apex-tripleo-heat-templates.git
9 years agoMerge "Add a default route to the external isolated network"
Jenkins [Wed, 1 Jul 2015 14:22:46 +0000 (14:22 +0000)]
Merge "Add a default route to the external isolated network"

9 years agoMerge "Remove bridge from nic1 in network bond templates"
Jenkins [Wed, 1 Jul 2015 14:22:35 +0000 (14:22 +0000)]
Merge "Remove bridge from nic1 in network bond templates"

9 years agoMerge "Add special handling of neutron-server service startup to fix race"
Jenkins [Wed, 1 Jul 2015 14:05:09 +0000 (14:05 +0000)]
Merge "Add special handling of neutron-server service startup to fix race"

9 years agoMerge "Include Redis VIP in example environment"
Jenkins [Wed, 1 Jul 2015 10:08:04 +0000 (10:08 +0000)]
Merge "Include Redis VIP in example environment"

9 years agoAdd a default route to the external isolated network
Dan Sneddon [Mon, 29 Jun 2015 16:17:53 +0000 (09:17 -0700)]
Add a default route to the external isolated network

This change adds a parameter for ExternalInterfaceDefaultRoute
and uses that parameter to set the default route on the controller
nodes. This allows Horizon and the public APIs to be reachable from
routed networks outside the overcloud.

Co-Authored-By: Dan Prince <dprince@redhat.com>
Change-Id: I67a72767342237049f53f5085a6faf891fbf0c30

9 years agoMerge "Drop swift ceilometer middleware."
Jenkins [Mon, 29 Jun 2015 13:54:37 +0000 (13:54 +0000)]
Merge "Drop swift ceilometer middleware."

9 years agoRemove bridge from nic1 in network bond templates
Dan Sneddon [Sat, 27 Jun 2015 22:01:28 +0000 (15:01 -0700)]
Remove bridge from nic1 in network bond templates

The bridge that is built on the bonds in the bond-with-vlans
example has an extraneous bridge on the storage and compute
templates, and an incorrect bridge on the controller template.
There is no reason to do anything on nic1, which is assumed to
be the provisioning interface, because it will be configured by
DHCP. Also, on the controller template we actually want br-ex
to contain the VLAN with the external network, rather than be
configured on the provisioning interface.

Change-Id: Ibe2343d5281f7b63a7b63b17d96d8442d0b96105

9 years agoMerge "Add missing Pacemaker constraint against Keystone"
Jenkins [Fri, 26 Jun 2015 12:27:36 +0000 (12:27 +0000)]
Merge "Add missing Pacemaker constraint against Keystone"

9 years agoMerge "Set MariaDB package name in RedHat.yaml"
Jenkins [Fri, 26 Jun 2015 11:39:53 +0000 (11:39 +0000)]
Merge "Set MariaDB package name in RedHat.yaml"

9 years agoMerge "Enable mysql_clustercheck for Pacemaker scenario"
Jenkins [Fri, 26 Jun 2015 09:52:25 +0000 (09:52 +0000)]
Merge "Enable mysql_clustercheck for Pacemaker scenario"

9 years agoMerge "Increase mongodb_conn_validator timeout to 600"
Jenkins [Fri, 26 Jun 2015 09:14:46 +0000 (09:14 +0000)]
Merge "Increase mongodb_conn_validator timeout to 600"

9 years agoInclude Redis VIP in example environment
Dan Sneddon [Tue, 16 Jun 2015 02:11:03 +0000 (19:11 -0700)]
Include Redis VIP in example environment

The network isolation code in the TripleO Heat templates has files
in the environment folder that can be included to enable network
isolation. This updates the environment file to include the VIP
for Redis.

Change-Id: Ic05720c565d9ecf76bf7485b969cb2d9ead9fd6f

9 years agoAdd missing Pacemaker constraint against Keystone
Giulio Fidente [Thu, 25 Jun 2015 14:59:21 +0000 (16:59 +0200)]
Add missing Pacemaker constraint against Keystone

The Heat contraints group was missing the initial
dependency on Keystone, causing Pacemaker to Heat before or
in parallel to Keystone.

Given Systemd can define dependencies in the unit files, this was
additionally causing an unmanaged start of Keystone making
cluster initialization to fail (with Keystone start timeout blocking
all the depending resources).

Also moves Keystone -> Ceilomter constraint on top of Ceilometer
constraints group for clarity.

