blob: cbeb1d7a5eb607b20c1d72710eb53fbf7131925f [file] [log] [blame]
Dean Troyer67787e62012-05-02 11:48:15 -05001# lib/cinder
Dean Troyer6d04fd72012-12-21 11:03:37 -06002# Install and start **Cinder** volume service
Dean Troyer67787e62012-05-02 11:48:15 -05003
4# Dependencies:
5# - functions
Attila Fazekas91b8d132013-01-06 22:40:09 +01006# - DEST, DATA_DIR, STACK_USER must be defined
Dean Troyer67787e62012-05-02 11:48:15 -05007# SERVICE_{TENANT_NAME|PASSWORD} must be defined
Dean Troyerbc071bc2012-10-01 14:06:44 -05008# ``KEYSTONE_TOKEN_FORMAT`` must be defined
Dean Troyer67787e62012-05-02 11:48:15 -05009
10# stack.sh
11# ---------
Attila Fazekasb79574b2012-12-01 10:42:46 +010012# install_cinder
13# configure_cinder
14# init_cinder
15# start_cinder
16# stop_cinder
17# cleanup_cinder
Dean Troyer67787e62012-05-02 11:48:15 -050018
Dean Troyer7903b792012-09-13 17:16:12 -050019# Save trace setting
20XTRACE=$(set +o | grep xtrace)
21set +o xtrace
Dean Troyer67787e62012-05-02 11:48:15 -050022
23
24# Defaults
25# --------
26
Mate Lakatb2fdafe2012-11-20 15:52:21 +000027# set up default driver
28CINDER_DRIVER=${CINDER_DRIVER:-default}
29
Dean Troyer67787e62012-05-02 11:48:15 -050030# set up default directories
31CINDER_DIR=$DEST/cinder
Dean Troyer50ac7922012-09-13 14:02:01 -050032CINDERCLIENT_DIR=$DEST/python-cinderclient
33CINDER_STATE_PATH=${CINDER_STATE_PATH:=$DATA_DIR/cinder}
Dean Troyer671c16e2012-12-13 16:22:38 -060034CINDER_AUTH_CACHE_DIR=${CINDER_AUTH_CACHE_DIR:-/var/cache/cinder}
35
Dean Troyer50ac7922012-09-13 14:02:01 -050036CINDER_CONF_DIR=/etc/cinder
37CINDER_CONF=$CINDER_CONF_DIR/cinder.conf
Dean Troyer671c16e2012-12-13 16:22:38 -060038CINDER_API_PASTE_INI=$CINDER_CONF_DIR/api-paste.ini
Dean Troyer50ac7922012-09-13 14:02:01 -050039
40# Support entry points installation of console scripts
41if [[ -d $CINDER_DIR/bin ]]; then
Monty Taylor9fbeedd2012-08-17 12:52:27 -040042 CINDER_BIN_DIR=$CINDER_DIR/bin
43else
44 CINDER_BIN_DIR=/usr/local/bin
45fi
Dean Troyer67787e62012-05-02 11:48:15 -050046
47# Name of the lvm volume group to use/create for iscsi volumes
48VOLUME_GROUP=${VOLUME_GROUP:-stack-volumes}
49VOLUME_NAME_PREFIX=${VOLUME_NAME_PREFIX:-volume-}
50
Dean Troyer22853c12013-01-07 15:18:12 -060051# _clean_volume_group removes all cinder volumes from the specified volume group
52# _clean_volume_group $VOLUME_GROUP $VOLUME_NAME_PREFIX
53function _clean_volume_group() {
54 local vg=$1
55 local vg_prefix=$2
56 # Clean out existing volumes
57 for lv in `sudo lvs --noheadings -o lv_name $vg`; do
58 # vg_prefix prefixes the LVs we want
59 if [[ "${lv#$vg_prefix}" != "$lv" ]]; then
60 sudo lvremove -f $vg/$lv
61 fi
62 done
63}
64
Dean Troyer67787e62012-05-02 11:48:15 -050065# cleanup_cinder() - Remove residual data files, anything left over from previous
66# runs that a clean run would need to clean up
67function cleanup_cinder() {
Sean Dague252f2f52012-12-20 16:41:57 -050068 # ensure the volume group is cleared up because fails might
69 # leave dead volumes in the group
70 TARGETS=$(sudo tgtadm --op show --mode target)
71 if [ $? -ne 0 ]; then
72 # If tgt driver isn't running this won't work obviously
73 # So check the response and restart if need be
74 echo "tgtd seems to be in a bad state, restarting..."
75 if is_ubuntu; then
76 restart_service tgt
77 else
78 restart_service tgtd
79 fi
80 TARGETS=$(sudo tgtadm --op show --mode target)
81 fi
82
83 if [[ -n "$TARGETS" ]]; then
84 iqn_list=( $(grep --no-filename -r iqn $SCSI_PERSIST_DIR | sed 's/<target //' | sed 's/>//') )
85 for i in "${iqn_list[@]}"; do
86 echo removing iSCSI target: $i
87 sudo tgt-admin --delete $i
88 done
89 fi
90
91 if is_service_enabled cinder; then
92 sudo rm -rf $CINDER_STATE_PATH/volumes/*
93 fi
94
95 if is_ubuntu; then
96 stop_service tgt
97 else
98 stop_service tgtd
99 fi
100
Dean Troyer22853c12013-01-07 15:18:12 -0600101 # Campsite rule: leave behind a volume group at least as clean as we found it
102 _clean_volume_group $VOLUME_GROUP $VOLUME_NAME_PREFIX
Dean Troyer67787e62012-05-02 11:48:15 -0500103}
104
105# configure_cinder() - Set config files, create data dirs, etc
106function configure_cinder() {
107 setup_develop $CINDER_DIR
108 setup_develop $CINDERCLIENT_DIR
109
110 if [[ ! -d $CINDER_CONF_DIR ]]; then
111 sudo mkdir -p $CINDER_CONF_DIR
112 fi
Attila Fazekas91b8d132013-01-06 22:40:09 +0100113 sudo chown $STACK_USER $CINDER_CONF_DIR
Dean Troyer67787e62012-05-02 11:48:15 -0500114
115 cp -p $CINDER_DIR/etc/cinder/policy.json $CINDER_CONF_DIR
116
John Griffith4e823ff2012-07-20 13:18:17 -0600117 # Set the paths of certain binaries
Vincent Untz856a11e2012-11-21 16:04:12 +0100118 CINDER_ROOTWRAP=$(get_rootwrap_location cinder)
John Griffith4e823ff2012-07-20 13:18:17 -0600119
120 # If Cinder ships the new rootwrap filters files, deploy them
121 # (owned by root) and add a parameter to $CINDER_ROOTWRAP
122 ROOTWRAP_CINDER_SUDOER_CMD="$CINDER_ROOTWRAP"
123 if [[ -d $CINDER_DIR/etc/cinder/rootwrap.d ]]; then
124 # Wipe any existing rootwrap.d files first
125 if [[ -d $CINDER_CONF_DIR/rootwrap.d ]]; then
126 sudo rm -rf $CINDER_CONF_DIR/rootwrap.d
127 fi
128 # Deploy filters to /etc/cinder/rootwrap.d
129 sudo mkdir -m 755 $CINDER_CONF_DIR/rootwrap.d
130 sudo cp $CINDER_DIR/etc/cinder/rootwrap.d/*.filters $CINDER_CONF_DIR/rootwrap.d
131 sudo chown -R root:root $CINDER_CONF_DIR/rootwrap.d
132 sudo chmod 644 $CINDER_CONF_DIR/rootwrap.d/*
133 # Set up rootwrap.conf, pointing to /etc/cinder/rootwrap.d
134 sudo cp $CINDER_DIR/etc/cinder/rootwrap.conf $CINDER_CONF_DIR/
135 sudo sed -e "s:^filters_path=.*$:filters_path=$CINDER_CONF_DIR/rootwrap.d:" -i $CINDER_CONF_DIR/rootwrap.conf
136 sudo chown root:root $CINDER_CONF_DIR/rootwrap.conf
137 sudo chmod 0644 $CINDER_CONF_DIR/rootwrap.conf
138 # Specify rootwrap.conf as first parameter to cinder-rootwrap
139 CINDER_ROOTWRAP="$CINDER_ROOTWRAP $CINDER_CONF_DIR/rootwrap.conf"
140 ROOTWRAP_CINDER_SUDOER_CMD="$CINDER_ROOTWRAP *"
141 fi
142
143 TEMPFILE=`mktemp`
144 echo "$USER ALL=(root) NOPASSWD: $ROOTWRAP_CINDER_SUDOER_CMD" >$TEMPFILE
145 chmod 0440 $TEMPFILE
146 sudo chown root:root $TEMPFILE
147 sudo mv $TEMPFILE /etc/sudoers.d/cinder-rootwrap
148
