Merge "Use SoftwareDeployments for consistency in extraconfig"
[apex-tripleo-heat-templates.git] / puppet / manifests / overcloud_controller_pacemaker.pp
1 # Copyright 2015 Red Hat, Inc.
2 # All Rights Reserved.
3 #
4 # Licensed under the Apache License, Version 2.0 (the "License"); you may
5 # not use this file except in compliance with the License. You may obtain
6 # a copy of the License at
7 #
8 #     http://www.apache.org/licenses/LICENSE-2.0
9 #
10 # Unless required by applicable law or agreed to in writing, software
11 # distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
12 # WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
13 # License for the specific language governing permissions and limitations
14 # under the License.
15
16 Pcmk_resource <| |> {
17   tries     => 10,
18   try_sleep => 3,
19 }
20
21 if !str2bool(hiera('enable_package_install', 'false')) {
22   case $::osfamily {
23     'RedHat': {
24       Package { provider => 'norpm' } # provided by tripleo-puppet
25     }
26     default: {
27       warning('enable_package_install option not supported.')
28     }
29   }
30 }
31
32 if $::hostname == downcase(hiera('bootstrap_nodeid')) {
33   $pacemaker_master = true
34   $sync_db = true
35 } else {
36   $pacemaker_master = false
37   $sync_db = false
38 }
39
40 # When to start and enable services which haven't been Pacemakerized
41 # FIXME: remove when we start all OpenStack services using Pacemaker
42 # (occurences of this variable will be gradually replaced with false)
43 $non_pcmk_start = hiera('step') >= 4
44
45 if hiera('step') >= 1 {
46
47   create_resources(sysctl::value, hiera('sysctl_settings'), {})
48
49   if count(hiera('ntp::servers')) > 0 {
50     include ::ntp
51   }
52
53   $controller_node_ips = split(hiera('controller_node_ips'), ',')
54   $controller_node_names = split(downcase(hiera('controller_node_names')), ',')
55   class { '::tripleo::loadbalancer' :
56     controller_hosts       => $controller_node_ips,
57     controller_hosts_names => $controller_node_names,
58     redis                  => true,
59     manage_vip             => false,
60     haproxy_service_manage => false,
61   }
62
63   $pacemaker_cluster_members = downcase(regsubst(hiera('controller_node_names'), ',', ' ', 'G'))
64   user { 'hacluster':
65    ensure => present,
66   } ->
67   class { '::pacemaker':
68     hacluster_pwd => hiera('hacluster_pwd'),
69   } ->
70   class { '::pacemaker::corosync':
71     cluster_members => $pacemaker_cluster_members,
72     setup_cluster   => $pacemaker_master,
73   }
74   class { '::pacemaker::stonith':
75     disable => true,
76   }
77
78   # Only configure RabbitMQ in this step, don't start it yet to
79   # avoid races where non-master nodes attempt to start without
80   # config (eg. binding on 0.0.0.0)
81   # The module ignores erlang_cookie if cluster_config is false
82   class { '::rabbitmq':
83     service_manage          => false,
84     tcp_keepalive           => false,
85     config_kernel_variables => hiera('rabbitmq_kernel_variables'),
86     config_variables        => hiera('rabbitmq_config_variables'),
87     environment_variables   => hiera('rabbitmq_environment'),
88   } ->
89   file { '/var/lib/rabbitmq/.erlang.cookie':
90     ensure  => 'present',
91     owner   => 'rabbitmq',
92     group   => 'rabbitmq',
93     mode    => '0400',
94     content => hiera('rabbitmq::erlang_cookie'),
95     replace => true,
96   }
97
98   if downcase(hiera('ceilometer_backend')) == 'mongodb' {
99     include ::mongodb::globals
100     class { '::mongodb::server' :
101       service_manage => false,
102     }
103   }
104
105   # Memcached
106   class {'::memcached' :
107     service_manage => false,
108   }
109
110   # Redis
111   class { '::redis' :
112     service_manage => false,
113     notify_service => false,
114   }
115
116   # Galera
117   if str2bool(hiera('enable_galera', 'true')) {
118     $mysql_config_file = '/etc/my.cnf.d/galera.cnf'
119   } else {
120     $mysql_config_file = '/etc/my.cnf.d/server.cnf'
121   }
122   $galera_nodes = downcase(hiera('galera_node_names', $::hostname))
123   $galera_nodes_count = count(split($galera_nodes, ','))
124
125   $mysqld_options = {
126     'mysqld' => {
127       'skip-name-resolve'             => '1',
128       'binlog_format'                 => 'ROW',
129       'default-storage-engine'        => 'innodb',
130       'innodb_autoinc_lock_mode'      => '2',
131       'innodb_locks_unsafe_for_binlog'=> '1',
132       'query_cache_size'              => '0',
133       'query_cache_type'              => '0',
134       'bind-address'                  => hiera('mysql_bind_host'),
135       'max_connections'               => '1024',
136       'open_files_limit'              => '-1',
137       'wsrep_provider'                => '/usr/lib64/galera/libgalera_smm.so',
138       'wsrep_cluster_name'            => 'galera_cluster',
139       'wsrep_slave_threads'           => '1',
140       'wsrep_certify_nonPK'           => '1',
141       'wsrep_max_ws_rows'             => '131072',
142       'wsrep_max_ws_size'             => '1073741824',
143       'wsrep_debug'                   => '0',
144       'wsrep_convert_LOCK_to_trx'     => '0',
145       'wsrep_retry_autocommit'        => '1',
146       'wsrep_auto_increment_control'  => '1',
147       'wsrep_drupal_282555_workaround'=> '0',
148       'wsrep_causal_reads'            => '0',
149       'wsrep_notify_cmd'              => '',
150       'wsrep_sst_method'              => 'rsync',
151     }
152   }
153
154   class { '::mysql::server':
155     create_root_user   => false,
156     create_root_my_cnf => false,
157     config_file        => $mysql_config_file,
158     override_options   => $mysqld_options,
159     service_manage     => false,
160   }
161
162 }
163
164 if hiera('step') >= 2 {
165
166   if $pacemaker_master {
167
168     # FIXME: we should not have to access tripleo::loadbalancer class
169     # parameters here to configure pacemaker VIPs. The configuration
170     # of pacemaker VIPs could move into puppet-tripleo or we should
171     # make use of less specific hiera parameters here for the settings.
172     $control_vip = hiera('tripleo::loadbalancer::controller_virtual_ip')
173     pacemaker::resource::ip { 'control_vip':
174       ip_address => $control_vip,
175     }
176     $public_vip = hiera('tripleo::loadbalancer::public_virtual_ip')
177     pacemaker::resource::ip { 'public_vip':
178       ip_address => $public_vip,
179     }
180
181     $internal_api_vip = hiera('tripleo::loadbalancer::internal_api_virtual_ip')
182     if $internal_api_vip and $internal_api_vip != $control_vip {
183       pacemaker::resource::ip { 'internal_api_vip':
184         ip_address => $internal_api_vip,
185       }
186     }
187
188     $storage_vip = hiera('tripleo::loadbalancer::storage_virtual_ip')
189     if $storage_vip and $storage_vip != $control_vip {
190       pacemaker::resource::ip { 'storage_vip':
191         ip_address => $storage_vip,
192       }
193     }
194
195     $storage_mgmt_vip = hiera('tripleo::loadbalancer::storage_mgmt_virtual_ip')
196     if $storage_mgmt_vip and $storage_mgmt_vip != $control_vip {
197       pacemaker::resource::ip { 'storage_mgmt_vip':
198         ip_address => $storage_mgmt_vip,
199       }
200     }
201
202     pacemaker::resource::service { 'haproxy':
203       clone_params => true,
204     }
205     pacemaker::resource::service { $::memcached::params::service_name :
206       clone_params => true,
207       require      => Class['::memcached'],
208     }
209
210     pacemaker::resource::ocf { 'rabbitmq':
211       ocf_agent_name  => 'heartbeat:rabbitmq-cluster',
212       resource_params => 'set_policy=\'ha-all ^(?!amq\.).* {"ha-mode":"all"}\'',
213       clone_params    => 'ordered=true interleave=true',
214       require         => Class['::rabbitmq'],
215     }
216
217     if downcase(hiera('ceilometer_backend')) == 'mongodb' {
218       pacemaker::resource::service { $::mongodb::params::service_name :
219         op_params    => 'start timeout=120s',
220         clone_params => true,
221         require      => Class['::mongodb::server'],
222       }
223       # NOTE (spredzy) : The replset can only be run
224       # once all the nodes have joined the cluster.
225       $mongo_node_ips = hiera('mongo_node_ips')
226       $mongo_node_ips_with_port = suffix($mongo_node_ips, ':27017')
227       $mongo_node_string = join($mongo_node_ips_with_port, ',')
228       $mongodb_pacemaker_resource = Pacemaker::Resource::Service[$::mongodb::params::service_name]
229       $mongodb_replset = hiera('mongodb::server::replset')
230       mongodb_conn_validator { $mongo_node_ips_with_port :
231         require => Pacemaker::Resource::Service[$::mongodb::params::service_name],
232         before  => Mongodb_replset[$mongodb_replset],
233       }
234       mongodb_replset { $mongodb_replset :
235         members => $mongo_node_ips_with_port,
236       }
237     }
238
239     pacemaker::resource::ocf { 'galera' :
240       ocf_agent_name  => 'heartbeat:galera',
241       op_params       => 'promote timeout=300s on-fail=block',
242       master_params   => '',
243       meta_params     => "master-max=${galera_nodes_count} ordered=true",
244       resource_params => "additional_parameters='--open-files-limit=16384' enable_creation=true wsrep_cluster_address='gcomm://${galera_nodes}'",
245       require         => Class['::mysql::server'],
246       before          => Exec['galera-ready'],
247     }
248
249     pacemaker::resource::ocf { 'redis':
250       ocf_agent_name  => 'heartbeat:redis',
251       master_params   => '',
252       meta_params     => 'notify=true ordered=true interleave=true',
253       resource_params => 'wait_last_known_master=true',
254       require         => Class['::redis'],
255     }
256     $redis_vip = hiera('redis_vip')
257     if $redis_vip and $redis_vip != $control_vip {
258         pacemaker::resource::ip { 'vip-redis':
259           ip_address => $redis_vip,
260         }
261     }
262     pacemaker::constraint::base { 'redis-master-then-vip-redis':
263       constraint_type => 'order',
264       first_resource  => 'redis-master',
265       second_resource => "ip-${redis_vip}",
266       first_action    => 'promote',
267       second_action   => 'start',
268       require => [Pacemaker::Resource::Ocf['redis'],
269                   Pacemaker::Resource::Ip['vip-redis']],
270     }
271     pacemaker::constraint::colocation { 'vip-redis-with-redis-master':
272       source  => "ip-${redis_vip}",
273       target  => 'redis-master',
274       score   => 'INFINITY',
275       require => [Pacemaker::Resource::Ocf['redis'],
276                   Pacemaker::Resource::Ip['vip-redis']],
277     }
278
279   }
280
281   exec { 'galera-ready' :
282     command     => '/usr/bin/clustercheck >/dev/null',
283     timeout     => 30,
284     tries       => 180,
285     try_sleep   => 10,
286     environment => ["AVAILABLE_WHEN_READONLY=0"],
287     require     => File['/etc/sysconfig/clustercheck'],
288   }
289
290   file { '/etc/sysconfig/clustercheck' :
291     ensure  => file,
292     content => "MYSQL_USERNAME=root\n
293 MYSQL_PASSWORD=''\n
294 MYSQL_HOST=localhost\n",
295   }
296
297   xinetd::service { 'galera-monitor' :
298     port           => '9200',
299     server         => '/usr/bin/clustercheck',
300     per_source     => 'UNLIMITED',
301     log_on_success => '',
302     log_on_failure => 'HOST',
303     flags          => 'REUSE',
304     service_type   => 'UNLISTED',
305     user           => 'root',
306     group          => 'root',
307     require        => File['/etc/sysconfig/clustercheck'],
308   }
309
310   # Create all the database schemas
311   # Example DSN format: mysql://user:password@host/dbname
312   if $sync_db {
313     $allowed_hosts = ['%',hiera('mysql_bind_host')]
314     $keystone_dsn = split(hiera('keystone::database_connection'), '[@:/?]')
315     class { 'keystone::db::mysql':
316       user          => $keystone_dsn[3],
317       password      => $keystone_dsn[4],
318       host          => $keystone_dsn[5],
319       dbname        => $keystone_dsn[6],
320       allowed_hosts => $allowed_hosts,
321       require       => Exec['galera-ready'],
322     }
323     $glance_dsn = split(hiera('glance::api::database_connection'), '[@:/?]')
324     class { 'glance::db::mysql':
325       user          => $glance_dsn[3],
326       password      => $glance_dsn[4],
327       host          => $glance_dsn[5],
328       dbname        => $glance_dsn[6],
329       allowed_hosts => $allowed_hosts,
330       require       => Exec['galera-ready'],
331     }
332     $nova_dsn = split(hiera('nova::database_connection'), '[@:/?]')
333     class { 'nova::db::mysql':
334       user          => $nova_dsn[3],
335       password      => $nova_dsn[4],
336       host          => $nova_dsn[5],
337       dbname        => $nova_dsn[6],
338       allowed_hosts => $allowed_hosts,
339       require       => Exec['galera-ready'],
340     }
341     $neutron_dsn = split(hiera('neutron::server::database_connection'), '[@:/?]')
342     class { 'neutron::db::mysql':
343       user          => $neutron_dsn[3],
344       password      => $neutron_dsn[4],
345       host          => $neutron_dsn[5],
346       dbname        => $neutron_dsn[6],
347       allowed_hosts => $allowed_hosts,
348       require       => Exec['galera-ready'],
349     }
350     $cinder_dsn = split(hiera('cinder::database_connection'), '[@:/?]')
351     class { 'cinder::db::mysql':
352       user          => $cinder_dsn[3],
353       password      => $cinder_dsn[4],
354       host          => $cinder_dsn[5],
355       dbname        => $cinder_dsn[6],
356       allowed_hosts => $allowed_hosts,
357       require       => Exec['galera-ready'],
358     }
359     $heat_dsn = split(hiera('heat::database_connection'), '[@:/?]')
360     class { 'heat::db::mysql':
361       user          => $heat_dsn[3],
362       password      => $heat_dsn[4],
363       host          => $heat_dsn[5],
364       dbname        => $heat_dsn[6],
365       allowed_hosts => $allowed_hosts,
366       require       => Exec['galera-ready'],
367     }
368     if downcase(hiera('ceilometer_backend')) == 'mysql' {
369       $ceilometer_dsn = split(hiera('ceilometer_mysql_conn_string'), '[@:/?]')
370       class { 'ceilometer::db::mysql':
371         user          => $ceilometer_dsn[3],
372         password      => $ceilometer_dsn[4],
373         host          => $ceilometer_dsn[5],
374         dbname        => $ceilometer_dsn[6],
375         allowed_hosts => $allowed_hosts,
376         require       => Exec['galera-ready'],
377       }
378     }
379   }
380
381   # pre-install swift here so we can build rings
382   include ::swift
383
384   # Ceph
385   $cinder_enable_rbd_backend = hiera('cinder_enable_rbd_backend', false)
386   $enable_ceph = $cinder_enable_rbd_backend
387
388   if $enable_ceph {
389     class { 'ceph::profile::params':
390       mon_initial_members => downcase(hiera('ceph_mon_initial_members'))
391     }
392     include ::ceph::profile::mon
393   }
394
395   if str2bool(hiera('enable_ceph_storage', 'false')) {
396     include ::ceph::profile::client
397     include ::ceph::profile::osd
398   }
399
400
401 } #END STEP 2
402
403 if hiera('step') >= 3 {
404
405   class { '::keystone':
406     sync_db => $sync_db,
407     manage_service => false,
408     enabled => false,
409   }
410
411   #TODO: need a cleanup-keystone-tokens.sh solution here
412   keystone_config {
413     'ec2/driver': value => 'keystone.contrib.ec2.backends.sql.Ec2';
414   }
415   file { [ '/etc/keystone/ssl', '/etc/keystone/ssl/certs', '/etc/keystone/ssl/private' ]:
416     ensure  => 'directory',
417     owner   => 'keystone',
418     group   => 'keystone',
419     require => Package['keystone'],
420   }
421   file { '/etc/keystone/ssl/certs/signing_cert.pem':
422     content => hiera('keystone_signing_certificate'),
423     owner   => 'keystone',
424     group   => 'keystone',
425     notify  => Service['keystone'],
426     require => File['/etc/keystone/ssl/certs'],
427   }
428   file { '/etc/keystone/ssl/private/signing_key.pem':
429     content => hiera('keystone_signing_key'),
430     owner   => 'keystone',
431     group   => 'keystone',
432     notify  => Service['keystone'],
433     require => File['/etc/keystone/ssl/private'],
434   }
435   file { '/etc/keystone/ssl/certs/ca.pem':
436     content => hiera('keystone_ca_certificate'),
437     owner   => 'keystone',
438     group   => 'keystone',
439     notify  => Service['keystone'],
440     require => File['/etc/keystone/ssl/certs'],
441   }
442
443   $glance_backend = downcase(hiera('glance_backend', 'swift'))
444   case $glance_backend {
445       swift: { $glance_store = 'glance.store.swift.Store' }
446       file: { $glance_store = 'glance.store.filesystem.Store' }
447       rbd: { $glance_store = 'glance.store.rbd.Store' }
448       default: { fail('Unrecognized glance_backend parameter.') }
449   }
450
451   # TODO: notifications, scrubber, etc.
452   include ::glance
453   class { 'glance::api':
454     known_stores => [$glance_store],
455     manage_service => false,
456     enabled => false,
457   }
458   class { '::glance::registry' :
459     sync_db => $sync_db,
460     manage_service => false,
461     enabled => false,
462   }
463   include join(['::glance::backend::', $glance_backend])
464
465   include ::nova
466
467   class { '::nova::api' :
468     sync_db => $sync_db,
469     manage_service => false,
470     enabled => false,
471   }
472   class { '::nova::cert' :
473     manage_service => false,
474     enabled => false,
475   }
476   class { '::nova::conductor' :
477     manage_service => false,
478     enabled => false,
479   }
480   class { '::nova::consoleauth' :
481     manage_service => false,
482     enabled => false,
483   }
484   class { '::nova::vncproxy' :
485     manage_service => false,
486     enabled => false,
487   }
488   class { '::nova::scheduler' :
489     manage_service => false,
490     enabled => false,
491   }
492   include ::nova::network::neutron
493
494   # Neutron class definitions
495   include ::neutron
496   class { '::neutron::server' :
497     sync_db => $sync_db,
498     manage_service => false,
499     enabled => false,
500   }
501   class { '::neutron::agents::dhcp' :
502     manage_service => false,
503     enabled => false,
504   }
505   class { '::neutron::agents::l3' :
506     manage_service => false,
507     enabled => false,
508   }
509   class { 'neutron::agents::metadata':
510     manage_service => false,
511     enabled => false,
512   }
513   file { '/etc/neutron/dnsmasq-neutron.conf':
514     content => hiera('neutron_dnsmasq_options'),
515     owner   => 'neutron',
516     group   => 'neutron',
517     notify  => Service['neutron-dhcp-service'],
518     require => Package['neutron'],
519   }
520   class { 'neutron::plugins::ml2':
521     flat_networks   => split(hiera('neutron_flat_networks'), ','),
522     tenant_network_types => [hiera('neutron_tenant_network_type')],
523   }
524   class { 'neutron::agents::ml2::ovs':
525     # manage_service   => false # not implemented
526     enabled          => false,
527     bridge_mappings  => split(hiera('neutron_bridge_mappings'), ','),
528     tunnel_types     => split(hiera('neutron_tunnel_types'), ','),
529   }
530
531   include ::cinder
532   class { '::cinder::api':
533     sync_db => $sync_db,
534     manage_service => false,
535     enabled => false,
536   }
537   class { '::cinder::scheduler' :
538     manage_service => false,
539     enabled => false,
540   }
541   class { '::cinder::volume' :
542     manage_service => false,
543     enabled => false,
544   }
545   include ::cinder::glance
546   class {'cinder::setup_test_volume':
547     size => join([hiera('cinder_lvm_loop_device_size'), 'M']),
548   }
549
550   $cinder_enable_iscsi = hiera('cinder_enable_iscsi_backend', true)
551   if $cinder_enable_iscsi {
552     $cinder_iscsi_backend = 'tripleo_iscsi'
553
554     cinder::backend::iscsi { $cinder_iscsi_backend :
555       iscsi_ip_address => hiera('cinder_iscsi_ip_address'),
556       iscsi_helper     => hiera('cinder_iscsi_helper'),
557     }
558   }
559
560   if $enable_ceph {
561
562     Ceph_pool {
563       pg_num  => hiera('ceph::profile::params::osd_pool_default_pg_num'),
564       pgp_num => hiera('ceph::profile::params::osd_pool_default_pgp_num'),
565       size    => hiera('ceph::profile::params::osd_pool_default_size'),
566     }
567
568     $ceph_pools = hiera('ceph_pools')
569     ceph::pool { $ceph_pools : }
570   }
571
572   if $cinder_enable_rbd_backend {
573     $cinder_rbd_backend = 'tripleo_ceph'
574
575     cinder_config {
576       "${cinder_rbd_backend}/host": value => 'hostgroup';
577     }
578
579     cinder::backend::rbd { $cinder_rbd_backend :
580       rbd_pool        => 'volumes',
581       rbd_user        => 'openstack',
582       rbd_secret_uuid => hiera('ceph::profile::params::fsid'),
583       require         => Ceph::Pool['volumes'],
584     }
585   }
586
587   if hiera('cinder_enable_netapp_backend', false) {
588     $cinder_netapp_backend = hiera('cinder::backend::netapp::title')
589
590     cinder_config {
591       "${cinder_netapp_backend}/host": value => 'hostgroup';
592     }
593
594     if hiera('cinder_netapp_nfs_shares', undef) {
595       $cinder_netapp_nfs_shares = split(hiera('cinder_netapp_nfs_shares', undef), ',')
596     }
597
598     cinder::backend::netapp { $cinder_netapp_backend :
599       nfs_shares => $cinder_netapp_nfs_shares,
600     }
601   }
602
603   $cinder_enabled_backends = delete_undef_values([$cinder_iscsi_backend, $cinder_rbd_backend, $cinder_netapp_backend])
604   class { '::cinder::backends' :
605     enabled_backends => $cinder_enabled_backends,
606   }
607
608   # swift proxy
609   class { '::swift::proxy' :
610     manage_service => $non_pcmk_start,
611     enabled => $non_pcmk_start,
612   }
613   include ::swift::proxy::proxy_logging
614   include ::swift::proxy::healthcheck
615   include ::swift::proxy::cache
616   include ::swift::proxy::keystone
617   include ::swift::proxy::authtoken
618   include ::swift::proxy::staticweb
619   include ::swift::proxy::ceilometer
620   include ::swift::proxy::ratelimit
621   include ::swift::proxy::catch_errors
622   include ::swift::proxy::tempurl
623   include ::swift::proxy::formpost
624
625   # swift storage
626   if str2bool(hiera('enable_swift_storage', 'true')) {
627     class {'::swift::storage::all':
628       mount_check => str2bool(hiera('swift_mount_check'))
629     }
630     class {'::swift::storage::account':
631       manage_service => $non_pcmk_start,
632       enabled => $non_pcmk_start,
633     }
634     class {'::swift::storage::container':
635       manage_service => $non_pcmk_start,
636       enabled => $non_pcmk_start,
637     }
638     class {'::swift::storage::object':
639       manage_service => $non_pcmk_start,
640       enabled => $non_pcmk_start,
641     }
642     if(!defined(File['/srv/node'])) {
643       file { '/srv/node':
644         ensure  => directory,
645         owner   => 'swift',
646         group   => 'swift',
647         require => Package['openstack-swift'],
648       }
649     }
650     $swift_components = ['account', 'container', 'object']
651     swift::storage::filter::recon { $swift_components : }
652     swift::storage::filter::healthcheck { $swift_components : }
653   }
654
655   # Ceilometer
656   $ceilometer_backend = downcase(hiera('ceilometer_backend'))
657   case $ceilometer_backend {
658     /mysql/ : {
659       $ceilometer_database_connection = hiera('ceilometer_mysql_conn_string')
660     }
661     default : {
662       $ceilometer_database_connection = "mongodb://${mongo_node_string}/ceilometer?replicaSet=${mongodb_replset}"
663     }
664   }
665   include ::ceilometer
666   class { '::ceilometer::api' :
667     manage_service => false,
668     enabled => false,
669   }
670   class { '::ceilometer::agent::notification' :
671     manage_service => false,
672     enabled => false,
673   }
674   class { '::ceilometer::agent::central' :
675     manage_service => false,
676     enabled => false,
677   }
678   class { '::ceilometer::alarm::notifier' :
679     manage_service => false,
680     enabled => false,
681   }
682   class { '::ceilometer::alarm::evaluator' :
683     manage_service => false,
684     enabled => false,
685   }
686   class { '::ceilometer::collector' :
687     manage_service => false,
688     enabled => false,
689   }
690   include ::ceilometer::expirer
691   class { '::ceilometer::db' :
692     database_connection => $ceilometer_database_connection,
693     sync_db             => $sync_db,
694   }
695   include ceilometer::agent::auth
696
697   Cron <| title == 'ceilometer-expirer' |> { command => "sleep $((\$(od -A n -t d -N 3 /dev/urandom) % 86400)) && ${::ceilometer::params::expirer_command}" }
698
699   # Heat
700   class { '::heat' :
701     sync_db => $sync_db,
702   }
703   class { '::heat::api' :
704     manage_service => false,
705     enabled => false,
706   }
707   class { '::heat::api_cfn' :
708     manage_service => false,
709     enabled => false,
710   }
711   class { '::heat::api_cloudwatch' :
712     manage_service => false,
713     enabled => false,
714   }
715   class { '::heat::engine' :
716     manage_service => false,
717     enabled => false,
718   }
719
720   # httpd/apache and horizon
721   # NOTE(gfidente): server-status can be consumed by the pacemaker resource agent
722   include ::apache
723   include ::apache::mod::status
724   $vhost_params = {
725     add_listen => false,
726     priority   => 10,
727   }
728   class { 'horizon':
729     cache_server_ip    => hiera('memcache_node_ips', '127.0.0.1'),
730     vhost_extra_params => $vhost_params,
731     server_aliases     => $::hostname,
732   }
733
734   $snmpd_user = hiera('snmpd_readonly_user_name')
735   snmp::snmpv3_user { $snmpd_user:
736     authtype => 'MD5',
737     authpass => hiera('snmpd_readonly_user_password'),
738   }
739   class { 'snmp':
740     agentaddress => ['udp:161','udp6:[::1]:161'],
741     snmpd_config => [ join(['rouser ', hiera('snmpd_readonly_user_name')]), 'proc  cron', 'includeAllDisks  10%', 'master agentx', 'trapsink localhost public', 'iquerySecName internalUser', 'rouser internalUser', 'defaultMonitors yes', 'linkUpDownNotifications yes' ],
742   }
743
744 } #END STEP 3
745
746 if hiera('step') >= 4 {
747   if $pacemaker_master {
748
749     # Keystone
750     pacemaker::resource::service { $::keystone::params::service_name :
751       clone_params => "interleave=true",
752     }
753
754     # Cinder
755     pacemaker::resource::service { $::cinder::params::api_service :
756       clone_params => "interleave=true",
757       require      => Pacemaker::Resource::Service[$::keystone::params::service_name],
758     }
759     pacemaker::resource::service { $::cinder::params::scheduler_service :
760       clone_params => "interleave=true",
761     }
762     pacemaker::resource::service { $::cinder::params::volume_service : }
763
764     pacemaker::constraint::base { 'keystone-then-cinder-api-constraint':
765       constraint_type => 'order',
766       first_resource  => "${::keystone::params::service_name}-clone",
767       second_resource => "${::cinder::params::api_service}-clone",
768       first_action    => 'start',
769       second_action   => 'start',
770       require         => [Pacemaker::Resource::Service[$::cinder::params::api_service],
771                           Pacemaker::Resource::Service[$::keystone::params::service_name]],
772     }
773     pacemaker::constraint::base { 'cinder-api-then-cinder-scheduler-constraint':
774       constraint_type => "order",
775       first_resource => "${::cinder::params::api_service}-clone",
776       second_resource => "${::cinder::params::scheduler_service}-clone",
777       first_action => "start",
778       second_action => "start",
779       require => [Pacemaker::Resource::Service[$::cinder::params::api_service],
780                   Pacemaker::Resource::Service[$::cinder::params::scheduler_service]],
781     }
782     pacemaker::constraint::colocation { 'cinder-scheduler-with-cinder-api-colocation':
783       source => "${::cinder::params::scheduler_service}-clone",
784       target => "${::cinder::params::api_service}-clone",
785       score => "INFINITY",
786       require => [Pacemaker::Resource::Service[$::cinder::params::api_service],
787                   Pacemaker::Resource::Service[$::cinder::params::scheduler_service]],
788     }
789     pacemaker::constraint::base { 'cinder-scheduler-then-cinder-volume-constraint':
790       constraint_type => "order",
791       first_resource => "${::cinder::params::scheduler_service}-clone",
792       second_resource => "${::cinder::params::volume_service}",
793       first_action => "start",
794       second_action => "start",
795       require => [Pacemaker::Resource::Service[$::cinder::params::scheduler_service],
796                   Pacemaker::Resource::Service[$::cinder::params::volume_service]],
797     }
798     pacemaker::constraint::colocation { 'cinder-volume-with-cinder-scheduler-colocation':
799       source => "${::cinder::params::volume_service}",
800       target => "${::cinder::params::scheduler_service}-clone",
801       score => "INFINITY",
802       require => [Pacemaker::Resource::Service[$::cinder::params::scheduler_service],
803                   Pacemaker::Resource::Service[$::cinder::params::volume_service]],
804     }
805
806     # Glance
807     pacemaker::resource::service { $::glance::params::registry_service_name :
808       clone_params => "interleave=true",
809       require      => Pacemaker::Resource::Service[$::keystone::params::service_name],
810     }
811     pacemaker::resource::service { $::glance::params::api_service_name :
812       clone_params => "interleave=true",
813     }
814
815     pacemaker::constraint::base { 'keystone-then-glance-registry-constraint':
816       constraint_type => 'order',
817       first_resource  => "${::keystone::params::service_name}-clone",
818       second_resource => "${::glance::params::registry_service_name}-clone",
819       first_action    => 'start',
820       second_action   => 'start',
821       require         => [Pacemaker::Resource::Service[$::glance::params::registry_service_name],
822                           Pacemaker::Resource::Service[$::keystone::params::service_name]],
823     }
824     pacemaker::constraint::base { 'glance-registry-then-glance-api-constraint':
825       constraint_type => "order",
826       first_resource  => "${::glance::params::registry_service_name}-clone",
827       second_resource => "${::glance::params::api_service_name}-clone",
828       first_action    => "start",
829       second_action   => "start",
830       require => [Pacemaker::Resource::Service[$::glance::params::registry_service_name],
831                   Pacemaker::Resource::Service[$::glance::params::api_service_name]],
832     }
833     pacemaker::constraint::colocation { 'glance-api-with-glance-registry-colocation':
834       source  => "${::glance::params::api_service_name}-clone",
835       target  => "${::glance::params::registry_service_name}-clone",
836       score   => "INFINITY",
837       require => [Pacemaker::Resource::Service[$::glance::params::registry_service_name],
838                   Pacemaker::Resource::Service[$::glance::params::api_service_name]],
839     }
840
841     # Neutron
842     pacemaker::resource::service { $::neutron::params::server_service:
843       op_params => "start timeout=90",
844       clone_params   => "interleave=true",
845       require => Pacemaker::Resource::Service[$::keystone::params::service_name]
846     }
847     pacemaker::resource::service { $::neutron::params::l3_agent_service:
848       clone_params   => "interleave=true",
849     }
850     pacemaker::resource::service { $::neutron::params::dhcp_agent_service:
851       clone_params   => "interleave=true",
852     }
853     pacemaker::resource::service { $::neutron::params::ovs_agent_service:
854       clone_params => "interleave=true",
855     }
856     pacemaker::resource::service { $::neutron::params::metadata_agent_service:
857       clone_params => "interleave=true",
858     }
859     pacemaker::resource::ocf { $::neutron::params::ovs_cleanup_service:
860       ocf_agent_name => "neutron:OVSCleanup",
861       clone_params => "interleave=true",
862     }
863     pacemaker::resource::ocf { 'neutron-netns-cleanup':
864       ocf_agent_name => "neutron:NetnsCleanup",
865       clone_params => "interleave=true",
866     }
867     pacemaker::resource::ocf { 'neutron-scale':
868       ocf_agent_name => "neutron:NeutronScale",
869       clone_params => "globally-unique=true clone-max=3 interleave=true",
870     }
871     pacemaker::constraint::base { 'keystone-to-neutron-server-constraint':
872       constraint_type => "order",
873       first_resource => "${::keystone::params::service_name}-clone",
874       second_resource => "${::neutron::params::server_service}-clone",
875       first_action => "start",
876       second_action => "start",
877       require => [Pacemaker::Resource::Service[$::keystone::params::service_name],
878                   Pacemaker::Resource::Service[$::neutron::params::server_service]],
879     }
880     pacemaker::constraint::base { 'neutron-server-to-neutron-scale-constraint':
881       constraint_type => "order",
882       first_resource => "${::neutron::params::server_service}-clone",
883       second_resource => "neutron-scale-clone",
884       first_action => "start",
885       second_action => "start",
886       require => [Pacemaker::Resource::Service[$::neutron::params::server_service],
887                   Pacemaker::Resource::Ocf['neutron-scale']],
888     }
889     pacemaker::constraint::base { 'neutron-scale-to-ovs-cleanup-constraint':
890       constraint_type => "order",
891       first_resource => "neutron-scale-clone",
892       second_resource => "${::neutron::params::ovs_cleanup_service}-clone",
893       first_action => "start",
894       second_action => "start",
895       require => [Pacemaker::Resource::Ocf['neutron-scale'],
896                   Pacemaker::Resource::Ocf["${::neutron::params::ovs_cleanup_service}"]],
897     }
898     pacemaker::constraint::colocation { 'neutron-scale-to-ovs-cleanup-colocation':
899       source => "${::neutron::params::ovs_cleanup_service}-clone",
900       target => "neutron-scale-clone",
901       score => "INFINITY",
902       require => [Pacemaker::Resource::Ocf['neutron-scale'],
903                   Pacemaker::Resource::Ocf["${::neutron::params::ovs_cleanup_service}"]],
904     }
905     pacemaker::constraint::base { 'neutron-ovs-cleanup-to-netns-cleanup-constraint':
906       constraint_type => "order",
907       first_resource => "${::neutron::params::ovs_cleanup_service}-clone",
908       second_resource => "neutron-netns-cleanup-clone",
909       first_action => "start",
910       second_action => "start",
911       require => [Pacemaker::Resource::Ocf["${::neutron::params::ovs_cleanup_service}"],
912                   Pacemaker::Resource::Ocf['neutron-netns-cleanup']],
913     }
914     pacemaker::constraint::colocation { 'neutron-ovs-cleanup-to-netns-cleanup-colocation':
915       source => "neutron-netns-cleanup-clone",
916       target => "${::neutron::params::ovs_cleanup_service}-clone",
917       score => "INFINITY",
918       require => [Pacemaker::Resource::Ocf["${::neutron::params::ovs_cleanup_service}"],
919                   Pacemaker::Resource::Ocf['neutron-netns-cleanup']],
920     }
921     pacemaker::constraint::base { 'neutron-netns-cleanup-to-openvswitch-agent-constraint':
922       constraint_type => "order",
923       first_resource => "neutron-netns-cleanup-clone",
924       second_resource => "${::neutron::params::ovs_agent_service}-clone",
925       first_action => "start",
926       second_action => "start",
927       require => [Pacemaker::Resource::Ocf["neutron-netns-cleanup"],
928                   Pacemaker::Resource::Service["${::neutron::params::ovs_agent_service}"]],
929     }
930     pacemaker::constraint::colocation { 'neutron-netns-cleanup-to-openvswitch-agent-colocation':
931       source => "${::neutron::params::ovs_agent_service}-clone",
932       target => "neutron-netns-cleanup-clone",
933       score => "INFINITY",
934       require => [Pacemaker::Resource::Ocf["neutron-netns-cleanup"],
935                   Pacemaker::Resource::Service["${::neutron::params::ovs_agent_service}"]],
936     }
937     pacemaker::constraint::base { 'neutron-openvswitch-agent-to-dhcp-agent-constraint':
938       constraint_type => "order",
939       first_resource => "${::neutron::params::ovs_agent_service}-clone",
940       second_resource => "${::neutron::params::dhcp_agent_service}-clone",
941       first_action => "start",
942       second_action => "start",
943       require => [Pacemaker::Resource::Service["${::neutron::params::ovs_agent_service}"],
944                   Pacemaker::Resource::Service["${::neutron::params::dhcp_agent_service}"]],
945
946     }
947     pacemaker::constraint::colocation { 'neutron-openvswitch-agent-to-dhcp-agent-colocation':
948       source => "${::neutron::params::dhcp_agent_service}-clone",
949       target => "${::neutron::params::ovs_agent_service}-clone",
950       score => "INFINITY",
951       require => [Pacemaker::Resource::Service["${::neutron::params::ovs_agent_service}"],
952                   Pacemaker::Resource::Service["${::neutron::params::dhcp_agent_service}"]],
953     }
954     pacemaker::constraint::base { 'neutron-dhcp-agent-to-l3-agent-constraint':
955       constraint_type => "order",
956       first_resource => "${::neutron::params::dhcp_agent_service}-clone",
957       second_resource => "${::neutron::params::l3_agent_service}-clone",
958       first_action => "start",
959       second_action => "start",
960       require => [Pacemaker::Resource::Service["${::neutron::params::dhcp_agent_service}"],
961                   Pacemaker::Resource::Service["${::neutron::params::l3_agent_service}"]]
962     }
963     pacemaker::constraint::colocation { 'neutron-dhcp-agent-to-l3-agent-colocation':
964       source => "${::neutron::params::l3_agent_service}-clone",
965       target => "${::neutron::params::dhcp_agent_service}-clone",
966       score => "INFINITY",
967       require => [Pacemaker::Resource::Service["${::neutron::params::dhcp_agent_service}"],
968                   Pacemaker::Resource::Service["${::neutron::params::l3_agent_service}"]]
969     }
970     pacemaker::constraint::base { 'neutron-l3-agent-to-metadata-agent-constraint':
971       constraint_type => "order",
972       first_resource => "${::neutron::params::l3_agent_service}-clone",
973       second_resource => "${::neutron::params::metadata_agent_service}-clone",
974       first_action => "start",
975       second_action => "start",
976       require => [Pacemaker::Resource::Service["${::neutron::params::l3_agent_service}"],
977                   Pacemaker::Resource::Service["${::neutron::params::metadata_agent_service}"]]
978     }
979     pacemaker::constraint::colocation { 'neutron-l3-agent-to-metadata-agent-colocation':
980       source => "${::neutron::params::metadata_agent_service}-clone",
981       target => "${::neutron::params::l3_agent_service}-clone",
982       score => "INFINITY",
983       require => [Pacemaker::Resource::Service["${::neutron::params::l3_agent_service}"],
984                   Pacemaker::Resource::Service["${::neutron::params::metadata_agent_service}"]]
985     }
986
987     # Nova
988     pacemaker::resource::service { $::nova::params::api_service_name :
989       clone_params    => "interleave=true",
990       op_params       => "monitor start-delay=10s",
991     }
992     pacemaker::resource::service { $::nova::params::conductor_service_name :
993       clone_params    => "interleave=true",
994       op_params       => "monitor start-delay=10s",
995     }
996     pacemaker::resource::service { $::nova::params::consoleauth_service_name :
997       clone_params    => "interleave=true",
998       op_params       => "monitor start-delay=10s",
999       require         => Pacemaker::Resource::Service[$::keystone::params::service_name],
1000     }
1001     pacemaker::resource::service { $::nova::params::vncproxy_service_name :
1002       clone_params    => "interleave=true",
1003       op_params       => "monitor start-delay=10s",
1004     }
1005     pacemaker::resource::service { $::nova::params::scheduler_service_name :
1006       clone_params    => "interleave=true",
1007       op_params       => "monitor start-delay=10s",
1008     }
1009
1010     pacemaker::constraint::base { 'keystone-then-nova-consoleauth-constraint':
1011       constraint_type => 'order',
1012       first_resource  => "${::keystone::params::service_name}-clone",
1013       second_resource => "${::nova::params::consoleauth_service_name}-clone",
1014       first_action    => 'start',
1015       second_action   => 'start',
1016       require         => [Pacemaker::Resource::Service[$::nova::params::consoleauth_service_name],
1017                           Pacemaker::Resource::Service[$::keystone::params::service_name]],
1018     }
1019     pacemaker::constraint::base { 'nova-consoleauth-then-nova-vncproxy-constraint':
1020       constraint_type => "order",
1021       first_resource  => "${::nova::params::consoleauth_service_name}-clone",
1022       second_resource => "${::nova::params::vncproxy_service_name}-clone",
1023       first_action    => "start",
1024       second_action   => "start",
1025       require => [Pacemaker::Resource::Service[$::nova::params::consoleauth_service_name],
1026                   Pacemaker::Resource::Service[$::nova::params::vncproxy_service_name]],
1027     }
1028     pacemaker::constraint::colocation { 'nova-vncproxy-with-nova-consoleauth-colocation':
1029       source => "${::nova::params::vncproxy_service_name}-clone",
1030       target => "${::nova::params::consoleauth_service_name}-clone",
1031       score => "INFINITY",
1032       require => [Pacemaker::Resource::Service[$::nova::params::consoleauth_service_name],
1033                   Pacemaker::Resource::Service[$::nova::params::vncproxy_service_name]],
1034     }
1035     # FIXME(gfidente): novncproxy will not start unless websockify is updated to 0.6
1036     # which is not the case for f20 nor f21; ucomment when it becomes available
1037     #pacemaker::constraint::base { 'nova-vncproxy-then-nova-api-constraint':
1038     #  constraint_type => "order",
1039     #  first_resource  => "${::nova::params::vncproxy_service_name}-clone",
1040     #  second_resource => "${::nova::params::api_service_name}-clone",
1041     #  first_action    => "start",
1042     #  second_action   => "start",
1043     #  require => [Pacemaker::Resource::Service[$::nova::params::vncproxy_service_name],
1044     #              Pacemaker::Resource::Service[$::nova::params::api_service_name]],
1045     #}
1046     #pacemaker::constraint::colocation { 'nova-api-with-nova-vncproxy-colocation':
1047     #  source => "${::nova::params::api_service_name}-clone",
1048     #  target => "${::nova::params::vncproxy_service_name}-clone",
1049     #  score => "INFINITY",
1050     #  require => [Pacemaker::Resource::Service[$::nova::params::vncproxy_service_name],
1051     #              Pacemaker::Resource::Service[$::nova::params::api_service_name]],
1052     #}
1053     pacemaker::constraint::base { 'nova-api-then-nova-scheduler-constraint':
1054       constraint_type => "order",
1055       first_resource  => "${::nova::params::api_service_name}-clone",
1056       second_resource => "${::nova::params::scheduler_service_name}-clone",
1057       first_action    => "start",
1058       second_action   => "start",
1059       require => [Pacemaker::Resource::Service[$::nova::params::api_service_name],
1060                   Pacemaker::Resource::Service[$::nova::params::scheduler_service_name]],
1061     }
1062     pacemaker::constraint::colocation { 'nova-scheduler-with-nova-api-colocation':
1063       source => "${::nova::params::scheduler_service_name}-clone",
1064       target => "${::nova::params::api_service_name}-clone",
1065       score => "INFINITY",
1066       require => [Pacemaker::Resource::Service[$::nova::params::api_service_name],
1067                   Pacemaker::Resource::Service[$::nova::params::scheduler_service_name]],
1068     }
1069     pacemaker::constraint::base { 'nova-scheduler-then-nova-conductor-constraint':
1070       constraint_type => "order",
1071       first_resource  => "${::nova::params::scheduler_service_name}-clone",
1072       second_resource => "${::nova::params::conductor_service_name}-clone",
1073       first_action    => "start",
1074       second_action   => "start",
1075       require => [Pacemaker::Resource::Service[$::nova::params::scheduler_service_name],
1076                   Pacemaker::Resource::Service[$::nova::params::conductor_service_name]],
1077     }
1078     pacemaker::constraint::colocation { 'nova-conductor-with-nova-scheduler-colocation':
1079       source => "${::nova::params::conductor_service_name}-clone",
1080       target => "${::nova::params::scheduler_service_name}-clone",
1081       score => "INFINITY",
1082       require => [Pacemaker::Resource::Service[$::nova::params::scheduler_service_name],
1083                   Pacemaker::Resource::Service[$::nova::params::conductor_service_name]],
1084     }
1085
1086     # Ceilometer
1087     pacemaker::resource::service { $::ceilometer::params::agent_central_service_name :
1088       clone_params => 'interleave=true',
1089       require      => [Pacemaker::Resource::Service[$::keystone::params::service_name],
1090                        $mongodb_pacemaker_resource],
1091     }
1092     pacemaker::resource::service { $::ceilometer::params::collector_service_name :
1093       clone_params => 'interleave=true',
1094     }
1095     pacemaker::resource::service { $::ceilometer::params::api_service_name :
1096       clone_params => 'interleave=true',
1097     }
1098     pacemaker::resource::service { $::ceilometer::params::alarm_evaluator_service_name :
1099       clone_params => 'interleave=true',
1100     }
1101     pacemaker::resource::service { $::ceilometer::params::alarm_notifier_service_name :
1102       clone_params => 'interleave=true',
1103     }
1104     pacemaker::resource::service { $::ceilometer::params::agent_notification_service_name :
1105       clone_params => 'interleave=true',
1106     }
1107     pacemaker::resource::ocf { 'delay' :
1108       ocf_agent_name  => 'heartbeat:Delay',
1109       clone_params    => 'interleave=true',
1110       resource_params => 'startdelay=10',
1111     }
1112     pacemaker::constraint::base { 'ceilometer-central-then-ceilometer-collector-constraint':
1113       constraint_type => 'order',
1114       first_resource  => "${::ceilometer::params::agent_central_service_name}-clone",
1115       second_resource => "${::ceilometer::params::collector_service_name}-clone",
1116       first_action    => 'start',
1117       second_action   => 'start',
1118       require         => [Pacemaker::Resource::Service[$::ceilometer::params::agent_central_service_name],
1119                           Pacemaker::Resource::Service[$::ceilometer::params::collector_service_name]],
1120     }
1121     pacemaker::constraint::base { 'ceilometer-collector-then-ceilometer-api-constraint':
1122       constraint_type => 'order',
1123       first_resource  => "${::ceilometer::params::collector_service_name}-clone",
1124       second_resource => "${::ceilometer::params::api_service_name}-clone",
1125       first_action    => 'start',
1126       second_action   => 'start',
1127       require         => [Pacemaker::Resource::Service[$::ceilometer::params::collector_service_name],
1128                           Pacemaker::Resource::Service[$::ceilometer::params::api_service_name]],
1129     }
1130     pacemaker::constraint::colocation { 'ceilometer-api-with-ceilometer-collector-colocation':
1131       source  => "${::ceilometer::params::api_service_name}-clone",
1132       target  => "${::ceilometer::params::collector_service_name}-clone",
1133       score   => 'INFINITY',
1134       require => [Pacemaker::Resource::Service[$::ceilometer::params::api_service_name],
1135                   Pacemaker::Resource::Service[$::ceilometer::params::collector_service_name]],
1136     }
1137     pacemaker::constraint::base { 'ceilometer-api-then-ceilometer-delay-constraint':
1138       constraint_type => 'order',
1139       first_resource  => "${::ceilometer::params::api_service_name}-clone",
1140       second_resource => 'delay-clone',
1141       first_action    => 'start',
1142       second_action   => 'start',
1143       require         => [Pacemaker::Resource::Service[$::ceilometer::params::api_service_name],
1144                           Pacemaker::Resource::Ocf['delay']],
1145     }
1146     pacemaker::constraint::colocation { 'ceilometer-delay-with-ceilometer-api-colocation':
1147       source  => 'delay-clone',
1148       target  => "${::ceilometer::params::api_service_name}-clone",
1149       score   => 'INFINITY',
1150       require => [Pacemaker::Resource::Service[$::ceilometer::params::api_service_name],
1151                   Pacemaker::Resource::Ocf['delay']],
1152     }
1153     pacemaker::constraint::base { 'ceilometer-delay-then-ceilometer-alarm-evaluator-constraint':
1154       constraint_type => 'order',
1155       first_resource  => 'delay-clone',
1156       second_resource => "${::ceilometer::params::alarm_evaluator_service_name}-clone",
1157       first_action    => 'start',
1158       second_action   => 'start',
1159       require         => [Pacemaker::Resource::Service[$::ceilometer::params::alarm_evaluator_service_name],
1160                           Pacemaker::Resource::Ocf['delay']],
1161     }
1162     pacemaker::constraint::colocation { 'ceilometer-alarm-evaluator-with-ceilometer-delay-colocation':
1163       source  => "${::ceilometer::params::alarm_evaluator_service_name}-clone",
1164       target  => 'delay-clone',
1165       score   => 'INFINITY',
1166       require => [Pacemaker::Resource::Service[$::ceilometer::params::api_service_name],
1167                   Pacemaker::Resource::Ocf['delay']],
1168     }
1169     pacemaker::constraint::base { 'ceilometer-alarm-evaluator-then-ceilometer-alarm-notifier-constraint':
1170       constraint_type => 'order',
1171       first_resource  => "${::ceilometer::params::alarm_evaluator_service_name}-clone",
1172       second_resource => "${::ceilometer::params::alarm_notifier_service_name}-clone",
1173       first_action    => 'start',
1174       second_action   => 'start',
1175       require         => [Pacemaker::Resource::Service[$::ceilometer::params::alarm_evaluator_service_name],
1176                           Pacemaker::Resource::Service[$::ceilometer::params::alarm_notifier_service_name]],
1177     }
1178     pacemaker::constraint::colocation { 'ceilometer-alarm-notifier-with-ceilometer-alarm-evaluator-colocation':
1179       source  => "${::ceilometer::params::alarm_notifier_service_name}-clone",
1180       target  => "${::ceilometer::params::alarm_evaluator_service_name}-clone",
1181       score   => 'INFINITY',
1182       require => [Pacemaker::Resource::Service[$::ceilometer::params::alarm_evaluator_service_name],
1183                   Pacemaker::Resource::Service[$::ceilometer::params::alarm_notifier_service_name]],