Logs and more infos at [1]

1. https://bugzilla.redhat.com/show_bug.cgi?id=1235703

Change-Id: I9505fd46c5bf278afc8ff919c7e768e2de194cb8

9 years agoMerge "Ensure mysql/mariadb service is not enabled on boot"
Jenkins [Thu, 25 Jun 2015 10:44:06 +0000 (10:44 +0000)]
Merge "Ensure mysql/mariadb service is not enabled on boot"

9 years agoMerge "Do not set explicitly galera_master to any of the nodes"
Jenkins [Thu, 25 Jun 2015 08:21:33 +0000 (08:21 +0000)]
Merge "Do not set explicitly galera_master to any of the nodes"

9 years agoEnable mysql_clustercheck for Pacemaker scenario
Giulio Fidente [Thu, 25 Jun 2015 00:36:17 +0000 (02:36 +0200)]
Enable mysql_clustercheck for Pacemaker scenario

Change-Id: I154c90e6d019807758332e3aefe5dde9d79db6ac
Related-Bug: 1456701
Depends-On: I7199c7e5d759a76f58c0f48b40e9d460a3163886

9 years agoEnsure mysql/mariadb service is not enabled on boot
Giulio Fidente [Wed, 24 Jun 2015 23:12:43 +0000 (01:12 +0200)]
Ensure mysql/mariadb service is not enabled on boot

Change-Id: I42462a6de2bf70ef71899833c3f27633f0f59493
Closes-Bug: 1468549
Closes-Bug: https://bugzilla.redhat.com/show_bug.cgi?id=1235454

9 years agoSet MariaDB package name in RedHat.yaml
Dan Prince [Wed, 24 Jun 2015 17:19:55 +0000 (13:19 -0400)]
Set MariaDB package name in RedHat.yaml

This moves the hard coded package name for mariadb into
the RedHat specific hieradata file. This was recently added
to controller.yaml in a1b3fa3e84185b6969a8acfda475fe7fc48bd5a1.

Also, resolves an issue where RedHat.yaml wasn't actually
getting deployed. This is something that should have happened
in 5009cc64322e9fb5723799eb9fbd79076a2dc5da.

Change-Id: Iaa30be3c53a7c54d31d47b997966b0106a202ea4

9 years agoMerge "Make puppet-applying *Post resources depend on hieradata"
Jenkins [Wed, 24 Jun 2015 17:00:17 +0000 (17:00 +0000)]
Merge "Make puppet-applying *Post resources depend on hieradata"

9 years agoIncrease mongodb_conn_validator timeout to 600
Giulio Fidente [Wed, 24 Jun 2015 08:52:15 +0000 (10:52 +0200)]
Increase mongodb_conn_validator timeout to 600

This will increase the mongodb_conn_validator timeout from 60 secs
(the default) to 600 secs; it should take much less in normal
circumstances to start mongod but nodes might not be starting it all
at the same time so we use a larger timeframe for the availablity
checks.

Change-Id: I0ee210be94b33d1c08d67f287aa745743a6649d3

9 years agoDo not set explicitly galera_master to any of the nodes
Giulio Fidente [Tue, 23 Jun 2015 12:45:00 +0000 (14:45 +0200)]
Do not set explicitly galera_master to any of the nodes

We will manage nodes membership using the clustercheck script and
marking all backends as backup, see change:
I7199c7e5d759a76f58c0f48b40e9d460a3163886

Related-Bug: 1467918
Change-Id: I56ebd2d8405ac35c707666d993b396f04aeb683e

9 years agoAdd special handling of neutron-server service startup to fix race
Giulio Fidente [Tue, 23 Jun 2015 11:41:19 +0000 (13:41 +0200)]
Add special handling of neutron-server service startup to fix race

Neutron will populate the database with some data as soon as the
neutron-server service is started; we want this to happen from a
single node before normal Pacemaker initialization.

Change-Id: I422972502fbb10ddae3201464bbd6885749de31e
Closes-Bug: 1467904
Closes-Bug: https://bugzilla.redhat.com/show_bug.cgi?id=1233061

9 years agoMerge "Specify mariadb package name to meet puppetlabs-mysql requirement"
Jenkins [Tue, 23 Jun 2015 09:25:14 +0000 (09:25 +0000)]
Merge "Specify mariadb package name to meet puppetlabs-mysql requirement"

9 years agoMerge "Leave control of Redis balancing in static hieradata"
Jenkins [Tue, 23 Jun 2015 09:12:12 +0000 (09:12 +0000)]
Merge "Leave control of Redis balancing in static hieradata"

9 years agoMerge "Add support for isolating block storage nets"
Jenkins [Tue, 23 Jun 2015 08:55:58 +0000 (08:55 +0000)]
Merge "Add support for isolating block storage nets"

9 years agoMerge "Fix MongoDB connection url configuration in Ceilometer"
Jenkins [Mon, 22 Jun 2015 11:57:20 +0000 (11:57 +0000)]
Merge "Fix MongoDB connection url configuration in Ceilometer"

9 years agoMerge "Use SoftwareDeployments for consistency in extraconfig"
Jenkins [Mon, 22 Jun 2015 10:27:39 +0000 (10:27 +0000)]
Merge "Use SoftwareDeployments for consistency in extraconfig"

9 years agoFix MongoDB connection url configuration in Ceilometer
Giulio Fidente [Thu, 18 Jun 2015 15:38:29 +0000 (17:38 +0200)]
Fix MongoDB connection url configuration in Ceilometer

Change-Id: I8a56e7b067044bace5def63ea6170ed817f48acd
Closes-Bug: 1467437
Closes-Bug: https://bugzilla.redhat.com/show_bug.cgi?id=1233283

9 years agoMerge "Enable httpd balancing for Horizon"
Jenkins [Mon, 22 Jun 2015 09:09:47 +0000 (09:09 +0000)]
Merge "Enable httpd balancing for Horizon"

9 years agoAdd support for isolating block storage nets
Dan Prince [Sat, 6 Jun 2015 14:25:05 +0000 (10:25 -0400)]
Add support for isolating block storage nets

This patch updates the cinder block storage role
for Puppet so that it supports network isolation.
This includes using the (optional) isolated networks
for MySQL, Glance API, and iscsi network traffic.

Change-Id: Icdfbf5fce7380e6049babca0cd50ca2e4008c1b0

9 years agoDrop swift ceilometer middleware.
Dan Prince [Sun, 21 Jun 2015 11:59:42 +0000 (07:59 -0400)]
Drop swift ceilometer middleware.

Per Ceilometer commit 191f7bf9ccee33d8444f7dac5c09ceccce72ca29
 (change ID: Ifd1861e3df46fad0e44ff9b5cbd58711bbc87c97) the
Swift Ceilometer middleware no longer exists so we need
to drop it in order to work with the latest upstream
package.

Change-Id: Iebaad0ba477001d663c6875b32d691bbfcda3d8d

9 years agoLeave control of Redis balancing in static hieradata
Giulio Fidente [Fri, 19 Jun 2015 02:31:10 +0000 (04:31 +0200)]
Leave control of Redis balancing in static hieradata

Redis balancing is controlled by static hieradata [1] we don't
need to override it into manifest.

1. https://github.com/openstack/tripleo-heat-templates/blob/master/puppet/hieradata/controller.yaml#L111

Change-Id: Ie2a5a4cbee0a55f2572f182b18c036efc299dbef

9 years agoMerge "Enable loadbalancing of the Redis VIP, defaults to False"
Jenkins [Thu, 18 Jun 2015 20:15:27 +0000 (20:15 +0000)]
Merge "Enable loadbalancing of the Redis VIP, defaults to False"

9 years agoMerge "Fix grammar nits in bond-with-vlans templates"
Jenkins [Thu, 18 Jun 2015 19:53:40 +0000 (19:53 +0000)]
Merge "Fix grammar nits in bond-with-vlans templates"

9 years agoMerge "Rename ServiceNetMap: NeutronLocalIp"
Jenkins [Thu, 18 Jun 2015 14:52:27 +0000 (14:52 +0000)]
Merge "Rename ServiceNetMap: NeutronLocalIp"

9 years agoEnable httpd balancing for Horizon
Giulio Fidente [Wed, 17 Jun 2015 20:04:16 +0000 (22:04 +0200)]
Enable httpd balancing for Horizon

We need to customize the default apache::ip param or the default
vhost configured will listen on ::80

Change-Id: I195a083f727da940841beb3a0c37dade02c6d1ca

9 years agoUse SoftwareDeployments for consistency in extraconfig
Steven Hardy [Thu, 18 Jun 2015 13:13:58 +0000 (09:13 -0400)]
Use SoftwareDeployments for consistency in extraconfig

Currently we've got a mix of SoftwareConfig resource with
StructuredDeployments resources - while this will work it's
inconsistent and normally using the corresponding
SoftwareDeployments resouce is encourgaged instead.

Change-Id: I308d62d4ff491c073e3e8650fd4c2c65bf96d14a

9 years agoEnable loadbalancing of the Redis VIP, defaults to False
marios [Thu, 18 Jun 2015 09:21:29 +0000 (12:21 +0300)]
Enable loadbalancing of the Redis VIP, defaults to False

We have to set it to true as the default is false which means the
redis vip can't be reached. This was manifested as a problem with
ceilometer agent reaching the coordination url like [1].

Co-Authored-By: Giulio Fidente <gfidente@redhat.com>
[1] https://bugzilla.redhat.com/attachment.cgi?id=1040023
Closes-Bug: https://bugzilla.redhat.com/show_bug.cgi?id=1232797
Change-Id: I1cd63308d0ac1d17542e1a2a909ee1a9680ed4b3

9 years agoBind novncproxy to its own network
Ben Nemec [Fri, 15 May 2015 17:53:35 +0000 (12:53 -0500)]
Bind novncproxy to its own network

By default the nova vncproxy binds to 0.0.0.0, which will fail in
a loadbalanced environment.  This makes it bind to its network.

