apex-tripleo-heat-templates.git
7 years agoAdds Doctor DS driver to Congress 67/39067/2
Carlos Goncalves [Thu, 10 Aug 2017 13:44:31 +0000 (15:44 +0200)]
Adds Doctor DS driver to Congress

Include the Doctor data source driver to the list of drivers to load.

JIRA: APEX-498

Change-Id: I0749ed6e0d27bd4c9a5bb19657579d400501d09e
Signed-off-by: Carlos Goncalves <carlos.goncalves@neclab.eu>
7 years agoAdds networking-sfc support 57/38557/3
Tim Rozet [Tue, 1 Aug 2017 20:58:00 +0000 (16:58 -0400)]
Adds networking-sfc support

Enables deployment of service function chaining via the networking-sfc
project.

Implements: blueprint networking-sfc-support

Depends-On: Icd433ddc6ae7de19a09f9e33b410a362c317138a

Change-Id: I230b31dc9ed0ecc5046064628ba2f2505e589522
Signed-off-by: Tim Rozet <trozet@redhat.com>
7 years agoAdd Barometer service as a Compute role. 81/36681/2
jhinman1 [Wed, 28 Jun 2017 22:45:42 +0000 (18:45 -0400)]
Add Barometer service as a Compute role.

Change-Id: I397d2557639c87ab8afacd076a5b9fd7c056dce7
Signed-off-by: jhinman1 <john.hinman@intel.com>
7 years agoMerge "Correcting keystone authtoken params for congress"
Tim Rozet [Tue, 1 Aug 2017 13:38:44 +0000 (13:38 +0000)]
Merge "Correcting keystone authtoken params for congress"

7 years agoMerge "Add VPP and Honeycomb services (#104)"
Tim Rozet [Mon, 31 Jul 2017 17:17:52 +0000 (17:17 +0000)]
Merge "Add VPP and Honeycomb services (#104)"

7 years agoCorrecting keystone authtoken params for congress 39/38439/2
Dan Radez [Mon, 31 Jul 2017 13:05:51 +0000 (09:05 -0400)]
Correcting keystone authtoken params for congress

JIRA: APEX-495

Change-Id: Ibada3c58e2ba870defef356363dbf54d02c8a965
Signed-off-by: Dan Radez <dradez@redhat.com>
7 years agoAdd VPP and Honeycomb services (#104) 95/37795/5
Feng Pan [Wed, 19 Jul 2017 16:40:59 +0000 (12:40 -0400)]
Add VPP and Honeycomb services (#104)

- Add VPP and honeycomb service
- Add NeutronOverlayIPVersion setting for IPv6 vxlan tunnel endpoint

Change-Id: If11092e6581445a70e63c8f6c48518698b3cc8fc
Signed-off-by: Feng Pan <fpan@redhat.com>
7 years agoAdding NeutronCorePlugin service to BGPVPN scenario 93/37793/1
Ricardo Noriega [Wed, 19 Jul 2017 16:16:30 +0000 (18:16 +0200)]
Adding NeutronCorePlugin service to BGPVPN scenario

  It is necessary for OpenDaylight deployments

Change-Id: I9b487c58aef01f45cceaddf751fa89a3fa8a7998
Signed-off-by: Ricardo Noriega <rnoriega@redhat.com>
7 years agoEnables OpenDaylight clustering in HA deployments 75/37275/1
Tim Rozet [Thu, 26 Jan 2017 17:18:24 +0000 (12:18 -0500)]
Enables OpenDaylight clustering in HA deployments

Port 2550 is required for inter-ODL communication when clustering.
odl-jolokia feature is required to expose REST APIs from ODL for
monitoring the cluster.

Implements: blueprint opendaylight-ha

Depends-On: Ic9a955a1c2afc040b2f9c6fb86573c04a60f9f31

Change-Id: Ie108ab75cce0cb7d89e72637c600e30fc241d186
Signed-off-by: Tim Rozet <trozet@redhat.com>
7 years agoAdd BGPVPN composable service
Ricardo Noriega [Thu, 29 Jun 2017 16:02:28 +0000 (18:02 +0200)]
Add BGPVPN composable service

Depends-On: I4af82d456c9d999667f2ef4d16e8f6822463d331
Change-Id: Id28df6ed307976fbb20fa1300f7349b743d96569
Signed-off-by: Ricardo Noriega <rnoriega@redhat.com>
7 years agoPointing apex fork to opnfv's gerrit
Dan Radez [Tue, 9 May 2017 12:57:56 +0000 (08:57 -0400)]
Pointing apex fork to opnfv's gerrit

Change-Id: Ic65cfeee4a55e993629f831c8c9d9addf6f3dff4
Signed-off-by: Dan Radez <dradez@redhat.com>
7 years agoBackport container CI environments to Ocata
Jiri Stransky [Mon, 10 Jul 2017 14:45:55 +0000 (16:45 +0200)]
Backport container CI environments to Ocata

Merging change I8361bc8be442b45c3ef6bdccdc53598fcb1d9540 broke the
upgrade jobs from Ocata to Pike, as until now we've been taking the
scenario files from Pike when they were undefined in Ocata, but this
obviously stops working when they reference other files that are also
undefined in Ocata (like all-nodes-validation-disabled.yaml).

Backporting the scenarios and required files to Ocata should solve
these kinds of issues, but will make managing the scenarios, which are
still in emerging state, slightly more difficult.

Change-Id: I8a54cf984f41b5e21cf1c4a667da5b8f135ffb15
Closes-Bug: #1703391

7 years agocisco nexus: keep OVS on the Compute
Gonéri Le Bouder [Wed, 21 Jun 2017 19:00:27 +0000 (15:00 -0400)]
cisco nexus: keep OVS on the Compute

The Cisco Nexus-UCSM environment relies on OVS for the communication
with compute nodes. This is a partial revert of
I4c98008107568b3b65decd7640e25c7d2b1ea9ff.

Change-Id: I453d4bc83314a76fd779884fb2f8cd1731d2bcaa
Related-Bug: #1687597
(cherry picked from commit 9eb4311c9d07cb14824d502904cce2dfce23cb88)

7 years agoDisable swift middleware ceilometer pipeline by default
Pradeep Kilambi [Fri, 23 Jun 2017 14:37:24 +0000 (10:37 -0400)]
Disable swift middleware ceilometer pipeline by default

This generates tons of unnecessary events when gnocchi uses swift backend.
We end up filtering most of these anyway. So lets disable this so it
doesn't put useless load. Also changing the default project to service as
thats what gnocchi uses to authenticate with swift.

Closes-bug: #1693339

Change-Id: I40f47d46fdb06f31a739b590bf653bca71e33f61
(cherry picked from commit 142b5a28896d788a7112ae8bd2885e6c7dfcc832)

7 years agoMerge "Enable periodic task to discover cell hosts when ironic is used" into stable...
Jenkins [Tue, 27 Jun 2017 15:07:32 +0000 (15:07 +0000)]
Merge "Enable periodic task to discover cell hosts when ironic is used" into stable/ocata

7 years agoEnable periodic task to discover cell hosts when ironic is used
Dmitry Tantsur [Tue, 13 Jun 2017 16:05:33 +0000 (18:05 +0200)]
Enable periodic task to discover cell hosts when ironic is used

Starting with the Ocata release, bare metal nodes are no longer get recognized
by nova automatically. To avoid forcing users into running nova manage command
each time they enroll a node, we will have to allow enable the periodic task
to do so.

Change-Id: I8b0afac54dc9bd51dbe2ae4f237e4de50459be0f
Closes-Bug: #1697724
(cherry picked from commit f0807b535b0cff5eac82fdaa9719650f79839c15)

7 years agoFixes incorrect glance api network
Tim Rozet [Wed, 21 Jun 2017 15:40:21 +0000 (11:40 -0400)]
Fixes incorrect glance api network

The glance API network was being set to storage and it should be
internal_api.

Closes-Bug: 1699535

Change-Id: I75bc05aeab999f0e3eb3f4ebaceb276e888addc9
Signed-off-by: Tim Rozet <trozet@redhat.com>
(cherry picked from commit efefc0911858a42977a8073c48f428646b4a7fc0)

7 years agoAdd parameter Ec2ApiExternalNetwork for VPCs
Sven Anderson [Thu, 13 Apr 2017 16:29:50 +0000 (18:29 +0200)]
Add parameter Ec2ApiExternalNetwork for VPCs

Change-Id: I26652afe0f513ec354c05570e7fa0e5b4b0ab669
Related-Bug: #1676491
(cherry picked from commit 773505222f2022e829d3aa3dbb8200af0ac952e3)

7 years agoMerge "Add support for Cinder "NAS secure" driver params" into stable/ocata
Jenkins [Sat, 17 Jun 2017 20:59:48 +0000 (20:59 +0000)]
Merge "Add support for Cinder "NAS secure" driver params" into stable/ocata

7 years agoMerge "Add support for autofencing to Pacemaker Remote." into stable/ocata
Jenkins [Fri, 16 Jun 2017 23:25:16 +0000 (23:25 +0000)]
Merge "Add support for autofencing to Pacemaker Remote." into stable/ocata

7 years agoMerge "Add ignore_projects to filter gnocchi events" into stable/ocata
Jenkins [Fri, 16 Jun 2017 21:41:57 +0000 (21:41 +0000)]
Merge "Add ignore_projects to filter gnocchi events" into stable/ocata

7 years agoMerge "Dell SC: Add exclude_domain_ip option" into stable/ocata
Jenkins [Fri, 16 Jun 2017 16:33:14 +0000 (16:33 +0000)]
Merge "Dell SC: Add exclude_domain_ip option" into stable/ocata

7 years agoAdd support for Cinder "NAS secure" driver params
Alan Bishop [Thu, 4 May 2017 16:31:56 +0000 (12:31 -0400)]
Add support for Cinder "NAS secure" driver params

Add new parameters that control the NAS security settings in Cinder's
NFS and NetApp back end drivers. The settings are disabled by default.

Partial-Bug: #1688332
Depends-On: I76e2ce10acf7b671be6a2785829ebb3012b79308
Change-Id: I306a8378dc1685132f7ea3ed91d345eaae70046f
(cherry picked from commit 4a48ad89a16b79ac57475a3cb4427b9b60dcd3e3)

7 years agoMerge "Add fqdn_external" into stable/ocata
Jenkins [Thu, 15 Jun 2017 21:52:41 +0000 (21:52 +0000)]
Merge "Add fqdn_external" into stable/ocata

7 years agoAdd ignore_projects to filter gnocchi events
Pradeep Kilambi [Tue, 23 May 2017 14:41:22 +0000 (10:41 -0400)]
Add ignore_projects to filter gnocchi events

Without this, ceilometer db gets hammered with gnocchi swift events.
Keystone creds are required so middleware can query for id.

Related change:  I5c0f4f1a2c7fe7eb39ea6441970e9ac0946a4ec1

Change-Id: I9a7a80252703e470a69dc10352e7ece45ab23150
(cherry picked from commit 37447494de7380409f4461835a2b1882ead37985)

7 years agoDell SC: Add exclude_domain_ip option
rajinir [Mon, 10 Apr 2017 18:21:38 +0000 (13:21 -0500)]
Dell SC: Add exclude_domain_ip option

This option allows users to exclude some fault domains.
Otherwise all domains are returned.

Change-Id: Iefd1a44c8fe217aee5845bba35def571317bb123
Closes-Bug: #1681490
Depends-On: I6eb2bcc7db003a5eebd3924e3e4eb44e35f60483
(cherry picked from commit e0bc8d6813d7cd0ecbef1dfe17d9d3cfec4225d7)

7 years agoMerge "Dell SC: Add secondary DSM support" into stable/ocata
Jenkins [Wed, 14 Jun 2017 15:04:14 +0000 (15:04 +0000)]
Merge "Dell SC: Add secondary DSM support" into stable/ocata

7 years agoAdd fqdn_external
Alex Schultz [Tue, 13 Jun 2017 15:39:11 +0000 (09:39 -0600)]
Add fqdn_external

In newton, we used to construct the fqdn_$NETWORK in puppet-tripleo for
external, internal_api, storage, storage_mgmt, tenant, management, and
ctrlplane. When this was moved into THT, we accidently dropped external
which leads to deployment failures if a service is moved to the external
network and the configuration consumes the fqdn_external hiera key.
Specifically this is reproduced if the MysqlNetwork is switch to to
exernal, then the deployment fails because the bind address which is set
to use fqdn_external is blank.

Change-Id: I01ad0c14cb3dc38aad7528345c928b86628433c1
Closes-Bug: #1697722
(cherry picked from commit 426de202880c890360bd446907aca44ca1e73a03)

7 years agoMoving *postconfig where it was *postpuppet
Carlos Camacho [Thu, 8 Jun 2017 21:18:44 +0000 (23:18 +0200)]
Moving *postconfig where it was *postpuppet

We need to ensure that the pacemaker cluster restarts
in the end of the deployment.

Due to the resources renaming we added the
postconfig resource not in the end of the
deployment as it was *postpuppet.

Closes-bug: 1695904

Change-Id: Ic6978fcff591635223b354831cd6cbe0802316cf

7 years agoAdd support for autofencing to Pacemaker Remote.
Chris Jones [Tue, 25 Apr 2017 15:03:10 +0000 (16:03 +0100)]
Add support for autofencing to Pacemaker Remote.

We now pass configuration for autofencing to Pacemaker Remote nodes.

Change-Id: Ibb9c65a83cc909528024c538cf3bcc96390c555e
Depends-On: I87c60bd56feac6dedc00a3c458b805aa9b71d9ce
Closes-Bug: #1686115
(cherry picked from commit 05953542a6b688ee549671a46cecb5951b6c3fee)

7 years agoExpose metric delay processing metric
Pradeep Kilambi [Fri, 21 Apr 2017 20:16:38 +0000 (16:16 -0400)]
Expose metric delay processing metric

For performance reasons we might want to tweak this param
lets expose this via tripleo. The puppet changes were
added in this patch I5de5283d1b14e0bba63d6d9a440611914ba86ca4

Change-Id: I72f1fe3a47060fe37602a70b8a74fba72209127c
(cherry picked from commit e33e76684c9b60b9ce50ad7996529ed49dddd9d9)

7 years agoFix the constraints for THT params NeutronDpdkCoreList and HostCpusList
Karthik S [Wed, 31 May 2017 12:31:59 +0000 (08:31 -0400)]
Fix the constraints for THT params NeutronDpdkCoreList and HostCpusList

This fix needs to be backported to ocata.

Conflicts:
puppet/services/neutron-ovs-dpdk-agent.yaml

Signed-off-by: Karthik S <ksundara@redhat.com>
Closes-Bug: #1694703
Change-Id: I5938761efa4f56e576f41929e0bc12df246ac81a
(cherry picked from commit 61480182f8a6f27ab7e1e73b9dd79e17a4927f0f)

7 years agoMerge "Restrict nova migration ssh tunnel" into stable/ocata
Jenkins [Mon, 5 Jun 2017 23:17:37 +0000 (23:17 +0000)]
Merge "Restrict nova migration ssh tunnel" into stable/ocata

7 years agoMerge "Handle upgrading cinder-volume under pacemaker" into stable/ocata
Jenkins [Mon, 5 Jun 2017 19:26:15 +0000 (19:26 +0000)]
Merge "Handle upgrading cinder-volume under pacemaker" into stable/ocata

7 years agoMerge "Updated from global requirements" into stable/ocata
Jenkins [Fri, 2 Jun 2017 23:57:27 +0000 (23:57 +0000)]
Merge "Updated from global requirements" into stable/ocata

7 years agoHandle upgrading cinder-volume under pacemaker
Alan Bishop [Tue, 23 May 2017 14:42:24 +0000 (10:42 -0400)]
Handle upgrading cinder-volume under pacemaker

Add upgrade tasks for cinder-volume when it's controlled by pacemaker:

o Stop the service before the entire pacemaker cluster is stopped.
  This ensures the service is stopped before infrastructure services
  (e.g. rabbitmq) go away.
o Migrate the cinder DB prior to restarting the service. This covers
  the situation when puppet-cinder (who otherwise would handle the db
  sync) isn't managing the service.
o Start the service after the rest of the pacemaker cluster has been
  started.

Closes-Bug: #1691851
Change-Id: I5874ab862964fadb68320d5c4de39b20f53dc25c
(cherry picked from commit c4e3bbe039135f32f0e198365e704b3dbfd00290)

7 years agoRestrict nova migration ssh tunnel
Oliver Walsh [Wed, 19 Apr 2017 13:51:02 +0000 (14:51 +0100)]
Restrict nova migration ssh tunnel

Specify the allowed networks for migration ssh tunneling.

bp tripleo-cold-migration

Change-Id: Iab022bdfb655e3c52fecebf416e75c9e981072ab
Depends-on: Idb56acd1e1ecb5a5fd4d942969be428cc9cbe293
(cherry picked from commit 3d8af2fcf8e2d41600fa10584120a8117e7ef40c)

7 years agoUpdated from global requirements
OpenStack Proposal Bot [Tue, 30 May 2017 19:09:04 +0000 (19:09 +0000)]
Updated from global requirements

Change-Id: Ife3a3ee576b940f1f8a06d26a0cb99d69423cf9f

7 years agoEnable arp_accept for all interfaces
Ihar Hrachyshka [Wed, 24 May 2017 01:13:28 +0000 (18:13 -0700)]
Enable arp_accept for all interfaces

OpenStack heavily relies on gratuitous ARP updates when moving floating
IP addresses between devices. When a floating IP moves, Neutron L3 agent
issues a burst of gratuitous ARP packets that should update any existing
ARP table entries on all nodes that belong to the same network segment.

Due to locktime kernel behavior, some gratuitous ARP packets may be
ignored [1], rendering ARP table entries broken for some time. Due to a
kernel bug [2], the time may be as long as hours, depending on other
traffic flowing to the node.

With the current EL7 kernel, the only way to make sure that nodes honor
all sent gratuitous ARP updates is to set arp_accept to 1; this will
disable locktime mechanism for the packets sent by Neutron L3 agent, and
will make sure ARP tables are always updated.

[1] https://patchwork.ozlabs.org/patch/762732/
[2] https://bugzilla.redhat.com/show_bug.cgi?id=1450203

Conflicts:
puppet/services/kernel.yaml

Related-Bug: #1690165
Change-Id: I863b240e0ab4c4d5bb844f91b607fd0937d5cedf
(cherry picked from commit 804fd3427eeb31a2846ee096dbdac924ec39bcbc)

7 years agoAdd heat environment for disabling all telemetry services
John Trowbridge [Thu, 25 May 2017 13:24:57 +0000 (09:24 -0400)]
Add heat environment for disabling all telemetry services

This will be used in our HA OVB CI job where we currently are
failing due to running out of memory. Telemetry will still be
tested via scenarios, but this will free up a large chunk of
memory in the most memory intensive job.

Closes-Bug: 1693174
Change-Id: Idefe9f0de47c5b0f29b7326642d697ed179e2eb8
(cherry picked from commit 0751d69e3b6560ef87ed43859df92fdcc08f9cd1)

7 years agoAdd $STACK_NAME input var
James Slagle [Thu, 27 Apr 2017 17:00:17 +0000 (13:00 -0400)]
Add $STACK_NAME input var

The stack name can now be overridden in the get-occ-config.sh script for
deployed-server's by setting the $STACK_NAME variable in the
environment.

Change-Id: Iecba21499b80e463b4c629be53c309996d39472d
Closes-Bug: #1686719
(cherry picked from commit e17590c69e599a3eb6b4a18d2d6dbef9dede9ea8)

7 years agoDell SC: Add secondary DSM support
rajinir [Mon, 10 Apr 2017 18:32:06 +0000 (13:32 -0500)]
Dell SC: Add secondary DSM support

Adds support for a secondary DSM in case the primary becomes
unavailable.

Change-Id: I0887e15a7e1c90a4f333bef6cdbb5d43ba0cd838
Closes-Bug: #1681492
Depends-On: I331466e4f254b2b8ff7891b796e78cd30c2c87f7
(cherry picked from commit 69be0c2ae7131af20385b4f11a8190ed9fba32c7)

7 years agoMerge "Timeout early on pcs cluster status check0 during upgrade." into stable/ocata
Jenkins [Mon, 22 May 2017 15:00:00 +0000 (15:00 +0000)]
Merge "Timeout early on pcs cluster status check0 during upgrade." into stable/ocata

7 years agoMerge "Addition of firewall rules for Nuage" into stable/ocata
Jenkins [Sat, 20 May 2017 01:15:01 +0000 (01:15 +0000)]
Merge "Addition of firewall rules for Nuage" into stable/ocata

7 years agoMerge "Disable Manila CephFS snapshots by default" into stable/ocata
Jenkins [Sat, 20 May 2017 01:08:03 +0000 (01:08 +0000)]
Merge "Disable Manila CephFS snapshots by default" into stable/ocata

7 years agoAdd NodeCreateBatchSize parameter
Steven Hardy [Fri, 17 Mar 2017 09:53:14 +0000 (09:53 +0000)]
Add NodeCreateBatchSize parameter

This uses the heat resource group batched create feature to ensure
we don't create more than 30 nodes at a time, which has been reported
as the maximum supported by the default ironic ipxe/TFTP configuration.

Closes-Bug: #1688550
Change-Id: If3651e4c465d8d7bd4c8f2b48d45b1272ff2d272
Depends-On: I3551456664daf89d01f98bde85d7fb22a01d4a03
(cherry picked from commit 129881f2c600217ff06b4570950b4e60ff9a63b5)

7 years agoTimeout early on pcs cluster status check0 during upgrade.
Sofer Athlan-Guyot [Thu, 6 Apr 2017 14:55:08 +0000 (16:55 +0200)]
Timeout early on pcs cluster status check0 during upgrade.

There is a windows for the pcs cluster status to hang forever[1].  We
add a timeout during check0 to avoid this situation.  2 minutes should
be more than enought to get all the pcsd nodes to reply.

[1] https://bugzilla.redhat.com/show_bug.cgi?id=1292858

Closes-Bug: #1680477

Change-Id: Icb3dc76e031a3d4f26294f37d169f2f61d30973e
(cherry picked from commit 0ea21f51a8128e536404ffd87f741443c9287593)

7 years agoMerge "Disable ComputeNeutron* for cisco-nexus-ucsm" into stable/ocata
Jenkins [Tue, 16 May 2017 22:06:43 +0000 (22:06 +0000)]
Merge "Disable ComputeNeutron* for cisco-nexus-ucsm" into stable/ocata

7 years agoFix SshHostPubKeyDeployment on containerized nova-compute.
Oliver Walsh [Mon, 15 May 2017 20:21:57 +0000 (21:21 +0100)]
Fix SshHostPubKeyDeployment on containerized nova-compute.

This is failing since https://review.openstack.org/458672 merged
because the ssh host keys are not mapped to the container.

Change-Id: Ie868654f13bee04da642337cc344871903f40473
Closes-bug: #1690911

7 years agoDisable ComputeNeutron* for cisco-nexus-ucsm
Steven Hardy [Wed, 3 May 2017 08:44:21 +0000 (09:44 +0100)]
Disable ComputeNeutron* for cisco-nexus-ucsm

It seems this wasn't adjusted when https://review.openstack.org/#/c/338315/
landed, which added interfaces for compute specific neutron configuration,
which is disabled for most vendor backends.

Change-Id: I4c98008107568b3b65decd7640e25c7d2b1ea9ff
Related-Bug: #1687597
(cherry picked from commit 95fbda4d0254edb12bfec1ccd41d3b5f6204fe8f)

7 years agoMerge "Fix for the resource ControllerPostPuppetMaintenanceModeDeployment" into stabl...
Jenkins [Sat, 13 May 2017 00:40:39 +0000 (00:40 +0000)]
Merge "Fix for the resource ControllerPostPuppetMaintenanceModeDeployment" into stable/ocata

7 years agoMerge "Merge pre|post puppet resources into pre|post config." into stable/ocata
Jenkins [Fri, 12 May 2017 03:06:32 +0000 (03:06 +0000)]
Merge "Merge pre|post puppet resources into pre|post config." into stable/ocata

7 years agoFix for the resource ControllerPostPuppetMaintenanceModeDeployment
Carlos Camacho [Thu, 27 Apr 2017 09:00:32 +0000 (11:00 +0200)]
Fix for the resource ControllerPostPuppetMaintenanceModeDeployment

Depends-On: If88f403c85b79bd896a24c7816486709bd67706f
Closes-Bug:1686619
Change-Id: I7c32ca39a456de9833d30c31d41fcb727d2b0a34
(cherry picked from commit 77b4bd53dae1882ae3094597e674218b7773eda9)

7 years agoMerge pre|post puppet resources into pre|post config.
Jenkins [Mon, 24 Apr 2017 18:42:00 +0000 (18:42 +0000)]
Merge pre|post puppet resources into pre|post config.

The [Pre|Post]Puppet resources were renamed in
https://review.openstack.org/#/c/365763.
This was intended for having a pre/post deployment
steps using an agnostic name instead of
being attached to a technology.

The renaming was unintentionally reverted in
https://review.openstack.org/#/c/393644/ and
https://review.openstack.org/#/c/434451.

This submission merge both resources into one,
and remove the old pre|post hooks.

Change-Id: Ic9d97f172efd2db74255363679b60f1d2dc4e064
Closes-bug: #1669756
(cherry picked from commit 258c6ce52d0c8467f34693722a883d96345802b2)

7 years agoFix up pacemaker_status test in yum_update.sh
Michele Baldessari [Thu, 4 May 2017 09:46:45 +0000 (11:46 +0200)]
Fix up pacemaker_status test in yum_update.sh

In change I2aae4e2fdfec526c835f8967b54e1db3757bca17 we did the
following:
-pacemaker_status=$(systemctl is-active pacemaker || :)
+pacemaker_status=""
+if hiera -c /etc/puppet/hiera.yaml service_names | grep -q pacemaker;
then
+ pacemaker_status=$(systemctl is-active pacemaker)
+fi

we did that so due to LP#1668266: we did not want systemctl is-active to
fail on non pacemaker nodes. The problem with the above hiera check is
that it will match on pacemaker_remote nodes as well.

We cannot piggyback the pacemaker_enabled hiera key because that is true
on all nodes. So let's make the test check only for pacemaker service
without matching pacemaker remote. Tested with:
1) Test on a controller node with pacemaker service enabled
[root@overcloud-controller-0 ~]# hiera -c /etc/puppet/hiera.yaml -a service_names |grep '\bpacemaker\b'
"pacemaker",
[root@overcloud-controller-0 ~]# echo $?
0

2) Test on a compute node without pacemaker:
[root@overcloud-novacompute-0 puppet]# hiera -c /etc/puppet/hiera.yaml service_names |grep '\bpacemaker\b'
[root@overcloud-novacompute-0 puppet]# echo $?
1

3) Test on a node with pacemaker_remote in the service_names key:
[root@overcloud-novacompute-0 puppet]# hiera -c /etc/puppet/hiera.yaml service_names |grep '\bpacemaker\b'
[root@overcloud-novacompute-0 puppet]# echo $?
1

[root@overcloud-novacompute-0 puppet]# hiera -c /etc/puppet/hiera.yaml service_names |grep '\bpacemaker_remote\b'
 "pacemaker_remote"]
[root@overcloud-novacompute-0 puppet]# echo $?
0

NB: cherry-pick was not 100% clean due to unrelated lines being cleaned
up in master.

Change-Id: I54c5756ba6dea791aef89a79bc0b538ba02ae48a
Closes-Bug: #1688214
(cherry picked from commit 2244290424ffa7781fb5b64688908c218cd10ecd)

7 years agoInitial VIP ipv6 minor update code
Michele Baldessari [Thu, 27 Apr 2017 19:41:11 +0000 (21:41 +0200)]
Initial VIP ipv6 minor update code

To test this change we deployed a stock master with ipv6 which created a bunch
of ipv6 with /64 netmask:
[root@overcloud-controller-0 ~]# pcs resource show ip-fd00.fd00.fd00.2000..18
 Resource: ip-fd00.fd00.fd00.2000..18 (class=ocf provider=heartbeat type=IPaddr2)
  Attributes: ip=fd00:fd00:fd00:2000::18 cidr_netmask=64
  Operations: start interval=0s timeout=20s (ip-fd00.fd00.fd00.2000..18-start-interval-0s)
              stop interval=0s timeout=20s (ip-fd00.fd00.fd00.2000..18-stop-interval-0s)
              monitor interval=10s timeout=20s (ip-fd00.fd00.fd00.2000..18-monitor-interval-10s)

Then we update the THT folder with this patch and upload the new scripts on the undercloud via:
openstack overcloud deploy --update-plan-only ....

Then we kick off the minor update workflow:
openstack overcloud update stack -i overcloud

Once the controller-0 node (bootstrap node for pacemaker) is completed we have the
correct VIP configuration:
[root@overcloud-controller-0 heat-config-script]# pcs resource show ip-fd00.fd00.fd00.2000..18
 Resource: ip-fd00.fd00.fd00.2000..18 (class=ocf provider=heartbeat type=IPaddr2)
  Attributes: ip=fd00:fd00:fd00:2000::18 cidr_netmask=128 nic=vlan20 lvs_ipv6_addrlabel=true lvs_ipv6_addrlabel_value=99
  Operations: start interval=0s timeout=20s (ip-fd00.fd00.fd00.2000..18-start-interval-0s)
              stop interval=0s timeout=20s (ip-fd00.fd00.fd00.2000..18-stop-interval-0s)
              monitor interval=10s timeout=20s (ip-fd00.fd00.fd00.2000..18-monitor-interval-10s)

Also verified that running the script a second time does not alter the
(already fixed) VIPs.

Co-Authored-By: Damien Ciabrini <dciabrin@redhat.com>
Change-Id: I765cd5c9b57134dff61f67ce726bf88af90f8090
(cherry picked from commit 4923f5c4991bd539888b4175fae20025d6ef3957)

7 years agoAddition of firewall rules for Nuage
lokesh-jain [Mon, 3 Apr 2017 20:32:53 +0000 (16:32 -0400)]
Addition of firewall rules for Nuage

Added VxLAN and metadata agent firewall rules to neutron-compute-plugin
for Nuage. Removed a deprecated parameter 'OSControllerIp' as well.

Change-Id: If10c300db48c66b9ebeaf74b5f5fee9132e75366
(cherry picked from commit d5309c9443cbfe50ba5e7c15f025393a58b0804c)

7 years agoEnsure AllNodesExtraConfig runs before AllNodesDeploySteps
Steven Hardy [Tue, 2 May 2017 10:54:12 +0000 (11:54 +0100)]
Ensure AllNodesExtraConfig runs before AllNodesDeploySteps

When implementing custom roles, we lost an implicit dependency that
ensured AllNodesExtraConfig is applied before AllNodesDeploySteps,
which causes problems if you need to write hieradata via the
AllNodesExtraConfig hook (some cisco integrations we have in tree
do this, and are now broken because the ordering is no longer ensured.

Change-Id: Ie78ecbb4e135ab7f196867ef9d8d271049a9cd10
Closes-Bug: #1687597
(cherry picked from commit 4efc067a7e2965fc7a07eb05b019d0e3e8160606)

7 years agoUnset the UpgradeInitCommand on converge
marios [Thu, 27 Apr 2017 13:51:42 +0000 (16:51 +0300)]
Unset the UpgradeInitCommand on converge

In the converge envs we unset the UpgradeInitCommon since we used
that for the N..O upgrades workflow. However an operator may have
also overridden the UpgradeInitCommand so we should unset that
too.

Closes-Bug: 1686918
Change-Id: I3b316d04b78a4ab1e3f9f69948e42e6fb0ad6632
(cherry picked from commit 7d87b8225bd640fee4b55fd66e793391526f6d54)

7 years agoMerge "Change the default for rabbitmq back to ha-mode: all" into stable/ocata
Jenkins [Fri, 28 Apr 2017 09:59:04 +0000 (09:59 +0000)]
Merge "Change the default for rabbitmq back to ha-mode: all" into stable/ocata

7 years agoMerge "upgrades: deploy mod_ssl when upgrading apache" into stable/ocata
Jenkins [Fri, 28 Apr 2017 09:21:14 +0000 (09:21 +0000)]
Merge "upgrades: deploy mod_ssl when upgrading apache" into stable/ocata

7 years agoMerge "Prepare 6.1.0 (ocata)" into stable/ocata
Jenkins [Thu, 27 Apr 2017 20:20:53 +0000 (20:20 +0000)]
Merge "Prepare 6.1.0 (ocata)" into stable/ocata

7 years agoMerge "Cinder-api upgrade: use httpd instead of apachectl" into stable/ocata
Jenkins [Thu, 27 Apr 2017 20:20:11 +0000 (20:20 +0000)]
Merge "Cinder-api upgrade: use httpd instead of apachectl" into stable/ocata

7 years agoMerge "Align hyperconverged-ceph.yaml environment and adds some validation" into...
Jenkins [Thu, 27 Apr 2017 19:19:06 +0000 (19:19 +0000)]
Merge "Align hyperconverged-ceph.yaml environment and adds some validation" into stable/ocata

7 years agoPrepare 6.1.0 (ocata)
Emilien Macchi [Thu, 27 Apr 2017 16:17:46 +0000 (12:17 -0400)]
Prepare 6.1.0 (ocata)

Change-Id: Idb0423f9cf76234b9f44cacf32dd34cd9ae4e655

7 years agoupgrades: deploy mod_ssl when upgrading apache
Sofer Athlan-Guyot [Wed, 26 Apr 2017 21:10:24 +0000 (23:10 +0200)]
upgrades: deploy mod_ssl when upgrading apache

1) When Apache is upgraded, install mod_ssl rpm.
   See https://bugs.launchpad.net/tripleo/+bug/1682448
   to understand why we need mod_ssl.

2) All services that run Apache for API will use the snippet from
   Apache service to deploy mod_ssl, so we don't duplicate the code
   in all services. It's using the same mechanism as ovs upgrade to
   compile upgrade_tasks between both services.

Change-Id: Ia2f6fea45c2c09790c49baab19b1efcab25e9a84
Closes-Bug: #1686503
(cherry picked from commit a6041608ca68aad4298ed9e8febafc442a250a55)

7 years agoCinder-api upgrade: use httpd instead of apachectl
Sofer Athlan-Guyot [Wed, 26 Apr 2017 20:38:13 +0000 (22:38 +0200)]
Cinder-api upgrade: use httpd instead of apachectl

It doesn't work downstream, so the httpd command was recommended.

Change-Id: I4807333b80dad10f16e5deb56cbfdda656cd1e50
(cherry picked from commit 0b05d7fd9b0e8811755499642647919eaf64cc39)

7 years agoChange the default for rabbitmq back to ha-mode: all
Michele Baldessari [Wed, 26 Apr 2017 08:29:18 +0000 (10:29 +0200)]
Change the default for rabbitmq back to ha-mode: all

In change Ib62001c03e1e08f58cf0c6e0ba07a8879a584084 we switched the
rabbitmq queues HA mode from ha-all to ha-exactly. While this gives us a
nice performance boost with rabbitmq, it makes rabbit less resilient to
network glitches as we painfully found out via
https://bugzilla.redhat.com/show_bug.cgi?id=1441635.

This is the THT part of the change that changes the default to
ha-mode: all.

NB: not clean cherry-pick due to the added metadata_settings line in
master

Closes-Bug: #1686337
Co-Authored-By: Damien Ciabrini <dciabrin@redhat.com>
Co-Authored-By: John Eckersberg <jeckersb@redhat.com>
Change-Id: I7afcf2b3c8deb13fc2134e4cae9c06a44e775384
Depends-On: I9a90e71094b8d8d58b5be0a45a2979701b0ac21c
(cherry picked from commit 90fc4b2e27ef6f612a82dfc5e08884629d0fe0bf)

7 years agoIncrease documentation about parameters
Juan Badia Payno [Thu, 2 Mar 2017 18:47:23 +0000 (19:47 +0100)]
Increase documentation about parameters

CollectdServer, CollectdServerPort, CollectdSecurityLevel, CollectdUsername, CollectdPassword

Change-Id: I43a0aca6f620f2570bdfd88531e70611867337b0
(cherry picked from commit f209f0aa48d277ecb8300ef33225f6ce6e24a4ae)

7 years agoMerge "SSHD Service extensions" into stable/ocata
Jenkins [Tue, 25 Apr 2017 22:58:54 +0000 (22:58 +0000)]
Merge "SSHD Service extensions" into stable/ocata

7 years agoMerge "sensu: fix upgrade case when service is added" into stable/ocata
Jenkins [Tue, 25 Apr 2017 22:04:25 +0000 (22:04 +0000)]
Merge "sensu: fix upgrade case when service is added" into stable/ocata

7 years agoMerge "Deploy ceilometer_auth_enabled to node containing keystone" into stable/ocata
Jenkins [Tue, 25 Apr 2017 19:48:32 +0000 (19:48 +0000)]
Merge "Deploy ceilometer_auth_enabled to node containing keystone" into stable/ocata

7 years agoMerge "Remove no longer used environment files - older upgrade workflows" into stable...
Jenkins [Tue, 25 Apr 2017 19:10:04 +0000 (19:10 +0000)]
Merge "Remove no longer used environment files - older upgrade workflows" into stable/ocata

7 years agoMerge "Add migration SSH tunneling support" into stable/ocata
Jenkins [Tue, 25 Apr 2017 18:45:36 +0000 (18:45 +0000)]
Merge "Add migration SSH tunneling support" into stable/ocata

7 years agoMerge "SSH known_hosts config" into stable/ocata
Jenkins [Tue, 25 Apr 2017 16:48:39 +0000 (16:48 +0000)]
Merge "SSH known_hosts config" into stable/ocata

7 years agoDeploy ceilometer_auth_enabled to node containing keystone
Juan Antonio Osorio Robles [Mon, 24 Apr 2017 15:53:05 +0000 (18:53 +0300)]
Deploy ceilometer_auth_enabled to node containing keystone

This hiera key is used by keystone to create the ceilometer service
user. It works in CI cause keystone and the ceilometer services are in
the same node. However, this fails if keystone is deployed on a separate
note.

We should only deploy it in the nodes containing the keystone service
since it's only relevant to create the service user.

Change-Id: Ic0f02fe9a78a1fe14ac2b87197692fbd80c003b8
Closes-Bug: #1685828
(cherry picked from commit f1f6b5dc7d698a36f04186856fb94b4115d121dc)

7 years agoDisable Manila CephFS snapshots by default
Jan Provaznik [Tue, 21 Feb 2017 11:00:48 +0000 (12:00 +0100)]
Disable Manila CephFS snapshots by default

Because CephFS Snapshots are still an experimental feature and
also Manila Ceph driver has this feature disabled by default,
it makes sense to not override this value by default.

Change-Id: I3dacbd7a3c673d2f34998ee9f433889727c6a0f7
(cherry picked from commit 99371a90a29b4f9ffda606263540a1ef0b919633)

7 years agoRemove no longer used environment files - older upgrade workflows
marios [Fri, 21 Apr 2017 14:47:59 +0000 (17:47 +0300)]
Remove no longer used environment files - older upgrade workflows

In I7831d20eae6ab9668a919b451301fe669e2b1346 we removed some of
the old upgrades but left the environment files removed here.

Related-Bug: 1673447
Change-Id: Ib3eca5687285b280832d19b647c3b4aa3d9ac36d
(cherry picked from commit 61632a621b1ef0fc0e3d20080eb8a5ff05952bbe)

7 years agosensu: fix upgrade case when service is added
Emilien Macchi [Fri, 7 Apr 2017 15:54:48 +0000 (11:54 -0400)]
sensu: fix upgrade case when service is added

When service is added during an upgrade, fix the ansible syntax
to use the right variable for return code.

Change-Id: I974699fb8b0dcbe5ffa6935c394df4ac8e7b21d4
(cherry picked from commit deb9b4cad5a59e650922067841604a4bc121c228)

7 years agoMerge "Fix bogus parameters in get_param" into stable/ocata
Jenkins [Fri, 21 Apr 2017 15:14:49 +0000 (15:14 +0000)]
Merge "Fix bogus parameters in get_param" into stable/ocata

7 years agoSSHD Service extensions
Luke Hinds [Sun, 12 Mar 2017 03:24:35 +0000 (03:24 +0000)]
SSHD Service extensions

This change implements a MOTD message and provides a hash of
sshd config options which are sourced to the puppet-ssh module
as a hash.

The SSHD puppet service is enabled by default, as it is
required for Idb56acd1e1ecb5a5fd4d942969be428cc9cbe293.
Also added the service to the CI roles.

Change-Id: Ie2e01d93082509b8ede37297067eab03bb1ab06e
Depends-On: I1d09530d69e42c0c36311789166554a889e46556
Closes-Bug: #1668543
Co-Authored-By: Oliver Walsh <owalsh@redhat.com>
(cherry picked from commit 5e14f95a4a46fcf88293f1b0fa93327566614d43)

7 years agoMerge "N->O Manual puppet commands have the right modulepath." into stable/ocata
Jenkins [Fri, 21 Apr 2017 12:14:55 +0000 (12:14 +0000)]
Merge "N->O Manual puppet commands have the right modulepath." into stable/ocata

7 years agoMerge "Run token flush cron job hourly by default" into stable/ocata
Jenkins [Fri, 21 Apr 2017 09:06:02 +0000 (09:06 +0000)]
Merge "Run token flush cron job hourly by default" into stable/ocata

7 years agoMerge "Update Dell EMC Cinder back end services" into stable/ocata
Jenkins [Fri, 21 Apr 2017 07:14:02 +0000 (07:14 +0000)]
Merge "Update Dell EMC Cinder back end services" into stable/ocata

7 years agoMerge "Add composable role support for NetApp Cinder back end" into stable/ocata
Jenkins [Fri, 21 Apr 2017 06:41:16 +0000 (06:41 +0000)]
Merge "Add composable role support for NetApp Cinder back end" into stable/ocata

7 years agoMerge "Replace references to the 192.0.2 network" into stable/ocata
Jenkins [Fri, 21 Apr 2017 06:01:09 +0000 (06:01 +0000)]
Merge "Replace references to the 192.0.2 network" into stable/ocata

7 years agoMerge "N->O upgrade, fix wrong parameters to nova placement." into stable/ocata
Jenkins [Fri, 21 Apr 2017 03:39:48 +0000 (03:39 +0000)]
Merge "N->O upgrade, fix wrong parameters to nova placement." into stable/ocata

7 years agoAdd migration SSH tunneling support
Oliver Walsh [Tue, 28 Mar 2017 15:15:08 +0000 (16:15 +0100)]
Add migration SSH tunneling support

This enables nova cold migration.

This also switches to SSH as the default transport for live-migration.
The tripleo-common mistral action that generates passwords supplies the
MigrationSshKey parameter that enables this.
The TCP transport is no longer used for live-migration and the firewall
port has been closed.

Change-Id: I4e55a987c93673796525988a2e4cc264a6b5c24f
Depends-On: I367757cbe8757d11943af7e41af620f9ce919a06
Depends-On: I9e7a1862911312ad942233ac8fc828f4e1be1dcf
Depends-On: Iac1763761c652bed637cb7cf85bc12347b5fe7ec
(cherry picked from commit 0271a63e52b961eab0da2f5c6a61811a7a1498f7)

7 years agoSSH known_hosts config
Oliver Walsh [Fri, 24 Mar 2017 14:35:09 +0000 (14:35 +0000)]
SSH known_hosts config

Fetch the host public keys from each node, combine them all and write to the
system-wide ssh known hosts. The alternative of disabling host key
 verification is vulnerable to a MITM attack.

Change-Id: Ib572b5910720b1991812256e68c975f7fbe2239c
(cherry picked from commit 7d3552a105ad5aa62cad0998c11df5ec6bd06ed6)

7 years agoMerge "Use comma_delimited_list for token flush cron time settings" into stable/ocata
Jenkins [Thu, 20 Apr 2017 21:30:10 +0000 (21:30 +0000)]
Merge "Use comma_delimited_list for token flush cron time settings" into stable/ocata

7 years agoN->O Manual puppet commands have the right modulepath.
Sofer Athlan-Guyot [Thu, 20 Apr 2017 10:30:46 +0000 (12:30 +0200)]
N->O Manual puppet commands have the right modulepath.

In two places during upgrade we manually trigger puppet.

There can be a problem when new puppet modules are added, and their
corresponding symlinks in /etc/puppet/modules are not created during
the installation as their are installed in
/usr/share/openstack-puppet/modules.  To prevent the issue tripleo set
modulepath in the templates.

We must use the same modulepath to make sure that we don't fail
because of missing module in the manual puppet run.

This particulary happens when you upgrade from M->N->O, as the base
image in Mitaka doesn't have the proper symlinks and they are not
created during the installation of the package.

Closes-Bug: #1684587

Change-Id: I79df6ea33f1c58e13309176a6de41b7572541fd6
(cherry picked from commit 79c2d0f3d411da9e57731d9da79d25a3e0364eb2)

7 years agoMerge "Touch /etc/httpd/conf.d/ssl.conf" into stable/ocata
Jenkins [Thu, 20 Apr 2017 11:20:07 +0000 (11:20 +0000)]
Merge "Touch /etc/httpd/conf.d/ssl.conf" into stable/ocata

7 years agoN->O upgrade, fix wrong parameters to nova placement.
Sofer Athlan-Guyot [Wed, 19 Apr 2017 09:26:45 +0000 (11:26 +0200)]
N->O upgrade, fix wrong parameters to nova placement.

According to [1] we need os_region_name, not region_name.  Furthermore
the os_interface is configured as well.  The hard check on this
parameter was introduced in ocata[2], explaining why the newton version
did not chock on it.

[1] https://docs.openstack.org/ocata/config-reference/compute/config-options.html
[2] https://github.com/openstack/nova/commit/d486315e0

Closes-Bug: #1684058
Change-Id: If6118bf03e832fe3fa5ea4fcb1b436afd2adf80a
(cherry picked from commit 88a3168b3019f7c8232c14b95d4c7c6fb5080f03)

7 years agoMerge "Decouple Swift ringbuilding logic" into stable/ocata
Jenkins [Wed, 19 Apr 2017 15:12:34 +0000 (15:12 +0000)]
Merge "Decouple Swift ringbuilding logic" into stable/ocata

7 years agoMerge "Modify pci_passthrough hiera value as string" into stable/ocata
Jenkins [Wed, 19 Apr 2017 10:45:48 +0000 (10:45 +0000)]
Merge "Modify pci_passthrough hiera value as string" into stable/ocata

7 years agoRun token flush cron job hourly by default
Juan Antonio Osorio Robles [Wed, 12 Apr 2017 11:31:53 +0000 (14:31 +0300)]
Run token flush cron job hourly by default

Running this job once a day has proven problematic for large
deployments as seen in the bug report. Setting it to run hourly
would be an improvement to the current situation, as the flushes
wouldn't need to process as much data.

Note that this only affects people using UUID as the token provider.

Change-Id: I462e4da2bfdbcba0403ecde5d613386938e2283a
Related-Bug: #1649616
(cherry picked from commit 65e643aca2202f031db94f1ccd3d44e195e5e772)

7 years agoUse comma_delimited_list for token flush cron time settings
Juan Antonio Osorio Robles [Wed, 12 Apr 2017 11:30:27 +0000 (14:30 +0300)]
Use comma_delimited_list for token flush cron time settings

This allows us to better configure these parametes, e.g. we could set
the cron job to run more times per day, and not just one.

Change-Id: I0a151808804809c0742bcfa8ac876e22f5ce5570
Closes-Bug: #1682097
(cherry picked from commit df36f221dd402a5b93585a6851fb1eb43de91967)

7 years agoTouch /etc/httpd/conf.d/ssl.conf
Lukas Bezdicka [Thu, 13 Apr 2017 17:31:29 +0000 (19:31 +0200)]
Touch /etc/httpd/conf.d/ssl.conf

To ensure that yum update passes without issues we touch ssl.conf.
Proper fix is https://review.openstack.org/#/c/456712/

Depends-On: Ic5a0719f67d3795a9edca25284d1cf6f088073e8
Closes-Bug: #1682448
Resolves: rhbz#1441977
Change-Id: I73e5272c64df4aa5900f544a5d9f0670544ca679

7 years agoFix bogus parameters in get_param
Bogdan Dobrelya [Mon, 6 Mar 2017 16:49:01 +0000 (17:49 +0100)]
Fix bogus parameters in get_param

Change-Id: I1b5658efaaa26c473ceef184a962ec320f267ffe
Signed-off-by: Bogdan Dobrelya <bdobreli@redhat.com>
(cherry picked from commit e88dfbc4ca115be9522ee0fc0bdb5b60f9ddd7a7)

7 years agoMerge "Add params to tweak memory limit on mongodb" into stable/ocata
Jenkins [Mon, 17 Apr 2017 21:54:21 +0000 (21:54 +0000)]
Merge "Add params to tweak memory limit on mongodb" into stable/ocata