blob: c6d46631146c7ac47aded49f81344b5eab64f1fa [file] [log] [blame]
Sean M. Collins2a242512016-05-03 09:03:09 -04001#!/bin/bash
2# Subnet IP version
3IP_VERSION=${IP_VERSION:-"4+6"}
4# Validate IP_VERSION
5if [[ $IP_VERSION != "4" ]] && [[ $IP_VERSION != "6" ]] && [[ $IP_VERSION != "4+6" ]]; then
6 die $LINENO "IP_VERSION must be either 4, 6, or 4+6"
7fi
8# Specify if the initial private and external networks should be created
9NEUTRON_CREATE_INITIAL_NETWORKS=${NEUTRON_CREATE_INITIAL_NETWORKS:-True}
10
11## Provider Network Information
12PROVIDER_SUBNET_NAME=${PROVIDER_SUBNET_NAME:-"provider_net"}
13IPV6_PROVIDER_SUBNET_NAME=${IPV6_PROVIDER_SUBNET_NAME:-"provider_net_v6"}
14IPV6_PROVIDER_FIXED_RANGE=${IPV6_PROVIDER_FIXED_RANGE:-}
15IPV6_PROVIDER_NETWORK_GATEWAY=${IPV6_PROVIDER_NETWORK_GATEWAY:-}
16
17PUBLIC_BRIDGE=${PUBLIC_BRIDGE:-br-ex}
Ihar Hrachyshka7b5c7dc2016-07-15 20:17:13 +020018PUBLIC_BRIDGE_MTU=${PUBLIC_BRIDGE_MTU:-1500}
Sean M. Collins2a242512016-05-03 09:03:09 -040019
Kevin Benton1554ade2016-07-22 09:40:19 -070020# If Q_ASSIGN_GATEWAY_TO_PUBLIC_BRIDGE=True, assign the gateway IP of the public
21# subnet to the public bridge interface even if Q_USE_PROVIDERNET_FOR_PUBLIC is
22# used.
23Q_ASSIGN_GATEWAY_TO_PUBLIC_BRIDGE=${Q_ASSIGN_GATEWAY_TO_PUBLIC_BRIDGE:-True}
24
YAMAMOTO Takashi1aa43682016-07-21 19:37:04 +090025# The name of the default router
26Q_ROUTER_NAME=${Q_ROUTER_NAME:-router1}
27
Sean M. Collins2a242512016-05-03 09:03:09 -040028# If Q_USE_PUBLIC_VETH=True, create and use a veth pair instead of
29# PUBLIC_BRIDGE. This is intended to be used with
30# Q_USE_PROVIDERNET_FOR_PUBLIC=True.
31Q_USE_PUBLIC_VETH=${Q_USE_PUBLIC_VETH:-False}
32Q_PUBLIC_VETH_EX=${Q_PUBLIC_VETH_EX:-veth-pub-ex}
33Q_PUBLIC_VETH_INT=${Q_PUBLIC_VETH_INT:-veth-pub-int}
34
vsaienkod8942212016-05-13 12:51:30 +030035# The next variable is configured by plugin
Sean M. Collins2a242512016-05-03 09:03:09 -040036# e.g. _configure_neutron_l3_agent or lib/neutron_plugins/*
37#
Sean M. Collins2a242512016-05-03 09:03:09 -040038# L3 routers exist per tenant
39Q_L3_ROUTER_PER_TENANT=${Q_L3_ROUTER_PER_TENANT:-True}
40
41
Tim Swansonbb7d2f22017-12-16 17:14:10 -050042# Use providernet for public network
Sean M. Collins2a242512016-05-03 09:03:09 -040043#
Tim Swansonbb7d2f22017-12-16 17:14:10 -050044# If Q_USE_PROVIDERNET_FOR_PUBLIC=True, use a provider network
Sean M. Collins2a242512016-05-03 09:03:09 -040045# for external interface of neutron l3-agent. In that case,
46# PUBLIC_PHYSICAL_NETWORK specifies provider:physical_network value
47# used for the network. In case of ofagent, you should add the
48# corresponding entry to your OFAGENT_PHYSICAL_INTERFACE_MAPPINGS.
49# For openvswitch agent, you should add the corresponding entry to
Harald Jensås16ac21f2023-08-31 15:06:52 +020050# your OVS_BRIDGE_MAPPINGS and for OVN add the corresponding entry
51# to your OVN_BRIDGE_MAPPINGS.
Sean M. Collins2a242512016-05-03 09:03:09 -040052#
53# eg. (ofagent)
54# Q_USE_PROVIDERNET_FOR_PUBLIC=True
55# Q_USE_PUBLIC_VETH=True
56# PUBLIC_PHYSICAL_NETWORK=public
57# OFAGENT_PHYSICAL_INTERFACE_MAPPINGS=public:veth-pub-int
58#
59# eg. (openvswitch agent)
60# Q_USE_PROVIDERNET_FOR_PUBLIC=True
61# PUBLIC_PHYSICAL_NETWORK=public
62# OVS_BRIDGE_MAPPINGS=public:br-ex
Tim Swansonbb7d2f22017-12-16 17:14:10 -050063#
Harald Jensås16ac21f2023-08-31 15:06:52 +020064# eg. (ovn agent)
65# Q_USER_PROVIDERNET_FOR_PUBLIC=True
66# PUBLIC_PHYSICAL_NETWORK=public
67# OVN_BRIDGE_MAPPINGS=public:br-ex
68#
Tim Swansonbb7d2f22017-12-16 17:14:10 -050069# The provider-network-type defaults to flat, however, the values
70# PUBLIC_PROVIDERNET_TYPE and PUBLIC_PROVIDERNET_SEGMENTATION_ID could
71# be set to specify the parameters for an alternate network type.
