blob: 3eed689932cb8fdbc62d096412576cc35fef6fa9 [file] [log] [blame]
Matthew Treinishb86cda92013-07-29 11:22:23 -04001# Copyright 2013 IBM Corp.
2#
3# Licensed under the Apache License, Version 2.0 (the "License"); you may
4# not use this file except in compliance with the License. You may obtain
5# a copy of the License at
6#
7# http://www.apache.org/licenses/LICENSE-2.0
8#
9# Unless required by applicable law or agreed to in writing, software
10# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
11# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
12# License for the specific language governing permissions and limitations
13# under the License.
14
Miguel Lavalleb8fabc52013-08-23 11:19:57 -050015import netaddr
Masayuki Igawabfa07602015-01-20 18:47:17 +090016from tempest_lib import exceptions as lib_exc
Miguel Lavalleb8fabc52013-08-23 11:19:57 -050017
Matthew Treinishb86cda92013-07-29 11:22:23 -040018from tempest import clients
Marc Kodererd2690fe2014-07-16 14:17:47 +020019from tempest.common import cred_provider
Masayuki Igawa259c1132013-10-31 17:48:44 +090020from tempest.common.utils import data_utils
Matthew Treinishb86cda92013-07-29 11:22:23 -040021from tempest import config
22from tempest import exceptions
23from tempest.openstack.common import log as logging
24
Sean Dague86bd8422013-12-20 09:56:44 -050025CONF = config.CONF
Matthew Treinishb86cda92013-07-29 11:22:23 -040026LOG = logging.getLogger(__name__)
27
28
Marc Kodererd2690fe2014-07-16 14:17:47 +020029class IsolatedCreds(cred_provider.CredentialProvider):
Matthew Treinishb86cda92013-07-29 11:22:23 -040030
Andrea Frittolic0978352015-02-06 15:57:40 +000031 def __init__(self, name, password='pass', network_resources=None):
32 super(IsolatedCreds, self).__init__(name, password, network_resources)
Matthew Treinish9f756a02014-01-15 10:26:07 -050033 self.network_resources = network_resources
Matthew Treinishb86cda92013-07-29 11:22:23 -040034 self.isolated_creds = {}
Miguel Lavalleb8fabc52013-08-23 11:19:57 -050035 self.isolated_net_resources = {}
36 self.ports = []
Matthew Treinishb86cda92013-07-29 11:22:23 -040037 self.password = password
Miguel Lavalleb8fabc52013-08-23 11:19:57 -050038 self.identity_admin_client, self.network_admin_client = (
39 self._get_admin_clients())
Matthew Treinishb86cda92013-07-29 11:22:23 -040040
Miguel Lavalleb8fabc52013-08-23 11:19:57 -050041 def _get_admin_clients(self):
Matthew Treinishb86cda92013-07-29 11:22:23 -040042 """
Miguel Lavalleb8fabc52013-08-23 11:19:57 -050043 Returns a tuple with instances of the following admin clients (in this
44 order):
45 identity
46 network
Matthew Treinishb86cda92013-07-29 11:22:23 -040047 """
Andrea Frittolic0978352015-02-06 15:57:40 +000048 os = clients.AdminManager()
Andrea Frittoli422fbdf2014-03-20 10:05:18 +000049 return os.identity_client, os.network_client
Matthew Treinishb86cda92013-07-29 11:22:23 -040050
51 def _create_tenant(self, name, description):
David Kranzb7afa922014-12-30 10:56:26 -050052 tenant = self.identity_admin_client.create_tenant(
Andrea Frittoliae9aca02014-09-25 11:43:11 +010053 name=name, description=description)
Matthew Treinishb86cda92013-07-29 11:22:23 -040054 return tenant
55
56 def _get_tenant_by_name(self, name):
David Kranzb7afa922014-12-30 10:56:26 -050057 tenant = self.identity_admin_client.get_tenant_by_name(name)
