Sean Dague | e263c82 | 2014-12-05 14:25:28 -0500 | [diff] [blame] | 1 | #!/bin/bash |
| 2 | # |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 3 | # lib/rpc_backend |
| 4 | # Interface for interactig with different rpc backend |
| 5 | # rpc backend settings |
| 6 | |
| 7 | # Dependencies: |
Adam Spiers | 6a5aa7c | 2013-10-24 11:27:02 +0100 | [diff] [blame] | 8 | # |
| 9 | # - ``functions`` file |
Abhishek Chanda | d5b74c6 | 2014-12-12 02:15:55 +0530 | [diff] [blame] | 10 | # - ``RABBIT_{HOST|PASSWORD|USERID}`` must be defined when RabbitMQ is used |
Kenneth Giusti | 7e58c06 | 2014-07-23 16:44:37 -0400 | [diff] [blame] | 11 | # - ``RPC_MESSAGING_PROTOCOL`` option for configuring the messaging protocol |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 12 | |
| 13 | # ``stack.sh`` calls the entry points in this order: |
| 14 | # |
Adam Spiers | 6a5aa7c | 2013-10-24 11:27:02 +0100 | [diff] [blame] | 15 | # - check_rpc_backend |
| 16 | # - install_rpc_backend |
| 17 | # - restart_rpc_backend |
| 18 | # - iniset_rpc_backend |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 19 | |
| 20 | # Save trace setting |
| 21 | XTRACE=$(set +o | grep xtrace) |
| 22 | set +o xtrace |
| 23 | |
Dean Troyer | cc6b443 | 2013-04-08 15:38:03 -0500 | [diff] [blame] | 24 | |
| 25 | # Functions |
| 26 | # --------- |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 27 | |
Matthieu Huin | 7a7a466 | 2013-04-15 17:13:41 +0200 | [diff] [blame] | 28 | |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 29 | # Make sure we only have one rpc backend enabled. |
| 30 | # Also check the specified rpc backend is available on your platform. |
Ian Wienand | aee18c7 | 2014-02-21 15:35:08 +1100 | [diff] [blame] | 31 | function check_rpc_backend { |
Dean Troyer | 3ef23bc | 2014-07-25 14:56:22 -0500 | [diff] [blame] | 32 | local c svc |
| 33 | |
Matthieu Huin | 7a7a466 | 2013-04-15 17:13:41 +0200 | [diff] [blame] | 34 | local rpc_needed=1 |
| 35 | # We rely on the fact that filenames in lib/* match the service names |
| 36 | # that can be passed as arguments to is_service_enabled. |
| 37 | # We check for a call to iniset_rpc_backend in these files, meaning |
| 38 | # the service needs a backend. |
Vishvananda Ishaya | 78a53d9 | 2013-05-09 17:20:31 -0700 | [diff] [blame] | 39 | rpc_candidates=$(grep -rl iniset_rpc_backend $TOP_DIR/lib/ | awk -F/ '{print $NF}') |
Matthieu Huin | 7a7a466 | 2013-04-15 17:13:41 +0200 | [diff] [blame] | 40 | for c in ${rpc_candidates}; do |
| 41 | if is_service_enabled $c; then |
| 42 | rpc_needed=0 |
| 43 | break |
| 44 | fi |
| 45 | done |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 46 | local rpc_backend_cnt=0 |
| 47 | for svc in qpid zeromq rabbit; do |
| 48 | is_service_enabled $svc && |
Dean Troyer | ffd1768 | 2014-08-02 16:07:03 -0500 | [diff] [blame] | 49 | (( rpc_backend_cnt++ )) || true |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 50 | done |
| 51 | if [ "$rpc_backend_cnt" -gt 1 ]; then |
