blob: e6b801658c0f7124c973fd8207e581978340a713 [file] [log] [blame]
Ivan Berezovskiy77187172018-09-14 15:47:36 +04001#cloud-config
Ivan Berezovskiy39fa6562018-10-09 12:58:55 +04002output:
3 all: '| tee -a /var/log/cloud-init-output.log /dev/tty0'
Ivan Berezovskiy77187172018-09-14 15:47:36 +04004write_files:
5 - owner: root:root
6 path: /etc/cloud/master_environment
7 permissions: '0644'
8 content: |
Dennis Dmitriev8fa33f92018-10-10 01:13:48 +03009 [ -f /etc/cloud/master_environment_override ] && . /etc/cloud/master_environment_override
10 export SALT_MASTER_DEPLOY_IP=${SALT_MASTER_DEPLOY_IP:-"172.16.164.15"}
11 export SALT_MASTER_MINION_ID=${SALT_MASTER_MINION_ID:-"cfg01.deploy-name.local"}
12 export DEPLOY_NETWORK_GW=${DEPLOY_NETWORK_GW:-"172.16.164.1"}
13 export DEPLOY_NETWORK_NETMASK=${DEPLOY_NETWORK_NETMASK:-"255.255.255.192"}
14 export DEPLOY_NETWORK_MTU=${DEPLOY_NETWORK_MTU:-"1500"}
15 export DNS_SERVERS=${DNS_SERVERS:-"8.8.8.8"}
azvyagintsev829bfd82018-12-19 12:58:17 +020016
Dennis Dmitriev8fa33f92018-10-10 01:13:48 +030017 export http_proxy=${http_proxy:-""}
18 export https_proxy=${https_proxy:-""}
azvyagintsev829bfd82018-12-19 12:58:17 +020019
20 export MCP_VERSION=${MCP_VERSION:-"stable"}
21
Dennis Dmitriev8fa33f92018-10-10 01:13:48 +030022 export PIPELINES_FROM_ISO=${PIPELINES_FROM_ISO:-"true"}
23 export PIPELINE_REPO_URL=${PIPELINE_REPO_URL:-"https://github.com/Mirantis"}
azvyagintsev829bfd82018-12-19 12:58:17 +020024
25 export MCP_SALT_REPO_URL=${MCP_SALT_REPO_URL:-"http://mirror.mirantis.com/"}
26 export MCP_SALT_REPO=${MCP_SALT_REPO:-"deb [arch=amd64] $MCP_SALT_REPO_URL/$MCP_VERSION/salt-formulas/xenial xenial main"}
azvyagintsev60906252019-05-16 12:30:25 +030027
28 export ENABLE_MCP_SALT_REPO_UPDATES=${ENABLE_MCP_SALT_REPO_UPDATES:-"true"}
azvyagintsev829bfd82018-12-19 12:58:17 +020029 export MCP_SALT_REPO_UPDATES=${MCP_SALT_REPO_UPDATES:-"deb [arch=amd64] $MCP_SALT_REPO_URL/update/$MCP_VERSION/salt-formulas/xenial xenial main"}
30 export MCP_SALT_REPO_KEY=${MCP_SALT_REPO_KEY:-"${MCP_SALT_REPO_URL}/${MCP_VERSION}/salt-formulas/xenial/archive-salt-formulas.key"}
31
Dennis Dmitriev8fa33f92018-10-10 01:13:48 +030032 export FORMULAS=${FORMULAS:-"salt-formula-*"}
azvyagintsev829bfd82018-12-19 12:58:17 +020033 export SALT_OPTS=${SALT_OPTS:-"-l debug -t 30 --retcode-passthrough --no-color"}
Dennis Dmitriev8fa33f92018-10-10 01:13:48 +030034 export CFG_BOOTSTRAP_DRIVE_URL=${CFG_BOOTSTRAP_DRIVE_URL:-""}
azvyagintsevbe5060d2019-06-11 16:15:58 +030035 export WGET_OPTS=${WGET_OPTS:-"--progress=dot:mega --waitretry=15 --retry-connrefused"}
azvyagintsev829bfd82018-12-19 12:58:17 +020036
Ivan Berezovskiy77187172018-09-14 15:47:36 +040037master_config:
38 - &master_config |
39 function _post_maas_cfg() {
40 source /var/lib/maas/.maas_login.sh
41 # disable backports for maas enlist pkg repo. Those operation enforce maas
42 # to re-create sources.list and drop [source] fetch-definition from it.
43 main_arch_id=$(maas ${PROFILE} package-repositories read | jq -r ".[] | select(.name==\"main_archive\") | .id")
44 maas ${PROFILE} package-repository update ${main_arch_id} "disabled_pockets=backports" || true
45 maas ${PROFILE} package-repository update ${main_arch_id} "disabled_components=multiverse" || true
46 maas ${PROFILE} package-repository update ${main_arch_id} "arches=amd64" || true
47 # Remove stale notifications, which appear during sources configuration.
48 for i in $(maas ${PROFILE} notifications read | jq ".[]| .id"); do
49 maas ${PROFILE} notification delete ${i} || true
50 done
51 }
52
53 function process_formulas(){
54 local RECLASS_ROOT=${RECLASS_ROOT:-/srv/salt/reclass/}
55 local FORMULAS_PATH=${FORMULAS_PATH:-/usr/share/salt-formulas}
azvyagintsevbe5060d2019-06-11 16:15:58 +030056 local _tname="/tmp/archive-salt-formulas_${RANDOM}.key"
Ivan Berezovskiy77187172018-09-14 15:47:36 +040057
azvyagintsevbe5060d2019-06-11 16:15:58 +030058 wget ${WGET_OPTS} -O ${_tname} ${MCP_SALT_REPO_KEY}
59 apt-key add ${_tname}
60
azvyagintsev829bfd82018-12-19 12:58:17 +020061 echo "${MCP_SALT_REPO}" > /etc/apt/sources.list.d/mcp_salt.list
azvyagintsev60906252019-05-16 12:30:25 +030062 if [[ "${ENABLE_MCP_SALT_REPO_UPDATES}" == "true" ]] ; then
63 echo "${MCP_SALT_REPO_UPDATES}" >> /etc/apt/sources.list.d/mcp_salt.list
64 fi
Ivan Berezovskiy77187172018-09-14 15:47:36 +040065 apt-get update
66 apt-get install -y salt-formula-*
67
68 [ ! -d ${RECLASS_ROOT}/classes/service ] && mkdir -p ${RECLASS_ROOT}/classes/service
69 for formula_service in $(ls /usr/share/salt-formulas/reclass/service/); do
70 #Since some salt formula names contain "-" and in symlinks they should contain "_" adding replacement
71 formula_service=${formula_service//-/$"_"}
72 if [ ! -L "${RECLASS_ROOT}/classes/service/${formula_service}" ]; then
73 ln -sf ${FORMULAS_PATH}/reclass/service/${formula_service} ${RECLASS_ROOT}/classes/service/${formula_service}
74 fi
75 done
76 }
77
78 function enable_services(){
Stanislav Riazanovc69bfc02018-12-07 16:52:14 +040079 local services="salt-api salt-master salt-minion"
80 if [ ! -f /opt/postgresql_in_docker ]; then
81 local services="${services} postgresql.service"
82 fi
83 for s in ${services} ; do
Ivan Berezovskiy77187172018-09-14 15:47:36 +040084 systemctl enable ${s} || true
85 systemctl restart ${s} || true
86 done
87 }
88
89 function process_network(){
90 echo "Configuring network interfaces"
91 find /etc/network/interfaces.d/ -type f -delete
92 kill $(pidof /sbin/dhclient) || /bin/true
93 envsubst < /root/interfaces > /etc/network/interfaces
94 ip a flush dev ens3
95 rm -f /var/run/network/ifstate.ens3
96 if [[ $(grep -E "^\ *gateway\ " /etc/network/interfaces) ]]; then
97 (ip r s | grep ^default) && ip r d default || /bin/true
98 fi;
99 ifup ens3
100 }
101
102 function process_maas(){
Stanislav Riazanov450ceaa2018-12-18 20:17:07 +0400103 maas_cluster_enabled=$(salt-call --out=text pillar.get maas:cluster:enabled | awk '{print $2}' | tr "[:upper:]" "[:lower:]" )
104 _region=$(salt-call --out=text pillar.get maas:region:enabled | awk '{print $2}' | tr "[:upper:]" "[:lower:]" )
105 if ([ -f /opt/postgresql_in_docker ] && ([[ "${maas_cluster_enabled}" == "true" ]] || [[ "${_region}" == "true" ]])); then
Stanislav Riazanovc69bfc02018-12-07 16:52:14 +0400106 systemctl disable postgresql.service
107 wait_for_postgresql
108 salt-call ${SALT_OPTS} state.sls postgresql.client
109 else
110 postgres_enabled=$(salt-call --out=text pillar.get postgresql:server:enabled | awk '{print $2}' | tr "[:upper:]" "[:lower:]")
111 if [[ "${postgres_enabled}" == "true" ]]; then
112 salt-call ${SALT_OPTS} state.sls postgresql.server
113 fi
Ivan Berezovskiy77187172018-09-14 15:47:36 +0400114 fi
115
Ivan Berezovskiy77187172018-09-14 15:47:36 +0400116 if [[ "${maas_cluster_enabled}" == "true" ]]; then
117 salt-call ${SALT_OPTS} state.sls maas.cluster
118 else
119 echo "WARNING: maas.cluster skipped!"
120 fi
121 if [[ "$_region" == "true" ]]; then
Stanislav Riazanov450ceaa2018-12-18 20:17:07 +0400122 salt-call ${SALT_OPTS} state.sls maas.region
Ivan Berezovskiy77187172018-09-14 15:47:36 +0400123 else
124 echo "WARNING: maas.region skipped!"
125 fi
126 # Do not move it under first cluster-only check!
127 if [[ "${maas_cluster_enabled}" == "true" ]]; then
128 _post_maas_cfg
129 fi
130 }
131
Stanislav Riazanovc69bfc02018-12-07 16:52:14 +0400132 function wait_for_postgresql() {
133 salt_string="salt-call --out=text pillar.get postgresql:client:server:server01:admin"
azvyagintsev2249f882019-05-21 20:06:34 +0300134 local pg_port=$(${salt_string}:port | awk '{print $2}')
135 local pg_host=$(${salt_string}:host | awk '{print $2}')
136 local wait_time=0
137 until [[ $(/usr/bin/pg_isready -h ${pg_host} -p ${pg_port} | awk '{ print $3 }' ) == 'accepting' ]]; do
138 if [[ $wait_time -gt 20 ]]; then
139 echo "ERROR: wait_for_postgresql failed" ; exit 1
140 fi
Stanislav Riazanovc69bfc02018-12-07 16:52:14 +0400141 echo "Waiting for postgres at: ${pg_host}:${pg_port}"
142 sleep $(( wait_time++ ));
143 done
144 }
145
Ivan Berezovskiy11d374b2018-11-26 18:00:23 +0400146 function wait_for_jenkins() {
147 # Wait for jenkins to be functional
148 jport=$(salt-call --out=text pillar.get jenkins:master:http:port | awk '{print $2}')
149 jport=${jport:-8081}
150 wait_time=0
azvyagintsev2249f882019-05-21 20:06:34 +0300151 until [[ $(curl -sL -w "%{http_code}" localhost:$jport -o /dev/null) == 200 ]] ; do
152 if [[ $wait_time -gt 20 ]]; then
153 echo "ERROR: wait_for_jenkins failed" ; exit 1
154 fi
Ivan Berezovskiy11d374b2018-11-26 18:00:23 +0400155 sleep $(( wait_time++ ))
156 done
157 }
158
Stanislav Riazanovc69bfc02018-12-07 16:52:14 +0400159 function process_swarm() {
azvyagintsev2249f882019-05-21 20:06:34 +0300160 local _swarm=$(salt-call --out=text pillar.get docker:swarm:advertise_addr | awk '{print $2}')
Stanislav Riazanovc69bfc02018-12-07 16:52:14 +0400161 if [[ "${_swarm}" != "" ]]; then
162 salt-call ${SALT_OPTS} state.sls docker.swarm
163 fi
164 _docker=$(salt-call --out=text pillar.get docker:client:enabled | awk '{print $2}')
165 if [[ "${_docker}" != "" ]]; then
166 salt-call ${SALT_OPTS} state.sls docker.client
167 fi
azvyagintsevc2d715c2019-01-03 13:29:36 +0200168 salt-call ${SALT_OPTS} state.sls docker.client.images
Ivan Berezovskiy5f7a80f2018-12-17 18:08:31 +0400169 }
170
Ivan Berezovskiyfba80942018-11-16 13:11:44 +0400171 function process_jenkins() {
172 # INFO: jenkins is in docker in 2019.x releases
Ivan Berezovskiy040c3c62018-11-30 16:48:49 +0400173 if [ -f /opt/jenkins_in_docker ]; then
174 rm -v /opt/jenkins_in_docker
Ivan Berezovskiyfba80942018-11-16 13:11:44 +0400175 export JENKINS_HOME=/srv/volumes/jenkins
Ivan Berezovskiyfba80942018-11-16 13:11:44 +0400176 _nginx=$(salt-call --out=text pillar.get nginx:server:enabled | awk '{print $2}')
177 if [[ "${_nginx}" != "" ]]; then
178 salt-call ${SALT_OPTS} state.sls nginx
179 fi
Ivan Berezovskiy11d374b2018-11-26 18:00:23 +0400180 _jenabled=$(salt-call --out=text pillar.get docker:client:stack:jenkins | awk '{print $2}')
181 _jclient=$(salt-call --out=text pillar.get jenkins:client | awk '{print $2}')
182 if [[ "${_jenabled}" != "" && "${_jclient}" != "" ]]; then
183 wait_for_jenkins
Ivan Berezovskiyfba80942018-11-16 13:11:44 +0400184 salt-call ${SALT_OPTS} state.sls jenkins.client
185 fi
186 else
187 export JENKINS_HOME=/var/lib/jenkins
188 systemctl enable jenkins
189 systemctl start jenkins
Ivan Berezovskiy11d374b2018-11-26 18:00:23 +0400190 wait_for_jenkins
Ivan Berezovskiyfba80942018-11-16 13:11:44 +0400191 _jjobs=$(salt-call --out=text pillar.get jenkins:client:job | awk '{print $2}')
192 if [[ "${_jjobs}" != "" ]]; then
193 salt-call ${SALT_OPTS} state.sls jenkins.client
194 fi
195 systemctl stop jenkins
196 find ${JENKINS_HOME}/jenkins.model.JenkinsLocationConfiguration.xml -type f -print0 | xargs -0 sed -i -e "s/10.167.4.15/$SALT_MASTER_DEPLOY_IP/g"
Ivan Berezovskiy77187172018-09-14 15:47:36 +0400197 fi
Ivan Berezovskiyfba80942018-11-16 13:11:44 +0400198
Ivan Berezovskiy73cad8e2018-11-23 18:53:13 +0400199 ssh-keyscan cfg01 > ${JENKINS_HOME}/.ssh/known_hosts && chmod a+r ${JENKINS_HOME}/.ssh/known_hosts || true
Ivan Berezovskiy77187172018-09-14 15:47:36 +0400200 }
201
azvyagintsev2249f882019-05-21 20:06:34 +0300202 function failsafe_ssh_key(){
Ivan Berezovskiy77187172018-09-14 15:47:36 +0400203 if [ -f /mnt/root_auth_keys ]; then
azvyagintsev2249f882019-05-21 20:06:34 +0300204 echo 'Installing failsafe public ssh key from /mnt/root_auth_keys to /root/.ssh/authorized_keys'
Ivan Berezovskiy77187172018-09-14 15:47:36 +0400205 install -m 0700 -d /root/.ssh
206 cat /mnt/root_auth_keys >> /root/.ssh/authorized_keys
207 chmod 600 /root/.ssh/authorized_keys
208 sed -i "s/^PermitRootLogin.*/PermitRootLogin yes/g" /etc/ssh/sshd_config
209 sed -i "s/^PasswordAuthentication.*/PasswordAuthentication yes/g" /etc/ssh/sshd_config
210 service ssh restart
211 fi
212 }
213
azvyagintsev2249f882019-05-21 20:06:34 +0300214 function wait_for_salt(){
215 local wait_time=0
216 until $(salt-call --timeout=30 test.ping &> /dev/null ); do
217 if [[ $wait_time -gt 15 ]]; then
218 echo "ERROR: wait_for_salt failed" ; exit 1
219 fi
220 sleep $(( wait_time++ ))
221 done
222 }
223
azvyagintsev9a0d7e52018-10-17 20:15:22 +0300224 function process_salt_base(){
225 # PROD-21179| PROD-21792 : To describe such trick's around salt.XX state ordering
226 salt-call ${SALT_OPTS} state.sls salt.master
227 # Wait for salt-master to wake up after restart
228 sleep 5
azvyagintsev2249f882019-05-21 20:06:34 +0300229 wait_for_salt
azvyagintsev9a0d7e52018-10-17 20:15:22 +0300230 # Run salt.minion.ca to prepare CA certificate before salt.minion.cert is used
231 salt-call ${SALT_OPTS} state.sls salt.minion.ca
Ann Taraday5a63afc2018-12-20 23:00:11 +0400232 # Add sleep for completion of postponed restart of salt-minion. PROD-25986
233 sleep 15
azvyagintsev9a0d7e52018-10-17 20:15:22 +0300234 salt-call ${SALT_OPTS} state.sls salt.minion
235 # Wait for salt-minion to wake up after restart
azvyagintsev2249f882019-05-21 20:06:34 +0300236 wait_for_salt
237 salt-call ${SALT_OPTS} state.apply salt
238 salt-call ${SALT_OPTS} state.apply reclass
azvyagintsev9a0d7e52018-10-17 20:15:22 +0300239 }
240 #== Body ==================================================================#
241
Ivan Berezovskiy77187172018-09-14 15:47:36 +0400242 . /etc/cloud/master_environment
243 printenv | sort -u
azvyagintsev2249f882019-05-21 20:06:34 +0300244 # WA for https://gerrit.mcp.mirantis.com/#/c/34514/
245 echo "INFO: stopping orphaned maas"
246 systemctl stop maas-rackd.service maas-dhcpd.service maas-dhcpd6.service || true
247 systemctl disable maas-rackd.service maas-dhcpd.service maas-dhcpd6.service || true
248
Ivan Berezovskiy77187172018-09-14 15:47:36 +0400249 process_network
250
251 echo "Preparing metadata model"
252 if [[ -n "${CFG_BOOTSTRAP_DRIVE_URL}" ]]; then
azvyagintsev829bfd82018-12-19 12:58:17 +0200253 echo "CFG_BOOTSTRAP_DRIVE_URL detected,downloading..."
254 _tname="cfg01_${RANDOM}.iso"
azvyagintsevbe5060d2019-06-11 16:15:58 +0300255 wget ${WGET_OPTS} -O /${_tname} "${CFG_BOOTSTRAP_DRIVE_URL}"
256 mount -o loop /${_tname} /mnt
Ivan Berezovskiy77187172018-09-14 15:47:36 +0400257 else
258 mount /dev/cdrom /mnt/
259 fi
260 cp -rT /mnt/model/model /srv/salt/reclass
261 chown -R root:root /srv/salt/reclass/* || true
262 chown -R root:root /srv/salt/reclass/.git* || true
263 chmod -R 644 /srv/salt/reclass/classes/cluster/* || true
264 chmod -R 644 /srv/salt/reclass/classes/system/* || true
265
266 failsafe_ssh_key
267
268 echo "Configuring salt"
269 envsubst < /root/minion.conf > /etc/salt/minion.d/minion.conf
Dmitry Pyzhov15c0ac42018-12-11 17:10:08 +0300270 if [ -f /mnt/gpg/salt_master_pillar.asc ]; then
azvyagintsev2249f882019-05-21 20:06:34 +0300271 mkdir -p /etc/salt/gpgkeys
272 chmod 0700 /etc/salt/gpgkeys
Dmitry Pyzhov15c0ac42018-12-11 17:10:08 +0300273 GNUPGHOME=/etc/salt/gpgkeys gpg --import /mnt/gpg/salt_master_pillar.asc
274 fi
Ivan Berezovskiy77187172018-09-14 15:47:36 +0400275 enable_services
276
277 # Wait for salt-master and salt-minion to wake up after restart
azvyagintsev2249f882019-05-21 20:06:34 +0300278 wait_for_salt
Ivan Berezovskiy77187172018-09-14 15:47:36 +0400279
280 while true; do
281 salt-key | grep "$SALT_MASTER_MINION_ID" && break
282 sleep 5
283 done
284
Ivan Berezovskiy77187172018-09-14 15:47:36 +0400285 echo "updating local git repos"
286 if [[ "$PIPELINES_FROM_ISO" == "true" ]] ; then
287 cp -r /mnt/mk-pipelines/* /home/repo/mk/mk-pipelines/
288 cp -r /mnt/pipeline-library/* /home/repo/mcp-ci/pipeline-library/
289 umount /mnt || true
290 chown -R git:www-data /home/repo/mk/mk-pipelines/*
291 chown -R git:www-data /home/repo/mcp-ci/pipeline-library/*
292 else
293 umount /mnt || true
294 git clone --mirror "${PIPELINE_REPO_URL}/mk-pipelines.git" /home/repo/mk/mk-pipelines/
295 git clone --mirror "${PIPELINE_REPO_URL}/pipeline-library.git" /home/repo/mcp-ci/pipeline-library/
296 chown -R git:www-data /home/repo/mk/mk-pipelines/*
297 chown -R git:www-data /home/repo/mcp-ci/pipeline-library/*
298 fi
299
300 process_formulas
301
302 salt-call saltutil.refresh_pillar
303 salt-call saltutil.sync_all
304 if ! $(reclass -n ${SALT_MASTER_MINION_ID} > /dev/null ) ; then
305 echo "ERROR: Reclass render failed!"
306 exit 1
307 fi
308
309 salt-call ${SALT_OPTS} state.sls linux.network,linux,openssh
azvyagintsev9a0d7e52018-10-17 20:15:22 +0300310 process_salt_base
Stanislav Riazanov450ceaa2018-12-18 20:17:07 +0400311
Martin Polreicha7ae5c92019-05-29 15:02:32 +0200312 _nginx_enabled=$(salt-call --out=newline_values_only pillar.get nginx:server:enabled | tr "[:upper:]" "[:lower:]")
313 if [[ "${_nginx_enabled}" == "true" ]]; then
314 salt-call ${SALT_OPTS} state.apply nginx.server
315 fi
Stanislav Riazanovc69bfc02018-12-07 16:52:14 +0400316
317 if [ -f /opt/jenkins_in_docker ] || [ -f /opt/postgresql_in_docker ]; then
318 process_swarm
319 fi
320 if [ -f /opt/jenkins_in_docker ] && [ ! -f /opt/postgresql_in_docker ]; then
321 docker stack rm postgresql || true
322 fi
Ivan Berezovskiy77187172018-09-14 15:47:36 +0400323
Ivan Berezovskiy77187172018-09-14 15:47:36 +0400324 process_jenkins
Stanislav Riazanovc69bfc02018-12-07 16:52:14 +0400325 process_maas
Ivan Berezovskiy77187172018-09-14 15:47:36 +0400326
Ivan Berezovskiyfba80942018-11-16 13:11:44 +0400327 stop_services="salt-api salt-master salt-minion maas-rackd.service maas-regiond.service postgresql.service"
Ivan Berezovskiy77187172018-09-14 15:47:36 +0400328 for s in ${stop_services} ; do
329 systemctl stop ${s} || true
330 sleep 1
331 done
azvyagintsevc1c62042018-09-26 11:47:49 +0300332 # Set bootstrap-done flag for future
333 mkdir -p /var/log/mcp/
334 touch /var/log/mcp/.bootstrap_done
Ivan Berezovskiy77187172018-09-14 15:47:36 +0400335 sync
336 reboot
337runcmd:
azvyagintsevc1c62042018-09-26 11:47:49 +0300338 - [bash, -cex, *master_config]