blob: 1f737fb58b907dff5bf360eae3bcdcacc7a7f6ba [file] [log] [blame]
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +01001#!/bin/bash
2#
3# Licensed under the Apache License, Version 2.0 (the "License"); you may
4# not use this file except in compliance with the License. You may obtain
5# a copy of the License at
6#
7# http://www.apache.org/licenses/LICENSE-2.0
8#
9# Unless required by applicable law or agreed to in writing, software
10# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
11# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
12# License for the specific language governing permissions and limitations
13# under the License.
14#
15
16# Global Sources
17# --------------
18
19# There are some ovs functions OVN depends on that must be sourced from
20# the ovs neutron plugins.
21source ${TOP_DIR}/lib/neutron_plugins/ovs_base
22source ${TOP_DIR}/lib/neutron_plugins/openvswitch_agent
23
Ian Wienand77835632021-05-13 13:14:42 +100024# Load devstack ovs compliation and loading functions
25source ${TOP_DIR}/lib/neutron_plugins/ovs_source
26
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +010027# Defaults
28# --------
29
Slawek Kaplonski7ba26f52020-09-17 11:13:52 +020030Q_BUILD_OVS_FROM_GIT=$(trueorfalse True Q_BUILD_OVS_FROM_GIT)
31
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +010032# Set variables for building OVN from source
33OVN_REPO=${OVN_REPO:-https://github.com/ovn-org/ovn.git}
34OVN_REPO_NAME=$(basename ${OVN_REPO} | cut -f1 -d'.')
35OVN_REPO_NAME=${OVN_REPO_NAME:-ovn}
36OVN_BRANCH=${OVN_BRANCH:-v20.06.1}
37# The commit removing OVN bits from the OVS tree, it is the commit that is not
38# present in OVN tree and is used to distinguish if OVN is part of OVS or not.
39# https://github.com/openvswitch/ovs/commit/05bf1dbb98b0635a51f75e268ef8aed27601401d
40OVN_SPLIT_HASH=05bf1dbb98b0635a51f75e268ef8aed27601401d
41
42if is_service_enabled tls-proxy; then
43 OVN_PROTO=ssl
44else
45 OVN_PROTO=tcp
46fi
47
48# How to connect to ovsdb-server hosting the OVN SB database.
49OVN_SB_REMOTE=${OVN_SB_REMOTE:-$OVN_PROTO:$SERVICE_HOST:6642}
50
51# How to connect to ovsdb-server hosting the OVN NB database
52OVN_NB_REMOTE=${OVN_NB_REMOTE:-$OVN_PROTO:$SERVICE_HOST:6641}
53
54# ml2/config for neutron_sync_mode
55OVN_NEUTRON_SYNC_MODE=${OVN_NEUTRON_SYNC_MODE:-log}
56
57# Configured DNS servers to be used with internal_dns extension, only
58# if the subnet DNS is not configured.
59OVN_DNS_SERVERS=${OVN_DNS_SERVERS:-8.8.8.8}
60
61# The type of OVN L3 Scheduler to use. The OVN L3 Scheduler determines the
62# hypervisor/chassis where a routers gateway should be hosted in OVN. The
63# default OVN L3 scheduler is leastloaded
64OVN_L3_SCHEDULER=${OVN_L3_SCHEDULER:-leastloaded}
65
66# A UUID to uniquely identify this system. If one is not specified, a random
67# one will be generated. A randomly generated UUID will be saved in a file
Slawek Kaplonski1ed276c2021-03-11 13:10:28 +010068# $OVS_SYSCONFDIR/system-id.conf (typically /etc/openvswitch/system-id.conf)
69# so that the same one will be re-used if you re-run DevStack or restart
70# Open vSwitch service.
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +010071OVN_UUID=${OVN_UUID:-}
72
73# Whether or not to build the openvswitch kernel module from ovs. This is required
74# unless the distro kernel includes ovs+conntrack support.
75OVN_BUILD_MODULES=$(trueorfalse False OVN_BUILD_MODULES)
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +000076OVN_BUILD_FROM_SOURCE=$(trueorfalse False OVN_BUILD_FROM_SOURCE)
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +010077
78# Whether or not to install the ovs python module from ovs source. This can be
79# used to test and validate new ovs python features. This should only be used
80# for development purposes since the ovs python version is controlled by OpenStack
81# requirements.
82OVN_INSTALL_OVS_PYTHON_MODULE=$(trueorfalse False OVN_INSTALL_OVS_PYTHON_MODULE)
83
84# GENEVE overlay protocol overhead. Defaults to 38 bytes plus the IP version
85# overhead (20 bytes for IPv4 (default) or 40 bytes for IPv6) which is determined
86# based on the ML2 overlay_ip_version option. The ML2 framework will use this to
87# configure the MTU DHCP option.
88OVN_GENEVE_OVERHEAD=${OVN_GENEVE_OVERHEAD:-38}
89
Lucas Alvares Gomese38a39a2021-05-14 09:14:24 +010090# The log level of the OVN databases (north and south).
91# Supported log levels are: off, emer, err, warn, info or dbg.
92# More information about log levels can be found at
93# http://www.openvswitch.org/support/dist-docs/ovs-appctl.8.txt
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +010094OVN_DBS_LOG_LEVEL=${OVN_DBS_LOG_LEVEL:-info}
95
96OVN_META_CONF=$NEUTRON_CONF_DIR/neutron_ovn_metadata_agent.ini
97OVN_META_DATA_HOST=${OVN_META_DATA_HOST:-$(ipv6_unquote $SERVICE_HOST)}
98
Lucas Alvares Gomese38a39a2021-05-14 09:14:24 +010099# If True (default) the node will be considered a gateway node.
