blob: abc9c63614afceceb455525d8402ea0a4587659c [file] [log] [blame]
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +01001#!/bin/bash
2#
3# Licensed under the Apache License, Version 2.0 (the "License"); you may
4# not use this file except in compliance with the License. You may obtain
5# a copy of the License at
6#
7# http://www.apache.org/licenses/LICENSE-2.0
8#
9# Unless required by applicable law or agreed to in writing, software
10# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
11# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
12# License for the specific language governing permissions and limitations
13# under the License.
14#
15
16# Global Sources
17# --------------
18
19# There are some ovs functions OVN depends on that must be sourced from
20# the ovs neutron plugins.
21source ${TOP_DIR}/lib/neutron_plugins/ovs_base
22source ${TOP_DIR}/lib/neutron_plugins/openvswitch_agent
23
24# Load devstack ovs base functions
25source $NEUTRON_DIR/devstack/lib/ovs
26
27
28# Defaults
29# --------
30
Slawek Kaplonski7ba26f52020-09-17 11:13:52 +020031Q_BUILD_OVS_FROM_GIT=$(trueorfalse True Q_BUILD_OVS_FROM_GIT)
32
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +010033# Set variables for building OVN from source
34OVN_REPO=${OVN_REPO:-https://github.com/ovn-org/ovn.git}
35OVN_REPO_NAME=$(basename ${OVN_REPO} | cut -f1 -d'.')
36OVN_REPO_NAME=${OVN_REPO_NAME:-ovn}
37OVN_BRANCH=${OVN_BRANCH:-v20.06.1}
38# The commit removing OVN bits from the OVS tree, it is the commit that is not
39# present in OVN tree and is used to distinguish if OVN is part of OVS or not.
40# https://github.com/openvswitch/ovs/commit/05bf1dbb98b0635a51f75e268ef8aed27601401d
41OVN_SPLIT_HASH=05bf1dbb98b0635a51f75e268ef8aed27601401d
42
43if is_service_enabled tls-proxy; then
44 OVN_PROTO=ssl
45else
46 OVN_PROTO=tcp
47fi
48
49# How to connect to ovsdb-server hosting the OVN SB database.
50OVN_SB_REMOTE=${OVN_SB_REMOTE:-$OVN_PROTO:$SERVICE_HOST:6642}
51
52# How to connect to ovsdb-server hosting the OVN NB database
53OVN_NB_REMOTE=${OVN_NB_REMOTE:-$OVN_PROTO:$SERVICE_HOST:6641}
54
55# ml2/config for neutron_sync_mode
56OVN_NEUTRON_SYNC_MODE=${OVN_NEUTRON_SYNC_MODE:-log}
57
58# Configured DNS servers to be used with internal_dns extension, only
59# if the subnet DNS is not configured.
60OVN_DNS_SERVERS=${OVN_DNS_SERVERS:-8.8.8.8}
61
62# The type of OVN L3 Scheduler to use. The OVN L3 Scheduler determines the
63# hypervisor/chassis where a routers gateway should be hosted in OVN. The
64# default OVN L3 scheduler is leastloaded
65OVN_L3_SCHEDULER=${OVN_L3_SCHEDULER:-leastloaded}
66
67# A UUID to uniquely identify this system. If one is not specified, a random
68# one will be generated. A randomly generated UUID will be saved in a file
69# 'ovn-uuid' so that the same one will be re-used if you re-run DevStack.
70OVN_UUID=${OVN_UUID:-}
71
72# Whether or not to build the openvswitch kernel module from ovs. This is required
73# unless the distro kernel includes ovs+conntrack support.
74OVN_BUILD_MODULES=$(trueorfalse False OVN_BUILD_MODULES)
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +000075OVN_BUILD_FROM_SOURCE=$(trueorfalse False OVN_BUILD_FROM_SOURCE)
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +010076
77# Whether or not to install the ovs python module from ovs source. This can be
78# used to test and validate new ovs python features. This should only be used
79# for development purposes since the ovs python version is controlled by OpenStack
80# requirements.
81OVN_INSTALL_OVS_PYTHON_MODULE=$(trueorfalse False OVN_INSTALL_OVS_PYTHON_MODULE)
82
83# GENEVE overlay protocol overhead. Defaults to 38 bytes plus the IP version
84# overhead (20 bytes for IPv4 (default) or 40 bytes for IPv6) which is determined
85# based on the ML2 overlay_ip_version option. The ML2 framework will use this to
86# configure the MTU DHCP option.
87OVN_GENEVE_OVERHEAD=${OVN_GENEVE_OVERHEAD:-38}
88
89# The log level of the OVN databases (north and south)
90OVN_DBS_LOG_LEVEL=${OVN_DBS_LOG_LEVEL:-info}
91
92OVN_META_CONF=$NEUTRON_CONF_DIR/neutron_ovn_metadata_agent.ini
93OVN_META_DATA_HOST=${OVN_META_DATA_HOST:-$(ipv6_unquote $SERVICE_HOST)}
94
Lucas Alvares Gomes6ecfe672020-09-23 11:54:19 +010095export OVSDB_SERVER_LOCAL_HOST=$SERVICE_LOCAL_HOST
96if [[ "$SERVICE_IP_VERSION" == 6 ]]; then
97 OVSDB_SERVER_LOCAL_HOST=[$OVSDB_SERVER_LOCAL_HOST]
98fi
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +010099
100OVN_IGMP_SNOOPING_ENABLE=$(trueorfalse False OVN_IGMP_SNOOPING_ENABLE)
101
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000102OVS_PREFIX=
103if [[ "$OVN_BUILD_FROM_SOURCE" == "True" ]]; then
104 OVS_PREFIX=/usr/local
105fi
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100106OVS_SBINDIR=$OVS_PREFIX/sbin
107OVS_BINDIR=$OVS_PREFIX/bin
108OVS_RUNDIR=$OVS_PREFIX/var/run/openvswitch
109OVS_SHAREDIR=$OVS_PREFIX/share/openvswitch
110OVS_SCRIPTDIR=$OVS_SHAREDIR/scripts
111OVS_DATADIR=$DATA_DIR/ovs
112
113OVN_DATADIR=$DATA_DIR/ovn
114OVN_SHAREDIR=$OVS_PREFIX/share/ovn
115OVN_SCRIPTDIR=$OVN_SHAREDIR/scripts
116OVN_RUNDIR=$OVS_PREFIX/var/run/ovn
117
118NEUTRON_OVN_BIN_DIR=$(get_python_exec_prefix)
119NEUTRON_OVN_METADATA_BINARY="neutron-ovn-metadata-agent"
120
121STACK_GROUP="$( id --group --name "$STACK_USER" )"
122
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000123OVN_NORTHD_SERVICE=ovn-northd.service
124if is_ubuntu; then
125 # The ovn-central.service file on Ubuntu is responsible for starting
126 # ovn-northd and the OVN DBs (on CentOS this is done by ovn-northd.service)
127 OVN_NORTHD_SERVICE=ovn-central.service
128fi
129OVSDB_SERVER_SERVICE=ovsdb-server.service
130OVS_VSWITCHD_SERVICE=ovs-vswitchd.service
131OVN_CONTROLLER_SERVICE=ovn-controller.service
132OVN_CONTROLLER_VTEP_SERVICE=ovn-controller-vtep.service
133if [[ "$OVN_BUILD_FROM_SOURCE" == "True" ]]; then
134 OVSDB_SERVER_SERVICE=devstack@ovsdb-server.service
135 OVS_VSWITCHD_SERVICE=devstack@ovs-vswitchd.service
136 OVN_NORTHD_SERVICE=devstack@ovn-northd.service
137 OVN_CONTROLLER_SERVICE=devstack@ovn-controller.service
138 OVN_CONTROLLER_VTEP_SERVICE=devstack@ovn-controller-vtep.service
139fi
140
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100141# Defaults Overwrite
142# ------------------
143
144Q_ML2_PLUGIN_MECHANISM_DRIVERS=${Q_ML2_PLUGIN_MECHANISM_DRIVERS:-ovn,logger}
145Q_ML2_PLUGIN_TYPE_DRIVERS=${Q_ML2_PLUGIN_TYPE_DRIVERS:-local,flat,vlan,geneve}
146Q_ML2_TENANT_NETWORK_TYPE=${Q_ML2_TENANT_NETWORK_TYPE:-"geneve"}
147Q_ML2_PLUGIN_GENEVE_TYPE_OPTIONS=${Q_ML2_PLUGIN_GENEVE_TYPE_OPTIONS:-"vni_ranges=1:65536"}
Lucas Alvares Gomese7625fc2020-08-26 09:46:35 +0100148Q_ML2_PLUGIN_EXT_DRIVERS=${Q_ML2_PLUGIN_EXT_DRIVERS:-port_security,qos}
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100149# this one allows empty:
150ML2_L3_PLUGIN=${ML2_L3_PLUGIN-"ovn-router"}
151
152
153# Utility Functions
154# -----------------
155
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000156function wait_for_sock_file {
157 local count=0
158 while [ ! -S $1 ]; do
159 sleep 1
160 count=$((count+1))
161 if [ "$count" -gt 5 ]; then
162 die $LINENO "Socket $1 not found"
163 fi
164 done
165}
166
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100167function use_new_ovn_repository {
168 if [ -z "$is_new_ovn" ]; then
169 local ovs_repo_dir=$DEST/$OVS_REPO_NAME
170 if [ ! -d $ovs_repo_dir ]; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000171 git_timed clone $OVS_REPO $ovs_repo_dir
172 pushd $ovs_repo_dir
173 git checkout $OVS_BRANCH
174 popd
175 else
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100176 clone_repository $OVS_REPO $ovs_repo_dir $OVS_BRANCH
177 fi
178 # Check the split commit exists in the current branch
179 pushd $ovs_repo_dir
180 git log $OVS_BRANCH --pretty=format:"%H" | grep -q $OVN_SPLIT_HASH
181 is_new_ovn=$?
182 popd
183 fi
184 return $is_new_ovn
185}
186
187# NOTE(rtheis): Function copied from DevStack _neutron_ovs_base_setup_bridge
188# and _neutron_ovs_base_add_bridge with the call to neutron-ovs-cleanup
189# removed. The call is not relevant for OVN, as it is specific to the use
190# of Neutron's OVS agent and hangs when running stack.sh because
191# neutron-ovs-cleanup uses the OVSDB native interface.
192function ovn_base_setup_bridge {
193 local bridge=$1
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000194 local addbr_cmd="sudo ovs-vsctl --no-wait -- --may-exist add-br $bridge -- set bridge $bridge protocols=OpenFlow13,OpenFlow15"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100195
196 if [ "$OVS_DATAPATH_TYPE" != "system" ] ; then
197 addbr_cmd="$addbr_cmd -- set Bridge $bridge datapath_type=${OVS_DATAPATH_TYPE}"
198 fi
199
200 $addbr_cmd
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000201 sudo ovs-vsctl --no-wait br-set-external-id $bridge bridge-id $bridge
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100202}
203
204function _start_process {
205 $SYSTEMCTL daemon-reload
206 $SYSTEMCTL enable $1
207 $SYSTEMCTL restart $1
208}
209
210function _run_process {
211 local service=$1
212 local cmd="$2"
213 local stop_cmd="$3"
214 local group=$4
215 local user=${5:-$STACK_USER}
216
217 local systemd_service="devstack@$service.service"
218 local unit_file="$SYSTEMD_DIR/$systemd_service"
219 local environment="OVN_RUNDIR=$OVS_RUNDIR OVN_DBDIR=$OVN_DATADIR OVN_LOGDIR=$LOGDIR OVS_RUNDIR=$OVS_RUNDIR OVS_DBDIR=$OVS_DATADIR OVS_LOGDIR=$LOGDIR"
220
221 echo "Starting $service executed command": $cmd
222
223 write_user_unit_file $systemd_service "$cmd" "$group" "$user"
224 iniset -sudo $unit_file "Service" "Type" "forking"
225 iniset -sudo $unit_file "Service" "RemainAfterExit" "yes"
226 iniset -sudo $unit_file "Service" "KillMode" "mixed"
227 iniset -sudo $unit_file "Service" "LimitNOFILE" "65536"
228 iniset -sudo $unit_file "Service" "Environment" "$environment"
229 if [ -n "$stop_cmd" ]; then
230 iniset -sudo $unit_file "Service" "ExecStop" "$stop_cmd"
231 fi
232
233 _start_process $systemd_service
234
235 local testcmd="test -e $OVS_RUNDIR/$service.pid"
236 test_with_retry "$testcmd" "$service did not start" $SERVICE_TIMEOUT 1
237 sudo ovs-appctl -t $service vlog/set console:off syslog:info file:info
238}
239
240function clone_repository {
241 local repo=$1
242 local dir=$2
243 local branch=$3
244 # Set ERROR_ON_CLONE to false to avoid the need of having the
245 # repositories like OVN and OVS in the required_projects of the job
246 # definition.
247 ERROR_ON_CLONE=false git_clone $repo $dir $branch
248}
249
250function get_ext_gw_interface {
251 # Get ext_gw_interface depending on value of Q_USE_PUBLIC_VETH
252 # This function is copied directly from the devstack neutron-legacy script
253 if [[ "$Q_USE_PUBLIC_VETH" == "True" ]]; then
254 echo $Q_PUBLIC_VETH_EX
255 else
256 # Disable in-band as we are going to use local port
257 # to communicate with VMs
258 sudo ovs-vsctl set Bridge $PUBLIC_BRIDGE \
259 other_config:disable-in-band=true
260 echo $PUBLIC_BRIDGE
261 fi
262}
263
264function create_public_bridge {
265 # Create the public bridge that OVN will use
266 # This logic is based on the devstack neutron-legacy _neutron_configure_router_v4 and _v6
267 local ext_gw_ifc
268 ext_gw_ifc=$(get_ext_gw_interface)
269
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000270 sudo ovs-vsctl --may-exist add-br $ext_gw_ifc -- set bridge $ext_gw_ifc protocols=OpenFlow13,OpenFlow15
271 sudo ovs-vsctl set open . external-ids:ovn-bridge-mappings=$PHYSICAL_NETWORK:$ext_gw_ifc
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100272 if [ -n "$FLOATING_RANGE" ]; then
273 local cidr_len=${FLOATING_RANGE#*/}
Brian Haleyaf79a932021-03-15 12:20:42 -0400274 sudo ip addr replace $PUBLIC_NETWORK_GATEWAY/$cidr_len dev $ext_gw_ifc
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100275 fi
276
277 # Ensure IPv6 RAs are accepted on the interface with the default route.
278 # This is needed for neutron-based devstack clouds to work in
279 # IPv6-only clouds in the gate. Please do not remove this without
280 # talking to folks in Infra. This fix is based on a devstack fix for
281 # neutron L3 agent: https://review.openstack.org/#/c/359490/.
282 default_route_dev=$(ip route | grep ^default | awk '{print $5}')
283 sudo sysctl -w net.ipv6.conf.$default_route_dev.accept_ra=2
284
285 sudo sysctl -w net.ipv6.conf.all.forwarding=1
286 if [ -n "$IPV6_PUBLIC_RANGE" ]; then
287 local ipv6_cidr_len=${IPV6_PUBLIC_RANGE#*/}
Brian Haleyaf79a932021-03-15 12:20:42 -0400288 sudo ip -6 addr replace $IPV6_PUBLIC_NETWORK_GATEWAY/$ipv6_cidr_len dev $ext_gw_ifc
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100289 fi
290
291 sudo ip link set $ext_gw_ifc up
292}
293
294function _disable_libvirt_apparmor {
295 if ! sudo aa-status --enabled ; then
296 return 0
297 fi
298 # NOTE(arosen): This is used as a work around to allow newer versions
299 # of libvirt to work with ovs configured ports. See LP#1466631.
300 # requires the apparmor-utils
301 install_package apparmor-utils
302 # disables apparmor for libvirtd
303 sudo aa-complain /etc/apparmor.d/usr.sbin.libvirtd
304}
305
306
307# OVN compilation functions
308# -------------------------
309
310
311# compile_ovn() - Compile OVN from source and load needed modules
312# Accepts three parameters:
313# - first optional is False by default and means that
314# modules are built and installed.
315# - second optional parameter defines prefix for
316# ovn compilation
317# - third optional parameter defines localstatedir for
318# ovn single machine runtime
319function compile_ovn {
320 local build_modules=${1:-False}
321 local prefix=$2
322 local localstatedir=$3
323
324 if [ -n "$prefix" ]; then
325 prefix="--prefix=$prefix"
326 fi
327
328 if [ -n "$localstatedir" ]; then
329 localstatedir="--localstatedir=$localstatedir"
330 fi
331
332 clone_repository $OVN_REPO $DEST/$OVN_REPO_NAME $OVN_BRANCH
333 pushd $DEST/$OVN_REPO_NAME
334
335 if [ ! -f configure ] ; then
336 ./boot.sh
337 fi
338
339 if [ ! -f config.status ] || [ configure -nt config.status ] ; then
340 ./configure --with-ovs-source=$DEST/$OVS_REPO_NAME $prefix $localstatedir
341 fi
342 make -j$(($(nproc) + 1))
343 sudo make install
344 popd
345}
346
347
348# OVN Neutron driver functions
349# ----------------------------
350
351# OVN service sanity check
352function ovn_sanity_check {
353 if is_service_enabled q-agt neutron-agt; then
354 die $LINENO "The q-agt/neutron-agt service must be disabled with OVN."
355 elif is_service_enabled q-l3 neutron-l3; then
356 die $LINENO "The q-l3/neutron-l3 service must be disabled with OVN."
357 elif is_service_enabled q-svc neutron-api && [[ ! $Q_ML2_PLUGIN_MECHANISM_DRIVERS =~ "ovn" ]]; then
358 die $LINENO "OVN needs to be enabled in \$Q_ML2_PLUGIN_MECHANISM_DRIVERS"
359 elif is_service_enabled q-svc neutron-api && [[ ! $Q_ML2_PLUGIN_TYPE_DRIVERS =~ "geneve" ]]; then
360 die $LINENO "Geneve needs to be enabled in \$Q_ML2_PLUGIN_TYPE_DRIVERS to be used with OVN"
361 fi
362}
363
364# install_ovn() - Collect source and prepare
365function install_ovn {
Slawek Kaplonski7ba26f52020-09-17 11:13:52 +0200366 if [[ "$Q_BUILD_OVS_FROM_GIT" == "False" ]]; then
367 echo "Installation of OVS from source disabled."
368 return 0
369 fi
370
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100371 echo "Installing OVN and dependent packages"
372
373 # Check the OVN configuration
374 ovn_sanity_check
375
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100376 # Install tox, used to generate the config (see devstack/override-defaults)
377 pip_install tox
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100378
379 sudo mkdir -p $OVS_RUNDIR
380 sudo chown $(whoami) $OVS_RUNDIR
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000381 # NOTE(lucasagomes): To keep things simpler, let's reuse the same
382 # RUNDIR for both OVS and OVN. This way we avoid having to specify the
383 # --db option in the ovn-{n,s}bctl commands while playing with DevStack
384 sudo ln -s $OVS_RUNDIR $OVN_RUNDIR
385
386 if [[ "$OVN_BUILD_FROM_SOURCE" == "True" ]]; then
387 # If OVS is already installed, remove it, because we're about to
388 # re-install it from source.
389 for package in openvswitch openvswitch-switch openvswitch-common; do
390 if is_package_installed $package ; then
391 uninstall_package $package
392 fi
393 done
394
395 remove_ovs_packages
396 sudo rm -f $OVS_RUNDIR/*
397
398 compile_ovs $OVN_BUILD_MODULES
399 if use_new_ovn_repository; then
400 compile_ovn $OVN_BUILD_MODULES
401 fi
402
403 sudo mkdir -p $OVS_PREFIX/var/log/openvswitch
404 sudo chown $(whoami) $OVS_PREFIX/var/log/openvswitch
405 sudo mkdir -p $OVS_PREFIX/var/log/ovn
406 sudo chown $(whoami) $OVS_PREFIX/var/log/ovn
407 else
408 fixup_ovn_centos
409 install_package $(get_packages openvswitch)
410 install_package $(get_packages ovn)
411 fi
412
413 # Ensure that the OVS commands are accessible in the PATH
414 export PATH=$OVS_BINDIR:$PATH
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100415
416 # Archive log files and create new
417 local log_archive_dir=$LOGDIR/archive
418 mkdir -p $log_archive_dir
419 for logfile in ovs-vswitchd.log ovn-northd.log ovn-controller.log ovn-controller-vtep.log ovs-vtep.log ovsdb-server.log ovsdb-server-nb.log ovsdb-server-sb.log; do
420 if [ -f "$LOGDIR/$logfile" ] ; then
421 mv "$LOGDIR/$logfile" "$log_archive_dir/$logfile.${CURRENT_LOG_TIME}"
422 fi
423 done
424
425 # Install ovsdbapp from source if requested
426 if use_library_from_git "ovsdbapp"; then
427 git_clone_by_name "ovsdbapp"
428 setup_dev_lib "ovsdbapp"
429 fi
430
431 # Install ovs python module from ovs source.
432 if [[ "$OVN_INSTALL_OVS_PYTHON_MODULE" == "True" ]]; then
433 sudo pip uninstall -y ovs
434 # Clone the OVS repository if it's not yet present
435 clone_repository $OVS_REPO $DEST/$OVS_REPO_NAME $OVS_BRANCH
436 sudo pip install -e $DEST/$OVS_REPO_NAME/python
437 fi
438}
439
440# filter_network_api_extensions() - Remove non-supported API extensions by
441# the OVN driver from the list of enabled API extensions
442function filter_network_api_extensions {
443 SUPPORTED_NETWORK_API_EXTENSIONS=$($PYTHON -c \
444 'from neutron.common.ovn import extensions ;\
445 print(",".join(extensions.ML2_SUPPORTED_API_EXTENSIONS))')
446 SUPPORTED_NETWORK_API_EXTENSIONS=$SUPPORTED_NETWORK_API_EXTENSIONS,$($PYTHON -c \
447 'from neutron.common.ovn import extensions ;\
448 print(",".join(extensions.ML2_SUPPORTED_API_EXTENSIONS_OVN_L3))')
449 if is_service_enabled q-qos neutron-qos ; then
450 SUPPORTED_NETWORK_API_EXTENSIONS="$SUPPORTED_NETWORK_API_EXTENSIONS,qos"
451 fi
452 NETWORK_API_EXTENSIONS=${NETWORK_API_EXTENSIONS:-$SUPPORTED_NETWORK_API_EXTENSIONS}
453 extensions=$(echo $NETWORK_API_EXTENSIONS | tr ', ' '\n' | sort -u)
454 supported_ext=$(echo $SUPPORTED_NETWORK_API_EXTENSIONS | tr ', ' '\n' | sort -u)
455 enabled_ext=$(comm -12 <(echo -e "$extensions") <(echo -e "$supported_ext"))
456 disabled_ext=$(comm -3 <(echo -e "$extensions") <(echo -e "$enabled_ext"))
457
458 # Log a message in case some extensions had to be disabled because
459 # they are not supported by the OVN driver
460 if [ ! -z "$disabled_ext" ]; then
461 _disabled=$(echo $disabled_ext | tr ' ' ',')
462 echo "The folling network API extensions have been disabled because they are not supported by OVN: $_disabled"
463 fi
464
465 # Export the final list of extensions that have been enabled and are
466 # supported by OVN
467 export NETWORK_API_EXTENSIONS=$(echo $enabled_ext | tr ' ' ',')
468}
469
470function configure_ovn_plugin {
471 echo "Configuring Neutron for OVN"
472
473 if is_service_enabled q-svc ; then
474 filter_network_api_extensions
475 populate_ml2_config /$Q_PLUGIN_CONF_FILE ml2_type_geneve max_header_size=$OVN_GENEVE_OVERHEAD
476 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_nb_connection="$OVN_NB_REMOTE"
477 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_sb_connection="$OVN_SB_REMOTE"
478 if is_service_enabled tls-proxy; then
479 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_sb_ca_cert="$INT_CA_DIR/ca-chain.pem"
480 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_sb_certificate="$INT_CA_DIR/$DEVSTACK_CERT_NAME.crt"
481 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_sb_private_key="$INT_CA_DIR/private/$DEVSTACK_CERT_NAME.key"
482 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_nb_ca_cert="$INT_CA_DIR/ca-chain.pem"
483 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_nb_certificate="$INT_CA_DIR/$DEVSTACK_CERT_NAME.crt"
484 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_nb_private_key="$INT_CA_DIR/private/$DEVSTACK_CERT_NAME.key"
485 fi
486 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn neutron_sync_mode="$OVN_NEUTRON_SYNC_MODE"
487 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_l3_scheduler="$OVN_L3_SCHEDULER"
488 populate_ml2_config /$Q_PLUGIN_CONF_FILE securitygroup enable_security_group="$Q_USE_SECGROUP"
489 inicomment /$Q_PLUGIN_CONF_FILE securitygroup firewall_driver
490
491 if is_service_enabled q-ovn-metadata-agent; then
492 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_metadata_enabled=True
493 else
494 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_metadata_enabled=False
495 fi
496
497 if is_service_enabled q-dns neutron-dns ; then
498 iniset $NEUTRON_CONF DEFAULT dns_domain openstackgate.local
499 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn dns_servers="$OVN_DNS_SERVERS"
500 fi
501
502 iniset $NEUTRON_CONF ovs igmp_snooping_enable $OVN_IGMP_SNOOPING_ENABLE
503 fi
504
505 if is_service_enabled q-dhcp neutron-dhcp ; then
506 iniset $NEUTRON_CONF DEFAULT dhcp_agent_notification True
507 else
508 iniset $NEUTRON_CONF DEFAULT dhcp_agent_notification False
509 fi
510
511 if is_service_enabled n-api-meta ; then
512 if is_service_enabled q-ovn-metadata-agent ; then
513 iniset $NOVA_CONF neutron service_metadata_proxy True
514 fi
515 fi
516}
517
518function configure_ovn {
519 echo "Configuring OVN"
520
521 if [ -z "$OVN_UUID" ] ; then
522 if [ -f ./ovn-uuid ] ; then
523 OVN_UUID=$(cat ovn-uuid)
524 else
525 OVN_UUID=$(uuidgen)
526 echo $OVN_UUID > ovn-uuid
527 fi
528 fi
529
530 # Metadata
531 if is_service_enabled q-ovn-metadata-agent && is_service_enabled ovn-controller; then
532 sudo install -d -o $STACK_USER $NEUTRON_CONF_DIR
533
534 mkdir -p $NEUTRON_DIR/etc/neutron/plugins/ml2
535 (cd $NEUTRON_DIR && exec ./tools/generate_config_file_samples.sh)
536
537 cp $NEUTRON_DIR/etc/neutron_ovn_metadata_agent.ini.sample $OVN_META_CONF
538 configure_root_helper_options $OVN_META_CONF
539
540 iniset $OVN_META_CONF DEFAULT debug $ENABLE_DEBUG_LOG_LEVEL
541 iniset $OVN_META_CONF DEFAULT nova_metadata_host $OVN_META_DATA_HOST
542 iniset $OVN_META_CONF DEFAULT metadata_workers $API_WORKERS
543 iniset $OVN_META_CONF DEFAULT state_path $NEUTRON_STATE_PATH
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000544 iniset $OVN_META_CONF ovs ovsdb_connection tcp:$OVSDB_SERVER_LOCAL_HOST:6640
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100545 iniset $OVN_META_CONF ovn ovn_sb_connection $OVN_SB_REMOTE
546 if is_service_enabled tls-proxy; then
547 iniset $OVN_META_CONF ovn \
548 ovn_sb_ca_cert $INT_CA_DIR/ca-chain.pem
549 iniset $OVN_META_CONF ovn \
550 ovn_sb_certificate $INT_CA_DIR/$DEVSTACK_CERT_NAME.crt
551 iniset $OVN_META_CONF ovn \
552 ovn_sb_private_key $INT_CA_DIR/private/$DEVSTACK_CERT_NAME.key
553 fi
554 fi
555}
556
557function init_ovn {
558 # clean up from previous (possibly aborted) runs
559 # create required data files
560
561 # Assumption: this is a dedicated test system and there is nothing important
562 # in the ovn, ovn-nb, or ovs databases. We're going to trash them and
563 # create new ones on each devstack run.
564
565 _disable_libvirt_apparmor
566
567 mkdir -p $OVN_DATADIR
568 mkdir -p $OVS_DATADIR
569
570 rm -f $OVS_DATADIR/*.db
571 rm -f $OVS_DATADIR/.*.db.~lock~
572 rm -f $OVN_DATADIR/*.db
573 rm -f $OVN_DATADIR/.*.db.~lock~
574}
575
576function _start_ovs {
577 echo "Starting OVS"
578 if is_service_enabled ovn-controller ovn-controller-vtep ovn-northd; then
579 # ovsdb-server and ovs-vswitchd are used privately in OVN as openvswitch service names.
580 enable_service ovsdb-server
581 enable_service ovs-vswitchd
582
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000583 if [[ "$OVN_BUILD_FROM_SOURCE" == "True" ]]; then
584 if [ ! -f $OVS_DATADIR/conf.db ]; then
585 ovsdb-tool create $OVS_DATADIR/conf.db $OVS_SHAREDIR/vswitch.ovsschema
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100586 fi
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100587
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000588 if is_service_enabled ovn-controller-vtep; then
589 if [ ! -f $OVS_DATADIR/vtep.db ]; then
590 ovsdb-tool create $OVS_DATADIR/vtep.db $OVS_SHAREDIR/vtep.ovsschema
591 fi
592 fi
593
594 local dbcmd="$OVS_SBINDIR/ovsdb-server --remote=punix:$OVS_RUNDIR/db.sock --remote=ptcp:6640:$OVSDB_SERVER_LOCAL_HOST --pidfile --detach --log-file"
595 dbcmd+=" --remote=db:Open_vSwitch,Open_vSwitch,manager_options"
596 if is_service_enabled ovn-controller-vtep; then
597 dbcmd+=" --remote=db:hardware_vtep,Global,managers $OVS_DATADIR/vtep.db"
598 fi
599 dbcmd+=" $OVS_DATADIR/conf.db"
600 _run_process ovsdb-server "$dbcmd"
601
602 # Note: ovn-controller will create and configure br-int once it is started.
603 # So, no need to create it now because nothing depends on that bridge here.
604 local ovscmd="$OVS_SBINDIR/ovs-vswitchd --log-file --pidfile --detach"
605 _run_process ovs-vswitchd "$ovscmd" "" "$STACK_GROUP" "root"
606 else
607 _start_process "$OVSDB_SERVER_SERVICE"
608 _start_process "$OVS_VSWITCHD_SERVICE"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100609 fi
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100610
611 echo "Configuring OVSDB"
612 if is_service_enabled tls-proxy; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000613 sudo ovs-vsctl --no-wait set-ssl \
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100614 $INT_CA_DIR/private/$DEVSTACK_CERT_NAME.key \
615 $INT_CA_DIR/$DEVSTACK_CERT_NAME.crt \
616 $INT_CA_DIR/ca-chain.pem
617 fi
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000618
619 sudo ovs-vsctl --no-wait set-manager ptcp:6640:$OVSDB_SERVER_LOCAL_HOST
620 sudo ovs-vsctl --no-wait set open_vswitch . system-type="devstack"
621 sudo ovs-vsctl --no-wait set open_vswitch . external-ids:system-id="$OVN_UUID"
622 sudo ovs-vsctl --no-wait set open_vswitch . external-ids:ovn-remote="$OVN_SB_REMOTE"
623 sudo ovs-vsctl --no-wait set open_vswitch . external-ids:ovn-bridge="br-int"
624 sudo ovs-vsctl --no-wait set open_vswitch . external-ids:ovn-encap-type="geneve"
625 sudo ovs-vsctl --no-wait set open_vswitch . external-ids:ovn-encap-ip="$HOST_IP"
626 sudo ovs-vsctl --no-wait set open_vswitch . external-ids:hostname="$LOCAL_HOSTNAME"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100627 # Select this chassis to host gateway routers
628 if [[ "$ENABLE_CHASSIS_AS_GW" == "True" ]]; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000629 sudo ovs-vsctl --no-wait set open_vswitch . external-ids:ovn-cms-options="enable-chassis-as-gw"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100630 fi
631
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100632 if is_provider_network || [[ $Q_USE_PROVIDERNET_FOR_PUBLIC == "True" ]]; then
633 ovn_base_setup_bridge $OVS_PHYSICAL_BRIDGE
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000634 sudo ovs-vsctl set open . external-ids:ovn-bridge-mappings=${PHYSICAL_NETWORK}:${OVS_PHYSICAL_BRIDGE}
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100635 fi
636
637 if is_service_enabled ovn-controller-vtep ; then
638 ovn_base_setup_bridge br-v
639 vtep-ctl add-ps br-v
640 vtep-ctl set Physical_Switch br-v tunnel_ips=$HOST_IP
641
642 enable_service ovs-vtep
643 local vtepcmd="$OVS_SCRIPTDIR/ovs-vtep --log-file --pidfile --detach br-v"
644 _run_process ovs-vtep "$vtepcmd" "" "$STACK_GROUP" "root"
645
646 vtep-ctl set-manager tcp:$HOST_IP:6640
647 fi
648 fi
649}
650
651function _start_ovn_services {
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000652 _start_process "$OVSDB_SERVER_SERVICE"
653 _start_process "$OVS_VSWITCHD_SERVICE"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100654
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100655 if is_service_enabled ovn-northd ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000656 _start_process "$OVN_NORTHD_SERVICE"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100657 fi
658 if is_service_enabled ovn-controller ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000659 _start_process "$OVN_CONTROLLER_SERVICE"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100660 fi
661 if is_service_enabled ovn-controller-vtep ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000662 _start_process "$OVN_CONTROLLER_VTEP_SERVICE"
663 fi
664 if is_service_enabled ovs-vtep ; then
665 _start_process "devstack@ovs-vtep.service"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100666 fi
667 if is_service_enabled q-ovn-metadata-agent; then
668 _start_process "devstack@q-ovn-metadata-agent.service"
669 fi
670}
671
672# start_ovn() - Start running processes, including screen
673function start_ovn {
674 echo "Starting OVN"
675
676 _start_ovs
677
678 local SCRIPTDIR=$OVN_SCRIPTDIR
679 if ! use_new_ovn_repository; then
680 SCRIPTDIR=$OVS_SCRIPTDIR
681 fi
682
683 if is_service_enabled ovn-northd ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000684 if [[ "$OVN_BUILD_FROM_SOURCE" == "True" ]]; then
685 local cmd="/bin/bash $SCRIPTDIR/ovn-ctl --no-monitor start_northd"
686 local stop_cmd="/bin/bash $SCRIPTDIR/ovn-ctl stop_northd"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100687
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000688 _run_process ovn-northd "$cmd" "$stop_cmd"
689 else
690 _start_process "$OVN_NORTHD_SERVICE"
691 fi
692
693 # Wait for the service to be ready
694 wait_for_sock_file $OVS_RUNDIR/ovnnb_db.sock
695 wait_for_sock_file $OVS_RUNDIR/ovnsb_db.sock
696
697 if is_service_enabled tls-proxy; then
698 sudo ovn-nbctl --db=unix:$OVS_RUNDIR/ovnnb_db.sock set-ssl $INT_CA_DIR/private/$DEVSTACK_CERT_NAME.key $INT_CA_DIR/$DEVSTACK_CERT_NAME.crt $INT_CA_DIR/ca-chain.pem
699 sudo ovn-sbctl --db=unix:$OVS_RUNDIR/ovnsb_db.sock set-ssl $INT_CA_DIR/private/$DEVSTACK_CERT_NAME.key $INT_CA_DIR/$DEVSTACK_CERT_NAME.crt $INT_CA_DIR/ca-chain.pem
700 fi
701 sudo ovn-nbctl --db=unix:$OVS_RUNDIR/ovnnb_db.sock set-connection p${OVN_PROTO}:6641:$SERVICE_LISTEN_ADDRESS -- set connection . inactivity_probe=60000
702 sudo ovn-sbctl --db=unix:$OVS_RUNDIR/ovnsb_db.sock set-connection p${OVN_PROTO}:6642:$SERVICE_LISTEN_ADDRESS -- set connection . inactivity_probe=60000
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100703 sudo ovs-appctl -t $OVS_RUNDIR/ovnnb_db.ctl vlog/set console:off syslog:$OVN_DBS_LOG_LEVEL file:$OVN_DBS_LOG_LEVEL
704 sudo ovs-appctl -t $OVS_RUNDIR/ovnsb_db.ctl vlog/set console:off syslog:$OVN_DBS_LOG_LEVEL file:$OVN_DBS_LOG_LEVEL
705 fi
706
707 if is_service_enabled ovn-controller ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000708 if [[ "$OVN_BUILD_FROM_SOURCE" == "True" ]]; then
709 local cmd="/bin/bash $SCRIPTDIR/ovn-ctl --no-monitor start_controller"
710 local stop_cmd="/bin/bash $SCRIPTDIR/ovn-ctl stop_controller"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100711
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000712 _run_process ovn-controller "$cmd" "$stop_cmd" "$STACK_GROUP" "root"
713 else
714 _start_process "$OVN_CONTROLLER_SERVICE"
715 fi
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100716 fi
717
718 if is_service_enabled ovn-controller-vtep ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000719 if [[ "$OVN_BUILD_FROM_SOURCE" == "True" ]]; then
720 local cmd="$OVS_BINDIR/ovn-controller-vtep --log-file --pidfile --detach --ovnsb-db=$OVN_SB_REMOTE"
721 _run_process ovn-controller-vtep "$cmd" "" "$STACK_GROUP" "root"
722 else
723 _start_process "$OVN_CONTROLLER_VTEP_SERVICE"
724 fi
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100725 fi
726
727 if is_service_enabled q-ovn-metadata-agent; then
728 run_process q-ovn-metadata-agent "$NEUTRON_OVN_BIN_DIR/$NEUTRON_OVN_METADATA_BINARY --config-file $OVN_META_CONF"
729 # Format logging
730 setup_logging $OVN_META_CONF
731 fi
732
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100733 _start_ovn_services
734}
735
736function _stop_ovs_dp {
737 sudo ovs-dpctl dump-dps | sudo xargs -n1 ovs-dpctl del-dp
738 modprobe -q -r vport_geneve vport_vxlan openvswitch || true
739}
740
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000741function _stop_process {
742 local service=$1
743 echo "Stopping process $service"
744 if $SYSTEMCTL is-enabled $service; then
745 $SYSTEMCTL stop $service
746 $SYSTEMCTL disable $service
747 fi
748}
749
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100750function stop_ovn {
751 if is_service_enabled q-ovn-metadata-agent; then
752 sudo pkill -9 -f haproxy || :
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000753 _stop_process "devstack@q-ovn-metadata-agent.service"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100754 fi
755 if is_service_enabled ovn-controller-vtep ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000756 _stop_process "$OVN_CONTROLLER_VTEP_SERVICE"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100757 fi
758 if is_service_enabled ovn-controller ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000759 _stop_process "$OVN_CONTROLLER_SERVICE"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100760 fi
761 if is_service_enabled ovn-northd ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000762 _stop_process "$OVN_NORTHD_SERVICE"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100763 fi
764 if is_service_enabled ovs-vtep ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000765 _stop_process "devstack@ovs-vtep.service"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100766 fi
767
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000768 _stop_process "$OVS_VSWITCHD_SERVICE"
769 _stop_process "$OVSDB_SERVER_SERVICE"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100770
771 _stop_ovs_dp
772}
773
774function _cleanup {
775 local path=${1:-$DEST/$OVN_REPO_NAME}
776 pushd $path
777 cd $path
778 sudo make uninstall
779 sudo make distclean
780 popd
781}
782
783# cleanup_ovn() - Remove residual data files, anything left over from previous
784# runs that a clean run would need to clean up
785function cleanup_ovn {
786 local ovn_path=$DEST/$OVN_REPO_NAME
787 local ovs_path=$DEST/$OVS_REPO_NAME
788
789 if [ -d $ovn_path ]; then
790 _cleanup $ovn_path
791 fi
792
793 if [ -d $ovs_path ]; then
794 _cleanup $ovs_path
795 fi
796
797 sudo rm -f $OVN_RUNDIR
798}