Kevin Benton1554ade2016-07-22 09:40:19 -070072Q_USE_PROVIDERNET_FOR_PUBLIC=${Q_USE_PROVIDERNET_FOR_PUBLIC:-True}
Sean M. Collins2a242512016-05-03 09:03:09 -040073PUBLIC_PHYSICAL_NETWORK=${PUBLIC_PHYSICAL_NETWORK:-public}
74
75# Generate 40-bit IPv6 Global ID to comply with RFC 4193
76IPV6_GLOBAL_ID=`uuidgen | sed s/-//g | cut -c 23- | sed -e "s/\(..\)\(....\)\(....\)/\1:\2:\3/"`
77
78# IPv6 gateway and subnet defaults, in case they are not customized in localrc
79IPV6_RA_MODE=${IPV6_RA_MODE:-slaac}
80IPV6_ADDRESS_MODE=${IPV6_ADDRESS_MODE:-slaac}
81IPV6_PUBLIC_SUBNET_NAME=${IPV6_PUBLIC_SUBNET_NAME:-ipv6-public-subnet}
82IPV6_PRIVATE_SUBNET_NAME=${IPV6_PRIVATE_SUBNET_NAME:-ipv6-private-subnet}
Kevin Benton4bfbc292016-11-15 17:26:05 -080083IPV6_ADDRS_SAFE_TO_USE=${IPV6_ADDRS_SAFE_TO_USE:-fd$IPV6_GLOBAL_ID::/56}
84# if we got larger than a /64 safe to use, we only use the first /64 to
85# avoid side effects outlined in rfc7421
Clark Boylana5afa7d2016-11-18 12:32:19 -080086FIXED_RANGE_V6=${FIXED_RANGE_V6:-$(echo $IPV6_ADDRS_SAFE_TO_USE | awk -F '/' '{ print $1"/"($2>63 ? $2 : 64) }')}
Brian Haley31813e92016-08-22 15:39:22 -040087IPV6_PRIVATE_NETWORK_GATEWAY=${IPV6_PRIVATE_NETWORK_GATEWAY:-}
Sean M. Collins2a242512016-05-03 09:03:09 -040088IPV6_PUBLIC_RANGE=${IPV6_PUBLIC_RANGE:-2001:db8::/64}
89IPV6_PUBLIC_NETWORK_GATEWAY=${IPV6_PUBLIC_NETWORK_GATEWAY:-2001:db8::2}
90IPV6_ROUTER_GW_IP=${IPV6_ROUTER_GW_IP:-2001:db8::1}
91
92# Gateway and subnet defaults, in case they are not customized in localrc
Brian Haley31813e92016-08-22 15:39:22 -040093NETWORK_GATEWAY=${NETWORK_GATEWAY:-}
94PUBLIC_NETWORK_GATEWAY=${PUBLIC_NETWORK_GATEWAY:-}
Sean M. Collins2a242512016-05-03 09:03:09 -040095PRIVATE_SUBNET_NAME=${PRIVATE_SUBNET_NAME:-"private-subnet"}
96PUBLIC_SUBNET_NAME=${PUBLIC_SUBNET_NAME:-"public-subnet"}
97
98# Subnetpool defaults
rajinirc58a1552016-09-27 17:14:59 -050099USE_SUBNETPOOL=${USE_SUBNETPOOL:-True}
Jens Rosenboomf069acf2017-02-24 16:25:59 +0100100SUBNETPOOL_NAME_V4=${SUBNETPOOL_NAME:-"shared-default-subnetpool-v4"}
101SUBNETPOOL_NAME_V6=${SUBNETPOOL_NAME:-"shared-default-subnetpool-v6"}
Sean M. Collins2a242512016-05-03 09:03:09 -0400102
Kevin Benton4bfbc292016-11-15 17:26:05 -0800103SUBNETPOOL_PREFIX_V4=${SUBNETPOOL_PREFIX_V4:-$IPV4_ADDRS_SAFE_TO_USE}
104SUBNETPOOL_PREFIX_V6=${SUBNETPOOL_PREFIX_V6:-$IPV6_ADDRS_SAFE_TO_USE}
Sean M. Collins2a242512016-05-03 09:03:09 -0400105
Kevin Benton4bfbc292016-11-15 17:26:05 -0800106SUBNETPOOL_SIZE_V4=${SUBNETPOOL_SIZE_V4:-26}
Sean M. Collins2a242512016-05-03 09:03:09 -0400107SUBNETPOOL_SIZE_V6=${SUBNETPOOL_SIZE_V6:-64}
108
Henry Gessau734f1442016-09-17 19:28:53 -0400109default_v4_route_devs=$(ip -4 route | grep ^default | awk '{print $5}')
Henry Gessau734f1442016-09-17 19:28:53 -0400110
aojeagarcia866efef2018-09-28 10:43:46 +0200111default_v6_route_devs=$(ip -6 route list match default table all | grep via | awk '{print $5}')
Monty Taylorc12d1d92016-08-23 19:07:57 -0500112
Sean M. Collins2a242512016-05-03 09:03:09 -0400113function _determine_config_l3 {
Angus Leesa1c70f22016-05-31 14:43:14 +1000114 local opts="--config-file $NEUTRON_CONF --config-file $Q_L3_CONF_FILE"
Sean M. Collins2a242512016-05-03 09:03:09 -0400115 echo "$opts"
116}
117
118function _configure_neutron_l3_agent {
Sean M. Collins2a242512016-05-03 09:03:09 -0400119
120 cp $NEUTRON_DIR/etc/l3_agent.ini.sample $Q_L3_CONF_FILE
121
Sean M. Collins2a242512016-05-03 09:03:09 -0400122 iniset $Q_L3_CONF_FILE DEFAULT debug $ENABLE_DEBUG_LOG_LEVEL
Sean M. Collinsa2ed0552016-05-11 15:35:10 -0400123 iniset $Q_L3_CONF_FILE AGENT root_helper "$Q_RR_COMMAND"
Sean M. Collins2a242512016-05-03 09:03:09 -0400124 if [[ "$Q_USE_ROOTWRAP_DAEMON" == "True" ]]; then
Sean M. Collinsa2ed0552016-05-11 15:35:10 -0400125 iniset $Q_L3_CONF_FILE AGENT root_helper_daemon "$Q_RR_DAEMON_COMMAND"
Sean M. Collins2a242512016-05-03 09:03:09 -0400126 fi
127
128 _neutron_setup_interface_driver $Q_L3_CONF_FILE
129
Stephen Finucane24e29f22016-06-15 14:31:51 +0100130 neutron_plugin_configure_l3_agent $Q_L3_CONF_FILE
Sean M. Collins2a242512016-05-03 09:03:09 -0400131
Slawek Kaplonskib1a89eb2021-08-26 21:42:32 +0200132 _configure_public_network_connectivity
Sean M. Collins2a242512016-05-03 09:03:09 -0400133}
134
135# Explicitly set router id in l3 agent configuration
136function _neutron_set_router_id {
137 if [[ "$Q_L3_ROUTER_PER_TENANT" == "False" ]]; then
138 iniset $Q_L3_CONF_FILE DEFAULT router_id $ROUTER_ID
139 fi
140}
141
142# Get ext_gw_interface depending on value of Q_USE_PUBLIC_VETH
143function _neutron_get_ext_gw_interface {
144 if [[ "$Q_USE_PUBLIC_VETH" == "True" ]]; then
145 echo $Q_PUBLIC_VETH_EX
146 else
147 # Disable in-band as we are going to use local port
148 # to communicate with VMs
149 sudo ovs-vsctl set Bridge $PUBLIC_BRIDGE \
150 other_config:disable-in-band=true
151 echo $PUBLIC_BRIDGE
152 fi
153}
154
155function create_neutron_initial_network {
Sean M. Collins2a242512016-05-03 09:03:09 -0400156 # Allow drivers that need to create an initial network to do so here
157 if type -p neutron_plugin_create_initial_network_profile > /dev/null; then
158 neutron_plugin_create_initial_network_profile $PHYSICAL_NETWORK
159 fi
160
Matt Van Dijkd7a3f5c2016-08-16 15:46:58 +0000161 if is_networking_extension_supported "auto-allocated-topology"; then
rajinirc58a1552016-09-27 17:14:59 -0500162 if [[ "$USE_SUBNETPOOL" == "True" ]]; then
163 if [[ "$IP_VERSION" =~ 4.* ]]; then
Slawek Kaplonski14a0c092022-01-28 09:44:40 +0100164 SUBNETPOOL_V4_ID=$(openstack --os-cloud devstack-admin --os-region "$REGION_NAME" subnet pool create $SUBNETPOOL_NAME_V4 --default-prefix-length $SUBNETPOOL_SIZE_V4 --pool-prefix $SUBNETPOOL_PREFIX_V4 --share --default -f value -c id)
rajinirc58a1552016-09-27 17:14:59 -0500165 fi
166 if [[ "$IP_VERSION" =~ .*6 ]]; then
Slawek Kaplonski14a0c092022-01-28 09:44:40 +0100167 SUBNETPOOL_V6_ID=$(openstack --os-cloud devstack-admin --os-region "$REGION_NAME" subnet pool create $SUBNETPOOL_NAME_V6 --default-prefix-length $SUBNETPOOL_SIZE_V6 --pool-prefix $SUBNETPOOL_PREFIX_V6 --share --default -f value -c id)
rajinirc58a1552016-09-27 17:14:59 -0500168 fi
Matt Van Dijkd7a3f5c2016-08-16 15:46:58 +0000169 fi
170 fi
171
Sean M. Collins2a242512016-05-03 09:03:09 -0400172 if is_provider_network; then
173 die_if_not_set $LINENO PHYSICAL_NETWORK "You must specify the PHYSICAL_NETWORK"
174 die_if_not_set $LINENO PROVIDER_NETWORK_TYPE "You must specify the PROVIDER_NETWORK_TYPE"
Eliad Cohenfdfc1442022-08-16 13:00:45 -0400175 NET_ID=$(openstack --os-cloud devstack-admin-demo --os-region "$REGION_NAME" network create $PHYSICAL_NETWORK --provider-network-type $PROVIDER_NETWORK_TYPE --provider-physical-network "$PHYSICAL_NETWORK" ${SEGMENTATION_ID:+--provider-segment $SEGMENTATION_ID} --share -f value -c id)