Dean Troyer67787e62012-05-02 11:48:15 -0500149 cp $CINDER_DIR/etc/cinder/api-paste.ini $CINDER_API_PASTE_INI
150 iniset $CINDER_API_PASTE_INI filter:authtoken auth_host $KEYSTONE_AUTH_HOST
151 iniset $CINDER_API_PASTE_INI filter:authtoken auth_port $KEYSTONE_AUTH_PORT
152 iniset $CINDER_API_PASTE_INI filter:authtoken auth_protocol $KEYSTONE_AUTH_PROTOCOL
153 iniset $CINDER_API_PASTE_INI filter:authtoken admin_tenant_name $SERVICE_TENANT_NAME
154 iniset $CINDER_API_PASTE_INI filter:authtoken admin_user cinder
155 iniset $CINDER_API_PASTE_INI filter:authtoken admin_password $SERVICE_PASSWORD
Akihiro MOTOKI5e3deb62012-12-11 17:09:02 +0900156 iniset $CINDER_API_PASTE_INI filter:authtoken signing_dir $CINDER_AUTH_CACHE_DIR
Dean Troyerbc071bc2012-10-01 14:06:44 -0500157
Dean Troyer67787e62012-05-02 11:48:15 -0500158 cp $CINDER_DIR/etc/cinder/cinder.conf.sample $CINDER_CONF
159 iniset $CINDER_CONF DEFAULT auth_strategy keystone
160 iniset $CINDER_CONF DEFAULT verbose True
161 iniset $CINDER_CONF DEFAULT volume_group $VOLUME_GROUP
162 iniset $CINDER_CONF DEFAULT volume_name_template ${VOLUME_NAME_PREFIX}%s
163 iniset $CINDER_CONF DEFAULT iscsi_helper tgtadm
Terry Wilson428af5a2012-11-01 16:12:39 -0400164 local dburl
165 database_connection_url dburl cinder
166 iniset $CINDER_CONF DEFAULT sql_connection $dburl
Dean Troyer67787e62012-05-02 11:48:15 -0500167 iniset $CINDER_CONF DEFAULT api_paste_config $CINDER_API_PASTE_INI
John Griffith4e823ff2012-07-20 13:18:17 -0600168 iniset $CINDER_CONF DEFAULT root_helper "sudo ${CINDER_ROOTWRAP}"
John Griffith43bedda2012-08-21 15:26:15 -0600169 iniset $CINDER_CONF DEFAULT osapi_volume_extension cinder.api.openstack.volume.contrib.standard_extensions
Dean Troyer50ac7922012-09-13 14:02:01 -0500170 iniset $CINDER_CONF DEFAULT state_path $CINDER_STATE_PATH
John Griffith4e823ff2012-07-20 13:18:17 -0600171
Dean Troyer4d3049e2012-11-06 20:38:14 -0600172 if [ "$SYSLOG" != "False" ]; then
173 iniset $CINDER_CONF DEFAULT use_syslog True
174 fi
175
Gary Kottonf71bf192012-08-06 11:15:36 -0400176 if is_service_enabled qpid ; then
177 iniset $CINDER_CONF DEFAULT rpc_backend cinder.openstack.common.rpc.impl_qpid
ewindisch3bae7c22012-01-18 11:18:35 -0500178 elif is_service_enabled zeromq; then
179 iniset $CINDER_CONF DEFAULT rpc_backend nova.openstack.common.rpc.impl_zmq
Gary Kottonf71bf192012-08-06 11:15:36 -0400180 elif [ -n "$RABBIT_HOST" ] && [ -n "$RABBIT_PASSWORD" ]; then
181 iniset $CINDER_CONF DEFAULT rabbit_host $RABBIT_HOST
182 iniset $CINDER_CONF DEFAULT rabbit_password $RABBIT_PASSWORD
183 fi
184
James E. Blair213c4162012-11-06 09:38:36 +0100185 if [[ "$CINDER_SECURE_DELETE" == "False" ]]; then
186 iniset $CINDER_CONF DEFAULT secure_delete False
Pádraig Bradyeac93702013-01-02 16:02:54 +0000187 iniset $CINDER_CONF DEFAULT volume_clear none
James E. Blair213c4162012-11-06 09:38:36 +0100188 fi
189
Chmouel Boudjnah1057bff2012-08-03 11:42:51 +0000190 if [ "$LOG_COLOR" == "True" ] && [ "$SYSLOG" == "False" ]; then
191 # Add color to logging output
Joe Gordonc99853c2013-01-03 17:39:16 -0800192 iniset $CINDER_CONF DEFAULT logging_context_format_string "%(asctime)s.%(msecs)d %(color)s%(levelname)s %(name)s [%(request_id)s %(user_id)s %(project_id)s%(color)s] %(instance)s%(color)s%(message)s"
193 iniset $CINDER_CONF DEFAULT logging_default_format_string "%(asctime)s.%(msecs)d %(color)s%(levelname)s %(name)s [-%(color)s] %(instance)s%(color)s%(message)s"
Chmouel Boudjnah1057bff2012-08-03 11:42:51 +0000194 iniset $CINDER_CONF DEFAULT logging_debug_format_suffix "from (pid=%(process)d) %(funcName)s %(pathname)s:%(lineno)d"
Joe Gordonc99853c2013-01-03 17:39:16 -0800195 iniset $CINDER_CONF DEFAULT logging_exception_prefix "%(color)s%(asctime)s.%(msecs)d TRACE %(name)s %(instance)s"
Chmouel Boudjnah1057bff2012-08-03 11:42:51 +0000196 fi
Mate Lakatb2fdafe2012-11-20 15:52:21 +0000197
198 if [ "$CINDER_DRIVER" == "XenAPINFS" ]; then
199 (
200 set -u
Mate Lakata0ca45f2012-12-06 17:45:49 +0000201 iniset $CINDER_CONF DEFAULT volume_driver "cinder.volume.drivers.xenapi.sm.XenAPINFSDriver"
Mate Lakatb2fdafe2012-11-20 15:52:21 +0000202 iniset $CINDER_CONF DEFAULT xenapi_connection_url "$CINDER_XENAPI_CONNECTION_URL"
203 iniset $CINDER_CONF DEFAULT xenapi_connection_username "$CINDER_XENAPI_CONNECTION_USERNAME"
204 iniset $CINDER_CONF DEFAULT xenapi_connection_password "$CINDER_XENAPI_CONNECTION_PASSWORD"
205 iniset $CINDER_CONF DEFAULT xenapi_nfs_server "$CINDER_XENAPI_NFS_SERVER"
206 iniset $CINDER_CONF DEFAULT xenapi_nfs_serverpath "$CINDER_XENAPI_NFS_SERVERPATH"
207 )
Mate Lakatb2fdafe2012-11-20 15:52:21 +0000208 fi
Dean Troyer67787e62012-05-02 11:48:15 -0500209}
210
Dean Troyer671c16e2012-12-13 16:22:38 -0600211# create_cinder_accounts() - Set up common required cinder accounts
212
213# Tenant User Roles
214# ------------------------------------------------------------------
215# service cinder admin # if enabled
216
217# Migrated from keystone_data.sh
218create_cinder_accounts() {
219
220 SERVICE_TENANT=$(keystone tenant-list | awk "/ $SERVICE_TENANT_NAME / { print \$2 }")
221 ADMIN_ROLE=$(keystone role-list | awk "/ admin / { print \$2 }")
222
223 # Cinder
224 if [[ "$ENABLED_SERVICES" =~ "c-api" ]]; then
225 CINDER_USER=$(keystone user-create \
226 --name=cinder \
227 --pass="$SERVICE_PASSWORD" \
228 --tenant_id $SERVICE_TENANT \
229 --email=cinder@example.com \
230 | grep " id " | get_field 2)
231 keystone user-role-add \
232 --tenant_id $SERVICE_TENANT \
233 --user_id $CINDER_USER \
234 --role_id $ADMIN_ROLE
235 if [[ "$KEYSTONE_CATALOG_BACKEND" = 'sql' ]]; then
236 CINDER_SERVICE=$(keystone service-create \
237 --name=cinder \
238 --type=volume \
239 --description="Cinder Volume Service" \
240 | grep " id " | get_field 2)
241 keystone endpoint-create \
242 --region RegionOne \
243 --service_id $CINDER_SERVICE \
244 --publicurl "http://$SERVICE_HOST:8776/v1/\$(tenant_id)s" \
245 --adminurl "http://$SERVICE_HOST:8776/v1/\$(tenant_id)s" \
246 --internalurl "http://$SERVICE_HOST:8776/v1/\$(tenant_id)s"
247 fi
248 fi
249}
250
Dean Troyer67787e62012-05-02 11:48:15 -0500251# init_cinder() - Initialize database and volume group
252function init_cinder() {
253 # Force nova volumes off
254 NOVA_ENABLED_APIS=$(echo $NOVA_ENABLED_APIS | sed "s/osapi_volume,//")
255
Terry Wilson428af5a2012-11-01 16:12:39 -0400256 if is_service_enabled $DATABASE_BACKENDS; then
Dean Troyer67787e62012-05-02 11:48:15 -0500257 # (re)create cinder database
Terry Wilson428af5a2012-11-01 16:12:39 -0400258 recreate_database cinder utf8
Dean Troyer67787e62012-05-02 11:48:15 -0500259
260 # (re)create cinder database
Monty Taylor9fbeedd2012-08-17 12:52:27 -0400261 $CINDER_BIN_DIR/cinder-manage db sync
Dean Troyer67787e62012-05-02 11:48:15 -0500262 fi
263
264 if is_service_enabled c-vol; then
265 # Configure a default volume group called '`stack-volumes`' for the volume
266 # service if it does not yet exist. If you don't wish to use a file backed
267 # volume group, create your own volume group called ``stack-volumes`` before
268 # invoking ``stack.sh``.
269 #
Eoghan Glynn9cb17762012-07-15 10:22:45 +0100270 # By default, the backing file is 5G in size, and is stored in ``/opt/stack/data``.
Dean Troyer67787e62012-05-02 11:48:15 -0500271
272 if ! sudo vgs $VOLUME_GROUP; then
273 VOLUME_BACKING_FILE=${VOLUME_BACKING_FILE:-$DATA_DIR/${VOLUME_GROUP}-backing-file}
Dean Troyer67787e62012-05-02 11:48:15 -0500274 # Only create if the file doesn't already exists
275 [[ -f $VOLUME_BACKING_FILE ]] || truncate -s $VOLUME_BACKING_FILE_SIZE $VOLUME_BACKING_FILE
276 DEV=`sudo losetup -f --show $VOLUME_BACKING_FILE`
277 # Only create if the loopback device doesn't contain $VOLUME_GROUP
278 if ! sudo vgs $VOLUME_GROUP; then sudo vgcreate $VOLUME_GROUP $DEV; fi
279 fi
280
Dean Troyer50ac7922012-09-13 14:02:01 -0500281 mkdir -p $CINDER_STATE_PATH/volumes
Chuck Short3f603d92012-07-28 13:28:33 -0500282
Dean Troyer67787e62012-05-02 11:48:15 -0500283 if sudo vgs $VOLUME_GROUP; then
Vincent Untz00011c02012-12-06 09:56:32 +0100284 if is_fedora || is_suse; then
285 # service is not started by default
Vincent Untz0230aa82012-06-14 08:51:01 +0200286 start_service tgtd
287 fi
288
Dean Troyer67787e62012-05-02 11:48:15 -0500289 # Remove iscsi targets
290 sudo tgtadm --op show --mode target | grep $VOLUME_NAME_PREFIX | grep Target | cut -f3 -d ' ' | sudo xargs -n1 tgt-admin --delete || true
Dean Troyer22853c12013-01-07 15:18:12 -0600291 # Start with a clean volume group
292 _clean_volume_group $VOLUME_GROUP $VOLUME_NAME_PREFIX
Dean Troyer67787e62012-05-02 11:48:15 -0500293 fi
294 fi
Dean Troyerbc071bc2012-10-01 14:06:44 -0500295
Akihiro MOTOKI5e3deb62012-12-11 17:09:02 +0900296 # Create cache dir
297 sudo mkdir -p $CINDER_AUTH_CACHE_DIR
Attila Fazekas91b8d132013-01-06 22:40:09 +0100298 sudo chown $STACK_USER $CINDER_AUTH_CACHE_DIR
Vishvananda Ishaya23431f32012-12-12 15:57:33 -0800299 rm -f $CINDER_AUTH_CACHE_DIR/*