1184     }
1185     pacemaker::constraint::base { 'ceilometer-alarm-notifier-then-ceilometer-notification-constraint':
1186       constraint_type => 'order',
1187       first_resource  => "${::ceilometer::params::alarm_notifier_service_name}-clone",
1188       second_resource => "${::ceilometer::params::agent_notification_service_name}-clone",
1189       first_action    => 'start',
1190       second_action   => 'start',
1191       require         => [Pacemaker::Resource::Service[$::ceilometer::params::agent_notification_service_name],
1192                           Pacemaker::Resource::Service[$::ceilometer::params::alarm_notifier_service_name]],
1193     }
1194     pacemaker::constraint::colocation { 'ceilometer-notification-with-ceilometer-alarm-notifier-colocation':
1195       source  => "${::ceilometer::params::agent_notification_service_name}-clone",
1196       target  => "${::ceilometer::params::alarm_notifier_service_name}-clone",
1197       score   => 'INFINITY',
1198       require => [Pacemaker::Resource::Service[$::ceilometer::params::agent_notification_service_name],
1199                   Pacemaker::Resource::Service[$::ceilometer::params::alarm_notifier_service_name]],
1200     }
1201     if downcase(hiera('ceilometer_backend')) == 'mongodb' {
1202       pacemaker::constraint::base { 'mongodb-then-ceilometer-central-constraint':
1203         constraint_type => 'order',
1204         first_resource  => "${::mongodb::params::service_name}-clone",
1205         second_resource => "${::ceilometer::params::agent_central_service_name}-clone",
1206         first_action    => 'start',
1207         second_action   => 'start',
1208         require         => [Pacemaker::Resource::Service[$::ceilometer::params::agent_central_service_name],
1209                             Pacemaker::Resource::Service[$::mongodb::params::service_name]],
1210       }
1211     }
1212     pacemaker::constraint::base { 'vip-redis-then-ceilometer-central':
1213       constraint_type => 'order',
1214       first_resource  => "ip-${redis_vip}",
1215       second_resource => "${::ceilometer::params::agent_central_service_name}-clone",
1216       first_action    => 'start',
1217       second_action   => 'start',
1218       require => [Pacemaker::Resource::Service[$::ceilometer::params::agent_central_service_name],
1219                   Pacemaker::Resource::Ip['vip-redis']],
1220     }
1221     pacemaker::constraint::base { 'keystone-then-ceilometer-central-constraint':
1222       constraint_type => 'order',
1223       first_resource  => "${::keystone::params::service_name}-clone",
1224       second_resource => "${::ceilometer::params::agent_central_service_name}-clone",
1225       first_action    => 'start',
1226       second_action   => 'start',
1227       require         => [Pacemaker::Resource::Service[$::ceilometer::params::agent_central_service_name],
1228                           Pacemaker::Resource::Service[$::keystone::params::service_name]],
1229     }
1230
1231     # Heat
1232     pacemaker::resource::service { $::heat::params::api_service_name :
1233       clone_params => 'interleave=true',
1234     }
1235     pacemaker::resource::service { $::heat::params::api_cloudwatch_service_name :
1236       clone_params => 'interleave=true',
1237     }
1238     pacemaker::resource::service { $::heat::params::api_cfn_service_name :
1239       clone_params => 'interleave=true',
1240     }
1241     pacemaker::resource::service { $::heat::params::engine_service_name :
1242       clone_params => 'interleave=true',
1243     }
1244     pacemaker::constraint::base { 'heat-api-then-heat-api-cfn-constraint':
1245       constraint_type => 'order',
1246       first_resource  => "${::heat::params::api_service_name}-clone",
1247       second_resource => "${::heat::params::api_cfn_service_name}-clone",
1248       first_action    => 'start',
1249       second_action   => 'start',
1250       require => [Pacemaker::Resource::Service[$::heat::params::api_service_name],
1251                   Pacemaker::Resource::Service[$::heat::params::api_cfn_service_name]],
1252     }
1253     pacemaker::constraint::colocation { 'heat-api-cfn-with-heat-api-colocation':
1254       source  => "${::heat::params::api_cfn_service_name}-clone",
1255       target  => "${::heat::params::api_service_name}-clone",
1256       score   => 'INFINITY',
1257       require => [Pacemaker::Resource::Service[$::heat::params::api_cfn_service_name],
1258                   Pacemaker::Resource::Service[$::heat::params::api_service_name]],
1259     }
1260     pacemaker::constraint::base { 'heat-api-cfn-then-heat-api-cloudwatch-constraint':
1261       constraint_type => 'order',
1262       first_resource  => "${::heat::params::api_cfn_service_name}-clone",
1263       second_resource => "${::heat::params::api_cloudwatch_service_name}-clone",
1264       first_action    => 'start',
1265       second_action   => 'start',
1266       require => [Pacemaker::Resource::Service[$::heat::params::api_cloudwatch_service_name],
1267                   Pacemaker::Resource::Service[$::heat::params::api_cfn_service_name]],
1268     }
1269     pacemaker::constraint::colocation { 'heat-api-cloudwatch-with-heat-api-cfn-colocation':
1270       source  => "${::heat::params::api_cloudwatch_service_name}-clone",
1271       target  => "${::heat::params::api_cfn_service_name}-clone",
1272       score   => 'INFINITY',
1273       require => [Pacemaker::Resource::Service[$::heat::params::api_cfn_service_name],
1274                   Pacemaker::Resource::Service[$::heat::params::api_cloudwatch_service_name]],
1275     }
1276     pacemaker::constraint::base { 'heat-api-cloudwatch-then-heat-engine-constraint':
1277       constraint_type => 'order',
1278       first_resource  => "${::heat::params::api_cloudwatch_service_name}-clone",
1279       second_resource => "${::heat::params::engine_service_name}-clone",
1280       first_action    => 'start',
1281       second_action   => 'start',
1282       require => [Pacemaker::Resource::Service[$::heat::params::api_cloudwatch_service_name],
1283                   Pacemaker::Resource::Service[$::heat::params::engine_service_name]],
1284     }
1285     pacemaker::constraint::colocation { 'heat-engine-with-heat-api-cloudwatch-colocation':
1286       source  => "${::heat::params::engine_service_name}-clone",
1287       target  => "${::heat::params::api_cloudwatch_service_name}-clone",
1288       score   => 'INFINITY',
1289       require => [Pacemaker::Resource::Service[$::heat::params::api_cloudwatch_service_name],
1290                   Pacemaker::Resource::Service[$::heat::params::engine_service_name]],
1291     }
1292     pacemaker::constraint::base { 'ceilometer-notification-then-heat-api-constraint':
1293       constraint_type => 'order',
1294       first_resource  => "${::ceilometer::params::agent_notification_service_name}-clone",
1295       second_resource => "${::heat::params::api_service_name}-clone",
1296       first_action    => 'start',
1297       second_action   => 'start',
1298       require         => [Pacemaker::Resource::Service[$::heat::params::api_service_name],
1299                           Pacemaker::Resource::Service[$::ceilometer::params::agent_notification_service_name]],
1300     }
1301
1302     # Horizon
1303     pacemaker::resource::service { $::horizon::params::http_service:
1304         clone_params => "interleave=true",
1305     }
1306
1307
1308   }
1309
1310 } #END STEP 4