blob: b46537f5a329efbd24b1a9728e63464b272559bd [file] [log] [blame]
Attila Fazekasece6a332012-11-29 14:19:41 +01001# lib/swift
Dean Troyer6d04fd72012-12-21 11:03:37 -06002# Functions to control the configuration and operation of the **Swift** service
Attila Fazekasece6a332012-11-29 14:19:41 +01003
4# Dependencies:
Adam Spiers6a5aa7c2013-10-24 11:27:02 +01005#
6# - ``functions`` file
7# - ``apache`` file
8# - ``DEST``, ``SCREEN_NAME``, `SWIFT_HASH` must be defined
9# - ``STACK_USER`` must be defined
10# - ``SWIFT_DATA_DIR`` or ``DATA_DIR`` must be defined
11# - ``lib/keystone`` file
12#
Attila Fazekasece6a332012-11-29 14:19:41 +010013# ``stack.sh`` calls the entry points in this order:
14#
Adam Spiers6a5aa7c2013-10-24 11:27:02 +010015# - install_swift
16# - _config_swift_apache_wsgi
17# - configure_swift
18# - init_swift
19# - start_swift
20# - stop_swift
21# - cleanup_swift
22# - _cleanup_swift_apache_wsgi
Attila Fazekasece6a332012-11-29 14:19:41 +010023
24# Save trace setting
25XTRACE=$(set +o | grep xtrace)
26set +o xtrace
27
28
29# Defaults
30# --------
31
Attila Fazekasece6a332012-11-29 14:19:41 +010032# Set up default directories
Attila Fazekasece6a332012-11-29 14:19:41 +010033SWIFT_DIR=$DEST/swift
34SWIFTCLIENT_DIR=$DEST/python-swiftclient
Dean Troyer64ab7742012-12-28 15:38:28 -060035SWIFT_AUTH_CACHE_DIR=${SWIFT_AUTH_CACHE_DIR:-/var/cache/swift}
zhang-hared98a5d02013-06-21 18:18:02 +080036SWIFT_APACHE_WSGI_DIR=${SWIFT_APACHE_WSGI_DIR:-/var/www/swift}
Dean Troyerb7490da2013-03-18 16:07:56 -050037SWIFT3_DIR=$DEST/swift3
Attila Fazekasece6a332012-11-29 14:19:41 +010038
39# TODO: add logging to different location.
40
41# Set ``SWIFT_DATA_DIR`` to the location of swift drives and objects.
42# Default is the common DevStack data directory.
43SWIFT_DATA_DIR=${SWIFT_DATA_DIR:-${DATA_DIR}/swift}
Attila Fazekase6024412013-09-15 18:38:48 +020044SWIFT_DISK_IMAGE=${SWIFT_DATA_DIR}/drives/images/swift.img
Attila Fazekasece6a332012-11-29 14:19:41 +010045
Dean Troyer6ec72fa2013-03-13 11:44:53 -050046# Set ``SWIFT_CONF_DIR`` to the location of the configuration files.
Attila Fazekasece6a332012-11-29 14:19:41 +010047# Default is ``/etc/swift``.
Dean Troyer6ec72fa2013-03-13 11:44:53 -050048# TODO(dtroyer): remove SWIFT_CONFIG_DIR after cutting stable/grizzly
49SWIFT_CONF_DIR=${SWIFT_CONF_DIR:-${SWIFT_CONFIG_DIR:-/etc/swift}}
Attila Fazekasece6a332012-11-29 14:19:41 +010050
Dean Troyerb7490da2013-03-18 16:07:56 -050051if is_service_enabled s-proxy && is_service_enabled swift3; then
52 # If we are using swift3, we can default the s3 port to swift instead
53 # of nova-objectstore
54 S3_SERVICE_PORT=${S3_SERVICE_PORT:-8080}
55fi
56
Attila Fazekasece6a332012-11-29 14:19:41 +010057# DevStack will create a loop-back disk formatted as XFS to store the
Kevin Lydad66c9652013-01-09 13:39:57 +000058# swift data. Set ``SWIFT_LOOPBACK_DISK_SIZE`` to the disk size in
59# kilobytes.
Attila Fazekasece6a332012-11-29 14:19:41 +010060# Default is 1 gigabyte.
Attila Fazekase6024412013-09-15 18:38:48 +020061SWIFT_LOOPBACK_DISK_SIZE_DEFAULT=1G
Attila Fazekas3418c1c2013-09-16 18:35:49 +020062# if tempest enabled the default size is 4 Gigabyte.
63if is_service_enabled tempest; then
Attila Fazekase6024412013-09-15 18:38:48 +020064 SWIFT_LOOPBACK_DISK_SIZE_DEFAULT=${SWIFT_LOOPBACK_DISK_SIZE:-4G}
Attila Fazekas3418c1c2013-09-16 18:35:49 +020065fi
66
67SWIFT_LOOPBACK_DISK_SIZE=${SWIFT_LOOPBACK_DISK_SIZE:-$SWIFT_LOOPBACK_DISK_SIZE_DEFAULT}
Attila Fazekasece6a332012-11-29 14:19:41 +010068
Chmouel Boudjnahbc3a3392013-02-23 04:00:51 +010069# Set ``SWIFT_EXTRAS_MIDDLEWARE`` to extras middlewares.
Chmouel Boudjnah1fba1aa2013-08-02 00:40:05 +020070# Default is ``staticweb, tempurl, formpost``
71SWIFT_EXTRAS_MIDDLEWARE=${SWIFT_EXTRAS_MIDDLEWARE:-tempurl formpost staticweb}
Chmouel Boudjnahbc3a3392013-02-23 04:00:51 +010072
Cyril Roelandtd9883402013-09-27 15:16:51 +000073# Set ``SWIFT_EXTRAS_MIDDLEWARE_LAST`` to extras middlewares that need to be at
74# the end of the pipeline.
75SWIFT_EXTRAS_MIDDLEWARE_LAST=${SWIFT_EXTRAS_MIDDLEWARE_LAST}
76
Joe H. Rahme1ce2ffd2013-10-22 15:19:09 +020077# Set ``SWIFT_EXTRAS_MIDDLEWARE_NO_AUTH`` to extras middlewares that need to be at
78# the beginning of the pipeline, before authentication middlewares.
