2 ##############################################################################
3 # Copyright (c) 2015 Tim Rozet (Red Hat), Dan Radez (Red Hat) and others.
5 # All rights reserved. This program and the accompanying materials
6 # are made available under the terms of the Apache License, Version 2.0
7 # which accompanies this distribution, and is available at
8 # http://www.apache.org/licenses/LICENSE-2.0
9 ##############################################################################
11 # Deploy script to install provisioning server for OPNFV Apex
12 # author: Dan Radez (dradez@redhat.com)
13 # author: Tim Rozet (trozet@redhat.com)
15 # Based on RDO Manager http://www.rdoproject.org
20 reset=$(tput sgr0 || echo "")
21 blue=$(tput setaf 4 || echo "")
22 red=$(tput setaf 1 || echo "")
23 green=$(tput setaf 2 || echo "")
27 ntp_server="pool.ntp.org"
28 net_isolation_enabled="TRUE"
34 declare -A deploy_options_array
35 declare -a performance_options
38 SSH_OPTIONS=(-o StrictHostKeyChecking=no -o GlobalKnownHostsFile=/dev/null -o UserKnownHostsFile=/dev/null -o LogLevel=error)
40 CONFIG=${CONFIG:-'/var/opt/opnfv'}
41 RESOURCES=${RESOURCES:-"$CONFIG/images"}
42 LIB=${LIB:-"$CONFIG/lib"}
43 OPNFV_NETWORK_TYPES="admin_network private_network public_network storage_network"
49 # Netmap used to map networks to OVS bridge names
50 NET_MAP['admin_network']="br-admin"
51 NET_MAP['private_network']="br-private"
52 NET_MAP['public_network']="br-public"
53 NET_MAP['storage_network']="br-storage"
54 ext_net_type="interface"
59 $LIB/common-functions.sh
60 $LIB/utility-functions.sh
61 $LIB/installer/onos/onos_gw_mac_update.sh
63 for lib_file in ${lib_files[@]}; do
64 if ! source $lib_file; then
65 echo -e "${red}ERROR: Failed to source $lib_file${reset}"
71 ##translates yaml into variables
72 ##params: filename, prefix (ex. "config_")
73 ##usage: parse_yaml opnfv_ksgen_settings.yml "config_"
76 local s='[[:space:]]*' w='[a-zA-Z0-9_]*' fs=$(echo @|tr @ '\034')
77 sed -ne "s|^\($s\)\($w\)$s:$s\"\(.*\)\"$s\$|\1$fs\2$fs\3|p" \
78 -e "s|^\($s\)\($w\)$s:$s\(.*\)$s\$|\1$fs\2$fs\3|p" $1 |
80 indent = length($1)/2;
82 for (i in vname) {if (i > indent) {delete vname[i]}}
84 vn=""; for (i=0; i<indent; i++) {vn=(vn)(vname[i])("_")}
85 printf("%s%s%s=%s\n", "'$prefix'",vn, $2, $3);
90 ##checks if prefix exists in string
91 ##params: string, prefix
92 ##usage: contains_prefix "deploy_setting_launcher=1" "deploy_setting"
96 if echo $mystr | grep -E "^$prefix.*$" > /dev/null; then
102 ##parses variable from a string with '='
103 ##and removes global prefix
104 ##params: string, prefix
105 ##usage: parse_setting_var 'deploy_myvar=2' 'deploy_'
106 parse_setting_var() {
109 if echo $mystr | grep -E "^.+\=" > /dev/null; then
110 echo $(echo $mystr | grep -Eo "^.+\=" | tr -d '=' | sed 's/^'"$prefix"'//')
115 ##parses value from a string with '='
117 ##usage: parse_setting_value
118 parse_setting_value() {
120 echo $(echo $mystr | grep -Eo "\=.*$" | tr -d '=')
123 ##parses network settings yaml into globals
124 parse_network_settings() {
126 if output=$(python3.4 -B $LIB/python/apex-python-utils.py parse-net-settings -s $NETSETS -i $net_isolation_enabled -e $CONFIG/network-environment.yaml); then
127 echo -e "${blue}${output}${reset}"
130 echo -e "${red}ERROR: Failed to parse network settings file $NETSETS ${reset}"
135 ##parses deploy settings yaml into globals
136 parse_deploy_settings() {
138 if output=$(python3.4 -B $LIB/python/apex-python-utils.py parse-deploy-settings -f $DEPLOY_SETTINGS_FILE); then
139 echo -e "${blue}${output}${reset}"
142 echo -e "${red}ERROR: Failed to parse deploy settings file $DEPLOY_SETTINGS_FILE ${reset}"
147 ##parses baremetal yaml settings into compatible json
148 ##writes the json to $CONFIG/instackenv_tmp.json
150 ##usage: parse_inventory_file
151 parse_inventory_file() {
152 local inventory=$(parse_yaml $INVENTORY_FILE)
154 local node_prefix="node"
159 # detect number of nodes
160 for entry in $inventory; do
161 if echo $entry | grep -Eo "^nodes_node[0-9]+_" > /dev/null; then
162 this_node=$(echo $entry | grep -Eo "^nodes_node[0-9]+_")
163 if [[ "$inventory_list" != *"$this_node"* ]]; then
164 inventory_list+="$this_node "
169 inventory_list=$(echo $inventory_list | sed 's/ $//')
171 for node in $inventory_list; do
175 node_total=$node_count
177 if [[ "$node_total" -lt 5 && "$ha_enabled" == "True" ]]; then
178 echo -e "${red}ERROR: You must provide at least 5 nodes for HA baremetal deployment${reset}"
180 elif [[ "$node_total" -lt 2 ]]; then
181 echo -e "${red}ERROR: You must provide at least 2 nodes for non-HA baremetal deployment${reset}"
185 eval $(parse_yaml $INVENTORY_FILE) || {
186 echo "${red}Failed to parse inventory.yaml. Aborting.${reset}"
196 for node in $inventory_list; do
200 \"pm_password\": \"$(eval echo \${${node}ipmi_pass})\",
201 \"pm_type\": \"$(eval echo \${${node}pm_type})\",
203 \"$(eval echo \${${node}mac_address})\"
205 \"cpu\": \"$(eval echo \${${node}cpus})\",
206 \"memory\": \"$(eval echo \${${node}memory})\",
207 \"disk\": \"$(eval echo \${${node}disk})\",
208 \"arch\": \"$(eval echo \${${node}arch})\",
209 \"pm_user\": \"$(eval echo \${${node}ipmi_user})\",
210 \"pm_addr\": \"$(eval echo \${${node}ipmi_ip})\",
211 \"capabilities\": \"$(eval echo \${${node}capabilities})\"
213 instackenv_output+=${node_output}
214 if [ $node_count -lt $node_total ]; then
215 instackenv_output+=" },"
217 instackenv_output+=" }"
225 #Copy instackenv.json to undercloud for baremetal
226 echo -e "{blue}Parsed instackenv JSON:\n${instackenv_output}${reset}"
227 ssh -T ${SSH_OPTIONS[@]} "stack@$UNDERCLOUD" <<EOI
228 cat > instackenv.json << EOF
234 ##verify internet connectivity
236 function verify_internet {
237 if ping -c 2 $ping_site > /dev/null; then
238 if ping -c 2 www.google.com > /dev/null; then
239 echo "${blue}Internet connectivity detected${reset}"
242 echo "${red}Internet connectivity detected, but DNS lookup failed${reset}"
246 echo "${red}No internet connectivity detected${reset}"
251 ##download dependencies if missing and configure host
253 function configure_deps {
254 if ! verify_internet; then
255 echo "${red}Will not download dependencies${reset}"
259 # verify ip forwarding
260 if sysctl net.ipv4.ip_forward | grep 0; then
261 sudo sysctl -w net.ipv4.ip_forward=1
262 sudo sh -c "echo 'net.ipv4.ip_forward = 1' >> /etc/sysctl.conf"
265 # ensure no dhcp server is running on jumphost
266 if ! sudo systemctl status dhcpd | grep dead; then
267 echo "${red}WARN: DHCP Server detected on jumphost, disabling...${reset}"
268 sudo systemctl stop dhcpd
269 sudo systemctl disable dhcpd
272 # ensure networks are configured
273 systemctl status libvirtd || systemctl start libvirtd
274 systemctl status openvswitch || systemctl start openvswitch
276 # If flat we only use admin network
277 if [[ "$net_isolation_enabled" == "FALSE" ]]; then
278 virsh_enabled_networks="admin_network"
279 enabled_network_list="admin_network"
280 # For baremetal we only need to create/attach Undercloud to admin and public
281 elif [ "$virtual" == "FALSE" ]; then
282 virsh_enabled_networks="admin_network public_network"
284 virsh_enabled_networks=$enabled_network_list
287 # ensure default network is configured correctly
288 libvirt_dir="/usr/share/libvirt/networks"
289 virsh net-list --all | grep default || virsh net-define ${libvirt_dir}/default.xml
290 virsh net-list --all | grep -E "default\s+active" > /dev/null || virsh net-start default
291 virsh net-list --all | grep -E "default\s+active\s+yes" > /dev/null || virsh net-autostart --network default
293 if [[ -z "$virtual" || "$virtual" == "FALSE" ]]; then
294 for network in ${OPNFV_NETWORK_TYPES}; do
295 echo "${blue}INFO: Creating Virsh Network: $network & OVS Bridge: ${NET_MAP[$network]}${reset}"
296 ovs-vsctl list-br | grep "^${NET_MAP[$network]}$" > /dev/null || ovs-vsctl add-br ${NET_MAP[$network]}
297 virsh net-list --all | grep $network > /dev/null || (cat > ${libvirt_dir}/apex-virsh-net.xml && virsh net-define ${libvirt_dir}/apex-virsh-net.xml) << EOF
299 <name>$network</name>
300 <forward mode='bridge'/>
301 <bridge name='${NET_MAP[$network]}'/>
302 <virtualport type='openvswitch'/>
305 if ! (virsh net-list --all | grep $network > /dev/null); then
306 echo "${red}ERROR: unable to create network: ${network}${reset}"
309 rm -f ${libvirt_dir}/apex-virsh-net.xml &> /dev/null;
310 virsh net-list | grep -E "$network\s+active" > /dev/null || virsh net-start $network
311 virsh net-list | grep -E "$network\s+active\s+yes" > /dev/null || virsh net-autostart --network $network
314 echo -e "${blue}INFO: Bridges set: ${reset}"
317 # bridge interfaces to correct OVS instances for baremetal deployment
318 for network in ${enabled_network_list}; do
319 if [[ "$network" != "admin_network" && "$network" != "public_network" ]]; then
322 this_interface=$(eval echo \${${network}_bridged_interface})
323 # check if this a bridged interface for this network
324 if [[ ! -z "$this_interface" || "$this_interface" != "none" ]]; then
325 if ! attach_interface_to_ovs ${NET_MAP[$network]} ${this_interface} ${network}; then
326 echo -e "${red}ERROR: Unable to bridge interface ${this_interface} to bridge ${NET_MAP[$network]} for enabled network: ${network}${reset}"
329 echo -e "${blue}INFO: Interface ${this_interface} bridged to bridge ${NET_MAP[$network]} for enabled network: ${network}${reset}"
332 echo "${red}ERROR: Unable to determine interface to bridge to for enabled network: ${network}${reset}"
337 for network in ${OPNFV_NETWORK_TYPES}; do
338 echo "${blue}INFO: Creating Virsh Network: $network${reset}"
339 virsh net-list --all | grep $network > /dev/null || (cat > ${libvirt_dir}/apex-virsh-net.xml && virsh net-define ${libvirt_dir}/apex-virsh-net.xml) << EOF
341 <name>$network</name>
342 <bridge name='${NET_MAP[$network]}'/>
345 if ! (virsh net-list --all | grep $network > /dev/null); then
346 echo "${red}ERROR: unable to create network: ${network}${reset}"
349 rm -f ${libvirt_dir}/apex-virsh-net.xml &> /dev/null;
350 virsh net-list | grep -E "$network\s+active" > /dev/null || virsh net-start $network
351 virsh net-list | grep -E "$network\s+active\s+yes" > /dev/null || virsh net-autostart --network $network
354 echo -e "${blue}INFO: Bridges set: ${reset}"
358 echo -e "${blue}INFO: virsh networks set: ${reset}"
361 # ensure storage pool exists and is started
362 virsh pool-list --all | grep default > /dev/null || virsh pool-define-as --name default dir --target /var/lib/libvirt/images
363 virsh pool-list | grep -Eo "default\s+active" > /dev/null || (virsh pool-autostart default; virsh pool-start default)
365 if ! egrep '^flags.*(vmx|svm)' /proc/cpuinfo > /dev/null; then
366 echo "${red}virtualization extensions not found, kvm kernel module insertion may fail.\n \
367 Are you sure you have enabled vmx in your bios or hypervisor?${reset}"
370 if ! lsmod | grep kvm > /dev/null; then modprobe kvm; fi
371 if ! lsmod | grep kvm_intel > /dev/null; then modprobe kvm_intel; fi
373 if ! lsmod | grep kvm > /dev/null; then
374 echo "${red}kvm kernel modules not loaded!${reset}"
379 if [ ! -e ~/.ssh/id_rsa.pub ]; then
380 ssh-keygen -t rsa -N "" -f ~/.ssh/id_rsa
383 echo "${blue}All dependencies installed and running${reset}"
386 ##verify vm exists, an has a dhcp lease assigned to it
388 function setup_undercloud_vm {
389 if ! virsh list --all | grep undercloud > /dev/null; then
390 undercloud_nets="default admin_network"
391 if [[ $enabled_network_list =~ "public_network" ]]; then
392 undercloud_nets+=" public_network"
394 define_vm undercloud hd 30 "$undercloud_nets" 4 12288
396 ### this doesn't work for some reason I was getting hangup events so using cp instead
397 #virsh vol-upload --pool default --vol undercloud.qcow2 --file $CONFIG/stack/undercloud.qcow2
398 #2015-12-05 12:57:20.569+0000: 8755: info : libvirt version: 1.2.8, package: 16.el7_1.5 (CentOS BuildSystem <http://bugs.centos.org>, 2015-11-03-13:56:46, worker1.bsys.centos.org)
399 #2015-12-05 12:57:20.569+0000: 8755: warning : virKeepAliveTimerInternal:143 : No response from client 0x7ff1e231e630 after 6 keepalive messages in 35 seconds
400 #2015-12-05 12:57:20.569+0000: 8756: warning : virKeepAliveTimerInternal:143 : No response from client 0x7ff1e231e630 after 6 keepalive messages in 35 seconds
401 #error: cannot close volume undercloud.qcow2
402 #error: internal error: received hangup / error event on socket
403 #error: Reconnected to the hypervisor
405 local undercloud_dst=/var/lib/libvirt/images/undercloud.qcow2
406 cp -f $RESOURCES/undercloud.qcow2 $undercloud_dst
408 # resize Undercloud machine
409 echo "Checking if Undercloud needs to be resized..."
410 undercloud_size=$(LIBGUESTFS_BACKEND=direct virt-filesystems --long -h --all -a $undercloud_dst |grep device | grep -Eo "[0-9\.]+G" | sed -n 's/\([0-9][0-9]*\).*/\1/p')
411 if [ "$undercloud_size" -lt 30 ]; then
412 qemu-img resize /var/lib/libvirt/images/undercloud.qcow2 +25G
413 LIBGUESTFS_BACKEND=direct virt-resize --expand /dev/sda1 $RESOURCES/undercloud.qcow2 $undercloud_dst
414 LIBGUESTFS_BACKEND=direct virt-customize -a $undercloud_dst --run-command 'xfs_growfs -d /dev/sda1 || true'
415 new_size=$(LIBGUESTFS_BACKEND=direct virt-filesystems --long -h --all -a $undercloud_dst |grep filesystem | grep -Eo "[0-9\.]+G" | sed -n 's/\([0-9][0-9]*\).*/\1/p')
416 if [ "$new_size" -lt 30 ]; then
417 echo "Error resizing Undercloud machine, disk size is ${new_size}"
420 echo "Undercloud successfully resized"
423 echo "Skipped Undercloud resize, upstream is large enough"
427 echo "Found Undercloud VM, using existing VM"
430 # if the VM is not running update the authkeys and start it
431 if ! virsh list | grep undercloud > /dev/null; then
432 echo "Injecting ssh key to Undercloud VM"
433 LIBGUESTFS_BACKEND=direct virt-customize -a $undercloud_dst --run-command "mkdir -p /root/.ssh/" \
434 --upload ~/.ssh/id_rsa.pub:/root/.ssh/authorized_keys \
435 --run-command "chmod 600 /root/.ssh/authorized_keys && restorecon /root/.ssh/authorized_keys" \
436 --run-command "cp /root/.ssh/authorized_keys /home/stack/.ssh/" \
437 --run-command "chown stack:stack /home/stack/.ssh/authorized_keys && chmod 600 /home/stack/.ssh/authorized_keys"
438 virsh start undercloud
441 sleep 10 # let undercloud get started up
443 # get the undercloud VM IP
445 echo -n "${blue}Waiting for Undercloud's dhcp address${reset}"
446 undercloud_mac=$(virsh domiflist undercloud | grep default | awk '{ print $5 }')
447 while ! $(arp -e | grep ${undercloud_mac} > /dev/null) && [ $CNT -gt 0 ]; do
452 UNDERCLOUD=$(arp -e | grep ${undercloud_mac} | awk {'print $1'})
454 if [ -z "$UNDERCLOUD" ]; then
455 echo "\n\nCan't get IP for Undercloud. Can Not Continue."
458 echo -e "${blue}\rUndercloud VM has IP $UNDERCLOUD${reset}"
462 echo -en "${blue}\rValidating Undercloud VM connectivity${reset}"
463 while ! ping -c 1 $UNDERCLOUD > /dev/null && [ $CNT -gt 0 ]; do
468 if [ "$CNT" -eq 0 ]; then
469 echo "Failed to contact Undercloud. Can Not Continue"
473 while ! ssh -T ${SSH_OPTIONS[@]} "root@$UNDERCLOUD" "echo ''" 2>&1> /dev/null && [ $CNT -gt 0 ]; do
478 if [ "$CNT" -eq 0 ]; then
479 echo "Failed to connect to Undercloud. Can Not Continue"
483 # extra space to overwrite the previous connectivity output
484 echo -e "${blue}\r ${reset}"
486 ssh -T ${SSH_OPTIONS[@]} "root@$UNDERCLOUD" "if ! ip a s eth2 | grep ${public_network_provisioner_ip} > /dev/null; then ip a a ${public_network_provisioner_ip}/${public_network_cidr##*/} dev eth2; ip link set up dev eth2; fi"
488 # ssh key fix for stack user
489 ssh -T ${SSH_OPTIONS[@]} "root@$UNDERCLOUD" "restorecon -r /home/stack"
492 ##Create virtual nodes in virsh
493 ##params: vcpus, ramsize
494 function setup_virtual_baremetal {
499 elif [ -z "$2" ]; then
506 #start by generating the opening json for instackenv.json
507 cat > $CONFIG/instackenv-virt.json << EOF
512 # next create the virtual machines and add their definitions to the file
513 if [ ha_enabled == "False" ]; then
514 # 1 controller + computes
515 # zero based so just pass compute count
516 vm_index=$VM_COMPUTES
518 # 3 controller + computes
519 # zero based so add 2 to compute count
520 vm_index=$((2+$VM_COMPUTES))
523 for i in $(seq 0 $vm_index); do
524 if ! virsh list --all | grep baremetal${i} > /dev/null; then
525 define_vm baremetal${i} network 41 'admin_network' $vcpus $ramsize
526 for n in private_network public_network storage_network; do
527 if [[ $enabled_network_list =~ $n ]]; then
529 virsh attach-interface --domain baremetal${i} --type network --source $n --model rtl8139 --config
533 echo "Found Baremetal ${i} VM, using existing VM"
535 #virsh vol-list default | grep baremetal${i} 2>&1> /dev/null || virsh vol-create-as default baremetal${i}.qcow2 41G --format qcow2
536 mac=$(virsh domiflist baremetal${i} | grep admin_network | awk '{ print $5 }')
538 cat >> $CONFIG/instackenv-virt.json << EOF
540 "pm_addr": "192.168.122.1",
542 "pm_password": "INSERT_STACK_USER_PRIV_KEY",
543 "pm_type": "pxe_ssh",
548 "memory": "$ramsize",
555 #truncate the last line to remove the comma behind the bracket
556 tail -n 1 $CONFIG/instackenv-virt.json | wc -c | xargs -I {} truncate $CONFIG/instackenv-virt.json -s -{}
558 #finally reclose the bracket and close the instackenv.json file
559 cat >> $CONFIG/instackenv-virt.json << EOF
563 "host-ip": "192.168.122.1",
564 "power_manager": "nova.virt.baremetal.virtual_power_driver.VirtualPowerManager",
566 "ssh-key": "INSERT_STACK_USER_PRIV_KEY",
572 ##Create virtual nodes in virsh
573 ##params: name - String: libvirt name for VM
574 ## bootdev - String: boot device for the VM
575 ## disksize - Number: size of the disk in GB
576 ## ovs_bridges: - List: list of ovs bridges
577 ## vcpus - Number of VCPUs to use (defaults to 4)
578 ## ramsize - Size of RAM for VM in MB (defaults to 8192)
579 function define_vm () {
585 elif [ -z "$6" ]; then
593 # Create the libvirt storage volume
594 if virsh vol-list default | grep ${1}.qcow2 2>&1> /dev/null; then
595 volume_path=$(virsh vol-path --pool default ${1}.qcow2 || echo "/var/lib/libvirt/images/${1}.qcow2")
596 echo "Volume ${1} exists. Deleting Existing Volume $volume_path"
597 virsh vol-dumpxml ${1}.qcow2 --pool default > /dev/null || echo '' #ok for this to fail
599 virsh vol-delete ${1}.qcow2 --pool default
601 virsh vol-create-as default ${1}.qcow2 ${3}G --format qcow2
602 volume_path=$(virsh vol-path --pool default ${1}.qcow2)
603 if [ ! -f $volume_path ]; then
604 echo "$volume_path Not created successfully... Aborting"
609 /usr/libexec/openstack-tripleo/configure-vm --name $1 \
611 --image "$volume_path" \
616 --libvirt-nic-driver virtio \
617 --baremetal-interface $4
620 ##Copy over the glance images and instackenv json file
622 function configure_undercloud {
623 local controller_nic_template compute_nic_template
625 echo "Copying configuration files to Undercloud"
626 if [[ "$net_isolation_enabled" == "TRUE" ]]; then
627 echo -e "${blue}Network Environment set for Deployment: ${reset}"
628 cat /tmp/network-environment.yaml
629 scp ${SSH_OPTIONS[@]} /tmp/network-environment.yaml "stack@$UNDERCLOUD":
631 # check for ODL L3/ONOS
632 if [ "${deploy_options_array['sdn_l3']}" == 'True' ]; then
636 if ! controller_nic_template=$(python3.4 -B $LIB/python/apex-python-utils.py nic-template -t $CONFIG/nics-controller.yaml.jinja2 -n "$enabled_network_list" -e $ext_net_type -af $ip_addr_family); then
637 echo -e "${red}ERROR: Failed to generate controller NIC heat template ${reset}"
641 if ! compute_nic_template=$(python3.4 -B $LIB/python/apex-python-utils.py nic-template -t $CONFIG/nics-compute.yaml.jinja2 -n "$enabled_network_list" -e $ext_net_type -af $ip_addr_family); then
642 echo -e "${red}ERROR: Failed to generate compute NIC heat template ${reset}"
645 ssh -T ${SSH_OPTIONS[@]} "stack@$UNDERCLOUD" << EOI
647 cat > nics/controller.yaml << EOF
648 $controller_nic_template
650 cat > nics/compute.yaml << EOF
651 $compute_nic_template
656 # ensure stack user on Undercloud machine has an ssh key
657 ssh -T ${SSH_OPTIONS[@]} "stack@$UNDERCLOUD" "if [ ! -e ~/.ssh/id_rsa.pub ]; then ssh-keygen -t rsa -N '' -f ~/.ssh/id_rsa; fi"
659 if [ "$virtual" == "TRUE" ]; then
661 # copy the Undercloud VM's stack user's pub key to
662 # root's auth keys so that Undercloud can control
663 # vm power on the hypervisor
664 ssh ${SSH_OPTIONS[@]} "stack@$UNDERCLOUD" "cat /home/stack/.ssh/id_rsa.pub" >> /root/.ssh/authorized_keys
666 DEPLOY_OPTIONS+=" --libvirt-type qemu"
667 INSTACKENV=$CONFIG/instackenv-virt.json
669 # upload instackenv file to Undercloud for virtual deployment
670 scp ${SSH_OPTIONS[@]} $INSTACKENV "stack@$UNDERCLOUD":instackenv.json
673 # allow stack to control power management on the hypervisor via sshkey
674 # only if this is a virtual deployment
675 if [ "$virtual" == "TRUE" ]; then
676 ssh -T ${SSH_OPTIONS[@]} "stack@$UNDERCLOUD" <<EOI
677 while read -r line; do
678 stack_key=\${stack_key}\\\\\\\\n\${line}
679 done < <(cat ~/.ssh/id_rsa)
680 stack_key=\$(echo \$stack_key | sed 's/\\\\\\\\n//')
681 sed -i 's~INSERT_STACK_USER_PRIV_KEY~'"\$stack_key"'~' instackenv.json
685 # copy stack's ssh key to this users authorized keys
686 ssh -T ${SSH_OPTIONS[@]} "root@$UNDERCLOUD" "cat /home/stack/.ssh/id_rsa.pub" >> ~/.ssh/authorized_keys
688 # disable requiretty for sudo
689 ssh -T ${SSH_OPTIONS[@]} "root@$UNDERCLOUD" "sed -i 's/Defaults\s*requiretty//'" /etc/sudoers
691 # configure undercloud on Undercloud VM
692 echo "Running undercloud configuration."
693 echo "Logging undercloud configuration to undercloud:/home/stack/apex-undercloud-install.log"
694 ssh -T ${SSH_OPTIONS[@]} "stack@$UNDERCLOUD" << EOI
695 if [[ "$net_isolation_enabled" == "TRUE" ]]; then
696 sed -i 's/#local_ip/local_ip/' undercloud.conf
697 sed -i 's/#network_gateway/network_gateway/' undercloud.conf
698 sed -i 's/#network_cidr/network_cidr/' undercloud.conf
699 sed -i 's/#dhcp_start/dhcp_start/' undercloud.conf
700 sed -i 's/#dhcp_end/dhcp_end/' undercloud.conf
701 sed -i 's/#inspection_iprange/inspection_iprange/' undercloud.conf
702 sed -i 's/#undercloud_debug/undercloud_debug/' undercloud.conf
704 openstack-config --set undercloud.conf DEFAULT local_ip ${admin_network_provisioner_ip}/${admin_network_cidr##*/}
705 openstack-config --set undercloud.conf DEFAULT network_gateway ${admin_network_provisioner_ip}
706 openstack-config --set undercloud.conf DEFAULT network_cidr ${admin_network_cidr}
707 openstack-config --set undercloud.conf DEFAULT dhcp_start ${admin_network_dhcp_range%%,*}
708 openstack-config --set undercloud.conf DEFAULT dhcp_end ${admin_network_dhcp_range##*,}
709 openstack-config --set undercloud.conf DEFAULT inspection_iprange ${admin_network_introspection_range}
710 openstack-config --set undercloud.conf DEFAULT undercloud_debug false
714 sudo sed -i '/CephClusterFSID:/c\\ CephClusterFSID: \\x27$(cat /proc/sys/kernel/random/uuid)\\x27' /usr/share/openstack-tripleo-heat-templates/environments/storage-environment.yaml
715 sudo sed -i '/CephMonKey:/c\\ CephMonKey: \\x27'"\$(ceph-authtool --gen-print-key)"'\\x27' /usr/share/openstack-tripleo-heat-templates/environments/storage-environment.yaml
716 sudo sed -i '/CephAdminKey:/c\\ CephAdminKey: \\x27'"\$(ceph-authtool --gen-print-key)"'\\x27' /usr/share/openstack-tripleo-heat-templates/environments/storage-environment.yaml
718 # we assume that packages will not need to be updated with undercloud install
719 # and that it will be used only to configure the undercloud
720 # packages updates would need to be handled manually with yum update
721 sudo cp -f /usr/share/diskimage-builder/elements/yum/bin/install-packages /usr/share/diskimage-builder/elements/yum/bin/install-packages.bak
722 cat << 'EOF' | sudo tee /usr/share/diskimage-builder/elements/yum/bin/install-packages > /dev/null
727 openstack undercloud install &> apex-undercloud-install.log || {
728 # cat the undercloud install log incase it fails
729 echo "ERROR: openstack undercloud install has failed. Dumping Log:"
730 cat apex-undercloud-install.log
735 sudo systemctl restart openstack-glance-api
736 sudo systemctl restart openstack-nova-conductor
737 sudo systemctl restart openstack-nova-compute
739 sudo sed -i '/num_engine_workers/c\num_engine_workers = 2' /etc/heat/heat.conf
740 sudo sed -i '/#workers\s=/c\workers = 2' /etc/heat/heat.conf
741 sudo systemctl restart openstack-heat-engine
742 sudo systemctl restart openstack-heat-api
744 # WORKAROUND: must restart the above services to fix sync problem with nova compute manager
745 # TODO: revisit and file a bug if necessary. This should eventually be removed
746 # as well as glance api problem
747 echo -e "${blue}INFO: Sleeping 15 seconds while services come back from restart${reset}"
752 ##preping it for deployment and launch the deploy
754 function undercloud_prep_overcloud_deploy {
755 if [[ "${#deploy_options_array[@]}" -eq 0 || "${deploy_options_array['sdn_controller']}" == 'opendaylight' ]]; then
756 if [ "${deploy_options_array['sdn_l3']}" == 'True' ]; then
757 DEPLOY_OPTIONS+=" -e /usr/share/openstack-tripleo-heat-templates/environments/opendaylight_l3.yaml"
758 elif [ "${deploy_options_array['sfc']}" == 'True' ]; then
759 DEPLOY_OPTIONS+=" -e /usr/share/openstack-tripleo-heat-templates/environments/opendaylight_sfc.yaml"
760 elif [ "${deploy_options_array['vpn']}" == 'True' ]; then
761 DEPLOY_OPTIONS+=" -e /usr/share/openstack-tripleo-heat-templates/environments/opendaylight_sdnvpn.yaml"
763 DEPLOY_OPTIONS+=" -e /usr/share/openstack-tripleo-heat-templates/environments/opendaylight.yaml"
765 SDN_IMAGE=opendaylight
766 if [ "${deploy_options_array['sfc']}" == 'True' ]; then
768 if [ ! -f $RESOURCES/overcloud-full-${SDN_IMAGE}.qcow2 ]; then
769 echo "${red} $RESOURCES/overcloud-full-${SDN_IMAGE}.qcow2 is required to execute an SFC deployment."
770 echo "Please install the opnfv-apex-opendaylight-sfc package to provide this overcloud image for deployment.${reset}"
774 elif [ "${deploy_options_array['sdn_controller']}" == 'opendaylight-external' ]; then
775 DEPLOY_OPTIONS+=" -e /usr/share/openstack-tripleo-heat-templates/environments/opendaylight-external.yaml"
776 SDN_IMAGE=opendaylight
777 elif [ "${deploy_options_array['sdn_controller']}" == 'onos' ]; then
778 DEPLOY_OPTIONS+=" -e /usr/share/openstack-tripleo-heat-templates/environments/onos.yaml"
780 elif [ "${deploy_options_array['sdn_controller']}" == 'opencontrail' ]; then
781 echo -e "${red}ERROR: OpenContrail is currently unsupported...exiting${reset}"
783 elif [[ -z "${deploy_options_array['sdn_controller']}" || "${deploy_options_array['sdn_controller']}" == 'False' ]]; then
784 echo -e "${blue}INFO: SDN Controller disabled...will deploy nosdn scenario${reset}"
785 SDN_IMAGE=opendaylight
787 echo "${red}Invalid sdn_controller: ${deploy_options_array['sdn_controller']}${reset}"
788 echo "${red}Valid choices are opendaylight, opendaylight-external, onos, opencontrail, False, or null${reset}"
792 # Make sure the correct overcloud image is available
793 if [ ! -f $RESOURCES/overcloud-full-${SDN_IMAGE}.qcow2 ]; then
794 echo "${red} $RESOURCES/overcloud-full-${SDN_IMAGE}.qcow2 is required to execute your deployment."
795 echo "Both ONOS and OpenDaylight are currently deployed from this image."
796 echo "Please install the opnfv-apex package to provide this overcloud image for deployment.${reset}"
800 echo "Copying overcloud image to Undercloud"
801 ssh -T ${SSH_OPTIONS[@]} "stack@$UNDERCLOUD" "rm -f overcloud-full.qcow2"
802 scp ${SSH_OPTIONS[@]} $RESOURCES/overcloud-full-${SDN_IMAGE}.qcow2 "stack@$UNDERCLOUD":overcloud-full.qcow2
804 # Push performance options to subscript to modify per-role images as needed
805 for option in "${performance_options[@]}" ; do
806 echo -e "${blue}Setting performance option $option${reset}"
807 ssh -T ${SSH_OPTIONS[@]} "stack@$UNDERCLOUD" "bash build_perf_image.sh $option"
810 # Add performance deploy options if they have been set
811 if [ ! -z "${deploy_options_array['performance']}" ]; then
812 DEPLOY_OPTIONS+=" -e /usr/share/openstack-tripleo-heat-templates/environments/numa.yaml"
815 # make sure ceph is installed
816 DEPLOY_OPTIONS+=" -e /usr/share/openstack-tripleo-heat-templates/environments/storage-environment.yaml"
818 # scale compute nodes according to inventory
819 total_nodes=$(ssh -T ${SSH_OPTIONS[@]} "root@$UNDERCLOUD" "cat /home/stack/instackenv.json | grep -c memory")
821 # check if HA is enabled
822 if [[ "$ha_enabled" == "True" ]]; then
823 DEPLOY_OPTIONS+=" --control-scale 3"
824 compute_nodes=$((total_nodes - 3))
825 DEPLOY_OPTIONS+=" -e /usr/share/openstack-tripleo-heat-templates/environments/puppet-pacemaker.yaml"
827 compute_nodes=$((total_nodes - 1))
830 if [ "$compute_nodes" -le 0 ]; then
831 echo -e "${red}ERROR: Invalid number of compute nodes: ${compute_nodes}. Check your inventory file.${reset}"
834 echo -e "${blue}INFO: Number of compute nodes set for deployment: ${compute_nodes}${reset}"
835 DEPLOY_OPTIONS+=" --compute-scale ${compute_nodes}"
838 if [[ "$net_isolation_enabled" == "TRUE" ]]; then
839 #DEPLOY_OPTIONS+=" -e /usr/share/openstack-tripleo-heat-templates/environments/network-isolation.yaml"
840 DEPLOY_OPTIONS+=" -e network-environment.yaml"
843 if [[ "$ha_enabled" == "True" ]] || [[ "$net_isolation_enabled" == "TRUE" ]]; then
844 DEPLOY_OPTIONS+=" --ntp-server $ntp_server"
847 if [[ ! "$virtual" == "TRUE" ]]; then
848 DEPLOY_OPTIONS+=" --control-flavor control --compute-flavor compute"
850 DEPLOY_OPTIONS+=" -e virtual-environment.yaml"
853 DEPLOY_OPTIONS+=" -e opnfv-environment.yaml"
855 echo -e "${blue}INFO: Deploy options set:\n${DEPLOY_OPTIONS}${reset}"
857 ssh -T ${SSH_OPTIONS[@]} "stack@$UNDERCLOUD" <<EOI
858 if [ "$debug" == 'TRUE' ]; then
859 LIBGUESTFS_BACKEND=direct virt-customize -a overcloud-full.qcow2 --root-password password:opnfvapex
864 echo "Uploading overcloud glance images"
865 openstack overcloud image upload
867 bash -x set_perf_images.sh ${performance_roles[@]}
869 echo "Configuring undercloud and discovering nodes"
870 openstack baremetal import --json instackenv.json
871 openstack baremetal configure boot
872 #if [[ -z "$virtual" ]]; then
873 # openstack baremetal introspection bulk start
875 echo "Configuring flavors"
876 for flavor in baremetal control compute; do
877 echo -e "${blue}INFO: Updating flavor: \${flavor}${reset}"
878 if openstack flavor list | grep \${flavor}; then
879 openstack flavor delete \${flavor}
881 openstack flavor create --id auto --ram 4096 --disk 39 --vcpus 1 \${flavor}
882 if ! openstack flavor list | grep \${flavor}; then
883 echo -e "${red}ERROR: Unable to create flavor \${flavor}${reset}"
886 openstack flavor set --property "cpu_arch"="x86_64" --property "capabilities:boot_option"="local" baremetal
887 openstack flavor set --property "cpu_arch"="x86_64" --property "capabilities:boot_option"="local" --property "capabilities:profile"="control" control
888 openstack flavor set --property "cpu_arch"="x86_64" --property "capabilities:boot_option"="local" --property "capabilities:profile"="compute" compute
889 echo "Configuring nameserver on ctlplane network"
890 neutron subnet-update \$(neutron subnet-list | grep -v id | grep -v \\\\-\\\\- | awk {'print \$2'}) --dns-nameserver 8.8.8.8
891 echo "Executing overcloud deployment, this should run for an extended period without output."
892 sleep 60 #wait for Hypervisor stats to check-in to nova
893 # save deploy command so it can be used for debugging
894 cat > deploy_command << EOF
895 openstack overcloud deploy --templates $DEPLOY_OPTIONS --timeout 90
899 if [ "$interactive" == "TRUE" ]; then
900 if ! prompt_user "Overcloud Deployment"; then
901 echo -e "${blue}INFO: User requests exit${reset}"
906 ssh -T ${SSH_OPTIONS[@]} "stack@$UNDERCLOUD" <<EOI
908 openstack overcloud deploy --templates $DEPLOY_OPTIONS --timeout 90
909 if ! heat stack-list | grep CREATE_COMPLETE 1>/dev/null; then
910 $(typeset -f debug_stack)
916 if [ "$debug" == 'TRUE' ]; then
917 ssh -T ${SSH_OPTIONS[@]} "stack@$UNDERCLOUD" <<EOI
919 echo "Keystone Endpoint List:"
920 keystone endpoint-list
921 echo "Keystone Service List"
922 keystone service-list
923 cinder quota-show \$(openstack project list | grep admin | awk {'print \$2'})
928 ##Post configuration after install
930 function configure_post_install {
931 local opnfv_attach_networks ovs_ip ip_range net_cidr tmp_ip
932 opnfv_attach_networks="admin_network public_network"
934 echo -e "${blue}INFO: Post Install Configuration Running...${reset}"
936 ssh -T ${SSH_OPTIONS[@]} "stack@$UNDERCLOUD" <<EOI
939 echo "Configuring Neutron external network"
940 neutron net-create external --router:external=True --tenant-id \$(keystone tenant-get service | grep id | awk '{ print \$4 }')
941 neutron subnet-create --name external-net --tenant-id \$(keystone tenant-get service | grep id | awk '{ print \$4 }') --disable-dhcp external --gateway ${public_network_gateway} --allocation-pool start=${public_network_floating_ip_range%%,*},end=${public_network_floating_ip_range##*,} ${public_network_cidr}
944 echo -e "${blue}INFO: Checking if OVS bridges have IP addresses...${reset}"
945 for network in ${opnfv_attach_networks}; do
946 ovs_ip=$(find_ip ${NET_MAP[$network]})
948 if [ -n "$ovs_ip" ]; then
949 echo -e "${blue}INFO: OVS Bridge ${NET_MAP[$network]} has IP address ${ovs_ip}${reset}"
951 echo -e "${blue}INFO: OVS Bridge ${NET_MAP[$network]} missing IP, will configure${reset}"
952 # use last IP of allocation pool
953 eval "ip_range=\${${network}_usable_ip_range}"
954 ovs_ip=${ip_range##*,}
955 eval "net_cidr=\${${network}_cidr}"
956 sudo ip addr add ${ovs_ip}/${net_cidr##*/} dev ${NET_MAP[$network]}
957 sudo ip link set up ${NET_MAP[$network]}
958 tmp_ip=$(find_ip ${NET_MAP[$network]})
959 if [ -n "$tmp_ip" ]; then
960 echo -e "${blue}INFO: OVS Bridge ${NET_MAP[$network]} IP set: ${tmp_ip}${reset}"
963 echo -e "${red}ERROR: Unable to set OVS Bridge ${NET_MAP[$network]} with IP: ${ovs_ip}${reset}"
969 # for virtual, we NAT public network through Undercloud
970 if [ "$virtual" == "TRUE" ]; then
971 if ! configure_undercloud_nat ${public_network_cidr}; then
972 echo -e "${red}ERROR: Unable to NAT undercloud with external net: ${public_network_cidr}${reset}"
975 echo -e "${blue}INFO: Undercloud VM has been setup to NAT Overcloud public network${reset}"
979 # for sfc deployments we need the vxlan workaround
980 if [ "${deploy_options_array['sfc']}" == 'True' ]; then
981 ssh -T ${SSH_OPTIONS[@]} "stack@$UNDERCLOUD" <<EOI
984 for node in \$(nova list | grep -Eo "[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+"); do
985 ssh -T ${SSH_OPTIONS[@]} "heat-admin@\$node" <<EOF
986 sudo ifconfig br-int up
987 sudo ip route add 123.123.123.0/24 dev br-int
993 # Collect deployment logs
994 ssh -T ${SSH_OPTIONS[@]} "stack@$UNDERCLOUD" <<EOI
995 mkdir -p ~/deploy_logs
999 for node in \$(nova list | grep -Eo "[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+"); do
1000 ssh -T ${SSH_OPTIONS[@]} "heat-admin@\$node" <<EOF
1001 sudo cp /var/log/messages /home/heat-admin/messages.log
1002 sudo chown heat-admin /home/heat-admin/messages.log
1004 scp ${SSH_OPTIONS[@]} heat-admin@\$node:/home/heat-admin/messages.log ~/deploy_logs/\$node.messages.log
1005 if [ "$debug" == "TRUE" ]; then
1006 nova list --ip \$node
1007 echo "---------------------------"
1008 echo "-----/var/log/messages-----"
1009 echo "---------------------------"
1010 cat ~/deploy_logs/\$node.messages.log
1011 echo "---------------------------"
1012 echo "----------END LOG----------"
1013 echo "---------------------------"
1015 ssh -T ${SSH_OPTIONS[@]} "heat-admin@\$node" <<EOF
1016 sudo rm -f /home/heat-admin/messages.log
1020 # Print out the dashboard URL
1022 echo "Overcloud dashboard available at http://\$(heat output-show overcloud PublicVip | sed 's/"//g')/dashboard"
1028 echo -e "Usage:\n$0 [arguments] \n"
1029 echo -e " -d|--deploy-settings : Full path to deploy settings yaml file. Optional. Defaults to null"
1030 echo -e " -i|--inventory : Full path to inventory yaml file. Required only for baremetal"
1031 echo -e " -n|--net-settings : Full path to network settings file. Optional."
1032 echo -e " -p|--ping-site : site to use to verify IP connectivity. Optional. Defaults to 8.8.8.8"
1033 echo -e " -v|--virtual : Virtualize overcloud nodes instead of using baremetal."
1034 echo -e " --flat : disable Network Isolation and use a single flat network for the underlay network."
1035 echo -e " --no-post-config : disable Post Install configuration."
1036 echo -e " --debug : enable debug output."
1037 echo -e " --interactive : enable interactive deployment mode which requires user to confirm steps of deployment."
1038 echo -e " --virtual-cpus : Number of CPUs to use per Overcloud VM in a virtual deployment (defaults to 4)."
1039 echo -e " --virtual-ram : Amount of RAM to use per Overcloud VM in GB (defaults to 8)."
1042 ##translates the command line parameters into variables
1043 ##params: $@ the entire command line is passed
1044 ##usage: parse_cmd_line() "$@"
1046 echo -e "\n\n${blue}This script is used to deploy the Apex Installer and Provision OPNFV Target System${reset}\n\n"
1047 echo "Use -h to display help"
1050 while [ "${1:0:1}" = "-" ]
1057 -d|--deploy-settings)
1058 DEPLOY_SETTINGS_FILE=$2
1059 echo "Deployment Configuration file: $2"
1068 echo "Network Settings Configuration file: $2"
1073 echo "Using $2 as the ping site"
1078 echo "Executing a Virtual Deployment"
1082 net_isolation_enabled="FALSE"
1083 echo "Underlay Network Isolation Disabled: using flat configuration"
1088 echo "Post install configuration disabled"
1093 echo "Enable debug output"
1098 echo "Interactive mode enabled"
1103 echo "Number of CPUs per VM set to $VM_CPUS"
1108 echo "Amount of RAM per VM set to $VM_RAM"
1111 --virtual-computes )
1113 echo "Virtual Compute nodes set to $VM_COMPUTES"
1123 if [[ ! -z "$NETSETS" && "$net_isolation_enabled" == "FALSE" ]]; then
1124 echo -e "${red}INFO: Single flat network requested. Only admin_network settings will be used!${reset}"
1125 elif [[ -z "$NETSETS" ]]; then
1126 echo -e "${red}ERROR: You must provide a network_settings file with -n.${reset}"
1130 if [[ -n "$virtual" && -n "$INVENTORY_FILE" ]]; then
1131 echo -e "${red}ERROR: You should not specify an inventory with virtual deployments${reset}"
1135 if [[ -z "$DEPLOY_SETTINGS_FILE" || ! -f "$DEPLOY_SETTINGS_FILE" ]]; then
1136 echo -e "${red}ERROR: Deploy Settings: ${DEPLOY_SETTINGS_FILE} does not exist! Exiting...${reset}"
1140 if [[ ! -z "$NETSETS" && ! -f "$NETSETS" ]]; then
1141 echo -e "${red}ERROR: Network Settings: ${NETSETS} does not exist! Exiting...${reset}"
1145 if [[ ! -z "$INVENTORY_FILE" && ! -f "$INVENTORY_FILE" ]]; then
1146 echo -e "{$red}ERROR: Inventory File: ${INVENTORY_FILE} does not exist! Exiting...${reset}"
1150 if [[ -z "$virtual" && -z "$INVENTORY_FILE" ]]; then
1151 echo -e "${red}ERROR: You must specify an inventory file for baremetal deployments! Exiting...${reset}"
1155 if [[ "$net_isolation_enabled" == "FALSE" && "$post_config" == "TRUE" ]]; then
1156 echo -e "${blue}INFO: Post Install Configuration will be skipped. It is not supported with --flat${reset}"
1165 # Make sure jinja2 is installed
1166 easy_install-3.4 jinja2 > /dev/null
1168 echo -e "${blue}INFO: Parsing network settings file...${reset}"
1169 parse_network_settings
1170 if ! configure_deps; then
1171 echo -e "${red}Dependency Validation Failed, Exiting.${reset}"
1174 if [ -n "$DEPLOY_SETTINGS_FILE" ]; then
1175 echo -e "${blue}INFO: Parsing deploy settings file...${reset}"
1176 parse_deploy_settings
1179 if [ "$virtual" == "TRUE" ]; then
1180 setup_virtual_baremetal $VM_CPUS $VM_RAM
1181 elif [ -n "$INVENTORY_FILE" ]; then
1182 parse_inventory_file
1184 configure_undercloud
1185 undercloud_prep_overcloud_deploy
1186 if [ "$post_config" == "TRUE" ]; then
1187 if ! configure_post_install; then
1188 echo -e "${red}ERROR:Post Install Configuration Failed, Exiting.${reset}"
1191 echo -e "${blue}INFO: Post Install Configuration Complete${reset}"
1194 if [[ "${deploy_options_array['sdn_controller']}" == 'onos' ]]; then
1195 if ! onos_update_gw_mac ${public_network_cidr} ${public_network_gateway}; then
1196 echo -e "${red}ERROR:ONOS Post Install Configuration Failed, Exiting.${reset}"
1199 echo -e "${blue}INFO: ONOS Post Install Configuration Complete${reset}"