blob: 6e0efa24a792227cb6ded2cc5cd4e3d7fa2591d4 [file] [log] [blame]
Jude Cross986e3f52017-07-24 14:57:20 -07001# Copyright 2018 Rackspace US Inc. All rights reserved.
2#
3# Licensed under the Apache License, Version 2.0 (the "License"); you may
4# not use this file except in compliance with the License. You may obtain
5# a copy of the License at
6#
7# http://www.apache.org/licenses/LICENSE-2.0
8#
9# Unless required by applicable law or agreed to in writing, software
10# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
11# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
12# License for the specific language governing permissions and limitations
13# under the License.
14
15import ipaddress
rbubyr6978e022025-03-18 14:58:39 +010016import netaddr
Michael Johnsonbaf12e02020-10-27 16:10:28 -070017import os
Jude Cross986e3f52017-07-24 14:57:20 -070018import random
Gregory Thiemongea2c234e2021-11-02 17:08:29 +010019import re
Jude Cross986e3f52017-07-24 14:57:20 -070020import shlex
Jude Cross986e3f52017-07-24 14:57:20 -070021import string
22import subprocess
23import tempfile
24
Michael Johnsonbaf12e02020-10-27 16:10:28 -070025from cryptography.hazmat.primitives import serialization
Gregory Thiemongeb0da4f32022-02-04 08:58:06 +010026from oslo_config import cfg
Jude Cross986e3f52017-07-24 14:57:20 -070027from oslo_log import log as logging
28from oslo_utils import uuidutils
Gregory Thiemongecba3b222024-05-16 02:57:08 -040029from tempest import clients
Jude Cross986e3f52017-07-24 14:57:20 -070030from tempest import config
Gregory Thiemongecba3b222024-05-16 02:57:08 -040031from tempest.lib import auth
Jude Cross986e3f52017-07-24 14:57:20 -070032from tempest.lib.common.utils import data_utils
33from tempest.lib.common.utils.linux import remote_client
Jude Cross986e3f52017-07-24 14:57:20 -070034from tempest.lib import exceptions
35from tempest import test
Michael Johnson04dc5cb2019-01-20 11:03:50 -080036import tenacity
Jude Cross986e3f52017-07-24 14:57:20 -070037
Michael Johnsonbaf12e02020-10-27 16:10:28 -070038from octavia_tempest_plugin.common import cert_utils
Jude Cross986e3f52017-07-24 14:57:20 -070039from octavia_tempest_plugin.common import constants as const
Tom Weiningerc03e9c32024-04-23 14:07:04 +020040import octavia_tempest_plugin.services.load_balancer.v2 as lbv2
Michael Johnson6006de72021-02-21 01:42:39 +000041from octavia_tempest_plugin.tests import RBAC_tests
Jude Cross986e3f52017-07-24 14:57:20 -070042from octavia_tempest_plugin.tests import validators
43from octavia_tempest_plugin.tests import waiters
44
45CONF = config.CONF
46LOG = logging.getLogger(__name__)
47
Gregory Thiemonge29d17902019-04-30 15:06:17 +020048
Michael Johnson6006de72021-02-21 01:42:39 +000049class LoadBalancerBaseTest(validators.ValidatorsMixin,
50 RBAC_tests.RBACTestsMixin, test.BaseTestCase):
Jude Cross986e3f52017-07-24 14:57:20 -070051 """Base class for load balancer tests."""
52
Gregory Thiemonge3497f6c2021-04-19 21:33:13 +020053 if CONF.load_balancer.RBAC_test_type == const.OWNERADMIN:
54 credentials = [
55 'admin', 'primary', ['lb_admin', CONF.load_balancer.admin_role],
56 ['lb_member', CONF.load_balancer.member_role],
57 ['lb_member2', CONF.load_balancer.member_role]]
Michael Johnson6dac8ff2023-03-09 00:04:37 +000058 elif CONF.load_balancer.RBAC_test_type == const.KEYSTONE_DEFAULT_ROLES:
Michael Johnson6006de72021-02-21 01:42:39 +000059 credentials = [
Michael Johnson6dac8ff2023-03-09 00:04:37 +000060 'admin', 'primary',
Gregory Thiemongecba3b222024-05-16 02:57:08 -040061 ['lb_admin', 'admin'],
62 ['lb_observer', 'reader'],
63 ['lb_global_observer', 'reader'],
64 ['lb_member', 'member'],
65 ['lb_member2', 'member']]
66 # Note: an additional non-member user is added in setup_credentials
Michael Johnson6006de72021-02-21 01:42:39 +000067 else:
68 credentials = [
69 'admin', 'primary', ['lb_admin', CONF.load_balancer.admin_role],
70 ['lb_observer', CONF.load_balancer.observer_role, 'reader'],
71 ['lb_global_observer', CONF.load_balancer.global_observer_role,
72 'reader'],
Michael Johnson9e9f5262023-01-18 17:59:17 +000073 # Note: Some projects are now requiring the 'member' role by
74 # default (nova for example) so make sure our creds have this role
75 ['lb_member', CONF.load_balancer.member_role, 'member'],
76 ['lb_member2', CONF.load_balancer.member_role, 'member']]
Michael Johnson6006de72021-02-21 01:42:39 +000077
Michael Johnson6006de72021-02-21 01:42:39 +000078 # A tuple of credentials that will be allocated by tempest using the
79 # 'credentials' list above. These are used to build RBAC test lists.
80 allocated_creds = []
81 for cred in credentials:
82 if isinstance(cred, list):
83 allocated_creds.append('os_roles_' + cred[0])
84 else:
85 allocated_creds.append('os_' + cred)
86 # Tests shall not mess with the list of allocated credentials
87 allocated_credentials = tuple(allocated_creds)
Jude Cross986e3f52017-07-24 14:57:20 -070088
Adam Harwelle029af22018-05-24 17:13:28 -070089 webserver1_response = 1
90 webserver2_response = 5
Michael Johnsondfd818a2018-08-21 20:54:54 -070091 used_ips = []
Jude Cross986e3f52017-07-24 14:57:20 -070092
Michael Johnson89bdbcd2020-03-19 15:59:19 -070093 SRC_PORT_NUMBER_MIN = 32768
94 SRC_PORT_NUMBER_MAX = 61000
Gregory Thiemonge29d17902019-04-30 15:06:17 +020095 src_port_number = SRC_PORT_NUMBER_MIN
96
Jude Cross986e3f52017-07-24 14:57:20 -070097 @classmethod
98 def skip_checks(cls):
99 """Check if we should skip all of the children tests."""
100 super(LoadBalancerBaseTest, cls).skip_checks()
101
102 service_list = {
103 'load_balancer': CONF.service_available.load_balancer,
104 }
105
106 live_service_list = {
107 'compute': CONF.service_available.nova,
108 'image': CONF.service_available.glance,
109 'neutron': CONF.service_available.neutron
110 }
111
112 if not CONF.load_balancer.test_with_noop:
113 service_list.update(live_service_list)
114
115 for service, available in service_list.items():
116 if not available:
zhangzs2a6cf672018-11-10 16:13:11 +0800117 skip_msg = ("{0} skipped as {1} service is not "
Jude Cross986e3f52017-07-24 14:57:20 -0700118 "available.".format(cls.__name__, service))
119 raise cls.skipException(skip_msg)
120
121 # We must be able to reach our VIP and instances
122 if not (CONF.network.project_networks_reachable
123 or CONF.network.public_network_id):
124 msg = ('Either project_networks_reachable must be "true", or '
125 'public_network_id must be defined.')
126 raise cls.skipException(msg)
127
128 @classmethod
Gregory Thiemongecba3b222024-05-16 02:57:08 -0400129 def _setup_new_user_role_client(cls, project_id, role_name):
130 user = {
131 'name': data_utils.rand_name('user'),
132 'password': data_utils.rand_password()
133 }
134 user_id = cls.os_admin.users_v3_client.create_user(
135 **user)['user']['id']
136 cls._created_users.append(user_id)
137 roles = cls.os_admin.roles_v3_client.list_roles(
138 name=role_name)['roles']
139 if len(roles) == 0:
140 role = {
141 'name': role_name
142 }
143 role_id = cls.os_admin.roles_v3_client.create_role(
144 **role)['role']['id']
145 cls._created_roles.append(role_id)
146 else:
147 role_id = roles[0]['id']
148 cls.os_admin.roles_v3_client.create_user_role_on_project(
149 project_id, user_id, role_id
150 )
151 creds = auth.KeystoneV3Credentials(
152 user_id=user_id,
153 password=user['password'],
154 project_id=project_id
155 )
156 auth_provider = clients.get_auth_provider(creds)
157 creds = auth_provider.fill_credentials()
158 return clients.Manager(credentials=creds)
159
160 @classmethod
Jude Cross986e3f52017-07-24 14:57:20 -0700161 def setup_credentials(cls):
162 """Setup test credentials and network resources."""
163 # Do not auto create network resources
164 cls.set_network_resources()
165 super(LoadBalancerBaseTest, cls).setup_credentials()
166
Gregory Thiemongecba3b222024-05-16 02:57:08 -0400167 cls._created_projects = []
168 cls._created_users = []
169 cls._created_roles = []
170
171 non_dyn_users = []
172
173 if CONF.load_balancer.RBAC_test_type == const.KEYSTONE_DEFAULT_ROLES:
174 # Create a non-member user for keystone_default_roles
175 # When using dynamic credentials, tempest cannot create a user
176 # without a role, it always adds at least the "member" role.
177 # We manually create the user with a temporary role
178 project_id = cls.os_admin.projects_client.create_project(
179 data_utils.rand_name()
180 )['project']['id']
181 cls._created_projects.append(project_id)
182 cls.os_not_member = cls._setup_new_user_role_client(
183 project_id,
184 data_utils.rand_name('role'))
185 cls.allocated_creds.append('os_not_member')
186 non_dyn_users.append('not_member')
187
188 # Tests shall not mess with the list of allocated credentials
189 cls.allocated_credentials = tuple(cls.allocated_creds)
190
Bas de Bruijne530a88a2022-12-15 11:12:45 -0400191 if not CONF.load_balancer.log_user_roles:
192 return
193
Michael Johnson6006de72021-02-21 01:42:39 +0000194 # Log the user roles for this test run
195 role_name_cache = {}
Gregory Thiemongecba3b222024-05-16 02:57:08 -0400196 for cred in cls.credentials + non_dyn_users:
Michael Johnson6006de72021-02-21 01:42:39 +0000197 user_roles = []
198 if isinstance(cred, list):
199 user_name = cred[0]
200 cred_obj = getattr(cls, 'os_roles_' + cred[0])
201 else:
202 user_name = cred
203 cred_obj = getattr(cls, 'os_' + cred)
204 params = {'user.id': cred_obj.credentials.user_id,
Rodolfo Alonso Hernandezb5969972025-02-17 14:23:38 +0000205 'scope.project.id': cred_obj.credentials.project_id}
Michael Johnson6006de72021-02-21 01:42:39 +0000206 roles = cls.os_admin.role_assignments_client.list_role_assignments(
207 **params)['role_assignments']
208 for role in roles:
209 role_id = role['role']['id']
210 try:
211 role_name = role_name_cache[role_id]
212 except KeyError:
213 role_name = cls.os_admin.roles_v3_client.show_role(
214 role_id)['role']['name']
215 role_name_cache[role_id] = role_name
216 user_roles.append([role_name, role['scope']])
217 LOG.info("User %s has roles: %s", user_name, user_roles)
218
Jude Cross986e3f52017-07-24 14:57:20 -0700219 @classmethod
Gregory Thiemongecba3b222024-05-16 02:57:08 -0400220 def clear_credentials(cls):
221 for user_id in cls._created_users:
222 cls.os_admin.users_v3_client.delete_user(user_id)
223 for project_id in cls._created_projects:
224 cls.os_admin.projects_client.delete_project(project_id)
225 for role_id in cls._created_roles:
226 cls.os_admin.roles_v3_client.delete_role(role_id)
227 super().clear_credentials()
228
229 @classmethod
Jude Cross986e3f52017-07-24 14:57:20 -0700230 def setup_clients(cls):
231 """Setup client aliases."""
232 super(LoadBalancerBaseTest, cls).setup_clients()
Michael Johnson29d8e612021-06-23 16:16:12 +0000233 lb_admin_prefix = cls.os_roles_lb_admin.load_balancer_v2
Jude Cross986e3f52017-07-24 14:57:20 -0700234 cls.lb_mem_float_ip_client = cls.os_roles_lb_member.floating_ips_client
235 cls.lb_mem_keypairs_client = cls.os_roles_lb_member.keypairs_client
236 cls.lb_mem_net_client = cls.os_roles_lb_member.networks_client
237 cls.lb_mem_ports_client = cls.os_roles_lb_member.ports_client
238 cls.lb_mem_routers_client = cls.os_roles_lb_member.routers_client
239 cls.lb_mem_SG_client = cls.os_roles_lb_member.security_groups_client
240 cls.lb_mem_SGr_client = (
241 cls.os_roles_lb_member.security_group_rules_client)
242 cls.lb_mem_servers_client = cls.os_roles_lb_member.servers_client
243 cls.lb_mem_subnet_client = cls.os_roles_lb_member.subnets_client
Tom Weiningerc03e9c32024-04-23 14:07:04 +0200244 cls.mem_lb_client: lbv2.LoadbalancerClient = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000245 cls.os_roles_lb_member.load_balancer_v2.LoadbalancerClient())
Tom Weiningerc03e9c32024-04-23 14:07:04 +0200246 cls.mem_listener_client: lbv2.ListenerClient = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000247 cls.os_roles_lb_member.load_balancer_v2.ListenerClient())
Tom Weiningerc03e9c32024-04-23 14:07:04 +0200248 cls.mem_pool_client: lbv2.PoolClient = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000249 cls.os_roles_lb_member.load_balancer_v2.PoolClient())
Tom Weiningerc03e9c32024-04-23 14:07:04 +0200250 cls.mem_member_client: lbv2.MemberClient = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000251 cls.os_roles_lb_member.load_balancer_v2.MemberClient())
Tom Weiningerc03e9c32024-04-23 14:07:04 +0200252 cls.mem_healthmonitor_client: lbv2.HealthMonitorClient = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000253 cls.os_roles_lb_member.load_balancer_v2.HealthMonitorClient())
Tom Weiningerc03e9c32024-04-23 14:07:04 +0200254 cls.mem_l7policy_client: lbv2.L7PolicyClient = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000255 cls.os_roles_lb_member.load_balancer_v2.L7PolicyClient())
Tom Weiningerc03e9c32024-04-23 14:07:04 +0200256 cls.mem_l7rule_client: lbv2.L7RuleClient = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000257 cls.os_roles_lb_member.load_balancer_v2.L7RuleClient())
Tom Weiningerc03e9c32024-04-23 14:07:04 +0200258 cls.lb_admin_amphora_client: lbv2.AmphoraClient = (
259 lb_admin_prefix.AmphoraClient())
260 cls.lb_admin_flavor_profile_client: lbv2.FlavorProfileClient = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000261 lb_admin_prefix.FlavorProfileClient())
Tom Weiningerc03e9c32024-04-23 14:07:04 +0200262 cls.lb_admin_flavor_client: lbv2.FlavorClient = (
263 lb_admin_prefix.FlavorClient())
264 cls.mem_flavor_client: lbv2.FlavorClient = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000265 cls.os_roles_lb_member.load_balancer_v2.FlavorClient())
Tom Weiningerc03e9c32024-04-23 14:07:04 +0200266 cls.mem_provider_client: lbv2.ProviderClient = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000267 cls.os_roles_lb_member.load_balancer_v2.ProviderClient())
Carlos Goncalvesc2e12162019-02-14 23:57:44 +0100268 cls.os_admin_servers_client = cls.os_admin.servers_client
Gregory Thiemonge54225ad2021-02-04 15:25:17 +0100269 cls.os_admin_routers_client = cls.os_admin.routers_client
270 cls.os_admin_subnetpools_client = cls.os_admin.subnetpools_client
Adam Harwellc2aa20c2019-11-20 11:15:07 -0800271 cls.lb_admin_flavor_capabilities_client = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000272 lb_admin_prefix.FlavorCapabilitiesClient())
Adam Harwellc2aa20c2019-11-20 11:15:07 -0800273 cls.lb_admin_availability_zone_capabilities_client = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000274 lb_admin_prefix.AvailabilityZoneCapabilitiesClient())
Adam Harwellc2aa20c2019-11-20 11:15:07 -0800275 cls.lb_admin_availability_zone_profile_client = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000276 lb_admin_prefix.AvailabilityZoneProfileClient())
Adam Harwellc2aa20c2019-11-20 11:15:07 -0800277 cls.lb_admin_availability_zone_client = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000278 lb_admin_prefix.AvailabilityZoneClient())
Adam Harwellc2aa20c2019-11-20 11:15:07 -0800279 cls.mem_availability_zone_client = (
Michael Johnson29d8e612021-06-23 16:16:12 +0000280 cls.os_roles_lb_member.load_balancer_v2.AvailabilityZoneClient())
Gregory Thiemonge5010dc02021-02-02 14:59:27 +0100281 cls.os_admin_compute_flavors_client = cls.os_admin.flavors_client
Jude Cross986e3f52017-07-24 14:57:20 -0700282
283 @classmethod
284 def resource_setup(cls):
285 """Setup resources needed by the tests."""
286 super(LoadBalancerBaseTest, cls).resource_setup()
287
288 conf_lb = CONF.load_balancer
289
Michael Johnsondfd818a2018-08-21 20:54:54 -0700290 cls.api_version = cls.mem_lb_client.get_max_api_version()
291
Jude Cross986e3f52017-07-24 14:57:20 -0700292 if conf_lb.test_subnet_override and not conf_lb.test_network_override:
293 raise exceptions.InvalidConfiguration(
294 "Configuration value test_network_override must be "
295 "specified if test_subnet_override is used.")
296
Michael Johnson6a9236a2020-08-04 23:54:54 +0000297 # TODO(johnsom) Remove this
Maciej Józefczykb6df5f82019-12-10 10:12:30 +0000298 # Get loadbalancing algorithms supported by provider driver.
299 try:
300 algorithms = const.SUPPORTED_LB_ALGORITHMS[
301 CONF.load_balancer.provider]
302 except KeyError:
303 algorithms = const.SUPPORTED_LB_ALGORITHMS['default']
304 # Set default algorithm as first from the list.
305 cls.lb_algorithm = algorithms[0]
306
Jude Cross986e3f52017-07-24 14:57:20 -0700307 show_subnet = cls.lb_mem_subnet_client.show_subnet
308 if CONF.load_balancer.test_with_noop:
309 cls.lb_member_vip_net = {'id': uuidutils.generate_uuid()}
310 cls.lb_member_vip_subnet = {'id': uuidutils.generate_uuid()}
311 cls.lb_member_1_net = {'id': uuidutils.generate_uuid()}
312 cls.lb_member_1_subnet = {'id': uuidutils.generate_uuid()}
313 cls.lb_member_2_net = {'id': uuidutils.generate_uuid()}
314 cls.lb_member_2_subnet = {'id': uuidutils.generate_uuid()}
315 if CONF.load_balancer.test_with_ipv6:
Michael Johnson5a16ad32018-10-18 14:49:11 -0700316 cls.lb_member_vip_ipv6_net = {'id': uuidutils.generate_uuid()}
Jude Cross986e3f52017-07-24 14:57:20 -0700317 cls.lb_member_vip_ipv6_subnet = {'id':
318 uuidutils.generate_uuid()}
319 cls.lb_member_1_ipv6_subnet = {'id': uuidutils.generate_uuid()}
320 cls.lb_member_2_ipv6_subnet = {'id': uuidutils.generate_uuid()}
Michael Johnson590fbe12019-07-03 14:30:01 -0700321 cls.lb_member_vip_ipv6_subnet_stateful = True
Jude Cross986e3f52017-07-24 14:57:20 -0700322 return
323 elif CONF.load_balancer.test_network_override:
324 if conf_lb.test_subnet_override:
325 override_subnet = show_subnet(conf_lb.test_subnet_override)
326 else:
327 override_subnet = None
328
329 show_net = cls.lb_mem_net_client.show_network
330 override_network = show_net(conf_lb.test_network_override)
331 override_network = override_network.get('network')
332
333 cls.lb_member_vip_net = override_network
334 cls.lb_member_vip_subnet = override_subnet
335 cls.lb_member_1_net = override_network
336 cls.lb_member_1_subnet = override_subnet
337 cls.lb_member_2_net = override_network
338 cls.lb_member_2_subnet = override_subnet
339
340 if (CONF.load_balancer.test_with_ipv6 and
Michael Polenchuke1f3ed52022-01-18 15:44:56 +0400341 conf_lb.test_ipv6_subnet_override):
Jude Cross986e3f52017-07-24 14:57:20 -0700342 override_ipv6_subnet = show_subnet(
Michael Polenchuke1f3ed52022-01-18 15:44:56 +0400343 conf_lb.test_ipv6_subnet_override)
Jude Cross986e3f52017-07-24 14:57:20 -0700344 cls.lb_member_vip_ipv6_subnet = override_ipv6_subnet
345 cls.lb_member_1_ipv6_subnet = override_ipv6_subnet
346 cls.lb_member_2_ipv6_subnet = override_ipv6_subnet
Michael Johnson590fbe12019-07-03 14:30:01 -0700347 cls.lb_member_vip_ipv6_subnet_stateful = False
348 if (override_ipv6_subnet[0]['ipv6_address_mode'] ==
349 'dhcpv6-stateful'):
350 cls.lb_member_vip_ipv6_subnet_stateful = True
Jude Cross986e3f52017-07-24 14:57:20 -0700351 else:
352 cls.lb_member_vip_ipv6_subnet = None
353 cls.lb_member_1_ipv6_subnet = None
354 cls.lb_member_2_ipv6_subnet = None
355 else:
356 cls._create_networks()
357
Michael Johnson77b8bae2024-11-08 01:39:29 +0000358 LOG.debug('Octavia Setup: lb_member_vip_net = %s',
359 cls.lb_member_vip_net[const.ID])
Jude Cross986e3f52017-07-24 14:57:20 -0700360 if cls.lb_member_vip_subnet:
Michael Johnson77b8bae2024-11-08 01:39:29 +0000361 LOG.debug('Octavia Setup: lb_member_vip_subnet = %s',
362 cls.lb_member_vip_subnet[const.ID])
363 LOG.debug('Octavia Setup: lb_member_1_net = %s',
364 cls.lb_member_1_net[const.ID])
Jude Cross986e3f52017-07-24 14:57:20 -0700365 if cls.lb_member_1_subnet:
Michael Johnson77b8bae2024-11-08 01:39:29 +0000366 LOG.debug('Octavia Setup: lb_member_1_subnet = %s',
367 cls.lb_member_1_subnet[const.ID])
368 LOG.debug('Octavia Setup: lb_member_2_net = %s',
369 cls.lb_member_2_net[const.ID])
Jude Cross986e3f52017-07-24 14:57:20 -0700370 if cls.lb_member_2_subnet:
Michael Johnson77b8bae2024-11-08 01:39:29 +0000371 LOG.debug('Octavia Setup: lb_member_2_subnet = %s',
372 cls.lb_member_2_subnet[const.ID])
Michael Johnson124ba8b2018-08-30 16:06:05 -0700373 if CONF.load_balancer.test_with_ipv6:
374 if cls.lb_member_vip_ipv6_subnet:
Michael Johnson77b8bae2024-11-08 01:39:29 +0000375 LOG.debug('Octavia Setup: lb_member_vip_ipv6_subnet = %s',
376 cls.lb_member_vip_ipv6_subnet[const.ID])
Michael Johnson124ba8b2018-08-30 16:06:05 -0700377 if cls.lb_member_1_ipv6_subnet:
Michael Johnson77b8bae2024-11-08 01:39:29 +0000378 LOG.debug('Octavia Setup: lb_member_1_ipv6_subnet = %s',
379 cls.lb_member_1_ipv6_subnet[const.ID])
Michael Johnson124ba8b2018-08-30 16:06:05 -0700380 if cls.lb_member_2_ipv6_subnet:
Michael Johnson77b8bae2024-11-08 01:39:29 +0000381 LOG.debug('Octavia Setup: lb_member_2_ipv6_subnet = %s',
382 cls.lb_member_2_ipv6_subnet[const.ID])
Jude Cross986e3f52017-07-24 14:57:20 -0700383
Jude Cross986e3f52017-07-24 14:57:20 -0700384 @classmethod
Michael Johnson04dc5cb2019-01-20 11:03:50 -0800385 # Neutron can be slow to clean up ports from the subnets/networks.
386 # Retry this delete a few times if we get a "Conflict" error to give
387 # neutron time to fully cleanup the ports.
388 @tenacity.retry(
389 retry=tenacity.retry_if_exception_type(exceptions.Conflict),
390 wait=tenacity.wait_incrementing(
Vasyl Saienko08f25652021-05-12 16:30:26 +0300391 const.RETRY_INITIAL_DELAY, const.RETRY_BACKOFF, const.RETRY_MAX),
392 stop=tenacity.stop_after_attempt(const.RETRY_ATTEMPTS))
Michael Johnson04dc5cb2019-01-20 11:03:50 -0800393 def _logging_delete_network(cls, net_id):
394 try:
395 cls.lb_mem_net_client.delete_network(net_id)
396 except Exception:
Michael Johnson77b8bae2024-11-08 01:39:29 +0000397 LOG.error('Unable to delete network %s. Active ports:', net_id)
Michael Johnson04dc5cb2019-01-20 11:03:50 -0800398 LOG.error(cls.lb_mem_ports_client.list_ports())
399 raise
400
401 @classmethod
402 # Neutron can be slow to clean up ports from the subnets/networks.
