Merge "Fix barbican integration on compute nodes"
[fuel.git] / mcp / reclass / classes / cluster / mcp-common-ha / openstack_control.yml.j2
index cdebe3f..a7e8fcd 100644 (file)
@@ -20,8 +20,12 @@ classes:
   - system.heat.server.cluster
   - system.designate.server.cluster
   - system.designate.server.backend.bind
+  - system.barbican.server.cluster
+  - system.apache.server.site.barbican
+  - service.barbican.server.plugin.simple_crypto
+  - system.apache.server.single
   - system.bind.server.single
-  - system.haproxy.proxy.listen.openstack.nova-placement
+  - system.haproxy.proxy.listen.openstack.placement
   - system.glusterfs.client.cluster
   - system.glusterfs.client.volume.glance
   - system.glusterfs.client.volume.keystone
@@ -42,8 +46,8 @@ classes:
   # - system.salt.control.cluster.stacklight_log_cluster
   # - system.salt.control.cluster.stacklight_telemetry_cluster
   - cluster.mcp-common-ha.infra.kvm_pdf
-  - cluster.mcp-common-ha.include.maas_proxy
-  - cluster.mcp-common-ha.include.lab_proxy_pdf
+  - cluster.all-mcp-arch-common.opnfv.maas_proxy
+  - cluster.all-mcp-arch-common.opnfv.lab_proxy_pdf
 {%- endif %}
 parameters:
   _param:
@@ -67,9 +71,34 @@ parameters:
     cluster_node03_address: ${_param:openstack_control_node03_address}
     nova_vncproxy_url: https://${_param:cluster_public_host}:6080
     glusterfs_version: '3.13'
+    barbican_integration_enabled: 'false'
+  nova:
+    controller: &db_conn_recycle_time
+      database:
+        connection_recycle_time: ${_param:db_connection_recycle_time}
+      barbican:
+        enabled: ${_param:barbican_integration_enabled}
+  cinder:
+    controller:
+      <<: *db_conn_recycle_time
+  neutron:
+    server:
+      <<: *db_conn_recycle_time
+      vlan_aware_vms: true
+      root_helper_daemon: false
+  keystone:
+    server:
+      <<: *db_conn_recycle_time
+      cacert: /etc/ssl/certs/mcp_os_cacert
+      openrc_extra:
+        volume_device_name: vdc
+  glance:
+    server:
+      <<: *db_conn_recycle_time
 {%- if conf.MCP_VCP %}
   heat:
     server:
+      <<: *db_conn_recycle_time
       metadata:
         host: ${_param:openstack_proxy_control_address}
         port: 8000
@@ -98,10 +127,7 @@ parameters:
   apache:
     server:
       bind:
-        ~ports: ~
-      ~modules:
-        - rewrite
-        - wsgi
+        listen_default_ports: false
   # sync from common-ha kvm role
   glusterfs:
     server:
@@ -122,25 +148,25 @@ parameters:
             diagnostics.client-log-level: WARNING
             diagnostics.brick-log-level: WARNING
 {%- endif %}
-  neutron:
-    server:
-      vlan_aware_vms: true
-      root_helper_daemon: false
-  keystone:
-    server:
-      cacert: /etc/ssl/certs/mcp_os_cacert
-      openrc_extra:
-        volume_device_name: vdc
   haproxy:
     proxy:
       listen:
-        nova_placement_api:
-          health-check:
-            http:
-              ~options:
-                - expect status 405
-        ~heat_cloudwatch_api:
+        heat_cloudwatch_api:
           enabled: false
+        neutron_api:
+          # Set source balancing
+          type: heat
+  barbican:
+    server:
+      ks_notifications_enable: true
+      store:
+        software:
+          crypto_plugin: simple_crypto
+          store_plugin: store_crypto
+          global_default: true
+      database:
+        connection_recycle_time: ${_param:db_connection_recycle_time}
+        host: ${_param:openstack_database_address}
   bind:
     server:
       control: