blob: 51019a343260303af781cd00ca149912bd51b70c [file] [log] [blame]
Jesse Andrewsb0191512011-09-14 19:37:10 -07001#!/usr/bin/env bash
2
Dean Troyer27e32692012-03-16 16:16:56 -05003# **floating_ips.sh** - using the cloud can be fun
Jesse Andrewsb0191512011-09-14 19:37:10 -07004
5# we will use the ``nova`` cli tool provided by the ``python-novaclient``
Dean Troyer27e32692012-03-16 16:16:56 -05006# package to work out the instance connectivity
Jesse Andrewsb0191512011-09-14 19:37:10 -07007
Dean Troyer27e32692012-03-16 16:16:56 -05008echo "*********************************************************************"
Dean Troyer489bd2a2012-03-02 10:44:29 -06009echo "Begin DevStack Exercise: $0"
Dean Troyer27e32692012-03-16 16:16:56 -050010echo "*********************************************************************"
Dean Troyer489bd2a2012-03-02 10:44:29 -060011
Vishvananda Ishaya9b353672011-10-20 10:07:10 -070012# This script exits on an error so that errors don't compound and you see
Jesse Andrewsb19424f2011-09-14 22:03:04 -070013# only the first error that occured.
14set -o errexit
15
Vishvananda Ishaya9b353672011-10-20 10:07:10 -070016# Print the commands being run so that we can see the command that triggers
Jesse Andrewsb19424f2011-09-14 22:03:04 -070017# an error. It is also useful for following allowing as the install occurs.
18set -o xtrace
19
20
21# Settings
22# ========
Jesse Andrewsb0191512011-09-14 19:37:10 -070023
Dean Troyer51fb4542012-03-09 22:21:59 -060024# Keep track of the current directory
25EXERCISE_DIR=$(cd $(dirname "$0") && pwd)
26TOP_DIR=$(cd $EXERCISE_DIR/..; pwd)
Dean Troyer489bd2a2012-03-02 10:44:29 -060027
28# Import common functions
Dean Troyer51fb4542012-03-09 22:21:59 -060029source $TOP_DIR/functions
Dean Troyer489bd2a2012-03-02 10:44:29 -060030
31# Import configuration
Dean Troyer51fb4542012-03-09 22:21:59 -060032source $TOP_DIR/openrc
Jesse Andrewsb0191512011-09-14 19:37:10 -070033
Dean Troyer51fb4542012-03-09 22:21:59 -060034# Import exercise configuration
35source $TOP_DIR/exerciserc
Dean Troyer751c1522012-01-10 15:34:34 -060036
37# Instance type to create
38DEFAULT_INSTANCE_TYPE=${DEFAULT_INSTANCE_TYPE:-m1.tiny}
39
40# Boot this image, use first AMi image if unset
41DEFAULT_IMAGE_NAME=${DEFAULT_IMAGE_NAME:-ami}
42
43# Security group name
44SECGROUP=${SECGROUP:-test_secgroup}
45
46# Default floating IP pool name
Dean Troyer696ad332012-01-10 15:34:34 -060047DEFAULT_FLOATING_POOL=${DEFAULT_FLOATING_POOL:-nova}
Dean Troyer751c1522012-01-10 15:34:34 -060048
49# Additional floating IP pool and range
Dean Troyer696ad332012-01-10 15:34:34 -060050TEST_FLOATING_POOL=${TEST_FLOATING_POOL:-test}
51
Dean Troyer27e32692012-03-16 16:16:56 -050052
Jesse Andrews593828d2011-09-14 22:44:50 -070053# Launching a server
54# ==================
Jesse Andrewsb19424f2011-09-14 22:03:04 -070055
Jesse Andrews593828d2011-09-14 22:44:50 -070056# List servers for tenant:
Jesse Andrewsb0191512011-09-14 19:37:10 -070057nova list
Jesse Andrews593828d2011-09-14 22:44:50 -070058
Jesse Andrews593828d2011-09-14 22:44:50 -070059# Images
60# ------
61
62# Nova has a **deprecated** way of listing images.