Slawek Kaplonskicebd00a2022-02-17 11:57:30 +0100176 die_if_not_set $LINENO NET_ID "Failure creating NET_ID for $PHYSICAL_NETWORK"
Sean M. Collins2a242512016-05-03 09:03:09 -0400177
178 if [[ "$IP_VERSION" =~ 4.* ]]; then
Matt Van Dijkd7a3f5c2016-08-16 15:46:58 +0000179 if [ -z $SUBNETPOOL_V4_ID ]; then
180 fixed_range_v4=$FIXED_RANGE
181 fi
Eliad Cohenfdfc1442022-08-16 13:00:45 -0400182 SUBNET_ID=$(openstack --os-cloud devstack --os-region "$REGION_NAME" subnet create --ip-version 4 ${ALLOCATION_POOL:+--allocation-pool $ALLOCATION_POOL} $PROVIDER_SUBNET_NAME --gateway $NETWORK_GATEWAY ${SUBNETPOOL_V4_ID:+--subnet-pool $SUBNETPOOL_V4_ID} --network $NET_ID ${fixed_range_v4:+--subnet-range $fixed_range_v4} -f value -c id)
Slawek Kaplonskicebd00a2022-02-17 11:57:30 +0100183 die_if_not_set $LINENO SUBNET_ID "Failure creating SUBNET_ID for $PROVIDER_SUBNET_NAME"
Sean M. Collins2a242512016-05-03 09:03:09 -0400184 fi
185
Sean M. Collinse34ec992016-06-07 12:36:50 -0400186 if [[ "$IP_VERSION" =~ .*6 ]]; then
Jan Stodt05dc1aa2016-08-25 15:46:02 +0200187 die_if_not_set $LINENO IPV6_PROVIDER_FIXED_RANGE "IPV6_PROVIDER_FIXED_RANGE has not been set, but Q_USE_PROVIDER_NETWORKING is true and IP_VERSION includes 6"
188 die_if_not_set $LINENO IPV6_PROVIDER_NETWORK_GATEWAY "IPV6_PROVIDER_NETWORK_GATEWAY has not been set, but Q_USE_PROVIDER_NETWORKING is true and IP_VERSION includes 6"
Matt Van Dijkd7a3f5c2016-08-16 15:46:58 +0000189 if [ -z $SUBNETPOOL_V6_ID ]; then
190 fixed_range_v6=$IPV6_PROVIDER_FIXED_RANGE
191 fi
Eliad Cohenfdfc1442022-08-16 13:00:45 -0400192 IPV6_SUBNET_ID=$(openstack --os-cloud devstack --os-region "$REGION_NAME" subnet create --ip-version 6 --gateway $IPV6_PROVIDER_NETWORK_GATEWAY $IPV6_PROVIDER_SUBNET_NAME ${SUBNETPOOL_V6_ID:+--subnet-pool $SUBNETPOOL_V6_ID} --network $NET_ID ${fixed_range_v6:+--subnet-range $fixed_range_v6} -f value -c id)
Slawek Kaplonskicebd00a2022-02-17 11:57:30 +0100193 die_if_not_set $LINENO IPV6_SUBNET_ID "Failure creating IPV6_SUBNET_ID for $IPV6_PROVIDER_SUBNET_NAME"
Sean M. Collins2a242512016-05-03 09:03:09 -0400194 fi
195
196 if [[ $Q_AGENT == "openvswitch" ]]; then
197 sudo ip link set $OVS_PHYSICAL_BRIDGE up
198 sudo ip link set br-int up
199 sudo ip link set $PUBLIC_INTERFACE up
200 fi
201 else
Eliad Cohenfdfc1442022-08-16 13:00:45 -0400202 NET_ID=$(openstack --os-cloud devstack --os-region "$REGION_NAME" network create "$PRIVATE_NETWORK_NAME" -f value -c id)
Slawek Kaplonskicebd00a2022-02-17 11:57:30 +0100203 die_if_not_set $LINENO NET_ID "Failure creating NET_ID for $PRIVATE_NETWORK_NAME"
Sean M. Collins2a242512016-05-03 09:03:09 -0400204
205 if [[ "$IP_VERSION" =~ 4.* ]]; then
206 # Create IPv4 private subnet
Slawek Kaplonskicebd00a2022-02-17 11:57:30 +0100207 SUBNET_ID=$(_neutron_create_private_subnet_v4)
Sean M. Collins2a242512016-05-03 09:03:09 -0400208 fi
209
210 if [[ "$IP_VERSION" =~ .*6 ]]; then
211 # Create IPv6 private subnet
Slawek Kaplonskicebd00a2022-02-17 11:57:30 +0100212 IPV6_SUBNET_ID=$(_neutron_create_private_subnet_v6)
Sean M. Collins2a242512016-05-03 09:03:09 -0400213 fi
214 fi
215
Sean M. Collinsc35110e2016-05-18 10:38:51 -0400216 if is_networking_extension_supported "router" && is_networking_extension_supported "external-net"; then
Sean M. Collins2a242512016-05-03 09:03:09 -0400217 # Create a router, and add the private subnet as one of its interfaces
218 if [[ "$Q_L3_ROUTER_PER_TENANT" == "True" ]]; then
219 # create a tenant-owned router.
