blob: c27f302dac6de99da39184b7ce05689d1f9824e3 [file] [log] [blame]
Jude Cross986e3f52017-07-24 14:57:20 -07001# Copyright 2018 Rackspace US Inc. All rights reserved.
2#
3# Licensed under the Apache License, Version 2.0 (the "License"); you may
4# not use this file except in compliance with the License. You may obtain
5# a copy of the License at
6#
7# http://www.apache.org/licenses/LICENSE-2.0
8#
9# Unless required by applicable law or agreed to in writing, software
10# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
11# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
12# License for the specific language governing permissions and limitations
13# under the License.
14
15import ipaddress
rbubyr6978e022025-03-18 14:58:39 +010016import netaddr
Michael Johnsonbaf12e02020-10-27 16:10:28 -070017import os
Jude Cross986e3f52017-07-24 14:57:20 -070018import random
Gregory Thiemongea2c234e2021-11-02 17:08:29 +010019import re
Jude Cross986e3f52017-07-24 14:57:20 -070020import shlex
Jude Cross986e3f52017-07-24 14:57:20 -070021import string
22import subprocess
23import tempfile
24
Michael Johnsonbaf12e02020-10-27 16:10:28 -070025from cryptography.hazmat.primitives import serialization
Gregory Thiemongeb0da4f32022-02-04 08:58:06 +010026from oslo_config import cfg
Jude Cross986e3f52017-07-24 14:57:20 -070027from oslo_log import log as logging
28from oslo_utils import uuidutils
Gregory Thiemongecba3b222024-05-16 02:57:08 -040029from tempest import clients
Jude Cross986e3f52017-07-24 14:57:20 -070030from tempest import config
Gregory Thiemongecba3b222024-05-16 02:57:08 -040031from tempest.lib import auth
Jude Cross986e3f52017-07-24 14:57:20 -070032from tempest.lib.common.utils import data_utils
33from tempest.lib.common.utils.linux import remote_client
Jude Cross986e3f52017-07-24 14:57:20 -070034from tempest.lib import exceptions
35from tempest import test
Michael Johnson04dc5cb2019-01-20 11:03:50 -080036import tenacity
Jude Cross986e3f52017-07-24 14:57:20 -070037
Michael Johnsonbaf12e02020-10-27 16:10:28 -070038from octavia_tempest_plugin.common import cert_utils
Jude Cross986e3f52017-07-24 14:57:20 -070039from octavia_tempest_plugin.common import constants as const
Ilya Bumarskoveff9bae2023-03-16 14:12:09 +040040from octavia_tempest_plugin import config as config_octavia
Tom Weiningerc03e9c32024-04-23 14:07:04 +020041import octavia_tempest_plugin.services.load_balancer.v2 as lbv2
Michael Johnson6006de72021-02-21 01:42:39 +000042from octavia_tempest_plugin.tests import RBAC_tests
Jude Cross986e3f52017-07-24 14:57:20 -070043from octavia_tempest_plugin.tests import validators
44from octavia_tempest_plugin.tests import waiters
45
46CONF = config.CONF
47LOG = logging.getLogger(__name__)
48
Gregory Thiemonge29d17902019-04-30 15:06:17 +020049
Michael Johnson6006de72021-02-21 01:42:39 +000050class LoadBalancerBaseTest(validators.ValidatorsMixin,
51 RBAC_tests.RBACTestsMixin, test.BaseTestCase):
Jude Cross986e3f52017-07-24 14:57:20 -070052 """Base class for load balancer tests."""
53
Gregory Thiemonge3497f6c2021-04-19 21:33:13 +020054 if CONF.load_balancer.RBAC_test_type == const.OWNERADMIN:
55 credentials = [
56 'admin', 'primary', ['lb_admin', CONF.load_balancer.admin_role],
57 ['lb_member', CONF.load_balancer.member_role],
58 ['lb_member2', CONF.load_balancer.member_role]]
Michael Johnson6dac8ff2023-03-09 00:04:37 +000059 elif CONF.load_balancer.RBAC_test_type == const.KEYSTONE_DEFAULT_ROLES:
Michael Johnson6006de72021-02-21 01:42:39 +000060 credentials = [
Michael Johnson6dac8ff2023-03-09 00:04:37 +000061 'admin', 'primary',
Gregory Thiemongecba3b222024-05-16 02:57:08 -040062 ['lb_admin', 'admin'],
63 ['lb_observer', 'reader'],
64 ['lb_global_observer', 'reader'],
65 ['lb_member', 'member'],
66 ['lb_member2', 'member']]
67 # Note: an additional non-member user is added in setup_credentials
Michael Johnson6006de72021-02-21 01:42:39 +000068 else:
69 credentials = [
70 'admin', 'primary', ['lb_admin', CONF.load_balancer.admin_role],
71 ['lb_observer', CONF.load_balancer.observer_role, 'reader'],
72 ['lb_global_observer', CONF.load_balancer.global_observer_role,
73 'reader'],
Michael Johnson9e9f5262023-01-18 17:59:17 +000074 # Note: Some projects are now requiring the 'member' role by
75 # default (nova for example) so make sure our creds have this role
76 ['lb_member', CONF.load_balancer.member_role, 'member'],
77 ['lb_member2', CONF.load_balancer.member_role, 'member']]
Michael Johnson6006de72021-02-21 01:42:39 +000078
Michael Johnson6006de72021-02-21 01:42:39 +000079 # A tuple of credentials that will be allocated by tempest using the
80 # 'credentials' list above. These are used to build RBAC test lists.
81 allocated_creds = []
82 for cred in credentials:
83 if isinstance(cred, list):
84 allocated_creds.append('os_roles_' + cred[0])
85 else:
86 allocated_creds.append('os_' + cred)
87 # Tests shall not mess with the list of allocated credentials
88 allocated_credentials = tuple(allocated_creds)
Jude Cross986e3f52017-07-24 14:57:20 -070089
Adam Harwelle029af22018-05-24 17:13:28 -070090 webserver1_response = 1
91 webserver2_response = 5
Michael Johnsondfd818a2018-08-21 20:54:54 -070092 used_ips = []
Jude Cross986e3f52017-07-24 14:57:20 -070093
Michael Johnson89bdbcd2020-03-19 15:59:19 -070094 SRC_PORT_NUMBER_MIN = 32768
95 SRC_PORT_NUMBER_MAX = 61000
Gregory Thiemonge29d17902019-04-30 15:06:17 +020096 src_port_number = SRC_PORT_NUMBER_MIN
97
Jude Cross986e3f52017-07-24 14:57:20 -070098 @classmethod
99 def skip_checks(cls):
100 """Check if we should skip all of the children tests."""
101 super(LoadBalancerBaseTest, cls).skip_checks()
102
103 service_list = {
104 'load_balancer': CONF.service_available.load_balancer,
105 }
106
107 live_service_list = {
108 'compute': CONF.service_available.nova,
109 'image': CONF.service_available.glance,
110 'neutron': CONF.service_available.neutron
111 }
112
113 if not CONF.load_balancer.test_with_noop:
114 service_list.update(live_service_list)
115
116 for service, available in service_list.items():
117 if not available:
zhangzs2a6cf672018-11-10 16:13:11 +0800118 skip_msg = ("{0} skipped as {1} service is not "
Jude Cross986e3f52017-07-24 14:57:20 -0700119 "available.".format(cls.__name__, service))
120 raise cls.skipException(skip_msg)
121
122 # We must be able to reach our VIP and instances
123 if not (CONF.network.project_networks_reachable
124 or CONF.network.public_network_id):
125 msg = ('Either project_networks_reachable must be "true", or '
126 'public_network_id must be defined.')
127 raise cls.skipException(msg)
128
129 @classmethod
Gregory Thiemongecba3b222024-05-16 02:57:08 -0400130 def _setup_new_user_role_client(cls, project_id, role_name):
131 user = {
132 'name': data_utils.rand_name('user'),
133 'password': data_utils.rand_password()
134 }
135 user_id = cls.os_admin.users_v3_client.create_user(
136 **user)['user']['id']
137 cls._created_users.append(user_id)
138 roles = cls.os_admin.roles_v3_client.list_roles(
139 name=role_name)['roles']
140 if len(roles) == 0:
141 role = {
142 'name': role_name
143 }
144 role_id = cls.os_admin.roles_v3_client.create_role(
145 **role)['role']['id']
146 cls._created_roles.append(role_id)
147 else:
148 role_id = roles[0]['id']
149 cls.os_admin.roles_v3_client.create_user_role_on_project(
150 project_id, user_id, role_id
151 )
152 creds = auth.KeystoneV3Credentials(
153 user_id=user_id,
154 password=user['password'],
155 project_id=project_id
156 )
157 auth_provider = clients.get_auth_provider(creds)
158 creds = auth_provider.fill_credentials()
159 return clients.Manager(credentials=creds)
160
161 @classmethod
Jude Cross986e3f52017-07-24 14:57:20 -0700162 def setup_credentials(cls):
163 """Setup test credentials and network resources."""
164 # Do not auto create network resources
165 cls.set_network_resources()
166 super(LoadBalancerBaseTest, cls).setup_credentials()
167
Gregory Thiemongecba3b222024-05-16 02:57:08 -0400168 cls._created_projects = []
169 cls._created_users = []
170 cls._created_roles = []
171
172 non_dyn_users = []
173
174 if CONF.load_balancer.RBAC_test_type == const.KEYSTONE_DEFAULT_ROLES:
175 # Create a non-member user for keystone_default_roles
176 # When using dynamic credentials, tempest cannot create a user
177 # without a role, it always adds at least the "member" role.
