Enable TLS configuration for containerized HAProxy
[apex-tripleo-heat-templates.git] / common / deploy-steps.j2
1 # certain initialization steps (run in a container) will occur
2 # on the role marked as primary controller or the first role listed
3 {%- set primary_role = [roles[0]] -%}
4 {%- for role in roles -%}
5   {%- if 'primary' in role.tags and 'controller' in role.tags -%}
6     {%- set _ = primary_role.pop() -%}
7     {%- set _ = primary_role.append(role) -%}
8   {%- endif -%}
9 {%- endfor -%}
10 {%- set primary_role_name = primary_role[0].name -%}
11 # primary role is: {{primary_role_name}}
12 {% set deploy_steps_max = 6 -%}
13 {% set update_steps_max = 6 -%}
14
15 heat_template_version: pike
16
17 description: >
18   Post-deploy configuration steps via puppet for all roles,
19   as defined in ../roles_data.yaml
20
21 parameters:
22   servers:
23     type: json
24     description: Mapping of Role name e.g Controller to a list of servers
25   stack_name:
26     type: string
27     description: Name of the topmost stack
28   role_data:
29     type: json
30     description: Mapping of Role name e.g Controller to the per-role data
31   DeployIdentifier:
32     default: ''
33     type: string
34     description: >
35       Setting this to a unique value will re-run any deployment tasks which
36       perform configuration on a Heat stack-update.
37   EndpointMap:
38     default: {}
39     description: Mapping of service endpoint -> protocol. Typically set
40                  via parameter_defaults in the resource registry.
41     type: json
42   DockerPuppetDebug:
43     type: string
44     default: ''
45     description: Set to True to enable debug logging with docker-puppet.py
46   ctlplane_service_ips:
47     type: json
48
49 conditions:
50 {% for step in range(1, deploy_steps_max) %}
51   WorkflowTasks_Step{{step}}_Enabled:
52     or:
53     {%- for role in roles %}
54       - not:
55           equals:
56             - get_param: [role_data, {{role.name}}, service_workflow_tasks, step{{step}}]
57             - ''
58       - False
59     {%- endfor %}
60 {% endfor %}
61
62 resources:
63
64   RoleConfig:
65     type: OS::Heat::SoftwareConfig
66     properties:
67       group: ansible
68       options:
69         modulepath: /usr/share/ansible-modules
70       inputs:
71         - name: step
72         - name: role_name
73         - name: update_identifier
74         - name: bootstrap_server_id
75         - name: docker_puppet_debug
76       config:
77         str_replace:
78           template: |
79             - hosts: localhost
80               connection: local
81               tasks:
82               _TASKS
83           params:
84             _TASKS: {get_file: deploy-steps-tasks.yaml}
85
86 {%- for step in range(1, deploy_steps_max) %}
87 # BEGIN service_workflow_tasks handling
88   WorkflowTasks_Step{{step}}:
89     type: OS::Mistral::Workflow
90     condition: WorkflowTasks_Step{{step}}_Enabled
91     depends_on:
92     {%- if step == 1 %}
93     {%- for dep in roles %}
94       - {{dep.name}}PreConfig
95       - {{dep.name}}ArtifactsDeploy
96     {%- endfor %}
97     {%- else %}
98     {%- for dep in roles %}
99       - {{dep.name}}Deployment_Step{{step -1}}
100     {%- endfor %}
101     {%- endif %}
102     properties:
103       name: {list_join: [".", ["tripleo", {get_param: stack_name}, "workflowtasks", "step{{step}}"]]}
104       type: direct
105       tasks:
106         yaql:
107           expression: $.data.where($ != '').select($.get('step{{step}}')).where($ != null).flatten()
108           data:
109           {%- for role in roles %}
110             - get_param: [role_data, {{role.name}}, service_workflow_tasks]
111           {%- endfor %}
112
113   WorkflowTasks_Step{{step}}_Execution:
114     type: OS::Mistral::ExternalResource
115     condition: WorkflowTasks_Step{{step}}_Enabled
116     depends_on: WorkflowTasks_Step{{step}}
117     properties:
118       actions:
119         CREATE:
120           workflow: { get_resource: WorkflowTasks_Step{{step}} }
121           params:
122             env:
123               service_ips: { get_param: ctlplane_service_ips }
124               role_merged_configs:
125                 {%- for r in roles %}