63nova image-list
64
65# But we recommend using glance directly
Dean Troyer45495252012-04-13 13:16:38 -050066glance image-list
Jesse Andrews593828d2011-09-14 22:44:50 -070067
Dean Troyer751c1522012-01-10 15:34:34 -060068# Grab the id of the image to launch
Dean Troyer45495252012-04-13 13:16:38 -050069IMAGE=$(glance image-list | egrep " $DEFAULT_IMAGE_NAME " | get_field 1)
Jesse Andrewsd888e1c2011-10-15 20:01:12 -070070
Anthony Young20a2cae2011-10-17 16:02:24 -070071# Security Groups
72# ---------------
Anthony Young20a2cae2011-10-17 16:02:24 -070073
74# List of secgroups:
75nova secgroup-list
76
77# Create a secgroup
Dean Troyer751c1522012-01-10 15:34:34 -060078if ! nova secgroup-list | grep -q $SECGROUP; then
79 nova secgroup-create $SECGROUP "$SECGROUP description"
80 if ! timeout $ASSOCIATE_TIMEOUT sh -c "while ! nova secgroup-list | grep -q $SECGROUP; do sleep 1; done"; then
81 echo "Security group not created"
82 exit 1
83 fi
84fi
Jesse Andrewsd888e1c2011-10-15 20:01:12 -070085
Dean Troyerad101762012-06-27 22:04:40 -050086# Determinine instance type
Dean Troyer751c1522012-01-10 15:34:34 -060087# -------------------------
Jesse Andrewsd888e1c2011-10-15 20:01:12 -070088
Dean Troyer751c1522012-01-10 15:34:34 -060089# List of instance types:
Jesse Andrewsd888e1c2011-10-15 20:01:12 -070090nova flavor-list
91
Dean Troyer489bd2a2012-03-02 10:44:29 -060092INSTANCE_TYPE=`nova flavor-list | grep $DEFAULT_INSTANCE_TYPE | get_field 1`
Dean Troyer1d6e0e12011-12-23 12:45:13 -060093if [[ -z "$INSTANCE_TYPE" ]]; then
94 # grab the first flavor in the list to launch if default doesn't exist
Dean Troyer489bd2a2012-03-02 10:44:29 -060095 INSTANCE_TYPE=`nova flavor-list | head -n 4 | tail -n 1 | get_field 1`
Dean Troyer1d6e0e12011-12-23 12:45:13 -060096fi
Jesse Andrewsd888e1c2011-10-15 20:01:12 -070097
Dean Troyer489bd2a2012-03-02 10:44:29 -060098NAME="ex-float"
Jesse Andrewsd888e1c2011-10-15 20:01:12 -070099
Dean Troyer489bd2a2012-03-02 10:44:29 -0600100VM_UUID=`nova boot --flavor $INSTANCE_TYPE --image $IMAGE $NAME --security_groups=$SECGROUP | grep ' id ' | get_field 2`
101die_if_not_set VM_UUID "Failure launching $NAME"
Jesse Andrewsd888e1c2011-10-15 20:01:12 -0700102
Dean Troyerad101762012-06-27 22:04:40 -0500103
Jesse Andrews6fc71012011-10-24 11:29:08 -0700104# Testing
105# =======
106
107# First check if it spins up (becomes active and responds to ping on
108# internal ip). If you run this script from a nova node, you should
109# bypass security groups and have direct access to the server.
110
111# Waiting for boot
112# ----------------
113
Anthony Young79e807a2011-10-31 11:16:44 -0700114# check that the status is active within ACTIVE_TIMEOUT seconds
Dean Troyer751c1522012-01-10 15:34:34 -0600115if ! timeout $ACTIVE_TIMEOUT sh -c "while ! nova show $VM_UUID | grep status | grep -q ACTIVE; do sleep 1; done"; then
Jesse Andrews5a774832011-10-26 21:30:02 -0700116 echo "server didn't become active!"
117 exit 1
118fi
Jesse Andrewsd888e1c2011-10-15 20:01:12 -0700119
120# get the IP of the server
Dean Troyer489bd2a2012-03-02 10:44:29 -0600121IP=`nova show $VM_UUID | grep "private network" | get_field 2`
122die_if_not_set IP "Failure retrieving IP address"
Jesse Andrewsd888e1c2011-10-15 20:01:12 -0700123
Anthony Young8ecd2942011-10-24 22:58:14 -0700124# for single node deployments, we can ping private ips
Armando Migliaccio7d13f302012-04-19 22:26:16 +0100125MULTI_HOST=`trueorfalse False $MULTI_HOST`
126if [ "$MULTI_HOST" = "False" ]; then
Anthony Young8ecd2942011-10-24 22:58:14 -0700127 # sometimes the first ping fails (10 seconds isn't enough time for the VM's
Anthony Young79e807a2011-10-31 11:16:44 -0700128 # network to respond?), so let's ping for a default of 15 seconds with a
129 # timeout of a second for each ping.
130 if ! timeout $BOOT_TIMEOUT sh -c "while ! ping -c1 -w1 $IP; do sleep 1; done"; then
Jesse Andrewsab8dbce2011-10-26 21:23:20 -0700131 echo "Couldn't ping server"
132 exit 1
133 fi
Anthony Young79e807a2011-10-31 11:16:44 -0700134else
135 # On a multi-host system, without vm net access, do a sleep to wait for the boot
136 sleep $BOOT_TIMEOUT
Anthony Young8ecd2942011-10-24 22:58:14 -0700137fi
Jesse Andrews6fc71012011-10-24 11:29:08 -0700138
139# Security Groups & Floating IPs
140# ------------------------------
141
Dean Troyer751c1522012-01-10 15:34:34 -0600142if ! nova secgroup-list-rules $SECGROUP | grep -q icmp; then
143 # allow icmp traffic (ping)
144 nova secgroup-add-rule $SECGROUP icmp -1 -1 0.0.0.0/0
145 if ! timeout $ASSOCIATE_TIMEOUT sh -c "while ! nova secgroup-list-rules $SECGROUP | grep -q icmp; do sleep 1; done"; then
146 echo "Security group rule not created"
147 exit 1
148 fi
149fi
Anthony Young20a2cae2011-10-17 16:02:24 -0700150
151# List rules for a secgroup
152nova secgroup-list-rules $SECGROUP
153
Dean Troyer696ad332012-01-10 15:34:34 -0600154# allocate a floating ip from default pool
Dean Troyer489bd2a2012-03-02 10:44:29 -0600155FLOATING_IP=`nova floating-ip-create | grep $DEFAULT_FLOATING_POOL | get_field 1`
156die_if_not_set FLOATING_IP "Failure creating floating IP"
Anthony Young20a2cae2011-10-17 16:02:24 -0700157
Dean Troyer696ad332012-01-10 15:34:34 -0600158# list floating addresses
159if ! timeout $ASSOCIATE_TIMEOUT sh -c "while ! nova floating-ip-list | grep -q $FLOATING_IP; do sleep 1; done"; then
160 echo "Floating IP not allocated"
161 exit 1
162fi
Anthony Young20a2cae2011-10-17 16:02:24 -0700163
164# add floating ip to our server
Dean Troyer27e32692012-03-16 16:16:56 -0500165nova add-floating-ip $VM_UUID $FLOATING_IP || \
166 die "Failure adding floating IP $FLOATING_IP to $NAME"
Anthony Young20a2cae2011-10-17 16:02:24 -0700167
Anthony Young79e807a2011-10-31 11:16:44 -0700168# test we can ping our floating ip within ASSOCIATE_TIMEOUT seconds
169if ! timeout $ASSOCIATE_TIMEOUT sh -c "while ! ping -c1 -w1 $FLOATING_IP; do sleep 1; done"; then
Jesse Andrews5a774832011-10-26 21:30:02 -0700170 echo "Couldn't ping server with floating ip"
171 exit 1
172fi