Eliad Cohenfdfc1442022-08-16 13:00:45 -0400220 ROUTER_ID=$(openstack --os-cloud devstack --os-region "$REGION_NAME" router create $Q_ROUTER_NAME -f value -c id)
Slawek Kaplonskicebd00a2022-02-17 11:57:30 +0100221 die_if_not_set $LINENO ROUTER_ID "Failure creating router $Q_ROUTER_NAME"
Sean M. Collins2a242512016-05-03 09:03:09 -0400222 else
223 # Plugin only supports creating a single router, which should be admin owned.
Eliad Cohenfdfc1442022-08-16 13:00:45 -0400224 ROUTER_ID=$(openstack --os-cloud devstack-admin --os-region "$REGION_NAME" router create $Q_ROUTER_NAME -f value -c id)
Slawek Kaplonskicebd00a2022-02-17 11:57:30 +0100225 die_if_not_set $LINENO ROUTER_ID "Failure creating router $Q_ROUTER_NAME"
Sean M. Collins2a242512016-05-03 09:03:09 -0400226 fi
227
Armando Migliaccio4f11ff32016-10-27 06:15:23 -0700228 EXTERNAL_NETWORK_FLAGS="--external"
Matt Van Dijkd7a3f5c2016-08-16 15:46:58 +0000229 if is_networking_extension_supported "auto-allocated-topology"; then
Armando Migliaccio4f11ff32016-10-27 06:15:23 -0700230 EXTERNAL_NETWORK_FLAGS="$EXTERNAL_NETWORK_FLAGS --default"
Sean M. Collins2a242512016-05-03 09:03:09 -0400231 fi
232 # Create an external network, and a subnet. Configure the external network as router gw
233 if [ "$Q_USE_PROVIDERNET_FOR_PUBLIC" = "True" ]; then
Eliad Cohenfdfc1442022-08-16 13:00:45 -0400234 EXT_NET_ID=$(openstack --os-cloud devstack-admin --os-region "$REGION_NAME" network create "$PUBLIC_NETWORK_NAME" $EXTERNAL_NETWORK_FLAGS --provider-network-type ${PUBLIC_PROVIDERNET_TYPE:-flat} ${PUBLIC_PROVIDERNET_SEGMENTATION_ID:+--provider-segment $PUBLIC_PROVIDERNET_SEGMENTATION_ID} --provider-physical-network ${PUBLIC_PHYSICAL_NETWORK} -f value -c id)
Sean M. Collins2a242512016-05-03 09:03:09 -0400235 else
Eliad Cohenfdfc1442022-08-16 13:00:45 -0400236 EXT_NET_ID=$(openstack --os-cloud devstack-admin --os-region "$REGION_NAME" network create "$PUBLIC_NETWORK_NAME" $EXTERNAL_NETWORK_FLAGS -f value -c id)
Sean M. Collins2a242512016-05-03 09:03:09 -0400237 fi
238 die_if_not_set $LINENO EXT_NET_ID "Failure creating EXT_NET_ID for $PUBLIC_NETWORK_NAME"
239
240 if [[ "$IP_VERSION" =~ 4.* ]]; then
241 # Configure router for IPv4 public access
242 _neutron_configure_router_v4
243 fi
244
245 if [[ "$IP_VERSION" =~ .*6 ]]; then
246 # Configure router for IPv6 public access
247 _neutron_configure_router_v6
248 fi
249 fi
250}
251
252# Create private IPv4 subnet
253function _neutron_create_private_subnet_v4 {
Matt Van Dijkd7a3f5c2016-08-16 15:46:58 +0000254 if [ -z $SUBNETPOOL_V4_ID ]; then
255 fixed_range_v4=$FIXED_RANGE
256 fi
Slawek Kaplonski14a0c092022-01-28 09:44:40 +0100257 local subnet_params="--ip-version 4 "
Brian Haley31813e92016-08-22 15:39:22 -0400258 if [[ -n "$NETWORK_GATEWAY" ]]; then
259 subnet_params+="--gateway $NETWORK_GATEWAY "
260 fi
Slawek Kaplonski24b65ad2021-06-22 15:31:46 +0200261
Armando Migliaccio4f11ff32016-10-27 06:15:23 -0700262 subnet_params+="${SUBNETPOOL_V4_ID:+--subnet-pool $SUBNETPOOL_V4_ID} "
263 subnet_params+="${fixed_range_v4:+--subnet-range $fixed_range_v4} "
264 subnet_params+="--network $NET_ID $PRIVATE_SUBNET_NAME"
Sean M. Collins2a242512016-05-03 09:03:09 -0400265 local subnet_id
Eliad Cohenfdfc1442022-08-16 13:00:45 -0400266 subnet_id=$(openstack --os-cloud devstack-admin-demo --os-region "$REGION_NAME" subnet create $subnet_params -f value -c id)
Slawek Kaplonskicebd00a2022-02-17 11:57:30 +0100267 die_if_not_set $LINENO subnet_id "Failure creating private IPv4 subnet"
Sean M. Collins2a242512016-05-03 09:03:09 -0400268 echo $subnet_id
269}
270
271# Create private IPv6 subnet
272function _neutron_create_private_subnet_v6 {
Sean M. Collins2a242512016-05-03 09:03:09 -0400273 die_if_not_set $LINENO IPV6_RA_MODE "IPV6 RA Mode not set"
274 die_if_not_set $LINENO IPV6_ADDRESS_MODE "IPV6 Address Mode not set"
275 local ipv6_modes="--ipv6-ra-mode $IPV6_RA_MODE --ipv6-address-mode $IPV6_ADDRESS_MODE"
Matt Van Dijkd7a3f5c2016-08-16 15:46:58 +0000276 if [ -z $SUBNETPOOL_V6_ID ]; then
277 fixed_range_v6=$FIXED_RANGE_V6
278 fi
Slawek Kaplonski14a0c092022-01-28 09:44:40 +0100279 local subnet_params="--ip-version 6 "
Brian Haley31813e92016-08-22 15:39:22 -0400280 if [[ -n "$IPV6_PRIVATE_NETWORK_GATEWAY" ]]; then
281 subnet_params+="--gateway $IPV6_PRIVATE_NETWORK_GATEWAY "
282 fi
Armando Migliaccio4f11ff32016-10-27 06:15:23 -0700283 subnet_params+="${SUBNETPOOL_V6_ID:+--subnet-pool $SUBNETPOOL_V6_ID} "
Brian Haley1ec93a82017-01-12 16:11:11 -0500284 subnet_params+="${fixed_range_v6:+--subnet-range $fixed_range_v6} "
285 subnet_params+="$ipv6_modes --network $NET_ID $IPV6_PRIVATE_SUBNET_NAME "
Sean M. Collins2a242512016-05-03 09:03:09 -0400286 local ipv6_subnet_id
Eliad Cohenfdfc1442022-08-16 13:00:45 -0400287 ipv6_subnet_id=$(openstack --os-cloud devstack-admin-demo --os-region "$REGION_NAME" subnet create $subnet_params -f value -c id)
Slawek Kaplonskicebd00a2022-02-17 11:57:30 +0100288 die_if_not_set $LINENO ipv6_subnet_id "Failure creating private IPv6 subnet"
Sean M. Collins2a242512016-05-03 09:03:09 -0400289 echo $ipv6_subnet_id
290}
291
292# Create public IPv4 subnet
293function _neutron_create_public_subnet_v4 {
Slawek Kaplonski14a0c092022-01-28 09:44:40 +0100294 local subnet_params="--ip-version 4 "
Sean M. Collins2a242512016-05-03 09:03:09 -0400295 subnet_params+="${Q_FLOATING_ALLOCATION_POOL:+--allocation-pool $Q_FLOATING_ALLOCATION_POOL} "
Brian Haley31813e92016-08-22 15:39:22 -0400296 if [[ -n "$PUBLIC_NETWORK_GATEWAY" ]]; then
297 subnet_params+="--gateway $PUBLIC_NETWORK_GATEWAY "
298 fi
Armando Migliaccio4f11ff32016-10-27 06:15:23 -0700299 subnet_params+="--network $EXT_NET_ID --subnet-range $FLOATING_RANGE --no-dhcp "
300 subnet_params+="$PUBLIC_SUBNET_NAME"
Sean M. Collins2a242512016-05-03 09:03:09 -0400301 local id_and_ext_gw_ip
Slawek Kaplonski14a0c092022-01-28 09:44:40 +0100302 id_and_ext_gw_ip=$(openstack --os-cloud devstack-admin --os-region "$REGION_NAME" subnet create $subnet_params | grep -e 'gateway_ip' -e ' id ')
Sean M. Collins2a242512016-05-03 09:03:09 -0400303 die_if_not_set $LINENO id_and_ext_gw_ip "Failure creating public IPv4 subnet"
304 echo $id_and_ext_gw_ip
305}
306
307# Create public IPv6 subnet
308function _neutron_create_public_subnet_v6 {
Slawek Kaplonski14a0c092022-01-28 09:44:40 +0100309 local subnet_params="--ip-version 6 "
Sean M. Collins2a242512016-05-03 09:03:09 -0400310 subnet_params+="--gateway $IPV6_PUBLIC_NETWORK_GATEWAY "
Armando Migliaccio4f11ff32016-10-27 06:15:23 -0700311 subnet_params+="--network $EXT_NET_ID --subnet-range $IPV6_PUBLIC_RANGE --no-dhcp "
312 subnet_params+="$IPV6_PUBLIC_SUBNET_NAME"
Sean M. Collins2a242512016-05-03 09:03:09 -0400313 local ipv6_id_and_ext_gw_ip
Slawek Kaplonski14a0c092022-01-28 09:44:40 +0100314 ipv6_id_and_ext_gw_ip=$(openstack --os-cloud devstack-admin --os-region "$REGION_NAME" subnet create $subnet_params | grep -e 'gateway_ip' -e ' id ')
Sean M. Collins2a242512016-05-03 09:03:09 -0400315 die_if_not_set $LINENO ipv6_id_and_ext_gw_ip "Failure creating an IPv6 public subnet"
316 echo $ipv6_id_and_ext_gw_ip
317}
318
319# Configure neutron router for IPv4 public access
320function _neutron_configure_router_v4 {
Slawek Kaplonski14a0c092022-01-28 09:44:40 +0100321 openstack --os-cloud devstack-admin-demo --os-region "$REGION_NAME" router add subnet $ROUTER_ID $SUBNET_ID
Sean M. Collins2a242512016-05-03 09:03:09 -0400322 # Create a public subnet on the external network
323 local id_and_ext_gw_ip
324 id_and_ext_gw_ip=$(_neutron_create_public_subnet_v4 $EXT_NET_ID)
325 local ext_gw_ip
326 ext_gw_ip=$(echo $id_and_ext_gw_ip | get_field 2)
327 PUB_SUBNET_ID=$(echo $id_and_ext_gw_ip | get_field 5)
328 # Configure the external network as the default router gateway
Slawek Kaplonski14a0c092022-01-28 09:44:40 +0100329 openstack --os-cloud devstack-admin-demo --os-region "$REGION_NAME" router set --external-gateway $EXT_NET_ID $ROUTER_ID
Sean M. Collins2a242512016-05-03 09:03:09 -0400330
Radosław Piliszek95298782021-06-08 16:19:40 +0000331 # This logic is specific to using OVN or the l3-agent for layer 3
Slawek Kaplonskia52041c2022-11-18 11:39:56 +0100332 if ([[ $Q_AGENT == "ovn" ]] && [[ "$OVN_L3_CREATE_PUBLIC_NETWORK" == "True" ]] && is_service_enabled q-svc neutron-api) || is_service_enabled q-l3 neutron-l3; then
Sean M. Collins2a242512016-05-03 09:03:09 -0400333 # Configure and enable public bridge
334 local ext_gw_interface="none"
335 if is_neutron_ovs_base_plugin; then
336 ext_gw_interface=$(_neutron_get_ext_gw_interface)
337 elif [[ "$Q_AGENT" = "linuxbridge" ]]; then
Kevin Benton6a42a852016-07-21 11:11:54 -0700338 # Get the device the neutron router and network for $FIXED_RANGE
Sean M. Collins2a242512016-05-03 09:03:09 -0400339 # will be using.
