8f26af09c048129b6bd47c35db50b173dfd187f9
[apex-tripleo-heat-templates.git] / puppet / manifests / overcloud_controller_pacemaker.pp
1 # Copyright 2015 Red Hat, Inc.
2 # All Rights Reserved.
3 #
4 # Licensed under the Apache License, Version 2.0 (the "License"); you may
5 # not use this file except in compliance with the License. You may obtain
6 # a copy of the License at
7 #
8 #     http://www.apache.org/licenses/LICENSE-2.0
9 #
10 # Unless required by applicable law or agreed to in writing, software
11 # distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
12 # WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
13 # License for the specific language governing permissions and limitations
14 # under the License.
15
16 Pcmk_resource <| |> {
17   tries     => 10,
18   try_sleep => 3,
19 }
20
21 if !str2bool(hiera('enable_package_install', 'false')) {
22   case $::osfamily {
23     'RedHat': {
24       Package { provider => 'norpm' } # provided by tripleo-puppet
25     }
26     default: {
27       warning('enable_package_install option not supported.')
28     }
29   }
30 }
31
32 if $::hostname == downcase(hiera('bootstrap_nodeid')) {
33   $pacemaker_master = true
34   $sync_db = true
35 } else {
36   $pacemaker_master = false
37   $sync_db = false
38 }
39
40 # When to start and enable services which haven't been Pacemakerized
41 # FIXME: remove when we start all OpenStack services using Pacemaker
42 # (occurences of this variable will be gradually replaced with false)
43 $non_pcmk_start = hiera('step') >= 4
44
45 if hiera('step') >= 1 {
46
47   create_resources(sysctl::value, hiera('sysctl_settings'), {})
48
49   if count(hiera('ntp::servers')) > 0 {
50     include ::ntp
51   }
52
53   $controller_node_ips = split(hiera('controller_node_ips'), ',')
54   $controller_node_names = split(downcase(hiera('controller_node_names')), ',')
55   class { '::tripleo::loadbalancer' :
56     controller_hosts       => $controller_node_ips,
57     controller_hosts_names => $controller_node_names,
58     manage_vip             => false,
59     mysql_clustercheck     => true,
60     haproxy_service_manage => false,
61   }
62
63   $pacemaker_cluster_members = downcase(regsubst(hiera('controller_node_names'), ',', ' ', 'G'))
64   user { 'hacluster':
65    ensure => present,
66   } ->
67   class { '::pacemaker':
68     hacluster_pwd => hiera('hacluster_pwd'),
69   } ->
70   class { '::pacemaker::corosync':
71     cluster_members => $pacemaker_cluster_members,
72     setup_cluster   => $pacemaker_master,
73   }
74   class { '::pacemaker::stonith':
75     disable => true,
76   }
77
78   # Only configure RabbitMQ in this step, don't start it yet to
79   # avoid races where non-master nodes attempt to start without
80   # config (eg. binding on 0.0.0.0)
81   # The module ignores erlang_cookie if cluster_config is false
82   class { '::rabbitmq':
83     service_manage          => false,
84     tcp_keepalive           => false,
85     config_kernel_variables => hiera('rabbitmq_kernel_variables'),
86     config_variables        => hiera('rabbitmq_config_variables'),
87     environment_variables   => hiera('rabbitmq_environment'),
88   } ->
89   file { '/var/lib/rabbitmq/.erlang.cookie':
90     ensure  => 'present',
91     owner   => 'rabbitmq',
92     group   => 'rabbitmq',
93     mode    => '0400',
94     content => hiera('rabbitmq::erlang_cookie'),
95     replace => true,
96   }
97
98   if downcase(hiera('ceilometer_backend')) == 'mongodb' {
99     include ::mongodb::globals
100     class { '::mongodb::server' :
101       service_manage => false,
102     }
103   }
104
105   # Memcached
106   class {'::memcached' :
107     service_manage => false,
108   }
109
110   # Redis
111   class { '::redis' :
112     service_manage => false,
113     notify_service => false,
114   }
115
116   # Galera
117   if str2bool(hiera('enable_galera', 'true')) {
118     $mysql_config_file = '/etc/my.cnf.d/galera.cnf'
119   } else {
120     $mysql_config_file = '/etc/my.cnf.d/server.cnf'
121   }
122   $galera_nodes = downcase(hiera('galera_node_names', $::hostname))
123   $galera_nodes_count = count(split($galera_nodes, ','))
124
125   $mysqld_options = {
126     'mysqld' => {
127       'skip-name-resolve'             => '1',
128       'binlog_format'                 => 'ROW',
129       'default-storage-engine'        => 'innodb',
130       'innodb_autoinc_lock_mode'      => '2',
131       'innodb_locks_unsafe_for_binlog'=> '1',
132       'query_cache_size'              => '0',
133       'query_cache_type'              => '0',
134       'bind-address'                  => hiera('mysql_bind_host'),
135       'max_connections'               => '1024',
136       'open_files_limit'              => '-1',
137       'wsrep_provider'                => '/usr/lib64/galera/libgalera_smm.so',
138       'wsrep_cluster_name'            => 'galera_cluster',
139       'wsrep_slave_threads'           => '1',
140       'wsrep_certify_nonPK'           => '1',
141       'wsrep_max_ws_rows'             => '131072',
142       'wsrep_max_ws_size'             => '1073741824',
143       'wsrep_debug'                   => '0',
144       'wsrep_convert_LOCK_to_trx'     => '0',
145       'wsrep_retry_autocommit'        => '1',
146       'wsrep_auto_increment_control'  => '1',
147       'wsrep_drupal_282555_workaround'=> '0',
148       'wsrep_causal_reads'            => '0',
149       'wsrep_notify_cmd'              => '',
150       'wsrep_sst_method'              => 'rsync',
151     }
152   }
153
154   class { '::mysql::server':
155     create_root_user   => false,
156     create_root_my_cnf => false,
157     config_file        => $mysql_config_file,
158     override_options   => $mysqld_options,
159     service_manage     => false,
160     service_enabled    => false,
161   }
162
163 }
164
165 if hiera('step') >= 2 {
166
167   # NOTE(gfidente): the following vars are needed on all nodes so they
168   # need to stay out of pacemaker_master conditional
169   $mongo_node_ips_with_port = suffix(hiera('mongo_node_ips'), ':27017')
170   $mongodb_replset = hiera('mongodb::server::replset')
171
172   if $pacemaker_master {
173
174     # FIXME: we should not have to access tripleo::loadbalancer class
175     # parameters here to configure pacemaker VIPs. The configuration
176     # of pacemaker VIPs could move into puppet-tripleo or we should
177     # make use of less specific hiera parameters here for the settings.
