| Filip Pytloun | 0a07f70 | 2017-02-24 18:26:18 +0100 | [diff] [blame] | 1 | /** | 
 | 2 |  * | 
 | 3 |  * Launch heat stack with CI/CD lab infrastructure | 
 | 4 |  * | 
 | 5 |  * Expected parameters: | 
 | 6 |  *   HEAT_TEMPLATE_URL          URL to git repo with Heat templates | 
 | 7 |  *   HEAT_TEMPLATE_CREDENTIALS  Credentials to the Heat templates repo | 
 | 8 |  *   HEAT_TEMPLATE_BRANCH       Heat templates repo branch | 
 | 9 |  *   HEAT_STACK_NAME            Heat stack name | 
 | 10 |  *   HEAT_STACK_TEMPLATE        Heat stack HOT template | 
 | 11 |  *   HEAT_STACK_ENVIRONMENT     Heat stack environmental parameters | 
 | 12 |  *   HEAT_STACK_ZONE            Heat stack availability zone | 
 | 13 |  *   HEAT_STACK_PUBLIC_NET      Heat stack floating IP pool | 
 | 14 |  *   HEAT_STACK_DELETE          Delete Heat stack when finished (bool) | 
 | 15 |  *   HEAT_STACK_CLEANUP_JOB     Name of job for deleting Heat stack | 
 | 16 |  *   HEAT_STACK_REUSE           Reuse Heat stack (don't create one) | 
 | 17 |  * | 
 | 18 |  *   SALT_MASTER_CREDENTIALS    Credentials to the Salt API | 
| Filip Pytloun | e32fda8 | 2017-02-24 18:26:18 +0100 | [diff] [blame] | 19 |  *   SALT_MASTER_PORT           Port of salt-api, defaults to 8000 | 
| Filip Pytloun | 0a07f70 | 2017-02-24 18:26:18 +0100 | [diff] [blame] | 20 |  * | 
 | 21 |  *   OPENSTACK_API_URL          OpenStack API address | 
 | 22 |  *   OPENSTACK_API_CREDENTIALS  Credentials to the OpenStack API | 
 | 23 |  *   OPENSTACK_API_PROJECT      OpenStack project to connect to | 
 | 24 |  *   OPENSTACK_API_CLIENT       Versions of OpenStack python clients | 
 | 25 |  *   OPENSTACK_API_VERSION      Version of the OpenStack API (2/3) | 
 | 26 |  * | 
 | 27 |  */ | 
 | 28 |  | 
| Filip Pytloun | ad2b36b | 2017-03-04 20:33:41 +0100 | [diff] [blame] | 29 | common = new com.mirantis.mk.Common() | 
| Filip Pytloun | 0a07f70 | 2017-02-24 18:26:18 +0100 | [diff] [blame] | 30 | git = new com.mirantis.mk.Git() | 
 | 31 | openstack = new com.mirantis.mk.Openstack() | 
 | 32 | salt = new com.mirantis.mk.Salt() | 
 | 33 | orchestrate = new com.mirantis.mk.Orchestrate() | 
| Jakub Josef | 458913d | 2017-05-10 15:37:56 +0200 | [diff] [blame] | 34 | _MAX_PERMITTED_STACKS = 2 | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 35 | timestamps { | 
 | 36 |     node { | 
 | 37 |         try { | 
 | 38 |             // connection objects | 
 | 39 |             def openstackCloud | 
 | 40 |             def saltMaster | 
| Filip Pytloun | 0a07f70 | 2017-02-24 18:26:18 +0100 | [diff] [blame] | 41 |  | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 42 |             // value defaults | 
 | 43 |             def openstackVersion = OPENSTACK_API_CLIENT ? OPENSTACK_API_CLIENT : 'liberty' | 
 | 44 |             def openstackEnv = "${env.WORKSPACE}/venv" | 
| Filip Pytloun | 0a07f70 | 2017-02-24 18:26:18 +0100 | [diff] [blame] | 45 |  | 
| Filip Pytloun | 3eefd3d | 2017-03-03 14:13:41 +0100 | [diff] [blame] | 46 |             try { | 
 | 47 |                 sshPubKey = SSH_PUBLIC_KEY | 
 | 48 |             } catch (MissingPropertyException e) { | 
 | 49 |                 sshPubKey = false | 
 | 50 |             } | 
 | 51 |  | 
| Filip Pytloun | 794ad95 | 2017-03-03 10:39:26 +0100 | [diff] [blame] | 52 |             if (HEAT_STACK_REUSE.toBoolean() == true && HEAT_STACK_NAME == '') { | 
 | 53 |                 error("If you want to reuse existing stack you need to provide it's name") | 
 | 54 |             } | 
 | 55 |  | 
 | 56 |             if (HEAT_STACK_REUSE.toBoolean() == false) { | 
 | 57 |                 // Don't allow to set custom heat stack name | 
 | 58 |                 wrap([$class: 'BuildUser']) { | 
| Tomáš Kukrál | 24d7fe6 | 2017-03-03 10:57:11 +0100 | [diff] [blame] | 59 |                     if (env.BUILD_USER_ID) { | 
 | 60 |                         HEAT_STACK_NAME = "${env.BUILD_USER_ID}-${JOB_NAME}-${BUILD_NUMBER}" | 
 | 61 |                     } else { | 
 | 62 |                         HEAT_STACK_NAME = "jenkins-${JOB_NAME}-${BUILD_NUMBER}" | 
 | 63 |                     } | 
| Filip Pytloun | 794ad95 | 2017-03-03 10:39:26 +0100 | [diff] [blame] | 64 |                     currentBuild.description = HEAT_STACK_NAME | 
 | 65 |                 } | 
| Filip Pytloun | fd6726a | 2017-02-28 19:31:16 +0100 | [diff] [blame] | 66 |             } | 
| Filip Pytloun | 5b0954b | 2017-03-01 10:10:18 +0100 | [diff] [blame] | 67 |  | 
| Filip Pytloun | 3d045f8 | 2017-03-01 09:44:52 +0100 | [diff] [blame] | 68 |             // | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 69 |             // Bootstrap | 
| Filip Pytloun | 3d045f8 | 2017-03-01 09:44:52 +0100 | [diff] [blame] | 70 |             // | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 71 |  | 
 | 72 |             stage ('Download Heat templates') { | 
 | 73 |                 git.checkoutGitRepository('template', HEAT_TEMPLATE_URL, HEAT_TEMPLATE_BRANCH, HEAT_TEMPLATE_CREDENTIALS) | 
| Filip Pytloun | 3d045f8 | 2017-03-01 09:44:52 +0100 | [diff] [blame] | 74 |             } | 
| Filip Pytloun | 3d045f8 | 2017-03-01 09:44:52 +0100 | [diff] [blame] | 75 |  | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 76 |             stage('Install OpenStack CLI') { | 
 | 77 |                 openstack.setupOpenstackVirtualenv(openstackEnv, openstackVersion) | 
 | 78 |             } | 
| Filip Pytloun | 64123cd | 2017-03-01 11:26:17 +0100 | [diff] [blame] | 79 |  | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 80 |             stage('Connect to OpenStack cloud') { | 
| Vladislav Naumov | 822b739 | 2017-07-25 17:57:21 +0300 | [diff] [blame] | 81 |                 openstackCloud = openstack.createOpenstackEnv( | 
 | 82 |                     OPENSTACK_API_URL, OPENSTACK_API_CREDENTIALS, | 
 | 83 |                     OPENSTACK_API_PROJECT, OPENSTACK_API_PROJECT_DOMAIN, | 
 | 84 |                     OPENSTACK_API_PROJECT_ID, OPENSTACK_API_USER_DOMAIN, | 
 | 85 |                     OPENSTACK_API_VERSION) | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 86 |                 openstack.getKeystoneToken(openstackCloud, openstackEnv) | 
| Jakub Josef | 458913d | 2017-05-10 15:37:56 +0200 | [diff] [blame] | 87 |                 wrap([$class: 'BuildUser']) { | 
| Tomáš Kukrál | ab2f370 | 2017-05-11 09:17:43 +0200 | [diff] [blame] | 88 |                     if (env.BUILD_USER_ID && !env.BUILD_USER_ID.equals("jenkins") && !HEAT_STACK_REUSE.toBoolean()) { | 
| Jakub Josef | 78c3f8b | 2017-05-10 15:45:29 +0200 | [diff] [blame] | 89 |                         def existingStacks = openstack.getStacksForNameContains(openstackCloud, "${env.BUILD_USER_ID}-${JOB_NAME}", openstackEnv) | 
 | 90 |                         if(existingStacks.size() >= _MAX_PERMITTED_STACKS){ | 
| Jakub Josef | 124403a | 2017-05-10 15:58:06 +0200 | [diff] [blame] | 91 |                             HEAT_STACK_DELETE = "false" | 
| Jakub Josef | 78c3f8b | 2017-05-10 15:45:29 +0200 | [diff] [blame] | 92 |                             throw new Exception("You cannot create new stack, you already have ${_MAX_PERMITTED_STACKS} stacks of this type (${JOB_NAME}). \nStack names: ${existingStacks}") | 
 | 93 |                         } | 
| Jakub Josef | 458913d | 2017-05-10 15:37:56 +0200 | [diff] [blame] | 94 |                     } | 
 | 95 |                 } | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 96 |             } | 
 | 97 |  | 
| Filip Pytloun | 794ad95 | 2017-03-03 10:39:26 +0100 | [diff] [blame] | 98 |             if (HEAT_STACK_REUSE.toBoolean() == false) { | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 99 |                 stage('Launch new Heat stack') { | 
 | 100 |                     envParams = [ | 
 | 101 |                         'instance_zone': HEAT_STACK_ZONE, | 
 | 102 |                         'public_net': HEAT_STACK_PUBLIC_NET | 
 | 103 |                     ] | 
 | 104 |                     openstack.createHeatStack(openstackCloud, HEAT_STACK_NAME, HEAT_STACK_TEMPLATE, envParams, HEAT_STACK_ENVIRONMENT, openstackEnv) | 
 | 105 |                 } | 
 | 106 |             } | 
 | 107 |  | 
 | 108 |             stage('Connect to Salt master') { | 
 | 109 |                 def saltMasterPort | 
 | 110 |                 try { | 
 | 111 |                     saltMasterPort = SALT_MASTER_PORT | 
 | 112 |                 } catch (MissingPropertyException e) { | 
| Filip Pytloun | 2ef2613 | 2017-03-10 09:44:37 +0100 | [diff] [blame] | 113 |                     saltMasterPort = 6969 | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 114 |                 } | 
 | 115 |                 saltMasterHost = openstack.getHeatStackOutputParam(openstackCloud, HEAT_STACK_NAME, 'salt_master_ip', openstackEnv) | 
| Jakub Josef | bde0d44 | 2017-04-07 16:32:58 +0200 | [diff] [blame] | 116 |                 currentBuild.description = "${HEAT_STACK_NAME}: ${saltMasterHost}" | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 117 |                 saltMasterUrl = "http://${saltMasterHost}:${saltMasterPort}" | 
 | 118 |                 saltMaster = salt.connection(saltMasterUrl, SALT_MASTER_CREDENTIALS) | 
 | 119 |             } | 
 | 120 |  | 
 | 121 |             // | 
 | 122 |             // Install | 
 | 123 |             // | 
 | 124 |  | 
 | 125 |             stage('Install core infra') { | 
 | 126 |                 // salt.master, reclass | 
 | 127 |                 // refresh_pillar | 
 | 128 |                 // sync_all | 
 | 129 |                 // linux,openssh,salt.minion.ntp | 
 | 130 |  | 
 | 131 |                 orchestrate.installFoundationInfra(saltMaster) | 
 | 132 |                 orchestrate.validateFoundationInfra(saltMaster) | 
 | 133 |             } | 
 | 134 |  | 
 | 135 |             stage("Deploy GlusterFS") { | 
 | 136 |                 salt.enforceState(saltMaster, 'I@glusterfs:server', 'glusterfs.server.service', true) | 
| Filip Pytloun | 97e6fff | 2017-03-30 16:56:11 +0200 | [diff] [blame] | 137 |                 retry(2) { | 
 | 138 |                     salt.enforceState(saltMaster, 'ci01*', 'glusterfs.server.setup', true) | 
 | 139 |                 } | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 140 |                 sleep(5) | 
 | 141 |                 salt.enforceState(saltMaster, 'I@glusterfs:client', 'glusterfs.client', true) | 
| Filip Pytloun | 5555b45 | 2017-04-19 12:41:44 +0200 | [diff] [blame] | 142 |  | 
 | 143 |                 timeout(5) { | 
 | 144 |                     println "Waiting for GlusterFS volumes to get mounted.." | 
 | 145 |                     salt.cmdRun(saltMaster, 'I@glusterfs:client', 'while true; do systemctl -a|grep "GlusterFS File System"|grep -v mounted >/dev/null || break; done') | 
 | 146 |                 } | 
| Jakub Josef | fafd659 | 2017-03-27 18:53:17 +0200 | [diff] [blame] | 147 |                 print common.prettyPrint(salt.cmdRun(saltMaster, 'I@glusterfs:client', 'mount|grep fuse.glusterfs || echo "Command failed"')) | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 148 |             } | 
 | 149 |  | 
 | 150 |             stage("Deploy GlusterFS") { | 
 | 151 |                 salt.enforceState(saltMaster, 'I@haproxy:proxy', 'haproxy,keepalived') | 
 | 152 |             } | 
 | 153 |  | 
 | 154 |             stage("Setup Docker Swarm") { | 
 | 155 |                 salt.enforceState(saltMaster, 'I@docker:host', 'docker.host', true) | 
 | 156 |                 salt.enforceState(saltMaster, 'I@docker:swarm:role:master', 'docker.swarm', true) | 
 | 157 |                 salt.enforceState(saltMaster, 'I@docker:swarm:role:master', 'salt', true) | 
 | 158 |                 salt.runSaltProcessStep(saltMaster, 'I@docker:swarm:role:master', 'mine.flush') | 
 | 159 |                 salt.runSaltProcessStep(saltMaster, 'I@docker:swarm:role:master', 'mine.update') | 
 | 160 |                 salt.enforceState(saltMaster, 'I@docker:swarm', 'docker.swarm', true) | 
| Jakub Josef | fafd659 | 2017-03-27 18:53:17 +0200 | [diff] [blame] | 161 |                 print common.prettyPrint(salt.cmdRun(saltMaster, 'I@docker:swarm:role:master', 'docker node ls')) | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 162 |             } | 
 | 163 |  | 
| Ilya Kharin | 04c0998 | 2017-03-30 14:46:20 +0400 | [diff] [blame] | 164 |             stage("Configure OSS services") { | 
 | 165 |                 salt.enforceState(saltMaster, 'I@devops_portal:config', 'devops_portal.config') | 
| Ilya Kharin | 7a18c32 | 2017-04-24 18:49:34 +0400 | [diff] [blame] | 166 |                 salt.enforceState(saltMaster, 'I@rundeck:server', 'rundeck.server') | 
| Ilya Kharin | 04c0998 | 2017-03-30 14:46:20 +0400 | [diff] [blame] | 167 |             } | 
 | 168 |  | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 169 |             stage("Deploy Docker services") { | 
| Filip Pytloun | 82d628a | 2017-06-05 13:14:32 +0200 | [diff] [blame] | 170 |                 // We need /etc/aptly-publisher.yaml to be present before | 
 | 171 |                 // services are deployed | 
| Filip Pytloun | df7823c | 2017-06-14 15:22:40 +0200 | [diff] [blame] | 172 |                 // XXX: for some weird unknown reason, refresh_pillar is | 
 | 173 |                 // required to execute here | 
| Filip Pytloun | aebfa9c | 2017-06-14 16:12:57 +0200 | [diff] [blame] | 174 |                 salt.runSaltProcessStep(saltMaster, 'I@aptly:publisher', 'saltutil.refresh_pillar', [], null, true) | 
| Filip Pytloun | 82d628a | 2017-06-05 13:14:32 +0200 | [diff] [blame] | 175 |                 salt.enforceState(saltMaster, 'I@aptly:publisher', 'aptly.publisher', true) | 
| Filip Pytloun | 65b928d | 2017-04-18 17:19:30 +0200 | [diff] [blame] | 176 |                 retry(3) { | 
| Filip Pytloun | d6d1850 | 2017-04-13 15:35:07 +0200 | [diff] [blame] | 177 |                     sleep(5) | 
 | 178 |                     salt.enforceState(saltMaster, 'I@docker:swarm:role:master', 'docker.client') | 
 | 179 |                 } | 
| Ilya Kharin | 10e0ae3 | 2017-07-07 01:27:59 +0400 | [diff] [blame] | 180 |                 // XXX: Workaround to have `/var/lib/jenkins` on all | 
 | 181 |                 // nodes where are jenkins_slave services are created. | 
 | 182 |                 salt.runSaltProcessStep(saltMaster, 'I@docker:swarm', 'cmd.run', ['mkdir -p /var/lib/jenkins']) | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 183 |             } | 
 | 184 |  | 
 | 185 |             stage("Configure CI/CD services") { | 
| Filip Pytloun | 29d0bc1 | 2017-03-10 14:39:26 +0100 | [diff] [blame] | 186 |                 salt.syncAll(saltMaster, '*') | 
 | 187 |  | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 188 |                 // Aptly | 
| Filip Pytloun | 6cde788 | 2017-03-28 17:22:18 +0200 | [diff] [blame] | 189 |                 timeout(10) { | 
 | 190 |                     println "Waiting for Aptly to come up.." | 
| Filip Pytloun | b1ddf32 | 2017-05-12 16:18:31 +0200 | [diff] [blame] | 191 |                     retry(2) { | 
 | 192 |                         // XXX: retry to workaround magical VALUE_TRIMMED | 
 | 193 |                         // response from salt master + to give slow cloud some | 
 | 194 |                         // more time to settle down | 
 | 195 |                         salt.cmdRun(saltMaster, 'I@aptly:server', 'while true; do curl -sf http://172.16.10.254:8084/api/version >/dev/null && break; done') | 
 | 196 |                     } | 
| Filip Pytloun | 6cde788 | 2017-03-28 17:22:18 +0200 | [diff] [blame] | 197 |                 } | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 198 |                 salt.enforceState(saltMaster, 'I@aptly:server', 'aptly', true) | 
 | 199 |  | 
| Filip Pytloun | 0398381 | 2017-03-28 13:07:34 +0200 | [diff] [blame] | 200 |                 // OpenLDAP | 
 | 201 |                 timeout(10) { | 
 | 202 |                     println "Waiting for OpenLDAP to come up.." | 
| Filip Pytloun | b1ddf32 | 2017-05-12 16:18:31 +0200 | [diff] [blame] | 203 |                     salt.cmdRun(saltMaster, 'I@openldap:client', 'while true; do curl -sf ldap://172.16.10.254 >/dev/null && break; done') | 
| Filip Pytloun | 0398381 | 2017-03-28 13:07:34 +0200 | [diff] [blame] | 204 |                 } | 
 | 205 |                 salt.enforceState(saltMaster, 'I@openldap:client', 'openldap', true) | 
 | 206 |  | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 207 |                 // Gerrit | 
 | 208 |                 timeout(10) { | 
 | 209 |                     println "Waiting for Gerrit to come up.." | 
| Filip Pytloun | b1ddf32 | 2017-05-12 16:18:31 +0200 | [diff] [blame] | 210 |                     salt.cmdRun(saltMaster, 'I@gerrit:client', 'while true; do curl -sf 172.16.10.254:8080 >/dev/null && break; done') | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 211 |                 } | 
| Filip Pytloun | b1ddf32 | 2017-05-12 16:18:31 +0200 | [diff] [blame] | 212 |                 salt.enforceState(saltMaster, 'I@gerrit:client', 'gerrit', true) | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 213 |  | 
 | 214 |                 // Jenkins | 
 | 215 |                 timeout(10) { | 
 | 216 |                     println "Waiting for Jenkins to come up.." | 
| Filip Pytloun | b1ddf32 | 2017-05-12 16:18:31 +0200 | [diff] [blame] | 217 |                     salt.cmdRun(saltMaster, 'I@jenkins:client', 'while true; do curl -sf 172.16.10.254:8081 >/dev/null && break; done') | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 218 |                 } | 
| Filip Pytloun | 45d4074 | 2017-05-12 18:19:44 +0200 | [diff] [blame] | 219 |                 retry(2) { | 
 | 220 |                     // XXX: needs retry as first run installs python-jenkins | 
 | 221 |                     // thus make jenkins modules available for second run | 
 | 222 |                     salt.enforceState(saltMaster, 'I@jenkins:client', 'jenkins', true) | 
 | 223 |                 } | 
| Ilya Kharin | 7a18c32 | 2017-04-24 18:49:34 +0400 | [diff] [blame] | 224 |  | 
| Volodymyr Stoiko | 75e341e | 2017-05-30 01:45:21 +0300 | [diff] [blame] | 225 |                 // Postgres client - initialize OSS services databases | 
 | 226 |                 timeout(300){ | 
 | 227 |                     println "Waiting for postgresql database to come up.." | 
| Ilya Kharin | 51a5d97 | 2017-06-28 13:36:30 +0400 | [diff] [blame] | 228 |                     salt.cmdRun(saltMaster, 'I@postgresql:client', 'while true; do if docker service logs postgresql_db | grep "ready to accept"; then break; else sleep 5; fi; done') | 
| Volodymyr Stoiko | 75e341e | 2017-05-30 01:45:21 +0300 | [diff] [blame] | 229 |                 } | 
| Ilya Kharin | 51a5d97 | 2017-06-28 13:36:30 +0400 | [diff] [blame] | 230 |                 salt.enforceState(saltMaster, 'I@postgresql:client', 'postgresql.client', true, false) | 
| Volodymyr Stoiko | 75e341e | 2017-05-30 01:45:21 +0300 | [diff] [blame] | 231 |  | 
 | 232 |                 // Setup postgres database with integration between | 
 | 233 |                 // Pushkin notification service and Security Monkey security audit service | 
 | 234 |                 timeout(10) { | 
 | 235 |                     println "Waiting for Pushkin to come up.." | 
| Ilya Kharin | 51a5d97 | 2017-06-28 13:36:30 +0400 | [diff] [blame] | 236 |                     salt.cmdRun(saltMaster, 'I@postgresql:client', 'while true; do curl -sf 172.16.10.254:8887/apps >/dev/null && break; done') | 
| Volodymyr Stoiko | 75e341e | 2017-05-30 01:45:21 +0300 | [diff] [blame] | 237 |                 } | 
| Ilya Kharin | 51a5d97 | 2017-06-28 13:36:30 +0400 | [diff] [blame] | 238 |                 salt.enforceState(saltMaster, 'I@postgresql:client', 'postgresql.client', true) | 
| Volodymyr Stoiko | 75e341e | 2017-05-30 01:45:21 +0300 | [diff] [blame] | 239 |  | 
| Ilya Kharin | 7a18c32 | 2017-04-24 18:49:34 +0400 | [diff] [blame] | 240 |                 // Rundeck | 
 | 241 |                 timeout(10) { | 
 | 242 |                     println "Waiting for Rundeck to come up.." | 
| Filip Pytloun | b1ddf32 | 2017-05-12 16:18:31 +0200 | [diff] [blame] | 243 |                     salt.cmdRun(saltMaster, 'I@rundeck:client', 'while true; do curl -sf 172.16.10.254:4440 >/dev/null && break; done') | 
| Ilya Kharin | 7a18c32 | 2017-04-24 18:49:34 +0400 | [diff] [blame] | 244 |                 } | 
| Filip Pytloun | b1ddf32 | 2017-05-12 16:18:31 +0200 | [diff] [blame] | 245 |                 salt.enforceState(saltMaster, 'I@rundeck:client', 'rundeck.client', true) | 
| Volodymyr Stoiko | d73a8d4 | 2017-07-12 15:49:34 +0300 | [diff] [blame] | 246 |  | 
 | 247 |                 // Elasticsearch | 
 | 248 |                 timeout(10) { | 
 | 249 |                     println 'Waiting for Elasticsearch to come up..' | 
 | 250 |                     salt.cmdRun(saltMaster, 'I@elasticsearch:client', 'while true; do curl -sf 172.16.10.254:9200 >/dev/null && break; done') | 
 | 251 |                 } | 
 | 252 |                 salt.enforceState(saltMaster, 'I@elasticsearch:client', 'elasticsearch.client', true) | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 253 |             } | 
 | 254 |  | 
 | 255 |             stage("Finalize") { | 
 | 256 |                 // | 
| Filip Pytloun | 3eefd3d | 2017-03-03 14:13:41 +0100 | [diff] [blame] | 257 |                 // Deploy user's ssh key | 
 | 258 |                 // | 
| Filip Pytloun | 0da421f | 2017-03-03 18:50:45 +0100 | [diff] [blame] | 259 |                 def adminUser | 
 | 260 |                 def authorizedKeysFile | 
| Filip Pytloun | 9935af0 | 2017-05-15 18:09:17 +0200 | [diff] [blame] | 261 |                 def adminUserCmdOut = salt.cmdRun(saltMaster, 'I@salt:master', "[ ! -d /home/ubuntu ] || echo 'ubuntu user exists'") | 
| Filip Pytloun | bfa918a | 2017-03-04 10:01:30 +0100 | [diff] [blame] | 262 |                 if (adminUserCmdOut =~ /ubuntu user exists/) { | 
| Filip Pytloun | 0da421f | 2017-03-03 18:50:45 +0100 | [diff] [blame] | 263 |                     adminUser = "ubuntu" | 
 | 264 |                     authorizedKeysFile = "/home/ubuntu/.ssh/authorized_keys" | 
 | 265 |                 } else { | 
 | 266 |                     adminUser = "root" | 
 | 267 |                     authorizedKeysFile = "/root/.ssh/authorized_keys" | 
 | 268 |                 } | 
| Filip Pytloun | 3eefd3d | 2017-03-03 14:13:41 +0100 | [diff] [blame] | 269 |  | 
| Filip Pytloun | 0da421f | 2017-03-03 18:50:45 +0100 | [diff] [blame] | 270 |                 if (sshPubKey) { | 
| Filip Pytloun | 3eefd3d | 2017-03-03 14:13:41 +0100 | [diff] [blame] | 271 |                     println "Deploying provided ssh key at ${authorizedKeysFile}" | 
| Filip Pytloun | 4a847d6 | 2017-03-03 15:54:56 +0100 | [diff] [blame] | 272 |                     salt.cmdRun(saltMaster, '*', "echo '${sshPubKey}' | tee -a ${authorizedKeysFile}") | 
| Filip Pytloun | 3eefd3d | 2017-03-03 14:13:41 +0100 | [diff] [blame] | 273 |                 } | 
 | 274 |  | 
 | 275 |                 // | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 276 |                 // Generate docs | 
 | 277 |                 // | 
 | 278 |                 try { | 
| Filip Pytloun | 64ff079 | 2017-03-07 16:47:46 +0100 | [diff] [blame] | 279 |                     try { | 
 | 280 |                         // Run sphinx state to install sphinx-build needed in | 
 | 281 |                         // upcomming orchestrate | 
 | 282 |                         salt.enforceState(saltMaster, 'I@sphinx:server', 'sphinx') | 
 | 283 |                     } catch (Throwable e) { | 
 | 284 |                         true | 
 | 285 |                     } | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 286 |                     retry(3) { | 
| Filip Pytloun | 27e8fa0 | 2017-03-01 20:02:46 +0100 | [diff] [blame] | 287 |                         // TODO: fix salt.orchestrateSystem | 
 | 288 |                         // print salt.orchestrateSystem(saltMaster, ['expression': '*', 'type': 'compound'], 'sphinx.orch.generate_doc') | 
| Filip Pytloun | c17161d | 2017-03-03 09:50:54 +0100 | [diff] [blame] | 289 |                         def out = salt.cmdRun(saltMaster, 'I@salt:master', 'salt-run state.orchestrate sphinx.orch.generate_doc || echo "Command execution failed"') | 
| Jakub Josef | fafd659 | 2017-03-27 18:53:17 +0200 | [diff] [blame] | 290 |                         print common.prettyPrint(out) | 
| Filip Pytloun | c17161d | 2017-03-03 09:50:54 +0100 | [diff] [blame] | 291 |                         if (out =~ /Command execution failed/) { | 
 | 292 |                             throw new Exception("Command execution failed") | 
 | 293 |                         } | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 294 |                     } | 
 | 295 |                 } catch (Throwable e) { | 
 | 296 |                     // We don't want sphinx docs to ruin whole build, so possible | 
 | 297 |                     // errors are just ignored here | 
 | 298 |                     true | 
 | 299 |                 } | 
 | 300 |                 salt.enforceState(saltMaster, 'I@nginx:server', 'nginx') | 
 | 301 |  | 
| Filip Pytloun | a400040 | 2017-05-16 10:12:02 +0200 | [diff] [blame] | 302 |                 def failedSvc = salt.cmdRun(saltMaster, '*', """systemctl --failed | grep -E 'loaded[ \t]+failed' && echo 'Command execution failed' || true""") | 
| Jakub Josef | fafd659 | 2017-03-27 18:53:17 +0200 | [diff] [blame] | 303 |                 print common.prettyPrint(failedSvc) | 
| Filip Pytloun | bd61927 | 2017-03-22 12:21:01 +0100 | [diff] [blame] | 304 |                 if (failedSvc =~ /Command execution failed/) { | 
 | 305 |                     common.errorMsg("Some services are not running. Environment may not be fully functional!") | 
 | 306 |                 } | 
 | 307 |  | 
| Filip Pytloun | d942739 | 2017-03-04 13:58:08 +0100 | [diff] [blame] | 308 |                 common.successMsg(""" | 
| Filip Pytloun | 794ad95 | 2017-03-03 10:39:26 +0100 | [diff] [blame] | 309 |     ============================================================ | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 310 |     Your CI/CD lab has been deployed and you can enjoy it: | 
| Filip Pytloun | 3eefd3d | 2017-03-03 14:13:41 +0100 | [diff] [blame] | 311 |     Use sshuttle to connect to your private subnet: | 
 | 312 |  | 
| Filip Pytloun | 8546405 | 2017-03-03 16:31:43 +0100 | [diff] [blame] | 313 |         sshuttle -r ${adminUser}@${saltMasterHost} 172.16.10.0/24 | 
| Filip Pytloun | 3eefd3d | 2017-03-03 14:13:41 +0100 | [diff] [blame] | 314 |  | 
 | 315 |     And visit services running at 172.16.10.254 (vip address): | 
 | 316 |  | 
| Ilya Kharin | 04c0998 | 2017-03-30 14:46:20 +0400 | [diff] [blame] | 317 |         9600    HAProxy statistics | 
 | 318 |         8080    Gerrit | 
 | 319 |         8081    Jenkins | 
| Filip Pytloun | d0d700d | 2017-03-29 11:15:42 +0200 | [diff] [blame] | 320 |         8089    LDAP administration | 
| Ilya Kharin | 04c0998 | 2017-03-30 14:46:20 +0400 | [diff] [blame] | 321 |         4440    Rundeck | 
 | 322 |         8084    DevOps Portal | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 323 |         8091    Docker swarm visualizer | 
 | 324 |         8090    Reclass-generated documentation | 
 | 325 |  | 
| Filip Pytloun | 3eefd3d | 2017-03-03 14:13:41 +0100 | [diff] [blame] | 326 |     If you provided SSH_PUBLIC_KEY, you can use it to login, | 
 | 327 |     otherwise you need to get private key connected to this | 
 | 328 |     heat template. | 
 | 329 |  | 
 | 330 |     DON'T FORGET TO TERMINATE YOUR STACK WHEN YOU DON'T NEED IT! | 
| Filip Pytloun | 8546405 | 2017-03-03 16:31:43 +0100 | [diff] [blame] | 331 |     ============================================================""") | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 332 |             } | 
 | 333 |         } catch (Throwable e) { | 
 | 334 |             // If there was an error or exception thrown, the build failed | 
 | 335 |             currentBuild.result = "FAILURE" | 
 | 336 |             throw e | 
 | 337 |         } finally { | 
 | 338 |             // Cleanup | 
| Filip Pytloun | 794ad95 | 2017-03-03 10:39:26 +0100 | [diff] [blame] | 339 |             if (HEAT_STACK_DELETE.toBoolean() == true) { | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 340 |                 stage('Trigger cleanup job') { | 
| Ilya Kharin | 38b261d | 2017-06-29 01:42:59 +0400 | [diff] [blame] | 341 |                     build(job: 'deploy-stack-cleanup', parameters: [ | 
 | 342 |                         [$class: 'StringParameterValue', name: 'STACK_NAME', value: HEAT_STACK_NAME], | 
 | 343 |                         [$class: 'StringParameterValue', name: 'OPENSTACK_API_PROJECT', value: OPENSTACK_API_PROJECT], | 
 | 344 |                     ]) | 
| Filip Pytloun | bfce09d | 2017-03-01 19:00:43 +0100 | [diff] [blame] | 345 |                 } | 
| Filip Pytloun | fd6726a | 2017-02-28 19:31:16 +0100 | [diff] [blame] | 346 |             } | 
| Filip Pytloun | 2374198 | 2017-02-27 17:43:00 +0100 | [diff] [blame] | 347 |         } | 
| Filip Pytloun | f6e877f | 2017-02-28 19:38:16 +0100 | [diff] [blame] | 348 |     } | 
| Filip Pytloun | 0a07f70 | 2017-02-24 18:26:18 +0100 | [diff] [blame] | 349 | } |