403 # Retry this delete a few times if we get a "Conflict" error to give
404 # neutron time to fully cleanup the ports.
405 @tenacity.retry(
406 retry=tenacity.retry_if_exception_type(exceptions.Conflict),
407 wait=tenacity.wait_incrementing(
Vasyl Saienko08f25652021-05-12 16:30:26 +0300408 const.RETRY_INITIAL_DELAY, const.RETRY_BACKOFF, const.RETRY_MAX),
409 stop=tenacity.stop_after_attempt(const.RETRY_ATTEMPTS))
Michael Johnson04dc5cb2019-01-20 11:03:50 -0800410 def _logging_delete_subnet(cls, subnet_id):
411 try:
412 cls.lb_mem_subnet_client.delete_subnet(subnet_id)
413 except Exception:
Michael Johnson77b8bae2024-11-08 01:39:29 +0000414 LOG.error('Unable to delete subnet %s. Active ports:', subnet_id)
Michael Johnson04dc5cb2019-01-20 11:03:50 -0800415 LOG.error(cls.lb_mem_ports_client.list_ports())
416 raise
417
418 @classmethod
Jude Cross986e3f52017-07-24 14:57:20 -0700419 def _create_networks(cls):
420 """Creates networks, subnets, and routers used in tests.
421
422 The following are expected to be defined and available to the tests:
423 cls.lb_member_vip_net
424 cls.lb_member_vip_subnet
425 cls.lb_member_vip_ipv6_subnet (optional)
426 cls.lb_member_1_net
427 cls.lb_member_1_subnet
428 cls.lb_member_1_ipv6_subnet (optional)
429 cls.lb_member_2_net
430 cls.lb_member_2_subnet
431 cls.lb_member_2_ipv6_subnet (optional)
432 """
433
434 # Create tenant VIP network
435 network_kwargs = {
436 'name': data_utils.rand_name("lb_member_vip_network")}
437 if CONF.network_feature_enabled.port_security:
Andreas Jaeger4215b702020-03-28 20:13:46 +0100438 # Note: Allowed Address Pairs requires port security
439 network_kwargs['port_security_enabled'] = True
Jude Cross986e3f52017-07-24 14:57:20 -0700440 result = cls.lb_mem_net_client.create_network(**network_kwargs)
441 cls.lb_member_vip_net = result['network']
Michael Johnson77b8bae2024-11-08 01:39:29 +0000442 LOG.info('lb_member_vip_net: %s', cls.lb_member_vip_net)
Jude Cross986e3f52017-07-24 14:57:20 -0700443 cls.addClassResourceCleanup(
444 waiters.wait_for_not_found,
Michael Johnson04dc5cb2019-01-20 11:03:50 -0800445 cls._logging_delete_network,
Jude Cross986e3f52017-07-24 14:57:20 -0700446 cls.lb_mem_net_client.show_network,
447 cls.lb_member_vip_net['id'])
448
rbubyr6978e022025-03-18 14:58:39 +0100449 # Add allocation pool to prevent IP address conflicts with portprober
450 cidr = netaddr.IPNetwork(CONF.load_balancer.vip_subnet_cidr)
451 pool_start = ipaddress.ip_address(str(cidr[101]))
452 pool_end = ipaddress.ip_address(str(cidr[254]))
453 allocation_pools = [{'start': str(pool_start), 'end': str(pool_end)}]
454
Jude Cross986e3f52017-07-24 14:57:20 -0700455 # Create tenant VIP subnet
456 subnet_kwargs = {
457 'name': data_utils.rand_name("lb_member_vip_subnet"),
458 'network_id': cls.lb_member_vip_net['id'],
459 'cidr': CONF.load_balancer.vip_subnet_cidr,
rbubyr6978e022025-03-18 14:58:39 +0100460 'ip_version': 4,
461 'allocation_pools': allocation_pools
462 }
Jude Cross986e3f52017-07-24 14:57:20 -0700463 result = cls.lb_mem_subnet_client.create_subnet(**subnet_kwargs)
464 cls.lb_member_vip_subnet = result['subnet']
Michael Johnson77b8bae2024-11-08 01:39:29 +0000465 LOG.info('lb_member_vip_subnet: %s', cls.lb_member_vip_subnet)
Jude Cross986e3f52017-07-24 14:57:20 -0700466 cls.addClassResourceCleanup(
467 waiters.wait_for_not_found,
Michael Johnson04dc5cb2019-01-20 11:03:50 -0800468 cls._logging_delete_subnet,
Jude Cross986e3f52017-07-24 14:57:20 -0700469 cls.lb_mem_subnet_client.show_subnet,
470 cls.lb_member_vip_subnet['id'])
471
472 # Create tenant VIP IPv6 subnet
473 if CONF.load_balancer.test_with_ipv6:
Michael Johnson590fbe12019-07-03 14:30:01 -0700474 cls.lb_member_vip_ipv6_subnet_stateful = False
Gregory Thiemonge54225ad2021-02-04 15:25:17 +0100475 cls.lb_member_vip_ipv6_subnet_use_subnetpool = False
476 subnet_kwargs = {
477 'name': data_utils.rand_name("lb_member_vip_ipv6_subnet"),
478 'network_id': cls.lb_member_vip_net['id'],
479 'ip_version': 6}
480
481 # Use a CIDR from devstack's default IPv6 subnetpool if it exists,
482 # the subnetpool's cidr is routable from the devstack node
483 # through the default router
484 subnetpool_name = CONF.load_balancer.default_ipv6_subnetpool
485 if subnetpool_name:
486 subnetpool = cls.os_admin_subnetpools_client.list_subnetpools(
487 name=subnetpool_name)['subnetpools']
488 if len(subnetpool) == 1:
489 subnetpool = subnetpool[0]
490 subnet_kwargs['subnetpool_id'] = subnetpool['id']
491 cls.lb_member_vip_ipv6_subnet_use_subnetpool = True
492
493 if 'subnetpool_id' not in subnet_kwargs:
494 subnet_kwargs['cidr'] = (
495 CONF.load_balancer.vip_ipv6_subnet_cidr)
496
497 result = cls.lb_mem_subnet_client.create_subnet(
498 **subnet_kwargs)
499 cls.lb_member_vip_ipv6_net = cls.lb_member_vip_net
500 cls.lb_member_vip_ipv6_subnet = result['subnet']
501 cls.addClassResourceCleanup(