178     $control_vip = hiera('tripleo::loadbalancer::controller_virtual_ip')
179     pacemaker::resource::ip { 'control_vip':
180       ip_address => $control_vip,
181     }
182     $public_vip = hiera('tripleo::loadbalancer::public_virtual_ip')
183     pacemaker::resource::ip { 'public_vip':
184       ip_address => $public_vip,
185     }
186
187     $internal_api_vip = hiera('tripleo::loadbalancer::internal_api_virtual_ip')
188     if $internal_api_vip and $internal_api_vip != $control_vip {
189       pacemaker::resource::ip { 'internal_api_vip':
190         ip_address => $internal_api_vip,
191       }
192     }
193
194     $storage_vip = hiera('tripleo::loadbalancer::storage_virtual_ip')
195     if $storage_vip and $storage_vip != $control_vip {
196       pacemaker::resource::ip { 'storage_vip':
197         ip_address => $storage_vip,
198       }
199     }
200
201     $storage_mgmt_vip = hiera('tripleo::loadbalancer::storage_mgmt_virtual_ip')
202     if $storage_mgmt_vip and $storage_mgmt_vip != $control_vip {
203       pacemaker::resource::ip { 'storage_mgmt_vip':
204         ip_address => $storage_mgmt_vip,
205       }
206     }
207
208     pacemaker::resource::service { 'haproxy':
209       clone_params => true,
210     }
211     pacemaker::resource::service { $::memcached::params::service_name :
212       clone_params => true,
213       require      => Class['::memcached'],
214     }
215
216     pacemaker::resource::ocf { 'rabbitmq':
217       ocf_agent_name  => 'heartbeat:rabbitmq-cluster',
218       resource_params => 'set_policy=\'ha-all ^(?!amq\.).* {"ha-mode":"all"}\'',
219       clone_params    => 'ordered=true interleave=true',
220       require         => Class['::rabbitmq'],
221     }
222
223     if downcase(hiera('ceilometer_backend')) == 'mongodb' {
224       pacemaker::resource::service { $::mongodb::params::service_name :
225         op_params    => 'start timeout=120s',
226         clone_params => true,
227         require      => Class['::mongodb::server'],
228       }
229       # NOTE (spredzy) : The replset can only be run
230       # once all the nodes have joined the cluster.
231       mongodb_conn_validator { $mongo_node_ips_with_port :
232         require => Pacemaker::Resource::Service[$::mongodb::params::service_name],
233         before  => Mongodb_replset[$mongodb_replset],
234       }
235       mongodb_replset { $mongodb_replset :
236         members => $mongo_node_ips_with_port,
237       }
238     }
239
240     pacemaker::resource::ocf { 'galera' :
241       ocf_agent_name  => 'heartbeat:galera',
242       op_params       => 'promote timeout=300s on-fail=block',
243       master_params   => '',
244       meta_params     => "master-max=${galera_nodes_count} ordered=true",
245       resource_params => "additional_parameters='--open-files-limit=16384' enable_creation=true wsrep_cluster_address='gcomm://${galera_nodes}'",
246       require         => Class['::mysql::server'],
247       before          => Exec['galera-ready'],
248     }
249
250     pacemaker::resource::ocf { 'redis':
251       ocf_agent_name  => 'heartbeat:redis',
252       master_params   => '',
253       meta_params     => 'notify=true ordered=true interleave=true',
254       resource_params => 'wait_last_known_master=true',
255       require         => Class['::redis'],
256     }
257     $redis_vip = hiera('redis_vip')
258     if $redis_vip and $redis_vip != $control_vip {
259         pacemaker::resource::ip { 'vip-redis':
260           ip_address => $redis_vip,
261         }
262     }
263     pacemaker::constraint::base { 'redis-master-then-vip-redis':
264       constraint_type => 'order',
265       first_resource  => 'redis-master',
266       second_resource => "ip-${redis_vip}",
267       first_action    => 'promote',
268       second_action   => 'start',
269       require => [Pacemaker::Resource::Ocf['redis'],
270                   Pacemaker::Resource::Ip['vip-redis']],
271     }
272     pacemaker::constraint::colocation { 'vip-redis-with-redis-master':
273       source  => "ip-${redis_vip}",
274       target  => 'redis-master',
275       score   => 'INFINITY',
276       require => [Pacemaker::Resource::Ocf['redis'],
277                   Pacemaker::Resource::Ip['vip-redis']],
278     }
279
280   }
281
282   exec { 'galera-ready' :
283     command     => '/usr/bin/clustercheck >/dev/null',
284     timeout     => 30,
285     tries       => 180,
286     try_sleep   => 10,
287     environment => ["AVAILABLE_WHEN_READONLY=0"],
288     require     => File['/etc/sysconfig/clustercheck'],
289   }
290
291   file { '/etc/sysconfig/clustercheck' :
292     ensure  => file,
293     content => "MYSQL_USERNAME=root\n
294 MYSQL_PASSWORD=''\n
295 MYSQL_HOST=localhost\n",
296   }
297
298   xinetd::service { 'galera-monitor' :
299     port           => '9200',
300     server         => '/usr/bin/clustercheck',
301     per_source     => 'UNLIMITED',
302     log_on_success => '',
303     log_on_failure => 'HOST',
304     flags          => 'REUSE',
305     service_type   => 'UNLISTED',
306     user           => 'root',
307     group          => 'root',
308     require        => File['/etc/sysconfig/clustercheck'],
309   }
310
311   # Create all the database schemas
312   # Example DSN format: mysql://user:password@host/dbname
313   if $sync_db {
314     $allowed_hosts = ['%',hiera('mysql_bind_host')]
315     $keystone_dsn = split(hiera('keystone::database_connection'), '[@:/?]')
316     class { 'keystone::db::mysql':
317       user          => $keystone_dsn[3],
318       password      => $keystone_dsn[4],
319       host          => $keystone_dsn[5],
320       dbname        => $keystone_dsn[6],
321       allowed_hosts => $allowed_hosts,
322       require       => Exec['galera-ready'],
323     }
324     $glance_dsn = split(hiera('glance::api::database_connection'), '[@:/?]')
325     class { 'glance::db::mysql':
326       user          => $glance_dsn[3],
327       password      => $glance_dsn[4],
328       host          => $glance_dsn[5],
329       dbname        => $glance_dsn[6],
330       allowed_hosts => $allowed_hosts,
331       require       => Exec['galera-ready'],
332     }
333     $nova_dsn = split(hiera('nova::database_connection'), '[@:/?]')
334     class { 'nova::db::mysql':
335       user          => $nova_dsn[3],
336       password      => $nova_dsn[4],
337       host          => $nova_dsn[5],
338       dbname        => $nova_dsn[6],
339       allowed_hosts => $allowed_hosts,
340       require       => Exec['galera-ready'],
341     }
342     $neutron_dsn = split(hiera('neutron::server::database_connection'), '[@:/?]')
343     class { 'neutron::db::mysql':
344       user          => $neutron_dsn[3],
345       password      => $neutron_dsn[4],
346       host          => $neutron_dsn[5],
347       dbname        => $neutron_dsn[6],
348       allowed_hosts => $allowed_hosts,
349       require       => Exec['galera-ready'],
350     }
351     $cinder_dsn = split(hiera('cinder::database_connection'), '[@:/?]')
352     class { 'cinder::db::mysql':
353       user          => $cinder_dsn[3],
354       password      => $cinder_dsn[4],
355       host          => $cinder_dsn[5],
356       dbname        => $cinder_dsn[6],
357       allowed_hosts => $allowed_hosts,
358       require       => Exec['galera-ready'],
359     }
360     $heat_dsn = split(hiera('heat::database_connection'), '[@:/?]')
361     class { 'heat::db::mysql':
362       user          => $heat_dsn[3],
363       password      => $heat_dsn[4],
364       host          => $heat_dsn[5],
365       dbname        => $heat_dsn[6],
366       allowed_hosts => $allowed_hosts,
367       require       => Exec['galera-ready'],
368     }
369     if downcase(hiera('ceilometer_backend')) == 'mysql' {
370       $ceilometer_dsn = split(hiera('ceilometer_mysql_conn_string'), '[@:/?]')
371       class { 'ceilometer::db::mysql':
372         user          => $ceilometer_dsn[3],
373         password      => $ceilometer_dsn[4],
374         host          => $ceilometer_dsn[5],
375         dbname        => $ceilometer_dsn[6],
376         allowed_hosts => $allowed_hosts,
377         require       => Exec['galera-ready'],
378       }
379     }
380   }
381
382   # pre-install swift here so we can build rings
383   include ::swift
384
385   # Ceph
386   $cinder_enable_rbd_backend = hiera('cinder_enable_rbd_backend', false)
387   $enable_ceph = $cinder_enable_rbd_backend
388
389   if $enable_ceph {
390     class { 'ceph::profile::params':
391       mon_initial_members => downcase(hiera('ceph_mon_initial_members'))
392     }
393     include ::ceph::profile::mon
394   }
395
396   if str2bool(hiera('enable_ceph_storage', 'false')) {
397     include ::ceph::profile::client
398     include ::ceph::profile::osd
399   }
400
401
402 } #END STEP 2
403
404 if hiera('step') >= 3 {
405
406   class { '::keystone':
407     sync_db => $sync_db,
408     manage_service => false,
409     enabled => false,
410   }
411
412   #TODO: need a cleanup-keystone-tokens.sh solution here
413   keystone_config {
414     'ec2/driver': value => 'keystone.contrib.ec2.backends.sql.Ec2';
415   }
416   file { [ '/etc/keystone/ssl', '/etc/keystone/ssl/certs', '/etc/keystone/ssl/private' ]:
417     ensure  => 'directory',
418     owner   => 'keystone',
419     group   => 'keystone',
420     require => Package['keystone'],
421   }
422   file { '/etc/keystone/ssl/certs/signing_cert.pem':
423     content => hiera('keystone_signing_certificate'),
424     owner   => 'keystone',
425     group   => 'keystone',
426     notify  => Service['keystone'],
427     require => File['/etc/keystone/ssl/certs'],
428   }
429   file { '/etc/keystone/ssl/private/signing_key.pem':
430     content => hiera('keystone_signing_key'),
431     owner   => 'keystone',
432     group   => 'keystone',
433     notify  => Service['keystone'],
434     require => File['/etc/keystone/ssl/private'],
435   }
436   file { '/etc/keystone/ssl/certs/ca.pem':
437     content => hiera('keystone_ca_certificate'),
438     owner   => 'keystone',
439     group   => 'keystone',
440     notify  => Service['keystone'],
441     require => File['/etc/keystone/ssl/certs'],
442   }
443
444   $glance_backend = downcase(hiera('glance_backend', 'swift'))
445   case $glance_backend {
446       swift: { $glance_store = 'glance.store.swift.Store' }
447       file: { $glance_store = 'glance.store.filesystem.Store' }
448       rbd: { $glance_store = 'glance.store.rbd.Store' }
449       default: { fail('Unrecognized glance_backend parameter.') }
450   }
451
452   # TODO: notifications, scrubber, etc.
453   include ::glance
454   class { 'glance::api':
455     known_stores => [$glance_store],
456     manage_service => false,
457     enabled => false,
458   }
459   class { '::glance::registry' :
460     sync_db => $sync_db,
461     manage_service => false,
462     enabled => false,
463   }
464   include join(['::glance::backend::', $glance_backend])
465
466   include ::nova
467
468   class { '::nova::api' :
469     sync_db => $sync_db,
470     manage_service => false,
471     enabled => false,
472   }
473   class { '::nova::cert' :
474     manage_service => false,
475     enabled => false,
476   }
477   class { '::nova::conductor' :
478     manage_service => false,
479     enabled => false,
480   }
481   class { '::nova::consoleauth' :
482     manage_service => false,
483     enabled => false,
484   }
485   class { '::nova::vncproxy' :
486     manage_service => false,
487     enabled => false,
488   }
489   class { '::nova::scheduler' :
490     manage_service => false,
491     enabled => false,
492   }
493   include ::nova::network::neutron
494
495   # Neutron class definitions
496   include ::neutron
497   class { '::neutron::server' :
498     sync_db => $sync_db,
499     manage_service => false,
500     enabled => false,
501   }
502   class { '::neutron::agents::dhcp' :
503     manage_service => false,
504     enabled => false,
505   }
506   class { '::neutron::agents::l3' :
507     manage_service => false,
508     enabled => false,
509   }
510   class { 'neutron::agents::metadata':
511     manage_service => false,
512     enabled => false,
513   }
514   file { '/etc/neutron/dnsmasq-neutron.conf':
515     content => hiera('neutron_dnsmasq_options'),
516     owner   => 'neutron',
517     group   => 'neutron',
518     notify  => Service['neutron-dhcp-service'],
519     require => Package['neutron'],
520   }
521   class { 'neutron::plugins::ml2':
522     flat_networks   => split(hiera('neutron_flat_networks'), ','),
523     tenant_network_types => [hiera('neutron_tenant_network_type')],
524   }
525   class { 'neutron::agents::ml2::ovs':
526     # manage_service   => false # not implemented
527     enabled          => false,
528     bridge_mappings  => split(hiera('neutron_bridge_mappings'), ','),
529     tunnel_types     => split(hiera('neutron_tunnel_types'), ','),
530   }
531
532   include ::cinder
533   class { '::cinder::api':
534     sync_db => $sync_db,
535     manage_service => false,
536     enabled => false,
537   }
538   class { '::cinder::scheduler' :
539     manage_service => false,
540     enabled => false,
541   }
542   class { '::cinder::volume' :
543     manage_service => false,
544     enabled => false,
545   }
546   include ::cinder::glance
547   class {'cinder::setup_test_volume':
548     size => join([hiera('cinder_lvm_loop_device_size'), 'M']),
549   }
550
551   $cinder_enable_iscsi = hiera('cinder_enable_iscsi_backend', true)
552   if $cinder_enable_iscsi {
553     $cinder_iscsi_backend = 'tripleo_iscsi'
554
555     cinder::backend::iscsi { $cinder_iscsi_backend :
556       iscsi_ip_address => hiera('cinder_iscsi_ip_address'),
557       iscsi_helper     => hiera('cinder_iscsi_helper'),
558     }
559   }
560
561   if $enable_ceph {
562
563     Ceph_pool {
564       pg_num  => hiera('ceph::profile::params::osd_pool_default_pg_num'),
565       pgp_num => hiera('ceph::profile::params::osd_pool_default_pgp_num'),
566       size    => hiera('ceph::profile::params::osd_pool_default_size'),
567     }
568
569     $ceph_pools = hiera('ceph_pools')
570     ceph::pool { $ceph_pools : }
571   }
572
573   if $cinder_enable_rbd_backend {
574     $cinder_rbd_backend = 'tripleo_ceph'
575
576     cinder_config {
577       "${cinder_rbd_backend}/host": value => 'hostgroup';
578     }
579
580     cinder::backend::rbd { $cinder_rbd_backend :
581       rbd_pool        => 'volumes',
582       rbd_user        => 'openstack',
583       rbd_secret_uuid => hiera('ceph::profile::params::fsid'),
584       require         => Ceph::Pool['volumes'],
585     }
586   }
587
588   if hiera('cinder_enable_netapp_backend', false) {
589     $cinder_netapp_backend = hiera('cinder::backend::netapp::title')
590
591     cinder_config {
592       "${cinder_netapp_backend}/host": value => 'hostgroup';
593     }
594
595     if hiera('cinder_netapp_nfs_shares', undef) {
596       $cinder_netapp_nfs_shares = split(hiera('cinder_netapp_nfs_shares', undef), ',')
597     }
598
599     cinder::backend::netapp { $cinder_netapp_backend :
600       nfs_shares => $cinder_netapp_nfs_shares,
601     }
602   }
603
604   $cinder_enabled_backends = delete_undef_values([$cinder_iscsi_backend, $cinder_rbd_backend, $cinder_netapp_backend])
605   class { '::cinder::backends' :
606     enabled_backends => $cinder_enabled_backends,
607   }
608
609   # swift proxy
610   class { '::swift::proxy' :
611     manage_service => $non_pcmk_start,
612     enabled => $non_pcmk_start,
613   }
614   include ::swift::proxy::proxy_logging
615   include ::swift::proxy::healthcheck
616   include ::swift::proxy::cache
617   include ::swift::proxy::keystone
618   include ::swift::proxy::authtoken
619   include ::swift::proxy::staticweb
620   include ::swift::proxy::ceilometer
621   include ::swift::proxy::ratelimit
622   include ::swift::proxy::catch_errors
623   include ::swift::proxy::tempurl
624   include ::swift::proxy::formpost
625
626   # swift storage
627   if str2bool(hiera('enable_swift_storage', 'true')) {
628     class {'::swift::storage::all':
629       mount_check => str2bool(hiera('swift_mount_check'))
630     }
631     class {'::swift::storage::account':
632       manage_service => $non_pcmk_start,
633       enabled => $non_pcmk_start,
634     }
635     class {'::swift::storage::container':
636       manage_service => $non_pcmk_start,
637       enabled => $non_pcmk_start,
638     }
639     class {'::swift::storage::object':
640       manage_service => $non_pcmk_start,
641       enabled => $non_pcmk_start,
642     }
643     if(!defined(File['/srv/node'])) {
644       file { '/srv/node':
645         ensure  => directory,
646         owner   => 'swift',
647         group   => 'swift',
648         require => Package['openstack-swift'],
649       }
650     }
651     $swift_components = ['account', 'container', 'object']
652     swift::storage::filter::recon { $swift_components : }
653     swift::storage::filter::healthcheck { $swift_components : }
654   }
655
656   # Ceilometer
657   $ceilometer_backend = downcase(hiera('ceilometer_backend'))
658   case $ceilometer_backend {
659     /mysql/ : {
660       $ceilometer_database_connection = hiera('ceilometer_mysql_conn_string')
661     }
662     default : {
663       $mongo_node_string = join($mongo_node_ips_with_port, ',')
664       $ceilometer_database_connection = "mongodb://${mongo_node_string}/ceilometer?replicaSet=${mongodb_replset}"
665     }
666   }
667   include ::ceilometer
668   class { '::ceilometer::api' :
669     manage_service => false,
670     enabled => false,
671   }
672   class { '::ceilometer::agent::notification' :
673     manage_service => false,
674     enabled => false,
675   }
676   class { '::ceilometer::agent::central' :
677     manage_service => false,
678     enabled => false,
679   }
680   class { '::ceilometer::alarm::notifier' :
681     manage_service => false,
682     enabled => false,
683   }
684   class { '::ceilometer::alarm::evaluator' :
685     manage_service => false,
686     enabled => false,
687   }
688   class { '::ceilometer::collector' :
689     manage_service => false,
690     enabled => false,
691   }
692   include ::ceilometer::expirer
693   class { '::ceilometer::db' :
694     database_connection => $ceilometer_database_connection,
695     sync_db             => $sync_db,
696   }
697   include ceilometer::agent::auth
698
699   Cron <| title == 'ceilometer-expirer' |> { command => "sleep $((\$(od -A n -t d -N 3 /dev/urandom) % 86400)) && ${::ceilometer::params::expirer_command}" }
700
701   # Heat
702   class { '::heat' :
703     sync_db => $sync_db,
704   }
705   class { '::heat::api' :
706     manage_service => false,
707     enabled => false,
708   }
709   class { '::heat::api_cfn' :
710     manage_service => false,
711     enabled => false,
712   }
713   class { '::heat::api_cloudwatch' :
714     manage_service => false,
715     enabled => false,
716   }
717   class { '::heat::engine' :
718     manage_service => false,
719     enabled => false,
720   }
721
722   # httpd/apache and horizon
723   # NOTE(gfidente): server-status can be consumed by the pacemaker resource agent
724   include ::apache
725   include ::apache::mod::status
726   $vhost_params = {
727     add_listen => false,
728     priority   => 10,
729   }
730   class { 'horizon':
731     cache_server_ip    => hiera('memcache_node_ips', '127.0.0.1'),
732     vhost_extra_params => $vhost_params,
733     server_aliases     => $::hostname,
734   }
735
736   $snmpd_user = hiera('snmpd_readonly_user_name')
737   snmp::snmpv3_user { $snmpd_user:
738     authtype => 'MD5',
739     authpass => hiera('snmpd_readonly_user_password'),
740   }
741   class { 'snmp':
742     agentaddress => ['udp:161','udp6:[::1]:161'],
743     snmpd_config => [ join(['rouser ', hiera('snmpd_readonly_user_name')]), 'proc  cron', 'includeAllDisks  10%', 'master agentx', 'trapsink localhost public', 'iquerySecName internalUser', 'rouser internalUser', 'defaultMonitors yes', 'linkUpDownNotifications yes' ],
744   }
745
746 } #END STEP 3
747
748 if hiera('step') >= 4 {
749   if $pacemaker_master {
750
751     # Keystone
752     pacemaker::resource::service { $::keystone::params::service_name :
753       clone_params => "interleave=true",
754     }
755
756     # Cinder
757     pacemaker::resource::service { $::cinder::params::api_service :
758       clone_params => "interleave=true",
759       require      => Pacemaker::Resource::Service[$::keystone::params::service_name],
760     }
761     pacemaker::resource::service { $::cinder::params::scheduler_service :
762       clone_params => "interleave=true",
763     }
764     pacemaker::resource::service { $::cinder::params::volume_service : }
765
766     pacemaker::constraint::base { 'keystone-then-cinder-api-constraint':
767       constraint_type => 'order',
768       first_resource  => "${::keystone::params::service_name}-clone",
769       second_resource => "${::cinder::params::api_service}-clone",
770       first_action    => 'start',
771       second_action   => 'start',
772       require         => [Pacemaker::Resource::Service[$::cinder::params::api_service],
773                           Pacemaker::Resource::Service[$::keystone::params::service_name]],
774     }
775     pacemaker::constraint::base { 'cinder-api-then-cinder-scheduler-constraint':
776       constraint_type => "order",
777       first_resource => "${::cinder::params::api_service}-clone",
778       second_resource => "${::cinder::params::scheduler_service}-clone",
779       first_action => "start",
780       second_action => "start",
781       require => [Pacemaker::Resource::Service[$::cinder::params::api_service],
782                   Pacemaker::Resource::Service[$::cinder::params::scheduler_service]],
783     }
784     pacemaker::constraint::colocation { 'cinder-scheduler-with-cinder-api-colocation':
785       source => "${::cinder::params::scheduler_service}-clone",
786       target => "${::cinder::params::api_service}-clone",
787       score => "INFINITY",
788       require => [Pacemaker::Resource::Service[$::cinder::params::api_service],
789                   Pacemaker::Resource::Service[$::cinder::params::scheduler_service]],
790     }
791     pacemaker::constraint::base { 'cinder-scheduler-then-cinder-volume-constraint':
792       constraint_type => "order",
793       first_resource => "${::cinder::params::scheduler_service}-clone",
794       second_resource => "${::cinder::params::volume_service}",
795       first_action => "start",
796       second_action => "start",
797       require => [Pacemaker::Resource::Service[$::cinder::params::scheduler_service],
798                   Pacemaker::Resource::Service[$::cinder::params::volume_service]],
799     }
800     pacemaker::constraint::colocation { 'cinder-volume-with-cinder-scheduler-colocation':
801       source => "${::cinder::params::volume_service}",
802       target => "${::cinder::params::scheduler_service}-clone",
803       score => "INFINITY",
804       require => [Pacemaker::Resource::Service[$::cinder::params::scheduler_service],
805                   Pacemaker::Resource::Service[$::cinder::params::volume_service]],
806     }
807
808     # Glance
809     pacemaker::resource::service { $::glance::params::registry_service_name :
810       clone_params => "interleave=true",
811       require      => Pacemaker::Resource::Service[$::keystone::params::service_name],
812     }
813     pacemaker::resource::service { $::glance::params::api_service_name :
814       clone_params => "interleave=true",
815     }
816
817     pacemaker::constraint::base { 'keystone-then-glance-registry-constraint':
818       constraint_type => 'order',
819       first_resource  => "${::keystone::params::service_name}-clone",
820       second_resource => "${::glance::params::registry_service_name}-clone",
821       first_action    => 'start',
822       second_action   => 'start',
823       require         => [Pacemaker::Resource::Service[$::glance::params::registry_service_name],
824                           Pacemaker::Resource::Service[$::keystone::params::service_name]],
825     }
826     pacemaker::constraint::base { 'glance-registry-then-glance-api-constraint':
827       constraint_type => "order",
828       first_resource  => "${::glance::params::registry_service_name}-clone",
829       second_resource => "${::glance::params::api_service_name}-clone",
830       first_action    => "start",
831       second_action   => "start",
832       require => [Pacemaker::Resource::Service[$::glance::params::registry_service_name],
833                   Pacemaker::Resource::Service[$::glance::params::api_service_name]],
834     }
835     pacemaker::constraint::colocation { 'glance-api-with-glance-registry-colocation':
836       source  => "${::glance::params::api_service_name}-clone",
837       target  => "${::glance::params::registry_service_name}-clone",
838       score   => "INFINITY",
839       require => [Pacemaker::Resource::Service[$::glance::params::registry_service_name],
840                   Pacemaker::Resource::Service[$::glance::params::api_service_name]],
841     }
842
843     # Neutron
844     pacemaker::resource::service { $::neutron::params::server_service:
845       op_params => "start timeout=90",
846       clone_params   => "interleave=true",
847       require => Pacemaker::Resource::Service[$::keystone::params::service_name]
848     }
849     pacemaker::resource::service { $::neutron::params::l3_agent_service:
850       clone_params   => "interleave=true",
851     }
852     pacemaker::resource::service { $::neutron::params::dhcp_agent_service:
853       clone_params   => "interleave=true",
854     }
855     pacemaker::resource::service { $::neutron::params::ovs_agent_service:
856       clone_params => "interleave=true",
857     }
858     pacemaker::resource::service { $::neutron::params::metadata_agent_service:
859       clone_params => "interleave=true",
860     }
861     pacemaker::resource::ocf { $::neutron::params::ovs_cleanup_service:
862       ocf_agent_name => "neutron:OVSCleanup",
863       clone_params => "interleave=true",
864     }
865     pacemaker::resource::ocf { 'neutron-netns-cleanup':
866       ocf_agent_name => "neutron:NetnsCleanup",
867       clone_params => "interleave=true",
868     }
869     pacemaker::resource::ocf { 'neutron-scale':
870       ocf_agent_name => "neutron:NeutronScale",
871       clone_params => "globally-unique=true clone-max=3 interleave=true",
872     }
873     pacemaker::constraint::base { 'keystone-to-neutron-server-constraint':
874       constraint_type => "order",
875       first_resource => "${::keystone::params::service_name}-clone",
876       second_resource => "${::neutron::params::server_service}-clone",
877       first_action => "start",
878       second_action => "start",
879       require => [Pacemaker::Resource::Service[$::keystone::params::service_name],
880                   Pacemaker::Resource::Service[$::neutron::params::server_service]],
881     }
882     pacemaker::constraint::base { 'neutron-server-to-neutron-scale-constraint':
883       constraint_type => "order",
884       first_resource => "${::neutron::params::server_service}-clone",
885       second_resource => "neutron-scale-clone",
886       first_action => "start",
887       second_action => "start",
888       require => [Pacemaker::Resource::Service[$::neutron::params::server_service],
889                   Pacemaker::Resource::Ocf['neutron-scale']],
890     }
891     pacemaker::constraint::base { 'neutron-scale-to-ovs-cleanup-constraint':
892       constraint_type => "order",
893       first_resource => "neutron-scale-clone",
894       second_resource => "${::neutron::params::ovs_cleanup_service}-clone",
895       first_action => "start",
896       second_action => "start",
897       require => [Pacemaker::Resource::Ocf['neutron-scale'],
898                   Pacemaker::Resource::Ocf["${::neutron::params::ovs_cleanup_service}"]],
899     }
900     pacemaker::constraint::colocation { 'neutron-scale-to-ovs-cleanup-colocation':
901       source => "${::neutron::params::ovs_cleanup_service}-clone",
902       target => "neutron-scale-clone",
903       score => "INFINITY",
904       require => [Pacemaker::Resource::Ocf['neutron-scale'],
905                   Pacemaker::Resource::Ocf["${::neutron::params::ovs_cleanup_service}"]],
906     }
907     pacemaker::constraint::base { 'neutron-ovs-cleanup-to-netns-cleanup-constraint':
908       constraint_type => "order",
909       first_resource => "${::neutron::params::ovs_cleanup_service}-clone",
910       second_resource => "neutron-netns-cleanup-clone",
911       first_action => "start",
912       second_action => "start",
913       require => [Pacemaker::Resource::Ocf["${::neutron::params::ovs_cleanup_service}"],
914                   Pacemaker::Resource::Ocf['neutron-netns-cleanup']],
915     }
916     pacemaker::constraint::colocation { 'neutron-ovs-cleanup-to-netns-cleanup-colocation':
917       source => "neutron-netns-cleanup-clone",
918       target => "${::neutron::params::ovs_cleanup_service}-clone",
919       score => "INFINITY",
920       require => [Pacemaker::Resource::Ocf["${::neutron::params::ovs_cleanup_service}"],
921                   Pacemaker::Resource::Ocf['neutron-netns-cleanup']],
922     }
923     pacemaker::constraint::base { 'neutron-netns-cleanup-to-openvswitch-agent-constraint':
924       constraint_type => "order",
925       first_resource => "neutron-netns-cleanup-clone",
926       second_resource => "${::neutron::params::ovs_agent_service}-clone",
927       first_action => "start",
928       second_action => "start",
929       require => [Pacemaker::Resource::Ocf["neutron-netns-cleanup"],
930                   Pacemaker::Resource::Service["${::neutron::params::ovs_agent_service}"]],
931     }
932     pacemaker::constraint::colocation { 'neutron-netns-cleanup-to-openvswitch-agent-colocation':
933       source => "${::neutron::params::ovs_agent_service}-clone",
934       target => "neutron-netns-cleanup-clone",
935       score => "INFINITY",
936       require => [Pacemaker::Resource::Ocf["neutron-netns-cleanup"],
937                   Pacemaker::Resource::Service["${::neutron::params::ovs_agent_service}"]],
938     }
939     pacemaker::constraint::base { 'neutron-openvswitch-agent-to-dhcp-agent-constraint':
940       constraint_type => "order",
941       first_resource => "${::neutron::params::ovs_agent_service}-clone",
942       second_resource => "${::neutron::params::dhcp_agent_service}-clone",
943       first_action => "start",
944       second_action => "start",
945       require => [Pacemaker::Resource::Service["${::neutron::params::ovs_agent_service}"],
946                   Pacemaker::Resource::Service["${::neutron::params::dhcp_agent_service}"]],
947
948     }
949     pacemaker::constraint::colocation { 'neutron-openvswitch-agent-to-dhcp-agent-colocation':
950       source => "${::neutron::params::dhcp_agent_service}-clone",
951       target => "${::neutron::params::ovs_agent_service}-clone",
952       score => "INFINITY",
953       require => [Pacemaker::Resource::Service["${::neutron::params::ovs_agent_service}"],
954                   Pacemaker::Resource::Service["${::neutron::params::dhcp_agent_service}"]],
955     }
956     pacemaker::constraint::base { 'neutron-dhcp-agent-to-l3-agent-constraint':
957       constraint_type => "order",
958       first_resource => "${::neutron::params::dhcp_agent_service}-clone",
959       second_resource => "${::neutron::params::l3_agent_service}-clone",
960       first_action => "start",
961       second_action => "start",
962       require => [Pacemaker::Resource::Service["${::neutron::params::dhcp_agent_service}"],
963                   Pacemaker::Resource::Service["${::neutron::params::l3_agent_service}"]]
964     }
965     pacemaker::constraint::colocation { 'neutron-dhcp-agent-to-l3-agent-colocation':
966       source => "${::neutron::params::l3_agent_service}-clone",
967       target => "${::neutron::params::dhcp_agent_service}-clone",
968       score => "INFINITY",
969       require => [Pacemaker::Resource::Service["${::neutron::params::dhcp_agent_service}"],
970                   Pacemaker::Resource::Service["${::neutron::params::l3_agent_service}"]]
971     }
972     pacemaker::constraint::base { 'neutron-l3-agent-to-metadata-agent-constraint':
973       constraint_type => "order",
974       first_resource => "${::neutron::params::l3_agent_service}-clone",
975       second_resource => "${::neutron::params::metadata_agent_service}-clone",
976       first_action => "start",
977       second_action => "start",
978       require => [Pacemaker::Resource::Service["${::neutron::params::l3_agent_service}"],
979                   Pacemaker::Resource::Service["${::neutron::params::metadata_agent_service}"]]
980     }
981     pacemaker::constraint::colocation { 'neutron-l3-agent-to-metadata-agent-colocation':
982       source => "${::neutron::params::metadata_agent_service}-clone",
983       target => "${::neutron::params::l3_agent_service}-clone",
984       score => "INFINITY",
985       require => [Pacemaker::Resource::Service["${::neutron::params::l3_agent_service}"],
986                   Pacemaker::Resource::Service["${::neutron::params::metadata_agent_service}"]]
987     }
988
989     # Nova
990     pacemaker::resource::service { $::nova::params::api_service_name :
991       clone_params    => "interleave=true",
992       op_params       => "monitor start-delay=10s",
993     }
994     pacemaker::resource::service { $::nova::params::conductor_service_name :
995       clone_params    => "interleave=true",
996       op_params       => "monitor start-delay=10s",
997     }
998     pacemaker::resource::service { $::nova::params::consoleauth_service_name :
999       clone_params    => "interleave=true",
1000       op_params       => "monitor start-delay=10s",
1001       require         => Pacemaker::Resource::Service[$::keystone::params::service_name],
1002     }
1003     pacemaker::resource::service { $::nova::params::vncproxy_service_name :
1004       clone_params    => "interleave=true",
1005       op_params       => "monitor start-delay=10s",
1006     }
1007     pacemaker::resource::service { $::nova::params::scheduler_service_name :
1008       clone_params    => "interleave=true",
1009       op_params       => "monitor start-delay=10s",
1010     }
1011
1012     pacemaker::constraint::base { 'keystone-then-nova-consoleauth-constraint':
1013       constraint_type => 'order',
1014       first_resource  => "${::keystone::params::service_name}-clone",
1015       second_resource => "${::nova::params::consoleauth_service_name}-clone",
1016       first_action    => 'start',
1017       second_action   => 'start',
1018       require         => [Pacemaker::Resource::Service[$::nova::params::consoleauth_service_name],
1019                           Pacemaker::Resource::Service[$::keystone::params::service_name]],
1020     }
1021     pacemaker::constraint::base { 'nova-consoleauth-then-nova-vncproxy-constraint':
1022       constraint_type => "order",
1023       first_resource  => "${::nova::params::consoleauth_service_name}-clone",
1024       second_resource => "${::nova::params::vncproxy_service_name}-clone",
1025       first_action    => "start",
1026       second_action   => "start",
1027       require => [Pacemaker::Resource::Service[$::nova::params::consoleauth_service_name],
1028                   Pacemaker::Resource::Service[$::nova::params::vncproxy_service_name]],
1029     }
1030     pacemaker::constraint::colocation { 'nova-vncproxy-with-nova-consoleauth-colocation':
1031       source => "${::nova::params::vncproxy_service_name}-clone",
1032       target => "${::nova::params::consoleauth_service_name}-clone",
1033       score => "INFINITY",
1034       require => [Pacemaker::Resource::Service[$::nova::params::consoleauth_service_name],
1035                   Pacemaker::Resource::Service[$::nova::params::vncproxy_service_name]],
1036     }
1037     # FIXME(gfidente): novncproxy will not start unless websockify is updated to 0.6
1038     # which is not the case for f20 nor f21; ucomment when it becomes available
1039     #pacemaker::constraint::base { 'nova-vncproxy-then-nova-api-constraint':
1040     #  constraint_type => "order",
1041     #  first_resource  => "${::nova::params::vncproxy_service_name}-clone",
1042     #  second_resource => "${::nova::params::api_service_name}-clone",
1043     #  first_action    => "start",
1044     #  second_action   => "start",
1045     #  require => [Pacemaker::Resource::Service[$::nova::params::vncproxy_service_name],
1046     #              Pacemaker::Resource::Service[$::nova::params::api_service_name]],
1047     #}
1048     #pacemaker::constraint::colocation { 'nova-api-with-nova-vncproxy-colocation':
1049     #  source => "${::nova::params::api_service_name}-clone",
1050     #  target => "${::nova::params::vncproxy_service_name}-clone",
1051     #  score => "INFINITY",
1052     #  require => [Pacemaker::Resource::Service[$::nova::params::vncproxy_service_name],
1053     #              Pacemaker::Resource::Service[$::nova::params::api_service_name]],
1054     #}
1055     pacemaker::constraint::base { 'nova-api-then-nova-scheduler-constraint':
1056       constraint_type => "order",
1057       first_resource  => "${::nova::params::api_service_name}-clone",
1058       second_resource => "${::nova::params::scheduler_service_name}-clone",
1059       first_action    => "start",
1060       second_action   => "start",
1061       require => [Pacemaker::Resource::Service[$::nova::params::api_service_name],
1062                   Pacemaker::Resource::Service[$::nova::params::scheduler_service_name]],
1063     }
1064     pacemaker::constraint::colocation { 'nova-scheduler-with-nova-api-colocation':
1065       source => "${::nova::params::scheduler_service_name}-clone",
1066       target => "${::nova::params::api_service_name}-clone",
1067       score => "INFINITY",
1068       require => [Pacemaker::Resource::Service[$::nova::params::api_service_name],
1069                   Pacemaker::Resource::Service[$::nova::params::scheduler_service_name]],
1070     }
1071     pacemaker::constraint::base { 'nova-scheduler-then-nova-conductor-constraint':
1072       constraint_type => "order",
1073       first_resource  => "${::nova::params::scheduler_service_name}-clone",
1074       second_resource => "${::nova::params::conductor_service_name}-clone",
1075       first_action    => "start",
1076       second_action   => "start",
1077       require => [Pacemaker::Resource::Service[$::nova::params::scheduler_service_name],
1078                   Pacemaker::Resource::Service[$::nova::params::conductor_service_name]],
1079     }
1080     pacemaker::constraint::colocation { 'nova-conductor-with-nova-scheduler-colocation':
1081       source => "${::nova::params::conductor_service_name}-clone",
1082       target => "${::nova::params::scheduler_service_name}-clone",
1083       score => "INFINITY",
1084       require => [Pacemaker::Resource::Service[$::nova::params::scheduler_service_name],
1085                   Pacemaker::Resource::Service[$::nova::params::conductor_service_name]],
1086     }
1087
1088     # Ceilometer
1089     pacemaker::resource::service { $::ceilometer::params::agent_central_service_name :
1090       clone_params => 'interleave=true',
1091       require      => [Pacemaker::Resource::Service[$::keystone::params::service_name],
1092                        Pacemaker::Resource::Service[$::mongodb::params::service_name]],
1093     }
1094     pacemaker::resource::service { $::ceilometer::params::collector_service_name :
1095       clone_params => 'interleave=true',
1096     }
1097     pacemaker::resource::service { $::ceilometer::params::api_service_name :
1098       clone_params => 'interleave=true',
1099     }
1100     pacemaker::resource::service { $::ceilometer::params::alarm_evaluator_service_name :
1101       clone_params => 'interleave=true',
1102     }
1103     pacemaker::resource::service { $::ceilometer::params::alarm_notifier_service_name :
1104       clone_params => 'interleave=true',
1105     }
1106     pacemaker::resource::service { $::ceilometer::params::agent_notification_service_name :
1107       clone_params => 'interleave=true',
1108     }
1109     pacemaker::resource::ocf { 'delay' :
1110       ocf_agent_name  => 'heartbeat:Delay',
1111       clone_params    => 'interleave=true',
1112       resource_params => 'startdelay=10',
1113     }
1114     pacemaker::constraint::base { 'ceilometer-central-then-ceilometer-collector-constraint':
1115       constraint_type => 'order',
1116       first_resource  => "${::ceilometer::params::agent_central_service_name}-clone",
1117       second_resource => "${::ceilometer::params::collector_service_name}-clone",
1118       first_action    => 'start',
1119       second_action   => 'start',
1120       require         => [Pacemaker::Resource::Service[$::ceilometer::params::agent_central_service_name],
1121                           Pacemaker::Resource::Service[$::ceilometer::params::collector_service_name]],
1122     }
1123     pacemaker::constraint::base { 'ceilometer-collector-then-ceilometer-api-constraint':
1124       constraint_type => 'order',
1125       first_resource  => "${::ceilometer::params::collector_service_name}-clone",
1126       second_resource => "${::ceilometer::params::api_service_name}-clone",
1127       first_action    => 'start',
1128       second_action   => 'start',
1129       require         => [Pacemaker::Resource::Service[$::ceilometer::params::collector_service_name],
1130                           Pacemaker::Resource::Service[$::ceilometer::params::api_service_name]],
1131     }
1132     pacemaker::constraint::colocation { 'ceilometer-api-with-ceilometer-collector-colocation':
1133       source  => "${::ceilometer::params::api_service_name}-clone",
1134       target  => "${::ceilometer::params::collector_service_name}-clone",
1135       score   => 'INFINITY',
1136       require => [Pacemaker::Resource::Service[$::ceilometer::params::api_service_name],
1137                   Pacemaker::Resource::Service[$::ceilometer::params::collector_service_name]],
1138     }
1139     pacemaker::constraint::base { 'ceilometer-api-then-ceilometer-delay-constraint':
1140       constraint_type => 'order',
1141       first_resource  => "${::ceilometer::params::api_service_name}-clone",
1142       second_resource => 'delay-clone',
1143       first_action    => 'start',
1144       second_action   => 'start',
1145       require         => [Pacemaker::Resource::Service[$::ceilometer::params::api_service_name],
1146                           Pacemaker::Resource::Ocf['delay']],
1147     }
1148     pacemaker::constraint::colocation { 'ceilometer-delay-with-ceilometer-api-colocation':
1149       source  => 'delay-clone',
1150       target  => "${::ceilometer::params::api_service_name}-clone",
1151       score   => 'INFINITY',
1152       require => [Pacemaker::Resource::Service[$::ceilometer::params::api_service_name],
1153                   Pacemaker::Resource::Ocf['delay']],
1154     }
1155     pacemaker::constraint::base { 'ceilometer-delay-then-ceilometer-alarm-evaluator-constraint':
1156       constraint_type => 'order',
1157       first_resource  => 'delay-clone',
1158       second_resource => "${::ceilometer::params::alarm_evaluator_service_name}-clone",
1159       first_action    => 'start',
1160       second_action   => 'start',
1161       require         => [Pacemaker::Resource::Service[$::ceilometer::params::alarm_evaluator_service_name],
1162                           Pacemaker::Resource::Ocf['delay']],
1163     }
1164     pacemaker::constraint::colocation { 'ceilometer-alarm-evaluator-with-ceilometer-delay-colocation':
1165       source  => "${::ceilometer::params::alarm_evaluator_service_name}-clone",
1166       target  => 'delay-clone',
1167       score   => 'INFINITY',
1168       require => [Pacemaker::Resource::Service[$::ceilometer::params::api_service_name],
1169                   Pacemaker::Resource::Ocf['delay']],
1170     }
1171     pacemaker::constraint::base { 'ceilometer-alarm-evaluator-then-ceilometer-alarm-notifier-constraint':
1172       constraint_type => 'order',
1173       first_resource  => "${::ceilometer::params::alarm_evaluator_service_name}-clone",
1174       second_resource => "${::ceilometer::params::alarm_notifier_service_name}-clone",
1175       first_action    => 'start',
1176       second_action   => 'start',
1177       require         => [Pacemaker::Resource::Service[$::ceilometer::params::alarm_evaluator_service_name],
1178                           Pacemaker::Resource::Service[$::ceilometer::params::alarm_notifier_service_name]],
1179     }
1180     pacemaker::constraint::colocation { 'ceilometer-alarm-notifier-with-ceilometer-alarm-evaluator-colocation':
1181       source  => "${::ceilometer::params::alarm_notifier_service_name}-clone",
1182       target  => "${::ceilometer::params::alarm_evaluator_service_name}-clone",
1183       score   => 'INFINITY',
1184       require => [Pacemaker::Resource::Service[$::ceilometer::params::alarm_evaluator_service_name],
1185                   Pacemaker::Resource::Service[$::ceilometer::params::alarm_notifier_service_name]],
1186     }
1187     pacemaker::constraint::base { 'ceilometer-alarm-notifier-then-ceilometer-notification-constraint':
1188       constraint_type => 'order',
1189       first_resource  => "${::ceilometer::params::alarm_notifier_service_name}-clone",
1190       second_resource => "${::ceilometer::params::agent_notification_service_name}-clone",
1191       first_action    => 'start',
1192       second_action   => 'start',
1193       require         => [Pacemaker::Resource::Service[$::ceilometer::params::agent_notification_service_name],
1194                           Pacemaker::Resource::Service[$::ceilometer::params::alarm_notifier_service_name]],
1195     }
1196     pacemaker::constraint::colocation { 'ceilometer-notification-with-ceilometer-alarm-notifier-colocation':
1197       source  => "${::ceilometer::params::agent_notification_service_name}-clone",
1198       target  => "${::ceilometer::params::alarm_notifier_service_name}-clone",
1199       score   => 'INFINITY',
1200       require => [Pacemaker::Resource::Service[$::ceilometer::params::agent_notification_service_name],
1201                   Pacemaker::Resource::Service[$::ceilometer::params::alarm_notifier_service_name]],
1202     }
1203     if downcase(hiera('ceilometer_backend')) == 'mongodb' {
1204       pacemaker::constraint::base { 'mongodb-then-ceilometer-central-constraint':
1205         constraint_type => 'order',
1206         first_resource  => "${::mongodb::params::service_name}-clone",
1207         second_resource => "${::ceilometer::params::agent_central_service_name}-clone",
1208         first_action    => 'start',
1209         second_action   => 'start',
1210         require         => [Pacemaker::Resource::Service[$::ceilometer::params::agent_central_service_name],
1211                             Pacemaker::Resource::Service[$::mongodb::params::service_name]],
1212       }
1213     }
1214     pacemaker::constraint::base { 'vip-redis-then-ceilometer-central':
1215       constraint_type => 'order',
1216       first_resource  => "ip-${redis_vip}",
1217       second_resource => "${::ceilometer::params::agent_central_service_name}-clone",
1218       first_action    => 'start',
1219       second_action   => 'start',
1220       require => [Pacemaker::Resource::Service[$::ceilometer::params::agent_central_service_name],
1221                   Pacemaker::Resource::Ip['vip-redis']],
1222     }
1223     pacemaker::constraint::base { 'keystone-then-ceilometer-central-constraint':
1224       constraint_type => 'order',
1225       first_resource  => "${::keystone::params::service_name}-clone",
1226       second_resource => "${::ceilometer::params::agent_central_service_name}-clone",
1227       first_action    => 'start',
1228       second_action   => 'start',
1229       require         => [Pacemaker::Resource::Service[$::ceilometer::params::agent_central_service_name],
1230                           Pacemaker::Resource::Service[$::keystone::params::service_name]],
1231     }
1232
1233     # Heat
1234     pacemaker::resource::service { $::heat::params::api_service_name :
1235       clone_params => 'interleave=true',
1236     }
1237     pacemaker::resource::service { $::heat::params::api_cloudwatch_service_name :
1238       clone_params => 'interleave=true',
1239     }
1240     pacemaker::resource::service { $::heat::params::api_cfn_service_name :
1241       clone_params => 'interleave=true',
1242     }
1243     pacemaker::resource::service { $::heat::params::engine_service_name :
1244       clone_params => 'interleave=true',
1245     }
1246     pacemaker::constraint::base { 'heat-api-then-heat-api-cfn-constraint':
1247       constraint_type => 'order',
1248       first_resource  => "${::heat::params::api_service_name}-clone",
1249       second_resource => "${::heat::params::api_cfn_service_name}-clone",
1250       first_action    => 'start',
1251       second_action   => 'start',
1252       require => [Pacemaker::Resource::Service[$::heat::params::api_service_name],
1253                   Pacemaker::Resource::Service[$::heat::params::api_cfn_service_name]],
1254     }
1255     pacemaker::constraint::colocation { 'heat-api-cfn-with-heat-api-colocation':
1256       source  => "${::heat::params::api_cfn_service_name}-clone",
1257       target  => "${::heat::params::api_service_name}-clone",
1258       score   => 'INFINITY',
1259       require => [Pacemaker::Resource::Service[$::heat::params::api_cfn_service_name],
1260                   Pacemaker::Resource::Service[$::heat::params::api_service_name]],
1261     }
1262     pacemaker::constraint::base { 'heat-api-cfn-then-heat-api-cloudwatch-constraint':
1263       constraint_type => 'order',
1264       first_resource  => "${::heat::params::api_cfn_service_name}-clone",
1265       second_resource => "${::heat::params::api_cloudwatch_service_name}-clone",
1266       first_action    => 'start',
1267       second_action   => 'start',
1268       require => [Pacemaker::Resource::Service[$::heat::params::api_cloudwatch_service_name],
1269                   Pacemaker::Resource::Service[$::heat::params::api_cfn_service_name]],
1270     }
1271     pacemaker::constraint::colocation { 'heat-api-cloudwatch-with-heat-api-cfn-colocation':
1272       source  => "${::heat::params::api_cloudwatch_service_name}-clone",
1273       target  => "${::heat::params::api_cfn_service_name}-clone",
1274       score   => 'INFINITY',
1275       require => [Pacemaker::Resource::Service[$::heat::params::api_cfn_service_name],
1276                   Pacemaker::Resource::Service[$::heat::params::api_cloudwatch_service_name]],
1277     }
1278     pacemaker::constraint::base { 'heat-api-cloudwatch-then-heat-engine-constraint':
1279       constraint_type => 'order',
1280       first_resource  => "${::heat::params::api_cloudwatch_service_name}-clone",
1281       second_resource => "${::heat::params::engine_service_name}-clone",
1282       first_action    => 'start',
1283       second_action   => 'start',
1284       require => [Pacemaker::Resource::Service[$::heat::params::api_cloudwatch_service_name],
1285                   Pacemaker::Resource::Service[$::heat::params::engine_service_name]],
1286     }
1287     pacemaker::constraint::colocation { 'heat-engine-with-heat-api-cloudwatch-colocation':
1288       source  => "${::heat::params::engine_service_name}-clone",
1289       target  => "${::heat::params::api_cloudwatch_service_name}-clone",
1290       score   => 'INFINITY',
1291       require => [Pacemaker::Resource::Service[$::heat::params::api_cloudwatch_service_name],
1292                   Pacemaker::Resource::Service[$::heat::params::engine_service_name]],
1293     }
1294     pacemaker::constraint::base { 'ceilometer-notification-then-heat-api-constraint':
1295       constraint_type => 'order',
1296       first_resource  => "${::ceilometer::params::agent_notification_service_name}-clone",
1297       second_resource => "${::heat::params::api_service_name}-clone",
1298       first_action    => 'start',
1299       second_action   => 'start',
1300       require         => [Pacemaker::Resource::Service[$::heat::params::api_service_name],
1301                           Pacemaker::Resource::Service[$::ceilometer::params::agent_notification_service_name]],
1302     }
1303
1304     # Horizon
1305     pacemaker::resource::service { $::horizon::params::http_service:
1306         clone_params => "interleave=true",
1307     }
1308
1309
1310   }
1311
1312 } #END STEP 4