178 # We manually create the user with a temporary role
179 project_id = cls.os_admin.projects_client.create_project(
180 data_utils.rand_name()
181 )['project']['id']
182 cls._created_projects.append(project_id)
183 cls.os_not_member = cls._setup_new_user_role_client(
184 project_id,
185 data_utils.rand_name('role'))
186 cls.allocated_creds.append('os_not_member')
187 non_dyn_users.append('not_member')
188
189 # Tests shall not mess with the list of allocated credentials
190 cls.allocated_credentials = tuple(cls.allocated_creds)
191
Bas de Bruijne530a88a2022-12-15 11:12:45 -0400192 if not CONF.load_balancer.log_user_roles:
193 return
194
Michael Johnson6006de72021-02-21 01:42:39 +0000195 # Log the user roles for this test run
196 role_name_cache = {}
Gregory Thiemongecba3b222024-05-16 02:57:08 -0400197 for cred in cls.credentials + non_dyn_users:
Michael Johnson6006de72021-02-21 01:42:39 +0000198 user_roles = []
199 if isinstance(cred, list):
200 user_name = cred[0]
201 cred_obj = getattr(cls, 'os_roles_' + cred[0])
202 else:
203 user_name = cred
204 cred_obj = getattr(cls, 'os_' + cred)
205 params = {'user.id': cred_obj.credentials.user_id,
Rodolfo Alonso Hernandezb5969972025-02-17 14:23:38 +0000206 'scope.project.id': cred_obj.credentials.project_id}
Michael Johnson6006de72021-02-21 01:42:39 +0000207 roles = cls.os_admin.role_assignments_client.list_role_assignments(
208 **params)['role_assignments']
209 for role in roles:
210 role_id = role['role']['id']
211 try:
212 role_name = role_name_cache[role_id]
213 except KeyError:
214 role_name = cls.os_admin.roles_v3_client.show_role(
215 role_id)['role']['name']
216 role_name_cache[role_id] = role_name
217 user_roles.append([role_name, role['scope']])
218 LOG.info("User %s has roles: %s", user_name, user_roles)
219
Jude Cross986e3f52017-07-24 14:57:20 -0700220 @classmethod
Gregory Thiemongecba3b222024-05-16 02:57:08 -0400221 def clear_credentials(cls):
222 for user_id in cls._created_users:
223 cls.os_admin.users_v3_client.delete_user(user_id)
224 for project_id in cls._created_projects:
225 cls.os_admin.projects_client.delete_project(project_id)
226 for role_id in cls._created_roles:
227 cls.os_admin.roles_v3_client.delete_role(role_id)
228 super().clear_credentials()
229
230 @classmethod
Jude Cross986e3f52017-07-24 14:57:20 -0700231 def setup_clients(cls):
232 """Setup client aliases."""
233 super(LoadBalancerBaseTest, cls).setup_clients()
Michael Johnson29d8e612021-06-23 16:16:12 +0000234 lb_admin_prefix = cls.os_roles_lb_admin.load_balancer_v2
Jude Cross986e3f52017-07-24 14:57:20 -0700235 cls.lb_mem_float_ip_client = cls.os_roles_lb_member.floating_ips_client
236 cls.lb_mem_keypairs_client = cls.os_roles_lb_member.keypairs_client
237 cls.lb_mem_net_client = cls.os_roles_lb_member.networks_client
238 cls.lb_mem_ports_client = cls.os_roles_lb_member.ports_client
239 cls.lb_mem_routers_client = cls.os_roles_lb_member.routers_client
240 cls.lb_mem_SG_client = cls.os_roles_lb_member.security_groups_client
241 cls.lb_mem_SGr_client = (
242 cls.os_roles_lb_member.security_group_rules_client)
243 cls.lb_mem_servers_client = cls.os_roles_lb_member.servers_client
244 cls.lb_mem_subnet_client = cls.os_roles_lb_member.subnets_client
Tom Weiningerc03e9c32024-04-23 14:07:04 +0200245 cls.mem_lb_client: lbv2.LoadbalancerClient = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000246 cls.os_roles_lb_member.load_balancer_v2.LoadbalancerClient())
Tom Weiningerc03e9c32024-04-23 14:07:04 +0200247 cls.mem_listener_client: lbv2.ListenerClient = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000248 cls.os_roles_lb_member.load_balancer_v2.ListenerClient())
Tom Weiningerc03e9c32024-04-23 14:07:04 +0200249 cls.mem_pool_client: lbv2.PoolClient = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000250 cls.os_roles_lb_member.load_balancer_v2.PoolClient())
Tom Weiningerc03e9c32024-04-23 14:07:04 +0200251 cls.mem_member_client: lbv2.MemberClient = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000252 cls.os_roles_lb_member.load_balancer_v2.MemberClient())
Tom Weiningerc03e9c32024-04-23 14:07:04 +0200253 cls.mem_healthmonitor_client: lbv2.HealthMonitorClient = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000254 cls.os_roles_lb_member.load_balancer_v2.HealthMonitorClient())
Tom Weiningerc03e9c32024-04-23 14:07:04 +0200255 cls.mem_l7policy_client: lbv2.L7PolicyClient = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000256 cls.os_roles_lb_member.load_balancer_v2.L7PolicyClient())
Tom Weiningerc03e9c32024-04-23 14:07:04 +0200257 cls.mem_l7rule_client: lbv2.L7RuleClient = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000258 cls.os_roles_lb_member.load_balancer_v2.L7RuleClient())
Tom Weiningerc03e9c32024-04-23 14:07:04 +0200259 cls.lb_admin_amphora_client: lbv2.AmphoraClient = (
260 lb_admin_prefix.AmphoraClient())
261 cls.lb_admin_flavor_profile_client: lbv2.FlavorProfileClient = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000262 lb_admin_prefix.FlavorProfileClient())
Tom Weiningerc03e9c32024-04-23 14:07:04 +0200263 cls.lb_admin_flavor_client: lbv2.FlavorClient = (
264 lb_admin_prefix.FlavorClient())
265 cls.mem_flavor_client: lbv2.FlavorClient = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000266 cls.os_roles_lb_member.load_balancer_v2.FlavorClient())
Tom Weiningerc03e9c32024-04-23 14:07:04 +0200267 cls.mem_provider_client: lbv2.ProviderClient = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000268 cls.os_roles_lb_member.load_balancer_v2.ProviderClient())
Carlos Goncalvesc2e12162019-02-14 23:57:44 +0100269 cls.os_admin_servers_client = cls.os_admin.servers_client
Gregory Thiemonge54225ad2021-02-04 15:25:17 +0100270 cls.os_admin_routers_client = cls.os_admin.routers_client
271 cls.os_admin_subnetpools_client = cls.os_admin.subnetpools_client
Adam Harwellc2aa20c2019-11-20 11:15:07 -0800272 cls.lb_admin_flavor_capabilities_client = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000273 lb_admin_prefix.FlavorCapabilitiesClient())
Adam Harwellc2aa20c2019-11-20 11:15:07 -0800274 cls.lb_admin_availability_zone_capabilities_client = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000275 lb_admin_prefix.AvailabilityZoneCapabilitiesClient())
Adam Harwellc2aa20c2019-11-20 11:15:07 -0800276 cls.lb_admin_availability_zone_profile_client = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000277 lb_admin_prefix.AvailabilityZoneProfileClient())
Adam Harwellc2aa20c2019-11-20 11:15:07 -0800278 cls.lb_admin_availability_zone_client = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000279 lb_admin_prefix.AvailabilityZoneClient())
Adam Harwellc2aa20c2019-11-20 11:15:07 -0800280 cls.mem_availability_zone_client = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000281 cls.os_roles_lb_member.load_balancer_v2.AvailabilityZoneClient())
Gregory Thiemonge5010dc02021-02-02 14:59:27 +0100282 cls.os_admin_compute_flavors_client = cls.os_admin.flavors_client
Jude Cross986e3f52017-07-24 14:57:20 -0700283
284 @classmethod
285 def resource_setup(cls):
286 """Setup resources needed by the tests."""
287 super(LoadBalancerBaseTest, cls).resource_setup()
288
289 conf_lb = CONF.load_balancer
290
Michael Johnsondfd818a2018-08-21 20:54:54 -0700291 cls.api_version = cls.mem_lb_client.get_max_api_version()
292
Jude Cross986e3f52017-07-24 14:57:20 -0700293 if conf_lb.test_subnet_override and not conf_lb.test_network_override:
294 raise exceptions.InvalidConfiguration(
295 "Configuration value test_network_override must be "
296 "specified if test_subnet_override is used.")
297
Michael Johnson6a9236a2020-08-04 23:54:54 +0000298 # TODO(johnsom) Remove this
Maciej Józefczykb6df5f82019-12-10 10:12:30 +0000299 # Get loadbalancing algorithms supported by provider driver.
300 try:
301 algorithms = const.SUPPORTED_LB_ALGORITHMS[
302 CONF.load_balancer.provider]
303 except KeyError:
304 algorithms = const.SUPPORTED_LB_ALGORITHMS['default']
305 # Set default algorithm as first from the list.
306 cls.lb_algorithm = algorithms[0]
307
Jude Cross986e3f52017-07-24 14:57:20 -0700308 show_subnet = cls.lb_mem_subnet_client.show_subnet
309 if CONF.load_balancer.test_with_noop:
310 cls.lb_member_vip_net = {'id': uuidutils.generate_uuid()}
311 cls.lb_member_vip_subnet = {'id': uuidutils.generate_uuid()}
312 cls.lb_member_1_net = {'id': uuidutils.generate_uuid()}
313 cls.lb_member_1_subnet = {'id': uuidutils.generate_uuid()}
314 cls.lb_member_2_net = {'id': uuidutils.generate_uuid()}
315 cls.lb_member_2_subnet = {'id': uuidutils.generate_uuid()}
316 if CONF.load_balancer.test_with_ipv6:
Michael Johnson5a16ad32018-10-18 14:49:11 -0700317 cls.lb_member_vip_ipv6_net = {'id': uuidutils.generate_uuid()}
Jude Cross986e3f52017-07-24 14:57:20 -0700318 cls.lb_member_vip_ipv6_subnet = {'id':
319 uuidutils.generate_uuid()}
320 cls.lb_member_1_ipv6_subnet = {'id': uuidutils.generate_uuid()}
321 cls.lb_member_2_ipv6_subnet = {'id': uuidutils.generate_uuid()}
Michael Johnson590fbe12019-07-03 14:30:01 -0700322 cls.lb_member_vip_ipv6_subnet_stateful = True
Jude Cross986e3f52017-07-24 14:57:20 -0700323 return
324 elif CONF.load_balancer.test_network_override:
325 if conf_lb.test_subnet_override:
326 override_subnet = show_subnet(conf_lb.test_subnet_override)
327 else:
328 override_subnet = None
329
330 show_net = cls.lb_mem_net_client.show_network
331 override_network = show_net(conf_lb.test_network_override)
332 override_network = override_network.get('network')
333
334 cls.lb_member_vip_net = override_network
335 cls.lb_member_vip_subnet = override_subnet
336 cls.lb_member_1_net = override_network
337 cls.lb_member_1_subnet = override_subnet
338 cls.lb_member_2_net = override_network
339 cls.lb_member_2_subnet = override_subnet
340
341 if (CONF.load_balancer.test_with_ipv6 and
Michael Polenchuke1f3ed52022-01-18 15:44:56 +0400342 conf_lb.test_ipv6_subnet_override):
Jude Cross986e3f52017-07-24 14:57:20 -0700343 override_ipv6_subnet = show_subnet(
Michael Polenchuke1f3ed52022-01-18 15:44:56 +0400344 conf_lb.test_ipv6_subnet_override)
Jude Cross986e3f52017-07-24 14:57:20 -0700345 cls.lb_member_vip_ipv6_subnet = override_ipv6_subnet
346 cls.lb_member_1_ipv6_subnet = override_ipv6_subnet
347 cls.lb_member_2_ipv6_subnet = override_ipv6_subnet
Michael Johnson590fbe12019-07-03 14:30:01 -0700348 cls.lb_member_vip_ipv6_subnet_stateful = False
349 if (override_ipv6_subnet[0]['ipv6_address_mode'] ==
350 'dhcpv6-stateful'):
351 cls.lb_member_vip_ipv6_subnet_stateful = True
Jude Cross986e3f52017-07-24 14:57:20 -0700352 else:
353 cls.lb_member_vip_ipv6_subnet = None
354 cls.lb_member_1_ipv6_subnet = None
355 cls.lb_member_2_ipv6_subnet = None
356 else:
357 cls._create_networks()
358
Michael Johnson77b8bae2024-11-08 01:39:29 +0000359 LOG.debug('Octavia Setup: lb_member_vip_net = %s',
360 cls.lb_member_vip_net[const.ID])
Jude Cross986e3f52017-07-24 14:57:20 -0700361 if cls.lb_member_vip_subnet:
Michael Johnson77b8bae2024-11-08 01:39:29 +0000362 LOG.debug('Octavia Setup: lb_member_vip_subnet = %s',
363 cls.lb_member_vip_subnet[const.ID])
364 LOG.debug('Octavia Setup: lb_member_1_net = %s',
365 cls.lb_member_1_net[const.ID])
Jude Cross986e3f52017-07-24 14:57:20 -0700366 if cls.lb_member_1_subnet:
Michael Johnson77b8bae2024-11-08 01:39:29 +0000367 LOG.debug('Octavia Setup: lb_member_1_subnet = %s',
368 cls.lb_member_1_subnet[const.ID])
369 LOG.debug('Octavia Setup: lb_member_2_net = %s',
370 cls.lb_member_2_net[const.ID])
Jude Cross986e3f52017-07-24 14:57:20 -0700371 if cls.lb_member_2_subnet:
Michael Johnson77b8bae2024-11-08 01:39:29 +0000372 LOG.debug('Octavia Setup: lb_member_2_subnet = %s',
373 cls.lb_member_2_subnet[const.ID])
Michael Johnson124ba8b2018-08-30 16:06:05 -0700374 if CONF.load_balancer.test_with_ipv6:
375 if cls.lb_member_vip_ipv6_subnet:
Michael Johnson77b8bae2024-11-08 01:39:29 +0000376 LOG.debug('Octavia Setup: lb_member_vip_ipv6_subnet = %s',
377 cls.lb_member_vip_ipv6_subnet[const.ID])
Michael Johnson124ba8b2018-08-30 16:06:05 -0700378 if cls.lb_member_1_ipv6_subnet:
Michael Johnson77b8bae2024-11-08 01:39:29 +0000379 LOG.debug('Octavia Setup: lb_member_1_ipv6_subnet = %s',
380 cls.lb_member_1_ipv6_subnet[const.ID])
Michael Johnson124ba8b2018-08-30 16:06:05 -0700381 if cls.lb_member_2_ipv6_subnet:
Michael Johnson77b8bae2024-11-08 01:39:29 +0000382 LOG.debug('Octavia Setup: lb_member_2_ipv6_subnet = %s',
383 cls.lb_member_2_ipv6_subnet[const.ID])
Jude Cross986e3f52017-07-24 14:57:20 -0700384
Jude Cross986e3f52017-07-24 14:57:20 -0700385 @classmethod
Michael Johnson04dc5cb2019-01-20 11:03:50 -0800386 # Neutron can be slow to clean up ports from the subnets/networks.
387 # Retry this delete a few times if we get a "Conflict" error to give
388 # neutron time to fully cleanup the ports.
389 @tenacity.retry(
390 retry=tenacity.retry_if_exception_type(exceptions.Conflict),
391 wait=tenacity.wait_incrementing(
Vasyl Saienko08f25652021-05-12 16:30:26 +0300392 const.RETRY_INITIAL_DELAY, const.RETRY_BACKOFF, const.RETRY_MAX),
393 stop=tenacity.stop_after_attempt(const.RETRY_ATTEMPTS))
Michael Johnson04dc5cb2019-01-20 11:03:50 -0800394 def _logging_delete_network(cls, net_id):
395 try:
396 cls.lb_mem_net_client.delete_network(net_id)
397 except Exception:
Michael Johnson77b8bae2024-11-08 01:39:29 +0000398 LOG.error('Unable to delete network %s. Active ports:', net_id)
Michael Johnson04dc5cb2019-01-20 11:03:50 -0800399 LOG.error(cls.lb_mem_ports_client.list_ports())
400 raise
401
402 @classmethod
403 # Neutron can be slow to clean up ports from the subnets/networks.
404 # Retry this delete a few times if we get a "Conflict" error to give
405 # neutron time to fully cleanup the ports.
406 @tenacity.retry(
407 retry=tenacity.retry_if_exception_type(exceptions.Conflict),
408 wait=tenacity.wait_incrementing(
Vasyl Saienko08f25652021-05-12 16:30:26 +0300409 const.RETRY_INITIAL_DELAY, const.RETRY_BACKOFF, const.RETRY_MAX),
410 stop=tenacity.stop_after_attempt(const.RETRY_ATTEMPTS))
Michael Johnson04dc5cb2019-01-20 11:03:50 -0800411 def _logging_delete_subnet(cls, subnet_id):
412 try:
413 cls.lb_mem_subnet_client.delete_subnet(subnet_id)
414 except Exception:
Michael Johnson77b8bae2024-11-08 01:39:29 +0000415 LOG.error('Unable to delete subnet %s. Active ports:', subnet_id)
Michael Johnson04dc5cb2019-01-20 11:03:50 -0800416 LOG.error(cls.lb_mem_ports_client.list_ports())
417 raise
418
419 @classmethod
Jude Cross986e3f52017-07-24 14:57:20 -0700420 def _create_networks(cls):
421 """Creates networks, subnets, and routers used in tests.
422
423 The following are expected to be defined and available to the tests:
424 cls.lb_member_vip_net
425 cls.lb_member_vip_subnet
426 cls.lb_member_vip_ipv6_subnet (optional)
427 cls.lb_member_1_net
428 cls.lb_member_1_subnet
429 cls.lb_member_1_ipv6_subnet (optional)
430 cls.lb_member_2_net
431 cls.lb_member_2_subnet
432 cls.lb_member_2_ipv6_subnet (optional)
433 """
434
435 # Create tenant VIP network
436 network_kwargs = {
437 'name': data_utils.rand_name("lb_member_vip_network")}
438 if CONF.network_feature_enabled.port_security:
Andreas Jaeger4215b702020-03-28 20:13:46 +0100439 # Note: Allowed Address Pairs requires port security
440 network_kwargs['port_security_enabled'] = True
Jude Cross986e3f52017-07-24 14:57:20 -0700441 result = cls.lb_mem_net_client.create_network(**network_kwargs)
442 cls.lb_member_vip_net = result['network']
Michael Johnson77b8bae2024-11-08 01:39:29 +0000443 LOG.info('lb_member_vip_net: %s', cls.lb_member_vip_net)
Jude Cross986e3f52017-07-24 14:57:20 -0700444 cls.addClassResourceCleanup(
445 waiters.wait_for_not_found,
Michael Johnson04dc5cb2019-01-20 11:03:50 -0800446 cls._logging_delete_network,
Jude Cross986e3f52017-07-24 14:57:20 -0700447 cls.lb_mem_net_client.show_network,
448 cls.lb_member_vip_net['id'])
449
rbubyr6978e022025-03-18 14:58:39 +0100450 # Add allocation pool to prevent IP address conflicts with portprober
451 cidr = netaddr.IPNetwork(CONF.load_balancer.vip_subnet_cidr)
452 pool_start = ipaddress.ip_address(str(cidr[101]))
453 pool_end = ipaddress.ip_address(str(cidr[254]))
454 allocation_pools = [{'start': str(pool_start), 'end': str(pool_end)}]
455
Jude Cross986e3f52017-07-24 14:57:20 -0700456 # Create tenant VIP subnet
457 subnet_kwargs = {
458 'name': data_utils.rand_name("lb_member_vip_subnet"),
459 'network_id': cls.lb_member_vip_net['id'],
460 'cidr': CONF.load_balancer.vip_subnet_cidr,
rbubyr6978e022025-03-18 14:58:39 +0100461 'ip_version': 4,
462 'allocation_pools': allocation_pools
463 }
Jude Cross986e3f52017-07-24 14:57:20 -0700464 result = cls.lb_mem_subnet_client.create_subnet(**subnet_kwargs)
465 cls.lb_member_vip_subnet = result['subnet']
Michael Johnson77b8bae2024-11-08 01:39:29 +0000466 LOG.info('lb_member_vip_subnet: %s', cls.lb_member_vip_subnet)
Jude Cross986e3f52017-07-24 14:57:20 -0700467 cls.addClassResourceCleanup(
468 waiters.wait_for_not_found,
Michael Johnson04dc5cb2019-01-20 11:03:50 -0800469 cls._logging_delete_subnet,
Jude Cross986e3f52017-07-24 14:57:20 -0700470 cls.lb_mem_subnet_client.show_subnet,
471 cls.lb_member_vip_subnet['id'])
472
473 # Create tenant VIP IPv6 subnet
474 if CONF.load_balancer.test_with_ipv6:
Michael Johnson590fbe12019-07-03 14:30:01 -0700475 cls.lb_member_vip_ipv6_subnet_stateful = False
Gregory Thiemonge54225ad2021-02-04 15:25:17 +0100476 cls.lb_member_vip_ipv6_subnet_use_subnetpool = False
477 subnet_kwargs = {
478 'name': data_utils.rand_name("lb_member_vip_ipv6_subnet"),
479 'network_id': cls.lb_member_vip_net['id'],
480 'ip_version': 6}
481
482 # Use a CIDR from devstack's default IPv6 subnetpool if it exists,
483 # the subnetpool's cidr is routable from the devstack node
484 # through the default router
485 subnetpool_name = CONF.load_balancer.default_ipv6_subnetpool
486 if subnetpool_name:
487 subnetpool = cls.os_admin_subnetpools_client.list_subnetpools(
488 name=subnetpool_name)['subnetpools']
489 if len(subnetpool) == 1:
490 subnetpool = subnetpool[0]
491 subnet_kwargs['subnetpool_id'] = subnetpool['id']
492 cls.lb_member_vip_ipv6_subnet_use_subnetpool = True
493
494 if 'subnetpool_id' not in subnet_kwargs:
495 subnet_kwargs['cidr'] = (
496 CONF.load_balancer.vip_ipv6_subnet_cidr)
497
498 result = cls.lb_mem_subnet_client.create_subnet(
499 **subnet_kwargs)
500 cls.lb_member_vip_ipv6_net = cls.lb_member_vip_net
501 cls.lb_member_vip_ipv6_subnet = result['subnet']
502 cls.addClassResourceCleanup(
503 waiters.wait_for_not_found,
504 cls._logging_delete_subnet,
505 cls.lb_mem_subnet_client.show_subnet,
506 cls.lb_member_vip_ipv6_subnet['id'])
Carlos Goncalves84af48c2019-07-25 15:51:30 +0200507
Michael Johnson77b8bae2024-11-08 01:39:29 +0000508 LOG.info('lb_member_vip_ipv6_subnet: %s',
509 cls.lb_member_vip_ipv6_subnet)
Jude Cross986e3f52017-07-24 14:57:20 -0700510
511 # Create tenant member 1 network
512 network_kwargs = {
513 'name': data_utils.rand_name("lb_member_1_network")}
514 if CONF.network_feature_enabled.port_security:
515 if CONF.load_balancer.enable_security_groups:
516 network_kwargs['port_security_enabled'] = True
517 else:
518 network_kwargs['port_security_enabled'] = False
519 result = cls.lb_mem_net_client.create_network(**network_kwargs)
520 cls.lb_member_1_net = result['network']
Michael Johnson77b8bae2024-11-08 01:39:29 +0000521 LOG.info('lb_member_1_net: %s', cls.lb_member_1_net)
Jude Cross986e3f52017-07-24 14:57:20 -0700522 cls.addClassResourceCleanup(
523 waiters.wait_for_not_found,
Michael Johnson04dc5cb2019-01-20 11:03:50 -0800524 cls._logging_delete_network,
Jude Cross986e3f52017-07-24 14:57:20 -0700525 cls.lb_mem_net_client.show_network,
526 cls.lb_member_1_net['id'])
527
528 # Create tenant member 1 subnet
529 subnet_kwargs = {
530 'name': data_utils.rand_name("lb_member_1_subnet"),
531 'network_id': cls.lb_member_1_net['id'],
532 'cidr': CONF.load_balancer.member_1_ipv4_subnet_cidr,
533 'ip_version': 4}
534 result = cls.lb_mem_subnet_client.create_subnet(**subnet_kwargs)
535 cls.lb_member_1_subnet = result['subnet']
Michael Johnson77b8bae2024-11-08 01:39:29 +0000536 LOG.info('lb_member_1_subnet: %s', cls.lb_member_1_subnet)
Jude Cross986e3f52017-07-24 14:57:20 -0700537 cls.addClassResourceCleanup(
538 waiters.wait_for_not_found,
Michael Johnson04dc5cb2019-01-20 11:03:50 -0800539 cls._logging_delete_subnet,
Jude Cross986e3f52017-07-24 14:57:20 -0700540 cls.lb_mem_subnet_client.show_subnet,
541 cls.lb_member_1_subnet['id'])
542
543 # Create tenant member 1 ipv6 subnet
544 if CONF.load_balancer.test_with_ipv6:
545 subnet_kwargs = {
546 'name': data_utils.rand_name("lb_member_1_ipv6_subnet"),
547 'network_id': cls.lb_member_1_net['id'],
548 'cidr': CONF.load_balancer.member_1_ipv6_subnet_cidr,
549 'ip_version': 6}
550 result = cls.lb_mem_subnet_client.create_subnet(**subnet_kwargs)
Michael Johnsonbf916df2018-10-17 10:59:28 -0700551 cls.lb_member_1_subnet_prefix = (
552 CONF.load_balancer.member_1_ipv6_subnet_cidr.rpartition('/')[2]
553 )
Michael Johnson77b8bae2024-11-08 01:39:29 +0000554 assert (cls.lb_member_1_subnet_prefix.isdigit())
Jude Cross986e3f52017-07-24 14:57:20 -0700555 cls.lb_member_1_ipv6_subnet = result['subnet']
Michael Johnson77b8bae2024-11-08 01:39:29 +0000556 LOG.info('lb_member_1_ipv6_subnet: %s',
557 cls.lb_member_1_ipv6_subnet)
Jude Cross986e3f52017-07-24 14:57:20 -0700558 cls.addClassResourceCleanup(
559 waiters.wait_for_not_found,
Michael Johnson04dc5cb2019-01-20 11:03:50 -0800560 cls._logging_delete_subnet,
Jude Cross986e3f52017-07-24 14:57:20 -0700561 cls.lb_mem_subnet_client.show_subnet,
562 cls.lb_member_1_ipv6_subnet['id'])
563
564 # Create tenant member 2 network
565 network_kwargs = {
566 'name': data_utils.rand_name("lb_member_2_network")}
567 if CONF.network_feature_enabled.port_security:
568 if CONF.load_balancer.enable_security_groups:
569 network_kwargs['port_security_enabled'] = True
570 else:
571 network_kwargs['port_security_enabled'] = False
572 result = cls.lb_mem_net_client.create_network(**network_kwargs)
573 cls.lb_member_2_net = result['network']
Michael Johnson77b8bae2024-11-08 01:39:29 +0000574 LOG.info('lb_member_2_net: %s', cls.lb_member_2_net)
Jude Cross986e3f52017-07-24 14:57:20 -0700575 cls.addClassResourceCleanup(
576 waiters.wait_for_not_found,
Michael Johnson04dc5cb2019-01-20 11:03:50 -0800577 cls._logging_delete_network,
Jude Cross986e3f52017-07-24 14:57:20 -0700578 cls.lb_mem_net_client.show_network,
579 cls.lb_member_2_net['id'])
580
581 # Create tenant member 2 subnet
582 subnet_kwargs = {
583 'name': data_utils.rand_name("lb_member_2_subnet"),
584 'network_id': cls.lb_member_2_net['id'],
585 'cidr': CONF.load_balancer.member_2_ipv4_subnet_cidr,
586 'ip_version': 4}
587 result = cls.lb_mem_subnet_client.create_subnet(**subnet_kwargs)
588 cls.lb_member_2_subnet = result['subnet']
Michael Johnson77b8bae2024-11-08 01:39:29 +0000589 LOG.info('lb_member_2_subnet: %s', cls.lb_member_2_subnet)
Jude Cross986e3f52017-07-24 14:57:20 -0700590 cls.addClassResourceCleanup(
591 waiters.wait_for_not_found,
Michael Johnson04dc5cb2019-01-20 11:03:50 -0800592 cls._logging_delete_subnet,
Jude Cross986e3f52017-07-24 14:57:20 -0700593 cls.lb_mem_subnet_client.show_subnet,
594 cls.lb_member_2_subnet['id'])
595
596 # Create tenant member 2 ipv6 subnet
597 if CONF.load_balancer.test_with_ipv6:
598 subnet_kwargs = {
599 'name': data_utils.rand_name("lb_member_2_ipv6_subnet"),
600 'network_id': cls.lb_member_2_net['id'],
601 'cidr': CONF.load_balancer.member_2_ipv6_subnet_cidr,
602 'ip_version': 6}
603 result = cls.lb_mem_subnet_client.create_subnet(**subnet_kwargs)
Michael Johnsonbf916df2018-10-17 10:59:28 -0700604 cls.lb_member_2_subnet_prefix = (
605 CONF.load_balancer.member_2_ipv6_subnet_cidr.rpartition('/')[2]
606 )
Michael Johnson77b8bae2024-11-08 01:39:29 +0000607 assert (cls.lb_member_2_subnet_prefix.isdigit())
Jude Cross986e3f52017-07-24 14:57:20 -0700608 cls.lb_member_2_ipv6_subnet = result['subnet']
Michael Johnson77b8bae2024-11-08 01:39:29 +0000609 LOG.info('lb_member_2_ipv6_subnet: %s',
610 cls.lb_member_2_ipv6_subnet)
Jude Cross986e3f52017-07-24 14:57:20 -0700611 cls.addClassResourceCleanup(
612 waiters.wait_for_not_found,
Michael Johnson04dc5cb2019-01-20 11:03:50 -0800613 cls._logging_delete_subnet,
Jude Cross986e3f52017-07-24 14:57:20 -0700614 cls.lb_mem_subnet_client.show_subnet,
615 cls.lb_member_2_ipv6_subnet['id'])
616
Adam Harwellcd72b562018-05-07 11:37:22 -0700617 @classmethod
Michael Johnson07c9a632018-06-07 13:27:42 -0700618 def _setup_lb_network_kwargs(cls, lb_kwargs, ip_version=None,
619 use_fixed_ip=False):
Adam Harwell60ed9d92018-05-10 13:23:13 -0700620 if not ip_version:
621 ip_version = 6 if CONF.load_balancer.test_with_ipv6 else 4
Michael Johnson5a16ad32018-10-18 14:49:11 -0700622 if cls.lb_member_vip_subnet or cls.lb_member_vip_ipv6_subnet:
Adam Harwellcd72b562018-05-07 11:37:22 -0700623 ip_index = data_utils.rand_int_id(start=10, end=100)
Michael Johnsondfd818a2018-08-21 20:54:54 -0700624 while ip_index in cls.used_ips:
625 ip_index = data_utils.rand_int_id(start=10, end=100)
626 cls.used_ips.append(ip_index)
Adam Harwellcd72b562018-05-07 11:37:22 -0700627 if ip_version == 4:
Adam Harwellcd72b562018-05-07 11:37:22 -0700628 subnet_id = cls.lb_member_vip_subnet[const.ID]
Michael Johnson5a16ad32018-10-18 14:49:11 -0700629 if CONF.load_balancer.test_with_noop:
630 lb_vip_address = '198.18.33.33'
631 else:
632 subnet = cls.os_admin.subnets_client.show_subnet(subnet_id)
633 network = ipaddress.IPv4Network(subnet['subnet']['cidr'])
634 lb_vip_address = str(network[ip_index])
Adam Harwellcd72b562018-05-07 11:37:22 -0700635 else:
Adam Harwellcd72b562018-05-07 11:37:22 -0700636 subnet_id = cls.lb_member_vip_ipv6_subnet[const.ID]
Michael Johnson5a16ad32018-10-18 14:49:11 -0700637 if CONF.load_balancer.test_with_noop:
638 lb_vip_address = '2001:db8:33:33:33:33:33:33'
639 else:
640 subnet = cls.os_admin.subnets_client.show_subnet(subnet_id)
641 network = ipaddress.IPv6Network(subnet['subnet']['cidr'])
642 lb_vip_address = str(network[ip_index])
Michael Johnson590fbe12019-07-03 14:30:01 -0700643 # If the subnet is IPv6 slaac or dhcpv6-stateless
644 # neutron does not allow a fixed IP
645 if not cls.lb_member_vip_ipv6_subnet_stateful:
646 use_fixed_ip = False
Adam Harwellcd72b562018-05-07 11:37:22 -0700647 lb_kwargs[const.VIP_SUBNET_ID] = subnet_id
Michael Johnson07c9a632018-06-07 13:27:42 -0700648 if use_fixed_ip:
649 lb_kwargs[const.VIP_ADDRESS] = lb_vip_address
Adam Harwellcd72b562018-05-07 11:37:22 -0700650 if CONF.load_balancer.test_with_noop:
651 lb_kwargs[const.VIP_NETWORK_ID] = (
652 cls.lb_member_vip_net[const.ID])
Carlos Goncalvesbb238552020-01-15 10:10:55 +0000653 if ip_version == 6:
654 lb_kwargs[const.VIP_ADDRESS] = lb_vip_address
Adam Harwellcd72b562018-05-07 11:37:22 -0700655 else:
656 lb_kwargs[const.VIP_NETWORK_ID] = cls.lb_member_vip_net[const.ID]
657 lb_kwargs[const.VIP_SUBNET_ID] = None
658
Gregory Thiemongeece5ab42020-10-29 08:46:05 +0100659 def _validate_listener_protocol(self, protocol, raise_if_unsupported=True):
660 if (protocol == const.SCTP and
661 not self.mem_listener_client.is_version_supported(
662 self.api_version, '2.23')):
663 if raise_if_unsupported:
664 raise self.skipException('SCTP listener protocol '
665 'is only available on Octavia '
666 'API version 2.23 or newer.')
667 return False
Gleb Zimin8dd3b782024-10-07 12:10:00 +0200668 if CONF.load_balancer.provider == 'tungstenfabric':
669 self.check_tf_compatibility(protocol=protocol)
Gregory Thiemongeece5ab42020-10-29 08:46:05 +0100670 return True
671
ibumarskovd17e3da2020-09-03 18:21:29 +0400672 @classmethod
673 def check_tf_compatibility(cls, protocol=None, algorithm=None):
674 # TungstenFabric supported protocols and algorithms
Ilya Bumarskov62a136d2021-02-03 16:16:42 +0400675 tf_protocols = [const.HTTP, const.HTTPS, const.TCP,
ibumarskovd17e3da2020-09-03 18:21:29 +0400676 const.TERMINATED_HTTPS]
677 tf_algorithms = [const.LB_ALGORITHM_ROUND_ROBIN,
678 const.LB_ALGORITHM_LEAST_CONNECTIONS,
679 const.LB_ALGORITHM_SOURCE_IP]
680
681 if algorithm and algorithm not in tf_algorithms:
682 raise cls.skipException(
683 'TungstenFabric does not support {} algorithm.'
684 ''.format(algorithm))
685 if protocol and protocol not in tf_protocols:
686 raise cls.skipException(
687 'TungstenFabric does not support {} protocol.'
688 ''.format(protocol))
689
690 @classmethod
691 def _tf_create_listener(cls, name, proto, port, lb_id):
692 listener_kwargs = {
693 const.NAME: name,
694 const.PROTOCOL: proto,
695 const.PROTOCOL_PORT: port,
696 const.LOADBALANCER_ID: lb_id,
697 }
698 listener = cls.mem_listener_client.create_listener(**listener_kwargs)
699 return listener
700
701 @classmethod
702 def _tf_get_free_port(cls, lb_id):
703 port = 8081
704 lb = cls.mem_lb_client.show_loadbalancer(lb_id)
705 listeners = lb[const.LISTENERS]
706 if not listeners:
707 return port
708 ports = [cls.mem_listener_client.show_listener(x[const.ID])[
709 const.PROTOCOL_PORT] for x in listeners]
710 while port in ports:
711 port = port + 1
712 return port
713
Adam Harwellcd72b562018-05-07 11:37:22 -0700714
715class LoadBalancerBaseTestWithCompute(LoadBalancerBaseTest):
716 @classmethod
Gregory Thiemongeb0da4f32022-02-04 08:58:06 +0100717 def remote_client_args(cls):
718 # In case we're using octavia-tempest-plugin with old tempest releases
719 # (for instance on stable/train) that don't support ssh_key_type, catch
720 # the exception and don't pass any argument
721 args = {}
722 try:
723 args['ssh_key_type'] = CONF.validation.ssh_key_type
724 except cfg.NoSuchOptError:
725 pass
726 return args
727
728 @classmethod
Adam Harwellcd72b562018-05-07 11:37:22 -0700729 def resource_setup(cls):
730 super(LoadBalancerBaseTestWithCompute, cls).resource_setup()
731 # If validation is disabled in this cloud, we won't be able to
732 # start the webservers, so don't even boot them.
733 if not CONF.validation.run_validation:
734 return
735
736 # Create a keypair for the webservers
737 keypair_name = data_utils.rand_name('lb_member_keypair')
738 result = cls.lb_mem_keypairs_client.create_keypair(
739 name=keypair_name)
740 cls.lb_member_keypair = result['keypair']
Michael Johnson77b8bae2024-11-08 01:39:29 +0000741 LOG.info('lb_member_keypair: %s', cls.lb_member_keypair)
Adam Harwellcd72b562018-05-07 11:37:22 -0700742 cls.addClassResourceCleanup(
743 waiters.wait_for_not_found,
744 cls.lb_mem_keypairs_client.delete_keypair,
745 cls.lb_mem_keypairs_client.show_keypair,
746 keypair_name)
747
748 if (CONF.load_balancer.enable_security_groups and
749 CONF.network_feature_enabled.port_security):
750 # Set up the security group for the webservers
751 SG_name = data_utils.rand_name('lb_member_SG')
752 cls.lb_member_sec_group = (
753 cls.lb_mem_SG_client.create_security_group(
754 name=SG_name)['security_group'])
755 cls.addClassResourceCleanup(
756 waiters.wait_for_not_found,
757 cls.lb_mem_SG_client.delete_security_group,
758 cls.lb_mem_SG_client.show_security_group,
759 cls.lb_member_sec_group['id'])
760
761 # Create a security group rule to allow 80-81 (test webservers)
762 SGr = cls.lb_mem_SGr_client.create_security_group_rule(
763 direction='ingress',
764 security_group_id=cls.lb_member_sec_group['id'],
765 protocol='tcp',
766 ethertype='IPv4',
767 port_range_min=80,
768 port_range_max=81)['security_group_rule']
769 cls.addClassResourceCleanup(
770 waiters.wait_for_not_found,
771 cls.lb_mem_SGr_client.delete_security_group_rule,
772 cls.lb_mem_SGr_client.show_security_group_rule,
773 SGr['id'])
Gregory Thiemonge29d17902019-04-30 15:06:17 +0200774 # Create a security group rule to allow UDP 80-81 (test webservers)
775 SGr = cls.lb_mem_SGr_client.create_security_group_rule(
776 direction='ingress',
777 security_group_id=cls.lb_member_sec_group['id'],
778 protocol='udp',
779 ethertype='IPv4',
780 port_range_min=80,
781 port_range_max=81)['security_group_rule']
782 cls.addClassResourceCleanup(
783 waiters.wait_for_not_found,
784 cls.lb_mem_SGr_client.delete_security_group_rule,
785 cls.lb_mem_SGr_client.show_security_group_rule,
786 SGr['id'])
Michael Johnson74b6f2f2020-10-29 15:11:39 -0700787 # Create a security group rule to allow 443 (test webservers)
788 SGr = cls.lb_mem_SGr_client.create_security_group_rule(
789 direction='ingress',
790 security_group_id=cls.lb_member_sec_group['id'],
791 protocol='tcp',
792 ethertype='IPv4',
793 port_range_min=443,
794 port_range_max=443)['security_group_rule']
795 cls.addClassResourceCleanup(
796 waiters.wait_for_not_found,
797 cls.lb_mem_SGr_client.delete_security_group_rule,
798 cls.lb_mem_SGr_client.show_security_group_rule,
799 SGr['id'])
Michael Johnson031ecca2020-10-29 16:45:32 -0700800 # Create a security group rule to allow 9443 (test webservers)
801 # Used in the pool backend encryption client authentication tests
802 SGr = cls.lb_mem_SGr_client.create_security_group_rule(
803 direction='ingress',
804 security_group_id=cls.lb_member_sec_group['id'],
805 protocol='tcp',
806 ethertype='IPv4',
807 port_range_min=9443,
808 port_range_max=9443)['security_group_rule']
809 cls.addClassResourceCleanup(
810 waiters.wait_for_not_found,
811 cls.lb_mem_SGr_client.delete_security_group_rule,
812 cls.lb_mem_SGr_client.show_security_group_rule,
813 SGr['id'])
Gregory Thiemonge29d17902019-04-30 15:06:17 +0200814 # Create a security group rule to allow UDP 9999 (test webservers)
815 # Port 9999 is used to illustrate health monitor ERRORs on closed
816 # ports.
817 SGr = cls.lb_mem_SGr_client.create_security_group_rule(
818 direction='ingress',
819 security_group_id=cls.lb_member_sec_group['id'],
820 protocol='udp',
821 ethertype='IPv4',
822 port_range_min=9999,
823 port_range_max=9999)['security_group_rule']
824 cls.addClassResourceCleanup(
825 waiters.wait_for_not_found,
826 cls.lb_mem_SGr_client.delete_security_group_rule,
827 cls.lb_mem_SGr_client.show_security_group_rule,
828 SGr['id'])
Adam Harwellcd72b562018-05-07 11:37:22 -0700829 # Create a security group rule to allow 22 (ssh)
830 SGr = cls.lb_mem_SGr_client.create_security_group_rule(
831 direction='ingress',
832 security_group_id=cls.lb_member_sec_group['id'],
833 protocol='tcp',
834 ethertype='IPv4',
835 port_range_min=22,
836 port_range_max=22)['security_group_rule']
837 cls.addClassResourceCleanup(
838 waiters.wait_for_not_found,
839 cls.lb_mem_SGr_client.delete_security_group_rule,
840 cls.lb_mem_SGr_client.show_security_group_rule,
841 SGr['id'])
842 if CONF.load_balancer.test_with_ipv6:
843 # Create a security group rule to allow 80-81 (test webservers)
844 SGr = cls.lb_mem_SGr_client.create_security_group_rule(
845 direction='ingress',
846 security_group_id=cls.lb_member_sec_group['id'],
847 protocol='tcp',
848 ethertype='IPv6',
849 port_range_min=80,
850 port_range_max=81)['security_group_rule']
851 cls.addClassResourceCleanup(
852 waiters.wait_for_not_found,
853 cls.lb_mem_SGr_client.delete_security_group_rule,
854 cls.lb_mem_SGr_client.show_security_group_rule,
855 SGr['id'])
Gregory Thiemonge29d17902019-04-30 15:06:17 +0200856 # Create a security group rule to allow UDP 80-81 (test
857 # webservers)
858 SGr = cls.lb_mem_SGr_client.create_security_group_rule(
859 direction='ingress',
860 security_group_id=cls.lb_member_sec_group['id'],
861 protocol='udp',
862 ethertype='IPv6',
863 port_range_min=80,
864 port_range_max=81)['security_group_rule']
865 cls.addClassResourceCleanup(
866 waiters.wait_for_not_found,
867 cls.lb_mem_SGr_client.delete_security_group_rule,
868 cls.lb_mem_SGr_client.show_security_group_rule,
869 SGr['id'])
Michael Johnson74b6f2f2020-10-29 15:11:39 -0700870 # Create a security group rule to allow 443 (test webservers)
871 SGr = cls.lb_mem_SGr_client.create_security_group_rule(
872 direction='ingress',
873 security_group_id=cls.lb_member_sec_group['id'],
874 protocol='tcp',
875 ethertype='IPv6',
876 port_range_min=443,
877 port_range_max=443)['security_group_rule']
878 cls.addClassResourceCleanup(
879 waiters.wait_for_not_found,
880 cls.lb_mem_SGr_client.delete_security_group_rule,
881 cls.lb_mem_SGr_client.show_security_group_rule,
882 SGr['id'])
Michael Johnson031ecca2020-10-29 16:45:32 -0700883 # Create a security group rule to allow 9443 (test webservers)
884 # Used in the pool encryption client authentication tests
885 SGr = cls.lb_mem_SGr_client.create_security_group_rule(
886 direction='ingress',
887 security_group_id=cls.lb_member_sec_group['id'],
888 protocol='tcp',
889 ethertype='IPv6',
890 port_range_min=9443,
891 port_range_max=9443)['security_group_rule']
892 cls.addClassResourceCleanup(
893 waiters.wait_for_not_found,
894 cls.lb_mem_SGr_client.delete_security_group_rule,
895 cls.lb_mem_SGr_client.show_security_group_rule,
896 SGr['id'])
Adam Harwellcd72b562018-05-07 11:37:22 -0700897 # Create a security group rule to allow 22 (ssh)
898 SGr = cls.lb_mem_SGr_client.create_security_group_rule(
899 direction='ingress',
900 security_group_id=cls.lb_member_sec_group['id'],
901 protocol='tcp',
902 ethertype='IPv6',
903 port_range_min=22,
904 port_range_max=22)['security_group_rule']
905 cls.addClassResourceCleanup(
906 waiters.wait_for_not_found,
907 cls.lb_mem_SGr_client.delete_security_group_rule,
908 cls.lb_mem_SGr_client.show_security_group_rule,
909 SGr['id'])
910
Michael Johnson77b8bae2024-11-08 01:39:29 +0000911 LOG.info('lb_member_sec_group: %s', cls.lb_member_sec_group)
Adam Harwellcd72b562018-05-07 11:37:22 -0700912
Michael Johnsonbaf12e02020-10-27 16:10:28 -0700913 # Setup backend member reencryption PKI
914 cls._create_backend_reencryption_pki()
915
Adam Harwellcd72b562018-05-07 11:37:22 -0700916 # Create webserver 1 instance
917 server_details = cls._create_webserver('lb_member_webserver1',
918 cls.lb_member_1_net)
919
920 cls.lb_member_webserver1 = server_details['server']
921 cls.webserver1_ip = server_details.get('ipv4_address')
922 cls.webserver1_ipv6 = server_details.get('ipv6_address')
923 cls.webserver1_public_ip = server_details['public_ipv4_address']
924
Michael Johnson77b8bae2024-11-08 01:39:29 +0000925 LOG.debug('Octavia Setup: lb_member_webserver1 = %s',
926 cls.lb_member_webserver1[const.ID])
927 LOG.debug('Octavia Setup: webserver1_ip = %s', cls.webserver1_ip)
928 LOG.debug('Octavia Setup: webserver1_ipv6 = %s', cls.webserver1_ipv6)
929 LOG.debug('Octavia Setup: webserver1_public_ip = %s',
930 cls.webserver1_public_ip)
Adam Harwellcd72b562018-05-07 11:37:22 -0700931
932 # Create webserver 2 instance
933 server_details = cls._create_webserver('lb_member_webserver2',
934 cls.lb_member_2_net)
935
936 cls.lb_member_webserver2 = server_details['server']
937 cls.webserver2_ip = server_details.get('ipv4_address')
938 cls.webserver2_ipv6 = server_details.get('ipv6_address')
939 cls.webserver2_public_ip = server_details['public_ipv4_address']
940
Michael Johnson77b8bae2024-11-08 01:39:29 +0000941 LOG.debug('Octavia Setup: lb_member_webserver2 = %s',
942 cls.lb_member_webserver2[const.ID])
943 LOG.debug('Octavia Setup: webserver2_ip = %s', cls.webserver2_ip)
944 LOG.debug('Octavia Setup: webserver2_ipv6 = %s', cls.webserver2_ipv6)
945 LOG.debug('Octavia Setup: webserver2_public_ip = %s',
946 cls.webserver2_public_ip)
Adam Harwellcd72b562018-05-07 11:37:22 -0700947
Ilya Bumarskoveff9bae2023-03-16 14:12:09 +0400948 if (CONF.load_balancer.test_with_ipv6 and not
949 config_octavia.is_tungstenfabric_backend_enabled()):
Michael Johnsonbf916df2018-10-17 10:59:28 -0700950 # Enable the IPv6 nic in webserver 1
951 cls._enable_ipv6_nic_webserver(
952 cls.webserver1_public_ip, cls.lb_member_keypair['private_key'],
953 cls.webserver1_ipv6, cls.lb_member_1_subnet_prefix)
954
955 # Enable the IPv6 nic in webserver 2
956 cls._enable_ipv6_nic_webserver(
957 cls.webserver2_public_ip, cls.lb_member_keypair['private_key'],
958 cls.webserver2_ipv6, cls.lb_member_2_subnet_prefix)
959
Adam Harwellcd72b562018-05-07 11:37:22 -0700960 # Set up serving on webserver 1
961 cls._install_start_webserver(cls.webserver1_public_ip,
Adam Harwelle029af22018-05-24 17:13:28 -0700962 cls.lb_member_keypair['private_key'],
963 cls.webserver1_response)
Adam Harwellcd72b562018-05-07 11:37:22 -0700964
965 # Validate webserver 1
Adam Harwelle029af22018-05-24 17:13:28 -0700966 cls._validate_webserver(cls.webserver1_public_ip,
967 cls.webserver1_response)
Adam Harwellcd72b562018-05-07 11:37:22 -0700968
Gregory Thiemonge29d17902019-04-30 15:06:17 +0200969 # Validate udp server 1
970 cls._validate_udp_server(cls.webserver1_public_ip,
971 cls.webserver1_response)
972
Adam Harwellcd72b562018-05-07 11:37:22 -0700973 # Set up serving on webserver 2
974 cls._install_start_webserver(cls.webserver2_public_ip,
Adam Harwelle029af22018-05-24 17:13:28 -0700975 cls.lb_member_keypair['private_key'],
Michael Johnsonbaf12e02020-10-27 16:10:28 -0700976 cls.webserver2_response, revoke_cert=True)
Adam Harwellcd72b562018-05-07 11:37:22 -0700977
978 # Validate webserver 2
Adam Harwelle029af22018-05-24 17:13:28 -0700979 cls._validate_webserver(cls.webserver2_public_ip,
980 cls.webserver2_response)
Adam Harwellcd72b562018-05-07 11:37:22 -0700981
Gregory Thiemonge29d17902019-04-30 15:06:17 +0200982 # Validate udp server 2
983 cls._validate_udp_server(cls.webserver2_public_ip,
984 cls.webserver2_response)
985
Adam Harwellcd72b562018-05-07 11:37:22 -0700986 @classmethod
987 def _create_networks(cls):
988 super(LoadBalancerBaseTestWithCompute, cls)._create_networks()
Jude Cross986e3f52017-07-24 14:57:20 -0700989 # Create a router for the subnets (required for the floating IP)
990 router_name = data_utils.rand_name("lb_member_router")
991 result = cls.lb_mem_routers_client.create_router(
992 name=router_name, admin_state_up=True,
993 external_gateway_info=dict(
994 network_id=CONF.network.public_network_id))
995 cls.lb_member_router = result['router']
Michael Johnson77b8bae2024-11-08 01:39:29 +0000996 LOG.info('lb_member_router: %s', cls.lb_member_router)
Jude Cross986e3f52017-07-24 14:57:20 -0700997 cls.addClassResourceCleanup(
998 waiters.wait_for_not_found,
999 cls.lb_mem_routers_client.delete_router,
1000 cls.lb_mem_routers_client.show_router,
1001 cls.lb_member_router['id'])
1002
1003 # Add VIP subnet to router
1004 cls.lb_mem_routers_client.add_router_interface(
1005 cls.lb_member_router['id'],
1006 subnet_id=cls.lb_member_vip_subnet['id'])
1007 cls.addClassResourceCleanup(
1008 waiters.wait_for_not_found,
1009 cls.lb_mem_routers_client.remove_router_interface,
1010 cls.lb_mem_routers_client.remove_router_interface,
1011 cls.lb_member_router['id'],
1012 subnet_id=cls.lb_member_vip_subnet['id'])
1013
Gregory Thiemonge54225ad2021-02-04 15:25:17 +01001014 if (CONF.load_balancer.test_with_ipv6 and
1015 CONF.load_balancer.default_router and
1016 cls.lb_member_vip_ipv6_subnet_use_subnetpool):
1017
1018 router_name = CONF.load_balancer.default_router
1019 # if lb_member_vip_ipv6_subnet uses devstack's subnetpool,
1020 # plug the subnet into the default router
1021 router = cls.os_admin.routers_client.list_routers(
1022 name=router_name)['routers']
1023
1024 if len(router) == 1:
1025 router = router[0]
1026
1027 # Add IPv6 VIP subnet to router1
1028 cls.os_admin_routers_client.add_router_interface(
1029 router['id'],
1030 subnet_id=cls.lb_member_vip_ipv6_subnet['id'])
1031 cls.addClassResourceCleanup(
1032 waiters.wait_for_not_found,
1033 cls.os_admin_routers_client.remove_router_interface,
1034 cls.os_admin_routers_client.remove_router_interface,
1035 router['id'],
1036 subnet_id=cls.lb_member_vip_ipv6_subnet['id'])
1037
Jude Cross986e3f52017-07-24 14:57:20 -07001038 # Add member subnet 1 to router
1039 cls.lb_mem_routers_client.add_router_interface(
1040 cls.lb_member_router['id'],
1041 subnet_id=cls.lb_member_1_subnet['id'])
1042 cls.addClassResourceCleanup(
1043 waiters.wait_for_not_found,
Jude Cross986e3f52017-07-24 14:57:20 -07001044 cls.lb_mem_routers_client.remove_router_interface,
1045 cls.lb_mem_routers_client.remove_router_interface,
1046 cls.lb_member_router['id'], subnet_id=cls.lb_member_1_subnet['id'])
1047
1048 # Add member subnet 2 to router
1049 cls.lb_mem_routers_client.add_router_interface(
1050 cls.lb_member_router['id'],
1051 subnet_id=cls.lb_member_2_subnet['id'])
1052 cls.addClassResourceCleanup(
1053 waiters.wait_for_not_found,
1054 cls.lb_mem_routers_client.remove_router_interface,
1055 cls.lb_mem_routers_client.remove_router_interface,
1056 cls.lb_member_router['id'], subnet_id=cls.lb_member_2_subnet['id'])
1057
1058 @classmethod
1059 def _create_webserver(cls, name, network):
1060 """Creates a webserver with two ports.
1061
1062 webserver_details dictionary contains:
1063 server - The compute server object
1064 ipv4_address - The IPv4 address for the server (optional)
1065 ipv6_address - The IPv6 address for the server (optional)
1066 public_ipv4_address - The publicly accessible IPv4 address for the
1067 server, this may be a floating IP (optional)
1068
1069 :param name: The name of the server to create.
1070 :param network: The network to boot the server on.
1071 :returns: webserver_details dictionary.
1072 """
1073 server_kwargs = {
1074 'name': data_utils.rand_name(name),
1075 'flavorRef': CONF.compute.flavor_ref,
1076 'imageRef': CONF.compute.image_ref,
1077 'key_name': cls.lb_member_keypair['name']}
1078 if (CONF.load_balancer.enable_security_groups and
1079 CONF.network_feature_enabled.port_security):
1080 server_kwargs['security_groups'] = [
1081 {'name': cls.lb_member_sec_group['name']}]
1082 if not CONF.load_balancer.disable_boot_network:
1083 server_kwargs['networks'] = [{'uuid': network['id']}]
1084
1085 # Replace the name for clouds that have limitations
1086 if CONF.load_balancer.random_server_name_length:
1087 r = random.SystemRandom()
1088 server_kwargs['name'] = "m{}".format("".join(
1089 [r.choice(string.ascii_uppercase + string.digits)
1090 for _ in range(
1091 CONF.load_balancer.random_server_name_length - 1)]
1092 ))
1093 if CONF.load_balancer.availability_zone:
1094 server_kwargs['availability_zone'] = (
1095 CONF.load_balancer.availability_zone)
1096
1097 server = cls.lb_mem_servers_client.create_server(
1098 **server_kwargs)['server']
1099 cls.addClassResourceCleanup(
1100 waiters.wait_for_not_found,
1101 cls.lb_mem_servers_client.delete_server,
1102 cls.lb_mem_servers_client.show_server,
1103 server['id'])
1104 server = waiters.wait_for_status(
1105 cls.lb_mem_servers_client.show_server,
1106 server['id'], 'status', 'ACTIVE',
1107 CONF.load_balancer.build_interval,
1108 CONF.load_balancer.build_timeout,
1109 root_tag='server')
1110 webserver_details = {'server': server}
Michael Johnson77b8bae2024-11-08 01:39:29 +00001111 LOG.info('Created server: %s', server)
Jude Cross986e3f52017-07-24 14:57:20 -07001112
1113 addresses = server['addresses']
1114 if CONF.load_balancer.disable_boot_network:
1115 instance_network = addresses.values()[0]
1116 else:
1117 instance_network = addresses[network['name']]
1118 for addr in instance_network:
1119 if addr['version'] == 4:
1120 webserver_details['ipv4_address'] = addr['addr']
1121 if addr['version'] == 6:
1122 webserver_details['ipv6_address'] = addr['addr']
1123
1124 if CONF.validation.connect_method == 'floating':
1125 result = cls.lb_mem_ports_client.list_ports(
1126 network_id=network['id'],
1127 mac_address=instance_network[0]['OS-EXT-IPS-MAC:mac_addr'])
1128 port_id = result['ports'][0]['id']
Ilya Bumarskoveff9bae2023-03-16 14:12:09 +04001129 if config_octavia.is_tungstenfabric_backend_enabled():
1130 port = result['ports'][0]
1131 fixed_ip = None
1132 for ip in port["fixed_ips"]:
1133 if (type(ipaddress.ip_address(ip["ip_address"])) is
1134 ipaddress.IPv4Address):
1135 fixed_ip = ip["ip_address"]
1136 break
1137 assert fixed_ip is not None, (f"Port doesn't have ipv4 "
1138 f"address: {port['fixed_ips']}")
1139 result = cls.lb_mem_float_ip_client.create_floatingip(
1140 floating_network_id=CONF.network.public_network_id,
1141 port_id=port_id,
1142 fixed_ip_address=fixed_ip)
1143 else:
1144 result = cls.lb_mem_float_ip_client.create_floatingip(
1145 floating_network_id=CONF.network.public_network_id,
1146 port_id=port_id)
Jude Cross986e3f52017-07-24 14:57:20 -07001147 floating_ip = result['floatingip']
Michael Johnson77b8bae2024-11-08 01:39:29 +00001148 LOG.info('webserver1_floating_ip: %s', floating_ip)
Jude Cross986e3f52017-07-24 14:57:20 -07001149 cls.addClassResourceCleanup(
1150 waiters.wait_for_not_found,
1151 cls.lb_mem_float_ip_client.delete_floatingip,
1152 cls.lb_mem_float_ip_client.show_floatingip,
1153 floatingip_id=floating_ip['id'])
1154 webserver_details['public_ipv4_address'] = (
1155 floating_ip['floating_ip_address'])
1156 else:
1157 webserver_details['public_ipv4_address'] = (
1158 instance_network[0]['addr'])
1159
1160 return webserver_details
1161
1162 @classmethod
Gregory Thiemongea2c234e2021-11-02 17:08:29 +01001163 def _get_openssh_version(cls):
1164 p = subprocess.Popen(["ssh", "-V"],
1165 stdout=subprocess.PIPE,
1166 stderr=subprocess.PIPE)
1167 output = p.communicate()[1]
1168
1169 try:
1170 m = re.match(r"OpenSSH_(\d+)\.(\d+)", output.decode('utf-8'))
1171 version_maj = int(m.group(1))
1172 version_min = int(m.group(2))
1173 return version_maj, version_min
1174 except Exception:
1175 return None, None
1176
1177 @classmethod
1178 def _need_scp_protocol(cls):
1179 # When using scp >= 8.7, force the use of the SCP protocol,
1180 # the new default (SFTP protocol) doesn't work with
1181 # cirros VMs.
1182 ssh_version = cls._get_openssh_version()
Michael Johnson77b8bae2024-11-08 01:39:29 +00001183 LOG.debug("ssh_version = %s", ssh_version)
Gregory Thiemongea2c234e2021-11-02 17:08:29 +01001184 return (ssh_version[0] > 8 or
1185 (ssh_version[0] == 8 and ssh_version[1] >= 7))
1186
1187 @classmethod
Michael Johnsonbaf12e02020-10-27 16:10:28 -07001188 def _install_start_webserver(cls, ip_address, ssh_key, start_id,
1189 revoke_cert=False):
Michael Johnson27357352020-11-13 13:55:09 -08001190 local_file = CONF.load_balancer.test_server_path
Adam Harwellcd72b562018-05-07 11:37:22 -07001191
1192 linux_client = remote_client.RemoteClient(
Ade Leed0ea4062021-09-06 15:33:27 -04001193 ip_address, CONF.validation.image_ssh_user, pkey=ssh_key,
Gregory Thiemongeb0da4f32022-02-04 08:58:06 +01001194 **cls.remote_client_args())
Adam Harwellcd72b562018-05-07 11:37:22 -07001195 linux_client.validate_authentication()
1196
1197 with tempfile.NamedTemporaryFile() as key:
1198 key.write(ssh_key.encode('utf-8'))
1199 key.flush()
Gregory Thiemongea2c234e2021-11-02 17:08:29 +01001200 ssh_extra_args = (
1201 "-o PubkeyAcceptedKeyTypes=+ssh-rsa")
1202 if cls._need_scp_protocol():
1203 ssh_extra_args += " -O"
Adam Harwellcd72b562018-05-07 11:37:22 -07001204 cmd = ("scp -v -o UserKnownHostsFile=/dev/null "
Gregory Thiemongea2c234e2021-11-02 17:08:29 +01001205 "{7} "
Adam Harwellcd72b562018-05-07 11:37:22 -07001206 "-o StrictHostKeyChecking=no "
1207 "-o ConnectTimeout={0} -o ConnectionAttempts={1} "
1208 "-i {2} {3} {4}@{5}:{6}").format(
1209 CONF.load_balancer.scp_connection_timeout,
1210 CONF.load_balancer.scp_connection_attempts,
1211 key.name, local_file, CONF.validation.image_ssh_user,
Gregory Thiemongea2c234e2021-11-02 17:08:29 +01001212 ip_address, const.TEST_SERVER_BINARY,
1213 ssh_extra_args)
Adam Harwellcd72b562018-05-07 11:37:22 -07001214 args = shlex.split(cmd)
1215 subprocess_args = {'stdout': subprocess.PIPE,
1216 'stderr': subprocess.STDOUT,
1217 'cwd': None}
1218 proc = subprocess.Popen(args, **subprocess_args)
1219 stdout, stderr = proc.communicate()
1220 if proc.returncode != 0:
1221 raise exceptions.CommandFailed(proc.returncode, cmd,
1222 stdout, stderr)
Gregory Thiemongef72a8862019-08-06 17:25:42 +02001223
Michael Johnsonbaf12e02020-10-27 16:10:28 -07001224 cls._load_member_pki_content(ip_address, key,
1225 revoke_cert=revoke_cert)
1226
Gregory Thiemongef72a8862019-08-06 17:25:42 +02001227 # Enabling memory overcommit allows to run golang static binaries
1228 # compiled with a recent golang toolchain (>=1.11). Those binaries
1229 # allocate a large amount of virtual memory at init time, and this
1230 # allocation fails in tempest's nano flavor (64MB of RAM)
1231 # (golang issue reported in https://github.com/golang/go/issues/28114,
1232 # follow-up: https://github.com/golang/go/issues/28081)
1233 # TODO(gthiemonge): Remove this call when golang issue is resolved.
1234 linux_client.exec_command('sudo sh -c "echo 1 > '
1235 '/proc/sys/vm/overcommit_memory"')
1236
Michael Johnsonbaf12e02020-10-27 16:10:28 -07001237 # The initial process also supports HTTPS and HTTPS with client auth
1238 linux_client.exec_command(
1239 'sudo screen -d -m {0} -port 80 -id {1} -https_port 443 -cert {2} '
1240 '-key {3} -https_client_auth_port 9443 -client_ca {4}'.format(
1241 const.TEST_SERVER_BINARY, start_id, const.TEST_SERVER_CERT,
1242 const.TEST_SERVER_KEY, const.TEST_SERVER_CLIENT_CA))
1243
Adam Harwellcd72b562018-05-07 11:37:22 -07001244 linux_client.exec_command('sudo screen -d -m {0} -port 81 '
Michael Johnsonbaf12e02020-10-27 16:10:28 -07001245 '-id {1}'.format(const.TEST_SERVER_BINARY,
1246 start_id + 1))
Adam Harwellcd72b562018-05-07 11:37:22 -07001247
Michael Johnsonbf916df2018-10-17 10:59:28 -07001248 # Cirros does not configure the assigned IPv6 address by default
1249 # so enable it manually like tempest does here:
1250 # tempest/scenario/test_netowrk_v6.py turn_nic6_on()
1251 @classmethod
1252 def _enable_ipv6_nic_webserver(cls, ip_address, ssh_key,
1253 ipv6_address, ipv6_prefix):
1254 linux_client = remote_client.RemoteClient(
Ade Leed0ea4062021-09-06 15:33:27 -04001255 ip_address, CONF.validation.image_ssh_user, pkey=ssh_key,
Gregory Thiemongeb0da4f32022-02-04 08:58:06 +01001256 **cls.remote_client_args())
Michael Johnsonbf916df2018-10-17 10:59:28 -07001257 linux_client.validate_authentication()
1258
1259 linux_client.exec_command('sudo ip address add {0}/{1} dev '
1260 'eth0'.format(ipv6_address, ipv6_prefix))
1261
Adam Harwellcd72b562018-05-07 11:37:22 -07001262 @classmethod
Jude Cross986e3f52017-07-24 14:57:20 -07001263 def _validate_webserver(cls, ip_address, start_id):
1264 URL = 'http://{0}'.format(ip_address)
Michael Johnson89bdbcd2020-03-19 15:59:19 -07001265 cls.validate_URL_response(URL, expected_body=str(start_id))
Jude Cross986e3f52017-07-24 14:57:20 -07001266 URL = 'http://{0}:81'.format(ip_address)
Michael Johnson89bdbcd2020-03-19 15:59:19 -07001267 cls.validate_URL_response(URL, expected_body=str(start_id + 1))
Jude Cross986e3f52017-07-24 14:57:20 -07001268
Gregory Thiemonge29d17902019-04-30 15:06:17 +02001269 @classmethod
1270 def _validate_udp_server(cls, ip_address, start_id):
Michael Johnson89bdbcd2020-03-19 15:59:19 -07001271 res = cls.make_udp_request(ip_address, 80)
Gregory Thiemonge29d17902019-04-30 15:06:17 +02001272 if res != str(start_id):
1273 raise Exception("Response from test server doesn't match the "
1274 "expected value ({0} != {1}).".format(
1275 res, str(start_id)))
1276
Michael Johnson89bdbcd2020-03-19 15:59:19 -07001277 res = cls.make_udp_request(ip_address, 81)
Gregory Thiemonge29d17902019-04-30 15:06:17 +02001278 if res != str(start_id + 1):
1279 raise Exception("Response from test server doesn't match the "
1280 "expected value ({0} != {1}).".format(
1281 res, str(start_id + 1)))
Michael Johnsonbaf12e02020-10-27 16:10:28 -07001282
1283 @classmethod
1284 def _create_backend_reencryption_pki(cls):
1285 # Create a CA self-signed cert and key for the member test servers
1286 cls.member_ca_cert, cls.member_ca_key = (
1287 cert_utils.generate_ca_cert_and_key())
1288
1289 LOG.debug('Member CA Cert: %s', cls.member_ca_cert.public_bytes(
1290 serialization.Encoding.PEM))
1291 LOG.debug('Member CA private Key: %s', cls.member_ca_key.private_bytes(
1292 encoding=serialization.Encoding.PEM,
1293 format=serialization.PrivateFormat.TraditionalOpenSSL,
1294 encryption_algorithm=serialization.NoEncryption()))
1295 LOG.debug('Member CA public Key: %s',
1296 cls.member_ca_key.public_key().public_bytes(
1297 encoding=serialization.Encoding.PEM,
1298 format=serialization.PublicFormat.SubjectPublicKeyInfo))
1299
1300 # Create the member client authentication CA
1301 cls.member_client_ca_cert, member_client_ca_key = (
1302 cert_utils.generate_ca_cert_and_key())
1303
1304 # Create client cert and key
1305 cls.member_client_cn = uuidutils.generate_uuid()
1306 cls.member_client_cert, cls.member_client_key = (
1307 cert_utils.generate_client_cert_and_key(
1308 cls.member_client_ca_cert, member_client_ca_key,
1309 cls.member_client_cn))
1310 # Note: We are not revoking a client cert here as we don't need to
1311 # test the backend web server CRL checking.
1312
1313 @classmethod
1314 def _load_member_pki_content(cls, ip_address, ssh_key, revoke_cert=False):
1315 # Create webserver certificate and key
1316 cert, key = cert_utils.generate_server_cert_and_key(
1317 cls.member_ca_cert, cls.member_ca_key, ip_address)
1318
1319 LOG.debug('%s Cert: %s', ip_address, cert.public_bytes(
1320 serialization.Encoding.PEM))
1321 LOG.debug('%s private Key: %s', ip_address, key.private_bytes(
1322 encoding=serialization.Encoding.PEM,
1323 format=serialization.PrivateFormat.TraditionalOpenSSL,
1324 encryption_algorithm=serialization.NoEncryption()))
1325 public_key = key.public_key()
1326 LOG.debug('%s public Key: %s', ip_address, public_key.public_bytes(
1327 encoding=serialization.Encoding.PEM,
1328 format=serialization.PublicFormat.SubjectPublicKeyInfo))
1329
1330 # Create a CRL with a revoked certificate
1331 if revoke_cert:
1332 # Create a CRL with webserver 2 revoked
1333 cls.member_crl = cert_utils.generate_certificate_revocation_list(
1334 cls.member_ca_cert, cls.member_ca_key, cert)
1335
1336 # Load the certificate, key, and client CA certificate into the
1337 # test server.
1338 with tempfile.TemporaryDirectory() as tmpdir:
1339 os.umask(0)
1340 files_to_send = []
1341 cert_filename = os.path.join(tmpdir, const.CERT_PEM)
1342 files_to_send.append(cert_filename)
1343 with open(os.open(cert_filename, os.O_CREAT | os.O_WRONLY,
1344 0o700), 'w') as fh:
1345 fh.write(cert.public_bytes(
1346 serialization.Encoding.PEM).decode('utf-8'))
1347 fh.flush()
1348 key_filename = os.path.join(tmpdir, const.KEY_PEM)
1349 files_to_send.append(key_filename)
1350 with open(os.open(key_filename, os.O_CREAT | os.O_WRONLY,
1351 0o700), 'w') as fh:
1352 fh.write(key.private_bytes(
1353 encoding=serialization.Encoding.PEM,
1354 format=serialization.PrivateFormat.TraditionalOpenSSL,
1355 encryption_algorithm=serialization.NoEncryption()).decode(
1356 'utf-8'))
1357 fh.flush()
1358 client_ca_filename = os.path.join(tmpdir, const.CLIENT_CA_PEM)
1359 files_to_send.append(client_ca_filename)
1360 with open(os.open(client_ca_filename, os.O_CREAT | os.O_WRONLY,
1361 0o700), 'w') as fh:
1362 fh.write(cls.member_client_ca_cert.public_bytes(
1363 serialization.Encoding.PEM).decode('utf-8'))
1364 fh.flush()
1365
1366 # For security, we don't want to use a shell that can glob
1367 # the file names, so iterate over them.
1368 subprocess_args = {'stdout': subprocess.PIPE,
1369 'stderr': subprocess.STDOUT,
1370 'cwd': None}
Gregory Thiemongea2c234e2021-11-02 17:08:29 +01001371 ssh_extra_args = (
1372 "-o PubkeyAcceptedKeyTypes=+ssh-rsa")
1373 if cls._need_scp_protocol():
1374 ssh_extra_args += " -O"
Michael Johnsonbaf12e02020-10-27 16:10:28 -07001375 cmd = ("scp -v -o UserKnownHostsFile=/dev/null "
Gregory Thiemongea2c234e2021-11-02 17:08:29 +01001376 "{9} "
Michael Johnsonbaf12e02020-10-27 16:10:28 -07001377 "-o StrictHostKeyChecking=no "
1378 "-o ConnectTimeout={0} -o ConnectionAttempts={1} "
1379 "-i {2} {3} {4} {5} {6}@{7}:{8}").format(
1380 CONF.load_balancer.scp_connection_timeout,
1381 CONF.load_balancer.scp_connection_attempts,
1382 ssh_key.name, cert_filename, key_filename, client_ca_filename,
Gregory Thiemongea2c234e2021-11-02 17:08:29 +01001383 CONF.validation.image_ssh_user, ip_address, const.DEV_SHM_PATH,
1384 ssh_extra_args)
Michael Johnsonbaf12e02020-10-27 16:10:28 -07001385 args = shlex.split(cmd)
1386 proc = subprocess.Popen(args, **subprocess_args)
1387 stdout, stderr = proc.communicate()
1388 if proc.returncode != 0:
1389 raise exceptions.CommandFailed(proc.returncode, cmd,
1390 stdout, stderr)