Matthew Treinishb86cda92013-07-29 11:22:23 -040058 return tenant
59
60 def _create_user(self, username, password, tenant, email):
David Kranzb7afa922014-12-30 10:56:26 -050061 user = self.identity_admin_client.create_user(
Andrea Frittoliae9aca02014-09-25 11:43:11 +010062 username, password, tenant['id'], email)
Matthew Treinishb86cda92013-07-29 11:22:23 -040063 return user
64
65 def _get_user(self, tenant, username):
David Kranzb7afa922014-12-30 10:56:26 -050066 user = self.identity_admin_client.get_user_by_username(
Andrea Frittoliae9aca02014-09-25 11:43:11 +010067 tenant['id'], username)
Matthew Treinishb86cda92013-07-29 11:22:23 -040068 return user
69
70 def _list_roles(self):
David Kranzb7afa922014-12-30 10:56:26 -050071 roles = self.identity_admin_client.list_roles()
Matthew Treinishb86cda92013-07-29 11:22:23 -040072 return roles
73
Andrey Pavlovaf1fb702014-05-29 17:08:10 +040074 def _assign_user_role(self, tenant, user, role_name):
75 role = None
76 try:
77 roles = self._list_roles()
Andrea Frittoliae9aca02014-09-25 11:43:11 +010078 role = next(r for r in roles if r['name'] == role_name)
Andrey Pavlovaf1fb702014-05-29 17:08:10 +040079 except StopIteration:
80 msg = 'No "%s" role found' % role_name
Masayuki Igawabfa07602015-01-20 18:47:17 +090081 raise lib_exc.NotFound(msg)
Andrea Frittoliae9aca02014-09-25 11:43:11 +010082 self.identity_admin_client.assign_user_role(tenant['id'], user['id'],
83 role['id'])
Matthew Treinishb86cda92013-07-29 11:22:23 -040084
85 def _delete_user(self, user):
Andrea Frittoliae9aca02014-09-25 11:43:11 +010086 self.identity_admin_client.delete_user(user)
Matthew Treinishb86cda92013-07-29 11:22:23 -040087
88 def _delete_tenant(self, tenant):
Ala Rezmerita846eb7c2014-03-10 09:06:03 +010089 if CONF.service_available.neutron:
90 self._cleanup_default_secgroup(tenant)
Andrea Frittoliae9aca02014-09-25 11:43:11 +010091 self.identity_admin_client.delete_tenant(tenant)
Matthew Treinishb86cda92013-07-29 11:22:23 -040092
Sean Dague6969b902014-01-28 06:48:37 -050093 def _create_creds(self, suffix="", admin=False):
94 """Create random credentials under the following schema.
95
96 If the name contains a '.' is the full class path of something, and
97 we don't really care. If it isn't, it's probably a meaningful name,
98 so use it.
99
100 For logging purposes, -user and -tenant are long and redundant,
101 don't use them. The user# will be sufficient to figure it out.
102 """
103 if '.' in self.name:
104 root = ""
105 else:
106 root = self.name
107
108 tenant_name = data_utils.rand_name(root) + suffix
Matthew Treinishb86cda92013-07-29 11:22:23 -0400109 tenant_desc = tenant_name + "-desc"
Matthew Treinishb86cda92013-07-29 11:22:23 -0400110 tenant = self._create_tenant(name=tenant_name,
111 description=tenant_desc)
Sean Dague6969b902014-01-28 06:48:37 -0500112
113 username = data_utils.rand_name(root) + suffix
114 email = data_utils.rand_name(root) + suffix + "@example.com"
Matthew Treinishb86cda92013-07-29 11:22:23 -0400115 user = self._create_user(username, self.password,
116 tenant, email)
Sergey Shnaidman37099612014-07-10 09:43:41 +0400117 if CONF.service_available.swift:
118 # NOTE(andrey-mp): user needs this role to create containers
119 # in swift
120 swift_operator_role = CONF.object_storage.operator_role
121 self._assign_user_role(tenant, user, swift_operator_role)
Matthew Treinishb86cda92013-07-29 11:22:23 -0400122 if admin:
Andrey Pavlovaf1fb702014-05-29 17:08:10 +0400123 self._assign_user_role(tenant, user, CONF.identity.admin_role)
Matthew Treinish167b2be2015-01-15 17:20:27 -0500124 for role in CONF.auth.tempest_roles:
Hugh Saunders33438a12015-01-15 14:26:57 +0000125 self._assign_user_role(tenant, user, role)
Andrea Frittoli9612e812014-03-13 10:57:26 +0000126 return self._get_credentials(user, tenant)
Matthew Treinishb86cda92013-07-29 11:22:23 -0400127
Andrea Frittolifc315902014-03-20 09:21:44 +0000128 def _get_credentials(self, user, tenant):
Andrea Frittoli878d5ab2015-01-30 13:22:50 +0000129 return cred_provider.get_credentials(
Andrea Frittoliae9aca02014-09-25 11:43:11 +0100130 username=user['name'], user_id=user['id'],
131 tenant_name=tenant['name'], tenant_id=tenant['id'],
Andrea Frittolifc315902014-03-20 09:21:44 +0000132 password=self.password)
Miguel Lavalleb8fabc52013-08-23 11:19:57 -0500133
134 def _create_network_resources(self, tenant_id):
135 network = None
136 subnet = None
137 router = None
Matthew Treinish9f756a02014-01-15 10:26:07 -0500138 # Make sure settings
139 if self.network_resources:
140 if self.network_resources['router']:
141 if (not self.network_resources['subnet'] or
142 not self.network_resources['network']):
143 raise exceptions.InvalidConfiguration(
144 'A router requires a subnet and network')
145 elif self.network_resources['subnet']:
146 if not self.network_resources['network']:
147 raise exceptions.InvalidConfiguration(
148 'A subnet requires a network')
149 elif self.network_resources['dhcp']:
150 raise exceptions.InvalidConfiguration('DHCP requires a subnet')
151
Masayuki Igawa259c1132013-10-31 17:48:44 +0900152 data_utils.rand_name_root = data_utils.rand_name(self.name)
Matthew Treinish9f756a02014-01-15 10:26:07 -0500153 if not self.network_resources or self.network_resources['network']:
154 network_name = data_utils.rand_name_root + "-network"
155 network = self._create_network(network_name, tenant_id)
Miguel Lavalleb8fabc52013-08-23 11:19:57 -0500156 try:
Matthew Treinish9f756a02014-01-15 10:26:07 -0500157 if not self.network_resources or self.network_resources['subnet']:
158 subnet_name = data_utils.rand_name_root + "-subnet"
159 subnet = self._create_subnet(subnet_name, tenant_id,
160 network['id'])
161 if not self.network_resources or self.network_resources['router']:
162 router_name = data_utils.rand_name_root + "-router"
163 router = self._create_router(router_name, tenant_id)
164 self._add_router_interface(router['id'], subnet['id'])
Miguel Lavalleb8fabc52013-08-23 11:19:57 -0500165 except Exception:
166 if router:
167 self._clear_isolated_router(router['id'], router['name'])
168 if subnet:
169 self._clear_isolated_subnet(subnet['id'], subnet['name'])
170 if network:
171 self._clear_isolated_network(network['id'], network['name'])
172 raise
173 return network, subnet, router
174
175 def _create_network(self, name, tenant_id):
David Kranz34e88122014-12-11 15:24:05 -0500176 resp_body = self.network_admin_client.create_network(
Andrea Frittoliae9aca02014-09-25 11:43:11 +0100177 name=name, tenant_id=tenant_id)
Miguel Lavalleb8fabc52013-08-23 11:19:57 -0500178 return resp_body['network']
179
180 def _create_subnet(self, subnet_name, tenant_id, network_id):