79SWIFT_EXTRAS_MIDDLEWARE_NO_AUTH=${SWIFT_EXTRAS_MIDDLEWARE_NO_AUTH:-crossdomain}
80
Attila Fazekasece6a332012-11-29 14:19:41 +010081# The ring uses a configurable number of bits from a path’s MD5 hash as
82# a partition index that designates a device. The number of bits kept
83# from the hash is known as the partition power, and 2 to the partition
84# power indicates the partition count. Partitioning the full MD5 hash
85# ring allows other parts of the cluster to work in batches of items at
86# once which ends up either more efficient or at least less complex than
87# working with each item separately or the entire cluster all at once.
88# By default we define 9 for the partition count (which mean 512).
89SWIFT_PARTITION_POWER_SIZE=${SWIFT_PARTITION_POWER_SIZE:-9}
90
91# Set ``SWIFT_REPLICAS`` to configure how many replicas are to be
Chmouel Boudjnah0c3a5582013-03-06 10:58:33 +010092# configured for your Swift cluster. By default we are configuring
93# only one replica since this is way less CPU and memory intensive. If
94# you are planning to test swift replication you may want to set this
95# up to 3.
96SWIFT_REPLICAS=${SWIFT_REPLICAS:-1}
Attila Fazekasece6a332012-11-29 14:19:41 +010097SWIFT_REPLICAS_SEQ=$(seq ${SWIFT_REPLICAS})
98
99# Set ``OBJECT_PORT_BASE``, ``CONTAINER_PORT_BASE``, ``ACCOUNT_PORT_BASE``
100# Port bases used in port number calclution for the service "nodes"
101# The specified port number will be used, the additinal ports calculated by
102# base_port + node_num * 10
Dean Troyer1151d6f2013-03-29 14:06:52 -0500103OBJECT_PORT_BASE=${OBJECT_PORT_BASE:-6013}
104CONTAINER_PORT_BASE=${CONTAINER_PORT_BASE:-6011}
105ACCOUNT_PORT_BASE=${ACCOUNT_PORT_BASE:-6012}
Attila Fazekasece6a332012-11-29 14:19:41 +0100106
Dean Troyer6d04fd72012-12-21 11:03:37 -0600107
Dean Troyercc6b4432013-04-08 15:38:03 -0500108# Functions
109# ---------
Attila Fazekasece6a332012-11-29 14:19:41 +0100110
111# cleanup_swift() - Remove residual data files
112function cleanup_swift() {
Sean Dague101b4242013-10-22 08:47:11 -0400113 rm -f ${SWIFT_CONF_DIR}{*.builder,*.ring.gz,backups/*.builder,backups/*.ring.gz}
114 if egrep -q ${SWIFT_DATA_DIR}/drives/sdb1 /proc/mounts; then
115 sudo umount ${SWIFT_DATA_DIR}/drives/sdb1
116 fi
117 if [[ -e ${SWIFT_DISK_IMAGE} ]]; then
118 rm ${SWIFT_DISK_IMAGE}
119 fi
120 rm -rf ${SWIFT_DATA_DIR}/run/
121 if is_apache_enabled_service swift; then
122 _cleanup_swift_apache_wsgi
123 fi
zhang-hared98a5d02013-06-21 18:18:02 +0800124}
125
126# _cleanup_swift_apache_wsgi() - Remove wsgi files, disable and remove apache vhost file
127function _cleanup_swift_apache_wsgi() {
128 sudo rm -f $SWIFT_APACHE_WSGI_DIR/*.wsgi
Jamie Lennox54707012013-09-17 12:07:48 +1000129 disable_apache_site proxy-server
zhang-hared98a5d02013-06-21 18:18:02 +0800130 for node_number in ${SWIFT_REPLICAS_SEQ}; do
131 for type in object container account; do
132 site_name=${type}-server-${node_number}
Jamie Lennox54707012013-09-17 12:07:48 +1000133 disable_apache_site ${site_name}
zhang-hared98a5d02013-06-21 18:18:02 +0800134 sudo rm -f /etc/$APACHE_NAME/$APACHE_CONF_DIR/${site_name}
135 done
136 done
137}
138
139# _config_swift_apache_wsgi() - Set WSGI config files of Swift
140function _config_swift_apache_wsgi() {
141 sudo mkdir -p ${SWIFT_APACHE_WSGI_DIR}
142 local apache_vhost_dir=/etc/${APACHE_NAME}/$APACHE_CONF_DIR
143 local proxy_port=${SWIFT_DEFAULT_BIND_PORT:-8080}
144
145 # copy proxy vhost and wsgi file
146 sudo cp ${SWIFT_DIR}/examples/apache2/proxy-server.template ${apache_vhost_dir}/proxy-server
147 sudo sed -e "
148 /^#/d;/^$/d;
149 s/%PORT%/$proxy_port/g;
150 s/%SERVICENAME%/proxy-server/g;
151 s/%APACHE_NAME%/${APACHE_NAME}/g;
Jamie Lennoxd5824602013-09-17 11:44:37 +1000152 s/%USER%/${STACK_USER}/g;
zhang-hared98a5d02013-06-21 18:18:02 +0800153 " -i ${apache_vhost_dir}/proxy-server
Jamie Lennox54707012013-09-17 12:07:48 +1000154 enable_apache_site proxy-server
zhang-hared98a5d02013-06-21 18:18:02 +0800155
156 sudo cp ${SWIFT_DIR}/examples/wsgi/proxy-server.wsgi.template ${SWIFT_APACHE_WSGI_DIR}/proxy-server.wsgi
157 sudo sed -e "
158 /^#/d;/^$/d;
159 s/%SERVICECONF%/proxy-server.conf/g;
160 " -i ${SWIFT_APACHE_WSGI_DIR}/proxy-server.wsgi
zhang-hared98a5d02013-06-21 18:18:02 +0800161
162 # copy apache vhost file and set name and port
163 for node_number in ${SWIFT_REPLICAS_SEQ}; do
164 object_port=$[OBJECT_PORT_BASE + 10 * ($node_number - 1)]
165 container_port=$[CONTAINER_PORT_BASE + 10 * ($node_number - 1)]
166 account_port=$[ACCOUNT_PORT_BASE + 10 * ($node_number - 1)]
167
168 sudo cp ${SWIFT_DIR}/examples/apache2/object-server.template ${apache_vhost_dir}/object-server-${node_number}
169 sudo sed -e "
170 s/%PORT%/$object_port/g;
171 s/%SERVICENAME%/object-server-${node_number}/g;
172 s/%APACHE_NAME%/${APACHE_NAME}/g;
Jamie Lennoxd5824602013-09-17 11:44:37 +1000173 s/%USER%/${STACK_USER}/g;
zhang-hared98a5d02013-06-21 18:18:02 +0800174 " -i ${apache_vhost_dir}/object-server-${node_number}
Jamie Lennox54707012013-09-17 12:07:48 +1000175 enable_apache_site object-server-${node_number}
zhang-hared98a5d02013-06-21 18:18:02 +0800176
177 sudo cp ${SWIFT_DIR}/examples/wsgi/object-server.wsgi.template ${SWIFT_APACHE_WSGI_DIR}/object-server-${node_number}.wsgi
178 sudo sed -e "
179 /^#/d;/^$/d;
180 s/%SERVICECONF%/object-server\/${node_number}.conf/g;
181 " -i ${SWIFT_APACHE_WSGI_DIR}/object-server-${node_number}.wsgi
182
183 sudo cp ${SWIFT_DIR}/examples/apache2/container-server.template ${apache_vhost_dir}/container-server-${node_number}
184 sudo sed -e "
185 /^#/d;/^$/d;
186 s/%PORT%/$container_port/g;
187 s/%SERVICENAME%/container-server-${node_number}/g;
188 s/%APACHE_NAME%/${APACHE_NAME}/g;
Jamie Lennoxd5824602013-09-17 11:44:37 +1000189 s/%USER%/${STACK_USER}/g;
zhang-hared98a5d02013-06-21 18:18:02 +0800190 " -i ${apache_vhost_dir}/container-server-${node_number}
Jamie Lennox54707012013-09-17 12:07:48 +1000191 enable_apache_site container-server-${node_number}
zhang-hared98a5d02013-06-21 18:18:02 +0800192
193 sudo cp ${SWIFT_DIR}/examples/wsgi/container-server.wsgi.template ${SWIFT_APACHE_WSGI_DIR}/container-server-${node_number}.wsgi
194 sudo sed -e "
195 /^#/d;/^$/d;
196 s/%SERVICECONF%/container-server\/${node_number}.conf/g;
197 " -i ${SWIFT_APACHE_WSGI_DIR}/container-server-${node_number}.wsgi
198
199 sudo cp ${SWIFT_DIR}/examples/apache2/account-server.template ${apache_vhost_dir}/account-server-${node_number}
200 sudo sed -e "
Sean Dague101b4242013-10-22 08:47:11 -0400201 /^#/d;/^$/d;
zhang-hared98a5d02013-06-21 18:18:02 +0800202 s/%PORT%/$account_port/g;
203 s/%SERVICENAME%/account-server-${node_number}/g;
204 s/%APACHE_NAME%/${APACHE_NAME}/g;
Jamie Lennoxd5824602013-09-17 11:44:37 +1000205 s/%USER%/${STACK_USER}/g;
zhang-hared98a5d02013-06-21 18:18:02 +0800206 " -i ${apache_vhost_dir}/account-server-${node_number}
Jamie Lennox54707012013-09-17 12:07:48 +1000207 enable_apache_site account-server-${node_number}
zhang-hared98a5d02013-06-21 18:18:02 +0800208
209 sudo cp ${SWIFT_DIR}/examples/wsgi/account-server.wsgi.template ${SWIFT_APACHE_WSGI_DIR}/account-server-${node_number}.wsgi
210 sudo sed -e "
Sean Dague101b4242013-10-22 08:47:11 -0400211 /^#/d;/^$/d;
zhang-hared98a5d02013-06-21 18:18:02 +0800212 s/%SERVICECONF%/account-server\/${node_number}.conf/g;
213 " -i ${SWIFT_APACHE_WSGI_DIR}/account-server-${node_number}.wsgi
zhang-hared98a5d02013-06-21 18:18:02 +0800214 done
Attila Fazekasece6a332012-11-29 14:19:41 +0100215}
216
217# configure_swift() - Set config files, create data dirs and loop image
218function configure_swift() {
Joe H. Rahme1ce2ffd2013-10-22 15:19:09 +0200219 local swift_pipeline="${SWIFT_EXTRAS_MIDDLEWARE_NO_AUTH}"
Attila Fazekasece6a332012-11-29 14:19:41 +0100220 local node_number
221 local swift_node_config
222 local swift_log_dir
223
Attila Fazekasece6a332012-11-29 14:19:41 +0100224 # Make sure to kill all swift processes first
Chmouel Boudjnahad8b2762013-01-10 15:40:01 +0100225 swift-init --run-dir=${SWIFT_DATA_DIR}/run all stop || true
Attila Fazekasece6a332012-11-29 14:19:41 +0100226
Dean Troyer1c6c1122013-03-27 17:40:53 -0500227 sudo mkdir -p ${SWIFT_CONF_DIR}/{object,container,account}-server
228 sudo chown -R $USER: ${SWIFT_CONF_DIR}
Attila Fazekasece6a332012-11-29 14:19:41 +0100229
Dean Troyer6ec72fa2013-03-13 11:44:53 -0500230 if [[ "$SWIFT_CONF_DIR" != "/etc/swift" ]]; then
Attila Fazekasece6a332012-11-29 14:19:41 +0100231 # Some swift tools are hard-coded to use ``/etc/swift`` and are apparently not going to be fixed.
232 # Create a symlink if the config dir is moved
Dean Troyer6ec72fa2013-03-13 11:44:53 -0500233 sudo ln -sf ${SWIFT_CONF_DIR} /etc/swift
Attila Fazekasece6a332012-11-29 14:19:41 +0100234 fi
235
236 # Swift use rsync to synchronize between all the different
237 # partitions (which make more sense when you have a multi-node
238 # setup) we configure it with our version of rsync.
