8766263ab88ed383070eef16c2541ae385250306
[apex-tripleo-heat-templates.git] / puppet / hieradata / controller.yaml
1 # Hiera data here applies to all controller nodes
2
3 nova::api::enabled: true
4 nova::conductor::enabled: true
5 nova::consoleauth::enabled: true
6 nova::vncproxy::enabled: true
7 nova::scheduler::enabled: true
8
9 # rabbitmq
10 rabbitmq::delete_guest_user: false
11 rabbitmq::wipe_db_on_cookie_change: true
12 rabbitmq::port: '5672'
13 rabbitmq::package_source: undef
14 rabbitmq::repos_ensure: false
15 rabbitmq_environment:
16   RABBITMQ_NODENAME: "rabbit@%{::hostname}"
17   RABBITMQ_SERVER_ERL_ARGS: '"+K true +A30 +P 1048576 -kernel inet_default_connect_options [{nodelay,true},{raw,6,18,<<5000:64/native>>}] -kernel inet_default_listen_options [{raw,6,18,<<5000:64/native>>}]"'
18 rabbitmq_kernel_variables:
19   inet_dist_listen_min: '35672'
20   inet_dist_listen_max: '35672'
21 rabbitmq_config_variables:
22   tcp_listen_options: '[binary, {packet, raw}, {reuseaddr, true}, {backlog, 128}, {nodelay, true}, {exit_on_close, false}, {keepalive, true}]'
23   cluster_partition_handling: 'pause_minority'
24
25 mongodb::server::replset: tripleo
26 mongodb::server::journal: false
27
28 redis::port: 6379
29 redis::sentinel::master_name: "%{hiera('bootstrap_nodeid')}"
30 redis::sentinel::redis_host: "%{hiera('bootstrap_nodeid_ip')}"
31 redis::sentinel::notification_script: '/usr/local/bin/redis-notifications.sh'
32
33 # keystone
34 keystone::roles::admin::email: 'root@localhost'
35
36 # service tenant
37 glance::api::keystone_tenant: 'service'
38 aodh::api::keystone_tenant: 'service'
39 glance::registry::keystone_tenant: 'service'
40 neutron::server::auth_tenant: 'service'
41 neutron::agents::metadata::auth_tenant: 'service'
42 neutron::agents::l3::router_delete_namespaces: True
43 neutron::agents::dhcp::dhcp_delete_namespaces: True
44 cinder::api::keystone_tenant: 'service'
45 swift::proxy::authtoken::admin_tenant_name: 'service'
46 ceilometer::api::keystone_tenant: 'service'
47 heat::keystone_tenant: 'service'
48 sahara::admin_tenant_name: 'service'
49
50 # keystone
51 keystone::cron::token_flush::maxdelay: 3600
52 keystone::roles::admin::service_tenant: 'service'
53 keystone::roles::admin::admin_tenant: 'admin'
54 keystone::cron::token_flush::destination: '/dev/null'
55 keystone::config::keystone_config:
56   DEFAULT/secure_proxy_ssl_header:
57     value: 'HTTP_X_FORWARDED_PROTO'
58   ec2/driver:
59     value: 'keystone.contrib.ec2.backends.sql.Ec2'
60 keystone::service_name: 'httpd'
61 keystone::wsgi::apache::ssl: false
62
63 #swift
64 swift::proxy::pipeline:
65   - 'catch_errors'
66   - 'healthcheck'
67   - 'cache'
68   - 'ratelimit'
69   - 'tempurl'
70   - 'formpost'
71   - 'authtoken'
72   - 'keystone'
73   - 'staticweb'
74   - 'proxy-logging'
75   - 'proxy-server'
76
77 swift::proxy::account_autocreate: true
78
79 # glance
80 glance::api::pipeline: 'keystone'
81 glance::api::show_image_direct_url: true
82 glance::registry::pipeline: 'keystone'
83 glance::backend::swift::swift_store_create_container_on_put: true
84 glance_file_pcmk_directory: '/var/lib/glance/images'
85
86 # neutron
87 neutron::server::sync_db: true
88 neutron::agents::dhcp::dnsmasq_config_file: /etc/neutron/dnsmasq-neutron.conf
89
90 # nova
91 nova::notify_on_state_change: 'vm_and_task_state'
92 nova::api::default_floating_pool: 'public'
93 nova::api::sync_db_api: true
94 nova::scheduler::filter::ram_allocation_ratio: '1.0'
95 nova::cron::archive_deleted_rows::hour: '*/12'
96 nova::cron::archive_deleted_rows::destination: '/dev/null'
97 nova::notification_driver: messaging
98
99 # ceilometer
100 ceilometer::agent::auth::auth_endpoint_type: 'internalURL'
101
102 # cinder
103 cinder::scheduler::scheduler_driver: cinder.scheduler.filter_scheduler.FilterScheduler
104 cinder::cron::db_purge::destination: '/dev/null'
105 cinder::host: hostgroup
106 cinder_user_enabled_backends: []
107
108 # heat
109 heat::engine::configure_delegated_roles: false