Kevin Benton6a42a852016-07-21 11:11:54 -0700340 if [ "$Q_USE_PROVIDERNET_FOR_PUBLIC" = "True" ]; then
341 # in provider nets a bridge mapping uses the public bridge directly
342 ext_gw_interface=$PUBLIC_BRIDGE
343 else
344 # e.x. brq3592e767-da for NET_ID 3592e767-da66-4bcb-9bec-cdb03cd96102
345 ext_gw_interface=brq${EXT_NET_ID:0:11}
346 fi
Sean M. Collins2a242512016-05-03 09:03:09 -0400347 fi
348 if [[ "$ext_gw_interface" != "none" ]]; then
349 local cidr_len=${FLOATING_RANGE#*/}
350 local testcmd="ip -o link | grep -q $ext_gw_interface"
351 test_with_retry "$testcmd" "$ext_gw_interface creation failed"
Kevin Benton1554ade2016-07-22 09:40:19 -0700352 if [[ $(ip addr show dev $ext_gw_interface | grep -c $ext_gw_ip) == 0 && ( $Q_USE_PROVIDERNET_FOR_PUBLIC == "False" || $Q_USE_PUBLIC_VETH == "True" || $Q_ASSIGN_GATEWAY_TO_PUBLIC_BRIDGE == "True" ) ]]; then
Sean M. Collins2a242512016-05-03 09:03:09 -0400353 sudo ip addr add $ext_gw_ip/$cidr_len dev $ext_gw_interface
354 sudo ip link set $ext_gw_interface up
355 fi
Slawek Kaplonski14a0c092022-01-28 09:44:40 +0100356 ROUTER_GW_IP=$(openstack --os-cloud devstack-admin --os-region "$REGION_NAME" port list -c 'Fixed IP Addresses' --device-owner network:router_gateway | awk -F'ip_address' '{ print $2 }' | cut -f2 -d\' | tr '\n' ' ')
Sean M. Collins2a242512016-05-03 09:03:09 -0400357 die_if_not_set $LINENO ROUTER_GW_IP "Failure retrieving ROUTER_GW_IP"
Sean M. Collins2a242512016-05-03 09:03:09 -0400358 fi
359 _neutron_set_router_id
360 fi
361}
362
363# Configure neutron router for IPv6 public access
364function _neutron_configure_router_v6 {
Slawek Kaplonski14a0c092022-01-28 09:44:40 +0100365 openstack --os-cloud devstack-admin-demo --os-region "$REGION_NAME" router add subnet $ROUTER_ID $IPV6_SUBNET_ID
Sean M. Collins2a242512016-05-03 09:03:09 -0400366 # Create a public subnet on the external network
367 local ipv6_id_and_ext_gw_ip
368 ipv6_id_and_ext_gw_ip=$(_neutron_create_public_subnet_v6 $EXT_NET_ID)
369 local ipv6_ext_gw_ip
370 ipv6_ext_gw_ip=$(echo $ipv6_id_and_ext_gw_ip | get_field 2)
371 local ipv6_pub_subnet_id
372 ipv6_pub_subnet_id=$(echo $ipv6_id_and_ext_gw_ip | get_field 5)
373
374 # If the external network has not already been set as the default router
375 # gateway when configuring an IPv4 public subnet, do so now
376 if [[ "$IP_VERSION" == "6" ]]; then
Slawek Kaplonski14a0c092022-01-28 09:44:40 +0100377 openstack --os-cloud devstack-admin-demo --os-region "$REGION_NAME" router set --external-gateway $EXT_NET_ID $ROUTER_ID
Sean M. Collins2a242512016-05-03 09:03:09 -0400378 fi
379
Gregory Thiemonge949f5ad2021-03-15 18:25:04 +0100380 # This logic is specific to using OVN or the l3-agent for layer 3
Slawek Kaplonskia52041c2022-11-18 11:39:56 +0100381 if ([[ $Q_AGENT == "ovn" ]] && [[ "$OVN_L3_CREATE_PUBLIC_NETWORK" == "True" ]] && is_service_enabled q-svc neutron-api) || is_service_enabled q-l3 neutron-l3; then
aojeagarcia866efef2018-09-28 10:43:46 +0200382 # if the Linux host considers itself to be a router then it will
383 # ignore all router advertisements
Henry Gessau734f1442016-09-17 19:28:53 -0400384 # Ensure IPv6 RAs are accepted on interfaces with a default route.
