3b4b3cc9a19b074c610432f5449ed41a3f1e0918
[apex-tripleo-heat-templates.git] / puppet / manifests / overcloud_controller_pacemaker.pp
1 # Copyright 2015 Red Hat, Inc.
2 # All Rights Reserved.
3 #
4 # Licensed under the Apache License, Version 2.0 (the "License"); you may
5 # not use this file except in compliance with the License. You may obtain
6 # a copy of the License at
7 #
8 #     http://www.apache.org/licenses/LICENSE-2.0
9 #
10 # Unless required by applicable law or agreed to in writing, software
11 # distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
12 # WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
13 # License for the specific language governing permissions and limitations
14 # under the License.
15
16 Pcmk_resource <| |> {
17   tries     => 10,
18   try_sleep => 3,
19 }
20
21 if !str2bool(hiera('enable_package_install', 'false')) {
22   case $::osfamily {
23     'RedHat': {
24       Package { provider => 'norpm' } # provided by tripleo-puppet
25     }
26     default: {
27       warning('enable_package_install option not supported.')
28     }
29   }
30 }
31
32 if $::hostname == downcase(hiera('bootstrap_nodeid')) {
33   $pacemaker_master = true
34   $sync_db = true
35 } else {
36   $pacemaker_master = false
37   $sync_db = false
38 }
39
40 # When to start and enable services which haven't been Pacemakerized
41 # FIXME: remove when we start all OpenStack services using Pacemaker
42 # (occurences of this variable will be gradually replaced with false)
43 $non_pcmk_start = hiera('step') >= 4
44
45 if hiera('step') >= 1 {
46
47   create_resources(sysctl::value, hiera('sysctl_settings'), {})
48
49   if count(hiera('ntp::servers')) > 0 {
50     include ::ntp
51   }
52
53   $controller_node_ips = split(hiera('controller_node_ips'), ',')
54   $controller_node_names = split(downcase(hiera('controller_node_names')), ',')
55   class { '::tripleo::loadbalancer' :
56     controller_hosts       => $controller_node_ips,
57     controller_hosts_names => $controller_node_names,
58     manage_vip             => false,
59     mysql_clustercheck     => true,
60     haproxy_service_manage => false,
61   }
62
63   $pacemaker_cluster_members = downcase(regsubst(hiera('controller_node_names'), ',', ' ', 'G'))
64   user { 'hacluster':
65    ensure => present,
66   } ->
67   class { '::pacemaker':
68     hacluster_pwd => hiera('hacluster_pwd'),
69   } ->
70   class { '::pacemaker::corosync':
71     cluster_members => $pacemaker_cluster_members,
72     setup_cluster   => $pacemaker_master,
73   }
74   class { '::pacemaker::stonith':
75     disable => true,
76   }
77
78   # Only configure RabbitMQ in this step, don't start it yet to
79   # avoid races where non-master nodes attempt to start without
80   # config (eg. binding on 0.0.0.0)
81   # The module ignores erlang_cookie if cluster_config is false
82   class { '::rabbitmq':
83     service_manage          => false,
84     tcp_keepalive           => false,
85     config_kernel_variables => hiera('rabbitmq_kernel_variables'),
86     config_variables        => hiera('rabbitmq_config_variables'),
87     environment_variables   => hiera('rabbitmq_environment'),
88   } ->
89   file { '/var/lib/rabbitmq/.erlang.cookie':
90     ensure  => 'present',
91     owner   => 'rabbitmq',
92     group   => 'rabbitmq',
93     mode    => '0400',
94     content => hiera('rabbitmq::erlang_cookie'),
95     replace => true,
96   }
97
98   if downcase(hiera('ceilometer_backend')) == 'mongodb' {
99     include ::mongodb::globals
100     class { '::mongodb::server' :
101       service_manage => false,
102     }
103   }
104
105   # Memcached
106   class {'::memcached' :
107     service_manage => false,
108   }
109
110   # Redis
111   class { '::redis' :
112     service_manage => false,
113     notify_service => false,
114   }
115
116   # Galera
117   if str2bool(hiera('enable_galera', 'true')) {
118     $mysql_config_file = '/etc/my.cnf.d/galera.cnf'
119   } else {
120     $mysql_config_file = '/etc/my.cnf.d/server.cnf'
121   }
122   $galera_nodes = downcase(hiera('galera_node_names', $::hostname))
123   $galera_nodes_count = count(split($galera_nodes, ','))
124
125   $mysqld_options = {
126     'mysqld' => {
127       'skip-name-resolve'             => '1',
128       'binlog_format'                 => 'ROW',
129       'default-storage-engine'        => 'innodb',
130       'innodb_autoinc_lock_mode'      => '2',
131       'innodb_locks_unsafe_for_binlog'=> '1',
132       'query_cache_size'              => '0',
133       'query_cache_type'              => '0',
134       'bind-address'                  => hiera('mysql_bind_host'),
135       'max_connections'               => '1024',
136       'open_files_limit'              => '-1',
137       'wsrep_provider'                => '/usr/lib64/galera/libgalera_smm.so',
138       'wsrep_cluster_name'            => 'galera_cluster',
139       'wsrep_slave_threads'           => '1',
140       'wsrep_certify_nonPK'           => '1',
141       'wsrep_max_ws_rows'             => '131072',
142       'wsrep_max_ws_size'             => '1073741824',
143       'wsrep_debug'                   => '0',
144       'wsrep_convert_LOCK_to_trx'     => '0',
145       'wsrep_retry_autocommit'        => '1',
146       'wsrep_auto_increment_control'  => '1',
147       'wsrep_drupal_282555_workaround'=> '0',
148       'wsrep_causal_reads'            => '0',
149       'wsrep_notify_cmd'              => '',
150       'wsrep_sst_method'              => 'rsync',
151     }
152   }
153
154   class { '::mysql::server':
155     create_root_user   => false,
156     create_root_my_cnf => false,
157     config_file        => $mysql_config_file,
158     override_options   => $mysqld_options,
159     service_manage     => false,
160     service_enabled    => false,
161   }
162
163 }
164
165 if hiera('step') >= 2 {
166
167   # NOTE(gfidente): the following vars are needed on all nodes so they
168   # need to stay out of pacemaker_master conditional
169   $mongo_node_ips_with_port = suffix(hiera('mongo_node_ips'), ':27017')
170   $mongodb_replset = hiera('mongodb::server::replset')
171
172   if $pacemaker_master {
173
174     # FIXME: we should not have to access tripleo::loadbalancer class
175     # parameters here to configure pacemaker VIPs. The configuration
176     # of pacemaker VIPs could move into puppet-tripleo or we should
177     # make use of less specific hiera parameters here for the settings.
178     $control_vip = hiera('tripleo::loadbalancer::controller_virtual_ip')
179     pacemaker::resource::ip { 'control_vip':
180       ip_address => $control_vip,
181     }
182     $public_vip = hiera('tripleo::loadbalancer::public_virtual_ip')
183     pacemaker::resource::ip { 'public_vip':
184       ip_address => $public_vip,
185     }
186
187     $internal_api_vip = hiera('tripleo::loadbalancer::internal_api_virtual_ip')
188     if $internal_api_vip and $internal_api_vip != $control_vip {
189       pacemaker::resource::ip { 'internal_api_vip':
190         ip_address => $internal_api_vip,
191       }
192     }
193
194     $storage_vip = hiera('tripleo::loadbalancer::storage_virtual_ip')
195     if $storage_vip and $storage_vip != $control_vip {
196       pacemaker::resource::ip { 'storage_vip':
197         ip_address => $storage_vip,
198       }
199     }
200
201     $storage_mgmt_vip = hiera('tripleo::loadbalancer::storage_mgmt_virtual_ip')
202     if $storage_mgmt_vip and $storage_mgmt_vip != $control_vip {
203       pacemaker::resource::ip { 'storage_mgmt_vip':
204         ip_address => $storage_mgmt_vip,
205       }
206     }
207
208     pacemaker::resource::service { 'haproxy':
209       clone_params => true,
210     }
211     pacemaker::resource::service { $::memcached::params::service_name :
212       clone_params => true,
213       require      => Class['::memcached'],
214     }
215
216     pacemaker::resource::ocf { 'rabbitmq':
217       ocf_agent_name  => 'heartbeat:rabbitmq-cluster',
218       resource_params => 'set_policy=\'ha-all ^(?!amq\.).* {"ha-mode":"all"}\'',
219       clone_params    => 'ordered=true interleave=true',
220       require         => Class['::rabbitmq'],
221     }
222
223     if downcase(hiera('ceilometer_backend')) == 'mongodb' {
224       pacemaker::resource::service { $::mongodb::params::service_name :
225         op_params    => 'start timeout=120s',
226         clone_params => true,
227         require      => Class['::mongodb::server'],
228       }
229       # NOTE (spredzy) : The replset can only be run
230       # once all the nodes have joined the cluster.
231       mongodb_conn_validator { $mongo_node_ips_with_port :
232         timeout => '600',
233         require => Pacemaker::Resource::Service[$::mongodb::params::service_name],
234         before  => Mongodb_replset[$mongodb_replset],
235       }
236       mongodb_replset { $mongodb_replset :
237         members => $mongo_node_ips_with_port,
238       }
239     }
240
241     pacemaker::resource::ocf { 'galera' :
242       ocf_agent_name  => 'heartbeat:galera',
243       op_params       => 'promote timeout=300s on-fail=block',
244       master_params   => '',
245       meta_params     => "master-max=${galera_nodes_count} ordered=true",
246       resource_params => "additional_parameters='--open-files-limit=16384' enable_creation=true wsrep_cluster_address='gcomm://${galera_nodes}'",
247       require         => Class['::mysql::server'],
248       before          => Exec['galera-ready'],
249     }
250
251     pacemaker::resource::ocf { 'redis':
252       ocf_agent_name  => 'heartbeat:redis',
253       master_params   => '',
254       meta_params     => 'notify=true ordered=true interleave=true',
255       resource_params => 'wait_last_known_master=true',
256       require         => Class['::redis'],
257     }
258     $redis_vip = hiera('redis_vip')
259     if $redis_vip and $redis_vip != $control_vip {
260         pacemaker::resource::ip { 'vip-redis':
261           ip_address => $redis_vip,
262         }
263     }
264     pacemaker::constraint::base { 'redis-master-then-vip-redis':
265       constraint_type => 'order',
266       first_resource  => 'redis-master',
267       second_resource => "ip-${redis_vip}",
268       first_action    => 'promote',
269       second_action   => 'start',
270       require => [Pacemaker::Resource::Ocf['redis'],
271                   Pacemaker::Resource::Ip['vip-redis']],
272     }
273     pacemaker::constraint::colocation { 'vip-redis-with-redis-master':
274       source  => "ip-${redis_vip}",
275       target  => 'redis-master',
276       score   => 'INFINITY',
277       require => [Pacemaker::Resource::Ocf['redis'],
278                   Pacemaker::Resource::Ip['vip-redis']],
279     }
280
281   }
282
283   exec { 'galera-ready' :
284     command     => '/usr/bin/clustercheck >/dev/null',
285     timeout     => 30,
286     tries       => 180,
287     try_sleep   => 10,
288     environment => ["AVAILABLE_WHEN_READONLY=0"],
289     require     => File['/etc/sysconfig/clustercheck'],
290   }
291
292   file { '/etc/sysconfig/clustercheck' :
293     ensure  => file,
294     content => "MYSQL_USERNAME=root\n
295 MYSQL_PASSWORD=''\n
296 MYSQL_HOST=localhost\n",
297   }
298
299   xinetd::service { 'galera-monitor' :
300     port           => '9200',
301     server         => '/usr/bin/clustercheck',
302     per_source     => 'UNLIMITED',
303     log_on_success => '',
304     log_on_failure => 'HOST',
305     flags          => 'REUSE',
306     service_type   => 'UNLISTED',
307     user           => 'root',
308     group          => 'root',
309     require        => File['/etc/sysconfig/clustercheck'],
310   }
311
312   # Create all the database schemas
313   # Example DSN format: mysql://user:password@host/dbname
314   if $sync_db {
315     $allowed_hosts = ['%',hiera('mysql_bind_host')]
316     $keystone_dsn = split(hiera('keystone::database_connection'), '[@:/?]')
317     class { 'keystone::db::mysql':
318       user          => $keystone_dsn[3],
319       password      => $keystone_dsn[4],
320       host          => $keystone_dsn[5],
321       dbname        => $keystone_dsn[6],
322       allowed_hosts => $allowed_hosts,
323       require       => Exec['galera-ready'],
324     }
325     $glance_dsn = split(hiera('glance::api::database_connection'), '[@:/?]')
326     class { 'glance::db::mysql':
327       user          => $glance_dsn[3],
328       password      => $glance_dsn[4],
329       host          => $glance_dsn[5],
330       dbname        => $glance_dsn[6],
331       allowed_hosts => $allowed_hosts,
332       require       => Exec['galera-ready'],
333     }
334     $nova_dsn = split(hiera('nova::database_connection'), '[@:/?]')
335     class { 'nova::db::mysql':
336       user          => $nova_dsn[3],
337       password      => $nova_dsn[4],
338       host          => $nova_dsn[5],
339       dbname        => $nova_dsn[6],
340       allowed_hosts => $allowed_hosts,
341       require       => Exec['galera-ready'],
342     }
343     $neutron_dsn = split(hiera('neutron::server::database_connection'), '[@:/?]')
344     class { 'neutron::db::mysql':
345       user          => $neutron_dsn[3],
346       password      => $neutron_dsn[4],
347       host          => $neutron_dsn[5],
348       dbname        => $neutron_dsn[6],
349       allowed_hosts => $allowed_hosts,
350       require       => Exec['galera-ready'],
351     }
352     $cinder_dsn = split(hiera('cinder::database_connection'), '[@:/?]')
353     class { 'cinder::db::mysql':
354       user          => $cinder_dsn[3],
355       password      => $cinder_dsn[4],
356       host          => $cinder_dsn[5],
357       dbname        => $cinder_dsn[6],
358       allowed_hosts => $allowed_hosts,
359       require       => Exec['galera-ready'],
360     }
361     $heat_dsn = split(hiera('heat::database_connection'), '[@:/?]')
362     class { 'heat::db::mysql':
363       user          => $heat_dsn[3],
364       password      => $heat_dsn[4],
365       host          => $heat_dsn[5],
366       dbname        => $heat_dsn[6],
367       allowed_hosts => $allowed_hosts,
368       require       => Exec['galera-ready'],
369     }
370     if downcase(hiera('ceilometer_backend')) == 'mysql' {
371       $ceilometer_dsn = split(hiera('ceilometer_mysql_conn_string'), '[@:/?]')
372       class { 'ceilometer::db::mysql':
373         user          => $ceilometer_dsn[3],
374         password      => $ceilometer_dsn[4],
375         host          => $ceilometer_dsn[5],
376         dbname        => $ceilometer_dsn[6],
377         allowed_hosts => $allowed_hosts,
378         require       => Exec['galera-ready'],
379       }
380     }
381   }
382
383   # pre-install swift here so we can build rings
384   include ::swift
385
386   # Ceph
387   $cinder_enable_rbd_backend = hiera('cinder_enable_rbd_backend', false)
388   $enable_ceph = $cinder_enable_rbd_backend
389
390   if $enable_ceph {
391     class { 'ceph::profile::params':
392       mon_initial_members => downcase(hiera('ceph_mon_initial_members'))
393     }
394     include ::ceph::profile::mon
395   }
396
397   if str2bool(hiera('enable_ceph_storage', 'false')) {
398     include ::ceph::profile::client
399     include ::ceph::profile::osd
400   }
401
402
403 } #END STEP 2
404
405 if hiera('step') >= 3 {
406
407   class { '::keystone':
408     sync_db => $sync_db,
409     manage_service => false,
410     enabled => false,
411   }
412
413   #TODO: need a cleanup-keystone-tokens.sh solution here
414   keystone_config {
415     'ec2/driver': value => 'keystone.contrib.ec2.backends.sql.Ec2';
416   }
417   file { [ '/etc/keystone/ssl', '/etc/keystone/ssl/certs', '/etc/keystone/ssl/private' ]:
418     ensure  => 'directory',
419     owner   => 'keystone',
420     group   => 'keystone',
421     require => Package['keystone'],
422   }
423   file { '/etc/keystone/ssl/certs/signing_cert.pem':
424     content => hiera('keystone_signing_certificate'),
425     owner   => 'keystone',
426     group   => 'keystone',
427     notify  => Service['keystone'],
428     require => File['/etc/keystone/ssl/certs'],
429   }
430   file { '/etc/keystone/ssl/private/signing_key.pem':
431     content => hiera('keystone_signing_key'),
432     owner   => 'keystone',
433     group   => 'keystone',
434     notify  => Service['keystone'],
435     require => File['/etc/keystone/ssl/private'],
436   }
437   file { '/etc/keystone/ssl/certs/ca.pem':
438     content => hiera('keystone_ca_certificate'),
439     owner   => 'keystone',
440     group   => 'keystone',
441     notify  => Service['keystone'],
442     require => File['/etc/keystone/ssl/certs'],
443   }
444
445   $glance_backend = downcase(hiera('glance_backend', 'swift'))
446   case $glance_backend {
447       swift: { $glance_store = 'glance.store.swift.Store' }
448       file: { $glance_store = 'glance.store.filesystem.Store' }
449       rbd: { $glance_store = 'glance.store.rbd.Store' }
450       default: { fail('Unrecognized glance_backend parameter.') }
451   }
452
453   # TODO: notifications, scrubber, etc.
454   include ::glance
455   class { 'glance::api':
456     known_stores => [$glance_store],
457     manage_service => false,
458     enabled => false,
459   }
460   class { '::glance::registry' :
461     sync_db => $sync_db,
462     manage_service => false,
463     enabled => false,
464   }
465   include join(['::glance::backend::', $glance_backend])
466
467   include ::nova
468
469   class { '::nova::api' :
470     sync_db => $sync_db,
471     manage_service => false,
472     enabled => false,
473   }
474   class { '::nova::cert' :
475     manage_service => false,
476     enabled => false,
477   }
478   class { '::nova::conductor' :
479     manage_service => false,
480     enabled => false,
481   }
482   class { '::nova::consoleauth' :
483     manage_service => false,
484     enabled => false,
485   }
486   class { '::nova::vncproxy' :
487     manage_service => false,
488     enabled => false,
489   }
490   class { '::nova::scheduler' :
491     manage_service => false,
492     enabled => false,
493   }
494   include ::nova::network::neutron
495
496   # Neutron class definitions
497   include ::neutron
498   class { '::neutron::server' :
499     sync_db => $sync_db,
500     manage_service => false,
501     enabled => false,
502   }
503   class { '::neutron::agents::dhcp' :
504     manage_service => false,
505     enabled => false,
506   }
507   class { '::neutron::agents::l3' :
508     manage_service => false,
509     enabled => false,
510   }
511   class { 'neutron::agents::metadata':
512     manage_service => false,
513     enabled => false,
514   }
515   file { '/etc/neutron/dnsmasq-neutron.conf':
516     content => hiera('neutron_dnsmasq_options'),
517     owner   => 'neutron',
518     group   => 'neutron',
519     notify  => Service['neutron-dhcp-service'],
520     require => Package['neutron'],
521   }
522   class { 'neutron::plugins::ml2':
523     flat_networks   => split(hiera('neutron_flat_networks'), ','),
524     tenant_network_types => [hiera('neutron_tenant_network_type')],
525   }
526   class { 'neutron::agents::ml2::ovs':
527     # manage_service   => false # not implemented
528     enabled          => false,
529     bridge_mappings  => split(hiera('neutron_bridge_mappings'), ','),
530     tunnel_types     => split(hiera('neutron_tunnel_types'), ','),
531   }
532
533   include ::cinder
534   class { '::cinder::api':
535     sync_db => $sync_db,
536     manage_service => false,
537     enabled => false,
538   }
539   class { '::cinder::scheduler' :
540     manage_service => false,
541     enabled => false,
542   }
543   class { '::cinder::volume' :
544     manage_service => false,
545     enabled => false,
546   }
547   include ::cinder::glance
548   class {'cinder::setup_test_volume':
549     size => join([hiera('cinder_lvm_loop_device_size'), 'M']),
550   }
551
552   $cinder_enable_iscsi = hiera('cinder_enable_iscsi_backend', true)
553   if $cinder_enable_iscsi {
554     $cinder_iscsi_backend = 'tripleo_iscsi'
555
556     cinder::backend::iscsi { $cinder_iscsi_backend :
557       iscsi_ip_address => hiera('cinder_iscsi_ip_address'),
558       iscsi_helper     => hiera('cinder_iscsi_helper'),
559     }
560   }
561
562   if $enable_ceph {
563
564     Ceph_pool {
565       pg_num  => hiera('ceph::profile::params::osd_pool_default_pg_num'),
566       pgp_num => hiera('ceph::profile::params::osd_pool_default_pgp_num'),
567       size    => hiera('ceph::profile::params::osd_pool_default_size'),
568     }
569
570     $ceph_pools = hiera('ceph_pools')
571     ceph::pool { $ceph_pools : }
572   }
573
574   if $cinder_enable_rbd_backend {
575     $cinder_rbd_backend = 'tripleo_ceph'
576
577     cinder_config {
578       "${cinder_rbd_backend}/host": value => 'hostgroup';
579     }
580
581     cinder::backend::rbd { $cinder_rbd_backend :
582       rbd_pool        => 'volumes',
583       rbd_user        => 'openstack',
584       rbd_secret_uuid => hiera('ceph::profile::params::fsid'),
585       require         => Ceph::Pool['volumes'],
586     }
587   }
588
589   if hiera('cinder_enable_netapp_backend', false) {
590     $cinder_netapp_backend = hiera('cinder::backend::netapp::title')
591
592     cinder_config {
593       "${cinder_netapp_backend}/host": value => 'hostgroup';
594     }
595
596     if hiera('cinder_netapp_nfs_shares', undef) {
597       $cinder_netapp_nfs_shares = split(hiera('cinder_netapp_nfs_shares', undef), ',')
598     }
599
600     cinder::backend::netapp { $cinder_netapp_backend :
601       nfs_shares => $cinder_netapp_nfs_shares,
602     }
603   }
604
605   $cinder_enabled_backends = delete_undef_values([$cinder_iscsi_backend, $cinder_rbd_backend, $cinder_netapp_backend])
606   class { '::cinder::backends' :
607     enabled_backends => $cinder_enabled_backends,
608   }
609
610   # swift proxy
611   class { '::swift::proxy' :
612     manage_service => $non_pcmk_start,
613     enabled => $non_pcmk_start,
614   }
615   include ::swift::proxy::proxy_logging
616   include ::swift::proxy::healthcheck
617   include ::swift::proxy::cache
618   include ::swift::proxy::keystone
619   include ::swift::proxy::authtoken
620   include ::swift::proxy::staticweb
621   include ::swift::proxy::ratelimit
622   include ::swift::proxy::catch_errors
623   include ::swift::proxy::tempurl
624   include ::swift::proxy::formpost
625
626   # swift storage
627   if str2bool(hiera('enable_swift_storage', 'true')) {
628     class {'::swift::storage::all':
629       mount_check => str2bool(hiera('swift_mount_check'))
630     }
631     class {'::swift::storage::account':
632       manage_service => $non_pcmk_start,
633       enabled => $non_pcmk_start,
634     }
635     class {'::swift::storage::container':
636       manage_service => $non_pcmk_start,
637       enabled => $non_pcmk_start,
638     }
639     class {'::swift::storage::object':
640       manage_service => $non_pcmk_start,
641       enabled => $non_pcmk_start,
642     }
643     if(!defined(File['/srv/node'])) {
644       file { '/srv/node':
645         ensure  => directory,
646         owner   => 'swift',
647         group   => 'swift',
648         require => Package['openstack-swift'],
649       }
650     }
651     $swift_components = ['account', 'container', 'object']
652     swift::storage::filter::recon { $swift_components : }
653     swift::storage::filter::healthcheck { $swift_components : }
654   }
655
656   # Ceilometer
657   $ceilometer_backend = downcase(hiera('ceilometer_backend'))
658   case $ceilometer_backend {
659     /mysql/ : {
660       $ceilometer_database_connection = hiera('ceilometer_mysql_conn_string')
661     }
662     default : {
663       $mongo_node_string = join($mongo_node_ips_with_port, ',')
664       $ceilometer_database_connection = "mongodb://${mongo_node_string}/ceilometer?replicaSet=${mongodb_replset}"
665     }
666   }
667   include ::ceilometer
668   class { '::ceilometer::api' :
669     manage_service => false,
670     enabled => false,
671   }
672   class { '::ceilometer::agent::notification' :
673     manage_service => false,
674     enabled => false,
675   }
676   class { '::ceilometer::agent::central' :
677     manage_service => false,
678     enabled => false,
679   }
680   class { '::ceilometer::alarm::notifier' :
681     manage_service => false,
682     enabled => false,
683   }
684   class { '::ceilometer::alarm::evaluator' :
685     manage_service => false,
686     enabled => false,
687   }
688   class { '::ceilometer::collector' :
689     manage_service => false,
690     enabled => false,
691   }
692   include ::ceilometer::expirer
693   class { '::ceilometer::db' :
694     database_connection => $ceilometer_database_connection,
695     sync_db             => $sync_db,
696   }
697   include ceilometer::agent::auth
698
699   Cron <| title == 'ceilometer-expirer' |> { command => "sleep $((\$(od -A n -t d -N 3 /dev/urandom) % 86400)) && ${::ceilometer::params::expirer_command}" }
700
701   # Heat
702   class { '::heat' :
703     sync_db => $sync_db,
704   }
705   class { '::heat::api' :
706     manage_service => false,
707     enabled => false,
708   }
709   class { '::heat::api_cfn' :
710     manage_service => false,
711     enabled => false,
712   }
713   class { '::heat::api_cloudwatch' :
714     manage_service => false,
715     enabled => false,
716   }
717   class { '::heat::engine' :
718     manage_service => false,
719     enabled => false,
720   }
721
722   # httpd/apache and horizon
723   # NOTE(gfidente): server-status can be consumed by the pacemaker resource agent
724   include ::apache
725   include ::apache::mod::status
726   $vhost_params = {
727     add_listen => false,
728     priority   => 10,
729   }
730   class { 'horizon':
731     cache_server_ip    => hiera('memcache_node_ips', '127.0.0.1'),
732     vhost_extra_params => $vhost_params,
733     server_aliases     => $::hostname,
734   }
735
736   $snmpd_user = hiera('snmpd_readonly_user_name')
737   snmp::snmpv3_user { $snmpd_user:
738     authtype => 'MD5',
739     authpass => hiera('snmpd_readonly_user_password'),
740   }
741   class { 'snmp':
742     agentaddress => ['udp:161','udp6:[::1]:161'],
743     snmpd_config => [ join(['rouser ', hiera('snmpd_readonly_user_name')]), 'proc  cron', 'includeAllDisks  10%', 'master agentx', 'trapsink localhost public', 'iquerySecName internalUser', 'rouser internalUser', 'defaultMonitors yes', 'linkUpDownNotifications yes' ],
744   }
745
746 } #END STEP 3
747
748 if hiera('step') >= 4 {
749   if $pacemaker_master {
750
751     # Keystone
752     pacemaker::resource::service { $::keystone::params::service_name :
753       clone_params => "interleave=true",
754     }
755
756     # Cinder
757     pacemaker::resource::service { $::cinder::params::api_service :
758       clone_params => "interleave=true",
759       require      => Pacemaker::Resource::Service[$::keystone::params::service_name],
760     }
761     pacemaker::resource::service { $::cinder::params::scheduler_service :
762       clone_params => "interleave=true",
763     }
764     pacemaker::resource::service { $::cinder::params::volume_service : }
765
766     pacemaker::constraint::base { 'keystone-then-cinder-api-constraint':
767       constraint_type => 'order',
768       first_resource  => "${::keystone::params::service_name}-clone",
769       second_resource => "${::cinder::params::api_service}-clone",
770       first_action    => 'start',
771       second_action   => 'start',
772       require         => [Pacemaker::Resource::Service[$::cinder::params::api_service],
773                           Pacemaker::Resource::Service[$::keystone::params::service_name]],
774     }
775     pacemaker::constraint::base { 'cinder-api-then-cinder-scheduler-constraint':
776       constraint_type => "order",
777       first_resource => "${::cinder::params::api_service}-clone",
778       second_resource => "${::cinder::params::scheduler_service}-clone",
779       first_action => "start",
780       second_action => "start",
781       require => [Pacemaker::Resource::Service[$::cinder::params::api_service],
782                   Pacemaker::Resource::Service[$::cinder::params::scheduler_service]],
783     }
784     pacemaker::constraint::colocation { 'cinder-scheduler-with-cinder-api-colocation':
785       source => "${::cinder::params::scheduler_service}-clone",
786       target => "${::cinder::params::api_service}-clone",
787       score => "INFINITY",
788       require => [Pacemaker::Resource::Service[$::cinder::params::api_service],
789                   Pacemaker::Resource::Service[$::cinder::params::scheduler_service]],
790     }
791     pacemaker::constraint::base { 'cinder-scheduler-then-cinder-volume-constraint':
792       constraint_type => "order",
793       first_resource => "${::cinder::params::scheduler_service}-clone",
794       second_resource => "${::cinder::params::volume_service}",
795       first_action => "start",
796       second_action => "start",
797       require => [Pacemaker::Resource::Service[$::cinder::params::scheduler_service],
798                   Pacemaker::Resource::Service[$::cinder::params::volume_service]],
799     }
800     pacemaker::constraint::colocation { 'cinder-volume-with-cinder-scheduler-colocation':
801       source => "${::cinder::params::volume_service}",
802       target => "${::cinder::params::scheduler_service}-clone",
803       score => "INFINITY",
804       require => [Pacemaker::Resource::Service[$::cinder::params::scheduler_service],
805                   Pacemaker::Resource::Service[$::cinder::params::volume_service]],
806     }
807
808     # Glance
809     pacemaker::resource::service { $::glance::params::registry_service_name :
810       clone_params => "interleave=true",
811       require      => Pacemaker::Resource::Service[$::keystone::params::service_name],
812     }
813     pacemaker::resource::service { $::glance::params::api_service_name :
814       clone_params => "interleave=true",
815     }
816
817     pacemaker::constraint::base { 'keystone-then-glance-registry-constraint':
818       constraint_type => 'order',
819       first_resource  => "${::keystone::params::service_name}-clone",
820       second_resource => "${::glance::params::registry_service_name}-clone",
821       first_action    => 'start',
822       second_action   => 'start',
823       require         => [Pacemaker::Resource::Service[$::glance::params::registry_service_name],
824                           Pacemaker::Resource::Service[$::keystone::params::service_name]],
825     }
826     pacemaker::constraint::base { 'glance-registry-then-glance-api-constraint':
827       constraint_type => "order",
828       first_resource  => "${::glance::params::registry_service_name}-clone",
829       second_resource => "${::glance::params::api_service_name}-clone",
830       first_action    => "start",
831       second_action   => "start",
832       require => [Pacemaker::Resource::Service[$::glance::params::registry_service_name],
833                   Pacemaker::Resource::Service[$::glance::params::api_service_name]],
834     }
835     pacemaker::constraint::colocation { 'glance-api-with-glance-registry-colocation':
836       source  => "${::glance::params::api_service_name}-clone",
837       target  => "${::glance::params::registry_service_name}-clone",
838       score   => "INFINITY",
839       require => [Pacemaker::Resource::Service[$::glance::params::registry_service_name],
840                   Pacemaker::Resource::Service[$::glance::params::api_service_name]],
841     }
842
843     # Neutron
844     # NOTE(gfidente): Neutron will try to populate the database with some data
845     # as soon as neutron-server is started; to avoid races we want to make this
846     # happen only on one node, before normal Pacemaker initialization
847     # https://bugzilla.redhat.com/show_bug.cgi?id=1233061
848     exec { 'neutron-server-start-wait-stop' :
849       command   => "systemctl start neutron-server && \
850                     sleep 5s && \
851                     systemctl stop neutron-server",
852       path      => ["/usr/bin", "/usr/sbin"],
853     } ->
854     pacemaker::resource::service { $::neutron::params::server_service:
855       op_params => "start timeout=90",
856       clone_params   => "interleave=true",
857       require => Pacemaker::Resource::Service[$::keystone::params::service_name]
858     }
859     pacemaker::resource::service { $::neutron::params::l3_agent_service:
860       clone_params   => "interleave=true",
861     }
862     pacemaker::resource::service { $::neutron::params::dhcp_agent_service:
863       clone_params   => "interleave=true",
864     }
865     pacemaker::resource::service { $::neutron::params::ovs_agent_service:
866       clone_params => "interleave=true",
867     }
868     pacemaker::resource::service { $::neutron::params::metadata_agent_service:
869       clone_params => "interleave=true",
870     }
871     pacemaker::resource::ocf { $::neutron::params::ovs_cleanup_service:
872       ocf_agent_name => "neutron:OVSCleanup",
873       clone_params => "interleave=true",
874     }
875     pacemaker::resource::ocf { 'neutron-netns-cleanup':
876       ocf_agent_name => "neutron:NetnsCleanup",
877       clone_params => "interleave=true",
878     }
879     pacemaker::resource::ocf { 'neutron-scale':
880       ocf_agent_name => "neutron:NeutronScale",
881       clone_params => "globally-unique=true clone-max=3 interleave=true",
882     }
883     pacemaker::constraint::base { 'keystone-to-neutron-server-constraint':
884       constraint_type => "order",
885       first_resource => "${::keystone::params::service_name}-clone",
886       second_resource => "${::neutron::params::server_service}-clone",
887       first_action => "start",
888       second_action => "start",
889       require => [Pacemaker::Resource::Service[$::keystone::params::service_name],
890                   Pacemaker::Resource::Service[$::neutron::params::server_service]],
891     }
892     pacemaker::constraint::base { 'neutron-server-to-neutron-scale-constraint':
893       constraint_type => "order",
894       first_resource => "${::neutron::params::server_service}-clone",
895       second_resource => "neutron-scale-clone",
896       first_action => "start",
897       second_action => "start",
898       require => [Pacemaker::Resource::Service[$::neutron::params::server_service],
899                   Pacemaker::Resource::Ocf['neutron-scale']],
900     }
901     pacemaker::constraint::base { 'neutron-scale-to-ovs-cleanup-constraint':
902       constraint_type => "order",
903       first_resource => "neutron-scale-clone",
904       second_resource => "${::neutron::params::ovs_cleanup_service}-clone",
905       first_action => "start",
906       second_action => "start",
907       require => [Pacemaker::Resource::Ocf['neutron-scale'],
908                   Pacemaker::Resource::Ocf["${::neutron::params::ovs_cleanup_service}"]],
909     }
910     pacemaker::constraint::colocation { 'neutron-scale-to-ovs-cleanup-colocation':
911       source => "${::neutron::params::ovs_cleanup_service}-clone",
912       target => "neutron-scale-clone",
913       score => "INFINITY",
914       require => [Pacemaker::Resource::Ocf['neutron-scale'],
915                   Pacemaker::Resource::Ocf["${::neutron::params::ovs_cleanup_service}"]],
916     }
917     pacemaker::constraint::base { 'neutron-ovs-cleanup-to-netns-cleanup-constraint':
918       constraint_type => "order",
919       first_resource => "${::neutron::params::ovs_cleanup_service}-clone",
920       second_resource => "neutron-netns-cleanup-clone",
921       first_action => "start",
922       second_action => "start",
923       require => [Pacemaker::Resource::Ocf["${::neutron::params::ovs_cleanup_service}"],
924                   Pacemaker::Resource::Ocf['neutron-netns-cleanup']],
925     }
926     pacemaker::constraint::colocation { 'neutron-ovs-cleanup-to-netns-cleanup-colocation':
927       source => "neutron-netns-cleanup-clone",
928       target => "${::neutron::params::ovs_cleanup_service}-clone",
929       score => "INFINITY",
930       require => [Pacemaker::Resource::Ocf["${::neutron::params::ovs_cleanup_service}"],
931                   Pacemaker::Resource::Ocf['neutron-netns-cleanup']],
932     }
933     pacemaker::constraint::base { 'neutron-netns-cleanup-to-openvswitch-agent-constraint':
934       constraint_type => "order",
935       first_resource => "neutron-netns-cleanup-clone",
936       second_resource => "${::neutron::params::ovs_agent_service}-clone",
937       first_action => "start",
938       second_action => "start",
939       require => [Pacemaker::Resource::Ocf["neutron-netns-cleanup"],
940                   Pacemaker::Resource::Service["${::neutron::params::ovs_agent_service}"]],
941     }
942     pacemaker::constraint::colocation { 'neutron-netns-cleanup-to-openvswitch-agent-colocation':
943       source => "${::neutron::params::ovs_agent_service}-clone",
944       target => "neutron-netns-cleanup-clone",
945       score => "INFINITY",
946       require => [Pacemaker::Resource::Ocf["neutron-netns-cleanup"],
947                   Pacemaker::Resource::Service["${::neutron::params::ovs_agent_service}"]],
948     }
949     pacemaker::constraint::base { 'neutron-openvswitch-agent-to-dhcp-agent-constraint':
950       constraint_type => "order",
951       first_resource => "${::neutron::params::ovs_agent_service}-clone",
952       second_resource => "${::neutron::params::dhcp_agent_service}-clone",
953       first_action => "start",
954       second_action => "start",
955       require => [Pacemaker::Resource::Service["${::neutron::params::ovs_agent_service}"],
956                   Pacemaker::Resource::Service["${::neutron::params::dhcp_agent_service}"]],
957
958     }
959     pacemaker::constraint::colocation { 'neutron-openvswitch-agent-to-dhcp-agent-colocation':
960       source => "${::neutron::params::dhcp_agent_service}-clone",
961       target => "${::neutron::params::ovs_agent_service}-clone",
962       score => "INFINITY",
963       require => [Pacemaker::Resource::Service["${::neutron::params::ovs_agent_service}"],
964                   Pacemaker::Resource::Service["${::neutron::params::dhcp_agent_service}"]],
965     }
966     pacemaker::constraint::base { 'neutron-dhcp-agent-to-l3-agent-constraint':
967       constraint_type => "order",
968       first_resource => "${::neutron::params::dhcp_agent_service}-clone",
969       second_resource => "${::neutron::params::l3_agent_service}-clone",
970       first_action => "start",
971       second_action => "start",
972       require => [Pacemaker::Resource::Service["${::neutron::params::dhcp_agent_service}"],
973                   Pacemaker::Resource::Service["${::neutron::params::l3_agent_service}"]]
974     }
975     pacemaker::constraint::colocation { 'neutron-dhcp-agent-to-l3-agent-colocation':
976       source => "${::neutron::params::l3_agent_service}-clone",
977       target => "${::neutron::params::dhcp_agent_service}-clone",
978       score => "INFINITY",
979       require => [Pacemaker::Resource::Service["${::neutron::params::dhcp_agent_service}"],
980                   Pacemaker::Resource::Service["${::neutron::params::l3_agent_service}"]]
981     }
982     pacemaker::constraint::base { 'neutron-l3-agent-to-metadata-agent-constraint':
983       constraint_type => "order",
984       first_resource => "${::neutron::params::l3_agent_service}-clone",
985       second_resource => "${::neutron::params::metadata_agent_service}-clone",
986       first_action => "start",
987       second_action => "start",
988       require => [Pacemaker::Resource::Service["${::neutron::params::l3_agent_service}"],
989                   Pacemaker::Resource::Service["${::neutron::params::metadata_agent_service}"]]
990     }
991     pacemaker::constraint::colocation { 'neutron-l3-agent-to-metadata-agent-colocation':
992       source => "${::neutron::params::metadata_agent_service}-clone",
993       target => "${::neutron::params::l3_agent_service}-clone",
994       score => "INFINITY",
995       require => [Pacemaker::Resource::Service["${::neutron::params::l3_agent_service}"],
996                   Pacemaker::Resource::Service["${::neutron::params::metadata_agent_service}"]]
997     }
998
999     # Nova
1000     pacemaker::resource::service { $::nova::params::api_service_name :
1001       clone_params    => "interleave=true",
1002       op_params       => "monitor start-delay=10s",
1003     }
1004     pacemaker::resource::service { $::nova::params::conductor_service_name :
1005       clone_params    => "interleave=true",
1006       op_params       => "monitor start-delay=10s",
1007     }
1008     pacemaker::resource::service { $::nova::params::consoleauth_service_name :
1009       clone_params    => "interleave=true",
1010       op_params       => "monitor start-delay=10s",
1011       require         => Pacemaker::Resource::Service[$::keystone::params::service_name],
1012     }
1013     pacemaker::resource::service { $::nova::params::vncproxy_service_name :
1014       clone_params    => "interleave=true",
1015       op_params       => "monitor start-delay=10s",
1016     }
1017     pacemaker::resource::service { $::nova::params::scheduler_service_name :
1018       clone_params    => "interleave=true",
1019       op_params       => "monitor start-delay=10s",
1020     }
1021
1022     pacemaker::constraint::base { 'keystone-then-nova-consoleauth-constraint':
1023       constraint_type => 'order',
1024       first_resource  => "${::keystone::params::service_name}-clone",
1025       second_resource => "${::nova::params::consoleauth_service_name}-clone",
1026       first_action    => 'start',
1027       second_action   => 'start',
1028       require         => [Pacemaker::Resource::Service[$::nova::params::consoleauth_service_name],
1029                           Pacemaker::Resource::Service[$::keystone::params::service_name]],
1030     }
1031     pacemaker::constraint::base { 'nova-consoleauth-then-nova-vncproxy-constraint':
1032       constraint_type => "order",
1033       first_resource  => "${::nova::params::consoleauth_service_name}-clone",
1034       second_resource => "${::nova::params::vncproxy_service_name}-clone",
1035       first_action    => "start",
1036       second_action   => "start",
1037       require => [Pacemaker::Resource::Service[$::nova::params::consoleauth_service_name],
1038                   Pacemaker::Resource::Service[$::nova::params::vncproxy_service_name]],
1039     }
1040     pacemaker::constraint::colocation { 'nova-vncproxy-with-nova-consoleauth-colocation':
1041       source => "${::nova::params::vncproxy_service_name}-clone",
1042       target => "${::nova::params::consoleauth_service_name}-clone",
1043       score => "INFINITY",
1044       require => [Pacemaker::Resource::Service[$::nova::params::consoleauth_service_name],
1045                   Pacemaker::Resource::Service[$::nova::params::vncproxy_service_name]],
1046     }
1047     # FIXME(gfidente): novncproxy will not start unless websockify is updated to 0.6
1048     # which is not the case for f20 nor f21; ucomment when it becomes available
1049     #pacemaker::constraint::base { 'nova-vncproxy-then-nova-api-constraint':
1050     #  constraint_type => "order",
1051     #  first_resource  => "${::nova::params::vncproxy_service_name}-clone",
1052     #  second_resource => "${::nova::params::api_service_name}-clone",
1053     #  first_action    => "start",
1054     #  second_action   => "start",
1055     #  require => [Pacemaker::Resource::Service[$::nova::params::vncproxy_service_name],
1056     #              Pacemaker::Resource::Service[$::nova::params::api_service_name]],
1057     #}
1058     #pacemaker::constraint::colocation { 'nova-api-with-nova-vncproxy-colocation':
1059     #  source => "${::nova::params::api_service_name}-clone",
1060     #  target => "${::nova::params::vncproxy_service_name}-clone",
1061     #  score => "INFINITY",
1062     #  require => [Pacemaker::Resource::Service[$::nova::params::vncproxy_service_name],
1063     #              Pacemaker::Resource::Service[$::nova::params::api_service_name]],
1064     #}
1065     pacemaker::constraint::base { 'nova-api-then-nova-scheduler-constraint':
1066       constraint_type => "order",
1067       first_resource  => "${::nova::params::api_service_name}-clone",
1068       second_resource => "${::nova::params::scheduler_service_name}-clone",
1069       first_action    => "start",
1070       second_action   => "start",
1071       require => [Pacemaker::Resource::Service[$::nova::params::api_service_name],
1072                   Pacemaker::Resource::Service[$::nova::params::scheduler_service_name]],
1073     }
1074     pacemaker::constraint::colocation { 'nova-scheduler-with-nova-api-colocation':
1075       source => "${::nova::params::scheduler_service_name}-clone",
1076       target => "${::nova::params::api_service_name}-clone",
1077       score => "INFINITY",
1078       require => [Pacemaker::Resource::Service[$::nova::params::api_service_name],
1079                   Pacemaker::Resource::Service[$::nova::params::scheduler_service_name]],
1080     }
1081     pacemaker::constraint::base { 'nova-scheduler-then-nova-conductor-constraint':
1082       constraint_type => "order",
1083       first_resource  => "${::nova::params::scheduler_service_name}-clone",
1084       second_resource => "${::nova::params::conductor_service_name}-clone",
1085       first_action    => "start",
1086       second_action   => "start",
1087       require => [Pacemaker::Resource::Service[$::nova::params::scheduler_service_name],
1088                   Pacemaker::Resource::Service[$::nova::params::conductor_service_name]],
1089     }
1090     pacemaker::constraint::colocation { 'nova-conductor-with-nova-scheduler-colocation':
1091       source => "${::nova::params::conductor_service_name}-clone",
1092       target => "${::nova::params::scheduler_service_name}-clone",
1093       score => "INFINITY",
1094       require => [Pacemaker::Resource::Service[$::nova::params::scheduler_service_name],
1095                   Pacemaker::Resource::Service[$::nova::params::conductor_service_name]],
1096     }
1097
1098     # Ceilometer
1099     pacemaker::resource::service { $::ceilometer::params::agent_central_service_name :
1100       clone_params => 'interleave=true',
1101       require      => [Pacemaker::Resource::Service[$::keystone::params::service_name],
1102                        Pacemaker::Resource::Service[$::mongodb::params::service_name]],
1103     }
1104     pacemaker::resource::service { $::ceilometer::params::collector_service_name :
1105       clone_params => 'interleave=true',
1106     }
1107     pacemaker::resource::service { $::ceilometer::params::api_service_name :
1108       clone_params => 'interleave=true',
1109     }
1110     pacemaker::resource::service { $::ceilometer::params::alarm_evaluator_service_name :
1111       clone_params => 'interleave=true',
1112     }
1113     pacemaker::resource::service { $::ceilometer::params::alarm_notifier_service_name :
1114       clone_params => 'interleave=true',
1115     }
1116     pacemaker::resource::service { $::ceilometer::params::agent_notification_service_name :
1117       clone_params => 'interleave=true',
1118     }
1119     pacemaker::resource::ocf { 'delay' :
1120       ocf_agent_name  => 'heartbeat:Delay',
1121       clone_params    => 'interleave=true',
1122       resource_params => 'startdelay=10',
1123     }
1124     pacemaker::constraint::base { 'keystone-then-ceilometer-central-constraint':
1125       constraint_type => 'order',
1126       first_resource  => "${::keystone::params::service_name}-clone",
1127       second_resource => "${::ceilometer::params::agent_central_service_name}-clone",
1128       first_action    => 'start',
1129       second_action   => 'start',
1130       require         => [Pacemaker::Resource::Service[$::ceilometer::params::agent_central_service_name],
1131                           Pacemaker::Resource::Service[$::keystone::params::service_name]],
1132     }
1133     pacemaker::constraint::base { 'ceilometer-central-then-ceilometer-collector-constraint':
1134       constraint_type => 'order',
1135       first_resource  => "${::ceilometer::params::agent_central_service_name}-clone",
1136       second_resource => "${::ceilometer::params::collector_service_name}-clone",
1137       first_action    => 'start',
1138       second_action   => 'start',
1139       require         => [Pacemaker::Resource::Service[$::ceilometer::params::agent_central_service_name],
1140                           Pacemaker::Resource::Service[$::ceilometer::params::collector_service_name]],
1141     }
1142     pacemaker::constraint::base { 'ceilometer-collector-then-ceilometer-api-constraint':
1143       constraint_type => 'order',
1144       first_resource  => "${::ceilometer::params::collector_service_name}-clone",
1145       second_resource => "${::ceilometer::params::api_service_name}-clone",
1146       first_action    => 'start',
1147       second_action   => 'start',
1148       require         => [Pacemaker::Resource::Service[$::ceilometer::params::collector_service_name],
1149                           Pacemaker::Resource::Service[$::ceilometer::params::api_service_name]],
1150     }
1151     pacemaker::constraint::colocation { 'ceilometer-api-with-ceilometer-collector-colocation':
1152       source  => "${::ceilometer::params::api_service_name}-clone",
1153       target  => "${::ceilometer::params::collector_service_name}-clone",
1154       score   => 'INFINITY',
1155       require => [Pacemaker::Resource::Service[$::ceilometer::params::api_service_name],
1156                   Pacemaker::Resource::Service[$::ceilometer::params::collector_service_name]],
1157     }
1158     pacemaker::constraint::base { 'ceilometer-api-then-ceilometer-delay-constraint':
1159       constraint_type => 'order',
1160       first_resource  => "${::ceilometer::params::api_service_name}-clone",
1161       second_resource => 'delay-clone',
1162       first_action    => 'start',
1163       second_action   => 'start',
1164       require         => [Pacemaker::Resource::Service[$::ceilometer::params::api_service_name],
1165                           Pacemaker::Resource::Ocf['delay']],
1166     }
1167     pacemaker::constraint::colocation { 'ceilometer-delay-with-ceilometer-api-colocation':
1168       source  => 'delay-clone',
1169       target  => "${::ceilometer::params::api_service_name}-clone",
1170       score   => 'INFINITY',
1171       require => [Pacemaker::Resource::Service[$::ceilometer::params::api_service_name],
1172                   Pacemaker::Resource::Ocf['delay']],
1173     }
1174     pacemaker::constraint::base { 'ceilometer-delay-then-ceilometer-alarm-evaluator-constraint':
1175       constraint_type => 'order',
1176       first_resource  => 'delay-clone',
1177       second_resource => "${::ceilometer::params::alarm_evaluator_service_name}-clone",
1178       first_action    => 'start',
1179       second_action   => 'start',
1180       require         => [Pacemaker::Resource::Service[$::ceilometer::params::alarm_evaluator_service_name],
1181                           Pacemaker::Resource::Ocf['delay']],
1182     }
1183     pacemaker::constraint::colocation { 'ceilometer-alarm-evaluator-with-ceilometer-delay-colocation':
1184       source  => "${::ceilometer::params::alarm_evaluator_service_name}-clone",
1185       target  => 'delay-clone',
1186       score   => 'INFINITY',
1187       require => [Pacemaker::Resource::Service[$::ceilometer::params::api_service_name],
1188                   Pacemaker::Resource::Ocf['delay']],
1189     }
1190     pacemaker::constraint::base { 'ceilometer-alarm-evaluator-then-ceilometer-alarm-notifier-constraint':
1191       constraint_type => 'order',
1192       first_resource  => "${::ceilometer::params::alarm_evaluator_service_name}-clone",
1193       second_resource => "${::ceilometer::params::alarm_notifier_service_name}-clone",
1194       first_action    => 'start',
1195       second_action   => 'start',
1196       require         => [Pacemaker::Resource::Service[$::ceilometer::params::alarm_evaluator_service_name],
1197                           Pacemaker::Resource::Service[$::ceilometer::params::alarm_notifier_service_name]],
1198     }
1199     pacemaker::constraint::colocation { 'ceilometer-alarm-notifier-with-ceilometer-alarm-evaluator-colocation':
1200       source  => "${::ceilometer::params::alarm_notifier_service_name}-clone",
1201       target  => "${::ceilometer::params::alarm_evaluator_service_name}-clone",
1202       score   => 'INFINITY',
1203       require => [Pacemaker::Resource::Service[$::ceilometer::params::alarm_evaluator_service_name],
1204                   Pacemaker::Resource::Service[$::ceilometer::params::alarm_notifier_service_name]],
1205     }
1206     pacemaker::constraint::base { 'ceilometer-alarm-notifier-then-ceilometer-notification-constraint':
1207       constraint_type => 'order',
1208       first_resource  => "${::ceilometer::params::alarm_notifier_service_name}-clone",
1209       second_resource => "${::ceilometer::params::agent_notification_service_name}-clone",
1210       first_action    => 'start',
1211       second_action   => 'start',
1212       require         => [Pacemaker::Resource::Service[$::ceilometer::params::agent_notification_service_name],
1213                           Pacemaker::Resource::Service[$::ceilometer::params::alarm_notifier_service_name]],
1214     }
1215     pacemaker::constraint::colocation { 'ceilometer-notification-with-ceilometer-alarm-notifier-colocation':
1216       source  => "${::ceilometer::params::agent_notification_service_name}-clone",
1217       target  => "${::ceilometer::params::alarm_notifier_service_name}-clone",
1218       score   => 'INFINITY',
1219       require => [Pacemaker::Resource::Service[$::ceilometer::params::agent_notification_service_name],
1220                   Pacemaker::Resource::Service[$::ceilometer::params::alarm_notifier_service_name]],
1221     }
1222     if downcase(hiera('ceilometer_backend')) == 'mongodb' {
1223       pacemaker::constraint::base { 'mongodb-then-ceilometer-central-constraint':
1224         constraint_type => 'order',
1225         first_resource  => "${::mongodb::params::service_name}-clone",
1226         second_resource => "${::ceilometer::params::agent_central_service_name}-clone",
1227         first_action    => 'start',
1228         second_action   => 'start',
1229         require         => [Pacemaker::Resource::Service[$::ceilometer::params::agent_central_service_name],
1230                             Pacemaker::Resource::Service[$::mongodb::params::service_name]],
1231       }
1232     }
1233     pacemaker::constraint::base { 'vip-redis-then-ceilometer-central':
1234       constraint_type => 'order',
1235       first_resource  => "ip-${redis_vip}",
1236       second_resource => "${::ceilometer::params::agent_central_service_name}-clone",
1237       first_action    => 'start',
1238       second_action   => 'start',
1239       require => [Pacemaker::Resource::Service[$::ceilometer::params::agent_central_service_name],
1240                   Pacemaker::Resource::Ip['vip-redis']],
1241     }
1242
1243     # Heat
1244     pacemaker::resource::service { $::heat::params::api_service_name :
1245       clone_params => 'interleave=true',
1246     }
1247     pacemaker::resource::service { $::heat::params::api_cloudwatch_service_name :
1248       clone_params => 'interleave=true',
1249     }
1250     pacemaker::resource::service { $::heat::params::api_cfn_service_name :
1251       clone_params => 'interleave=true',
1252     }
1253     pacemaker::resource::service { $::heat::params::engine_service_name :
1254       clone_params => 'interleave=true',
1255     }
1256     pacemaker::constraint::base { 'keystone-then-heat-api-constraint':
1257       constraint_type => 'order',
1258       first_resource  => "${::keystone::params::service_name}-clone",
1259       second_resource => "${::heat::params::api_service_name}-clone",
1260       first_action    => 'start',
1261       second_action   => 'start',
1262       require         => [Pacemaker::Resource::Service[$::heat::params::api_service_name],
1263                           Pacemaker::Resource::Service[$::keystone::params::service_name]],
1264     }
1265     pacemaker::constraint::base { 'heat-api-then-heat-api-cfn-constraint':
1266       constraint_type => 'order',
1267       first_resource  => "${::heat::params::api_service_name}-clone",
1268       second_resource => "${::heat::params::api_cfn_service_name}-clone",
1269       first_action    => 'start',
1270       second_action   => 'start',
1271       require => [Pacemaker::Resource::Service[$::heat::params::api_service_name],
1272                   Pacemaker::Resource::Service[$::heat::params::api_cfn_service_name]],
1273     }
1274     pacemaker::constraint::colocation { 'heat-api-cfn-with-heat-api-colocation':
1275       source  => "${::heat::params::api_cfn_service_name}-clone",
1276       target  => "${::heat::params::api_service_name}-clone",
1277       score   => 'INFINITY',
1278       require => [Pacemaker::Resource::Service[$::heat::params::api_cfn_service_name],
1279                   Pacemaker::Resource::Service[$::heat::params::api_service_name]],
1280     }
1281     pacemaker::constraint::base { 'heat-api-cfn-then-heat-api-cloudwatch-constraint':
1282       constraint_type => 'order',
1283       first_resource  => "${::heat::params::api_cfn_service_name}-clone",
1284       second_resource => "${::heat::params::api_cloudwatch_service_name}-clone",
1285       first_action    => 'start',
1286       second_action   => 'start',
1287       require => [Pacemaker::Resource::Service[$::heat::params::api_cloudwatch_service_name],
1288                   Pacemaker::Resource::Service[$::heat::params::api_cfn_service_name]],
1289     }
1290     pacemaker::constraint::colocation { 'heat-api-cloudwatch-with-heat-api-cfn-colocation':
1291       source  => "${::heat::params::api_cloudwatch_service_name}-clone",
1292       target  => "${::heat::params::api_cfn_service_name}-clone",
1293       score   => 'INFINITY',
1294       require => [Pacemaker::Resource::Service[$::heat::params::api_cfn_service_name],
1295                   Pacemaker::Resource::Service[$::heat::params::api_cloudwatch_service_name]],
1296     }
1297     pacemaker::constraint::base { 'heat-api-cloudwatch-then-heat-engine-constraint':
1298       constraint_type => 'order',
1299       first_resource  => "${::heat::params::api_cloudwatch_service_name}-clone",
1300       second_resource => "${::heat::params::engine_service_name}-clone",
1301       first_action    => 'start',
1302       second_action   => 'start',
1303       require => [Pacemaker::Resource::Service[$::heat::params::api_cloudwatch_service_name],
1304                   Pacemaker::Resource::Service[$::heat::params::engine_service_name]],
1305     }
1306     pacemaker::constraint::colocation { 'heat-engine-with-heat-api-cloudwatch-colocation':
1307       source  => "${::heat::params::engine_service_name}-clone",
1308       target  => "${::heat::params::api_cloudwatch_service_name}-clone",
1309       score   => 'INFINITY',
1310       require => [Pacemaker::Resource::Service[$::heat::params::api_cloudwatch_service_name],
1311                   Pacemaker::Resource::Service[$::heat::params::engine_service_name]],
1312     }
1313     pacemaker::constraint::base { 'ceilometer-notification-then-heat-api-constraint':
1314       constraint_type => 'order',
1315       first_resource  => "${::ceilometer::params::agent_notification_service_name}-clone",
1316       second_resource => "${::heat::params::api_service_name}-clone",
1317       first_action    => 'start',
1318       second_action   => 'start',
1319       require         => [Pacemaker::Resource::Service[$::heat::params::api_service_name],
1320                           Pacemaker::Resource::Service[$::ceilometer::params::agent_notification_service_name]],
1321     }
1322
1323     # Horizon
1324     pacemaker::resource::service { $::horizon::params::http_service:
1325         clone_params => "interleave=true",
1326     }
1327
1328
1329   }
1330
1331 } #END STEP 4