239 sed -e "
240 s/%GROUP%/${USER_GROUP}/;
241 s/%USER%/$USER/;
242 s,%SWIFT_DATA_DIR%,$SWIFT_DATA_DIR,;
243 " $FILES/swift/rsyncd.conf | sudo tee /etc/rsyncd.conf
244 # rsyncd.conf just prepared for 4 nodes
Vincent Untzc18b9652012-12-04 12:36:34 +0100245 if is_ubuntu; then
Attila Fazekasece6a332012-11-29 14:19:41 +0100246 sudo sed -i '/^RSYNC_ENABLE=false/ { s/false/true/ }' /etc/default/rsync
247 else
248 sudo sed -i '/disable *= *yes/ { s/yes/no/ }' /etc/xinetd.d/rsync
249 fi
250
Dean Troyer6ec72fa2013-03-13 11:44:53 -0500251 SWIFT_CONFIG_PROXY_SERVER=${SWIFT_CONF_DIR}/proxy-server.conf
Attila Fazekasece6a332012-11-29 14:19:41 +0100252 cp ${SWIFT_DIR}/etc/proxy-server.conf-sample ${SWIFT_CONFIG_PROXY_SERVER}
253
254 iniuncomment ${SWIFT_CONFIG_PROXY_SERVER} DEFAULT user
255 iniset ${SWIFT_CONFIG_PROXY_SERVER} DEFAULT user ${USER}
256
257 iniuncomment ${SWIFT_CONFIG_PROXY_SERVER} DEFAULT swift_dir
Dean Troyer6ec72fa2013-03-13 11:44:53 -0500258 iniset ${SWIFT_CONFIG_PROXY_SERVER} DEFAULT swift_dir ${SWIFT_CONF_DIR}
Attila Fazekasece6a332012-11-29 14:19:41 +0100259
260 iniuncomment ${SWIFT_CONFIG_PROXY_SERVER} DEFAULT workers
261 iniset ${SWIFT_CONFIG_PROXY_SERVER} DEFAULT workers 1
262
263 iniuncomment ${SWIFT_CONFIG_PROXY_SERVER} DEFAULT log_level
264 iniset ${SWIFT_CONFIG_PROXY_SERVER} DEFAULT log_level DEBUG
265
266 iniuncomment ${SWIFT_CONFIG_PROXY_SERVER} DEFAULT bind_port
267 iniset ${SWIFT_CONFIG_PROXY_SERVER} DEFAULT bind_port ${SWIFT_DEFAULT_BIND_PORT:-8080}
268
Cyril Roelandtd9883402013-09-27 15:16:51 +0000269 # Configure Ceilometer
270 if is_service_enabled ceilometer; then
271 iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:ceilometer use "egg:ceilometer#swift"
272 SWIFT_EXTRAS_MIDDLEWARE_LAST="${SWIFT_EXTRAS_MIDDLEWARE_LAST} ceilometer"
273 fi
274
Chmouel Boudjnah5cac3782013-07-17 15:13:44 +0000275 # By default Swift will be installed with keystone and tempauth middleware
276 # and add the swift3 middleware if its configured for it. The token for
Adam Spierscb961592013-10-05 12:11:07 +0100277 # tempauth would be prefixed with the reseller_prefix setting `TEMPAUTH_` the
278 # token for keystoneauth would have the standard reseller_prefix `AUTH_`
Chmouel Boudjnah5cac3782013-07-17 15:13:44 +0000279 if is_service_enabled swift3;then
Joe H. Rahme1ce2ffd2013-10-22 15:19:09 +0200280 swift_pipeline+=" swift3 s3token "
Chmouel Boudjnahbc3a3392013-02-23 04:00:51 +0100281 fi
Chmouel Boudjnah5cac3782013-07-17 15:13:44 +0000282 swift_pipeline+=" authtoken keystoneauth tempauth "
Chmouel Boudjnahbc3a3392013-02-23 04:00:51 +0100283 sed -i "/^pipeline/ { s/tempauth/${swift_pipeline} ${SWIFT_EXTRAS_MIDDLEWARE}/ ;}" ${SWIFT_CONFIG_PROXY_SERVER}
Cyril Roelandtd9883402013-09-27 15:16:51 +0000284 sed -i "/^pipeline/ { s/proxy-server/${SWIFT_EXTRAS_MIDDLEWARE_LAST} proxy-server/ ; }" ${SWIFT_CONFIG_PROXY_SERVER}
Attila Fazekasece6a332012-11-29 14:19:41 +0100285
Chmouel Boudjnah5cac3782013-07-17 15:13:44 +0000286 iniuncomment ${SWIFT_CONFIG_PROXY_SERVER} filter:tempauth account_autocreate
Attila Fazekasece6a332012-11-29 14:19:41 +0100287 iniset ${SWIFT_CONFIG_PROXY_SERVER} app:proxy-server account_autocreate true
288
Chmouel Boudjnah5cac3782013-07-17 15:13:44 +0000289 iniuncomment ${SWIFT_CONFIG_PROXY_SERVER} filter:tempauth reseller_prefix
290 iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:tempauth reseller_prefix "TEMPAUTH"
291
Joe H. Rahme1ce2ffd2013-10-22 15:19:09 +0200292 # Configure Crossdomain
293 iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:crossdomain use "egg:swift#crossdomain"
294
Attila Fazekasece6a332012-11-29 14:19:41 +0100295 # Configure Keystone
296 sed -i '/^# \[filter:authtoken\]/,/^# \[filter:keystoneauth\]$/ s/^#[ \t]*//' ${SWIFT_CONFIG_PROXY_SERVER}
297 iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:authtoken auth_host $KEYSTONE_AUTH_HOST
298 iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:authtoken auth_port $KEYSTONE_AUTH_PORT
299 iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:authtoken auth_protocol $KEYSTONE_AUTH_PROTOCOL
300 iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:authtoken auth_uri $KEYSTONE_SERVICE_PROTOCOL://$KEYSTONE_SERVICE_HOST:$KEYSTONE_SERVICE_PORT/
301 iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:authtoken admin_tenant_name $SERVICE_TENANT_NAME
302 iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:authtoken admin_user swift
303 iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:authtoken admin_password $SERVICE_PASSWORD
Dean Troyer64ab7742012-12-28 15:38:28 -0600304 iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:authtoken signing_dir $SWIFT_AUTH_CACHE_DIR
Attila Fazekasece6a332012-11-29 14:19:41 +0100305
306 iniuncomment ${SWIFT_CONFIG_PROXY_SERVER} filter:keystoneauth use
307 iniuncomment ${SWIFT_CONFIG_PROXY_SERVER} filter:keystoneauth operator_roles
308 iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:keystoneauth operator_roles "Member, admin"
309
310 if is_service_enabled swift3; then
311 cat <<EOF >>${SWIFT_CONFIG_PROXY_SERVER}
312# NOTE(chmou): s3token middleware is not updated yet to use only
313# username and password.