| 52 | echo "ERROR: only one rpc backend may be enabled," |
| 53 | echo " set only one of 'rabbit', 'qpid', 'zeromq'" |
| 54 | echo " via ENABLED_SERVICES." |
Matthieu Huin | 7a7a466 | 2013-04-15 17:13:41 +0200 | [diff] [blame] | 55 | elif [ "$rpc_backend_cnt" == 0 ] && [ "$rpc_needed" == 0 ]; then |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 56 | echo "ERROR: at least one rpc backend must be enabled," |
| 57 | echo " set one of 'rabbit', 'qpid', 'zeromq'" |
| 58 | echo " via ENABLED_SERVICES." |
| 59 | fi |
| 60 | |
| 61 | if is_service_enabled qpid && ! qpid_is_supported; then |
Nachi Ueno | 07115eb | 2013-02-26 12:38:18 -0800 | [diff] [blame] | 62 | die $LINENO "Qpid support is not available for this version of your distribution." |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 63 | fi |
| 64 | } |
| 65 | |
Dean Troyer | 995eb92 | 2013-03-07 16:11:40 -0600 | [diff] [blame] | 66 | # clean up after rpc backend - eradicate all traces so changing backends |
| 67 | # produces a clean switch |
| 68 | function cleanup_rpc_backend { |
| 69 | if is_service_enabled rabbit; then |
| 70 | # Obliterate rabbitmq-server |
Abhishek Chanda | d5b74c6 | 2014-12-12 02:15:55 +0530 | [diff] [blame] | 71 | if [ -n "$RABBIT_USERID" ]; then |
| 72 | sudo rabbitmqctl delete_user "$RABBIT_USERID" |
| 73 | fi |
Dean Troyer | 995eb92 | 2013-03-07 16:11:40 -0600 | [diff] [blame] | 74 | uninstall_package rabbitmq-server |
DennyZhang | 557744f | 2013-10-14 09:50:13 -0500 | [diff] [blame] | 75 | sudo killall epmd || sudo killall -9 epmd |
Dean Troyer | 995eb92 | 2013-03-07 16:11:40 -0600 | [diff] [blame] | 76 | if is_ubuntu; then |
| 77 | # And the Erlang runtime too |
Sahid Orentino Ferdjaoui | e964827 | 2014-02-23 18:55:51 +0100 | [diff] [blame] | 78 | apt_get purge -y erlang* |
Dean Troyer | 995eb92 | 2013-03-07 16:11:40 -0600 | [diff] [blame] | 79 | fi |
| 80 | elif is_service_enabled qpid; then |
| 81 | if is_fedora; then |
zhhuabj | 5595fdc | 2013-05-08 18:27:20 +0800 | [diff] [blame] | 82 | uninstall_package qpid-cpp-server |
Dean Troyer | 995eb92 | 2013-03-07 16:11:40 -0600 | [diff] [blame] | 83 | elif is_ubuntu; then |
| 84 | uninstall_package qpidd |
| 85 | else |
| 86 | exit_distro_not_supported "qpid installation" |
| 87 | fi |
| 88 | elif is_service_enabled zeromq; then |
| 89 | if is_fedora; then |
Eric Windisch | 800bf38 | 2013-05-24 11:21:11 -0400 | [diff] [blame] | 90 | uninstall_package zeromq python-zmq redis |
Dean Troyer | 995eb92 | 2013-03-07 16:11:40 -0600 | [diff] [blame] | 91 | elif is_ubuntu; then |
Eric Windisch | 800bf38 | 2013-05-24 11:21:11 -0400 | [diff] [blame] | 92 | uninstall_package libzmq1 python-zmq redis-server |
Dean Troyer | 995eb92 | 2013-03-07 16:11:40 -0600 | [diff] [blame] | 93 | elif is_suse; then |
Eric Windisch | 800bf38 | 2013-05-24 11:21:11 -0400 | [diff] [blame] | 94 | uninstall_package libzmq1 python-pyzmq redis |
Dean Troyer | 995eb92 | 2013-03-07 16:11:40 -0600 | [diff] [blame] | 95 | else |
| 96 | exit_distro_not_supported "zeromq installation" |
| 97 | fi |
| 98 | fi |
Kenneth Giusti | 7e58c06 | 2014-07-23 16:44:37 -0400 | [diff] [blame] | 99 | |
| 100 | # Remove the AMQP 1.0 messaging libraries |
| 101 | if [ "$RPC_MESSAGING_PROTOCOL" == "AMQP1" ]; then |
| 102 | if is_fedora; then |
| 103 | uninstall_package qpid-proton-c-devel |
| 104 | uninstall_package python-qpid-proton |
| 105 | fi |
| 106 | # TODO(kgiusti) ubuntu cleanup |
| 107 | fi |
Dean Troyer | 995eb92 | 2013-03-07 16:11:40 -0600 | [diff] [blame] | 108 | } |
| 109 | |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 110 | # install rpc backend |
Ian Wienand | aee18c7 | 2014-02-21 15:35:08 +1100 | [diff] [blame] | 111 | function install_rpc_backend { |
Kenneth Giusti | 7e58c06 | 2014-07-23 16:44:37 -0400 | [diff] [blame] | 112 | # Regardless of the broker used, if AMQP 1.0 is configured load |
| 113 | # the necessary messaging client libraries for oslo.messaging |
| 114 | if [ "$RPC_MESSAGING_PROTOCOL" == "AMQP1" ]; then |
| 115 | if is_fedora; then |
| 116 | install_package qpid-proton-c-devel |
| 117 | install_package python-qpid-proton |
| 118 | elif is_ubuntu; then |
| 119 | # TODO(kgiusti) The QPID AMQP 1.0 protocol libraries |
| 120 | # are not yet in the ubuntu repos. Enable these installs |
| 121 | # once they are present: |
| 122 | #install_package libqpid-proton2-dev |
| 123 | #install_package python-qpid-proton |
| 124 | # Also add 'uninstall' directives in cleanup_rpc_backend()! |
| 125 | exit_distro_not_supported "QPID AMQP 1.0 Proton libraries" |
| 126 | else |
| 127 | exit_distro_not_supported "QPID AMQP 1.0 Proton libraries" |
| 128 | fi |
| 129 | # Install pyngus client API |
| 130 | # TODO(kgiusti) can remove once python qpid bindings are |
| 131 | # available on all supported platforms _and_ pyngus is added |
| 132 | # to the requirements.txt file in oslo.messaging |
| 133 | pip_install pyngus |
| 134 | fi |
| 135 | |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 136 | if is_service_enabled rabbit; then |
| 137 | # Install rabbitmq-server |
Ian Wienand | 7ccf4e0 | 2014-07-23 14:24:11 +1000 | [diff] [blame] | 138 | install_package rabbitmq-server |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 139 | elif is_service_enabled qpid; then |
| 140 | if is_fedora; then |
zhhuabj | 5595fdc | 2013-05-08 18:27:20 +0800 | [diff] [blame] | 141 | install_package qpid-cpp-server |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 142 | elif is_ubuntu; then |
| 143 | install_package qpidd |
| 144 | else |
| 145 | exit_distro_not_supported "qpid installation" |
| 146 | fi |
Kenneth Giusti | 062a3c3 | 2014-09-30 10:14:08 -0400 | [diff] [blame] | 147 | _configure_qpid |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 148 | elif is_service_enabled zeromq; then |
Eric Windisch | 800bf38 | 2013-05-24 11:21:11 -0400 | [diff] [blame] | 149 | # NOTE(ewindisch): Redis is not strictly necessary |
| 150 | # but there is a matchmaker driver that works |
| 151 | # really well & out of the box for multi-node. |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 152 | if is_fedora; then |
Eric Windisch | 800bf38 | 2013-05-24 11:21:11 -0400 | [diff] [blame] | 153 | install_package zeromq python-zmq redis |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 154 | elif is_ubuntu; then |
Eric Windisch | 800bf38 | 2013-05-24 11:21:11 -0400 | [diff] [blame] | 155 | install_package libzmq1 python-zmq redis-server |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 156 | elif is_suse; then |
Eric Windisch | 800bf38 | 2013-05-24 11:21:11 -0400 | [diff] [blame] | 157 | install_package libzmq1 python-pyzmq redis |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 158 | else |
| 159 | exit_distro_not_supported "zeromq installation" |
| 160 | fi |
Vincent Hou | 93a7a50 | 2013-09-27 06:16:54 -0400 | [diff] [blame] | 161 | # Necessary directory for socket location. |
| 162 | sudo mkdir -p /var/run/openstack |
| 163 | sudo chown $STACK_USER /var/run/openstack |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 164 | fi |
Kenneth Giusti | a1875b7 | 2014-09-15 14:21:55 -0400 | [diff] [blame] | 165 | |
| 166 | # If using the QPID broker, install the QPID python client API |
| 167 | if is_service_enabled qpid || [ -n "$QPID_HOST" ]; then |
| 168 | install_package python-qpid |
| 169 | fi |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 170 | } |
| 171 | |
| 172 | # restart the rpc backend |
Ian Wienand | aee18c7 | 2014-02-21 15:35:08 +1100 | [diff] [blame] | 173 | function restart_rpc_backend { |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 174 | if is_service_enabled rabbit; then |
| 175 | # Start rabbitmq-server |
| 176 | echo_summary "Starting RabbitMQ" |
Ben Nemec | ec5918f | 2014-01-30 16:07:23 +0000 | [diff] [blame] | 177 | # NOTE(bnemec): Retry initial rabbitmq configuration to deal with |
| 178 | # the fact that sometimes it fails to start properly. |
Ian Wienand | 64b56a5 | 2014-12-16 09:53:36 +1100 | [diff] [blame] | 179 | # Reference: https://bugzilla.redhat.com/show_bug.cgi?id=1144100 |
Dean Troyer | 3ef23bc | 2014-07-25 14:56:22 -0500 | [diff] [blame] | 180 | local i |
Ben Nemec | ec5918f | 2014-01-30 16:07:23 +0000 | [diff] [blame] | 181 | for i in `seq 10`; do |
Ian Wienand | 64b56a5 | 2014-12-16 09:53:36 +1100 | [diff] [blame] | 182 | local rc=0 |
| 183 | |
| 184 | [[ $i -eq "10" ]] && die $LINENO "Failed to set rabbitmq password" |
| 185 | |
Ben Nemec | ec5918f | 2014-01-30 16:07:23 +0000 | [diff] [blame] | 186 | if is_fedora || is_suse; then |
| 187 | # service is not started by default |
| 188 | restart_service rabbitmq-server |
| 189 | fi |
Ian Wienand | 64b56a5 | 2014-12-16 09:53:36 +1100 | [diff] [blame] | 190 | |
| 191 | rabbit_setuser "$RABBIT_USERID" "$RABBIT_PASSWORD" || rc=$? |
| 192 | if [ $rc -ne 0 ]; then |
| 193 | continue |
| 194 | fi |
| 195 | |
Ben Nemec | ec5918f | 2014-01-30 16:07:23 +0000 | [diff] [blame] | 196 | # change the rabbit password since the default is "guest" |
Ian Wienand | 64b56a5 | 2014-12-16 09:53:36 +1100 | [diff] [blame] | 197 | sudo rabbitmqctl change_password \ |
| 198 | $RABBIT_USERID $RABBIT_PASSWORD || rc=$? |
| 199 | if [ $rc -ne 0 ]; then |
| 200 | continue; |
| 201 | fi |
| 202 | |
| 203 | break |
Ben Nemec | ec5918f | 2014-01-30 16:07:23 +0000 | [diff] [blame] | 204 | done |
Kieran Spear | fb2a3ae | 2013-03-11 23:55:49 +0000 | [diff] [blame] | 205 | if is_service_enabled n-cell; then |
| 206 | # Add partitioned access for the child cell |
| 207 | if [ -z `sudo rabbitmqctl list_vhosts | grep child_cell` ]; then |
| 208 | sudo rabbitmqctl add_vhost child_cell |
Abhishek Chanda | d5b74c6 | 2014-12-12 02:15:55 +0530 | [diff] [blame] | 209 | sudo rabbitmqctl set_permissions -p child_cell $RABBIT_USERID ".*" ".*" ".*" |
Kieran Spear | fb2a3ae | 2013-03-11 23:55:49 +0000 | [diff] [blame] | 210 | fi |
| 211 | fi |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 212 | elif is_service_enabled qpid; then |
| 213 | echo_summary "Starting qpid" |
| 214 | restart_service qpidd |
| 215 | fi |
| 216 | } |
| 217 | |
| 218 | # iniset cofiguration |
Ian Wienand | aee18c7 | 2014-02-21 15:35:08 +1100 | [diff] [blame] | 219 | function iniset_rpc_backend { |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 220 | local package=$1 |
| 221 | local file=$2 |
| 222 | local section=$3 |
| 223 | if is_service_enabled zeromq; then |
Li Ma | ce1524d | 2014-12-21 00:46:34 -0800 | [diff] [blame] | 224 | iniset $file $section rpc_backend "zmq" |
Eric Windisch | 800bf38 | 2013-05-24 11:21:11 -0400 | [diff] [blame] | 225 | iniset $file $section rpc_zmq_matchmaker \ |
Li Ma | ce1524d | 2014-12-21 00:46:34 -0800 | [diff] [blame] | 226 | oslo.messaging._drivers.matchmaker_redis.MatchMakerRedis |
Eric Windisch | 800bf38 | 2013-05-24 11:21:11 -0400 | [diff] [blame] | 227 | # Set MATCHMAKER_REDIS_HOST if running multi-node. |
| 228 | MATCHMAKER_REDIS_HOST=${MATCHMAKER_REDIS_HOST:-127.0.0.1} |
| 229 | iniset $file matchmaker_redis host $MATCHMAKER_REDIS_HOST |
Jason Dillaman | 056df82 | 2013-07-01 08:52:13 -0400 | [diff] [blame] | 230 | elif is_service_enabled qpid || [ -n "$QPID_HOST" ]; then |
Kenneth Giusti | 7e58c06 | 2014-07-23 16:44:37 -0400 | [diff] [blame] | 231 | # For Qpid use the 'amqp' oslo.messaging transport when AMQP 1.0 is used |
| 232 | if [ "$RPC_MESSAGING_PROTOCOL" == "AMQP1" ]; then |
| 233 | iniset $file $section rpc_backend "amqp" |
| 234 | else |
| 235 | iniset $file $section rpc_backend ${package}.openstack.common.rpc.impl_qpid |
| 236 | fi |
Attila Fazekas | a3dc399 | 2013-07-11 11:26:35 +0200 | [diff] [blame] | 237 | iniset $file $section qpid_hostname ${QPID_HOST:-$SERVICE_HOST} |
Kenneth Giusti | 062a3c3 | 2014-09-30 10:14:08 -0400 | [diff] [blame] | 238 | if [ -n "$QPID_USERNAME" ]; then |
| 239 | iniset $file $section qpid_username $QPID_USERNAME |
