6bd8919f05700b03d09fa28ad5671a14c17192ee
[apex-tripleo-heat-templates.git] / puppet / manifests / overcloud_controller_pacemaker.pp
1 # Copyright 2015 Red Hat, Inc.
2 # All Rights Reserved.
3 #
4 # Licensed under the Apache License, Version 2.0 (the "License"); you may
5 # not use this file except in compliance with the License. You may obtain
6 # a copy of the License at
7 #
8 #     http://www.apache.org/licenses/LICENSE-2.0
9 #
10 # Unless required by applicable law or agreed to in writing, software
11 # distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
12 # WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
13 # License for the specific language governing permissions and limitations
14 # under the License.
15
16 Pcmk_resource <| |> {
17   tries     => 10,
18   try_sleep => 3,
19 }
20
21 if !str2bool(hiera('enable_package_install', 'false')) {
22   case $::osfamily {
23     'RedHat': {
24       Package { provider => 'norpm' } # provided by tripleo-puppet
25     }
26     default: {
27       warning('enable_package_install option not supported.')
28     }
29   }
30 }
31
32 if $::hostname == downcase(hiera('bootstrap_nodeid')) {
33   $pacemaker_master = true
34   $sync_db = true
35 } else {
36   $pacemaker_master = false
37   $sync_db = false
38 }
39
40 $enable_fencing = str2bool(hiera('enable_fencing', 'false')) and hiera('step') >= 5
41
42 # When to start and enable services which haven't been Pacemakerized
43 # FIXME: remove when we start all OpenStack services using Pacemaker
44 # (occurences of this variable will be gradually replaced with false)
45 $non_pcmk_start = hiera('step') >= 4
46
47 if hiera('step') >= 1 {
48
49   create_resources(sysctl::value, hiera('sysctl_settings'), {})
50
51   if count(hiera('ntp::servers')) > 0 {
52     include ::ntp
53   }
54
55   $controller_node_ips = split(hiera('controller_node_ips'), ',')
56   $controller_node_names = split(downcase(hiera('controller_node_names')), ',')
57   class { '::tripleo::loadbalancer' :
58     controller_hosts       => $controller_node_ips,
59     controller_hosts_names => $controller_node_names,
60     manage_vip             => false,
61     mysql_clustercheck     => true,
62     haproxy_service_manage => false,
63   }
64
65   $pacemaker_cluster_members = downcase(regsubst(hiera('controller_node_names'), ',', ' ', 'G'))
66   user { 'hacluster':
67    ensure => present,
68   } ->
69   class { '::pacemaker':
70     hacluster_pwd => hiera('hacluster_pwd'),
71   } ->
72   class { '::pacemaker::corosync':
73     cluster_members => $pacemaker_cluster_members,
74     setup_cluster   => $pacemaker_master,
75   }
76   class { '::pacemaker::stonith':
77     disable => !$enable_fencing,
78   }
79   if $enable_fencing {
80     include tripleo::fencing
81
82     # enable stonith after all fencing devices have been created
83     Class['tripleo::fencing'] -> Class['pacemaker::stonith']
84   }
85
86   # Only configure RabbitMQ in this step, don't start it yet to
87   # avoid races where non-master nodes attempt to start without
88   # config (eg. binding on 0.0.0.0)
89   # The module ignores erlang_cookie if cluster_config is false
90   class { '::rabbitmq':
91     service_manage          => false,
92     tcp_keepalive           => false,
93     config_kernel_variables => hiera('rabbitmq_kernel_variables'),
94     config_variables        => hiera('rabbitmq_config_variables'),
95     environment_variables   => hiera('rabbitmq_environment'),
96   } ->
97   file { '/var/lib/rabbitmq/.erlang.cookie':
98     ensure  => 'present',
99     owner   => 'rabbitmq',
100     group   => 'rabbitmq',
101     mode    => '0400',
102     content => hiera('rabbitmq::erlang_cookie'),
103     replace => true,
104   }
105
106   if downcase(hiera('ceilometer_backend')) == 'mongodb' {
107     include ::mongodb::globals
108     class { '::mongodb::server' :
109       service_manage => false,
110     }
111   }
112
113   # Memcached
114   class {'::memcached' :
115     service_manage => false,
116   }
117
118   # Redis
119   class { '::redis' :
120     service_manage => false,
121     notify_service => false,
122   }
123
124   # Galera
125   if str2bool(hiera('enable_galera', 'true')) {
126     $mysql_config_file = '/etc/my.cnf.d/galera.cnf'
127   } else {
128     $mysql_config_file = '/etc/my.cnf.d/server.cnf'
129   }
130   $galera_nodes = downcase(hiera('galera_node_names', $::hostname))
131   $galera_nodes_count = count(split($galera_nodes, ','))
132
133   $mysqld_options = {
134     'mysqld' => {
135       'skip-name-resolve'             => '1',
136       'binlog_format'                 => 'ROW',
137       'default-storage-engine'        => 'innodb',
138       'innodb_autoinc_lock_mode'      => '2',
139       'innodb_locks_unsafe_for_binlog'=> '1',
140       'query_cache_size'              => '0',
141       'query_cache_type'              => '0',
142       'bind-address'                  => hiera('mysql_bind_host'),
143       'max_connections'               => '1024',
144       'open_files_limit'              => '-1',
145       'wsrep_provider'                => '/usr/lib64/galera/libgalera_smm.so',
146       'wsrep_cluster_name'            => 'galera_cluster',
147       'wsrep_slave_threads'           => '1',
148       'wsrep_certify_nonPK'           => '1',
149       'wsrep_max_ws_rows'             => '131072',
150       'wsrep_max_ws_size'             => '1073741824',
151       'wsrep_debug'                   => '0',
152       'wsrep_convert_LOCK_to_trx'     => '0',
153       'wsrep_retry_autocommit'        => '1',
154       'wsrep_auto_increment_control'  => '1',
155       'wsrep_drupal_282555_workaround'=> '0',
156       'wsrep_causal_reads'            => '0',
157       'wsrep_notify_cmd'              => '',
158       'wsrep_sst_method'              => 'rsync',
159     }
160   }
161
162   class { '::mysql::server':
163     create_root_user   => false,
164     create_root_my_cnf => false,
165     config_file        => $mysql_config_file,
166     override_options   => $mysqld_options,
167     service_manage     => false,
168     service_enabled    => false,
169   }
170
171 }
172
173 if hiera('step') >= 2 {
174
175   # NOTE(gfidente): the following vars are needed on all nodes so they
176   # need to stay out of pacemaker_master conditional
177   $mongo_node_ips_with_port = suffix(hiera('mongo_node_ips'), ':27017')
178   $mongodb_replset = hiera('mongodb::server::replset')
179
180   if $pacemaker_master {
181
182     # FIXME: we should not have to access tripleo::loadbalancer class
183     # parameters here to configure pacemaker VIPs. The configuration
184     # of pacemaker VIPs could move into puppet-tripleo or we should
185     # make use of less specific hiera parameters here for the settings.
186     $control_vip = hiera('tripleo::loadbalancer::controller_virtual_ip')
187     pacemaker::resource::ip { 'control_vip':
188       ip_address => $control_vip,
189     }
190     $public_vip = hiera('tripleo::loadbalancer::public_virtual_ip')
191     pacemaker::resource::ip { 'public_vip':
192       ip_address => $public_vip,
193     }
194
195     $internal_api_vip = hiera('tripleo::loadbalancer::internal_api_virtual_ip')
196     if $internal_api_vip and $internal_api_vip != $control_vip {
197       pacemaker::resource::ip { 'internal_api_vip':
198         ip_address => $internal_api_vip,
199       }
200     }
201
202     $storage_vip = hiera('tripleo::loadbalancer::storage_virtual_ip')
203     if $storage_vip and $storage_vip != $control_vip {
204       pacemaker::resource::ip { 'storage_vip':
205         ip_address => $storage_vip,
206       }
207     }
208
209     $storage_mgmt_vip = hiera('tripleo::loadbalancer::storage_mgmt_virtual_ip')
210     if $storage_mgmt_vip and $storage_mgmt_vip != $control_vip {
211       pacemaker::resource::ip { 'storage_mgmt_vip':
212         ip_address => $storage_mgmt_vip,
213       }
214     }
215
216     pacemaker::resource::service { 'haproxy':
217       clone_params => true,
218     }
219     pacemaker::resource::service { $::memcached::params::service_name :
220       clone_params => true,
221       require      => Class['::memcached'],
222     }
223
224     pacemaker::resource::ocf { 'rabbitmq':
225       ocf_agent_name  => 'heartbeat:rabbitmq-cluster',
226       resource_params => 'set_policy=\'ha-all ^(?!amq\.).* {"ha-mode":"all"}\'',
227       clone_params    => 'ordered=true interleave=true',
228       require         => Class['::rabbitmq'],
229     }
230
231     if downcase(hiera('ceilometer_backend')) == 'mongodb' {
232       pacemaker::resource::service { $::mongodb::params::service_name :
233         op_params    => 'start timeout=120s',
234         clone_params => true,
235         require      => Class['::mongodb::server'],
236       }
237       # NOTE (spredzy) : The replset can only be run
238       # once all the nodes have joined the cluster.
239       mongodb_conn_validator { $mongo_node_ips_with_port :
240         timeout => '600',
241         require => Pacemaker::Resource::Service[$::mongodb::params::service_name],
242         before  => Mongodb_replset[$mongodb_replset],
243       }
244       mongodb_replset { $mongodb_replset :
245         members => $mongo_node_ips_with_port,
246       }
247     }
248
249     pacemaker::resource::ocf { 'galera' :
250       ocf_agent_name  => 'heartbeat:galera',
251       op_params       => 'promote timeout=300s on-fail=block',
252       master_params   => '',
253       meta_params     => "master-max=${galera_nodes_count} ordered=true",
254       resource_params => "additional_parameters='--open-files-limit=16384' enable_creation=true wsrep_cluster_address='gcomm://${galera_nodes}'",
255       require         => Class['::mysql::server'],
256       before          => Exec['galera-ready'],
257     }
258
259     pacemaker::resource::ocf { 'redis':
260       ocf_agent_name  => 'heartbeat:redis',
261       master_params   => '',
262       meta_params     => 'notify=true ordered=true interleave=true',
263       resource_params => 'wait_last_known_master=true',
264       require         => Class['::redis'],
265     }
266     $redis_vip = hiera('redis_vip')
267     if $redis_vip and $redis_vip != $control_vip {
268         pacemaker::resource::ip { 'vip-redis':
269           ip_address => $redis_vip,
270         }
271     }
272
273   }
274
275   exec { 'galera-ready' :
276     command     => '/usr/bin/clustercheck >/dev/null',
277     timeout     => 30,
278     tries       => 180,
279     try_sleep   => 10,
280     environment => ["AVAILABLE_WHEN_READONLY=0"],
281     require     => File['/etc/sysconfig/clustercheck'],
282   }
283
284   file { '/etc/sysconfig/clustercheck' :
285     ensure  => file,
286     content => "MYSQL_USERNAME=root\n
287 MYSQL_PASSWORD=''\n
288 MYSQL_HOST=localhost\n",
289   }
290
291   xinetd::service { 'galera-monitor' :
292     port           => '9200',
293     server         => '/usr/bin/clustercheck',
294     per_source     => 'UNLIMITED',
295     log_on_success => '',
296     log_on_failure => 'HOST',
297     flags          => 'REUSE',
298     service_type   => 'UNLISTED',
299     user           => 'root',
300     group          => 'root',
301     require        => File['/etc/sysconfig/clustercheck'],
302   }
303
304   # Create all the database schemas
305   # Example DSN format: mysql://user:password@host/dbname
306   if $sync_db {
307     $allowed_hosts = ['%',hiera('mysql_bind_host')]
308     $keystone_dsn = split(hiera('keystone::database_connection'), '[@:/?]')
309     class { 'keystone::db::mysql':
310       user          => $keystone_dsn[3],
311       password      => $keystone_dsn[4],
312       host          => $keystone_dsn[5],
313       dbname        => $keystone_dsn[6],
314       allowed_hosts => $allowed_hosts,
315       require       => Exec['galera-ready'],
316     }
317     $glance_dsn = split(hiera('glance::api::database_connection'), '[@:/?]')
318     class { 'glance::db::mysql':
319       user          => $glance_dsn[3],
320       password      => $glance_dsn[4],
321       host          => $glance_dsn[5],
322       dbname        => $glance_dsn[6],
323       allowed_hosts => $allowed_hosts,
324       require       => Exec['galera-ready'],
325     }
326     $nova_dsn = split(hiera('nova::database_connection'), '[@:/?]')
327     class { 'nova::db::mysql':
328       user          => $nova_dsn[3],
329       password      => $nova_dsn[4],
330       host          => $nova_dsn[5],
331       dbname        => $nova_dsn[6],
332       allowed_hosts => $allowed_hosts,
333       require       => Exec['galera-ready'],
334     }
335     $neutron_dsn = split(hiera('neutron::server::database_connection'), '[@:/?]')
336     class { 'neutron::db::mysql':
337       user          => $neutron_dsn[3],
338       password      => $neutron_dsn[4],
339       host          => $neutron_dsn[5],
340       dbname        => $neutron_dsn[6],
341       allowed_hosts => $allowed_hosts,
342       require       => Exec['galera-ready'],
343     }
344     $cinder_dsn = split(hiera('cinder::database_connection'), '[@:/?]')
345     class { 'cinder::db::mysql':
346       user          => $cinder_dsn[3],
347       password      => $cinder_dsn[4],
348       host          => $cinder_dsn[5],
349       dbname        => $cinder_dsn[6],
350       allowed_hosts => $allowed_hosts,
351       require       => Exec['galera-ready'],
352     }
353     $heat_dsn = split(hiera('heat::database_connection'), '[@:/?]')
354     class { 'heat::db::mysql':
355       user          => $heat_dsn[3],
356       password      => $heat_dsn[4],
357       host          => $heat_dsn[5],
358       dbname        => $heat_dsn[6],
359       allowed_hosts => $allowed_hosts,
360       require       => Exec['galera-ready'],
361     }
362     if downcase(hiera('ceilometer_backend')) == 'mysql' {
363       $ceilometer_dsn = split(hiera('ceilometer_mysql_conn_string'), '[@:/?]')
364       class { 'ceilometer::db::mysql':
365         user          => $ceilometer_dsn[3],
366         password      => $ceilometer_dsn[4],
367         host          => $ceilometer_dsn[5],
368         dbname        => $ceilometer_dsn[6],
369         allowed_hosts => $allowed_hosts,
370         require       => Exec['galera-ready'],
371       }
372     }
373   }
374
375   # pre-install swift here so we can build rings
376   include ::swift
377
378   # Ceph
379   $cinder_enable_rbd_backend = hiera('cinder_enable_rbd_backend', false)
380   $enable_ceph = $cinder_enable_rbd_backend
381
382   if $enable_ceph {
383     class { 'ceph::profile::params':
384       mon_initial_members => downcase(hiera('ceph_mon_initial_members'))
385     }
386     include ::ceph::profile::mon
387   }
388
389   if str2bool(hiera('enable_ceph_storage', 'false')) {
390     include ::ceph::profile::client
391     include ::ceph::profile::osd
392   }
393
394
395 } #END STEP 2
396
397 if hiera('step') >= 3 {
398
399   class { '::keystone':
400     sync_db => $sync_db,
401     manage_service => false,
402     enabled => false,
403   }
404
405   #TODO: need a cleanup-keystone-tokens.sh solution here
406   keystone_config {
407     'ec2/driver': value => 'keystone.contrib.ec2.backends.sql.Ec2';
408   }
409   file { [ '/etc/keystone/ssl', '/etc/keystone/ssl/certs', '/etc/keystone/ssl/private' ]:
410     ensure  => 'directory',
411     owner   => 'keystone',
412     group   => 'keystone',
413     require => Package['keystone'],
414   }
415   file { '/etc/keystone/ssl/certs/signing_cert.pem':
416     content => hiera('keystone_signing_certificate'),
417     owner   => 'keystone',
418     group   => 'keystone',
419     notify  => Service['keystone'],
420     require => File['/etc/keystone/ssl/certs'],
421   }
422   file { '/etc/keystone/ssl/private/signing_key.pem':
423     content => hiera('keystone_signing_key'),
424     owner   => 'keystone',
425     group   => 'keystone',
426     notify  => Service['keystone'],
427     require => File['/etc/keystone/ssl/private'],
428   }
429   file { '/etc/keystone/ssl/certs/ca.pem':
430     content => hiera('keystone_ca_certificate'),
431     owner   => 'keystone',
432     group   => 'keystone',
433     notify  => Service['keystone'],
434     require => File['/etc/keystone/ssl/certs'],
435   }
436
437   $glance_backend = downcase(hiera('glance_backend', 'swift'))
438   case $glance_backend {
439       swift: { $glance_store = 'glance.store.swift.Store' }
440       file: { $glance_store = 'glance.store.filesystem.Store' }
441       rbd: { $glance_store = 'glance.store.rbd.Store' }
442       default: { fail('Unrecognized glance_backend parameter.') }
443   }
444
445   # TODO: notifications, scrubber, etc.
446   include ::glance
447   class { 'glance::api':
448     known_stores => [$glance_store],
449     manage_service => false,
450     enabled => false,
451   }
452   class { '::glance::registry' :
453     sync_db => $sync_db,
454     manage_service => false,
455     enabled => false,
456   }
457   include join(['::glance::backend::', $glance_backend])
458
459   include ::nova
460
461   class { '::nova::api' :
462     sync_db => $sync_db,
463     manage_service => false,
464     enabled => false,
465   }
466   class { '::nova::cert' :
467     manage_service => false,
468     enabled => false,
469   }
470   class { '::nova::conductor' :
471     manage_service => false,
472     enabled => false,
473   }
474   class { '::nova::consoleauth' :
475     manage_service => false,
476     enabled => false,
477   }
478   class { '::nova::vncproxy' :
479     manage_service => false,
480     enabled => false,
481   }
482   class { '::nova::scheduler' :
483     manage_service => false,
484     enabled => false,
485   }
486   include ::nova::network::neutron
487
488   # Neutron class definitions
489   include ::neutron
490   class { '::neutron::server' :
491     sync_db => $sync_db,
492     manage_service => false,
493     enabled => false,
494   }
495   class { '::neutron::agents::dhcp' :
496     manage_service => false,
497     enabled => false,
498   }
499   class { '::neutron::agents::l3' :
500     manage_service => false,
501     enabled => false,
502   }
503   class { 'neutron::agents::metadata':
504     manage_service => false,
505     enabled => false,
506   }
507   file { '/etc/neutron/dnsmasq-neutron.conf':
508     content => hiera('neutron_dnsmasq_options'),
509     owner   => 'neutron',
510     group   => 'neutron',
511     notify  => Service['neutron-dhcp-service'],
512     require => Package['neutron'],
513   }
514   class { 'neutron::plugins::ml2':
515     flat_networks   => split(hiera('neutron_flat_networks'), ','),
516     tenant_network_types => [hiera('neutron_tenant_network_type')],
517   }
518   class { 'neutron::agents::ml2::ovs':
519     # manage_service   => false # not implemented
520     enabled          => false,
521     bridge_mappings  => split(hiera('neutron_bridge_mappings'), ','),
522     tunnel_types     => split(hiera('neutron_tunnel_types'), ','),
523   }
524
525   include ::cinder
526   class { '::cinder::api':
527     sync_db => $sync_db,
528     manage_service => false,
529     enabled => false,
530   }
531   class { '::cinder::scheduler' :
532     manage_service => false,
533     enabled => false,
534   }
535   class { '::cinder::volume' :
536     manage_service => false,
537     enabled => false,
538   }
539   include ::cinder::glance
540   class {'cinder::setup_test_volume':
541     size => join([hiera('cinder_lvm_loop_device_size'), 'M']),
542   }
543
544   $cinder_enable_iscsi = hiera('cinder_enable_iscsi_backend', true)
545   if $cinder_enable_iscsi {
546     $cinder_iscsi_backend = 'tripleo_iscsi'
547
548     cinder::backend::iscsi { $cinder_iscsi_backend :
549       iscsi_ip_address => hiera('cinder_iscsi_ip_address'),
550       iscsi_helper     => hiera('cinder_iscsi_helper'),
551     }
552   }
553
554   if $enable_ceph {
555
556     Ceph_pool {
557       pg_num  => hiera('ceph::profile::params::osd_pool_default_pg_num'),
558       pgp_num => hiera('ceph::profile::params::osd_pool_default_pgp_num'),
559       size    => hiera('ceph::profile::params::osd_pool_default_size'),
560     }
561
562     $ceph_pools = hiera('ceph_pools')
563     ceph::pool { $ceph_pools : }
564   }
565
566   if $cinder_enable_rbd_backend {
567     $cinder_rbd_backend = 'tripleo_ceph'
568
569     cinder_config {
570       "${cinder_rbd_backend}/host": value => 'hostgroup';
571     }
572
573     cinder::backend::rbd { $cinder_rbd_backend :
574       rbd_pool        => 'volumes',
575       rbd_user        => 'openstack',
576       rbd_secret_uuid => hiera('ceph::profile::params::fsid'),
577       require         => Ceph::Pool['volumes'],
578     }
579   }
580
581   if hiera('cinder_enable_netapp_backend', false) {
582     $cinder_netapp_backend = hiera('cinder::backend::netapp::title')
583
584     cinder_config {
585       "${cinder_netapp_backend}/host": value => 'hostgroup';
586     }
587
588     if hiera('cinder_netapp_nfs_shares', undef) {
589       $cinder_netapp_nfs_shares = split(hiera('cinder_netapp_nfs_shares', undef), ',')
590     }
591
592     cinder::backend::netapp { $cinder_netapp_backend :
593       nfs_shares => $cinder_netapp_nfs_shares,
594     }
595   }
596
597   $cinder_enabled_backends = delete_undef_values([$cinder_iscsi_backend, $cinder_rbd_backend, $cinder_netapp_backend])
598   class { '::cinder::backends' :
599     enabled_backends => $cinder_enabled_backends,
600   }
601
602   # swift proxy
603   class { '::swift::proxy' :
604     manage_service => $non_pcmk_start,
605     enabled => $non_pcmk_start,
606   }
607   include ::swift::proxy::proxy_logging
608   include ::swift::proxy::healthcheck
609   include ::swift::proxy::cache
610   include ::swift::proxy::keystone
611   include ::swift::proxy::authtoken
612   include ::swift::proxy::staticweb
613   include ::swift::proxy::ceilometer
614   include ::swift::proxy::ratelimit
615   include ::swift::proxy::catch_errors
616   include ::swift::proxy::tempurl
617   include ::swift::proxy::formpost
618
619   # swift storage
620   if str2bool(hiera('enable_swift_storage', 'true')) {
621     class {'::swift::storage::all':
622       mount_check => str2bool(hiera('swift_mount_check'))
623     }
624     class {'::swift::storage::account':
625       manage_service => $non_pcmk_start,
626       enabled => $non_pcmk_start,
627     }
628     class {'::swift::storage::container':
629       manage_service => $non_pcmk_start,
630       enabled => $non_pcmk_start,
631     }
632     class {'::swift::storage::object':
633       manage_service => $non_pcmk_start,
634       enabled => $non_pcmk_start,
635     }
636     if(!defined(File['/srv/node'])) {
637       file { '/srv/node':
638         ensure  => directory,
639         owner   => 'swift',
640         group   => 'swift',
641         require => Package['openstack-swift'],
642       }
643     }
644     $swift_components = ['account', 'container', 'object']
645     swift::storage::filter::recon { $swift_components : }
646     swift::storage::filter::healthcheck { $swift_components : }
647   }
648
649   # Ceilometer
650   $ceilometer_backend = downcase(hiera('ceilometer_backend'))
651   case $ceilometer_backend {
652     /mysql/ : {
653       $ceilometer_database_connection = hiera('ceilometer_mysql_conn_string')
654     }
655     default : {
656       $mongo_node_string = join($mongo_node_ips_with_port, ',')
657       $ceilometer_database_connection = "mongodb://${mongo_node_string}/ceilometer?replicaSet=${mongodb_replset}"
658     }
659   }
660   include ::ceilometer
661   class { '::ceilometer::api' :
662     manage_service => false,
663     enabled => false,
664   }
665   class { '::ceilometer::agent::notification' :
666     manage_service => false,
667     enabled => false,
668   }
669   class { '::ceilometer::agent::central' :
670     manage_service => false,
671     enabled => false,
672   }
673   class { '::ceilometer::alarm::notifier' :
674     manage_service => false,
675     enabled => false,
676   }
677   class { '::ceilometer::alarm::evaluator' :
678     manage_service => false,
679     enabled => false,
680   }
681   class { '::ceilometer::collector' :
682     manage_service => false,
683     enabled => false,
684   }
685   include ::ceilometer::expirer
686   class { '::ceilometer::db' :
687     database_connection => $ceilometer_database_connection,
688     sync_db             => $sync_db,
689   }
690   include ceilometer::agent::auth
691
692   Cron <| title == 'ceilometer-expirer' |> { command => "sleep $((\$(od -A n -t d -N 3 /dev/urandom) % 86400)) && ${::ceilometer::params::expirer_command}" }
693
694   # Heat
695   class { '::heat' :
696     sync_db => $sync_db,
697   }
698   class { '::heat::api' :
699     manage_service => false,
700     enabled => false,
701   }
702   class { '::heat::api_cfn' :
703     manage_service => false,
704     enabled => false,
705   }
706   class { '::heat::api_cloudwatch' :
707     manage_service => false,
708     enabled => false,
709   }
710   class { '::heat::engine' :
711     manage_service => false,
712     enabled => false,
713   }
714
715   # httpd/apache and horizon
716   # NOTE(gfidente): server-status can be consumed by the pacemaker resource agent
717   include ::apache
718   include ::apache::mod::status
719   $vhost_params = {
720     add_listen => false,
721     priority   => 10,
722   }
723   class { 'horizon':
724     cache_server_ip    => hiera('memcache_node_ips', '127.0.0.1'),
725     vhost_extra_params => $vhost_params,
726     server_aliases     => $::hostname,
727   }
728
729   $snmpd_user = hiera('snmpd_readonly_user_name')
730   snmp::snmpv3_user { $snmpd_user:
731     authtype => 'MD5',
732     authpass => hiera('snmpd_readonly_user_password'),
733   }
734   class { 'snmp':
735     agentaddress => ['udp:161','udp6:[::1]:161'],
736     snmpd_config => [ join(['rouser ', hiera('snmpd_readonly_user_name')]), 'proc  cron', 'includeAllDisks  10%', 'master agentx', 'trapsink localhost public', 'iquerySecName internalUser', 'rouser internalUser', 'defaultMonitors yes', 'linkUpDownNotifications yes' ],
737   }
738
739 } #END STEP 3
740
741 if hiera('step') >= 4 {
742   if $pacemaker_master {
743
744     # Keystone
745     pacemaker::resource::service { $::keystone::params::service_name :
746       clone_params => "interleave=true",
747     }
748
749     # Cinder
750     pacemaker::resource::service { $::cinder::params::api_service :
751       clone_params => "interleave=true",
752       require      => Pacemaker::Resource::Service[$::keystone::params::service_name],
753     }
754     pacemaker::resource::service { $::cinder::params::scheduler_service :
755       clone_params => "interleave=true",
756     }
757     pacemaker::resource::service { $::cinder::params::volume_service : }
758
759     pacemaker::constraint::base { 'keystone-then-cinder-api-constraint':
760       constraint_type => 'order',
761       first_resource  => "${::keystone::params::service_name}-clone",
762       second_resource => "${::cinder::params::api_service}-clone",
763       first_action    => 'start',
764       second_action   => 'start',
765       require         => [Pacemaker::Resource::Service[$::cinder::params::api_service],
766                           Pacemaker::Resource::Service[$::keystone::params::service_name]],
767     }
768     pacemaker::constraint::base { 'cinder-api-then-cinder-scheduler-constraint':
769       constraint_type => "order",
770       first_resource => "${::cinder::params::api_service}-clone",
771       second_resource => "${::cinder::params::scheduler_service}-clone",
772       first_action => "start",
773       second_action => "start",
774       require => [Pacemaker::Resource::Service[$::cinder::params::api_service],
775                   Pacemaker::Resource::Service[$::cinder::params::scheduler_service]],
776     }
777     pacemaker::constraint::colocation { 'cinder-scheduler-with-cinder-api-colocation':
778       source => "${::cinder::params::scheduler_service}-clone",
779       target => "${::cinder::params::api_service}-clone",
780       score => "INFINITY",
781       require => [Pacemaker::Resource::Service[$::cinder::params::api_service],
782                   Pacemaker::Resource::Service[$::cinder::params::scheduler_service]],
783     }
784     pacemaker::constraint::base { 'cinder-scheduler-then-cinder-volume-constraint':
785       constraint_type => "order",
786       first_resource => "${::cinder::params::scheduler_service}-clone",
787       second_resource => "${::cinder::params::volume_service}",
788       first_action => "start",
789       second_action => "start",
790       require => [Pacemaker::Resource::Service[$::cinder::params::scheduler_service],
791                   Pacemaker::Resource::Service[$::cinder::params::volume_service]],
792     }
793     pacemaker::constraint::colocation { 'cinder-volume-with-cinder-scheduler-colocation':
794       source => "${::cinder::params::volume_service}",
795       target => "${::cinder::params::scheduler_service}-clone",
796       score => "INFINITY",
797       require => [Pacemaker::Resource::Service[$::cinder::params::scheduler_service],
798                   Pacemaker::Resource::Service[$::cinder::params::volume_service]],
799     }
800
801     # Glance
802     pacemaker::resource::service { $::glance::params::registry_service_name :
803       clone_params => "interleave=true",
804       require      => Pacemaker::Resource::Service[$::keystone::params::service_name],
805     }
806     pacemaker::resource::service { $::glance::params::api_service_name :
807       clone_params => "interleave=true",
808     }
809
810     pacemaker::constraint::base { 'keystone-then-glance-registry-constraint':
811       constraint_type => 'order',
812       first_resource  => "${::keystone::params::service_name}-clone",
813       second_resource => "${::glance::params::registry_service_name}-clone",
814       first_action    => 'start',
815       second_action   => 'start',
816       require         => [Pacemaker::Resource::Service[$::glance::params::registry_service_name],
817                           Pacemaker::Resource::Service[$::keystone::params::service_name]],
818     }
819     pacemaker::constraint::base { 'glance-registry-then-glance-api-constraint':
820       constraint_type => "order",
821       first_resource  => "${::glance::params::registry_service_name}-clone",
822       second_resource => "${::glance::params::api_service_name}-clone",
823       first_action    => "start",
824       second_action   => "start",
825       require => [Pacemaker::Resource::Service[$::glance::params::registry_service_name],
826                   Pacemaker::Resource::Service[$::glance::params::api_service_name]],
827     }
828     pacemaker::constraint::colocation { 'glance-api-with-glance-registry-colocation':
829       source  => "${::glance::params::api_service_name}-clone",
830       target  => "${::glance::params::registry_service_name}-clone",
831       score   => "INFINITY",
832       require => [Pacemaker::Resource::Service[$::glance::params::registry_service_name],
833                   Pacemaker::Resource::Service[$::glance::params::api_service_name]],
834     }
835
836     # Neutron
837     # NOTE(gfidente): Neutron will try to populate the database with some data
838     # as soon as neutron-server is started; to avoid races we want to make this
839     # happen only on one node, before normal Pacemaker initialization
840     # https://bugzilla.redhat.com/show_bug.cgi?id=1233061
841     exec { 'neutron-server-start-wait-stop' :
842       command   => "systemctl start neutron-server && \
843                     sleep 5s && \
844                     systemctl stop neutron-server",
845       path      => ["/usr/bin", "/usr/sbin"],
846     } ->
847     pacemaker::resource::service { $::neutron::params::server_service:
848       op_params => "start timeout=90",
849       clone_params   => "interleave=true",
850       require => Pacemaker::Resource::Service[$::keystone::params::service_name]
851     }
852     pacemaker::resource::service { $::neutron::params::l3_agent_service:
853       clone_params   => "interleave=true",
854     }
855     pacemaker::resource::service { $::neutron::params::dhcp_agent_service:
856       clone_params   => "interleave=true",
857     }
858     pacemaker::resource::service { $::neutron::params::ovs_agent_service:
859       clone_params => "interleave=true",
860     }
861     pacemaker::resource::service { $::neutron::params::metadata_agent_service:
862       clone_params => "interleave=true",
863     }
864     pacemaker::resource::ocf { $::neutron::params::ovs_cleanup_service:
865       ocf_agent_name => "neutron:OVSCleanup",
866       clone_params => "interleave=true",
867     }
868     pacemaker::resource::ocf { 'neutron-netns-cleanup':
869       ocf_agent_name => "neutron:NetnsCleanup",
870       clone_params => "interleave=true",
871     }
872     pacemaker::resource::ocf { 'neutron-scale':
873       ocf_agent_name => "neutron:NeutronScale",
874       clone_params => "globally-unique=true clone-max=3 interleave=true",
875     }
876     pacemaker::constraint::base { 'keystone-to-neutron-server-constraint':
877       constraint_type => "order",
878       first_resource => "${::keystone::params::service_name}-clone",
879       second_resource => "${::neutron::params::server_service}-clone",
880       first_action => "start",
881       second_action => "start",
882       require => [Pacemaker::Resource::Service[$::keystone::params::service_name],
883                   Pacemaker::Resource::Service[$::neutron::params::server_service]],
884     }
885     pacemaker::constraint::base { 'neutron-server-to-neutron-scale-constraint':
886       constraint_type => "order",
887       first_resource => "${::neutron::params::server_service}-clone",
888       second_resource => "neutron-scale-clone",
889       first_action => "start",
890       second_action => "start",
891       require => [Pacemaker::Resource::Service[$::neutron::params::server_service],
892                   Pacemaker::Resource::Ocf['neutron-scale']],
893     }
894     pacemaker::constraint::base { 'neutron-scale-to-ovs-cleanup-constraint':
895       constraint_type => "order",
896       first_resource => "neutron-scale-clone",
897       second_resource => "${::neutron::params::ovs_cleanup_service}-clone",
898       first_action => "start",
899       second_action => "start",
900       require => [Pacemaker::Resource::Ocf['neutron-scale'],
901                   Pacemaker::Resource::Ocf["${::neutron::params::ovs_cleanup_service}"]],
902     }
903     pacemaker::constraint::colocation { 'neutron-scale-to-ovs-cleanup-colocation':
904       source => "${::neutron::params::ovs_cleanup_service}-clone",
905       target => "neutron-scale-clone",
906       score => "INFINITY",
907       require => [Pacemaker::Resource::Ocf['neutron-scale'],
908                   Pacemaker::Resource::Ocf["${::neutron::params::ovs_cleanup_service}"]],
909     }
910     pacemaker::constraint::base { 'neutron-ovs-cleanup-to-netns-cleanup-constraint':
911       constraint_type => "order",
912       first_resource => "${::neutron::params::ovs_cleanup_service}-clone",
913       second_resource => "neutron-netns-cleanup-clone",
914       first_action => "start",
915       second_action => "start",
916       require => [Pacemaker::Resource::Ocf["${::neutron::params::ovs_cleanup_service}"],
917                   Pacemaker::Resource::Ocf['neutron-netns-cleanup']],
918     }
919     pacemaker::constraint::colocation { 'neutron-ovs-cleanup-to-netns-cleanup-colocation':
920       source => "neutron-netns-cleanup-clone",
921       target => "${::neutron::params::ovs_cleanup_service}-clone",
922       score => "INFINITY",
923       require => [Pacemaker::Resource::Ocf["${::neutron::params::ovs_cleanup_service}"],
924                   Pacemaker::Resource::Ocf['neutron-netns-cleanup']],
925     }
926     pacemaker::constraint::base { 'neutron-netns-cleanup-to-openvswitch-agent-constraint':
927       constraint_type => "order",
928       first_resource => "neutron-netns-cleanup-clone",
929       second_resource => "${::neutron::params::ovs_agent_service}-clone",
930       first_action => "start",
931       second_action => "start",
932       require => [Pacemaker::Resource::Ocf["neutron-netns-cleanup"],
933                   Pacemaker::Resource::Service["${::neutron::params::ovs_agent_service}"]],
934     }
935     pacemaker::constraint::colocation { 'neutron-netns-cleanup-to-openvswitch-agent-colocation':
936       source => "${::neutron::params::ovs_agent_service}-clone",
937       target => "neutron-netns-cleanup-clone",
938       score => "INFINITY",
939       require => [Pacemaker::Resource::Ocf["neutron-netns-cleanup"],
940                   Pacemaker::Resource::Service["${::neutron::params::ovs_agent_service}"]],
941     }
942     pacemaker::constraint::base { 'neutron-openvswitch-agent-to-dhcp-agent-constraint':
943       constraint_type => "order",
944       first_resource => "${::neutron::params::ovs_agent_service}-clone",
945       second_resource => "${::neutron::params::dhcp_agent_service}-clone",
946       first_action => "start",
947       second_action => "start",
948       require => [Pacemaker::Resource::Service["${::neutron::params::ovs_agent_service}"],
949                   Pacemaker::Resource::Service["${::neutron::params::dhcp_agent_service}"]],
950
951     }
952     pacemaker::constraint::colocation { 'neutron-openvswitch-agent-to-dhcp-agent-colocation':
953       source => "${::neutron::params::dhcp_agent_service}-clone",
954       target => "${::neutron::params::ovs_agent_service}-clone",
955       score => "INFINITY",
956       require => [Pacemaker::Resource::Service["${::neutron::params::ovs_agent_service}"],
957                   Pacemaker::Resource::Service["${::neutron::params::dhcp_agent_service}"]],
958     }
959     pacemaker::constraint::base { 'neutron-dhcp-agent-to-l3-agent-constraint':
960       constraint_type => "order",
961       first_resource => "${::neutron::params::dhcp_agent_service}-clone",
962       second_resource => "${::neutron::params::l3_agent_service}-clone",
963       first_action => "start",
964       second_action => "start",
965       require => [Pacemaker::Resource::Service["${::neutron::params::dhcp_agent_service}"],
966                   Pacemaker::Resource::Service["${::neutron::params::l3_agent_service}"]]
967     }
968     pacemaker::constraint::colocation { 'neutron-dhcp-agent-to-l3-agent-colocation':
969       source => "${::neutron::params::l3_agent_service}-clone",
970       target => "${::neutron::params::dhcp_agent_service}-clone",
971       score => "INFINITY",
972       require => [Pacemaker::Resource::Service["${::neutron::params::dhcp_agent_service}"],
973                   Pacemaker::Resource::Service["${::neutron::params::l3_agent_service}"]]
974     }
975     pacemaker::constraint::base { 'neutron-l3-agent-to-metadata-agent-constraint':
976       constraint_type => "order",
977       first_resource => "${::neutron::params::l3_agent_service}-clone",
978       second_resource => "${::neutron::params::metadata_agent_service}-clone",
979       first_action => "start",
980       second_action => "start",
981       require => [Pacemaker::Resource::Service["${::neutron::params::l3_agent_service}"],
982                   Pacemaker::Resource::Service["${::neutron::params::metadata_agent_service}"]]
983     }
984     pacemaker::constraint::colocation { 'neutron-l3-agent-to-metadata-agent-colocation':
985       source => "${::neutron::params::metadata_agent_service}-clone",
986       target => "${::neutron::params::l3_agent_service}-clone",
987       score => "INFINITY",
988       require => [Pacemaker::Resource::Service["${::neutron::params::l3_agent_service}"],
989                   Pacemaker::Resource::Service["${::neutron::params::metadata_agent_service}"]]
990     }
991
992     # Nova
993     pacemaker::resource::service { $::nova::params::api_service_name :
994       clone_params    => "interleave=true",
995       op_params       => "monitor start-delay=10s",
996     }
997     pacemaker::resource::service { $::nova::params::conductor_service_name :
998       clone_params    => "interleave=true",
999       op_params       => "monitor start-delay=10s",
1000     }
1001     pacemaker::resource::service { $::nova::params::consoleauth_service_name :
1002       clone_params    => "interleave=true",
1003       op_params       => "monitor start-delay=10s",
1004       require         => Pacemaker::Resource::Service[$::keystone::params::service_name],
1005     }
1006     pacemaker::resource::service { $::nova::params::vncproxy_service_name :
1007       clone_params    => "interleave=true",
1008       op_params       => "monitor start-delay=10s",
1009     }
1010     pacemaker::resource::service { $::nova::params::scheduler_service_name :
1011       clone_params    => "interleave=true",
1012       op_params       => "monitor start-delay=10s",
1013     }
1014
1015     pacemaker::constraint::base { 'keystone-then-nova-consoleauth-constraint':
1016       constraint_type => 'order',
1017       first_resource  => "${::keystone::params::service_name}-clone",
1018       second_resource => "${::nova::params::consoleauth_service_name}-clone",
1019       first_action    => 'start',
1020       second_action   => 'start',
1021       require         => [Pacemaker::Resource::Service[$::nova::params::consoleauth_service_name],
1022                           Pacemaker::Resource::Service[$::keystone::params::service_name]],
1023     }
1024     pacemaker::constraint::base { 'nova-consoleauth-then-nova-vncproxy-constraint':
1025       constraint_type => "order",
1026       first_resource  => "${::nova::params::consoleauth_service_name}-clone",
1027       second_resource => "${::nova::params::vncproxy_service_name}-clone",
1028       first_action    => "start",
1029       second_action   => "start",
1030       require => [Pacemaker::Resource::Service[$::nova::params::consoleauth_service_name],
1031                   Pacemaker::Resource::Service[$::nova::params::vncproxy_service_name]],
1032     }
1033     pacemaker::constraint::colocation { 'nova-vncproxy-with-nova-consoleauth-colocation':
1034       source => "${::nova::params::vncproxy_service_name}-clone",
1035       target => "${::nova::params::consoleauth_service_name}-clone",
1036       score => "INFINITY",
1037       require => [Pacemaker::Resource::Service[$::nova::params::consoleauth_service_name],
1038                   Pacemaker::Resource::Service[$::nova::params::vncproxy_service_name]],
1039     }
1040     # FIXME(gfidente): novncproxy will not start unless websockify is updated to 0.6
1041     # which is not the case for f20 nor f21; ucomment when it becomes available
1042     #pacemaker::constraint::base { 'nova-vncproxy-then-nova-api-constraint':
1043     #  constraint_type => "order",
1044     #  first_resource  => "${::nova::params::vncproxy_service_name}-clone",
1045     #  second_resource => "${::nova::params::api_service_name}-clone",
1046     #  first_action    => "start",
1047     #  second_action   => "start",
1048     #  require => [Pacemaker::Resource::Service[$::nova::params::vncproxy_service_name],
1049     #              Pacemaker::Resource::Service[$::nova::params::api_service_name]],
1050     #}
1051     #pacemaker::constraint::colocation { 'nova-api-with-nova-vncproxy-colocation':
1052     #  source => "${::nova::params::api_service_name}-clone",
1053     #  target => "${::nova::params::vncproxy_service_name}-clone",
1054     #  score => "INFINITY",
1055     #  require => [Pacemaker::Resource::Service[$::nova::params::vncproxy_service_name],
1056     #              Pacemaker::Resource::Service[$::nova::params::api_service_name]],
1057     #}
1058     pacemaker::constraint::base { 'nova-api-then-nova-scheduler-constraint':
1059       constraint_type => "order",
1060       first_resource  => "${::nova::params::api_service_name}-clone",
1061       second_resource => "${::nova::params::scheduler_service_name}-clone",
1062       first_action    => "start",
1063       second_action   => "start",
1064       require => [Pacemaker::Resource::Service[$::nova::params::api_service_name],
1065                   Pacemaker::Resource::Service[$::nova::params::scheduler_service_name]],
1066     }
1067     pacemaker::constraint::colocation { 'nova-scheduler-with-nova-api-colocation':
1068       source => "${::nova::params::scheduler_service_name}-clone",
1069       target => "${::nova::params::api_service_name}-clone",
1070       score => "INFINITY",
1071       require => [Pacemaker::Resource::Service[$::nova::params::api_service_name],
1072                   Pacemaker::Resource::Service[$::nova::params::scheduler_service_name]],
1073     }
1074     pacemaker::constraint::base { 'nova-scheduler-then-nova-conductor-constraint':
1075       constraint_type => "order",
1076       first_resource  => "${::nova::params::scheduler_service_name}-clone",
1077       second_resource => "${::nova::params::conductor_service_name}-clone",
1078       first_action    => "start",
1079       second_action   => "start",
1080       require => [Pacemaker::Resource::Service[$::nova::params::scheduler_service_name],
1081                   Pacemaker::Resource::Service[$::nova::params::conductor_service_name]],
1082     }
1083     pacemaker::constraint::colocation { 'nova-conductor-with-nova-scheduler-colocation':
1084       source => "${::nova::params::conductor_service_name}-clone",
1085       target => "${::nova::params::scheduler_service_name}-clone",
1086       score => "INFINITY",
1087       require => [Pacemaker::Resource::Service[$::nova::params::scheduler_service_name],
1088                   Pacemaker::Resource::Service[$::nova::params::conductor_service_name]],
1089     }
1090
1091     # Ceilometer
1092     pacemaker::resource::service { $::ceilometer::params::agent_central_service_name :
1093       clone_params => 'interleave=true',
1094       require      => [Pacemaker::Resource::Service[$::keystone::params::service_name],
1095                        Pacemaker::Resource::Service[$::mongodb::params::service_name]],
1096     }
1097     pacemaker::resource::service { $::ceilometer::params::collector_service_name :
1098       clone_params => 'interleave=true',
1099     }
1100     pacemaker::resource::service { $::ceilometer::params::api_service_name :
1101       clone_params => 'interleave=true',
1102     }
1103     pacemaker::resource::service { $::ceilometer::params::alarm_evaluator_service_name :
1104       clone_params => 'interleave=true',
1105     }
1106     pacemaker::resource::service { $::ceilometer::params::alarm_notifier_service_name :
1107       clone_params => 'interleave=true',
1108     }
1109     pacemaker::resource::service { $::ceilometer::params::agent_notification_service_name :
1110       clone_params => 'interleave=true',
1111     }
1112     pacemaker::resource::ocf { 'delay' :
1113       ocf_agent_name  => 'heartbeat:Delay',
1114       clone_params    => 'interleave=true',
1115       resource_params => 'startdelay=10',
1116     }
1117     pacemaker::constraint::base { 'keystone-then-ceilometer-central-constraint':
1118       constraint_type => 'order',
1119       first_resource  => "${::keystone::params::service_name}-clone",
1120       second_resource => "${::ceilometer::params::agent_central_service_name}-clone",
1121       first_action    => 'start',
1122       second_action   => 'start',
1123       require         => [Pacemaker::Resource::Service[$::ceilometer::params::agent_central_service_name],
1124                           Pacemaker::Resource::Service[$::keystone::params::service_name]],
1125     }
1126     pacemaker::constraint::base { 'ceilometer-central-then-ceilometer-collector-constraint':
1127       constraint_type => 'order',
1128       first_resource  => "${::ceilometer::params::agent_central_service_name}-clone",
1129       second_resource => "${::ceilometer::params::collector_service_name}-clone",
1130       first_action    => 'start',
1131       second_action   => 'start',
1132       require         => [Pacemaker::Resource::Service[$::ceilometer::params::agent_central_service_name],
1133                           Pacemaker::Resource::Service[$::ceilometer::params::collector_service_name]],
1134     }
1135     pacemaker::constraint::base { 'ceilometer-collector-then-ceilometer-api-constraint':
1136       constraint_type => 'order',
1137       first_resource  => "${::ceilometer::params::collector_service_name}-clone",
1138       second_resource => "${::ceilometer::params::api_service_name}-clone",
1139       first_action    => 'start',
1140       second_action   => 'start',
1141       require         => [Pacemaker::Resource::Service[$::ceilometer::params::collector_service_name],
1142                           Pacemaker::Resource::Service[$::ceilometer::params::api_service_name]],
1143     }
1144     pacemaker::constraint::colocation { 'ceilometer-api-with-ceilometer-collector-colocation':
1145       source  => "${::ceilometer::params::api_service_name}-clone",
1146       target  => "${::ceilometer::params::collector_service_name}-clone",
1147       score   => 'INFINITY',
1148       require => [Pacemaker::Resource::Service[$::ceilometer::params::api_service_name],
1149                   Pacemaker::Resource::Service[$::ceilometer::params::collector_service_name]],
1150     }
1151     pacemaker::constraint::base { 'ceilometer-api-then-ceilometer-delay-constraint':
1152       constraint_type => 'order',
1153       first_resource  => "${::ceilometer::params::api_service_name}-clone",
1154       second_resource => 'delay-clone',
1155       first_action    => 'start',
1156       second_action   => 'start',
1157       require         => [Pacemaker::Resource::Service[$::ceilometer::params::api_service_name],
1158                           Pacemaker::Resource::Ocf['delay']],
1159     }
1160     pacemaker::constraint::colocation { 'ceilometer-delay-with-ceilometer-api-colocation':
1161       source  => 'delay-clone',
1162       target  => "${::ceilometer::params::api_service_name}-clone",
1163       score   => 'INFINITY',
1164       require => [Pacemaker::Resource::Service[$::ceilometer::params::api_service_name],
1165                   Pacemaker::Resource::Ocf['delay']],
1166     }
1167     pacemaker::constraint::base { 'ceilometer-delay-then-ceilometer-alarm-evaluator-constraint':
1168       constraint_type => 'order',
1169       first_resource  => 'delay-clone',
1170       second_resource => "${::ceilometer::params::alarm_evaluator_service_name}-clone",
1171       first_action    => 'start',
1172       second_action   => 'start',
1173       require         => [Pacemaker::Resource::Service[$::ceilometer::params::alarm_evaluator_service_name],
1174                           Pacemaker::Resource::Ocf['delay']],
1175     }
1176     pacemaker::constraint::colocation { 'ceilometer-alarm-evaluator-with-ceilometer-delay-colocation':
1177       source  => "${::ceilometer::params::alarm_evaluator_service_name}-clone",
1178       target  => 'delay-clone',
1179       score   => 'INFINITY',
1180       require => [Pacemaker::Resource::Service[$::ceilometer::params::api_service_name],
1181                   Pacemaker::Resource::Ocf['delay']],
1182     }
1183     pacemaker::constraint::base { 'ceilometer-alarm-evaluator-then-ceilometer-alarm-notifier-constraint':
1184       constraint_type => 'order',
1185       first_resource  => "${::ceilometer::params::alarm_evaluator_service_name}-clone",
1186       second_resource => "${::ceilometer::params::alarm_notifier_service_name}-clone",
1187       first_action    => 'start',
1188       second_action   => 'start',
1189       require         => [Pacemaker::Resource::Service[$::ceilometer::params::alarm_evaluator_service_name],
1190                           Pacemaker::Resource::Service[$::ceilometer::params::alarm_notifier_service_name]],
1191     }
1192     pacemaker::constraint::colocation { 'ceilometer-alarm-notifier-with-ceilometer-alarm-evaluator-colocation':
1193       source  => "${::ceilometer::params::alarm_notifier_service_name}-clone",
1194       target  => "${::ceilometer::params::alarm_evaluator_service_name}-clone",
1195       score   => 'INFINITY',
1196       require => [Pacemaker::Resource::Service[$::ceilometer::params::alarm_evaluator_service_name],
1197                   Pacemaker::Resource::Service[$::ceilometer::params::alarm_notifier_service_name]],
1198     }
1199     pacemaker::constraint::base { 'ceilometer-alarm-notifier-then-ceilometer-notification-constraint':
1200       constraint_type => 'order',
1201       first_resource  => "${::ceilometer::params::alarm_notifier_service_name}-clone",
1202       second_resource => "${::ceilometer::params::agent_notification_service_name}-clone",
1203       first_action    => 'start',
1204       second_action   => 'start',
1205       require         => [Pacemaker::Resource::Service[$::ceilometer::params::agent_notification_service_name],
1206                           Pacemaker::Resource::Service[$::ceilometer::params::alarm_notifier_service_name]],
1207     }
1208     pacemaker::constraint::colocation { 'ceilometer-notification-with-ceilometer-alarm-notifier-colocation':
1209       source  => "${::ceilometer::params::agent_notification_service_name}-clone",
1210       target  => "${::ceilometer::params::alarm_notifier_service_name}-clone",
1211       score   => 'INFINITY',
1212       require => [Pacemaker::Resource::Service[$::ceilometer::params::agent_notification_service_name],
1213                   Pacemaker::Resource::Service[$::ceilometer::params::alarm_notifier_service_name]],
1214     }
1215     if downcase(hiera('ceilometer_backend')) == 'mongodb' {
1216       pacemaker::constraint::base { 'mongodb-then-ceilometer-central-constraint':
1217         constraint_type => 'order',
1218         first_resource  => "${::mongodb::params::service_name}-clone",
1219         second_resource => "${::ceilometer::params::agent_central_service_name}-clone",
1220         first_action    => 'start',
1221         second_action   => 'start',
1222         require         => [Pacemaker::Resource::Service[$::ceilometer::params::agent_central_service_name],
1223                             Pacemaker::Resource::Service[$::mongodb::params::service_name]],
1224       }
1225     }
1226
1227     # Heat
1228     pacemaker::resource::service { $::heat::params::api_service_name :
1229       clone_params => 'interleave=true',
1230     }
1231     pacemaker::resource::service { $::heat::params::api_cloudwatch_service_name :
1232       clone_params => 'interleave=true',
1233     }
1234     pacemaker::resource::service { $::heat::params::api_cfn_service_name :
1235       clone_params => 'interleave=true',
1236     }
1237     pacemaker::resource::service { $::heat::params::engine_service_name :
1238       clone_params => 'interleave=true',
1239     }
1240     pacemaker::constraint::base { 'keystone-then-heat-api-constraint':
1241       constraint_type => 'order',
1242       first_resource  => "${::keystone::params::service_name}-clone",
1243       second_resource => "${::heat::params::api_service_name}-clone",
1244       first_action    => 'start',
1245       second_action   => 'start',
1246       require         => [Pacemaker::Resource::Service[$::heat::params::api_service_name],
1247                           Pacemaker::Resource::Service[$::keystone::params::service_name]],
1248     }
1249     pacemaker::constraint::base { 'heat-api-then-heat-api-cfn-constraint':
1250       constraint_type => 'order',
1251       first_resource  => "${::heat::params::api_service_name}-clone",
1252       second_resource => "${::heat::params::api_cfn_service_name}-clone",
1253       first_action    => 'start',
1254       second_action   => 'start',
1255       require => [Pacemaker::Resource::Service[$::heat::params::api_service_name],
1256                   Pacemaker::Resource::Service[$::heat::params::api_cfn_service_name]],
1257     }
1258     pacemaker::constraint::colocation { 'heat-api-cfn-with-heat-api-colocation':
1259       source  => "${::heat::params::api_cfn_service_name}-clone",
1260       target  => "${::heat::params::api_service_name}-clone",
1261       score   => 'INFINITY',
1262       require => [Pacemaker::Resource::Service[$::heat::params::api_cfn_service_name],
1263                   Pacemaker::Resource::Service[$::heat::params::api_service_name]],
1264     }
1265     pacemaker::constraint::base { 'heat-api-cfn-then-heat-api-cloudwatch-constraint':
1266       constraint_type => 'order',
1267       first_resource  => "${::heat::params::api_cfn_service_name}-clone",
1268       second_resource => "${::heat::params::api_cloudwatch_service_name}-clone",
1269       first_action    => 'start',
1270       second_action   => 'start',
1271       require => [Pacemaker::Resource::Service[$::heat::params::api_cloudwatch_service_name],
1272                   Pacemaker::Resource::Service[$::heat::params::api_cfn_service_name]],
1273     }
1274     pacemaker::constraint::colocation { 'heat-api-cloudwatch-with-heat-api-cfn-colocation':
1275       source  => "${::heat::params::api_cloudwatch_service_name}-clone",
1276       target  => "${::heat::params::api_cfn_service_name}-clone",
1277       score   => 'INFINITY',
1278       require => [Pacemaker::Resource::Service[$::heat::params::api_cfn_service_name],
1279                   Pacemaker::Resource::Service[$::heat::params::api_cloudwatch_service_name]],
1280     }
1281     pacemaker::constraint::base { 'heat-api-cloudwatch-then-heat-engine-constraint':
1282       constraint_type => 'order',
1283       first_resource  => "${::heat::params::api_cloudwatch_service_name}-clone",
1284       second_resource => "${::heat::params::engine_service_name}-clone",
1285       first_action    => 'start',
1286       second_action   => 'start',
1287       require => [Pacemaker::Resource::Service[$::heat::params::api_cloudwatch_service_name],
1288                   Pacemaker::Resource::Service[$::heat::params::engine_service_name]],
1289     }
1290     pacemaker::constraint::colocation { 'heat-engine-with-heat-api-cloudwatch-colocation':
1291       source  => "${::heat::params::engine_service_name}-clone",
1292       target  => "${::heat::params::api_cloudwatch_service_name}-clone",
1293       score   => 'INFINITY',
1294       require => [Pacemaker::Resource::Service[$::heat::params::api_cloudwatch_service_name],
1295                   Pacemaker::Resource::Service[$::heat::params::engine_service_name]],
1296     }
1297     pacemaker::constraint::base { 'ceilometer-notification-then-heat-api-constraint':
1298       constraint_type => 'order',
1299       first_resource  => "${::ceilometer::params::agent_notification_service_name}-clone",
1300       second_resource => "${::heat::params::api_service_name}-clone",
1301       first_action    => 'start',
1302       second_action   => 'start',
1303       require         => [Pacemaker::Resource::Service[$::heat::params::api_service_name],
1304                           Pacemaker::Resource::Service[$::ceilometer::params::agent_notification_service_name]],
1305     }
1306
1307     # Horizon
1308     pacemaker::resource::service { $::horizon::params::http_service:
1309         clone_params => "interleave=true",
1310     }
1311
1312
1313   }
1314
1315 } #END STEP 4