314[filter:s3token]
315paste.filter_factory = keystone.middleware.s3_token:filter_factory
316auth_port = ${KEYSTONE_AUTH_PORT}
317auth_host = ${KEYSTONE_AUTH_HOST}
318auth_protocol = ${KEYSTONE_AUTH_PROTOCOL}
319auth_token = ${SERVICE_TOKEN}
320admin_token = ${SERVICE_TOKEN}
321
322[filter:swift3]
323use = egg:swift3#swift3
324EOF
325 fi
326
Dean Troyer6ec72fa2013-03-13 11:44:53 -0500327 cp ${SWIFT_DIR}/etc/swift.conf-sample ${SWIFT_CONF_DIR}/swift.conf
328 iniset ${SWIFT_CONF_DIR}/swift.conf swift-hash swift_hash_path_suffix ${SWIFT_HASH}
Attila Fazekasece6a332012-11-29 14:19:41 +0100329
330 # This function generates an object/account/proxy configuration
331 # emulating 4 nodes on different ports
332 function generate_swift_config() {
333 local swift_node_config=$1
334 local node_id=$2
335 local bind_port=$3
Chmouel Boudjnah35633f02013-07-16 07:35:13 +0000336 local server_type=$4
Attila Fazekasece6a332012-11-29 14:19:41 +0100337
338 log_facility=$[ node_id - 1 ]
339 node_path=${SWIFT_DATA_DIR}/${node_number}
340
341 iniuncomment ${swift_node_config} DEFAULT user
342 iniset ${swift_node_config} DEFAULT user ${USER}
343
344 iniuncomment ${swift_node_config} DEFAULT bind_port
345 iniset ${swift_node_config} DEFAULT bind_port ${bind_port}
346
347 iniuncomment ${swift_node_config} DEFAULT swift_dir
Dean Troyer6ec72fa2013-03-13 11:44:53 -0500348 iniset ${swift_node_config} DEFAULT swift_dir ${SWIFT_CONF_DIR}
Attila Fazekasece6a332012-11-29 14:19:41 +0100349
350 iniuncomment ${swift_node_config} DEFAULT devices
351 iniset ${swift_node_config} DEFAULT devices ${node_path}
352
353 iniuncomment ${swift_node_config} DEFAULT log_facility
354 iniset ${swift_node_config} DEFAULT log_facility LOG_LOCAL${log_facility}
355
Chmouel Boudjnah82c09962013-07-16 07:16:07 +0000356 iniuncomment ${swift_node_config} DEFAULT disable_fallocate
357 iniset ${swift_node_config} DEFAULT disable_fallocate true
358
Attila Fazekasece6a332012-11-29 14:19:41 +0100359 iniuncomment ${swift_node_config} DEFAULT mount_check
360 iniset ${swift_node_config} DEFAULT mount_check false
361
362 iniuncomment ${swift_node_config} ${server_type}-replicator vm_test_mode
363 iniset ${swift_node_config} ${server_type}-replicator vm_test_mode yes
364 }
365
366 for node_number in ${SWIFT_REPLICAS_SEQ}; do
Dean Troyer6ec72fa2013-03-13 11:44:53 -0500367 swift_node_config=${SWIFT_CONF_DIR}/object-server/${node_number}.conf
Attila Fazekasece6a332012-11-29 14:19:41 +0100368 cp ${SWIFT_DIR}/etc/object-server.conf-sample ${swift_node_config}
Chmouel Boudjnah35633f02013-07-16 07:35:13 +0000369 generate_swift_config ${swift_node_config} ${node_number} $[OBJECT_PORT_BASE + 10 * (node_number - 1)] object
Chmouel Boudjnah8e5d2f02012-12-20 13:11:43 +0000370 iniset ${swift_node_config} filter:recon recon_cache_path ${SWIFT_DATA_DIR}/cache
371 # Using a sed and not iniset/iniuncomment because we want to a global
372 # modification and make sure it works for new sections.