Eoghan Glynn | 8c11f56 | 2013-03-01 12:09:01 +0000 | [diff] [blame] | 240 | iniset $file $section qpid_password $QPID_PASSWORD |
Eoghan Glynn | 8c11f56 | 2013-03-01 12:09:01 +0000 | [diff] [blame] | 241 | fi |
jiajun xu | 4a30b84 | 2013-01-22 11:49:03 +0800 | [diff] [blame] | 242 | elif is_service_enabled rabbit || { [ -n "$RABBIT_HOST" ] && [ -n "$RABBIT_PASSWORD" ]; }; then |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 243 | iniset $file $section rpc_backend ${package}.openstack.common.rpc.impl_kombu |
Nicolas Simonds | 8f084c6 | 2014-02-28 17:01:41 -0800 | [diff] [blame] | 244 | iniset $file $section rabbit_hosts $RABBIT_HOST |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 245 | iniset $file $section rabbit_password $RABBIT_PASSWORD |
Abhishek Chanda | d5b74c6 | 2014-12-12 02:15:55 +0530 | [diff] [blame] | 246 | iniset $file $section rabbit_userid $RABBIT_USERID |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 247 | fi |
| 248 | } |
| 249 | |
| 250 | # Check if qpid can be used on the current distro. |
| 251 | # qpid_is_supported |
Ian Wienand | aee18c7 | 2014-02-21 15:35:08 +1100 | [diff] [blame] | 252 | function qpid_is_supported { |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 253 | if [[ -z "$DISTRO" ]]; then |
| 254 | GetDistro |
| 255 | fi |
| 256 | |
Sean Dague | 2bb483d | 2014-01-03 09:41:27 -0500 | [diff] [blame] | 257 | # Qpid is not in openSUSE |
| 258 | ( ! is_suse ) |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 259 | } |
| 260 | |
Abhishek Chanda | d5b74c6 | 2014-12-12 02:15:55 +0530 | [diff] [blame] | 261 | function rabbit_setuser { |
| 262 | local user="$1" pass="$2" found="" out="" |
| 263 | out=$(sudo rabbitmqctl list_users) || |
| 264 | { echo "failed to list users" 1>&2; return 1; } |
| 265 | found=$(echo "$out" | awk '$1 == user { print $1 }' "user=$user") |
| 266 | if [ "$found" = "$user" ]; then |
| 267 | sudo rabbitmqctl change_password "$user" "$pass" || |
| 268 | { echo "failed changing pass for '$user'" 1>&2; return 1; } |
| 269 | else |
| 270 | sudo rabbitmqctl add_user "$user" "$pass" || |
| 271 | { echo "failed changing pass for $user"; return 1; } |
| 272 | fi |
| 273 | sudo rabbitmqctl set_permissions "$user" ".*" ".*" ".*" |
| 274 | } |
| 275 | |
Kenneth Giusti | 062a3c3 | 2014-09-30 10:14:08 -0400 | [diff] [blame] | 276 | # Set up the various configuration files used by the qpidd broker |
| 277 | function _configure_qpid { |
| 278 | |
| 279 | # the location of the configuration files have changed since qpidd 0.14 |
| 280 | local qpid_conf_file |
| 281 | if [ -e /etc/qpid/qpidd.conf ]; then |
| 282 | qpid_conf_file=/etc/qpid/qpidd.conf |
| 283 | elif [ -e /etc/qpidd.conf ]; then |
| 284 | qpid_conf_file=/etc/qpidd.conf |
| 285 | else |
| 286 | exit_distro_not_supported "qpidd.conf file not found!" |
| 287 | fi |
| 288 | |
| 289 | # force the ACL file to a known location |
| 290 | local qpid_acl_file=/etc/qpid/qpidd.acl |
| 291 | if [ ! -e $qpid_acl_file ]; then |
| 292 | sudo mkdir -p -m 755 `dirname $qpid_acl_file` |
| 293 | sudo touch $qpid_acl_file |
| 294 | sudo chmod o+r $qpid_acl_file |
| 295 | fi |
| 296 | sudo sed -i.bak '/^acl-file=/d' $qpid_conf_file |
| 297 | echo "acl-file=$qpid_acl_file" | sudo tee --append $qpid_conf_file |
| 298 | |
| 299 | sudo sed -i '/^auth=/d' $qpid_conf_file |
| 300 | if [ -z "$QPID_USERNAME" ]; then |
| 301 | # no QPID user configured, so disable authentication |
| 302 | # and access control |
| 303 | echo "auth=no" | sudo tee --append $qpid_conf_file |
| 304 | cat <<EOF | sudo tee $qpid_acl_file |
| 305 | acl allow all all |
| 306 | EOF |
| 307 | else |
| 308 | # Configure qpidd to use PLAIN authentication, and add |
| 309 | # QPID_USERNAME to the ACL: |
| 310 | echo "auth=yes" | sudo tee --append $qpid_conf_file |
| 311 | if [ -z "$QPID_PASSWORD" ]; then |
| 312 | read_password QPID_PASSWORD "ENTER A PASSWORD FOR QPID USER $QPID_USERNAME" |
| 313 | fi |
| 314 | # Create ACL to allow $QPID_USERNAME full access |
| 315 | cat <<EOF | sudo tee $qpid_acl_file |
| 316 | group admin ${QPID_USERNAME}@QPID |
| 317 | acl allow admin all |
| 318 | acl deny all all |
| 319 | EOF |
| 320 | # Add user to SASL database |
| 321 | if is_ubuntu; then |
| 322 | install_package sasl2-bin |
| 323 | elif is_fedora; then |
| 324 | install_package cyrus-sasl-lib |
| 325 | fi |
| 326 | local sasl_conf_file=/etc/sasl2/qpidd.conf |
| 327 | sudo sed -i.bak '/PLAIN/!s/mech_list: /mech_list: PLAIN /' $sasl_conf_file |
| 328 | local sasl_db=`sudo grep sasldb_path $sasl_conf_file | cut -f 2 -d ":" | tr -d [:blank:]` |
| 329 | if [ ! -e $sasl_db ]; then |
| 330 | sudo mkdir -p -m 755 `dirname $sasl_db` |
| 331 | fi |
| 332 | echo $QPID_PASSWORD | sudo saslpasswd2 -c -p -f $sasl_db -u QPID $QPID_USERNAME |
| 333 | sudo chmod o+r $sasl_db |
| 334 | fi |
| 335 | |
| 336 | # If AMQP 1.0 is specified, ensure that the version of the |
| 337 | # broker can support AMQP 1.0 and configure the queue and |
| 338 | # topic address patterns used by oslo.messaging. |
| 339 | if [ "$RPC_MESSAGING_PROTOCOL" == "AMQP1" ]; then |
| 340 | QPIDD=$(type -p qpidd) |
| 341 | if ! $QPIDD --help | grep -q "queue-patterns"; then |
| 342 | exit_distro_not_supported "qpidd with AMQP 1.0 support" |
| 343 | fi |
| 344 | if ! grep -q "queue-patterns=exclusive" $qpid_conf_file; then |
| 345 | cat <<EOF | sudo tee --append $qpid_conf_file |
| 346 | queue-patterns=exclusive |
| 347 | queue-patterns=unicast |
| 348 | topic-patterns=broadcast |
| 349 | EOF |
| 350 | fi |
| 351 | fi |
| 352 | } |
Dean Troyer | cc6b443 | 2013-04-08 15:38:03 -0500 | [diff] [blame] | 353 | |
Akihiro MOTOKI | b0f1c38 | 2013-01-13 17:58:12 +0900 | [diff] [blame] | 354 | # Restore xtrace |
| 355 | $XTRACE |
Sean Dague | 584d90e | 2013-03-29 14:34:53 -0400 | [diff] [blame] | 356 | |
Adam Spiers | 6a5aa7c | 2013-10-24 11:27:02 +0100 | [diff] [blame] | 357 | # Tell emacs to use shell-script-mode |
| 358 | ## Local variables: |
| 359 | ## mode: shell-script |
| 360 | ## End: |