Change-Id: I08776a8f6c72b63d73433b147c130fbc9a7110b0

9 years agoMerge "Remove DefaultSignalTransport from top-level template"
Jenkins [Thu, 18 Jun 2015 07:51:42 +0000 (07:51 +0000)]
Merge "Remove DefaultSignalTransport from top-level template"

9 years agoMerge "Remove NO_SIGNAL from ControllerClusterConfig"
Jenkins [Thu, 18 Jun 2015 07:51:35 +0000 (07:51 +0000)]
Merge "Remove NO_SIGNAL from ControllerClusterConfig"

9 years agoMerge "Remove NO_SIGNAL from Controller|ObjectSwiftDeployment"
Jenkins [Thu, 18 Jun 2015 07:51:27 +0000 (07:51 +0000)]
Merge "Remove NO_SIGNAL from Controller|ObjectSwiftDeployment"

9 years agoMerge "Remove NO_SIGNAL from ControllerBootstrapNodeDeployment"
Jenkins [Thu, 18 Jun 2015 07:51:19 +0000 (07:51 +0000)]
Merge "Remove NO_SIGNAL from ControllerBootstrapNodeDeployment"

9 years agoMerge "Remove Redis VirtualIP from params and build it from Neutron::Port"
Jenkins [Wed, 17 Jun 2015 22:11:27 +0000 (22:11 +0000)]
Merge "Remove Redis VirtualIP from params and build it from Neutron::Port"

9 years agoMerge "Fix allocation pool in external.yaml"
Jenkins [Wed, 17 Jun 2015 20:29:43 +0000 (20:29 +0000)]
Merge "Fix allocation pool in external.yaml"

9 years agoMerge "Make CephStorageDeployment depend on NetworkDeployment"
Jenkins [Wed, 17 Jun 2015 20:19:24 +0000 (20:19 +0000)]
Merge "Make CephStorageDeployment depend on NetworkDeployment"

9 years agoMerge "Remove NO_SIGNAL from puppet role templates"
Jenkins [Wed, 17 Jun 2015 20:18:41 +0000 (20:18 +0000)]
Merge "Remove NO_SIGNAL from puppet role templates"

9 years agoMerge "Adds horizon to pacemaker when puppet-pacemaker is enabled"
Jenkins [Wed, 17 Jun 2015 19:55:50 +0000 (19:55 +0000)]
Merge "Adds horizon to pacemaker when puppet-pacemaker is enabled"

9 years agoMerge "Fix Redis bind setting to use redis_network"
Jenkins [Wed, 17 Jun 2015 19:43:59 +0000 (19:43 +0000)]
Merge "Fix Redis bind setting to use redis_network"

9 years agoMerge "Allow control of hostname formatting"
Jenkins [Wed, 17 Jun 2015 18:46:59 +0000 (18:46 +0000)]
Merge "Allow control of hostname formatting"

9 years agoMerge "Add $hostname.localdomain alias to /etc/hosts"
Jenkins [Wed, 17 Jun 2015 18:38:22 +0000 (18:38 +0000)]
Merge "Add $hostname.localdomain alias to /etc/hosts"

9 years agoMerge "Remove unused EnablePacemaker param from templates"
Jenkins [Wed, 17 Jun 2015 18:36:42 +0000 (18:36 +0000)]
Merge "Remove unused EnablePacemaker param from templates"

9 years agoAllow control of hostname formatting
Steven Hardy [Mon, 15 Jun 2015 09:13:07 +0000 (05:13 -0400)]
Allow control of hostname formatting

Currently, we use the heat default server names, which results in some
fairly unreadable hostnames due to the level of nesting in the templates.

e.g ov-sszdbj5rdne-0-bhseh65edxv6-Controller-zoqc6tlypbdp

Instead, we allow the user to specify a format string per role, defaulted
to a string which formats the name e.g <stackname>-controller-<index>

e.g overcloud-controller-0

Optionally additional hostname components (not replaced by heat) could be
added, such that deployment time customization of hostnames via firstboot
scripts (e.g cloud-init) may be possible.

Should anyone wish to maintain the old heat-generated names, they can pass
an empty string via these parameters, which heat will treat as if no "name"
property was provided to OS::Nova::Server.

Change-Id: I1730caa0c2256f970da22ab21fa3aa1549b3f90b

9 years agoFix allocation pool in external.yaml
Dan Sneddon [Tue, 16 Jun 2015 18:27:32 +0000 (11:27 -0700)]
Fix allocation pool in external.yaml

The file network/external.yaml has a typo in the last commit. It
should have been a get_param instead of a get_resource. This
change fixes that line in that file.

Change-Id: Ibc0db0510e9b5dae3c4669a620c642357906cbc2

9 years agoConfigurable vlan_id's for isolated networks
Dan Prince [Tue, 9 Jun 2015 17:51:04 +0000 (13:51 -0400)]
Configurable vlan_id's for isolated networks

This patch adds parameters to configure the various
vlan IDs to all of the bond-with-vlans and single-nic-vlans
network config templates.

Change-Id: Ia6196735927777b73879e8086568f8a435597c6c

9 years agoMake puppet-applying *Post resources depend on hieradata
Steven Hardy [Fri, 12 Jun 2015 14:43:30 +0000 (15:43 +0100)]
Make puppet-applying *Post resources depend on hieradata

When you do a stack-update which affects, e.g ControllerDeployment
such that some value in hieradata is updated (for example changing
the "Debug" parameter to True), we only write the hieradata file and
don't reapply the manifests.

So we introduce a dependency on the deploy_stdout values from all
hieradata applying configs, such that the manifests will be re-applied
on update if the data is changed.

This requires https://review.openstack.org/#/c/190282/ so that
99-refresh-completed will return the derived config ID as part of the
deploy_stdout payload.

Closes-Bug: #1463092
Change-Id: I1175248c3236d0c42e37d062afce550efce8aadc

9 years agoMerge "Add BondInterfaceOvsOptions parameter"
Jenkins [Tue, 16 Jun 2015 07:50:28 +0000 (07:50 +0000)]
Merge "Add BondInterfaceOvsOptions parameter"

9 years agoMerge "network/config storage role fixes"
Jenkins [Tue, 16 Jun 2015 07:50:19 +0000 (07:50 +0000)]
Merge "network/config storage role fixes"

9 years agoMerge "Flexible IP allocations for isolated nets"
Jenkins [Tue, 16 Jun 2015 07:49:41 +0000 (07:49 +0000)]
Merge "Flexible IP allocations for isolated nets"

9 years agoMerge "Add support for isolating swift storage nets"
Jenkins [Tue, 16 Jun 2015 07:48:06 +0000 (07:48 +0000)]
Merge "Add support for isolating swift storage nets"

9 years agoMerge "Remove external bridge from Compute nodes"
Jenkins [Tue, 16 Jun 2015 07:47:36 +0000 (07:47 +0000)]
Merge "Remove external bridge from Compute nodes"

9 years agoAdd $hostname.localdomain alias to /etc/hosts
Giulio Fidente [Mon, 15 Jun 2015 16:26:03 +0000 (18:26 +0200)]
Add $hostname.localdomain alias to /etc/hosts

We want to make sure to be able to resolve the default domain
suffix (.localdomain) appended when no domain option is passed by
the dhcp server.

Change-Id: I33111e91b502f57da442e5745de2217bd6d2d882

9 years agoRemove Redis VirtualIP from params and build it from Neutron::Port
Giulio Fidente [Fri, 12 Jun 2015 14:17:19 +0000 (16:17 +0200)]
Remove Redis VirtualIP from params and build it from Neutron::Port

The redis_vip should come from a Neutron Port as its cidr depends
on the Neutron Network configuration. This change adds 2 new files
and modifies 1 in the network/ports directory:

- noop.yaml - Passes through the ctlplane Controller IP (modified)
- ctlplane_vip.yaml - Creates a new VIP on the control plane
- vip.yaml - Creates a VIP on the named network (for isolated nets)

Also, changes to overcloud-without-mergepy.yaml create the
Redis Virtual IP. The standard resource registry was modified to
use noop.yaml for the new Redis VIP. The Puppet resource registry
was modified to use ctlplane_vip.yaml by default, but can be made
to use vip.yaml when network isolation is used by using an
environment file. vip.yaml will place the VIP according to the
ServiceNetMap, which can also be overridden.

We use this new VIP port definition to assign a VIP to Redis,
but follow-up patches will assign VIPs to the rest of the
services in a similar fashion.

Co-Authored-By: Dan Sneddon <dsneddon@redhat.com>
Change-Id: I2cb44ea7a057c4064d0e1999702623618ee3390c

9 years agoFlexible IP allocations for isolated nets
Dan Prince [Fri, 12 Jun 2015 18:05:19 +0000 (14:05 -0400)]
Flexible IP allocations for isolated nets

This patch adds new '<net name>AllocationPool' parameters
to all of the isolated network nested stacks so that users
can easily control the allocation ranges on these networks.

Change-Id: I44b564831446c62e3489a69d992e0fb1f642b085

9 years agoFix Redis bind setting to use redis_network
Giulio Fidente [Fri, 12 Jun 2015 09:52:55 +0000 (11:52 +0200)]
Fix Redis bind setting to use redis_network

The Redis bind host should be set from [1] template.

1. https://github.com/openstack/tripleo-heat-templates/blob/master/puppet/controller-puppet.yaml#L985

Change-Id: I8713db1a7ad739692817921248edcc6b0e819ade

9 years agoAdds horizon to pacemaker when puppet-pacemaker is enabled
marios [Thu, 4 Jun 2015 09:02:16 +0000 (12:02 +0300)]
Adds horizon to pacemaker when puppet-pacemaker is enabled

Adds the horizon (httpd) service as pacemaker resource
Also adds a default for the horizon::django_session_engine [1]
which was previously unconfigured. Also adds a server-status.conf
for httpd/pacemaker [2]

[1] https://docs.djangoproject.com/en/dev/topics/http/sessions/#using-cached-sessions
[2] https://github.com/beekhof/osp-ha-deploy/blob/master/pcmk/horizon.scenario#L72

Change-Id: I320837dfecf3241355e8a3345d0ff271592da491

9 years agoRemove external bridge from Compute nodes
Dan Sneddon [Thu, 11 Jun 2015 22:44:05 +0000 (15:44 -0700)]
Remove external bridge from Compute nodes

This change modifies overcloud-resource-registry-puppet.yaml to
use net-config-noop.yaml as the default os-net-config template
for compute nodes. The current default of net-config-bridge.yaml
will set up a br-ex on the compute nodes. Since we are not using
DVR that is not needed.

Change-Id: I4e149a4f5a6d19e94e8c0245f52677f92f22d3ec

9 years agoRename ServiceNetMap: NeutronLocalIp
Dan Prince [Wed, 10 Jun 2015 23:51:04 +0000 (19:51 -0400)]
Rename ServiceNetMap: NeutronLocalIp

This patch renames the NeutronLocalIp option to be called
NeutronTenantNetwork. This is more consistent with
all of the other ServiceNetMap settings which end in
'Network' and initial end user feedback found the
old name a bit cryptic as well.

This is the network for neutron tenant traffic so lets
just name it that.

Change-Id: Id49afe75c372887453413c092190a5775aa3e1ee

9 years agoIsolate network traffic for Nova VNC proxy
Dan Prince [Wed, 10 Jun 2015 23:47:41 +0000 (19:47 -0400)]
Isolate network traffic for Nova VNC proxy

This patch makes it possible to configure the isolated network
for the Nova vnc proxy client.

Change-Id: I462dfaea94e5fe9cb260ba91a42433a250f07984

9 years agoAdd support for isolating swift storage nets
Dan Prince [Fri, 5 Jun 2015 02:47:15 +0000 (22:47 -0400)]
Add support for isolating swift storage nets

This patch updates the Puppet Swift storage role
so that it supports network isolation. By default
all traffic still flows on the ctlplane network
but if network isolation is enabled then network
traffic will flow over the configured storage_mgmt
network interface.

This patch also fixes a few critical issues with
the swift storage role that prevented it from
working:
 - oac_data for the swift devices was overriding the
   data provided in the swift_devices_and_proxy
   hieradata file.
 - the role was missing declarations to load hieradata
   files for swift_devices_and_proxy and all_nodes
 - The required snmpd settings were not getting set
   correctly in the 'object' hiera data file.

With all of these changes the Swift storage role
works correctly with and without network isolation.

Change-Id: I541abb2604380f603bba91ad88e54783ee450a8f

9 years agoAdd BondInterfaceOvsOptions parameter
Dan Prince [Tue, 9 Jun 2015 17:30:17 +0000 (13:30 -0400)]
Add BondInterfaceOvsOptions parameter

This patch adds a new BondInterfaceOvsOptions to the
bond-with-vlans network config templates. This can
be used to configure things like LACP or the bonding mode
via a nested stack heat parameter.

The patch also removes the hard coded ovs_options relating
to both bond-with-vlans and single-nic-with-vlans configurations
which do not actually require this setting to be hard coded
because by default OVS trunks vlan ports automatically.

Change-Id: I3effbccba8ed7ed28d6ba715e5709275d4e7f984

9 years agonetwork/config storage role fixes
Dan Prince [Thu, 4 Jun 2015 02:08:50 +0000 (22:08 -0400)]
network/config storage role fixes

None of the storage roles have Heat parameters for the bridge
name. Instead of wiring in Heat parameters for bridge name
this patch hard codes the bridge name for the storage roles
to 'br-storage'.

This functionally fixes the network config scripts for each
of the storage roles.

For the single-nic-vlans storage roles we also remove
the 'bond1' reference which was also incorrectly specified.

Change-Id: I460d1a17e44ee49e960117ec85edd3ae25894333

9 years agoMerge "Enable use of coordination_url in ceilometer"
Jenkins [Tue, 9 Jun 2015 07:55:13 +0000 (07:55 +0000)]
Merge "Enable use of coordination_url in ceilometer"

9 years agoMerge "Add Redis as a Pacemaker resource"
Jenkins [Tue, 9 Jun 2015 07:15:33 +0000 (07:15 +0000)]
Merge "Add Redis as a Pacemaker resource"

9 years agoMerge "Enable NetApp Backends in Cinder"
Jenkins [Mon, 8 Jun 2015 15:31:29 +0000 (15:31 +0000)]
Merge "Enable NetApp Backends in Cinder"

9 years agoConfig & deployments to update overcloud packages
Steve Baker [Mon, 4 May 2015 23:25:40 +0000 (11:25 +1200)]
Config & deployments to update overcloud packages

This change adds config and deployment resources to trigger package
updates on nodes. The deployments are triggered by doing a stack-update
and setting one of the parameters to a unique value.

The intent is that rolling update will be controlled by setting
breakpoints on all of the UpdateDeployment resources inside the
role resource groups.

Change-Id: I56bbf944ecd6cbdbf116021b8a53f9f9111c134f

9 years agoUpdate mongodb implementation to reflect master
Yanis Guenane [Tue, 26 May 2015 14:38:59 +0000 (16:38 +0200)]
Update mongodb implementation to reflect master

Two PR have been merged upstream that let use improve our current
implementation :

  * service_manage[1]
  * conn string has namevar[2]

[1] https://github.com/puppetlabs/puppetlabs-mongodb/pull/198
[2] https://github.com/puppetlabs/puppetlabs-mongodb/pull/200

Change-Id: Ia2247348a9e0292b5fcbc65ea1e41e6bc7c477fa

9 years agoEnable use of coordination_url in ceilometer
Yanis Guenane [Thu, 9 Apr 2015 10:24:53 +0000 (12:24 +0200)]
Enable use of coordination_url in ceilometer

Since t-h-t can now deploy a Redis cluster, we can rely on it as the
tooz backend for high availability.

Change-Id: If045a273388aa2e725b6de624e09aa9c85248cc4

9 years agoAdd Redis as a Pacemaker resource
Yanis Guenane [Wed, 13 May 2015 11:02:47 +0000 (13:02 +0200)]
Add Redis as a Pacemaker resource

Change-Id: I731b408f24da01c1bc897bfffe8fd4d5638932ed

9 years agoMerge "Fix list of type_drivers for ML2 plugin"
Jenkins [Fri, 5 Jun 2015 15:24:46 +0000 (15:24 +0000)]
Merge "Fix list of type_drivers for ML2 plugin"

9 years agoMerge "Wire Neutron VLAN ranges param as array to puppet"
Jenkins [Fri, 5 Jun 2015 15:23:50 +0000 (15:23 +0000)]
Merge "Wire Neutron VLAN ranges param as array to puppet"

9 years agoEnable NetApp Backends in Cinder
Ryan Hefner [Tue, 12 May 2015 17:52:43 +0000 (13:52 -0400)]
Enable NetApp Backends in Cinder

Enables support for configuring Cinder with a NetApp backend.
This change adds all relevant parameters for:
 - Clustered Data ONTAP (NFS, iSCSI, FC)
 - Data ONTAP 7-Mode (NFS, iSCSI, FC)
 - E-Series (iSCSI)

Change-Id: If6c6e511ef2d26c4794e3b37c61e5318485ff4db

9 years agoFix list of type_drivers for ML2 plugin
Giulio Fidente [Tue, 2 Jun 2015 06:21:13 +0000 (08:21 +0200)]
Fix list of type_drivers for ML2 plugin

The list of drivers loaded by the ML2 plugin does not have to
match the list of tenant_network_types, this will make ML2 load
the flat, gre, vxlan and vlan drivers so that the provider
networks can be of flat (default) and vlan type as well.

Change-Id: I0b74f86acf5c1ff644deb46c0a1d14129c1882d4

9 years agoWire Neutron VLAN ranges param as array to puppet
Giulio Fidente [Tue, 2 Jun 2015 12:32:55 +0000 (08:32 -0400)]
Wire Neutron VLAN ranges param as array to puppet

Turns NeutronNetworkVLANRanges into a list and makes it consumable by
neutron::plugins::ml2::network_vlan_ranges as an array. Previously
usage of vlans was impossible due to puppet-neutron failing to
join() network_vlan_ranges.

Also fixes wiring of network_vlan_ranges on computes and adds a
sample environment file to test use of vlans for tenant networks.

Change-Id: I8725cdb9591dd8d0b7125fdacbefdc9138703266

9 years agoIsolate the Ceph storage and storage_mgmt nets
Dan Prince [Thu, 4 Jun 2015 02:01:36 +0000 (22:01 -0400)]
Isolate the Ceph storage and storage_mgmt nets

This patch updates the Ceph configuration for the puppet
implementation so that it isolates the Ceph traffic
for the public and cluster interfaces. By default public traffic
runs on the "storage" network and the cluster traffic runs on the
"storage mgmt" network.

If network isolation is not enabled then the default
ctlplane address's will be used for both the public and
cluster interfaces.

Change-Id: I791244d72c8f42142d9de99e0cf0acdca19e62b0

9 years agoconfigure pacemaker VIPs for isolated networks
Dan Prince [Mon, 1 Jun 2015 14:37:35 +0000 (10:37 -0400)]
configure pacemaker VIPs for isolated networks

This patch updates the overcloud pacemaker role manifest so
that it optionally configures VIPs on isolated networks if
they are enabled.

Change-Id: I6123ee622abe4d8d7b5f76cf9bac43acd80c1f64

9 years agoSet glance_api_servers for cinder
Dan Prince [Mon, 1 Jun 2015 14:26:38 +0000 (10:26 -0400)]
Set glance_api_servers for cinder

This patch updates the hiera configuration for the Cinder API so
that we set glance_api_servers. By default Cinder constructs
a glance URL based on $my_ip (the local IP of the machine)
which may not be correct if you are running Glance on a non-default
internal network.

By setting glance_api_servers to the same thing we already
use for Nova we make Cinder contact the correct Glance URL
regardless of the network settings.

Change-Id: I1c56eb585ddfdc9989a8b55bc1bac819802f7794

9 years agopuppet controller role: per service VIP settings
Dan Prince [Mon, 1 Jun 2015 14:18:10 +0000 (10:18 -0400)]
puppet controller role: per service VIP settings

This patch refactors the puppet controller role so that it
makes use of per service VIP settings for each service.

Previously the VIP for the ctlplane was hard wired to
many of the controller service. With this patch we have
the ability to isolate traffic for services which
made use of the ctlplane and public VIPs for their
settings.

The implementation includes:

 * stops the use of the VirtualIP and PublicVirtualIP within the
   controller role. These parameters have now been replaced with
   per service heat parameters for the controller nested stack which
   are determined via VipMap based on per service settings in the heat
   environment.

 * All VIP configuration is now moved into puppet/vip-config.yaml.
   This made sense so we could deprecate the use of the VirtualIP
   and PublicVirtualIP settings above.

 * The puppet manifests for the controller were cleaned up for several
   to use Hiera directly instead of constructing URLs based on the
   static controller and public network VIPs. This improvement
   was something we wanted to do anyways and made the implementation
   cleaner.

Change-Id: I9b9a15be67f74bec97366408f7047acfd6ea0ec6

9 years agoMerge "horizon/keystone api should use internal_api NW"
Jenkins [Thu, 4 Jun 2015 14:01:37 +0000 (14:01 +0000)]
Merge "horizon/keystone api should use internal_api NW"

9 years agoMerge "Add virtual IPs for split out networks"
Jenkins [Thu, 4 Jun 2015 13:38:22 +0000 (13:38 +0000)]
Merge "Add virtual IPs for split out networks"

9 years agoMerge "Add PortName to ports stacks"
Jenkins [Thu, 4 Jun 2015 13:37:05 +0000 (13:37 +0000)]
Merge "Add PortName to ports stacks"

9 years agoMerge "Combine Heat API networks into single net"
Jenkins [Thu, 4 Jun 2015 13:36:51 +0000 (13:36 +0000)]
Merge "Combine Heat API networks into single net"

9 years agoMerge "Make all-nodes Ip networks configurable"
Jenkins [Thu, 4 Jun 2015 13:33:00 +0000 (13:33 +0000)]
Merge "Make all-nodes Ip networks configurable"

9 years agoMerge "Wire ServiceNetMap as a top level parameter"
Jenkins [Thu, 4 Jun 2015 13:32:37 +0000 (13:32 +0000)]
Merge "Wire ServiceNetMap as a top level parameter"

9 years agoMerge "Pass NeutronEnableTunnelling to controllers"
Jenkins [Thu, 4 Jun 2015 12:20:42 +0000 (12:20 +0000)]
Merge "Pass NeutronEnableTunnelling to controllers"

9 years agoMerge "Set VXLAN tunnels range to match GRE range"
Jenkins [Thu, 4 Jun 2015 12:20:35 +0000 (12:20 +0000)]
Merge "Set VXLAN tunnels range to match GRE range"

9 years agoMerge "Wire Neutron allow_automatic_l3agent_failover param to module"
Jenkins [Thu, 4 Jun 2015 10:38:24 +0000 (10:38 +0000)]
Merge "Wire Neutron allow_automatic_l3agent_failover param to module"

9 years agoPass NeutronEnableTunnelling to controllers
Giulio Fidente [Tue, 2 Jun 2015 08:13:29 +0000 (04:13 -0400)]
Pass NeutronEnableTunnelling to controllers

We forgot to pass NeutronEnableTunnelling param to controllers
(passed only to computes), making it unusable.

Change-Id: I74756732deabd1c7ba9039832ea169fd322a569f

9 years agoSet VXLAN tunnels range to match GRE range
Giulio Fidente [Mon, 1 Jun 2015 16:50:43 +0000 (12:50 -0400)]
Set VXLAN tunnels range to match GRE range

Change-Id: I16d259055fe4cd22541cd7abd7a26c71bbbaf292

9 years agoMerge "os-net-config templates to configure vlans"
Jenkins [Wed, 3 Jun 2015 15:03:54 +0000 (15:03 +0000)]
Merge "os-net-config templates to configure vlans"