100ENABLE_CHASSIS_AS_GW=$(trueorfalse True ENABLE_CHASSIS_AS_GW)
Lucas Alvares Gomes22038a92021-05-27 13:44:20 +0100101OVN_L3_CREATE_PUBLIC_NETWORK=$(trueorfalse True OVN_L3_CREATE_PUBLIC_NETWORK)
Lucas Alvares Gomese38a39a2021-05-14 09:14:24 +0100102
Lucas Alvares Gomes6ecfe672020-09-23 11:54:19 +0100103export OVSDB_SERVER_LOCAL_HOST=$SERVICE_LOCAL_HOST
104if [[ "$SERVICE_IP_VERSION" == 6 ]]; then
105 OVSDB_SERVER_LOCAL_HOST=[$OVSDB_SERVER_LOCAL_HOST]
106fi
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100107
108OVN_IGMP_SNOOPING_ENABLE=$(trueorfalse False OVN_IGMP_SNOOPING_ENABLE)
109
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000110OVS_PREFIX=
111if [[ "$OVN_BUILD_FROM_SOURCE" == "True" ]]; then
112 OVS_PREFIX=/usr/local
113fi
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100114OVS_SBINDIR=$OVS_PREFIX/sbin
115OVS_BINDIR=$OVS_PREFIX/bin
116OVS_RUNDIR=$OVS_PREFIX/var/run/openvswitch
117OVS_SHAREDIR=$OVS_PREFIX/share/openvswitch
118OVS_SCRIPTDIR=$OVS_SHAREDIR/scripts
119OVS_DATADIR=$DATA_DIR/ovs
Rodolfo Alonso Hernandez30819e62021-03-22 07:14:50 +0000120OVS_SYSCONFDIR=${OVS_SYSCONFDIR:-$OVS_PREFIX/etc/openvswitch}
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100121
122OVN_DATADIR=$DATA_DIR/ovn
123OVN_SHAREDIR=$OVS_PREFIX/share/ovn
124OVN_SCRIPTDIR=$OVN_SHAREDIR/scripts
125OVN_RUNDIR=$OVS_PREFIX/var/run/ovn
126
127NEUTRON_OVN_BIN_DIR=$(get_python_exec_prefix)
128NEUTRON_OVN_METADATA_BINARY="neutron-ovn-metadata-agent"
129
130STACK_GROUP="$( id --group --name "$STACK_USER" )"
131
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000132OVN_NORTHD_SERVICE=ovn-northd.service
133if is_ubuntu; then
134 # The ovn-central.service file on Ubuntu is responsible for starting
135 # ovn-northd and the OVN DBs (on CentOS this is done by ovn-northd.service)
136 OVN_NORTHD_SERVICE=ovn-central.service
137fi
138OVSDB_SERVER_SERVICE=ovsdb-server.service
139OVS_VSWITCHD_SERVICE=ovs-vswitchd.service
140OVN_CONTROLLER_SERVICE=ovn-controller.service
141OVN_CONTROLLER_VTEP_SERVICE=ovn-controller-vtep.service
142if [[ "$OVN_BUILD_FROM_SOURCE" == "True" ]]; then
143 OVSDB_SERVER_SERVICE=devstack@ovsdb-server.service
144 OVS_VSWITCHD_SERVICE=devstack@ovs-vswitchd.service
145 OVN_NORTHD_SERVICE=devstack@ovn-northd.service
146 OVN_CONTROLLER_SERVICE=devstack@ovn-controller.service
147 OVN_CONTROLLER_VTEP_SERVICE=devstack@ovn-controller-vtep.service
148fi
149
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100150# Defaults Overwrite
151# ------------------
152
153Q_ML2_PLUGIN_MECHANISM_DRIVERS=${Q_ML2_PLUGIN_MECHANISM_DRIVERS:-ovn,logger}
154Q_ML2_PLUGIN_TYPE_DRIVERS=${Q_ML2_PLUGIN_TYPE_DRIVERS:-local,flat,vlan,geneve}
155Q_ML2_TENANT_NETWORK_TYPE=${Q_ML2_TENANT_NETWORK_TYPE:-"geneve"}
156Q_ML2_PLUGIN_GENEVE_TYPE_OPTIONS=${Q_ML2_PLUGIN_GENEVE_TYPE_OPTIONS:-"vni_ranges=1:65536"}
Lucas Alvares Gomese7625fc2020-08-26 09:46:35 +0100157Q_ML2_PLUGIN_EXT_DRIVERS=${Q_ML2_PLUGIN_EXT_DRIVERS:-port_security,qos}
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100158# this one allows empty:
159ML2_L3_PLUGIN=${ML2_L3_PLUGIN-"ovn-router"}
160
Flavio Fernandesa2273cc2021-02-06 16:23:36 -0500161Q_LOG_DRIVER_RATE_LIMIT=${Q_LOG_DRIVER_RATE_LIMIT:-100}
162Q_LOG_DRIVER_BURST_LIMIT=${Q_LOG_DRIVER_BURST_LIMIT:-25}
163Q_LOG_DRIVER_LOG_BASE=${Q_LOG_DRIVER_LOG_BASE:-acl_log_meter}
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100164
165# Utility Functions
166# -----------------
167
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000168function wait_for_sock_file {
169 local count=0
170 while [ ! -S $1 ]; do
171 sleep 1
172 count=$((count+1))
173 if [ "$count" -gt 5 ]; then
174 die $LINENO "Socket $1 not found"
175 fi
176 done
177}
178
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100179function use_new_ovn_repository {
Lucas Alvares Gomese38a39a2021-05-14 09:14:24 +0100180 if [[ "$OVN_BUILD_FROM_SOURCE" == "False" ]]; then
181 return 0
182 fi
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100183 if [ -z "$is_new_ovn" ]; then
184 local ovs_repo_dir=$DEST/$OVS_REPO_NAME
185 if [ ! -d $ovs_repo_dir ]; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000186 git_timed clone $OVS_REPO $ovs_repo_dir
187 pushd $ovs_repo_dir
188 git checkout $OVS_BRANCH
189 popd
190 else
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100191 clone_repository $OVS_REPO $ovs_repo_dir $OVS_BRANCH
192 fi
193 # Check the split commit exists in the current branch
194 pushd $ovs_repo_dir
195 git log $OVS_BRANCH --pretty=format:"%H" | grep -q $OVN_SPLIT_HASH
196 is_new_ovn=$?
197 popd
198 fi
199 return $is_new_ovn
200}
201
202# NOTE(rtheis): Function copied from DevStack _neutron_ovs_base_setup_bridge
203# and _neutron_ovs_base_add_bridge with the call to neutron-ovs-cleanup
204# removed. The call is not relevant for OVN, as it is specific to the use
205# of Neutron's OVS agent and hangs when running stack.sh because
206# neutron-ovs-cleanup uses the OVSDB native interface.
207function ovn_base_setup_bridge {
208 local bridge=$1
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000209 local addbr_cmd="sudo ovs-vsctl --no-wait -- --may-exist add-br $bridge -- set bridge $bridge protocols=OpenFlow13,OpenFlow15"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100210
211 if [ "$OVS_DATAPATH_TYPE" != "system" ] ; then
212 addbr_cmd="$addbr_cmd -- set Bridge $bridge datapath_type=${OVS_DATAPATH_TYPE}"
213 fi
214
215 $addbr_cmd
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000216 sudo ovs-vsctl --no-wait br-set-external-id $bridge bridge-id $bridge
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100217}
218
219function _start_process {
220 $SYSTEMCTL daemon-reload
221 $SYSTEMCTL enable $1
222 $SYSTEMCTL restart $1
223}
224
225function _run_process {
226 local service=$1
227 local cmd="$2"
228 local stop_cmd="$3"
229 local group=$4
230 local user=${5:-$STACK_USER}
231
232 local systemd_service="devstack@$service.service"
233 local unit_file="$SYSTEMD_DIR/$systemd_service"
234 local environment="OVN_RUNDIR=$OVS_RUNDIR OVN_DBDIR=$OVN_DATADIR OVN_LOGDIR=$LOGDIR OVS_RUNDIR=$OVS_RUNDIR OVS_DBDIR=$OVS_DATADIR OVS_LOGDIR=$LOGDIR"
235
236 echo "Starting $service executed command": $cmd
237
238 write_user_unit_file $systemd_service "$cmd" "$group" "$user"
239 iniset -sudo $unit_file "Service" "Type" "forking"
240 iniset -sudo $unit_file "Service" "RemainAfterExit" "yes"
241 iniset -sudo $unit_file "Service" "KillMode" "mixed"
242 iniset -sudo $unit_file "Service" "LimitNOFILE" "65536"
243 iniset -sudo $unit_file "Service" "Environment" "$environment"
244 if [ -n "$stop_cmd" ]; then
245 iniset -sudo $unit_file "Service" "ExecStop" "$stop_cmd"
246 fi
247
248 _start_process $systemd_service
249
250 local testcmd="test -e $OVS_RUNDIR/$service.pid"
251 test_with_retry "$testcmd" "$service did not start" $SERVICE_TIMEOUT 1
252 sudo ovs-appctl -t $service vlog/set console:off syslog:info file:info
253}
254
255function clone_repository {
256 local repo=$1
257 local dir=$2
258 local branch=$3
259 # Set ERROR_ON_CLONE to false to avoid the need of having the
260 # repositories like OVN and OVS in the required_projects of the job
261 # definition.
262 ERROR_ON_CLONE=false git_clone $repo $dir $branch
263}
264
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100265function create_public_bridge {
266 # Create the public bridge that OVN will use
Radosław Piliszek95298782021-06-08 16:19:40 +0000267 sudo ovs-vsctl --may-exist add-br $PUBLIC_BRIDGE -- set bridge $PUBLIC_BRIDGE protocols=OpenFlow13,OpenFlow15
268 sudo ovs-vsctl set open . external-ids:ovn-bridge-mappings=$PHYSICAL_NETWORK:$PUBLIC_BRIDGE
Slawek Kaplonskib1a89eb2021-08-26 21:42:32 +0200269 _configure_public_network_connectivity
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100270}
271
272function _disable_libvirt_apparmor {
273 if ! sudo aa-status --enabled ; then
274 return 0
275 fi
276 # NOTE(arosen): This is used as a work around to allow newer versions
277 # of libvirt to work with ovs configured ports. See LP#1466631.