373 sed -i -e "s,#[ ]*recon_cache_path .*,recon_cache_path = ${SWIFT_DATA_DIR}/cache," ${swift_node_config}
Attila Fazekasece6a332012-11-29 14:19:41 +0100374
Dean Troyer6ec72fa2013-03-13 11:44:53 -0500375 swift_node_config=${SWIFT_CONF_DIR}/container-server/${node_number}.conf
Attila Fazekasece6a332012-11-29 14:19:41 +0100376 cp ${SWIFT_DIR}/etc/container-server.conf-sample ${swift_node_config}
Chmouel Boudjnah35633f02013-07-16 07:35:13 +0000377 generate_swift_config ${swift_node_config} ${node_number} $[CONTAINER_PORT_BASE + 10 * (node_number - 1)] container
Attila Fazekas83e10952012-11-30 23:28:07 +0100378 iniuncomment ${swift_node_config} app:container-server allow_versions
379 iniset ${swift_node_config} app:container-server allow_versions "true"
Chmouel Boudjnah8e5d2f02012-12-20 13:11:43 +0000380 sed -i -e "s,#[ ]*recon_cache_path .*,recon_cache_path = ${SWIFT_DATA_DIR}/cache," ${swift_node_config}
Attila Fazekasece6a332012-11-29 14:19:41 +0100381
Dean Troyer6ec72fa2013-03-13 11:44:53 -0500382 swift_node_config=${SWIFT_CONF_DIR}/account-server/${node_number}.conf
Attila Fazekasece6a332012-11-29 14:19:41 +0100383 cp ${SWIFT_DIR}/etc/account-server.conf-sample ${swift_node_config}
Chmouel Boudjnah35633f02013-07-16 07:35:13 +0000384 generate_swift_config ${swift_node_config} ${node_number} $[ACCOUNT_PORT_BASE + 10 * (node_number - 1)] account
Chmouel Boudjnah8e5d2f02012-12-20 13:11:43 +0000385 sed -i -e "s,#[ ]*recon_cache_path .*,recon_cache_path = ${SWIFT_DATA_DIR}/cache," ${swift_node_config}
Attila Fazekasece6a332012-11-29 14:19:41 +0100386 done
387
Chmouel Boudjnah0ce91a52013-07-05 11:59:24 +0000388 # Set new accounts in tempauth to match keystone tenant/user (to make testing easier)
389 iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:tempauth user_swifttenanttest1_swiftusertest1 "testing .admin"
390 iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:tempauth user_swifttenanttest2_swiftusertest2 "testing2 .admin"
391 iniset ${SWIFT_CONFIG_PROXY_SERVER} filter:tempauth user_swifttenanttest1_swiftusertest3 "testing3 .admin"
392
393 testfile=${SWIFT_CONF_DIR}/test.conf
394 cp ${SWIFT_DIR}/test/sample.conf ${testfile}
395
396 # Set accounts for functional tests
397 iniset ${testfile} func_test account swifttenanttest1
398 iniset ${testfile} func_test username swiftusertest1
399 iniset ${testfile} func_test username3 swiftusertest3
400 iniset ${testfile} func_test account2 swifttenanttest2
401 iniset ${testfile} func_test username2 swiftusertest2
402
Chmouel Boudjnah0ce91a52013-07-05 11:59:24 +0000403 if is_service_enabled key;then
404 iniuncomment ${testfile} func_test auth_version
405 iniset ${testfile} func_test auth_host ${KEYSTONE_SERVICE_HOST}
406 iniset ${testfile} func_test auth_port ${KEYSTONE_AUTH_PORT}
407 iniset ${testfile} func_test auth_prefix /v2.0/
408 fi
409
Attila Fazekasece6a332012-11-29 14:19:41 +0100410 swift_log_dir=${SWIFT_DATA_DIR}/logs
411 rm -rf ${swift_log_dir}
412 mkdir -p ${swift_log_dir}/hourly
413 sudo chown -R $USER:adm ${swift_log_dir}
414 sed "s,%SWIFT_LOGDIR%,${swift_log_dir}," $FILES/swift/rsyslog.conf | sudo \
415 tee /etc/rsyslog.d/10-swift.conf
zhang-hared98a5d02013-06-21 18:18:02 +0800416 if is_apache_enabled_service swift; then
417 _config_swift_apache_wsgi
418 fi
Attila Fazekasece6a332012-11-29 14:19:41 +0100419}
420
Dean Troyer1c6c1122013-03-27 17:40:53 -0500421# create_swift_disk - Create Swift backing disk
422function create_swift_disk() {
423 local node_number
424
425 # First do a bit of setup by creating the directories and
426 # changing the permissions so we can run it as our user.
427
428 USER_GROUP=$(id -g)
429 sudo mkdir -p ${SWIFT_DATA_DIR}/{drives,cache,run,logs}
430 sudo chown -R $USER:${USER_GROUP} ${SWIFT_DATA_DIR}
431
432 # Create a loopback disk and format it to XFS.
Attila Fazekase6024412013-09-15 18:38:48 +0200433 if [[ -e ${SWIFT_DISK_IMAGE} ]]; then
Dean Troyer1c6c1122013-03-27 17:40:53 -0500434 if egrep -q ${SWIFT_DATA_DIR}/drives/sdb1 /proc/mounts; then
435 sudo umount ${SWIFT_DATA_DIR}/drives/sdb1
Attila Fazekase6024412013-09-15 18:38:48 +0200436 sudo rm -f ${SWIFT_DISK_IMAGE}
Dean Troyer1c6c1122013-03-27 17:40:53 -0500437 fi
438 fi
439
440 mkdir -p ${SWIFT_DATA_DIR}/drives/images
Attila Fazekase6024412013-09-15 18:38:48 +0200441 sudo touch ${SWIFT_DISK_IMAGE}
442 sudo chown $USER: ${SWIFT_DISK_IMAGE}
Dean Troyer1c6c1122013-03-27 17:40:53 -0500443
Attila Fazekase6024412013-09-15 18:38:48 +0200444 truncate -s ${SWIFT_LOOPBACK_DISK_SIZE} ${SWIFT_DISK_IMAGE}
Dean Troyer1c6c1122013-03-27 17:40:53 -0500445
446 # Make a fresh XFS filesystem
Attila Fazekase6024412013-09-15 18:38:48 +0200447 mkfs.xfs -f -i size=1024 ${SWIFT_DISK_IMAGE}
Dean Troyer1c6c1122013-03-27 17:40:53 -0500448
449 # Mount the disk with mount options to make it as efficient as possible
450 mkdir -p ${SWIFT_DATA_DIR}/drives/sdb1
451 if ! egrep -q ${SWIFT_DATA_DIR}/drives/sdb1 /proc/mounts; then
452 sudo mount -t xfs -o loop,noatime,nodiratime,nobarrier,logbufs=8 \
Attila Fazekase6024412013-09-15 18:38:48 +0200453 ${SWIFT_DISK_IMAGE} ${SWIFT_DATA_DIR}/drives/sdb1
Dean Troyer1c6c1122013-03-27 17:40:53 -0500454 fi
455
456 # Create a link to the above mount and
457 # create all of the directories needed to emulate a few different servers
458 for node_number in ${SWIFT_REPLICAS_SEQ}; do
459 sudo ln -sf ${SWIFT_DATA_DIR}/drives/sdb1/$node_number ${SWIFT_DATA_DIR}/$node_number;
460 drive=${SWIFT_DATA_DIR}/drives/sdb1/${node_number}
461 node=${SWIFT_DATA_DIR}/${node_number}/node
462 node_device=${node}/sdb1
463 [[ -d $node ]] && continue
464 [[ -d $drive ]] && continue
465 sudo install -o ${USER} -g $USER_GROUP -d $drive
466 sudo install -o ${USER} -g $USER_GROUP -d $node_device
467 sudo chown -R $USER: ${node}
468 done
469}
Chmouel Boudjnahba313052013-07-10 21:03:43 +0200470# create_swift_accounts() - Set up standard swift accounts and extra
471# one for tests we do this by attaching all words in the account name
472# since we want to make it compatible with tempauth which use
473# underscores for separators.