Anthony Young20a2cae2011-10-17 16:02:24 -0700173
Dean Troyer751c1522012-01-10 15:34:34 -0600174# Allocate an IP from second floating pool
Dean Troyer489bd2a2012-03-02 10:44:29 -0600175TEST_FLOATING_IP=`nova floating-ip-create $TEST_FLOATING_POOL | grep $TEST_FLOATING_POOL | get_field 1`
176die_if_not_set TEST_FLOATING_IP "Failure creating floating IP in $TEST_FLOATING_POOL"
Dean Troyer696ad332012-01-10 15:34:34 -0600177
178# list floating addresses
179if ! timeout $ASSOCIATE_TIMEOUT sh -c "while ! nova floating-ip-list | grep $TEST_FLOATING_POOL | grep -q $TEST_FLOATING_IP; do sleep 1; done"; then
180 echo "Floating IP not allocated"
181 exit 1
182fi
183
Jesse Andrews6fc71012011-10-24 11:29:08 -0700184# dis-allow icmp traffic (ping)
Dean Troyer27e32692012-03-16 16:16:56 -0500185nova secgroup-delete-rule $SECGROUP icmp -1 -1 0.0.0.0/0 || die "Failure deleting security group rule from $SECGROUP"
Anthony Young20a2cae2011-10-17 16:02:24 -0700186
Anthony Young1de18c62011-11-01 14:19:18 -0500187# FIXME (anthony): make xs support security groups
Jesse Andrews16b6efa2011-11-10 11:46:18 -0800188if [ "$VIRT_DRIVER" != "xenserver" ]; then
Anthony Young1de18c62011-11-01 14:19:18 -0500189 # test we can aren't able to ping our floating ip within ASSOCIATE_TIMEOUT seconds
190 if ! timeout $ASSOCIATE_TIMEOUT sh -c "while ping -c1 -w1 $FLOATING_IP; do sleep 1; done"; then
191 print "Security group failure - ping should not be allowed!"
192 echo "Couldn't ping server with floating ip"
193 exit 1
194 fi
Anthony Young20a2cae2011-10-17 16:02:24 -0700195fi
196
197# de-allocate the floating ip
Dean Troyer27e32692012-03-16 16:16:56 -0500198nova floating-ip-delete $FLOATING_IP || die "Failure deleting floating IP $FLOATING_IP"
Jesse Andrewsd888e1c2011-10-15 20:01:12 -0700199
Dean Troyer696ad332012-01-10 15:34:34 -0600200# Delete second floating IP
Dean Troyer27e32692012-03-16 16:16:56 -0500201nova floating-ip-delete $TEST_FLOATING_IP || die "Failure deleting floating IP $TEST_FLOATING_IP"
Dean Troyer696ad332012-01-10 15:34:34 -0600202
Jesse Andrewsd888e1c2011-10-15 20:01:12 -0700203# shutdown the server
Dean Troyer27e32692012-03-16 16:16:56 -0500204nova delete $VM_UUID || die "Failure deleting instance $NAME"
Jesse Andrewsd888e1c2011-10-15 20:01:12 -0700205
Russell Bryant5836b152012-02-24 10:23:33 -0500206# make sure the VM shuts down within a reasonable time
207if ! timeout $TERMINATE_TIMEOUT sh -c "while nova show $VM_UUID | grep status | grep -q ACTIVE; do sleep 1; done"; then
208 echo "server didn't shut down!"
209 exit 1
210fi
211
Anthony Young20a2cae2011-10-17 16:02:24 -0700212# Delete a secgroup
Dean Troyer27e32692012-03-16 16:16:56 -0500213nova secgroup-delete $SECGROUP || die "Failure deleting security group $SECGROUP"
Dean Troyer489bd2a2012-03-02 10:44:29 -0600214
215set +o xtrace
Dean Troyer27e32692012-03-16 16:16:56 -0500216echo "*********************************************************************"
217echo "SUCCESS: End DevStack Exercise: $0"
218echo "*********************************************************************"