126                 {{r.name}}: {get_param: [role_data, {{r.name}}, merged_config_settings]}
127                 {%- endfor %}
128             evaluate_env: false
129         UPDATE:
130           workflow: { get_resource: WorkflowTasks_Step{{step}} }
131           params:
132             env:
133               service_ips: { get_param: ctlplane_service_ips }
134               role_merged_configs:
135                 {%- for r in roles %}
136                 {{r.name}}: {get_param: [role_data, {{r.name}}, merged_config_settings]}
137                 {%- endfor %}
138             evaluate_env: false
139       always_update: true
140 # END service_workflow_tasks handling
141 {% endfor %}
142
143 {% for role in roles %}
144   # Post deployment steps for all roles
145   # A single config is re-applied with an incrementing step number
146   # {{role.name}} Role steps
147   {{role.name}}ArtifactsConfig:
148     type: ../puppet/deploy-artifacts.yaml
149
150   {{role.name}}ArtifactsDeploy:
151     type: OS::Heat::StructuredDeploymentGroup
152     properties:
153       servers:  {get_param: [servers, {{role.name}}]}
154       config: {get_resource: {{role.name}}ArtifactsConfig}
155
156   {{role.name}}HostPrepConfig:
157     type: OS::Heat::SoftwareConfig
158     properties:
159       group: ansible
160       options:
161         modulepath: /usr/share/ansible-modules
162       config:
163         str_replace:
164           template: _PLAYBOOK
165           params:
166             _PLAYBOOK:
167               - hosts: localhost
168                 connection: local
169                 vars:
170                   puppet_config: {get_param: [role_data, {{role.name}}, puppet_config]}
171                   docker_puppet_script: {get_file: ../docker/docker-puppet.py}
172                   docker_puppet_tasks: {get_param: [role_data, {{role.name}}, docker_puppet_tasks]}
173                   docker_startup_configs: {get_param: [role_data, {{role.name}}, docker_config]}
174                   kolla_config: {get_param: [role_data, {{role.name}}, kolla_config]}
175                   bootstrap_server_id: {get_param: [servers, {{primary_role_name}}, '0']}
176                   puppet_step_config: {get_param: [role_data, {{role.name}}, step_config]}
177                 tasks:
178                   # Join host_prep_tasks with the other per-host configuration
179                   yaql:
180                     expression: $.data.host_prep_tasks + $.data.template_tasks
181                     data:
182                       host_prep_tasks: {get_param: [role_data, {{role.name}}, host_prep_tasks]}
183                       template_tasks:
184 {%- raw %}
185                         # Write the manifest for baremetal puppet configuration
186                         - name: Create /var/lib/tripleo-config directory
187                           file: path=/var/lib/tripleo-config state=directory
188                         - name: Write the puppet step_config manifest
189                           copy: content="{{puppet_step_config}}" dest=/var/lib/tripleo-config/puppet_step_config.pp force=yes
190                         # this creates a JSON config file for our docker-puppet.py script
191                         - name: Create /var/lib/docker-puppet
192                           file: path=/var/lib/docker-puppet state=directory
193                         - name: Write docker-puppet-tasks json files
194                           copy: content="{{puppet_config | to_json}}" dest=/var/lib/docker-puppet/docker-puppet.json force=yes
195                         # FIXME: can we move docker-puppet somewhere so it's installed via a package?
196                         - name: Write docker-puppet.py
197                           copy: content="{{docker_puppet_script}}" dest=/var/lib/docker-puppet/docker-puppet.py force=yes
198                         # Here we are dumping all the docker container startup configuration data
199                         # so that we can have access to how they are started outside of heat
200                         # and docker-cmd.  This lets us create command line tools to test containers.
201                         # FIXME do we need the docker-container-startup-configs.json or is the new per-step
202                         # data consumed by paunch enough?
203                         - name: Write docker-container-startup-configs
204                           copy: content="{{docker_startup_configs | to_json}}" dest=/var/lib/docker-container-startup-configs.json force=yes
205                         - name: Write per-step docker-container-startup-configs
206                           copy: content="{{item.value|to_json}}" dest="/var/lib/tripleo-config/docker-container-startup-config-{{item.key}}.json" force=yes
207                           with_dict: "{{docker_startup_configs}}"
208                         - name: Create /var/lib/kolla/config_files directory
209                           file: path=/var/lib/kolla/config_files state=directory
210                         - name: Write kolla config json files
211                           copy: content="{{item.value|to_json}}" dest="{{item.key}}" force=yes
212                           with_dict: "{{kolla_config}}"
213                         ########################################################
214                         # Bootstrap tasks, only performed on bootstrap_server_id
215                         ########################################################
216                         - name: Clean /var/lib/docker-puppet/docker-puppet-tasks*.json files
217                           file:
218                             path: "{{item}}"
219                             state: absent
220                           with_fileglob:
221                             - /var/lib/docker-puppet/docker-puppet-tasks*.json
222                           when: deploy_server_id == bootstrap_server_id
223                         - name: Write docker-puppet-tasks json files
224                           copy: content="{{item.value|to_json}}" dest=/var/lib/docker-puppet/docker-puppet-tasks{{item.key.replace("step_", "")}}.json force=yes
225                           with_dict: "{{docker_puppet_tasks}}"
226                           when: deploy_server_id == bootstrap_server_id
227 {%- endraw %}
228
229   {{role.name}}HostPrepDeployment:
230     type: OS::Heat::SoftwareDeploymentGroup
231     properties:
232       servers: {get_param: [servers, {{role.name}}]}
233       config: {get_resource: {{role.name}}HostPrepConfig}
234
235   # BEGIN CONFIG STEPS
236
237   {{role.name}}PreConfig:
238     type: OS::TripleO::Tasks::{{role.name}}PreConfig
239     depends_on: {{role.name}}HostPrepDeployment
240     properties:
241       servers: {get_param: [servers, {{role.name}}]}
242       input_values:
243         update_identifier: {get_param: DeployIdentifier}
244
245   {% for step in range(1, deploy_steps_max) %}
246   {{role.name}}Deployment_Step{{step}}:
247     type: OS::TripleO::DeploymentSteps
248     depends_on:
249       - WorkflowTasks_Step{{step}}_Execution
250     # TODO(gfidente): the following if/else condition
251     # replicates what is already defined for the
252     # WorkflowTasks_StepX resource and can be remove
253     # if https://bugs.launchpad.net/heat/+bug/1700569
254     # is fixed.
255     {%- if step == 1 %}
256     {%- for dep in roles %}
257       - {{dep.name}}PreConfig
258       - {{dep.name}}ArtifactsDeploy
259     {%- endfor %}
260     {%- else %}
261     {%- for dep in roles %}
262       - {{dep.name}}Deployment_Step{{step -1}}
263     {%- endfor %}
264     {%- endif %}
265     properties:
266       name: {{role.name}}Deployment_Step{{step}}
267       servers: {get_param: [servers, {{role.name}}]}
268       config: {get_resource: RoleConfig}
269       input_values:
270         step: {{step}}
271         role_name: {{role.name}}
272         update_identifier: {get_param: DeployIdentifier}
273         bootstrap_server_id: {get_param: [servers, {{primary_role_name}}, '0']}
274         docker_puppet_debug: {get_param: DockerPuppetDebug}
275   {% endfor %}
276   # END CONFIG STEPS
277
278   # Note, this should be the last step to execute configuration changes.
279   # Ensure that all {{role.name}}ExtraConfigPost steps are executed
280   # after all the previous deployment steps.
281   {{role.name}}ExtraConfigPost:
282     depends_on:
283   {%- for dep in roles %}
284       - {{dep.name}}Deployment_Step5
285   {%- endfor %}
286     type: OS::TripleO::NodeExtraConfigPost
287     properties:
288         servers: {get_param: [servers, {{role.name}}]}
289
290   # The {{role.name}}PostConfig steps are in charge of
291   # quiescing all services, i.e. in the Controller case,
292   # we should run a full service reload.
293   {{role.name}}PostConfig:
294     type: OS::TripleO::Tasks::{{role.name}}PostConfig
295     depends_on:
296   {%- for dep in roles %}
297       - {{dep.name}}ExtraConfigPost
298   {%- endfor %}
299     properties:
300       servers:  {get_param: servers}
301       input_values:
302         update_identifier: {get_param: DeployIdentifier}
303
304
305 {% endfor %}
306
307 outputs:
308   RoleConfig:
309     description: Mapping of config data for all roles
310     value:
311       deploy_steps_tasks: {get_file: deploy-steps-tasks.yaml}
312       deploy_steps_playbook: |
313         - hosts: overcloud
314           tasks:
315 {%- for role in roles %}
316             - include: {{role.name}}/host_prep_tasks.yaml
317               when: role_name == '{{role.name}}'
318 {%- endfor %}
319             - include: deploy_steps_tasks.yaml
320               with_sequence: count={{deploy_steps_max-1}}
321               loop_control:
322                 loop_var: step
323       update_steps_tasks: |
324 {%- for role in roles %}
325             - include: {{role.name}}/update_tasks.yaml
326               when: role_name == '{{role.name}}'
327 {%- endfor %}
328       update_steps_playbook: |
329         - hosts: overcloud
330           serial: 1
331           tasks:
332             - include: update_steps_tasks.yaml
333               with_sequence: count={{update_steps_max-1}}
334               loop_control:
335                 loop_var: step
336             - include: deploy_steps_tasks.yaml
337               with_sequence: count={{deploy_steps_max-1}}
338               loop_control:
339                 loop_var: step
340