Merge "Enable Zaqar API SSL"
[apex-tripleo-heat-templates.git] / docker / services / zaqar.yaml
1 heat_template_version: pike
2
3 description: >
4   OpenStack containerized Zaqar services
5
6 parameters:
7   DockerZaqarImage:
8     description: image
9     type: string
10   DockerZaqarConfigImage:
11     description: The container image to use for the zaqar config_volume
12     type: string
13   ZaqarManagementStore:
14     type: string
15     description: The management store for Zaqar
16     default: mongodb
17   EndpointMap:
18     default: {}
19     description: Mapping of service endpoint -> protocol. Typically set
20                  via parameter_defaults in the resource registry.
21     type: json
22   ServiceData:
23     default: {}
24     description: Dictionary packing service data
25     type: json
26   ServiceNetMap:
27     default: {}
28     description: Mapping of service_name -> network name. Typically set
29                  via parameter_defaults in the resource registry.  This
30                  mapping overrides those in ServiceNetMapDefaults.
31     type: json
32   DefaultPasswords:
33     default: {}
34     type: json
35   RoleName:
36     default: ''
37     description: Role name on which the service is applied
38     type: string
39   RoleParameters:
40     default: {}
41     description: Parameters specific to the role
42     type: json
43   EnableInternalTLS:
44     type: boolean
45     default: false
46
47 conditions:
48   zaqar_management_store_sqlalchemy: {equals : [{get_param: ZaqarManagementStore}, 'sqlalchemy']}
49   internal_tls_enabled: {get_param: EnableInternalTLS}
50
51 resources:
52
53   ContainersCommon:
54     type: ./containers-common.yaml
55
56   ZaqarBase:
57     type: ../../puppet/services/zaqar.yaml
58     properties:
59       EndpointMap: {get_param: EndpointMap}
60       ServiceData: {get_param: ServiceData}
61       ServiceNetMap: {get_param: ServiceNetMap}
62       DefaultPasswords: {get_param: DefaultPasswords}
63       RoleName: {get_param: RoleName}
64       RoleParameters: {get_param: RoleParameters}
65       EnableInternalTLS: {get_param: EnableInternalTLS}
66
67 outputs:
68   role_data:
69     description: Role data for the Zaqar API role.
70     value:
71       service_name: {get_attr: [ZaqarBase, role_data, service_name]}
72       config_settings: {get_attr: [ZaqarBase, role_data, config_settings]}
73       step_config: &step_config
74        get_attr: [ZaqarBase, role_data, step_config]
75       service_config_settings: {get_attr: [ZaqarBase, role_data, service_config_settings]}
76       # BEGIN DOCKER SETTINGS
77       puppet_config:
78         config_volume: zaqar
79         puppet_tags: zaqar_config
80         step_config: *step_config
81         config_image: {get_param: DockerZaqarConfigImage}
82       kolla_config:
83         /var/lib/kolla/config_files/zaqar.json:
84           command: /usr/sbin/httpd -DFOREGROUND
85           config_files:
86             - source: "/var/lib/kolla/config_files/src/*"
87               dest: "/"
88               merge: true
89               preserve_properties: true
90         /var/lib/kolla/config_files/zaqar_websocket.json:
91           command: /usr/bin/zaqar-server --config-file /etc/zaqar/zaqar.conf --config-file /etc/zaqar/1.conf
92           config_files:
93             - source: "/var/lib/kolla/config_files/src/*"
94               dest: "/"
95               merge: true
96               preserve_properties: true
97           permissions:
98             - path: /var/log/zaqar
99               owner: zaqar:zaqar
100               recurse: true
101       docker_config:
102         map_merge:
103           -
104             if:
105             - zaqar_management_store_sqlalchemy
106             -
107               step_2:
108                 zaqar_init_log:
109                   image: &zaqar_image {get_param: DockerZaqarImage}
110                   user: root
111                   volumes:
112                     - /var/log/containers/zaqar:/var/log/zaqar
113                   command: ['/bin/bash', '-c', 'chown -R zaqar:zaqar /var/log/zaqar']
114               step_3:
115                 zaqar_db_sync:
116                   image: *zaqar_image
117                   net: host
118                   privileged: false
119                   detach: false
120                   user: root
121                   volumes:
122                     list_concat:
123                       - {get_attr: [ContainersCommon, volumes]}
124                       -
125                         - /var/lib/config-data/zaqar/etc/zaqar/:/etc/zaqar/:ro
126                         - /var/log/containers/zaqar:/var/log/zaqar
127                   command: "/usr/bin/bootstrap_host_exec zaqar su zaqar -s /bin/bash -c 'zaqar-sql-db-manage upgrade head'"
128             - {}
129           - step_4:
130               zaqar:
131                 image: *zaqar_image
132                 net: host
133                 privileged: false
134                 restart: always
135                 # NOTE(mandre) kolla image changes the user to 'zaqar', we need it
136                 # to be root to run httpd
137                 user: root
138                 volumes:
139                   list_concat:
140                     - {get_attr: [ContainersCommon, volumes]}
141                     -
142                       - /var/lib/kolla/config_files/zaqar.json:/var/lib/kolla/config_files/config.json:ro
143                       - /var/lib/config-data/puppet-generated/zaqar/:/var/lib/kolla/config_files/src:ro
144                       - /var/log/containers/zaqar:/var/log/zaqar
145                       -
146                         if:
147                           - internal_tls_enabled
148                           - /etc/pki/tls/certs/httpd:/etc/pki/tls/certs/httpd:ro
149                           - ''
150                       -
151                         if:
152                           - internal_tls_enabled
153                           - /etc/pki/tls/private/httpd:/etc/pki/tls/private/httpd:ro
154                           - ''
155                 environment:
156                   - KOLLA_CONFIG_STRATEGY=COPY_ALWAYS
157               zaqar_websocket:
158                 image: *zaqar_image
159                 net: host
160                 privileged: false
161                 restart: always
162                 volumes:
163                   list_concat:
164                     - {get_attr: [ContainersCommon, volumes]}
165                     -
166                       - /var/lib/kolla/config_files/zaqar_websocket.json:/var/lib/kolla/config_files/config.json:ro
167                       - /var/lib/config-data/puppet-generated/zaqar/:/var/lib/kolla/config_files/src:ro
168                       - /var/log/containers/zaqar:/var/log/zaqar
169                 environment:
170                   - KOLLA_CONFIG_STRATEGY=COPY_ALWAYS
171       host_prep_tasks:
172         - name: create persistent logs directory
173           file:
174             path: /var/log/containers/zaqar
175             state: directory
176       upgrade_tasks:
177         - name: Stop and disable zaqar service
178           tags: step2
179           service: name=httpd state=stopped enabled=no
180       metadata_settings:
181         get_attr: [ZaqarBase, role_data, metadata_settings]