Monty Taylorc12d1d92016-08-23 19:07:57 -0500385 # This is needed for neutron-based devstack clouds to work in
386 # IPv6-only clouds in the gate. Please do not remove this without
387 # talking to folks in Infra.
Henry Gessau734f1442016-09-17 19:28:53 -0400388 for d in $default_v6_route_devs; do
Drago Rossonb34d4592016-09-26 13:23:23 -0500389 # Slashes must be used in this sysctl command because route devices
390 # can have dots in their names. If dots were used, dots in the
391 # device name would be reinterpreted as a slash, causing an error.
392 sudo sysctl -w net/ipv6/conf/$d/accept_ra=2
Henry Gessau734f1442016-09-17 19:28:53 -0400393 done
Jens Harbott0c9a6ca2019-09-19 13:57:43 +0000394 # Ensure IPv6 forwarding is enabled on the host
395 sudo sysctl -w net.ipv6.conf.all.forwarding=1
Sean M. Collins2a242512016-05-03 09:03:09 -0400396 # Configure and enable public bridge
397 # Override global IPV6_ROUTER_GW_IP with the true value from neutron
Slawek Kaplonski14a0c092022-01-28 09:44:40 +0100398 # NOTE(slaweq): when enforce scopes is enabled in Neutron, router's
399 # gateway ports aren't visible in API because such ports don't belongs
400 # to any tenant. Because of that, at least temporary we need to find
401 # IPv6 address of the router's gateway in a bit different way.
402 # It can be reverted when bug
403 # https://bugs.launchpad.net/neutron/+bug/1959332 will be fixed
404 IPV6_ROUTER_GW_IP=$(openstack --os-cloud devstack-admin-demo --os-region "$REGION_NAME" router show $ROUTER_ID -c external_gateway_info -f json | grep -C 1 $ipv6_pub_subnet_id | grep ip_address | awk '{print $2}' | tr -d '"')
Sean M. Collins2a242512016-05-03 09:03:09 -0400405 die_if_not_set $LINENO IPV6_ROUTER_GW_IP "Failure retrieving IPV6_ROUTER_GW_IP"
406
407 if is_neutron_ovs_base_plugin; then
408 local ext_gw_interface
409 ext_gw_interface=$(_neutron_get_ext_gw_interface)
410 local ipv6_cidr_len=${IPV6_PUBLIC_RANGE#*/}
411
Julia Kreger6964ba42022-04-25 08:48:20 -0700412 # Configure interface for public bridge by setting the interface
413 # to "up" in case the job is running entirely private network based
414 # testing.
415 sudo ip link set $ext_gw_interface up
Yi Zhaoa464ea72016-05-12 10:32:58 +0800416 sudo ip -6 addr replace $ipv6_ext_gw_ip/$ipv6_cidr_len dev $ext_gw_interface
Gregory Thiemonge949f5ad2021-03-15 18:25:04 +0100417 # Any IPv6 private subnet that uses the default IPV6 subnet pool
418 # and that is plugged into the default router (Q_ROUTER_NAME) will
419 # be reachable from the devstack node (ex: ipv6-private-subnet).
420 # Some scenario tests (such as octavia-tempest-plugin) rely heavily
421 # on this feature.
Matt Van Dijkd7a3f5c2016-08-16 15:46:58 +0000422 local replace_range=${SUBNETPOOL_PREFIX_V6}
423 if [[ -z "${SUBNETPOOL_V6_ID}" ]]; then
424 replace_range=${FIXED_RANGE_V6}
425 fi
426 sudo ip -6 route replace $replace_range via $IPV6_ROUTER_GW_IP dev $ext_gw_interface
Sean M. Collins2a242512016-05-03 09:03:09 -0400427 fi
428 _neutron_set_router_id
429 fi
430}
watanabe.isao4f4d95a2016-05-12 20:35:20 +0900431
Sean M. Collinsc35110e2016-05-18 10:38:51 -0400432function is_networking_extension_supported {
433 local extension=$1
434 # TODO(sc68cal) cache this instead of calling every time
Slawek Kaplonski14a0c092022-01-28 09:44:40 +0100435 EXT_LIST=$(openstack --os-cloud devstack-admin --os-region "$REGION_NAME" extension list --network -c Alias -f value)
Sean M. Collinsc35110e2016-05-18 10:38:51 -0400436 [[ $EXT_LIST =~ $extension ]] && return 0
437}
Slawek Kaplonskifaed11d2021-11-18 10:36:57 +0100438
439function plugin_agent_add_l3_agent_extension {
440 local l3_agent_extension=$1
441 if [[ -z "$L3_AGENT_EXTENSIONS" ]]; then
442 L3_AGENT_EXTENSIONS=$l3_agent_extension
443 elif [[ ! ,${L3_AGENT_EXTENSIONS}, =~ ,${l3_agent_extension}, ]]; then
444 L3_AGENT_EXTENSIONS+=",$l3_agent_extension"
445 fi
446}