Chmouel Boudjnah0ce91a52013-07-05 11:59:24 +0000474
475# Tenant User Roles
476# ------------------------------------------------------------------
Chmouel Boudjnahba313052013-07-10 21:03:43 +0200477# service swift service
Chmouel Boudjnah0ce91a52013-07-05 11:59:24 +0000478# swifttenanttest1 swiftusertest1 admin
479# swifttenanttest1 swiftusertest3 anotherrole
480# swifttenanttest2 swiftusertest2 admin
481
Chmouel Boudjnah0ce91a52013-07-05 11:59:24 +0000482function create_swift_accounts() {
Chmouel Boudjnahba313052013-07-10 21:03:43 +0200483 KEYSTONE_CATALOG_BACKEND=${KEYSTONE_CATALOG_BACKEND:-sql}
484
485 SERVICE_TENANT=$(keystone tenant-list | awk "/ $SERVICE_TENANT_NAME / { print \$2 }")
486 ADMIN_ROLE=$(keystone role-list | awk "/ admin / { print \$2 }")
487
488 SWIFT_USER=$(keystone user-create --name=swift --pass="$SERVICE_PASSWORD" \
489 --tenant_id $SERVICE_TENANT --email=swift@example.com | grep " id " | get_field 2)
Jorge Valderrama Romerof39ee962013-09-02 17:18:40 +0200490 keystone user-role-add --tenant-id $SERVICE_TENANT --user-id $SWIFT_USER --role-id $ADMIN_ROLE
Chmouel Boudjnahba313052013-07-10 21:03:43 +0200491
492 if [[ "$KEYSTONE_CATALOG_BACKEND" = 'sql' ]]; then
493 SWIFT_SERVICE=$(keystone service-create --name=swift --type="object-store" \
494 --description="Swift Service" | grep " id " | get_field 2)
495 keystone endpoint-create \
496 --region RegionOne \
497 --service_id $SWIFT_SERVICE \
498 --publicurl "http://$SERVICE_HOST:8080/v1/AUTH_\$(tenant_id)s" \
499 --adminurl "http://$SERVICE_HOST:8080" \
500 --internalurl "http://$SERVICE_HOST:8080/v1/AUTH_\$(tenant_id)s"
501 fi
502
Chmouel Boudjnah0ce91a52013-07-05 11:59:24 +0000503 SWIFT_TENANT_TEST1=$(keystone tenant-create --name=swifttenanttest1 | grep " id " | get_field 2)
504 SWIFT_USER_TEST1=$(keystone user-create --name=swiftusertest1 --pass=testing --email=test@example.com | grep " id " | get_field 2)
Jorge Valderrama Romerof39ee962013-09-02 17:18:40 +0200505 keystone user-role-add --user-id $SWIFT_USER_TEST1 --role-id $ADMIN_ROLE --tenant-id $SWIFT_TENANT_TEST1
Chmouel Boudjnah0ce91a52013-07-05 11:59:24 +0000506
507 SWIFT_USER_TEST3=$(keystone user-create --name=swiftusertest3 --pass=testing3 --email=test3@example.com | grep " id " | get_field 2)
Jorge Valderrama Romerof39ee962013-09-02 17:18:40 +0200508 keystone user-role-add --user-id $SWIFT_USER_TEST3 --role-id $ANOTHER_ROLE --tenant-id $SWIFT_TENANT_TEST1
Chmouel Boudjnah0ce91a52013-07-05 11:59:24 +0000509
510 SWIFT_TENANT_TEST2=$(keystone tenant-create --name=swifttenanttest2 | grep " id " | get_field 2)
511 SWIFT_USER_TEST2=$(keystone user-create --name=swiftusertest2 --pass=testing2 --email=test2@example.com | grep " id " | get_field 2)
Jorge Valderrama Romerof39ee962013-09-02 17:18:40 +0200512 keystone user-role-add --user-id $SWIFT_USER_TEST2 --role-id $ADMIN_ROLE --tenant-id $SWIFT_TENANT_TEST2
Chmouel Boudjnah0ce91a52013-07-05 11:59:24 +0000513}
Dean Troyer1c6c1122013-03-27 17:40:53 -0500514
Attila Fazekasece6a332012-11-29 14:19:41 +0100515# init_swift() - Initialize rings
516function init_swift() {
517 local node_number
518 # Make sure to kill all swift processes first
Chmouel Boudjnahad8b2762013-01-10 15:40:01 +0100519 swift-init --run-dir=${SWIFT_DATA_DIR}/run all stop || true
Attila Fazekasece6a332012-11-29 14:19:41 +0100520
Dean Troyer1c6c1122013-03-27 17:40:53 -0500521 # Forcibly re-create the backing filesystem
522 create_swift_disk
523
Attila Fazekasece6a332012-11-29 14:19:41 +0100524 # This is where we create three different rings for swift with
525 # different object servers binding on different ports.
