Merge "Enable TLS in the internal networkf or Mysql"
[apex-tripleo-heat-templates.git] / network / config / single-nic-linux-bridge-vlans / controller.yaml
1 heat_template_version: 2015-04-30
2
3 description: >
4   Software Config to drive os-net-config to configure VLANs for the
5   controller role.
6
7 parameters:
8   ControlPlaneIp:
9     default: ''
10     description: IP address/subnet on the ctlplane network
11     type: string
12   ExternalIpSubnet:
13     default: ''
14     description: IP address/subnet on the external network
15     type: string
16   InternalApiIpSubnet:
17     default: ''
18     description: IP address/subnet on the internal API network
19     type: string
20   StorageIpSubnet:
21     default: ''
22     description: IP address/subnet on the storage network
23     type: string
24   StorageMgmtIpSubnet:
25     default: ''
26     description: IP address/subnet on the storage mgmt network
27     type: string
28   TenantIpSubnet:
29     default: ''
30     description: IP address/subnet on the tenant network
31     type: string
32   ManagementIpSubnet: # Only populated when including environments/network-management.yaml
33     default: ''
34     description: IP address/subnet on the management network
35     type: string
36   ExternalNetworkVlanID:
37     default: 10
38     description: Vlan ID for the external network traffic.
39     type: number
40   InternalApiNetworkVlanID:
41     default: 20
42     description: Vlan ID for the internal_api network traffic.
43     type: number
44   StorageNetworkVlanID:
45     default: 30
46     description: Vlan ID for the storage network traffic.
47     type: number
48   StorageMgmtNetworkVlanID:
49     default: 40
50     description: Vlan ID for the storage mgmt network traffic.
51     type: number
52   TenantNetworkVlanID:
53     default: 50
54     description: Vlan ID for the tenant network traffic.
55     type: number
56   ManagementNetworkVlanID:
57     default: 60
58     description: Vlan ID for the management network traffic.
59     type: number
60   ControlPlaneDefaultRoute: # Override this via parameter_defaults
61     description: The default route of the control plane network.
62     type: string
63   ExternalInterfaceDefaultRoute:
64     default: '10.0.0.1'
65     description: default route for the external network
66     type: string
67   ManagementInterfaceDefaultRoute: # Commented out by default in this template
68     default: unset
69     description: The default route of the management network.
70     type: string
71   ControlPlaneSubnetCidr: # Override this via parameter_defaults
72     default: '24'
73     description: The subnet CIDR of the control plane network.
74     type: string
75   DnsServers: # Override this via parameter_defaults
76     default: []
77     description: A list of DNS servers (2 max for some implementations) that will be added to resolv.conf.
78     type: comma_delimited_list
79   EC2MetadataIp: # Override this via parameter_defaults
80     description: The IP address of the EC2 metadata server.
81     type: string
82
83 resources:
84   OsNetConfigImpl:
85     type: OS::Heat::StructuredConfig
86     properties:
87       group: os-apply-config
88       config:
89         os_net_config:
90           network_config:
91             -
92               type: linux_bridge
93               name: {get_input: bridge_name}
94               use_dhcp: false
95               dns_servers: {get_param: DnsServers}
96               addresses:
97                 -
98                   ip_netmask:
99                     list_join:
100                       - '/'
101                       - - {get_param: ControlPlaneIp}
102                         - {get_param: ControlPlaneSubnetCidr}
103               routes:
104                 -
105                   ip_netmask: 169.254.169.254/32
106                   next_hop: {get_param: EC2MetadataIp}
107                 -
108                   default: true
109                   next_hop: {get_param: ControlPlaneDefaultRoute}
110               members:
111                 -
112                   type: interface
113                   name: {get_input: interface_name}
114                   primary: true
115             -
116               type: vlan
117               vlan_id: {get_param: ExternalNetworkVlanID}
118               device: {get_input: bridge_name}
119               addresses:
120                 -
121                   ip_netmask: {get_param: ExternalIpSubnet}
122               routes:
123                 -
124                   default: true
125                   next_hop: {get_param: ExternalInterfaceDefaultRoute}
126             -
127               type: vlan
128               vlan_id: {get_param: InternalApiNetworkVlanID}
129               device: {get_input: bridge_name}
130               addresses:
131                 -
132                   ip_netmask: {get_param: InternalApiIpSubnet}
133             -
134               type: vlan
135               vlan_id: {get_param: StorageNetworkVlanID}
136               device: {get_input: bridge_name}
137               addresses:
138                 -
139                   ip_netmask: {get_param: StorageIpSubnet}
140             -
141               type: vlan
142               vlan_id: {get_param: StorageMgmtNetworkVlanID}
143               device: {get_input: bridge_name}
144               addresses:
145                 -
146                   ip_netmask: {get_param: StorageMgmtIpSubnet}
147             -
148               type: vlan
149               vlan_id: {get_param: TenantNetworkVlanID}
150               device: {get_input: bridge_name}
151               addresses:
152                 -
153                   ip_netmask: {get_param: TenantIpSubnet}
154               # Uncomment when including environments/network-management.yaml
155               # If setting default route on the Management interface, comment
156               # out the default route on the External interface. This will
157               # make the External API unreachable from remote subnets.
158               #-
159               #  type: vlan
160               #  vlan_id: {get_param: ManagementNetworkVlanID}
161               #  device: {get_input: bridge_name}
162               #  addresses:
163               #    -
164               #      ip_netmask: {get_param: ManagementIpSubnet}
165               #  routes:
166               #    -
167               #      default: true
168               #      next_hop: {get_param: ManagementInterfaceDefaultRoute}
169
170 outputs:
171   OS::stack_id:
172     description: The OsNetConfigImpl resource.
173     value: {get_resource: OsNetConfigImpl}