110 heat::engine::trusts_delegated_roles: []
111 heat::instance_user: ''
112 heat::cron::purge_deleted::age: 30
113 heat::cron::purge_deleted::age_type: 'days'
114 heat::cron::purge_deleted::maxdelay: 3600
115 heat::cron::purge_deleted::destination: '/dev/null'
116 heat::keystone::domain::domain_name: 'heat_stack'
117 heat::keystone::domain::domain_admin: 'heat_stack_domain_admin'
118 heat::keystone::domain::domain_admin_email: 'heat_stack_domain_admin@localhost'
119
120 # pacemaker
121 pacemaker::corosync::cluster_name: 'tripleo_cluster'
122 pacemaker::corosync::manage_fw: false
123 pacemaker::resource_defaults::defaults:
124   resource-stickiness: { value: INFINITY }
125 corosync_token_timeout: 10000
126
127 # horizon
128 horizon::cache_backend: django.core.cache.backends.memcached.MemcachedCache
129 horizon::django_session_engine: 'django.contrib.sessions.backends.cache'
130 horizon::vhost_extra_params:
131   add_listen: false
132   priority: 10
133
134 # mysql
135 mysql::server::manage_config_file: true
136
137
138 tripleo::loadbalancer::keystone_admin: true
139 tripleo::loadbalancer::keystone_public: true
140 tripleo::loadbalancer::neutron: true
141 tripleo::loadbalancer::cinder: true
142 tripleo::loadbalancer::glance_api: true
143 tripleo::loadbalancer::glance_registry: true
144 tripleo::loadbalancer::nova_ec2: true
145 tripleo::loadbalancer::nova_osapi: true
146 tripleo::loadbalancer::nova_metadata: true
147 tripleo::loadbalancer::nova_novncproxy: true
148 tripleo::loadbalancer::mysql: true
149 tripleo::loadbalancer::redis: true
150 tripleo::loadbalancer::sahara: true
151 tripleo::loadbalancer::swift_proxy_server: true
152 tripleo::loadbalancer::ceilometer: true
153 tripleo::loadbalancer::aodh: true
154 tripleo::loadbalancer::heat_api: true
155 tripleo::loadbalancer::heat_cloudwatch: true
156 tripleo::loadbalancer::heat_cfn: true
157 tripleo::loadbalancer::horizon: true
158
159 controller_classes: []
160 # firewall
161 tripleo::firewall::firewall_rules:
162   '101 mongodb_config':
163     port: 27019
164   '102 mongodb_sharding':
165     port: 27018
166   '103 mongod':
167     port: 27017
168   '104 mysql galera':
169     port:
170       - 873
171       - 3306
172       - 4444
173       - 4567
174       - 4568
175       - 9200
176   '105 ntp':
177     port: 123
178     proto: udp
179   '106 vrrp':
180     proto: vrrp
181   '107 haproxy stats':
182     port: 1993
183   '108 redis':
184     port:
185       - 6379
186       - 26379
187   '109 rabbitmq':
188     port:
189       - 5672
190       - 35672
191   '110 ceph':
192     port:
193       - 6789
194       - '6800-6810'
195   '111 keystone':
196     port:
197       - 5000
198       - 13000
199       - 35357
200       - 13357
201   '112 glance':
202     port:
203       - 9292
204       - 9191
205       - 13292
206   '113 nova':
207     port:
208       - 6080
209       - 13080
210       - 8773
211       - 3773
212       - 8774
213       - 13774
214       - 8775
215   '114 neutron server':
216     port:
217       - 9696
218       - 13696
219   '115 neutron dhcp input':
220     proto: 'udp'
221     port: 67
222   '116 neutron dhcp output':
223     proto: 'udp'
224     chain: 'OUTPUT'
225     port: 68
226   '118 neutron vxlan networks':
227     proto: 'udp'
228     port: 4789
229   '119 cinder':
230     port:
231       - 8776
232       - 13776
233   '120 iscsi initiator':
234     port: 3260
235   '121 memcached':
236     port: 11211
237   '122 swift proxy':
238     port:
239       - 8080
240       - 13808
241   '123 swift storage':
242     port:
243       - 873
244       - 6000
245       - 6001
246       - 6002
247   '124 ceilometer':
248     port:
249       - 8777
250       - 13777
251   '125 heat':
252     port:
253       - 8000
254       - 13800
255       - 8003
256       - 13003
257       - 8004
258       - 13004
259   '126 horizon':
260     port:
261       - 80
262       - 443
263   '127 snmp':
264     port: 161
265     proto: 'udp'
266   '128 aodh':
267     port:
268       - 8042
269       - 13042