502 waiters.wait_for_not_found,
503 cls._logging_delete_subnet,
504 cls.lb_mem_subnet_client.show_subnet,
505 cls.lb_member_vip_ipv6_subnet['id'])
Carlos Goncalves84af48c2019-07-25 15:51:30 +0200506
Michael Johnson77b8bae2024-11-08 01:39:29 +0000507 LOG.info('lb_member_vip_ipv6_subnet: %s',
508 cls.lb_member_vip_ipv6_subnet)
Jude Cross986e3f52017-07-24 14:57:20 -0700509
510 # Create tenant member 1 network
511 network_kwargs = {
512 'name': data_utils.rand_name("lb_member_1_network")}
513 if CONF.network_feature_enabled.port_security:
514 if CONF.load_balancer.enable_security_groups:
515 network_kwargs['port_security_enabled'] = True
516 else:
517 network_kwargs['port_security_enabled'] = False
518 result = cls.lb_mem_net_client.create_network(**network_kwargs)
519 cls.lb_member_1_net = result['network']
Michael Johnson77b8bae2024-11-08 01:39:29 +0000520 LOG.info('lb_member_1_net: %s', cls.lb_member_1_net)
Jude Cross986e3f52017-07-24 14:57:20 -0700521 cls.addClassResourceCleanup(
522 waiters.wait_for_not_found,
Michael Johnson04dc5cb2019-01-20 11:03:50 -0800523 cls._logging_delete_network,
Jude Cross986e3f52017-07-24 14:57:20 -0700524 cls.lb_mem_net_client.show_network,
525 cls.lb_member_1_net['id'])
526
527 # Create tenant member 1 subnet
528 subnet_kwargs = {
529 'name': data_utils.rand_name("lb_member_1_subnet"),
530 'network_id': cls.lb_member_1_net['id'],
531 'cidr': CONF.load_balancer.member_1_ipv4_subnet_cidr,
532 'ip_version': 4}
533 result = cls.lb_mem_subnet_client.create_subnet(**subnet_kwargs)
534 cls.lb_member_1_subnet = result['subnet']
Michael Johnson77b8bae2024-11-08 01:39:29 +0000535 LOG.info('lb_member_1_subnet: %s', cls.lb_member_1_subnet)
Jude Cross986e3f52017-07-24 14:57:20 -0700536 cls.addClassResourceCleanup(
537 waiters.wait_for_not_found,
Michael Johnson04dc5cb2019-01-20 11:03:50 -0800538 cls._logging_delete_subnet,
Jude Cross986e3f52017-07-24 14:57:20 -0700539 cls.lb_mem_subnet_client.show_subnet,
540 cls.lb_member_1_subnet['id'])
541
542 # Create tenant member 1 ipv6 subnet
543 if CONF.load_balancer.test_with_ipv6:
544 subnet_kwargs = {
545 'name': data_utils.rand_name("lb_member_1_ipv6_subnet"),
546 'network_id': cls.lb_member_1_net['id'],
547 'cidr': CONF.load_balancer.member_1_ipv6_subnet_cidr,
548 'ip_version': 6}
549 result = cls.lb_mem_subnet_client.create_subnet(**subnet_kwargs)
Michael Johnsonbf916df2018-10-17 10:59:28 -0700550 cls.lb_member_1_subnet_prefix = (
551 CONF.load_balancer.member_1_ipv6_subnet_cidr.rpartition('/')[2]
552 )
Michael Johnson77b8bae2024-11-08 01:39:29 +0000553 assert (cls.lb_member_1_subnet_prefix.isdigit())
Jude Cross986e3f52017-07-24 14:57:20 -0700554 cls.lb_member_1_ipv6_subnet = result['subnet']
Michael Johnson77b8bae2024-11-08 01:39:29 +0000555 LOG.info('lb_member_1_ipv6_subnet: %s',
556 cls.lb_member_1_ipv6_subnet)
Jude Cross986e3f52017-07-24 14:57:20 -0700557 cls.addClassResourceCleanup(
558 waiters.wait_for_not_found,
Michael Johnson04dc5cb2019-01-20 11:03:50 -0800559 cls._logging_delete_subnet,
Jude Cross986e3f52017-07-24 14:57:20 -0700560 cls.lb_mem_subnet_client.show_subnet,
561 cls.lb_member_1_ipv6_subnet['id'])
562
563 # Create tenant member 2 network
564 network_kwargs = {
565 'name': data_utils.rand_name("lb_member_2_network")}
566 if CONF.network_feature_enabled.port_security:
567 if CONF.load_balancer.enable_security_groups:
568 network_kwargs['port_security_enabled'] = True
569 else:
570 network_kwargs['port_security_enabled'] = False
571 result = cls.lb_mem_net_client.create_network(**network_kwargs)
572 cls.lb_member_2_net = result['network']
Michael Johnson77b8bae2024-11-08 01:39:29 +0000573 LOG.info('lb_member_2_net: %s', cls.lb_member_2_net)
Jude Cross986e3f52017-07-24 14:57:20 -0700574 cls.addClassResourceCleanup(
575 waiters.wait_for_not_found,
Michael Johnson04dc5cb2019-01-20 11:03:50 -0800576 cls._logging_delete_network,
Jude Cross986e3f52017-07-24 14:57:20 -0700577 cls.lb_mem_net_client.show_network,
578 cls.lb_member_2_net['id'])
579
580 # Create tenant member 2 subnet
581 subnet_kwargs = {
582 'name': data_utils.rand_name("lb_member_2_subnet"),
583 'network_id': cls.lb_member_2_net['id'],
584 'cidr': CONF.load_balancer.member_2_ipv4_subnet_cidr,
585 'ip_version': 4}
586 result = cls.lb_mem_subnet_client.create_subnet(**subnet_kwargs)
587 cls.lb_member_2_subnet = result['subnet']
Michael Johnson77b8bae2024-11-08 01:39:29 +0000588 LOG.info('lb_member_2_subnet: %s', cls.lb_member_2_subnet)
Jude Cross986e3f52017-07-24 14:57:20 -0700589 cls.addClassResourceCleanup(
590 waiters.wait_for_not_found,
Michael Johnson04dc5cb2019-01-20 11:03:50 -0800591 cls._logging_delete_subnet,
Jude Cross986e3f52017-07-24 14:57:20 -0700592 cls.lb_mem_subnet_client.show_subnet,
593 cls.lb_member_2_subnet['id'])
594
595 # Create tenant member 2 ipv6 subnet
596 if CONF.load_balancer.test_with_ipv6:
597 subnet_kwargs = {
598 'name': data_utils.rand_name("lb_member_2_ipv6_subnet"),
599 'network_id': cls.lb_member_2_net['id'],
600 'cidr': CONF.load_balancer.member_2_ipv6_subnet_cidr,
601 'ip_version': 6}
602 result = cls.lb_mem_subnet_client.create_subnet(**subnet_kwargs)
Michael Johnsonbf916df2018-10-17 10:59:28 -0700603 cls.lb_member_2_subnet_prefix = (
604 CONF.load_balancer.member_2_ipv6_subnet_cidr.rpartition('/')[2]
605 )
Michael Johnson77b8bae2024-11-08 01:39:29 +0000606 assert (cls.lb_member_2_subnet_prefix.isdigit())
Jude Cross986e3f52017-07-24 14:57:20 -0700607 cls.lb_member_2_ipv6_subnet = result['subnet']
Michael Johnson77b8bae2024-11-08 01:39:29 +0000608 LOG.info('lb_member_2_ipv6_subnet: %s',
609 cls.lb_member_2_ipv6_subnet)
Jude Cross986e3f52017-07-24 14:57:20 -0700610 cls.addClassResourceCleanup(
611 waiters.wait_for_not_found,
Michael Johnson04dc5cb2019-01-20 11:03:50 -0800612 cls._logging_delete_subnet,
Jude Cross986e3f52017-07-24 14:57:20 -0700613 cls.lb_mem_subnet_client.show_subnet,
614 cls.lb_member_2_ipv6_subnet['id'])
615
Adam Harwellcd72b562018-05-07 11:37:22 -0700616 @classmethod
Michael Johnson07c9a632018-06-07 13:27:42 -0700617 def _setup_lb_network_kwargs(cls, lb_kwargs, ip_version=None,
618 use_fixed_ip=False):
Adam Harwell60ed9d92018-05-10 13:23:13 -0700619 if not ip_version:
620 ip_version = 6 if CONF.load_balancer.test_with_ipv6 else 4
Michael Johnson5a16ad32018-10-18 14:49:11 -0700621 if cls.lb_member_vip_subnet or cls.lb_member_vip_ipv6_subnet:
Adam Harwellcd72b562018-05-07 11:37:22 -0700622 ip_index = data_utils.rand_int_id(start=10, end=100)
Michael Johnsondfd818a2018-08-21 20:54:54 -0700623 while ip_index in cls.used_ips:
624 ip_index = data_utils.rand_int_id(start=10, end=100)
625 cls.used_ips.append(ip_index)
Adam Harwellcd72b562018-05-07 11:37:22 -0700626 if ip_version == 4:
Adam Harwellcd72b562018-05-07 11:37:22 -0700627 subnet_id = cls.lb_member_vip_subnet[const.ID]
Michael Johnson5a16ad32018-10-18 14:49:11 -0700628 if CONF.load_balancer.test_with_noop:
629 lb_vip_address = '198.18.33.33'
630 else:
631 subnet = cls.os_admin.subnets_client.show_subnet(subnet_id)
632 network = ipaddress.IPv4Network(subnet['subnet']['cidr'])
633 lb_vip_address = str(network[ip_index])
Adam Harwellcd72b562018-05-07 11:37:22 -0700634 else:
Adam Harwellcd72b562018-05-07 11:37:22 -0700635 subnet_id = cls.lb_member_vip_ipv6_subnet[const.ID]
Michael Johnson5a16ad32018-10-18 14:49:11 -0700636 if CONF.load_balancer.test_with_noop:
637 lb_vip_address = '2001:db8:33:33:33:33:33:33'
638 else:
639 subnet = cls.os_admin.subnets_client.show_subnet(subnet_id)
640 network = ipaddress.IPv6Network(subnet['subnet']['cidr'])
641 lb_vip_address = str(network[ip_index])
Michael Johnson590fbe12019-07-03 14:30:01 -0700642 # If the subnet is IPv6 slaac or dhcpv6-stateless
643 # neutron does not allow a fixed IP
644 if not cls.lb_member_vip_ipv6_subnet_stateful:
645 use_fixed_ip = False
Adam Harwellcd72b562018-05-07 11:37:22 -0700646 lb_kwargs[const.VIP_SUBNET_ID] = subnet_id
Michael Johnson07c9a632018-06-07 13:27:42 -0700647 if use_fixed_ip:
648 lb_kwargs[const.VIP_ADDRESS] = lb_vip_address
Adam Harwellcd72b562018-05-07 11:37:22 -0700649 if CONF.load_balancer.test_with_noop:
650 lb_kwargs[const.VIP_NETWORK_ID] = (
651 cls.lb_member_vip_net[const.ID])
Carlos Goncalvesbb238552020-01-15 10:10:55 +0000652 if ip_version == 6:
653 lb_kwargs[const.VIP_ADDRESS] = lb_vip_address
Adam Harwellcd72b562018-05-07 11:37:22 -0700654 else:
655 lb_kwargs[const.VIP_NETWORK_ID] = cls.lb_member_vip_net[const.ID]
656 lb_kwargs[const.VIP_SUBNET_ID] = None
657
Gregory Thiemongeece5ab42020-10-29 08:46:05 +0100658 def _validate_listener_protocol(self, protocol, raise_if_unsupported=True):
659 if (protocol == const.SCTP and
660 not self.mem_listener_client.is_version_supported(
661 self.api_version, '2.23')):
662 if raise_if_unsupported:
663 raise self.skipException('SCTP listener protocol '
664 'is only available on Octavia '
665 'API version 2.23 or newer.')
666 return False
Gleb Zimin8dd3b782024-10-07 12:10:00 +0200667 if CONF.load_balancer.provider == 'tungstenfabric':
668 self.check_tf_compatibility(protocol=protocol)
Gregory Thiemongeece5ab42020-10-29 08:46:05 +0100669 return True
670
ibumarskovd17e3da2020-09-03 18:21:29 +0400671 @classmethod
672 def check_tf_compatibility(cls, protocol=None, algorithm=None):
673 # TungstenFabric supported protocols and algorithms
Ilya Bumarskov62a136d2021-02-03 16:16:42 +0400674 tf_protocols = [const.HTTP, const.HTTPS, const.TCP,
ibumarskovd17e3da2020-09-03 18:21:29 +0400675 const.TERMINATED_HTTPS]
676 tf_algorithms = [const.LB_ALGORITHM_ROUND_ROBIN,
677 const.LB_ALGORITHM_LEAST_CONNECTIONS,
678 const.LB_ALGORITHM_SOURCE_IP]
679
680 if algorithm and algorithm not in tf_algorithms:
681 raise cls.skipException(
682 'TungstenFabric does not support {} algorithm.'