278 # requires the apparmor-utils
279 install_package apparmor-utils
280 # disables apparmor for libvirtd
281 sudo aa-complain /etc/apparmor.d/usr.sbin.libvirtd
282}
283
284
285# OVN compilation functions
286# -------------------------
287
288
289# compile_ovn() - Compile OVN from source and load needed modules
290# Accepts three parameters:
291# - first optional is False by default and means that
292# modules are built and installed.
293# - second optional parameter defines prefix for
294# ovn compilation
295# - third optional parameter defines localstatedir for
296# ovn single machine runtime
297function compile_ovn {
298 local build_modules=${1:-False}
299 local prefix=$2
300 local localstatedir=$3
301
302 if [ -n "$prefix" ]; then
303 prefix="--prefix=$prefix"
304 fi
305
306 if [ -n "$localstatedir" ]; then
307 localstatedir="--localstatedir=$localstatedir"
308 fi
309
310 clone_repository $OVN_REPO $DEST/$OVN_REPO_NAME $OVN_BRANCH
311 pushd $DEST/$OVN_REPO_NAME
312
313 if [ ! -f configure ] ; then
314 ./boot.sh
315 fi
316
317 if [ ! -f config.status ] || [ configure -nt config.status ] ; then
318 ./configure --with-ovs-source=$DEST/$OVS_REPO_NAME $prefix $localstatedir
319 fi
320 make -j$(($(nproc) + 1))
321 sudo make install
322 popd
323}
324
325
326# OVN Neutron driver functions
327# ----------------------------
328
329# OVN service sanity check
330function ovn_sanity_check {
331 if is_service_enabled q-agt neutron-agt; then
332 die $LINENO "The q-agt/neutron-agt service must be disabled with OVN."
333 elif is_service_enabled q-l3 neutron-l3; then
334 die $LINENO "The q-l3/neutron-l3 service must be disabled with OVN."
335 elif is_service_enabled q-svc neutron-api && [[ ! $Q_ML2_PLUGIN_MECHANISM_DRIVERS =~ "ovn" ]]; then
336 die $LINENO "OVN needs to be enabled in \$Q_ML2_PLUGIN_MECHANISM_DRIVERS"
337 elif is_service_enabled q-svc neutron-api && [[ ! $Q_ML2_PLUGIN_TYPE_DRIVERS =~ "geneve" ]]; then
338 die $LINENO "Geneve needs to be enabled in \$Q_ML2_PLUGIN_TYPE_DRIVERS to be used with OVN"
339 fi
340}
341
342# install_ovn() - Collect source and prepare
343function install_ovn {
Slawek Kaplonski7ba26f52020-09-17 11:13:52 +0200344 if [[ "$Q_BUILD_OVS_FROM_GIT" == "False" ]]; then
345 echo "Installation of OVS from source disabled."
346 return 0
347 fi
348
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100349 echo "Installing OVN and dependent packages"
350
351 # Check the OVN configuration
352 ovn_sanity_check
353
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100354 # Install tox, used to generate the config (see devstack/override-defaults)
355 pip_install tox
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100356
357 sudo mkdir -p $OVS_RUNDIR
358 sudo chown $(whoami) $OVS_RUNDIR
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000359 # NOTE(lucasagomes): To keep things simpler, let's reuse the same
360 # RUNDIR for both OVS and OVN. This way we avoid having to specify the
361 # --db option in the ovn-{n,s}bctl commands while playing with DevStack
362 sudo ln -s $OVS_RUNDIR $OVN_RUNDIR
363
364 if [[ "$OVN_BUILD_FROM_SOURCE" == "True" ]]; then
365 # If OVS is already installed, remove it, because we're about to
366 # re-install it from source.
367 for package in openvswitch openvswitch-switch openvswitch-common; do
368 if is_package_installed $package ; then
369 uninstall_package $package
370 fi
371 done
372
373 remove_ovs_packages
374 sudo rm -f $OVS_RUNDIR/*
375
376 compile_ovs $OVN_BUILD_MODULES
377 if use_new_ovn_repository; then
378 compile_ovn $OVN_BUILD_MODULES
379 fi
380
381 sudo mkdir -p $OVS_PREFIX/var/log/openvswitch
382 sudo chown $(whoami) $OVS_PREFIX/var/log/openvswitch
383 sudo mkdir -p $OVS_PREFIX/var/log/ovn
384 sudo chown $(whoami) $OVS_PREFIX/var/log/ovn
385 else
386 fixup_ovn_centos
387 install_package $(get_packages openvswitch)
388 install_package $(get_packages ovn)
389 fi
390
391 # Ensure that the OVS commands are accessible in the PATH
392 export PATH=$OVS_BINDIR:$PATH
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100393
394 # Archive log files and create new
395 local log_archive_dir=$LOGDIR/archive
396 mkdir -p $log_archive_dir
397 for logfile in ovs-vswitchd.log ovn-northd.log ovn-controller.log ovn-controller-vtep.log ovs-vtep.log ovsdb-server.log ovsdb-server-nb.log ovsdb-server-sb.log; do
398 if [ -f "$LOGDIR/$logfile" ] ; then
399 mv "$LOGDIR/$logfile" "$log_archive_dir/$logfile.${CURRENT_LOG_TIME}"
400 fi
401 done
402
403 # Install ovsdbapp from source if requested
404 if use_library_from_git "ovsdbapp"; then
405 git_clone_by_name "ovsdbapp"
406 setup_dev_lib "ovsdbapp"
407 fi
408
409 # Install ovs python module from ovs source.
410 if [[ "$OVN_INSTALL_OVS_PYTHON_MODULE" == "True" ]]; then
411 sudo pip uninstall -y ovs
412 # Clone the OVS repository if it's not yet present
413 clone_repository $OVS_REPO $DEST/$OVS_REPO_NAME $OVS_BRANCH
414 sudo pip install -e $DEST/$OVS_REPO_NAME/python
415 fi
416}
417
418# filter_network_api_extensions() - Remove non-supported API extensions by
419# the OVN driver from the list of enabled API extensions
420function filter_network_api_extensions {
421 SUPPORTED_NETWORK_API_EXTENSIONS=$($PYTHON -c \
422 'from neutron.common.ovn import extensions ;\
423 print(",".join(extensions.ML2_SUPPORTED_API_EXTENSIONS))')
424 SUPPORTED_NETWORK_API_EXTENSIONS=$SUPPORTED_NETWORK_API_EXTENSIONS,$($PYTHON -c \
425 'from neutron.common.ovn import extensions ;\
426 print(",".join(extensions.ML2_SUPPORTED_API_EXTENSIONS_OVN_L3))')
427 if is_service_enabled q-qos neutron-qos ; then
428 SUPPORTED_NETWORK_API_EXTENSIONS="$SUPPORTED_NETWORK_API_EXTENSIONS,qos"
429 fi
430 NETWORK_API_EXTENSIONS=${NETWORK_API_EXTENSIONS:-$SUPPORTED_NETWORK_API_EXTENSIONS}
431 extensions=$(echo $NETWORK_API_EXTENSIONS | tr ', ' '\n' | sort -u)
432 supported_ext=$(echo $SUPPORTED_NETWORK_API_EXTENSIONS | tr ', ' '\n' | sort -u)
433 enabled_ext=$(comm -12 <(echo -e "$extensions") <(echo -e "$supported_ext"))
434 disabled_ext=$(comm -3 <(echo -e "$extensions") <(echo -e "$enabled_ext"))
435
436 # Log a message in case some extensions had to be disabled because
437 # they are not supported by the OVN driver
438 if [ ! -z "$disabled_ext" ]; then
439 _disabled=$(echo $disabled_ext | tr ' ' ',')
440 echo "The folling network API extensions have been disabled because they are not supported by OVN: $_disabled"
441 fi
442
443 # Export the final list of extensions that have been enabled and are
444 # supported by OVN
445 export NETWORK_API_EXTENSIONS=$(echo $enabled_ext | tr ' ' ',')
446}
447
448function configure_ovn_plugin {
449 echo "Configuring Neutron for OVN"
450
451 if is_service_enabled q-svc ; then
452 filter_network_api_extensions
453 populate_ml2_config /$Q_PLUGIN_CONF_FILE ml2_type_geneve max_header_size=$OVN_GENEVE_OVERHEAD
454 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_nb_connection="$OVN_NB_REMOTE"
455 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_sb_connection="$OVN_SB_REMOTE"
456 if is_service_enabled tls-proxy; then
457 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_sb_ca_cert="$INT_CA_DIR/ca-chain.pem"
458 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_sb_certificate="$INT_CA_DIR/$DEVSTACK_CERT_NAME.crt"
459 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_sb_private_key="$INT_CA_DIR/private/$DEVSTACK_CERT_NAME.key"
460 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_nb_ca_cert="$INT_CA_DIR/ca-chain.pem"
461 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_nb_certificate="$INT_CA_DIR/$DEVSTACK_CERT_NAME.crt"
462 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_nb_private_key="$INT_CA_DIR/private/$DEVSTACK_CERT_NAME.key"
463 fi
464 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn neutron_sync_mode="$OVN_NEUTRON_SYNC_MODE"
465 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_l3_scheduler="$OVN_L3_SCHEDULER"
466 populate_ml2_config /$Q_PLUGIN_CONF_FILE securitygroup enable_security_group="$Q_USE_SECGROUP"
467 inicomment /$Q_PLUGIN_CONF_FILE securitygroup firewall_driver
468
Flavio Fernandesa2273cc2021-02-06 16:23:36 -0500469 if is_service_enabled q-log neutron-log; then
470 populate_ml2_config /$Q_PLUGIN_CONF_FILE network_log rate_limit="$Q_LOG_DRIVER_RATE_LIMIT"
471 populate_ml2_config /$Q_PLUGIN_CONF_FILE network_log burst_limit="$Q_LOG_DRIVER_BURST_LIMIT"
472 inicomment /$Q_PLUGIN_CONF_FILE network_log local_output_log_base="$Q_LOG_DRIVER_LOG_BASE"
473 fi
474
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100475 if is_service_enabled q-ovn-metadata-agent; then
476 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_metadata_enabled=True
477 else
478 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_metadata_enabled=False
479 fi
480
481 if is_service_enabled q-dns neutron-dns ; then
482 iniset $NEUTRON_CONF DEFAULT dns_domain openstackgate.local
483 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn dns_servers="$OVN_DNS_SERVERS"
484 fi
485
486 iniset $NEUTRON_CONF ovs igmp_snooping_enable $OVN_IGMP_SNOOPING_ENABLE
487 fi
488
489 if is_service_enabled q-dhcp neutron-dhcp ; then
490 iniset $NEUTRON_CONF DEFAULT dhcp_agent_notification True
491 else
492 iniset $NEUTRON_CONF DEFAULT dhcp_agent_notification False
493 fi
494
495 if is_service_enabled n-api-meta ; then
496 if is_service_enabled q-ovn-metadata-agent ; then
497 iniset $NOVA_CONF neutron service_metadata_proxy True
498 fi
499 fi
500}
501
502function configure_ovn {
503 echo "Configuring OVN"
504
505 if [ -z "$OVN_UUID" ] ; then
Slawek Kaplonski1ed276c2021-03-11 13:10:28 +0100506 if [ -f $OVS_SYSCONFDIR/system-id.conf ]; then
507 OVN_UUID=$(cat $OVS_SYSCONFDIR/system-id.conf)
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100508 else
509 OVN_UUID=$(uuidgen)
Slawek Kaplonski1ed276c2021-03-11 13:10:28 +0100510 echo $OVN_UUID | sudo tee $OVS_SYSCONFDIR/system-id.conf
511 fi
512 else
513 local ovs_uuid
514 ovs_uuid=$(cat $OVS_SYSCONFDIR/system-id.conf)
515 if [ "$ovs_uuid" != $OVN_UUID ]; then
516 echo $OVN_UUID | sudo tee $OVS_SYSCONFDIR/system-id.conf
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100517 fi
518 fi
519
Lucas Alvares Gomes8903d8c2021-01-15 09:26:44 +0000520 # Erase the pre-set configurations from packages. DevStack will
521 # configure OVS and OVN accordingly for its use.
522 if [[ "$OVN_BUILD_FROM_SOURCE" == "False" ]] && is_fedora; then
523 sudo truncate -s 0 /etc/openvswitch/default.conf
524 sudo truncate -s 0 /etc/sysconfig/openvswitch
525 sudo truncate -s 0 /etc/sysconfig/ovn
526 fi
527
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100528 # Metadata
529 if is_service_enabled q-ovn-metadata-agent && is_service_enabled ovn-controller; then
530 sudo install -d -o $STACK_USER $NEUTRON_CONF_DIR
531
532 mkdir -p $NEUTRON_DIR/etc/neutron/plugins/ml2
533 (cd $NEUTRON_DIR && exec ./tools/generate_config_file_samples.sh)
534
535 cp $NEUTRON_DIR/etc/neutron_ovn_metadata_agent.ini.sample $OVN_META_CONF
536 configure_root_helper_options $OVN_META_CONF
537
538 iniset $OVN_META_CONF DEFAULT debug $ENABLE_DEBUG_LOG_LEVEL
539 iniset $OVN_META_CONF DEFAULT nova_metadata_host $OVN_META_DATA_HOST
540 iniset $OVN_META_CONF DEFAULT metadata_workers $API_WORKERS
541 iniset $OVN_META_CONF DEFAULT state_path $NEUTRON_STATE_PATH
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000542 iniset $OVN_META_CONF ovs ovsdb_connection tcp:$OVSDB_SERVER_LOCAL_HOST:6640
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100543 iniset $OVN_META_CONF ovn ovn_sb_connection $OVN_SB_REMOTE
544 if is_service_enabled tls-proxy; then
545 iniset $OVN_META_CONF ovn \
546 ovn_sb_ca_cert $INT_CA_DIR/ca-chain.pem
547 iniset $OVN_META_CONF ovn \
548 ovn_sb_certificate $INT_CA_DIR/$DEVSTACK_CERT_NAME.crt
549 iniset $OVN_META_CONF ovn \
550 ovn_sb_private_key $INT_CA_DIR/private/$DEVSTACK_CERT_NAME.key
551 fi
552 fi
553}
554
555function init_ovn {
556 # clean up from previous (possibly aborted) runs
557 # create required data files
558
559 # Assumption: this is a dedicated test system and there is nothing important
560 # in the ovn, ovn-nb, or ovs databases. We're going to trash them and
561 # create new ones on each devstack run.
562
563 _disable_libvirt_apparmor
564
565 mkdir -p $OVN_DATADIR
566 mkdir -p $OVS_DATADIR
567
568 rm -f $OVS_DATADIR/*.db
569 rm -f $OVS_DATADIR/.*.db.~lock~
570 rm -f $OVN_DATADIR/*.db
571 rm -f $OVN_DATADIR/.*.db.~lock~
572}
573
574function _start_ovs {
575 echo "Starting OVS"
576 if is_service_enabled ovn-controller ovn-controller-vtep ovn-northd; then
577 # ovsdb-server and ovs-vswitchd are used privately in OVN as openvswitch service names.
578 enable_service ovsdb-server
579 enable_service ovs-vswitchd
580
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000581 if [[ "$OVN_BUILD_FROM_SOURCE" == "True" ]]; then
582 if [ ! -f $OVS_DATADIR/conf.db ]; then
583 ovsdb-tool create $OVS_DATADIR/conf.db $OVS_SHAREDIR/vswitch.ovsschema
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100584 fi
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100585
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000586 if is_service_enabled ovn-controller-vtep; then
587 if [ ! -f $OVS_DATADIR/vtep.db ]; then
588 ovsdb-tool create $OVS_DATADIR/vtep.db $OVS_SHAREDIR/vtep.ovsschema
589 fi
590 fi
591
592 local dbcmd="$OVS_SBINDIR/ovsdb-server --remote=punix:$OVS_RUNDIR/db.sock --remote=ptcp:6640:$OVSDB_SERVER_LOCAL_HOST --pidfile --detach --log-file"
593 dbcmd+=" --remote=db:Open_vSwitch,Open_vSwitch,manager_options"
594 if is_service_enabled ovn-controller-vtep; then
595 dbcmd+=" --remote=db:hardware_vtep,Global,managers $OVS_DATADIR/vtep.db"
596 fi
597 dbcmd+=" $OVS_DATADIR/conf.db"
598 _run_process ovsdb-server "$dbcmd"
599
600 # Note: ovn-controller will create and configure br-int once it is started.
601 # So, no need to create it now because nothing depends on that bridge here.
602 local ovscmd="$OVS_SBINDIR/ovs-vswitchd --log-file --pidfile --detach"
603 _run_process ovs-vswitchd "$ovscmd" "" "$STACK_GROUP" "root"
604 else
605 _start_process "$OVSDB_SERVER_SERVICE"
606 _start_process "$OVS_VSWITCHD_SERVICE"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100607 fi
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100608
609 echo "Configuring OVSDB"
610 if is_service_enabled tls-proxy; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000611 sudo ovs-vsctl --no-wait set-ssl \
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100612 $INT_CA_DIR/private/$DEVSTACK_CERT_NAME.key \
613 $INT_CA_DIR/$DEVSTACK_CERT_NAME.crt \
614 $INT_CA_DIR/ca-chain.pem
615 fi
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000616
617 sudo ovs-vsctl --no-wait set-manager ptcp:6640:$OVSDB_SERVER_LOCAL_HOST
618 sudo ovs-vsctl --no-wait set open_vswitch . system-type="devstack"
619 sudo ovs-vsctl --no-wait set open_vswitch . external-ids:system-id="$OVN_UUID"
620 sudo ovs-vsctl --no-wait set open_vswitch . external-ids:ovn-remote="$OVN_SB_REMOTE"
621 sudo ovs-vsctl --no-wait set open_vswitch . external-ids:ovn-bridge="br-int"
622 sudo ovs-vsctl --no-wait set open_vswitch . external-ids:ovn-encap-type="geneve"
623 sudo ovs-vsctl --no-wait set open_vswitch . external-ids:ovn-encap-ip="$HOST_IP"
624 sudo ovs-vsctl --no-wait set open_vswitch . external-ids:hostname="$LOCAL_HOSTNAME"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100625 # Select this chassis to host gateway routers
626 if [[ "$ENABLE_CHASSIS_AS_GW" == "True" ]]; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000627 sudo ovs-vsctl --no-wait set open_vswitch . external-ids:ovn-cms-options="enable-chassis-as-gw"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100628 fi
629
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100630 if is_provider_network || [[ $Q_USE_PROVIDERNET_FOR_PUBLIC == "True" ]]; then
631 ovn_base_setup_bridge $OVS_PHYSICAL_BRIDGE
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000632 sudo ovs-vsctl set open . external-ids:ovn-bridge-mappings=${PHYSICAL_NETWORK}:${OVS_PHYSICAL_BRIDGE}
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100633 fi
634
635 if is_service_enabled ovn-controller-vtep ; then
636 ovn_base_setup_bridge br-v
637 vtep-ctl add-ps br-v
638 vtep-ctl set Physical_Switch br-v tunnel_ips=$HOST_IP
639
640 enable_service ovs-vtep
641 local vtepcmd="$OVS_SCRIPTDIR/ovs-vtep --log-file --pidfile --detach br-v"
642 _run_process ovs-vtep "$vtepcmd" "" "$STACK_GROUP" "root"
643
644 vtep-ctl set-manager tcp:$HOST_IP:6640
645 fi
646 fi
647}
648
649function _start_ovn_services {
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000650 _start_process "$OVSDB_SERVER_SERVICE"
651 _start_process "$OVS_VSWITCHD_SERVICE"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100652
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100653 if is_service_enabled ovn-northd ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000654 _start_process "$OVN_NORTHD_SERVICE"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100655 fi
656 if is_service_enabled ovn-controller ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000657 _start_process "$OVN_CONTROLLER_SERVICE"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100658 fi
659 if is_service_enabled ovn-controller-vtep ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000660 _start_process "$OVN_CONTROLLER_VTEP_SERVICE"
661 fi
662 if is_service_enabled ovs-vtep ; then
663 _start_process "devstack@ovs-vtep.service"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100664 fi
665 if is_service_enabled q-ovn-metadata-agent; then
666 _start_process "devstack@q-ovn-metadata-agent.service"
667 fi
668}
669
670# start_ovn() - Start running processes, including screen
671function start_ovn {
672 echo "Starting OVN"
673
674 _start_ovs
675
676 local SCRIPTDIR=$OVN_SCRIPTDIR
677 if ! use_new_ovn_repository; then
678 SCRIPTDIR=$OVS_SCRIPTDIR
679 fi
680
681 if is_service_enabled ovn-northd ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000682 if [[ "$OVN_BUILD_FROM_SOURCE" == "True" ]]; then
683 local cmd="/bin/bash $SCRIPTDIR/ovn-ctl --no-monitor start_northd"
684 local stop_cmd="/bin/bash $SCRIPTDIR/ovn-ctl stop_northd"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100685
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000686 _run_process ovn-northd "$cmd" "$stop_cmd"
687 else
688 _start_process "$OVN_NORTHD_SERVICE"
689 fi
690
691 # Wait for the service to be ready
692 wait_for_sock_file $OVS_RUNDIR/ovnnb_db.sock
693 wait_for_sock_file $OVS_RUNDIR/ovnsb_db.sock
694
695 if is_service_enabled tls-proxy; then
696 sudo ovn-nbctl --db=unix:$OVS_RUNDIR/ovnnb_db.sock set-ssl $INT_CA_DIR/private/$DEVSTACK_CERT_NAME.key $INT_CA_DIR/$DEVSTACK_CERT_NAME.crt $INT_CA_DIR/ca-chain.pem
697 sudo ovn-sbctl --db=unix:$OVS_RUNDIR/ovnsb_db.sock set-ssl $INT_CA_DIR/private/$DEVSTACK_CERT_NAME.key $INT_CA_DIR/$DEVSTACK_CERT_NAME.crt $INT_CA_DIR/ca-chain.pem
698 fi
699 sudo ovn-nbctl --db=unix:$OVS_RUNDIR/ovnnb_db.sock set-connection p${OVN_PROTO}:6641:$SERVICE_LISTEN_ADDRESS -- set connection . inactivity_probe=60000
700 sudo ovn-sbctl --db=unix:$OVS_RUNDIR/ovnsb_db.sock set-connection p${OVN_PROTO}:6642:$SERVICE_LISTEN_ADDRESS -- set connection . inactivity_probe=60000
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100701 sudo ovs-appctl -t $OVS_RUNDIR/ovnnb_db.ctl vlog/set console:off syslog:$OVN_DBS_LOG_LEVEL file:$OVN_DBS_LOG_LEVEL
702 sudo ovs-appctl -t $OVS_RUNDIR/ovnsb_db.ctl vlog/set console:off syslog:$OVN_DBS_LOG_LEVEL file:$OVN_DBS_LOG_LEVEL
703 fi
704
705 if is_service_enabled ovn-controller ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000706 if [[ "$OVN_BUILD_FROM_SOURCE" == "True" ]]; then
707 local cmd="/bin/bash $SCRIPTDIR/ovn-ctl --no-monitor start_controller"
708 local stop_cmd="/bin/bash $SCRIPTDIR/ovn-ctl stop_controller"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100709
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000710 _run_process ovn-controller "$cmd" "$stop_cmd" "$STACK_GROUP" "root"
711 else
712 _start_process "$OVN_CONTROLLER_SERVICE"
713 fi
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100714 fi
715
716 if is_service_enabled ovn-controller-vtep ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000717 if [[ "$OVN_BUILD_FROM_SOURCE" == "True" ]]; then
718 local cmd="$OVS_BINDIR/ovn-controller-vtep --log-file --pidfile --detach --ovnsb-db=$OVN_SB_REMOTE"
719 _run_process ovn-controller-vtep "$cmd" "" "$STACK_GROUP" "root"
720 else
721 _start_process "$OVN_CONTROLLER_VTEP_SERVICE"
722 fi
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100723 fi
724
725 if is_service_enabled q-ovn-metadata-agent; then
726 run_process q-ovn-metadata-agent "$NEUTRON_OVN_BIN_DIR/$NEUTRON_OVN_METADATA_BINARY --config-file $OVN_META_CONF"
727 # Format logging
728 setup_logging $OVN_META_CONF
729 fi
730
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100731 _start_ovn_services
732}
733
734function _stop_ovs_dp {
735 sudo ovs-dpctl dump-dps | sudo xargs -n1 ovs-dpctl del-dp
736 modprobe -q -r vport_geneve vport_vxlan openvswitch || true
737}
738
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000739function _stop_process {
740 local service=$1
741 echo "Stopping process $service"
742 if $SYSTEMCTL is-enabled $service; then
743 $SYSTEMCTL stop $service
744 $SYSTEMCTL disable $service
745 fi
746}
747
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100748function stop_ovn {
749 if is_service_enabled q-ovn-metadata-agent; then
750 sudo pkill -9 -f haproxy || :
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000751 _stop_process "devstack@q-ovn-metadata-agent.service"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100752 fi
753 if is_service_enabled ovn-controller-vtep ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000754 _stop_process "$OVN_CONTROLLER_VTEP_SERVICE"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100755 fi
756 if is_service_enabled ovn-controller ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000757 _stop_process "$OVN_CONTROLLER_SERVICE"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100758 fi
759 if is_service_enabled ovn-northd ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000760 _stop_process "$OVN_NORTHD_SERVICE"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100761 fi
762 if is_service_enabled ovs-vtep ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000763 _stop_process "devstack@ovs-vtep.service"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100764 fi
765
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000766 _stop_process "$OVS_VSWITCHD_SERVICE"
767 _stop_process "$OVSDB_SERVER_SERVICE"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100768
769 _stop_ovs_dp
770}
771
772function _cleanup {
773 local path=${1:-$DEST/$OVN_REPO_NAME}
774 pushd $path
775 cd $path
776 sudo make uninstall
777 sudo make distclean
778 popd
779}
780
781# cleanup_ovn() - Remove residual data files, anything left over from previous
782# runs that a clean run would need to clean up
783function cleanup_ovn {
784 local ovn_path=$DEST/$OVN_REPO_NAME
785 local ovs_path=$DEST/$OVS_REPO_NAME
786
787 if [ -d $ovn_path ]; then
788 _cleanup $ovn_path
789 fi
790
791 if [ -d $ovs_path ]; then
792 _cleanup $ovs_path
793 fi
794
795 sudo rm -f $OVN_RUNDIR
796}