Sean Dague86bd8422013-12-20 09:56:44 -0500181 base_cidr = netaddr.IPNetwork(CONF.network.tenant_network_cidr)
182 mask_bits = CONF.network.tenant_network_mask_bits
Miguel Lavalleb8fabc52013-08-23 11:19:57 -0500183 for subnet_cidr in base_cidr.subnet(mask_bits):
184 try:
Andrea Frittoliae9aca02014-09-25 11:43:11 +0100185 if self.network_resources:
David Kranz34e88122014-12-11 15:24:05 -0500186 resp_body = self.network_admin_client.\
Andrea Frittoliae9aca02014-09-25 11:43:11 +0100187 create_subnet(
188 network_id=network_id, cidr=str(subnet_cidr),
189 name=subnet_name,
190 tenant_id=tenant_id,
191 enable_dhcp=self.network_resources['dhcp'],
192 ip_version=4)
Miguel Lavalleb8fabc52013-08-23 11:19:57 -0500193 else:
David Kranz34e88122014-12-11 15:24:05 -0500194 resp_body = self.network_admin_client.\
Andrea Frittoliae9aca02014-09-25 11:43:11 +0100195 create_subnet(network_id=network_id,
196 cidr=str(subnet_cidr),
197 name=subnet_name,
198 tenant_id=tenant_id,
199 ip_version=4)
Miguel Lavalleb8fabc52013-08-23 11:19:57 -0500200 break
Masayuki Igawa4b29e472015-02-16 10:41:54 +0900201 except lib_exc.BadRequest as e:
Miguel Lavalleb8fabc52013-08-23 11:19:57 -0500202 if 'overlaps with another subnet' not in str(e):
203 raise
204 else:
David Kranzd4210412014-11-21 08:37:45 -0500205 message = 'Available CIDR for subnet creation could not be found'
206 raise Exception(message)
Miguel Lavalleb8fabc52013-08-23 11:19:57 -0500207 return resp_body['subnet']
208
209 def _create_router(self, router_name, tenant_id):
210 external_net_id = dict(
Sean Dague86bd8422013-12-20 09:56:44 -0500211 network_id=CONF.network.public_network_id)
David Kranz34e88122014-12-11 15:24:05 -0500212 resp_body = self.network_admin_client.create_router(
Andrea Frittoliae9aca02014-09-25 11:43:11 +0100213 router_name,
214 external_gateway_info=external_net_id,
215 tenant_id=tenant_id)
Miguel Lavalleb8fabc52013-08-23 11:19:57 -0500216 return resp_body['router']
217
218 def _add_router_interface(self, router_id, subnet_id):
Andrea Frittoliae9aca02014-09-25 11:43:11 +0100219 self.network_admin_client.add_router_interface_with_subnet_id(
220 router_id, subnet_id)
Miguel Lavalleb8fabc52013-08-23 11:19:57 -0500221
Miguel Lavalleb8fabc52013-08-23 11:19:57 -0500222 def get_primary_network(self):
223 return self.isolated_net_resources.get('primary')[0]
224
225 def get_primary_subnet(self):
226 return self.isolated_net_resources.get('primary')[1]
227
228 def get_primary_router(self):
229 return self.isolated_net_resources.get('primary')[2]
230
231 def get_admin_network(self):
232 return self.isolated_net_resources.get('admin')[0]
233
234 def get_admin_subnet(self):
235 return self.isolated_net_resources.get('admin')[1]
236
237 def get_admin_router(self):
238 return self.isolated_net_resources.get('admin')[2]
239
240 def get_alt_network(self):
241 return self.isolated_net_resources.get('alt')[0]
242
243 def get_alt_subnet(self):
244 return self.isolated_net_resources.get('alt')[1]
245
246 def get_alt_router(self):
247 return self.isolated_net_resources.get('alt')[2]
248
Andrea Frittoli9612e812014-03-13 10:57:26 +0000249 def get_credentials(self, credential_type):
Andrea Frittolifc315902014-03-20 09:21:44 +0000250 if self.isolated_creds.get(credential_type):
251 credentials = self.isolated_creds[credential_type]
Matthew Treinishb86cda92013-07-29 11:22:23 -0400252 else:
Andrea Frittolifc315902014-03-20 09:21:44 +0000253 is_admin = (credential_type == 'admin')
Andrea Frittoli9612e812014-03-13 10:57:26 +0000254 credentials = self._create_creds(admin=is_admin)
Andrea Frittolifc315902014-03-20 09:21:44 +0000255 self.isolated_creds[credential_type] = credentials
256 # Maintained until tests are ported
Andrea Frittolifc315902014-03-20 09:21:44 +0000257 LOG.info("Acquired isolated creds:\n credentials: %s"
258 % credentials)
Adam Gandelman85395e72014-07-29 18:34:33 -0700259 if (CONF.service_available.neutron and
260 not CONF.baremetal.driver_enabled):
Miguel Lavalleb8fabc52013-08-23 11:19:57 -0500261 network, subnet, router = self._create_network_resources(
Andrea Frittolifc315902014-03-20 09:21:44 +0000262 credentials.tenant_id)
263 self.isolated_net_resources[credential_type] = (
Miguel Lavalleb8fabc52013-08-23 11:19:57 -0500264 network, subnet, router,)
265 LOG.info("Created isolated network resources for : \n"
Andrea Frittolifc315902014-03-20 09:21:44 +0000266 + " credentials: %s" % credentials)
Andrea Frittoli9612e812014-03-13 10:57:26 +0000267 return credentials
Matthew Treinishb86cda92013-07-29 11:22:23 -0400268
Andrea Frittoli9612e812014-03-13 10:57:26 +0000269 def get_primary_creds(self):
270 return self.get_credentials('primary')
Matthew Treinishb86cda92013-07-29 11:22:23 -0400271
Andrea Frittoli9612e812014-03-13 10:57:26 +0000272 def get_admin_creds(self):
273 return self.get_credentials('admin')
Andrea Frittolifc315902014-03-20 09:21:44 +0000274
Andrea Frittoli9612e812014-03-13 10:57:26 +0000275 def get_alt_creds(self):
276 return self.get_credentials('alt')
Matthew Treinishb86cda92013-07-29 11:22:23 -0400277
Miguel Lavalleb8fabc52013-08-23 11:19:57 -0500278 def _clear_isolated_router(self, router_id, router_name):
279 net_client = self.network_admin_client
280 try:
281 net_client.delete_router(router_id)
Masayuki Igawabfa07602015-01-20 18:47:17 +0900282 except lib_exc.NotFound:
Miguel Lavalleb8fabc52013-08-23 11:19:57 -0500283 LOG.warn('router with name: %s not found for delete' %
284 router_name)
Miguel Lavalleb8fabc52013-08-23 11:19:57 -0500285
286 def _clear_isolated_subnet(self, subnet_id, subnet_name):
287 net_client = self.network_admin_client
288 try:
289 net_client.delete_subnet(subnet_id)
Masayuki Igawabfa07602015-01-20 18:47:17 +0900290 except lib_exc.NotFound:
Miguel Lavalleb8fabc52013-08-23 11:19:57 -0500291 LOG.warn('subnet with name: %s not found for delete' %
292 subnet_name)
Miguel Lavalleb8fabc52013-08-23 11:19:57 -0500293
294 def _clear_isolated_network(self, network_id, network_name):
295 net_client = self.network_admin_client
296 try:
297 net_client.delete_network(network_id)
Masayuki Igawabfa07602015-01-20 18:47:17 +0900298 except lib_exc.NotFound:
Miguel Lavalleb8fabc52013-08-23 11:19:57 -0500299 LOG.warn('network with name: %s not found for delete' %
300 network_name)
Miguel Lavalleb8fabc52013-08-23 11:19:57 -0500301
Ala Rezmerita846eb7c2014-03-10 09:06:03 +0100302 def _cleanup_default_secgroup(self, tenant):
303 net_client = self.network_admin_client
David Kranz34e88122014-12-11 15:24:05 -0500304 resp_body = net_client.list_security_groups(tenant_id=tenant,
305 name="default")
Ala Rezmerita846eb7c2014-03-10 09:06:03 +0100306 secgroups_to_delete = resp_body['security_groups']
307 for secgroup in secgroups_to_delete:
308 try:
309 net_client.delete_security_group(secgroup['id'])
Masayuki Igawabfa07602015-01-20 18:47:17 +0900310 except lib_exc.NotFound:
Ala Rezmerita846eb7c2014-03-10 09:06:03 +0100311 LOG.warn('Security group %s, id %s not found for clean-up' %
312 (secgroup['name'], secgroup['id']))
313
Miguel Lavalleb8fabc52013-08-23 11:19:57 -0500314 def _clear_isolated_net_resources(self):
315 net_client = self.network_admin_client
316 for cred in self.isolated_net_resources:
317 network, subnet, router = self.isolated_net_resources.get(cred)
Salvatore Orlandocf996c62014-01-30 09:15:18 -0800318 LOG.debug("Clearing network: %(network)s, "
Matthew Treinishfe094ea2014-12-09 01:19:27 +0000319 "subnet: %(subnet)s, router: %(router)s",
320 {'network': network, 'subnet': subnet, 'router': router})
Salvatore Orlandocf996c62014-01-30 09:15:18 -0800321 if (not self.network_resources or
322 self.network_resources.get('router')):
Matthew Treinish9f756a02014-01-15 10:26:07 -0500323 try:
Andrea Frittoliae9aca02014-09-25 11:43:11 +0100324 net_client.remove_router_interface_with_subnet_id(
325 router['id'], subnet['id'])
Masayuki Igawabfa07602015-01-20 18:47:17 +0900326 except lib_exc.NotFound:
Matthew Treinish9f756a02014-01-15 10:26:07 -0500327 LOG.warn('router with name: %s not found for delete' %
328 router['name'])
Matthew Treinish9f756a02014-01-15 10:26:07 -0500329 self._clear_isolated_router(router['id'], router['name'])
Salvatore Orlandocf996c62014-01-30 09:15:18 -0800330 if (not self.network_resources or
Salvatore Orlandocf996c62014-01-30 09:15:18 -0800331 self.network_resources.get('subnet')):
Matthew Treinish9f756a02014-01-15 10:26:07 -0500332 self._clear_isolated_subnet(subnet['id'], subnet['name'])
Salvatore Orlandocf996c62014-01-30 09:15:18 -0800333 if (not self.network_resources or
334 self.network_resources.get('network')):
Matthew Treinish9f756a02014-01-15 10:26:07 -0500335 self._clear_isolated_network(network['id'], network['name'])
ahmadfe72a402015-02-13 17:30:36 +0530336 self.isolated_net_resources = {}
Miguel Lavalleb8fabc52013-08-23 11:19:57 -0500337
Matthew Treinishb86cda92013-07-29 11:22:23 -0400338 def clear_isolated_creds(self):
339 if not self.isolated_creds:
340 return
Miguel Lavalleb8fabc52013-08-23 11:19:57 -0500341 self._clear_isolated_net_resources()
Andrea Frittolifc315902014-03-20 09:21:44 +0000342 for creds in self.isolated_creds.itervalues():
Matthew Treinishb86cda92013-07-29 11:22:23 -0400343 try:
Andrea Frittolifc315902014-03-20 09:21:44 +0000344 self._delete_user(creds.user_id)
Masayuki Igawabfa07602015-01-20 18:47:17 +0900345 except lib_exc.NotFound:
Andrea Frittolifc315902014-03-20 09:21:44 +0000346 LOG.warn("user with name: %s not found for delete" %
347 creds.username)
Matthew Treinishb86cda92013-07-29 11:22:23 -0400348 try:
Andrea Frittolifc315902014-03-20 09:21:44 +0000349 self._delete_tenant(creds.tenant_id)
Masayuki Igawabfa07602015-01-20 18:47:17 +0900350 except lib_exc.NotFound:
Andrea Frittolifc315902014-03-20 09:21:44 +0000351 LOG.warn("tenant with name: %s not found for delete" %
352 creds.tenant_name)
ahmadfe72a402015-02-13 17:30:36 +0530353 self.isolated_creds = {}
Andrea Frittoli8283b4e2014-07-17 13:28:58 +0100354
355 def is_multi_user(self):
356 return True
Yair Fried76488d72014-10-21 10:13:19 +0300357
358 def is_multi_tenant(self):
359 return True