Dean Troyer6ec72fa2013-03-13 11:44:53 -0500526 pushd ${SWIFT_CONF_DIR} >/dev/null && {
Attila Fazekasece6a332012-11-29 14:19:41 +0100527
528 rm -f *.builder *.ring.gz backups/*.builder backups/*.ring.gz
529
530 swift-ring-builder object.builder create ${SWIFT_PARTITION_POWER_SIZE} ${SWIFT_REPLICAS} 1
531 swift-ring-builder container.builder create ${SWIFT_PARTITION_POWER_SIZE} ${SWIFT_REPLICAS} 1
532 swift-ring-builder account.builder create ${SWIFT_PARTITION_POWER_SIZE} ${SWIFT_REPLICAS} 1
533
534 for node_number in ${SWIFT_REPLICAS_SEQ}; do
535 swift-ring-builder object.builder add z${node_number}-127.0.0.1:$[OBJECT_PORT_BASE + 10 * (node_number - 1)]/sdb1 1
536 swift-ring-builder container.builder add z${node_number}-127.0.0.1:$[CONTAINER_PORT_BASE + 10 * (node_number - 1)]/sdb1 1
537 swift-ring-builder account.builder add z${node_number}-127.0.0.1:$[ACCOUNT_PORT_BASE + 10 * (node_number - 1)]/sdb1 1
538 done
539 swift-ring-builder object.builder rebalance
540 swift-ring-builder container.builder rebalance
541 swift-ring-builder account.builder rebalance
542 } && popd >/dev/null
543
Dean Troyer64ab7742012-12-28 15:38:28 -0600544 # Create cache dir
545 sudo mkdir -p $SWIFT_AUTH_CACHE_DIR
Attila Fazekas91b8d132013-01-06 22:40:09 +0100546 sudo chown $STACK_USER $SWIFT_AUTH_CACHE_DIR
Dean Troyer64ab7742012-12-28 15:38:28 -0600547 rm -f $SWIFT_AUTH_CACHE_DIR/*
Attila Fazekasece6a332012-11-29 14:19:41 +0100548}
549
550function install_swift() {
551 git_clone $SWIFT_REPO $SWIFT_DIR $SWIFT_BRANCH
Dean Troyer253a1a32013-04-01 18:23:22 -0500552 setup_develop $SWIFT_DIR
zhang-hared98a5d02013-06-21 18:18:02 +0800553 if is_apache_enabled_service swift; then
554 install_apache_wsgi
555 fi
Attila Fazekasece6a332012-11-29 14:19:41 +0100556}
557
558function install_swiftclient() {
559 git_clone $SWIFTCLIENT_REPO $SWIFTCLIENT_DIR $SWIFTCLIENT_BRANCH
Dean Troyer253a1a32013-04-01 18:23:22 -0500560 setup_develop $SWIFTCLIENT_DIR
Attila Fazekasece6a332012-11-29 14:19:41 +0100561}
562
Attila Fazekasece6a332012-11-29 14:19:41 +0100563# start_swift() - Start running processes, including screen
564function start_swift() {
565 # (re)start rsyslog
566 restart_service rsyslog
Chmouel Boudjnah8ecbb382013-03-12 12:15:17 +0100567 # (re)start memcached to make sure we have a clean memcache.
568 restart_service memcached
569
Attila Fazekasece6a332012-11-29 14:19:41 +0100570 # Start rsync
Vincent Untzc18b9652012-12-04 12:36:34 +0100571 if is_ubuntu; then
Attila Fazekasece6a332012-11-29 14:19:41 +0100572 sudo /etc/init.d/rsync restart || :
573 else
574 sudo systemctl start xinetd.service
575 fi
576
zhang-hared98a5d02013-06-21 18:18:02 +0800577 if is_apache_enabled_service swift; then
zhang-hared98a5d02013-06-21 18:18:02 +0800578 restart_apache_server
579 swift-init --run-dir=${SWIFT_DATA_DIR}/run rest start
580 screen_it s-proxy "cd $SWIFT_DIR && sudo tail -f /var/log/$APACHE_NAME/proxy-server"
581 if [[ ${SWIFT_REPLICAS} == 1 ]]; then
582 for type in object container account; do
583 screen_it s-${type} "cd $SWIFT_DIR && sudo tail -f /var/log/$APACHE_NAME/${type}-server-1"
584 done
585 fi
586 return 0
587 fi
588
Sean Dague101b4242013-10-22 08:47:11 -0400589 # By default with only one replica we are launching the proxy,
590 # container, account and object server in screen in foreground and
591 # other services in background. If we have SWIFT_REPLICAS set to something
592 # greater than one we first spawn all the swift services then kill the proxy
593 # service so we can run it in foreground in screen. ``swift-init ...
594 # {stop|restart}`` exits with '1' if no servers are running, ignore it just
595 # in case
596 swift-init --run-dir=${SWIFT_DATA_DIR}/run all restart || true
597 if [[ ${SWIFT_REPLICAS} == 1 ]]; then
Chmouel Boudjnah0c3a5582013-03-06 10:58:33 +0100598 todo="object container account"
Sean Dague101b4242013-10-22 08:47:11 -0400599 fi
600 for type in proxy ${todo}; do
601 swift-init --run-dir=${SWIFT_DATA_DIR}/run ${type} stop || true
602 done
603 screen_it s-proxy "cd $SWIFT_DIR && $SWIFT_DIR/bin/swift-proxy-server ${SWIFT_CONF_DIR}/proxy-server.conf -v"
604 if [[ ${SWIFT_REPLICAS} == 1 ]]; then
605 for type in object container account; do
606 screen_it s-${type} "cd $SWIFT_DIR && $SWIFT_DIR/bin/swift-${type}-server ${SWIFT_CONF_DIR}/${type}-server/1.conf -v"
607 done
608 fi
Attila Fazekasece6a332012-11-29 14:19:41 +0100609}
610
611# stop_swift() - Stop running processes (non-screen)
612function stop_swift() {
zhang-hared98a5d02013-06-21 18:18:02 +0800613
614 if is_apache_enabled_service swift; then
615 swift-init --run-dir=${SWIFT_DATA_DIR}/run rest stop && return 0
616 fi
617
Attila Fazekasece6a332012-11-29 14:19:41 +0100618 # screen normally killed by unstack.sh
Dean Troyer995eb922013-03-07 16:11:40 -0600619 if type -p swift-init >/dev/null; then
Chmouel Boudjnah0c3a5582013-03-06 10:58:33 +0100620 swift-init --run-dir=${SWIFT_DATA_DIR}/run all stop || true
621 fi
Dean Troyer995eb922013-03-07 16:11:40 -0600622 # Dump the proxy server
623 sudo pkill -f swift-proxy-server
Attila Fazekasece6a332012-11-29 14:19:41 +0100624}
625
626# Restore xtrace
627$XTRACE
Sean Dague584d90e2013-03-29 14:34:53 -0400628
Adam Spiers6a5aa7c2013-10-24 11:27:02 +0100629# Tell emacs to use shell-script-mode
630## Local variables:
631## mode: shell-script
632## End: