Vasyl Saienko | 4a2832d | 2024-05-16 09:00:03 +0300 | [diff] [blame] | 1 | #!/bin/bash |
| 2 | set -x |
| 3 | set -e |
| 4 | # allow access to the local variables from prepare-metadata.py |
| 5 | set -a |
| 6 | |
| 7 | # ensure we don't re-source this in the same environment |
| 8 | [[ -z "$_INSTALL_SCRIPT" ]] || return 0 |
| 9 | declare -r -g _INSTALL_SCRIPT=1 |
| 10 | |
| 11 | # |
| 12 | # Variables in this block are passed from heat template |
| 13 | # |
| 14 | CONTROL_NETWORK_CIDR=${CONTROL_NETWORK_CIDR:-$control_network_cidr} |
| 15 | PUBLIC_INTERFACE=${PUBLIC_INTERFACE:-$private_floating_interface} |
| 16 | PUBLIC_INTERFACE_IP=${PUBLIC_INTERFACE_IP:-$private_floating_interface_ip} |
| 17 | PUBLIC_INTERFACE_CIDR=${PUBLIC_INTERFACE_CIDR:-$private_floating_network_cidr} |
Mykyta Karpin | ad86fe7 | 2025-01-20 08:25:20 +0100 | [diff] [blame^] | 18 | EXTERNAL_SEVICES_INTERFACE_IP=${EXTERNAL_SEVICES_INTERFACE_IP:-$external_services_interface_ip} |
| 19 | EXTERNAL_SEVICES_INTERFACE_CIDR=${EXTERNAL_SEVICES_INTERFACE_CIDR:-$external_services_network_cidr} |
Vasyl Saienko | 4a2832d | 2024-05-16 09:00:03 +0300 | [diff] [blame] | 20 | DEFAULT_INTERFACE=${DEFAULT_INTERFACE:-$default_interface} |
| 21 | STORAGE_BACKEND_INTERFACE=${STORAGE_BACKEND_INTERFACE:-$storage_backend_interface} |
| 22 | STORAGE_BACKEND_INTERFACE_IP=${STORAGE_BACKEND_INTERFACE_IP:-$storage_backend_network_interface_ip} |
| 23 | STORAGE_BACKEND_NETWORK=${STORAGE_BACKEND_NETWORK:-$storage_backend_network_cidr} |
| 24 | STORAGE_FRONTEND_INTERFACE=${STORAGE_FRONTEND_INTERFACE:-$storage_frontend_interface} |
| 25 | STORAGE_FRONTEND_INTERFACE_IP=${STORAGE_FRONTEND_INTERFACE_IP:-$storage_frontend_network_interface_ip} |
| 26 | STORAGE_FRONTEND_NETWORK=${STORAGE_FRONTEND_NETWORK:-$storage_frontend_network_cidr} |
| 27 | STORAGE_FRONTEND_NETWORK_NETMASK=$(echo ${STORAGE_FRONTEND_NETWORK} | cut -d'/' -f2) |
| 28 | |
| 29 | IRONIC_BAREMETAL_NETWORK=${IRONIC_BAREMETAL_NETWORK:-$ironic_baremetal_network_cidr} |
| 30 | IRONIC_BAREMETAL_INTERFACE_IP=${IRONIC_BAREMETAL_INTERFACE_IP:-$ironic_baremetal_interface_ip} |
| 31 | IRONIC_BAREMETAL_TUNNEL_NETWORK=${IRONIC_BAREMETAL_TUNNEL_NETWORK:-$ironic_baremetal_tunnel_cidr} |
| 32 | TUNNEL_INTERFACE_IP=${TUNNEL_INTERFACE_IP:-$tunnel_interface_ip} |
| 33 | FRR_BGP_NEIGHBORS=${FRR_BGP_NEIGHBORS:-$frr_bgp_neighbors} |
| 34 | FRR_EVPN_TUNNELS_RANGE=${FRR_EVPN_TUNNELS_RANGE:-$frr_evpn_tunnels_range} |
| 35 | FRR_EVPN_VXLAN_DST_PORT=${FRR_EVPN_VXLAN_DST_PORT:-$frr_evpn_vxlan_dst_port} |
| 36 | |
| 37 | NODE_TYPE=${NODE_TYPE:-$node_type} |
| 38 | KUBERNETES_INSTALLER=${KUBERNETES_INSTALLER:-$kubernetes_installer} |
| 39 | UCP_MASTER_HOST=${UCP_MASTER_HOST:-$ucp_master_host} |
| 40 | NODE_METADATA=${NODE_METADATA:-'$node_metadata'} |
| 41 | DOCKER_EE_URL=${DOCKER_EE_URL:-$docker_ee_url} |
| 42 | DOCKER_EE_RELEASE=${DOCKER_EE_RELEASE:-$docker_ee_release} |
| 43 | DOCKER_EE_PACKAGES=${DOCKER_EE_PACKAGES:-$docker_ee_packages} |
| 44 | DOCKER_UCP_IMAGE=${DOCKER_UCP_IMAGE:-$docker_ucp_image} |
| 45 | BINARY_BASE_URL=${BINARY_BASE_URL:-$binary_base_url} |
| 46 | UCP_DOCKER_SWARM_DATA_PORT=${UCP_DOCKER_SWARM_DATA_PORT:-$docker_ucp_swarm_data_port} |
Mykyta Karpin | 9df830a | 2024-09-12 14:25:01 +0200 | [diff] [blame] | 47 | UCP_AUDIT_LOG_LEVEL=${UCP_AUDIT_LOG_LEVEL:-$ucp_audit_log_level} |
Vasyl Saienko | 4a2832d | 2024-05-16 09:00:03 +0300 | [diff] [blame] | 48 | FLOATING_NETWORK_PREFIXES=${FLOATING_NETWORK_PREFIXES:-$private_floating_network_cidr} |
| 49 | IRONIC_MT_ENABLED=${IRONIC_MT_ENABLED:-$ironic_mt_enabled} |
| 50 | |
| 51 | HUGE_PAGES=${HUGE_PAGES:-$huge_pages} |
| 52 | TUNGSTENFABRIC_ENABLED=${TUNGSTENFABRIC_ENABLED:-$tungstenfabric_enabled} |
| 53 | SINGLE_NODE=${SINGLE_NODE:-$single_node} |
| 54 | DOCKER_DEFAULT_ADDRESS_POOL=${DOCKER_DEFAULT_ADDRESS_POOL:-$docker_default_address_pool} |
| 55 | LVM_LOOP_DEVICE_SIZE=${LVM_LOOP_DEVICE_SIZE:-$lvm_loop_device_size} |
| 56 | CINDER_LVM_LOOP_DEVICE_SIZE=${CINDER_LVM_LOOP_DEVICE_SIZE:-$cinder_lvm_loop_device_size} |
| 57 | SECURE_OVERLAY_ENABLED=${SECURE_OVERLAY_ENABLED:-$secure_overlay_enabled} |
| 58 | KUBECTL_VERSION=${KUBECTL_VERSION:-$kubectl_version} |
Vasyl Saienko | 92133c0 | 2024-05-16 10:18:51 +0300 | [diff] [blame] | 59 | KUBERNETES_CONTAINER_RUNTIME=${KUBERNETES_CONTAINER_RUNTIME:-$kubernetes_container_runtime} |
Vasyl Saienko | 4a2832d | 2024-05-16 09:00:03 +0300 | [diff] [blame] | 60 | |
| 61 | DEVOPS_UTILS_REFSPEC=${DEVOPS_UTILS_REFSPEC:-$devops_utils_refspec} |
Vasyl Saienko | 3e8ba73 | 2024-09-09 14:07:49 +0300 | [diff] [blame] | 62 | K0S_VERSION=${K0S_VERSION:-$k0s_version} |
Vasyl Saienko | 4a2832d | 2024-05-16 09:00:03 +0300 | [diff] [blame] | 63 | # |
| 64 | # End of block |
| 65 | # |
| 66 | |
| 67 | DEVOPS_UTILS_REPO=${DEVOPS_UTILS_REPO:-'https://gerrit.mcp.mirantis.com/oscore-tools/devops-utils'} |
| 68 | DEVOPS_UTILS_REFSPEC=${DEVOPS_UTILS_REFSPEC:-'master'} |
| 69 | DEVOPS_UTILS_DST=/usr/share/devops-utils |
| 70 | |
| 71 | #Wait external network |
Vasyl Saienko | 5942552 | 2024-05-17 14:00:19 +0300 | [diff] [blame] | 72 | netplan apply |
Vasyl Saienko | 4a2832d | 2024-05-16 09:00:03 +0300 | [diff] [blame] | 73 | systemctl restart systemd-resolved |
Vasyl Saienko | 5942552 | 2024-05-17 14:00:19 +0300 | [diff] [blame] | 74 | sleep 15 |
| 75 | curl --connect-timeout 10 --retry 12 --retry-delay 10 ${DEVOPS_UTILS_REPO} || (sleep 1; /bin/false) |
Vasyl Saienko | 4a2832d | 2024-05-16 09:00:03 +0300 | [diff] [blame] | 76 | |
Vasyl Saienko | 183863f | 2024-05-18 14:18:39 +0300 | [diff] [blame] | 77 | if [[ ! -d ${DEVOPS_UTILS_DST} ]]; then |
| 78 | git clone ${DEVOPS_UTILS_REPO} ${DEVOPS_UTILS_DST} |
| 79 | fi |
Vasyl Saienko | 4a2832d | 2024-05-16 09:00:03 +0300 | [diff] [blame] | 80 | pushd ${DEVOPS_UTILS_DST} |
| 81 | if echo "$DEVOPS_UTILS_REFSPEC" |grep -q "^refs"; then |
| 82 | git fetch ${DEVOPS_UTILS_REPO} ${DEVOPS_UTILS_REFSPEC} |
| 83 | git checkout FETCH_HEAD |
| 84 | else |
| 85 | git checkout ${DEVOPS_UTILS_REFSPEC} |
| 86 | fi |
| 87 | git log --oneline -10 |
| 88 | popd |
| 89 | |
| 90 | |
| 91 | source ${DEVOPS_UTILS_DST}/de/heat-templates/scripts/functions.sh |
| 92 | |
| 93 | function wait_condition_send { |
| 94 | local status=${1:-SUCCESS} |
| 95 | local reason=${2:-\"empty\"} |
| 96 | local data=${3:-\"empty\"} |
| 97 | local data_binary="{\"status\": \"$status\", \"reason\": \"$reason\", \"data\": $data}" |
| 98 | echo "Trying to send signal to wait condition 5 times: $data_binary" |
| 99 | WAIT_CONDITION_NOTIFY_EXIT_CODE=2 |
| 100 | i=0 |
| 101 | while (( ${WAIT_CONDITION_NOTIFY_EXIT_CODE} != 0 && ${i} < 5 )); do |
| 102 | $wait_condition_notify -k --data-binary "$data_binary" && WAIT_CONDITION_NOTIFY_EXIT_CODE=0 || WAIT_CONDITION_NOTIFY_EXIT_CODE=2 |
| 103 | i=$((i + 1)) |
| 104 | sleep 1 |
| 105 | done |
| 106 | if (( ${WAIT_CONDITION_NOTIFY_EXIT_CODE} !=0 && "${status}" == "SUCCESS" )) |
| 107 | then |
| 108 | status="FAILURE" |
| 109 | reason="Can't reach metadata service to report about SUCCESS." |
| 110 | fi |
| 111 | if [ "$status" == "FAILURE" ]; then |
| 112 | exit 1 |
| 113 | fi |
| 114 | } |
| 115 | |
| 116 | # Exit on any errors |
| 117 | function handle_exit { |
| 118 | if [ $? != 0 ] ; then |
| 119 | wait_condition_send "FAILURE" "Script terminated with an error." |
| 120 | fi |
| 121 | } |
| 122 | trap handle_exit EXIT |
| 123 | |
| 124 | if [[ "${BASH_SOURCE[0]}" == "${0}" ]]; then |
| 125 | case "$NODE_TYPE" in |
| 126 | # Please keep the "prepare_metadata_files", "disable-rp-filter", "network_config" and "prepare_network" functions |
| 127 | # at the very beginning in the same order. |
| 128 | ucp) |
Vasyl Saienko | 45280eb | 2024-06-24 11:45:13 +0000 | [diff] [blame] | 129 | configure_sysctl_limits |
Vasyl Saienko | f981351 | 2024-07-02 12:30:25 +0300 | [diff] [blame] | 130 | configure_logind_conf |
dbiletskiy | 70af819 | 2024-06-19 09:27:10 +0200 | [diff] [blame] | 131 | disable_unattended_upgr |
Vasyl Saienko | 4a2832d | 2024-05-16 09:00:03 +0300 | [diff] [blame] | 132 | setup_bind_mounts |
| 133 | wait_for_external_network |
| 134 | prepare_metadata_files |
| 135 | disable_rp_filter |
| 136 | network_config |
| 137 | prepare_network |
| 138 | if [[ "${KUBERNETES_INSTALLER}" == "ucp" ]]; then |
| 139 | prepare_docker_config |
| 140 | fi |
| 141 | install_required_packages |
| 142 | install_kubectl |
| 143 | configure_ntp |
| 144 | configure_atop |
Oleksandr Kononenko | dd272aa | 2024-12-09 20:13:46 +0200 | [diff] [blame] | 145 | workaround_default_forward_policy |
Vasyl Saienko | 4a2832d | 2024-05-16 09:00:03 +0300 | [diff] [blame] | 146 | if [[ "${KUBERNETES_INSTALLER}" == "ucp" ]]; then |
| 147 | install_docker |
| 148 | swarm_init |
| 149 | create_ucp_config |
| 150 | cache_images |
| 151 | install_ucp |
| 152 | download_bundles |
| 153 | rm_ucp_config |
| 154 | elif [[ "${KUBERNETES_INSTALLER}" == "k0s" ]]; then |
| 155 | download_k0s |
| 156 | install_k0s |
| 157 | fi |
Vasyl Saienko | 59e5b2a | 2024-09-09 08:57:18 +0300 | [diff] [blame] | 158 | wait_for_node |
| 159 | set_node_labels |
| 160 | collect_ceph_metadata |
| 161 | configure_contrack |
Vasyl Saienko | 4a2832d | 2024-05-16 09:00:03 +0300 | [diff] [blame] | 162 | if [[ "${KUBERNETES_INSTALLER}" == "ucp" ]]; then |
Vasyl Saienko | 4a2832d | 2024-05-16 09:00:03 +0300 | [diff] [blame] | 163 | disable_iptables_for_bridges |
| 164 | fi |
| 165 | if [[ "${SINGLE_NODE}" == true ]]; then |
| 166 | nested_virt_config |
Vasyl Saienko | 59e5b2a | 2024-09-09 08:57:18 +0300 | [diff] [blame] | 167 | if [[ "${KUBERNETES_INSTALLER}" == "ucp" ]]; then |
| 168 | disable_master_taint |
| 169 | fi |
Vasyl Saienko | 4a2832d | 2024-05-16 09:00:03 +0300 | [diff] [blame] | 170 | collect_interfaces_metadata |
| 171 | fi |
| 172 | cron_disable_calico_offloading |
| 173 | ;; |
| 174 | master) |
Vasyl Saienko | 45280eb | 2024-06-24 11:45:13 +0000 | [diff] [blame] | 175 | configure_sysctl_limits |
Vasyl Saienko | f981351 | 2024-07-02 12:30:25 +0300 | [diff] [blame] | 176 | configure_logind_conf |
dbiletskiy | 70af819 | 2024-06-19 09:27:10 +0200 | [diff] [blame] | 177 | disable_unattended_upgr |
Vasyl Saienko | 4a2832d | 2024-05-16 09:00:03 +0300 | [diff] [blame] | 178 | setup_bind_mounts |
| 179 | wait_for_external_network |
| 180 | nested_virt_config |
| 181 | prepare_metadata_files |
| 182 | disable_rp_filter |
| 183 | network_config |
| 184 | prepare_network |
| 185 | if [[ "${KUBERNETES_INSTALLER}" == "ucp" ]]; then |
| 186 | prepare_docker_config |
| 187 | fi |
| 188 | install_required_packages |
| 189 | install_kubectl |
| 190 | configure_ntp |
| 191 | configure_atop |
Oleksandr Kononenko | dd272aa | 2024-12-09 20:13:46 +0200 | [diff] [blame] | 192 | workaround_default_forward_policy |
Vasyl Saienko | 4a2832d | 2024-05-16 09:00:03 +0300 | [diff] [blame] | 193 | if [[ "${KUBERNETES_INSTALLER}" == "ucp" ]]; then |
| 194 | install_docker |
| 195 | cache_images |
| 196 | download_bundles |
| 197 | join_node manager |
| 198 | fi |
| 199 | wait_for_node |
| 200 | set_node_labels |
| 201 | collect_ceph_metadata |
| 202 | configure_contrack |
| 203 | if [[ "${KUBERNETES_INSTALLER}" == "ucp" ]]; then |
| 204 | disable_iptables_for_bridges |
| 205 | fi |
| 206 | collect_interfaces_metadata |
| 207 | cron_disable_calico_offloading |
| 208 | increase_iscsi_timeout |
| 209 | ;; |
| 210 | worker) |
Vasyl Saienko | 45280eb | 2024-06-24 11:45:13 +0000 | [diff] [blame] | 211 | configure_sysctl_limits |
Vasyl Saienko | f981351 | 2024-07-02 12:30:25 +0300 | [diff] [blame] | 212 | configure_logind_conf |
dbiletskiy | 70af819 | 2024-06-19 09:27:10 +0200 | [diff] [blame] | 213 | disable_unattended_upgr |
Vasyl Saienko | 4a2832d | 2024-05-16 09:00:03 +0300 | [diff] [blame] | 214 | setup_bind_mounts |
| 215 | wait_for_external_network |
| 216 | if [[ "${CONFIGURE_HUGE_PAGES}" == true ]]; then |
| 217 | configure_huge_pages |
| 218 | fi |
| 219 | nested_virt_config |
| 220 | prepare_metadata_files |
| 221 | disable_rp_filter |
| 222 | network_config |
| 223 | prepare_network |
| 224 | if [[ "${KUBERNETES_INSTALLER}" == "ucp" ]]; then |
| 225 | prepare_docker_config |
| 226 | fi |
| 227 | install_required_packages |
| 228 | install_kubectl |
| 229 | enable_iscsi |
| 230 | configure_ntp |
| 231 | configure_atop |
Oleksandr Kononenko | dd272aa | 2024-12-09 20:13:46 +0200 | [diff] [blame] | 232 | workaround_default_forward_policy |
Vasyl Saienko | 4a2832d | 2024-05-16 09:00:03 +0300 | [diff] [blame] | 233 | if [[ "${KUBERNETES_INSTALLER}" == "ucp" ]]; then |
| 234 | install_docker |
| 235 | cache_images |
| 236 | download_bundles |
| 237 | join_node worker |
| 238 | elif [[ "${KUBERNETES_INSTALLER}" == "k0s" ]]; then |
| 239 | download_k0s |
| 240 | download_k8s_metadata |
| 241 | join_k0s_node worker |
| 242 | fi |
| 243 | wait_for_node |
| 244 | set_node_labels |
| 245 | collect_ceph_metadata |
| 246 | configure_contrack |
| 247 | if [[ "${KUBERNETES_INSTALLER}" == "ucp" ]]; then |
| 248 | disable_iptables_for_bridges |
| 249 | fi |
| 250 | collect_interfaces_metadata |
| 251 | configure_lvm |
| 252 | cron_disable_calico_offloading |
| 253 | increase_iscsi_timeout |
| 254 | ;; |
| 255 | frr) |
Vasyl Saienko | 45280eb | 2024-06-24 11:45:13 +0000 | [diff] [blame] | 256 | configure_sysctl_limits |
dbiletskiy | 70af819 | 2024-06-19 09:27:10 +0200 | [diff] [blame] | 257 | disable_unattended_upgr |
Vasyl Saienko | 4a2832d | 2024-05-16 09:00:03 +0300 | [diff] [blame] | 258 | wait_for_external_network |
| 259 | prepare_metadata_files |
| 260 | disable_rp_filter |
| 261 | network_config |
| 262 | prepare_network |
| 263 | if [[ "${KUBERNETES_INSTALLER}" == "ucp" ]]; then |
| 264 | prepare_docker_config |
| 265 | fi |
| 266 | install_required_packages |
| 267 | configure_ntp |
| 268 | configure_atop |
| 269 | if [[ "${KUBERNETES_INSTALLER}" == "ucp" ]]; then |
| 270 | install_docker |
| 271 | cache_images |
| 272 | download_bundles |
| 273 | fi |
Oleksandr Kononenko | dd272aa | 2024-12-09 20:13:46 +0200 | [diff] [blame] | 274 | workaround_default_forward_policy |
Vasyl Saienko | 4a2832d | 2024-05-16 09:00:03 +0300 | [diff] [blame] | 275 | configure_contrack |
| 276 | disable_iptables_for_bridges |
| 277 | install_frr |
| 278 | cron_disable_calico_offloading |
| 279 | increase_iscsi_timeout |
| 280 | ;; |
| 281 | *) |
| 282 | echo "Usage: $0 {ucp|master|worker}" |
| 283 | exit 1 |
| 284 | esac |
| 285 | |
| 286 | wait_condition_send "SUCCESS" "Instance successfuly started." "${HW_METADATA}" |
| 287 | fi |