18:02 +0800579source $TOP_DIR/lib/apache
Brant Knudson0049c0c2014-01-16 18:16:48 -0600580
581# Import TLS functions
Dean Troyerc83a7e12012-11-29 11:47:58 -0600582source $TOP_DIR/lib/tls
Brant Knudson0049c0c2014-01-16 18:16:48 -0600583
584# Source project function libraries
Sean Dague0392a102013-07-31 13:07:45 -0400585source $TOP_DIR/lib/infra
Sean Dague3ed99c02017-06-20 14:09:30 -0400586source $TOP_DIR/lib/libraries
Daniel Genind4708672014-10-31 15:01:29 -0400587source $TOP_DIR/lib/lvm
Sean Dagueb562e6a2012-11-19 16:00:01 -0500588source $TOP_DIR/lib/horizon
Dean Troyerd81a0272012-08-31 18:04:55 -0500589source $TOP_DIR/lib/keystone
Dean Troyer73f6f252012-09-17 11:22:21 -0500590source $TOP_DIR/lib/glance
Dean Troyerbf67c192012-09-21 15:09:37 -0500591source $TOP_DIR/lib/nova
Chris Dent4d601752016-07-12 19:34:09 +0000592source $TOP_DIR/lib/placement
Dean Troyerd81a0272012-08-31 18:04:55 -0500593source $TOP_DIR/lib/cinder
Attila Fazekasece6a332012-11-29 14:19:41 +0100594source $TOP_DIR/lib/swift
Sean M. Collins2a242512016-05-03 09:03:09 -0400595source $TOP_DIR/lib/neutron
Brad Topolf127e2f2013-01-22 10:17:50 -0600596source $TOP_DIR/lib/ldap
Joe Gordone0b08d02014-08-20 00:34:55 -0700597source $TOP_DIR/lib/dstat
Ian Wienand2bbc9bb2019-02-11 12:25:38 +1100598source $TOP_DIR/lib/tcpdump
Davanum Srinivas546656f2017-03-14 07:05:19 -0400599source $TOP_DIR/lib/etcd3
Dean Troyerd81a0272012-08-31 18:04:55 -0500600
Dean Troyercdf3d762013-10-15 09:42:43 -0500601# Extras Source
602# --------------
603
604# Phase: source
Sean Dague2c65e712014-12-18 09:44:56 -0500605run_phase source
Dean Troyercdf3d762013-10-15 09:42:43 -0500606
Chris Dentc6d47012015-10-09 14:57:05 +0000607
Dean Troyerb7490da2013-03-18 16:07:56 -0500608# Interactive Configuration
609# -------------------------
610
611# Do all interactive config up front before the logging spew begins
James E. Blair213c4162012-11-06 09:38:36 +0100612
Anthony Young7a549f42011-10-12 07:13:13 +0000613# Generic helper to configure passwords
614function read_password {
Ian Wienand523f4882015-10-13 11:03:03 +1100615 local xtrace
616 xtrace=$(set +o | grep xtrace)
Anthony Young7a549f42011-10-12 07:13:13 +0000617 set +o xtrace
618 var=$1; msg=$2
619 pw=${!var}
620
Sahid Orentino Ferdjaoui9e032c22014-02-10 11:36:25 +0100621 if [[ -f $RC_DIR/localrc ]]; then
622 localrc=$TOP_DIR/localrc
623 else
Ian Wienand975f4202015-10-14 15:12:32 +1100624 localrc=$TOP_DIR/.localrc.password
Sahid Orentino Ferdjaoui9e032c22014-02-10 11:36:25 +0100625 fi
Anthony Young6015c822011-10-12 07:17:11 +0000626
Anthony Young7a549f42011-10-12 07:13:13 +0000627 # If the password is not defined yet, proceed to prompt user for a password.
628 if [ ! $pw ]; then
629 # If there is no localrc file, create one
Anthony Youngb4db2252011-10-12 14:08:08 -0700630 if [ ! -e $localrc ]; then
631 touch $localrc
Anthony Young7a549f42011-10-12 07:13:13 +0000632 fi
633
Ian Wienand975f4202015-10-14 15:12:32 +1100634 # Presumably if we got this far it can only be that our
635 # localrc is missing the required password. Prompt user for a
636 # password and write to localrc.
637
Anthony Youngb4db2252011-10-12 14:08:08 -0700638 echo ''
639 echo '################################################################################'
640 echo $msg
641 echo '################################################################################'
Ian Wienand975f4202015-10-14 15:12:32 +1100642 echo "This value will be written to ${localrc} file so you don't have to enter it "
Dean Troyer4e6a2b72011-12-29 17:27:45 -0600643 echo "again. Use only alphanumeric characters."
Anthony Youngb4db2252011-10-12 14:08:08 -0700644 echo "If you leave this blank, a random default value will be used."
Dean Troyer4e6a2b72011-12-29 17:27:45 -0600645 pw=" "
646 while true; do
647 echo "Enter a password now:"
648 read -e $var
649 pw=${!var}
650 [[ "$pw" = "`echo $pw | tr -cd [:alnum:]`" ]] && break
651 echo "Invalid chars in password. Try again:"
652 done
Anthony Youngb4db2252011-10-12 14:08:08 -0700653 if [ ! $pw ]; then
Attila Fazekasf71b5002014-05-28 09:52:22 +0200654 pw=$(generate_hex_string 10)
Anthony Young7a549f42011-10-12 07:13:13 +0000655 fi
Anthony Youngb4db2252011-10-12 14:08:08 -0700656 eval "$var=$pw"
657 echo "$var=$pw" >> $localrc
Anthony Young7a549f42011-10-12 07:13:13 +0000658 fi
Ian Wienand523f4882015-10-13 11:03:03 +1100659
660 # restore previous xtrace value
661 $xtrace
Anthony Young7a549f42011-10-12 07:13:13 +0000662}
663
Dean Troyer13dc5cc2012-03-27 14:50:45 -0500664
Dean Troyerb9182d62012-11-07 12:31:34 -0600665# Database Configuration
Dean Troyerdc97cb72015-03-28 08:20:50 -0500666# ----------------------
Dean Troyerb9182d62012-11-07 12:31:34 -0600667
Matt Riedemannb14665f2019-10-17 19:34:05 +0000668# To select between database backends, add the following to ``local.conf``:
Terry Wilson428af5a2012-11-01 16:12:39 -0400669#
Dean Troyerafc29fe2013-02-07 15:56:24 -0600670# disable_service mysql
Matt Riedemannb14665f2019-10-17 19:34:05 +0000671# enable_service postgresql
672#
673# The available database backends are listed in ``DATABASE_BACKENDS`` after
674# ``lib/database`` is sourced. ``mysql`` is the default.
675
Luigi Toscano29771c12019-02-21 10:36:18 +0100676if initialize_database_backends; then
677 echo "Using $DATABASE_TYPE database backend"
678 # Last chance for the database password. This must be handled here
679 # because read_password is not a library function.
680 read_password DATABASE_PASSWORD "ENTER A PASSWORD TO USE FOR THE DATABASE."
681else
682 echo "No database enabled"
683fi
Terry Wilson428af5a2012-11-01 16:12:39 -0400684
Dean Troyerb9182d62012-11-07 12:31:34 -0600685
Dean Troyerb7490da2013-03-18 16:07:56 -0500686# Queue Configuration
Dean Troyerdc97cb72015-03-28 08:20:50 -0500687# -------------------
Jesse Andrews782b9912011-10-02 16:53:21 -0400688
Anthony Younga8416442011-09-13 20:07:44 -0700689# Rabbit connection info
Dean Troyerdc97cb72015-03-28 08:20:50 -0500690# In multi node DevStack, second node needs ``RABBIT_USERID``, but rabbit
Joe Gordonf6287c22014-12-16 13:32:41 -0800691# isn't enabled.
Russell Bryant4a221452012-03-13 13:44:12 -0400692if is_service_enabled rabbit; then
Russell Bryant4a221452012-03-13 13:44:12 -0400693 read_password RABBIT_PASSWORD "ENTER A PASSWORD TO USE FOR RABBIT."
694fi
Jesse Andrewsba23cc72011-09-11 03:22:13 -0700695
Dean Troyerb7490da2013-03-18 16:07:56 -0500696
697# Keystone
Dean Troyerdc97cb72015-03-28 08:20:50 -0500698# --------
Dean Troyerb7490da2013-03-18 16:07:56 -0500699
Dean Troyer5ce44cd2015-02-12 22:18:33 -0600700if is_service_enabled keystone; then
Dean Troyerb7490da2013-03-18 16:07:56 -0500701 # Services authenticate to Identity with servicename/``SERVICE_PASSWORD``
702 read_password SERVICE_PASSWORD "ENTER A SERVICE_PASSWORD TO USE FOR THE SERVICE AUTHENTICATION."
703 # Horizon currently truncates usernames and passwords at 20 characters
704 read_password ADMIN_PASSWORD "ENTER A PASSWORD TO USE FOR HORIZON AND KEYSTONE (20 CHARS OR LESS)."
705
706 # Keystone can now optionally install OpenLDAP by enabling the ``ldap``
Dean Troyerdc97cb72015-03-28 08:20:50 -0500707 # service in ``local.conf`` (e.g. ``enable_service ldap``).
Dean Troyerb7490da2013-03-18 16:07:56 -0500708 # To clean out the Keystone contents in OpenLDAP set ``KEYSTONE_CLEAR_LDAP``
Dean Troyerdc97cb72015-03-28 08:20:50 -0500709 # to ``yes`` (e.g. ``KEYSTONE_CLEAR_LDAP=yes``) in ``local.conf``. To enable the
Dean Troyerb7490da2013-03-18 16:07:56 -0500710 # Keystone Identity Driver (``keystone.identity.backends.ldap.Identity``)
711 # set ``KEYSTONE_IDENTITY_BACKEND`` to ``ldap`` (e.g.
Dean Troyerdc97cb72015-03-28 08:20:50 -0500712 # ``KEYSTONE_IDENTITY_BACKEND=ldap``) in ``local.conf``.
Dean Troyerb7490da2013-03-18 16:07:56 -0500713
Dean Troyerdc97cb72015-03-28 08:20:50 -0500714 # Only request LDAP password if the service is enabled
Dean Troyerb7490da2013-03-18 16:07:56 -0500715 if is_service_enabled ldap; then
716 read_password LDAP_PASSWORD "ENTER A PASSWORD TO USE FOR LDAP"
Chmouel Boudjnah6ae9ea52012-07-05 06:50:51 +0000717 fi
Dean Troyerb7490da2013-03-18 16:07:56 -0500718fi
719
720
721# Swift
Dean Troyerdc97cb72015-03-28 08:20:50 -0500722# -----
Dean Troyerb7490da2013-03-18 16:07:56 -0500723
724if is_service_enabled s-proxy; then
Chmouel Boudjnah77b0e1d2012-02-29 16:55:43 +0000725 # We only ask for Swift Hash if we have enabled swift service.
Dean Troyerb9182d62012-11-07 12:31:34 -0600726 # ``SWIFT_HASH`` is a random unique string for a swift cluster that
Chmouel Boudjnahb2857e42011-11-03 16:19:14 +0100727 # can never change.
728 read_password SWIFT_HASH "ENTER A RANDOM SWIFT HASH."
Jim Rollenhagenabbb0e92014-08-05 18:01:48 +0000729
730 if [[ -z "$SWIFT_TEMPURL_KEY" ]] && [[ "$SWIFT_ENABLE_TEMPURLS" == "True" ]]; then
731 read_password SWIFT_TEMPURL_KEY "ENTER A KEY FOR SWIFT TEMPURLS."
732 fi
Chmouel Boudjnahb2857e42011-11-03 16:19:14 +0100733fi
Vishvananda Ishaya5f039322011-11-05 16:12:20 -0700734
Dean Troyer68162342015-05-13 15:41:03 -0500735# Save configuration values
736save_stackenv $LINENO
737
Dean Troyerdf0972c2012-03-07 17:31:03 -0600738
Jesse Andrews30f68e92011-09-13 00:59:54 -0700739# Install Packages
Jesse Andrewsd74257d2011-09-13 01:24:50 -0700740# ================
Dean Troyer7d28a0e2012-06-27 17:55:52 -0500741
Dean Troyer4a43b7b2012-08-28 17:43:40 -0500742# OpenStack uses a fair number of other projects.
Jesse Andrews30f68e92011-09-13 00:59:54 -0700743
Shashank Hegde2d91fe82015-08-18 18:33:55 -0700744# Bring down global requirements before any use of pip_install. This is
745# necessary to ensure that the constraints file is in place before we
746# attempt to apply any constraints to pip installs.
747git_clone $REQUIREMENTS_REPO $REQUIREMENTS_DIR $REQUIREMENTS_BRANCH
748
Dean Troyer7d28a0e2012-06-27 17:55:52 -0500749# Install package requirements
Dean Troyer48352ee2012-12-12 12:50:38 -0600750# Source it so the entire environment is available
Dean Troyer7903b792012-09-13 17:16:12 -0500751echo_summary "Installing package prerequisites"
Dean Troyer48352ee2012-12-12 12:50:38 -0600752source $TOP_DIR/tools/install_prereqs.sh
Monty Taylor47f02062012-07-26 11:09:24 -0500753
Dean Troyerdc97cb72015-03-28 08:20:50 -0500754# Configure an appropriate Python environment
Arata Notsu8b5d3cf2013-10-17 21:42:49 +0900755if [[ "$OFFLINE" != "True" ]]; then
Sean Dague53753292014-12-04 19:38:15 -0500756 PYPI_ALTERNATIVE_URL=${PYPI_ALTERNATIVE_URL:-""} $TOP_DIR/tools/install_pip.sh
Arata Notsu8b5d3cf2013-10-17 21:42:49 +0900757fi
Dean Troyer1a6d4492013-06-03 16:47:36 -0500758
Gael Chamoulaudd3121f62014-07-24 23:53:02 +0200759# Do the ugly hacks for broken packages and distros
Dean Troyer04a35112014-08-15 14:03:52 -0500760source $TOP_DIR/tools/fixup_stuff.sh
IWAMOTO Toshihiro4d835e32018-02-05 16:57:41 +0900761fixup_all
Dean Troyer9acc12a2013-08-09 15:09:31 -0500762
Colleen Murphy6eb2c592019-09-25 12:51:23 -0700763# Install subunit for the subunit output stream
764pip_install -U os-testr
765
Dr. Jens Harbott6808a342020-01-20 15:52:33 +0000766# the default rate limit of 1000 messages / 30 seconds is not
767# sufficient given how verbose our logging is.
768iniset -sudo /etc/systemd/journald.conf "Journal" "RateLimitBurst" "0"
769sudo systemctl restart systemd-journald
Dean Troyer5c3a63e2014-07-09 11:27:42 -0500770
Dean Troyerb1d8e8e2015-02-16 13:58:35 -0600771# Virtual Environment
772# -------------------
773
Yuki Nishiwaki0a9d03d2015-05-08 16:29:55 +0900774# Install required infra support libraries
775install_infra
776
Ian Wienand58243f62018-12-13 14:05:53 +1100777# Install bindep
778$VIRTUALENV_CMD $DEST/bindep-venv
779# TODO(ianw) : optionally install from zuul checkout?
780$DEST/bindep-venv/bin/pip install bindep
Ian Wienandfa9aadf2019-01-15 18:31:05 +1100781export BINDEP_CMD=${DEST}/bindep-venv/bin/bindep
782
783# Install packages as defined in plugin bindep.txt files
784pkgs="$( _get_plugin_bindep_packages )"
785if [[ -n "${pkgs}" ]]; then
786 install_package ${pkgs}
787fi
Ian Wienand58243f62018-12-13 14:05:53 +1100788
Dean Troyer5c3a63e2014-07-09 11:27:42 -0500789# Extras Pre-install
790# ------------------
Dean Troyer5c3a63e2014-07-09 11:27:42 -0500791# Phase: pre-install
Sean Dague2c65e712014-12-18 09:44:56 -0500792run_phase stack pre-install
Dean Troyer5c3a63e2014-07-09 11:27:42 -0500793
Dan Smith1f55d382017-05-16 08:50:53 -0700794# NOTE(danms): Set global limits before installing anything
795set_systemd_override DefaultLimitNOFILE ${ULIMIT_NOFILE}
796
Dean Troyer62d1d692013-08-01 17:40:40 -0500797install_rpc_backend
Dan Smithb1d85192017-02-23 08:01:32 -0800798restart_rpc_backend
Dean Troyer62d1d692013-08-01 17:40:40 -0500799
800if is_service_enabled $DATABASE_BACKENDS; then
801 install_database
Olivier Lemasle7dd890d2015-09-14 14:21:12 +0200802fi
803if [ -n "$DATABASE_TYPE" ]; then
Dean Troyer5686dbc2015-03-09 14:27:51 -0500804 install_database_python
Dean Troyer62d1d692013-08-01 17:40:40 -0500805fi
806
807if is_service_enabled neutron; then
808 install_neutron_agent_packages
809fi
810
Sean Dague62b56602017-06-19 08:27:16 -0400811if is_service_enabled etcd3; then
812 install_etcd3
813fi
814
Clark Boylancc072fd2017-05-31 20:27:59 -0700815# Setup TLS certs
816# ---------------
817
818# Do this early, before any webservers are set up to ensure
819# we don't run into problems with missing certs when apache
820# is restarted.
821if is_service_enabled tls-proxy; then
822 configure_CA
823 init_CA
824 init_cert
825fi
826
Federico Ressi19e4d972020-01-24 11:44:46 +0100827# Dstat
828# -----
829
830# Install dstat services prerequisites
831install_dstat
832
833
Dean Troyerfe51a902013-04-01 15:48:44 -0500834# Check Out and Install Source
835# ----------------------------
Dean Troyer4a43b7b2012-08-28 17:43:40 -0500836
Dean Troyer7903b792012-09-13 17:16:12 -0500837echo_summary "Installing OpenStack project source"
838
Sean Dague3ed99c02017-06-20 14:09:30 -0400839# Install additional libraries
840install_libs
Sean Dague1b6b5312013-07-31 06:46:34 -0400841
Sean Dague604e5982017-04-13 13:28:12 -0400842# Install uwsgi
843install_apache_uwsgi
844
Dean Troyerdc97cb72015-03-28 08:20:50 -0500845# Install client libraries
Jamie Lennox21a90772015-07-03 11:54:38 +1000846install_keystoneauth
Dean Troyerd81a0272012-08-31 18:04:55 -0500847install_keystoneclient
Dean Troyer73f6f252012-09-17 11:22:21 -0500848install_glanceclient
Dean Troyer253a1a32013-04-01 18:23:22 -0500849install_cinderclient
Dean Troyerbf67c192012-09-21 15:09:37 -0500850install_novaclient
Sean Dague75195b52013-07-25 15:38:09 -0400851if is_service_enabled swift glance horizon; then
Dean Troyerfe51a902013-04-01 15:48:44 -0500852 install_swiftclient
853fi
Sean Dague75195b52013-07-25 15:38:09 -0400854if is_service_enabled neutron nova horizon; then
Mark McClainb05c8762013-07-06 23:29:39 -0400855 install_neutronclient
Dean Troyerfe51a902013-04-01 15:48:44 -0500856fi
857
Morgan Fainberg58936fd2014-06-24 12:26:07 -0700858# Install middleware
859install_keystonemiddleware
860
Dean Troyer5ce44cd2015-02-12 22:18:33 -0600861if is_service_enabled keystone; then
Bartosz Górski0abde392014-02-28 14:15:19 +0100862 if [ "$KEYSTONE_AUTH_HOST" == "$SERVICE_HOST" ]; then
Dean Troyer8c2ce6e2015-02-18 14:47:54 -0600863 stack_install_service keystone
Bartosz Górski0abde392014-02-28 14:15:19 +0100864 configure_keystone
865 fi
Jesse Andrews38df1222011-11-20 09:55:44 -0800866fi
Attila Fazekasece6a332012-11-29 14:19:41 +0100867
Sean Dague8b416ae2016-03-25 08:58:54 -0400868if is_service_enabled swift; then
gordon chungb6197e62015-02-12 15:33:35 -0500869 if is_service_enabled ceilometer; then
870 install_ceilometermiddleware
871 fi
Dean Troyer8c2ce6e2015-02-18 14:47:54 -0600872 stack_install_service swift
Dean Troyerfe51a902013-04-01 15:48:44 -0500873 configure_swift
874
Kota Tsuyuzaki070e4ee2018-09-13 03:08:19 +0900875 # s3api middleware to provide S3 emulation to Swift
876 if is_service_enabled s3api; then
Dean Troyerdc97cb72015-03-28 08:20:50 -0500877 # Replace the nova-objectstore port by the swift port
rahmu9d2647a2013-04-24 10:40:07 +0200878 S3_SERVICE_PORT=8080
Chmouel Boudjnah6ae9ea52012-07-05 06:50:51 +0000879 fi
James E. Blaire7ce24f2011-11-10 13:05:13 -0800880fi
Attila Fazekasece6a332012-11-29 14:19:41 +0100881
Chmouel Boudjnaha6651e92012-02-16 10:16:52 +0000882if is_service_enabled g-api n-api; then
Dean Troyerdc97cb72015-03-28 08:20:50 -0500883 # Image catalog service
Dean Troyer8c2ce6e2015-02-18 14:47:54 -0600884 stack_install_service glance
Dean Troyerfe51a902013-04-01 15:48:44 -0500885 configure_glance
James E. Blaire7ce24f2011-11-10 13:05:13 -0800886fi
Dean Troyerfe51a902013-04-01 15:48:44 -0500887
888if is_service_enabled cinder; then
Dean Troyerdc97cb72015-03-28 08:20:50 -0500889 # Block volume service
Dean Troyer8c2ce6e2015-02-18 14:47:54 -0600890 stack_install_service cinder
Dean Troyerfe51a902013-04-01 15:48:44 -0500891 configure_cinder
892fi
893
Mark McClainb05c8762013-07-06 23:29:39 -0400894if is_service_enabled neutron; then
Dean Troyerdc97cb72015-03-28 08:20:50 -0500895 # Network service
Dean Troyer8c2ce6e2015-02-18 14:47:54 -0600896 stack_install_service neutron
Dean Troyerfe51a902013-04-01 15:48:44 -0500897fi
898
Dean Troyerbf67c192012-09-21 15:09:37 -0500899if is_service_enabled nova; then
Dean Troyerdc97cb72015-03-28 08:20:50 -0500900 # Compute service
Dean Troyer8c2ce6e2015-02-18 14:47:54 -0600901 stack_install_service nova
Dean Troyerfe51a902013-04-01 15:48:44 -0500902 configure_nova
Dean Troyerbf67c192012-09-21 15:09:37 -0500903fi
Dean Troyerfe51a902013-04-01 15:48:44 -0500904
Chris Dent4d601752016-07-12 19:34:09 +0000905if is_service_enabled placement; then
906 # placement api
907 stack_install_service placement
Chris Dent4d601752016-07-12 19:34:09 +0000908 configure_placement
909fi
910
Sean Dague51a225c2016-12-15 16:32:08 -0500911# create a placement-client fake service to know we need to configure
912# placement connectivity. We configure the placement service for nova
913# if placement-api or placement-client is active, and n-cpu on the
914# same box.
915if is_service_enabled placement placement-client; then
Prashant Shettyf58b3732017-02-23 13:48:12 +0000916 if is_service_enabled n-cpu || is_service_enabled n-sch; then
Sean Dague51a225c2016-12-15 16:32:08 -0500917 configure_placement_nova_compute
918 fi
919fi
920
Chmouel Boudjnaha6651e92012-02-16 10:16:52 +0000921if is_service_enabled horizon; then
Sean Dagueb562e6a2012-11-19 16:00:01 -0500922 # dashboard
Dean Troyer8c2ce6e2015-02-18 14:47:54 -0600923 stack_install_service horizon
James E. Blaire7ce24f2011-11-10 13:05:13 -0800924fi
Dean Troyerfe51a902013-04-01 15:48:44 -0500925
Sean Daguef3b2f4c2017-04-13 10:11:48 -0400926if is_service_enabled tls-proxy; then
Daniel P. Berrangec30b8de2016-11-14 13:23:14 +0000927 fix_system_ca_bundle_path
Dean Troyer67787e62012-05-02 11:48:15 -0500928fi
Jesse Andrewsba23cc72011-09-11 03:22:13 -0700929
Dean Troyercdf3d762013-10-15 09:42:43 -0500930# Extras Install
931# --------------
932
933# Phase: install
Sean Dague2c65e712014-12-18 09:44:56 -0500934run_phase stack install
Dean Troyercdf3d762013-10-15 09:42:43 -0500935
Dean Troyerdc97cb72015-03-28 08:20:50 -0500936# Install the OpenStack client, needed for most setup commands
Ihar Hrachyshka1ffa3322015-02-20 16:23:15 +0100937if use_library_from_git "python-openstackclient"; then
938 git_clone_by_name "python-openstackclient"
939 setup_dev_lib "python-openstackclient"
940else
Sean Dague60996b12015-04-08 09:06:49 -0400941 pip_install_gr python-openstackclient
Ihar Hrachyshka1ffa3322015-02-20 16:23:15 +0100942fi
943
Sean Dague85cf2932017-03-27 15:35:13 -0400944# Installs alias for osc so that we can collect timing for all
945# osc commands. Alias dies with stack.sh.
946install_oscwrap
947
Dean Troyerff603ef2011-11-22 17:48:10 -0600948# Syslog
Dean Troyerdf0972c2012-03-07 17:31:03 -0600949# ------
Dean Troyerff603ef2011-11-22 17:48:10 -0600950
951if [[ $SYSLOG != "False" ]]; then
Dean Troyerff603ef2011-11-22 17:48:10 -0600952 if [[ "$SYSLOG_HOST" = "$HOST_IP" ]]; then
953 # Configure the master host to receive
Dirk Mueller6bab8322018-03-02 21:13:12 +0100954 cat <<EOF | sudo tee /etc/rsyslog.d/90-stack-m.conf >/dev/null
Dean Troyerff603ef2011-11-22 17:48:10 -0600955\$ModLoad imrelp
956\$InputRELPServerRun $SYSLOG_PORT
957EOF
Dean Troyerff603ef2011-11-22 17:48:10 -0600958 else
959 # Set rsyslog to send to remote host
Dirk Mueller6bab8322018-03-02 21:13:12 +0100960 cat <<EOF | sudo tee /etc/rsyslog.d/90-stack-s.conf >/dev/null
Dean Troyerff603ef2011-11-22 17:48:10 -0600961*.* :omrelp:$SYSLOG_HOST:$SYSLOG_PORT
962EOF
Dean Troyerff603ef2011-11-22 17:48:10 -0600963 fi
cloudnulle4859f02013-05-28 14:10:58 -0500964
965 RSYSLOGCONF="/etc/rsyslog.conf"
966 if [ -f $RSYSLOGCONF ]; then
967 sudo cp -b $RSYSLOGCONF $RSYSLOGCONF.bak
968 if [[ $(grep '$SystemLogRateLimitBurst' $RSYSLOGCONF) ]]; then
969 sudo sed -i 's/$SystemLogRateLimitBurst\ .*/$SystemLogRateLimitBurst\ 0/' $RSYSLOGCONF
970 else
971 sudo sed -i '$ i $SystemLogRateLimitBurst\ 0' $RSYSLOGCONF
972 fi
973 if [[ $(grep '$SystemLogRateLimitInterval' $RSYSLOGCONF) ]]; then
974 sudo sed -i 's/$SystemLogRateLimitInterval\ .*/$SystemLogRateLimitInterval\ 0/' $RSYSLOGCONF
975 else
976 sudo sed -i '$ i $SystemLogRateLimitInterval\ 0' $RSYSLOGCONF
977 fi
978 fi
979
Dean Troyer7903b792012-09-13 17:16:12 -0500980 echo_summary "Starting rsyslog"
Dean Troyer13dc5cc2012-03-27 14:50:45 -0500981 restart_service rsyslog
Dean Troyerff603ef2011-11-22 17:48:10 -0600982fi
983
Dean Troyerdf0972c2012-03-07 17:31:03 -0600984
Atsushi SAKAIfe7b56c2015-11-13 17:06:16 +0900985# Export Certificate Authority Bundle
986# -----------------------------------
Jamie Lennoxbd24a8d2013-09-20 16:26:42 +1000987
988# If certificates were used and written to the SSL bundle file then these
989# should be exported so clients can validate their connections.
990
991if [ -f $SSL_BUNDLE_FILE ]; then
992 export OS_CACERT=$SSL_BUNDLE_FILE
993fi
994
995
Terry Wilson428af5a2012-11-01 16:12:39 -0400996# Configure database
997# ------------------
Dean Troyerb9182d62012-11-07 12:31:34 -0600998
Terry Wilson428af5a2012-11-01 16:12:39 -0400999if is_service_enabled $DATABASE_BACKENDS; then
1000 configure_database
Jesse Andrews24859062011-09-15 21:28:23 -07001001fi
1002
Dean Troyer68162342015-05-13 15:41:03 -05001003# Save configuration values
1004save_stackenv $LINENO
1005
Clark Boylanf85e0ba2017-03-17 12:54:30 -07001006# Kernel Samepage Merging (KSM)
1007# -----------------------------
1008
1009# Processes that mark their memory as mergeable can share identical memory
1010# pages if KSM is enabled. This is particularly useful for nova + libvirt
1011# backends but any other setup that marks its memory as mergeable can take
1012# advantage. The drawback is there is higher cpu load; however, we tend to
1013# be memory bound not cpu bound so enable KSM by default but allow people
1014# to opt out if the CPU time is more important to them.
1015
Chandan Kumare8db8672017-10-26 15:34:05 +05301016if [[ $ENABLE_KSM == "True" ]] ; then
Clark Boylanf85e0ba2017-03-17 12:54:30 -07001017 if [[ -f /sys/kernel/mm/ksm/run ]] ; then
1018 sudo sh -c "echo 1 > /sys/kernel/mm/ksm/run"
1019 fi
1020fi
1021
Dean Troyerdc97cb72015-03-28 08:20:50 -05001022
1023# Start Services
1024# ==============
1025
Sean Dague78096b52014-02-25 10:23:04 -05001026# Dstat
Dean Troyerdc97cb72015-03-28 08:20:50 -05001027# -----
Dean Troyer1a6d4492013-06-03 16:47:36 -05001028
Sean Daguef1eb0472014-02-11 17:28:56 -05001029# A better kind of sysstat, with the top process per time slice
Joe Gordone0b08d02014-08-20 00:34:55 -07001030start_dstat
Sean Dague062cdaf2014-02-10 22:24:49 -05001031
Ian Wienand2bbc9bb2019-02-11 12:25:38 +11001032# Run a background tcpdump for debugging
1033# Note: must set TCPDUMP_ARGS with the enabled service
1034if is_service_enabled tcpdump; then
1035 start_tcpdump
1036fi
1037
Davanum Srinivas546656f2017-03-14 07:05:19 -04001038# Etcd
1039# -----
1040
1041# etcd is a distributed key value store that provides a reliable way to store data across a cluster of machines
Andreas Scheuring94b9fae2017-05-24 13:31:13 +02001042if is_service_enabled etcd3; then
1043 start_etcd3
1044fi
Dean Troyer893e6632013-09-13 15:05:51 -05001045
Dean Troyerd81a0272012-08-31 18:04:55 -05001046# Keystone
1047# --------
1048
Patrick Easta5d965a2016-08-03 14:44:53 -07001049# Rather than just export these, we write them out to a
1050# intermediate userrc file that can also be used to debug if
1051# something goes wrong between here and running
1052# tools/create_userrc.sh (this script relies on services other
1053# than keystone being available, so we can't call it right now)
1054cat > $TOP_DIR/userrc_early <<EOF
Steve Martinelli923be5f2015-12-20 00:24:19 -05001055# Use this for debugging issues before files in accrc are created
1056
1057# Set up password auth credentials now that Keystone is bootstrapped
1058export OS_IDENTITY_API_VERSION=3
Jens Harbott32c00892019-04-10 10:33:39 +00001059export OS_AUTH_URL=$KEYSTONE_SERVICE_URI
Steve Martinelli923be5f2015-12-20 00:24:19 -05001060export OS_USERNAME=admin
1061export OS_USER_DOMAIN_ID=default
1062export OS_PASSWORD=$ADMIN_PASSWORD
1063export OS_PROJECT_NAME=admin
1064export OS_PROJECT_DOMAIN_ID=default
zhiyuan_cai6f1781f2016-04-07 18:36:46 +08001065export OS_REGION_NAME=$KEYSTONE_REGION_NAME
Steve Martinelli923be5f2015-12-20 00:24:19 -05001066
1067EOF
1068
Patrick Easta5d965a2016-08-03 14:44:53 -07001069if is_service_enabled tls-proxy; then
1070 echo "export OS_CACERT=$INT_CA_DIR/ca-chain.pem" >> $TOP_DIR/userrc_early
1071 start_tls_proxy http-services '*' 443 $SERVICE_HOST 80
1072fi
Rob Crittendenbe00e952016-03-24 18:09:22 -04001073
Patrick Easta5d965a2016-08-03 14:44:53 -07001074source $TOP_DIR/userrc_early
1075
1076if is_service_enabled keystone; then
1077 echo_summary "Starting Keystone"
1078
1079 if [ "$KEYSTONE_AUTH_HOST" == "$SERVICE_HOST" ]; then
1080 init_keystone
1081 start_keystone
1082 bootstrap_keystone
1083 fi
Dean Troyer42a59c22014-03-03 14:31:29 -06001084
Dean Troyerd835de82012-11-29 17:11:35 -06001085 create_keystone_accounts
Édouard Thuleau93a41562017-03-09 18:53:18 +01001086 if is_service_enabled nova; then
Dan Smith30d9bf92021-01-19 12:10:52 -08001087 async_runfunc create_nova_accounts
Édouard Thuleau93a41562017-03-09 18:53:18 +01001088 fi
1089 if is_service_enabled glance; then
Dan Smith30d9bf92021-01-19 12:10:52 -08001090 async_runfunc create_glance_accounts
Édouard Thuleau93a41562017-03-09 18:53:18 +01001091 fi
1092 if is_service_enabled cinder; then
Dan Smith30d9bf92021-01-19 12:10:52 -08001093 async_runfunc create_cinder_accounts
Édouard Thuleau93a41562017-03-09 18:53:18 +01001094 fi
1095 if is_service_enabled neutron; then
Dan Smith30d9bf92021-01-19 12:10:52 -08001096 async_runfunc create_neutron_accounts
Édouard Thuleau93a41562017-03-09 18:53:18 +01001097 fi
Dean Troyer42a59c22014-03-03 14:31:29 -06001098 if is_service_enabled swift; then
Dan Smith30d9bf92021-01-19 12:10:52 -08001099 async_runfunc create_swift_accounts
Ian Wienand0ff314c2013-07-17 16:30:19 +10001100 fi
1101
Dean Troyerd81a0272012-08-31 18:04:55 -05001102fi
1103
Monty Taylor7224eec2015-09-19 11:26:18 -04001104# Write a clouds.yaml file
1105write_clouds_yaml
Monty Taylor16a2d642015-09-19 11:19:31 -04001106
Tres Henryca85b792011-10-28 14:00:21 -07001107# Horizon
Dean Troyerdf0972c2012-03-07 17:31:03 -06001108# -------
Jesse Andrewscbe98d52011-10-02 17:47:32 -04001109
Chmouel Boudjnaha6651e92012-02-16 10:16:52 +00001110if is_service_enabled horizon; then
Akihiro Motoki43f62c02015-12-15 16:44:41 +09001111 echo_summary "Configuring Horizon"
Dan Smith30d9bf92021-01-19 12:10:52 -08001112 async_runfunc configure_horizon
Anthony Young70dc5e02011-09-15 16:52:43 -07001113fi
Jesse Andrews75a37652011-09-12 17:09:08 -07001114
Dan Smith30d9bf92021-01-19 12:10:52 -08001115async_wait create_nova_accounts create_glance_accounts create_cinder_accounts
1116async_wait create_neutron_accounts create_swift_accounts configure_horizon
Anthony Young3859f732011-09-14 02:33:43 -07001117
Jesse Andrewsd74257d2011-09-13 01:24:50 -07001118# Glance
1119# ------
1120
Radosław Piliszek09e860f2020-01-19 12:41:14 +01001121# NOTE(yoctozepto): limited to node hosting the database which is the controller
1122if is_service_enabled $DATABASE_BACKENDS && is_service_enabled glance; then
Dean Troyer7903b792012-09-13 17:16:12 -05001123 echo_summary "Configuring Glance"
Dan Smith30d9bf92021-01-19 12:10:52 -08001124 async_runfunc init_glance
Anthony Young70dc5e02011-09-15 16:52:43 -07001125fi
Jesse Andrews75a37652011-09-12 17:09:08 -07001126
Dean Troyer8c032d12013-09-23 13:53:13 -05001127
Mark McClainb05c8762013-07-06 23:29:39 -04001128# Neutron
Anthony Young60df29a2012-03-28 09:40:17 -07001129# -------
Dean Troyer7d28a0e2012-06-27 17:55:52 -05001130
Mark McClainb05c8762013-07-06 23:29:39 -04001131if is_service_enabled neutron; then
1132 echo_summary "Configuring Neutron"
Dean Troyerb9182d62012-11-07 12:31:34 -06001133
Mark McClainb05c8762013-07-06 23:29:39 -04001134 configure_neutron
Dirk Mueller297a50a2018-06-20 11:08:54 +02001135
Dean Troyerdc97cb72015-03-28 08:20:50 -05001136 # Run init_neutron only on the node hosting the Neutron API server
Sean M. Collins2a242512016-05-03 09:03:09 -04001137 if is_service_enabled $DATABASE_BACKENDS && is_service_enabled neutron; then
Dan Smith30d9bf92021-01-19 12:10:52 -08001138 async_runfunc init_neutron
Salvatore Orlandodd649882013-08-05 08:56:17 -07001139 fi
Dan Wendlandt0007f3a2012-05-18 13:37:47 -07001140fi
1141
Stephen Finucane4b8cba72019-05-21 14:17:11 +01001142
Jesse Andrewsd74257d2011-09-13 01:24:50 -07001143# Nova
1144# ----
Dean Troyerbd13b702012-02-13 11:22:36 -06001145
Stephen Finucane4b8cba72019-05-21 14:17:11 +01001146if is_service_enabled q-dhcp; then
Anthony Young55458452011-12-17 00:21:49 +00001147 # Delete traces of nova networks from prior runs
Davanum Srinivasd71d6e72013-01-28 19:15:57 -05001148 # Do not kill any dnsmasq instance spawned by NetworkManager
1149 netman_pid=$(pidof NetworkManager || true)
1150 if [ -z "$netman_pid" ]; then
1151 sudo killall dnsmasq || true
1152 else
1153 sudo ps h -o pid,ppid -C dnsmasq | grep -v $netman_pid | awk '{print $1}' | sudo xargs kill || true
1154 fi
1155
Anthony Young55458452011-12-17 00:21:49 +00001156 clean_iptables
Christian Berendt7a7fb492014-04-07 13:31:07 +00001157
Dean Troyer1a6d4492013-06-03 16:47:36 -05001158 # Force IP forwarding on, just in case
Dean Troyer0b31e862012-03-07 16:47:56 -06001159 sudo sysctl -w net.ipv4.ip_forward=1
Anthony Young70dc5e02011-09-15 16:52:43 -07001160fi
Jesse Andrews75a37652011-09-12 17:09:08 -07001161
Dean Troyer7d28a0e2012-06-27 17:55:52 -05001162
Chmouel Boudjnah28fa4e82011-11-01 12:30:55 +01001163# Storage Service
Dean Troyer7d28a0e2012-06-27 17:55:52 -05001164# ---------------
1165
Sean Dague8b416ae2016-03-25 08:58:54 -04001166if is_service_enabled swift; then
Dean Troyer7903b792012-09-13 17:16:12 -05001167 echo_summary "Configuring Swift"
Dan Smith30d9bf92021-01-19 12:10:52 -08001168 async_runfunc init_swift
Chmouel Boudjnah28fa4e82011-11-01 12:30:55 +01001169fi
1170
Dean Troyerdf0972c2012-03-07 17:31:03 -06001171
Anthony Youngacff87a2011-10-20 10:12:58 -07001172# Volume Service
1173# --------------
1174
Dean Troyer67787e62012-05-02 11:48:15 -05001175if is_service_enabled cinder; then
Dean Troyer7903b792012-09-13 17:16:12 -05001176 echo_summary "Configuring Cinder"
Dan Smith30d9bf92021-01-19 12:10:52 -08001177 async_runfunc init_cinder
Anthony Youngacff87a2011-10-20 10:12:58 -07001178fi
1179
Chris Dente8bad5c2018-04-25 13:01:03 +01001180# Placement Service
1181# ---------------
1182
1183if is_service_enabled placement; then
1184 echo_summary "Configuring placement"
Dan Smith30d9bf92021-01-19 12:10:52 -08001185 async_runfunc init_placement
Chris Dente8bad5c2018-04-25 13:01:03 +01001186fi
Dean Troyer2aa2a892013-08-04 19:53:19 -05001187
Dan Smith30d9bf92021-01-19 12:10:52 -08001188# Wait for neutron and placement before starting nova
1189async_wait init_neutron
1190async_wait init_placement
1191async_wait init_glance
1192async_wait init_swift
1193async_wait init_cinder
1194
Dean Troyer2aa2a892013-08-04 19:53:19 -05001195# Compute Service
1196# ---------------
1197
Dean Troyerbf67c192012-09-21 15:09:37 -05001198if is_service_enabled nova; then
1199 echo_summary "Configuring Nova"
1200 init_nova
Jesse Andrewsd1879c52011-09-16 16:28:13 -07001201
Dean Troyer86a79692012-10-22 15:24:46 -05001202 # Additional Nova configuration that is dependent on other services
Stephen Finucane4b8cba72019-05-21 14:17:11 +01001203 # TODO(stephenfin): Is it possible for neutron to *not* be enabled now? If
1204 # not, remove the if here
Mark McClainb05c8762013-07-06 23:29:39 -04001205 if is_service_enabled neutron; then
Dan Smith30d9bf92021-01-19 12:10:52 -08001206 async_runfunc configure_neutron_nova
Brad Hall1bfa3d52011-10-27 18:18:20 -07001207 fi
Anthony Youngb62b4ca2011-10-26 22:29:08 -07001208fi
1209
Dean Troyerdc97cb72015-03-28 08:20:50 -05001210
Dean Troyercdf3d762013-10-15 09:42:43 -05001211# Extras Configuration
1212# ====================
1213
1214# Phase: post-config
Sean Dague2c65e712014-12-18 09:44:56 -05001215run_phase stack post-config
Dean Troyercdf3d762013-10-15 09:42:43 -05001216
1217
Dean Troyer893e6632013-09-13 15:05:51 -05001218# Local Configuration
1219# ===================
1220
Dean Troyerdc97cb72015-03-28 08:20:50 -05001221# Apply configuration from ``local.conf`` if it exists for layer 2 services
Dean Troyer893e6632013-09-13 15:05:51 -05001222# Phase: post-config
1223merge_config_group $TOP_DIR/local.conf post-config
1224
1225
Jesse Andrewsd74257d2011-09-13 01:24:50 -07001226# Launch Services
1227# ===============
Jesse Andrews30f68e92011-09-13 00:59:54 -07001228
Jesse Andrewsdfcd2002011-09-13 13:17:22 -07001229# Only run the services specified in ``ENABLED_SERVICES``
1230
Attila Fazekasece6a332012-11-29 14:19:41 +01001231# Launch Swift Services
Sean Dague8b416ae2016-03-25 08:58:54 -04001232if is_service_enabled swift; then
Attila Fazekasece6a332012-11-29 14:19:41 +01001233 echo_summary "Starting Swift"
1234 start_swift
1235fi
1236
Lee Yarwoodda6de102018-01-22 11:42:01 +00001237# NOTE(lyarwood): By default use a single hardcoded fixed_key across devstack
1238# deployments. This ensures the keys match across nova and cinder across all
1239# hosts.
1240FIXED_KEY=${FIXED_KEY:-bae3516cc1c0eb18b05440eba8012a4a880a2ee04d584a9c1579445e675b12defdc716ec}
Lee Yarwoodda6de102018-01-22 11:42:01 +00001241if is_service_enabled cinder; then
1242 iniset $CINDER_CONF key_manager fixed_key "$FIXED_KEY"
Kaitlin Farrdef4c142014-01-06 08:52:49 -05001243fi
1244
Dan Smith30d9bf92021-01-19 12:10:52 -08001245async_wait configure_neutron_nova
1246
Clark Boylan06b73522021-04-29 11:46:35 -07001247# NOTE(clarkb): This must come after async_wait configure_neutron_nova because
1248# configure_neutron_nova modifies $NOVA_CONF and $NOVA_CPU_CONF as well. If
1249# we don't wait then these two ini updates race either other and can result
1250# in unexpected configs.
1251if is_service_enabled nova; then
1252 iniset $NOVA_CONF key_manager fixed_key "$FIXED_KEY"
1253 iniset $NOVA_CPU_CONF key_manager fixed_key "$FIXED_KEY"
1254fi
1255
Dean Troyer7d28a0e2012-06-27 17:55:52 -05001256# Launch the nova-api and wait for it to answer before continuing
Chmouel Boudjnaha6651e92012-02-16 10:16:52 +00001257if is_service_enabled n-api; then
Dean Troyer7903b792012-09-13 17:16:12 -05001258 echo_summary "Starting Nova API"
Dean Troyer3a3a2ba2012-12-11 15:26:24 -06001259 start_nova_api
Anthony Youngd000b222011-09-19 14:46:53 -07001260fi
Brad Hall1bfa3d52011-10-27 18:18:20 -07001261
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +01001262if is_service_enabled ovn-controller ovn-controller-vtep; then
1263 echo_summary "Starting OVN services"
1264 start_ovn_services
1265fi
1266
Sean M. Collins2a242512016-05-03 09:03:09 -04001267if is_service_enabled neutron-api; then
1268 echo_summary "Starting Neutron"
1269 start_neutron_api
Sean M. Collins2a242512016-05-03 09:03:09 -04001270elif is_service_enabled q-svc; then
Mark McClainb05c8762013-07-06 23:29:39 -04001271 echo_summary "Starting Neutron"
YAMAMOTO Takashia1875b12017-02-23 05:44:22 +09001272 configure_neutron_after_post_config
Mark McClainb05c8762013-07-06 23:29:39 -04001273 start_neutron_service_and_check
Brad Hall1bfa3d52011-10-27 18:18:20 -07001274fi
1275
Chris Dent7a74c2a2017-06-05 16:06:06 +00001276# Start placement before any of the service that are likely to want
1277# to use it to manage resource providers.
1278if is_service_enabled placement; then
1279 echo_summary "Starting Placement"
1280 start_placement
1281fi
1282
Mark McClainb05c8762013-07-06 23:29:39 -04001283if is_service_enabled neutron; then
Sean M. Collins2a242512016-05-03 09:03:09 -04001284 start_neutron
Akihiro MOTOKI66afb472012-12-21 15:34:13 +09001285fi
Salvatore Orlando6fbb28d2013-12-22 07:59:37 -08001286# Once neutron agents are started setup initial network elements
YAMAMOTO Takashi07edde12016-10-19 19:21:00 +00001287if is_service_enabled q-svc && [[ "$NEUTRON_CREATE_INITIAL_NETWORKS" == "True" ]]; then
1288 echo_summary "Creating initial neutron network elements"
Jens Harbottf8755bd2018-05-16 14:40:01 +00001289 # Here's where plugins can wire up their own networks instead
1290 # of the code in lib/neutron_plugins/services/l3
1291 if type -p neutron_plugin_create_initial_networks > /dev/null; then
1292 neutron_plugin_create_initial_networks
1293 else
1294 create_neutron_initial_network
1295 fi
1296
YAMAMOTO Takashi07edde12016-10-19 19:21:00 +00001297fi
Sean M. Collins2a242512016-05-03 09:03:09 -04001298
Dean Troyerbf67c192012-09-21 15:09:37 -05001299if is_service_enabled nova; then
1300 echo_summary "Starting Nova"
1301 start_nova
Dan Smith30d9bf92021-01-19 12:10:52 -08001302 async_runfunc create_flavors
Dean Troyerbf67c192012-09-21 15:09:37 -05001303fi
Dean Troyer67787e62012-05-02 11:48:15 -05001304if is_service_enabled cinder; then
Dean Troyer7903b792012-09-13 17:16:12 -05001305 echo_summary "Starting Cinder"
Dean Troyer67787e62012-05-02 11:48:15 -05001306 start_cinder
Dean Troyer09718332014-07-03 10:46:57 -05001307 create_volume_types
Dean Troyer67787e62012-05-02 11:48:15 -05001308fi
Sean Dagueb562e6a2012-11-19 16:00:01 -05001309
Abhishek Kekane057aaa62020-07-29 07:37:16 +00001310# This sleep is required for cinder volume service to become active and
1311# publish capabilities to cinder scheduler before creating the image-volume
1312if [[ "$USE_CINDER_FOR_GLANCE" == "True" ]]; then
1313 sleep 30
1314fi
1315
1316# Launch the Glance services
1317# NOTE (abhishekk): We need to start glance api service only after cinder
1318# service has started as on glance startup glance-api queries cinder for
1319# validating volume_type configured for cinder store of glance.
1320if is_service_enabled glance; then
1321 echo_summary "Starting Glance"
1322 start_glance
1323fi
1324
1325# Install Images
1326# ==============
1327
1328# Upload an image to Glance.
1329#
1330# The default image is CirrOS, a small testing image which lets you login as **root**
1331# CirrOS has a ``cloud-init`` analog supporting login via keypair and sending
1332# scripts as userdata.
1333# See https://help.ubuntu.com/community/CloudInit for more on ``cloud-init``
1334
1335# NOTE(yoctozepto): limited to node hosting the database which is the controller
1336if is_service_enabled $DATABASE_BACKENDS && is_service_enabled glance; then
1337 echo_summary "Uploading images"
1338
1339 for image_url in ${IMAGE_URLS//,/ }; do
1340 upload_image $image_url
1341 done
1342fi
1343
Gregory Thiemonge7befae62021-06-19 13:24:00 +02001344async_wait create_flavors
Dean Troyer7d28a0e2012-06-27 17:55:52 -05001345
Akihiro Motoki43f62c02015-12-15 16:44:41 +09001346if is_service_enabled horizon; then
1347 echo_summary "Starting Horizon"
1348 init_horizon
1349 start_horizon
1350fi
1351
Jamie Lennoxbd24a8d2013-09-20 16:26:42 +10001352
Andrey Pavlov50901422015-09-22 21:20:36 +03001353# Create account rc files
1354# =======================
1355
1356# Creates source able script files for easier user switching.
1357# This step also creates certificates for tenants and users,
1358# which is helpful in image bundle steps.
1359
1360if is_service_enabled nova && is_service_enabled keystone; then
1361 USERRC_PARAMS="-PA --target-dir $TOP_DIR/accrc"
1362
1363 if [ -f $SSL_BUNDLE_FILE ]; then
1364 USERRC_PARAMS="$USERRC_PARAMS --os-cacert $SSL_BUNDLE_FILE"
1365 fi
1366
Andrey Pavlov50901422015-09-22 21:20:36 +03001367 $TOP_DIR/tools/create_userrc.sh $USERRC_PARAMS
1368fi
1369
1370
1371# Save some values we generated for later use
1372save_stackenv
1373
1374
Dean Troyerdc97cb72015-03-28 08:20:50 -05001375# Wrapup configuration
1376# ====================
Dean Troyer893e6632013-09-13 15:05:51 -05001377
Dean Troyerdc97cb72015-03-28 08:20:50 -05001378# local.conf extra
1379# ----------------
1380
1381# Apply configuration from ``local.conf`` if it exists for layer 2 services
Dean Troyer893e6632013-09-13 15:05:51 -05001382# Phase: extra
1383merge_config_group $TOP_DIR/local.conf extra
1384
1385
Dean Troyer768295e2013-01-09 13:42:03 -06001386# Run extras
Dean Troyerdc97cb72015-03-28 08:20:50 -05001387# ----------
Dean Troyer768295e2013-01-09 13:42:03 -06001388
Dean Troyercdf3d762013-10-15 09:42:43 -05001389# Phase: extra
Sean Dague2c65e712014-12-18 09:44:56 -05001390run_phase stack extra
Dean Troyer768295e2013-01-09 13:42:03 -06001391
Ryan Hsufeb28832013-11-07 12:12:35 -08001392
Dean Troyerdc97cb72015-03-28 08:20:50 -05001393# local.conf post-extra
1394# ---------------------
1395
1396# Apply late configuration from ``local.conf`` if it exists for layer 2 services
Ryan Hsufeb28832013-11-07 12:12:35 -08001397# Phase: post-extra
1398merge_config_group $TOP_DIR/local.conf post-extra
1399
Dean Troyer768295e2013-01-09 13:42:03 -06001400
Sean Daguec71973e2015-09-08 07:12:48 -04001401# Sanity checks
1402# =============
1403
Sean Daguec2fe9162017-07-28 11:29:18 +00001404# Check that computes are all ready
1405#
1406# TODO(sdague): there should be some generic phase here.
1407if is_service_enabled n-cpu; then
1408 is_nova_ready
1409fi
1410
jiajun xua9414242012-12-06 16:30:57 +08001411# Check the status of running services
1412service_check
Dean Troyerf5633dd2012-03-28 11:21:40 -05001413
Dan Smith71119b42016-08-15 12:06:55 -07001414# Configure nova cellsv2
1415# ----------------------
1416
1417# Do this late because it requires compute hosts to have started
Matt Riedemannf1660812016-11-01 15:44:06 -04001418if is_service_enabled n-api; then
Sean Dague6d66e642016-12-05 06:28:26 -05001419 if is_service_enabled n-cpu; then
Matt Riedemannf15224c2017-03-02 12:45:47 -05001420 $TOP_DIR/tools/discover_hosts.sh
Sean Dague6d66e642016-12-05 06:28:26 -05001421 else
1422 # Some CI systems like Hyper-V build the control plane on
1423 # Linux, and join in non Linux Computes after setup. This
1424 # allows them to delay the processing until after their whole
1425 # environment is up.
1426 echo_summary "SKIPPING Cell setup because n-cpu is not enabled. You will have to do this manually before you have a working environment."
1427 fi
Matt Riedemann9e3b3bf2018-09-04 16:51:45 -04001428 # Run the nova-status upgrade check command which can also be used
1429 # to verify the base install. Note that this is good enough in a
1430 # single node deployment, but in a multi-node setup it won't verify
1431 # any subnodes - that would have to be driven from whatever tooling
1432 # is deploying the subnodes, e.g. the zuul v3 devstack-multinode job.
1433 $NOVA_BIN_DIR/nova-status --config-file $NOVA_CONF upgrade check
Dan Smith71119b42016-08-15 12:06:55 -07001434fi
1435
Jacky Hu78809042018-02-26 18:36:59 +08001436# Run local script
1437# ----------------
1438
1439# Run ``local.sh`` if it exists to perform user-managed tasks
1440if [[ -x $TOP_DIR/local.sh ]]; then
1441 echo "Running user script $TOP_DIR/local.sh"
1442 $TOP_DIR/local.sh
1443fi
1444
Steve Martinellibbe771a2015-01-20 13:30:33 -05001445# Bash completion
1446# ===============
1447
1448# Prepare bash completion for OSC
Ian Wienand474f5352019-08-08 09:15:11 +10001449# Note we use "command" to avoid the timing wrapper
1450# which isn't relevant here and floods logs
1451command openstack complete \
1452 | sudo tee /etc/bash_completion.d/osc.bash_completion > /dev/null
Steve Martinellibbe771a2015-01-20 13:30:33 -05001453
John Griffith4bf861c2015-03-17 21:07:39 -06001454# If cinder is configured, set global_filter for PV devices
1455if is_service_enabled cinder; then
1456 if is_ubuntu; then
1457 echo_summary "Configuring lvm.conf global device filter"
1458 set_lvm_filter
1459 else
1460 echo_summary "Skip setting lvm filters for non Ubuntu systems"
1461 fi
1462fi
Steve Martinellibbe771a2015-01-20 13:30:33 -05001463
Matthew Treinish655c22c2016-05-02 13:29:10 -04001464# Run test-config
1465# ---------------
1466
1467# Phase: test-config
1468run_phase stack test-config
1469
Sean Dague8bf8c8f2016-12-01 10:24:06 -05001470# Apply late configuration from ``local.conf`` if it exists for layer 2 services
1471# Phase: test-config
1472merge_config_group $TOP_DIR/local.conf test-config
Dean Troyerdc97cb72015-03-28 08:20:50 -05001473
Scott Moserb94f4bf2011-10-07 14:51:07 +00001474# Fin
1475# ===
1476
Dean Troyer471de7a2011-12-27 11:45:55 -06001477set +o xtrace
Scott Moserb94f4bf2011-10-07 14:51:07 +00001478
Dean Troyer7903b792012-09-13 17:16:12 -05001479if [[ -n "$LOGFILE" ]]; then
1480 exec 1>&3
1481 # Force all output to stdout and logs now
Dean Troyerbaa8b422012-09-24 15:02:05 -05001482 exec 1> >( tee -a "${LOGFILE}" ) 2>&1
Dean Troyer7903b792012-09-13 17:16:12 -05001483else
1484 # Force all output to stdout now
1485 exec 1>&3
1486fi
1487
Dan Smith30d9bf92021-01-19 12:10:52 -08001488# Make sure we didn't leak any background tasks
1489async_cleanup
1490
Sean Dague95c33d52015-10-07 11:05:59 -04001491# Dump out the time totals
1492time_totals
Dan Smith30d9bf92021-01-19 12:10:52 -08001493async_print_timing
Dean Troyerdf0972c2012-03-07 17:31:03 -06001494
Jesse Andrews24859062011-09-15 21:28:23 -07001495# Using the cloud
Dean Troyerdc97cb72015-03-28 08:20:50 -05001496# ===============
Jesse Andrews24859062011-09-15 21:28:23 -07001497
Jesse Andrewse19d8842011-11-01 20:06:55 -07001498echo ""
1499echo ""
1500echo ""
Brian Haley180f5eb2015-06-16 13:14:31 -04001501echo "This is your host IP address: $HOST_IP"
1502if [ "$HOST_IPV6" != "" ]; then
1503 echo "This is your host IPv6 address: $HOST_IPV6"
1504fi
Jesse Andrewse19d8842011-11-01 20:06:55 -07001505
Dean Troyerdf0972c2012-03-07 17:31:03 -06001506# If you installed Horizon on this server you should be able
root40a37002011-09-20 18:06:14 +00001507# to access the site using your browser.
Chmouel Boudjnaha6651e92012-02-16 10:16:52 +00001508if is_service_enabled horizon; then
David Lyle7b105c52015-07-27 17:14:32 -06001509 echo "Horizon is now available at http://$SERVICE_HOST$HORIZON_APACHE_ROOT"
Jesse Andrews24859062011-09-15 21:28:23 -07001510fi
1511
Dean Troyerdf0972c2012-03-07 17:31:03 -06001512# If Keystone is present you can point ``nova`` cli to this server
Dean Troyer5ce44cd2015-02-12 22:18:33 -06001513if is_service_enabled keystone; then
Dean Troyerdc97cb72015-03-28 08:20:50 -05001514 echo "Keystone is serving at $KEYSTONE_SERVICE_URI/"
Dean Troyerdf0972c2012-03-07 17:31:03 -06001515 echo "The default users are: admin and demo"
1516 echo "The password: $ADMIN_PASSWORD"
Jesse Andrews24859062011-09-15 21:28:23 -07001517fi
termie523c4052011-09-28 19:49:40 -05001518
Dean Troyerafc29fe2013-02-07 15:56:24 -06001519# Warn that a deprecated feature was used
1520if [[ -n "$DEPRECATED_TEXT" ]]; then
Sean Dague2c0faca2017-06-28 09:13:04 -04001521 echo
1522 echo -e "WARNING: $DEPRECATED_TEXT"
1523 echo
Dean Troyerced65172012-03-02 16:36:16 -06001524fi
1525
Dr. Jens Harbott6808a342020-01-20 15:52:33 +00001526echo
1527echo "Services are running under systemd unit files."
1528echo "For more information see: "
1529echo "https://docs.openstack.org/devstack/latest/systemd.html"
1530echo
Sean Dague8b8441f2017-05-02 06:14:11 -04001531
Ian Wienand07cbc442017-06-30 12:29:19 +10001532# Useful info on current state
1533cat /etc/devstack-version
Sean Dague2c0faca2017-06-28 09:13:04 -04001534echo
1535
Dean Troyer4a43b7b2012-08-28 17:43:40 -05001536# Indicate how long this took to run (bash maintained variable ``SECONDS``)
Dean Troyer7903b792012-09-13 17:16:12 -05001537echo_summary "stack.sh completed in $SECONDS seconds."
Dean Troyer80684552014-03-05 11:50:23 -06001538
Sean Dague2c0faca2017-06-28 09:13:04 -04001539
Dean Troyer80684552014-03-05 11:50:23 -06001540# Restore/close logging file descriptors
1541exec 1>&3
1542exec 2>&3
1543exec 3>&-
1544exec 6>&-