Dean Troyer67787e62012-05-02 11:48:15 -0500300}
301
302# install_cinder() - Collect source and prepare
303function install_cinder() {
304 git_clone $CINDER_REPO $CINDER_DIR $CINDER_BRANCH
305 git_clone $CINDERCLIENT_REPO $CINDERCLIENT_DIR $CINDERCLIENT_BRANCH
306}
307
Mate Lakata39caac2012-09-03 15:45:53 +0100308# apply config.d approach (e.g. Oneiric does not have this)
309function _configure_tgt_for_config_d() {
310 if [[ ! -d /etc/tgt/conf.d/ ]]; then
Attila Fazekasb79574b2012-12-01 10:42:46 +0100311 sudo mkdir -p /etc/tgt/conf.d
Mate Lakata39caac2012-09-03 15:45:53 +0100312 echo "include /etc/tgt/conf.d/*.conf" | sudo tee -a /etc/tgt/targets.conf
313 fi
314}
315
Dean Troyer67787e62012-05-02 11:48:15 -0500316# start_cinder() - Start running processes, including screen
317function start_cinder() {
318 if is_service_enabled c-vol; then
Attila Fazekasb79574b2012-12-01 10:42:46 +0100319 _configure_tgt_for_config_d
320 if [[ ! -f /etc/tgt/conf.d/stack.conf ]]; then
321 echo "include $CINDER_STATE_PATH/volumes/*" | sudo tee /etc/tgt/conf.d/stack.conf
322 fi
Vincent Untzc18b9652012-12-04 12:36:34 +0100323 if is_ubuntu; then
Dean Troyer67787e62012-05-02 11:48:15 -0500324 # tgt in oneiric doesn't restart properly if tgtd isn't running
325 # do it in two steps
326 sudo stop tgt || true
327 sudo start tgt
Vincent Untz00011c02012-12-06 09:56:32 +0100328 elif is_fedora; then
Dean Troyer67787e62012-05-02 11:48:15 -0500329 # bypass redirection to systemctl during restart
330 sudo /sbin/service --skip-redirect tgtd restart
Vincent Untz00011c02012-12-06 09:56:32 +0100331 elif is_suse; then
332 restart_service tgtd
333 else
334 # note for other distros: unstack.sh also uses the tgt/tgtd service
335 # name, and would need to be adjusted too
336 exit_distro_not_supported "restarting tgt"
Dean Troyer67787e62012-05-02 11:48:15 -0500337 fi
338 fi
339
Monty Taylor9fbeedd2012-08-17 12:52:27 -0400340 screen_it c-api "cd $CINDER_DIR && $CINDER_BIN_DIR/cinder-api --config-file $CINDER_CONF"
341 screen_it c-vol "cd $CINDER_DIR && $CINDER_BIN_DIR/cinder-volume --config-file $CINDER_CONF"
342 screen_it c-sch "cd $CINDER_DIR && $CINDER_BIN_DIR/cinder-scheduler --config-file $CINDER_CONF"
Dean Troyer67787e62012-05-02 11:48:15 -0500343}
344
Dean Troyer699a29f2012-09-10 14:10:27 -0500345# stop_cinder() - Stop running processes
Dean Troyer67787e62012-05-02 11:48:15 -0500346function stop_cinder() {
Dean Troyer699a29f2012-09-10 14:10:27 -0500347 # Kill the cinder screen windows
348 for serv in c-api c-sch c-vol; do
349 screen -S $SCREEN_NAME -p $serv -X kill
350 done
Dean Troyer67787e62012-05-02 11:48:15 -0500351
352 if is_service_enabled c-vol; then
Vincent Untz90dd96d2012-12-13 08:59:57 +0100353 if is_ubuntu; then
354 stop_service tgt
355 else
356 stop_service tgtd
357 fi
Dean Troyer67787e62012-05-02 11:48:15 -0500358 fi
359}
Dean Troyer7903b792012-09-13 17:16:12 -0500360
361# Restore xtrace
362$XTRACE