683 ''.format(algorithm))
684 if protocol and protocol not in tf_protocols:
685 raise cls.skipException(
686 'TungstenFabric does not support {} protocol.'
687 ''.format(protocol))
688
689 @classmethod
690 def _tf_create_listener(cls, name, proto, port, lb_id):
691 listener_kwargs = {
692 const.NAME: name,
693 const.PROTOCOL: proto,
694 const.PROTOCOL_PORT: port,
695 const.LOADBALANCER_ID: lb_id,
696 }
697 listener = cls.mem_listener_client.create_listener(**listener_kwargs)
698 return listener
699
700 @classmethod
701 def _tf_get_free_port(cls, lb_id):
702 port = 8081
703 lb = cls.mem_lb_client.show_loadbalancer(lb_id)
704 listeners = lb[const.LISTENERS]
705 if not listeners:
706 return port
707 ports = [cls.mem_listener_client.show_listener(x[const.ID])[
708 const.PROTOCOL_PORT] for x in listeners]
709 while port in ports:
710 port = port + 1
711 return port
712
aarefievc3761ef2025-10-21 10:36:07 -0700713 @classmethod
714 def wait_for_status(cls, show_client, id, status_key, status,
715 check_interval, check_timeout,
716 root_tag=None, error_ok=False,
717 **kwargs):
718 try:
719 return waiters.wait_for_status(
720 show_client, id, status_key, status,
721 check_interval, check_timeout,
722 root_tag=root_tag,
723 error_ok=error_ok, **kwargs)
724 except exceptions.TimeoutException:
725 amphoras = cls.lb_admin_amphora_client.list_amphorae(
726 query_params='{loadbalancer_id}={lb_id}'.format(
727 loadbalancer_id=const.LOADBALANCER_ID, lb_id=id))
728 servers = [{'id': amp[const.COMPUTE_ID]} for amp in amphoras]
729 if servers and not CONF.compute_feature_enabled.console_output:
730 LOG.debug('Console output not supported, cannot log')
731 raise
732 for server in servers:
733 try:
734 output = cls.os_admin_servers_client.get_console_output(
735 server['id'], **kwargs)['output']
736 LOG.debug('Console output for %s\nbody=\n%s',
737 server['id'], output)
738 except exceptions.NotFound:
739 LOG.debug("Server %s disappeared(deleted) while looking "
740 "for the console log", server['id'])
741 raise
742
Adam Harwellcd72b562018-05-07 11:37:22 -0700743
744class LoadBalancerBaseTestWithCompute(LoadBalancerBaseTest):
745 @classmethod
Gregory Thiemongeb0da4f32022-02-04 08:58:06 +0100746 def remote_client_args(cls):
747 # In case we're using octavia-tempest-plugin with old tempest releases
748 # (for instance on stable/train) that don't support ssh_key_type, catch
749 # the exception and don't pass any argument
750 args = {}
751 try:
752 args['ssh_key_type'] = CONF.validation.ssh_key_type
753 except cfg.NoSuchOptError:
754 pass
755 return args
756
757 @classmethod
Adam Harwellcd72b562018-05-07 11:37:22 -0700758 def resource_setup(cls):
759 super(LoadBalancerBaseTestWithCompute, cls).resource_setup()
760 # If validation is disabled in this cloud, we won't be able to
761 # start the webservers, so don't even boot them.
762 if not CONF.validation.run_validation:
763 return
764
765 # Create a keypair for the webservers
766 keypair_name = data_utils.rand_name('lb_member_keypair')
767 result = cls.lb_mem_keypairs_client.create_keypair(
768 name=keypair_name)
769 cls.lb_member_keypair = result['keypair']
Michael Johnson77b8bae2024-11-08 01:39:29 +0000770 LOG.info('lb_member_keypair: %s', cls.lb_member_keypair)
Adam Harwellcd72b562018-05-07 11:37:22 -0700771 cls.addClassResourceCleanup(
772 waiters.wait_for_not_found,
773 cls.lb_mem_keypairs_client.delete_keypair,
774 cls.lb_mem_keypairs_client.show_keypair,
775 keypair_name)
776
777 if (CONF.load_balancer.enable_security_groups and
778 CONF.network_feature_enabled.port_security):
779 # Set up the security group for the webservers
780 SG_name = data_utils.rand_name('lb_member_SG')
781 cls.lb_member_sec_group = (
782 cls.lb_mem_SG_client.create_security_group(
783 name=SG_name)['security_group'])
784 cls.addClassResourceCleanup(
785 waiters.wait_for_not_found,
786 cls.lb_mem_SG_client.delete_security_group,
787 cls.lb_mem_SG_client.show_security_group,
788 cls.lb_member_sec_group['id'])
789
790 # Create a security group rule to allow 80-81 (test webservers)
791 SGr = cls.lb_mem_SGr_client.create_security_group_rule(
792 direction='ingress',
793 security_group_id=cls.lb_member_sec_group['id'],
794 protocol='tcp',
795 ethertype='IPv4',
796 port_range_min=80,
797 port_range_max=81)['security_group_rule']
798 cls.addClassResourceCleanup(
799 waiters.wait_for_not_found,
800 cls.lb_mem_SGr_client.delete_security_group_rule,
801 cls.lb_mem_SGr_client.show_security_group_rule,
802 SGr['id'])
Gregory Thiemonge29d17902019-04-30 15:06:17 +0200803 # Create a security group rule to allow UDP 80-81 (test webservers)
804 SGr = cls.lb_mem_SGr_client.create_security_group_rule(
805 direction='ingress',
806 security_group_id=cls.lb_member_sec_group['id'],
807 protocol='udp',
808 ethertype='IPv4',
809 port_range_min=80,
810 port_range_max=81)['security_group_rule']
811 cls.addClassResourceCleanup(
812 waiters.wait_for_not_found,
813 cls.lb_mem_SGr_client.delete_security_group_rule,
814 cls.lb_mem_SGr_client.show_security_group_rule,
815 SGr['id'])
Michael Johnson74b6f2f2020-10-29 15:11:39 -0700816 # Create a security group rule to allow 443 (test webservers)
817 SGr = cls.lb_mem_SGr_client.create_security_group_rule(
818 direction='ingress',
819 security_group_id=cls.lb_member_sec_group['id'],
820 protocol='tcp',
821 ethertype='IPv4',
822 port_range_min=443,
823 port_range_max=443)['security_group_rule']
824 cls.addClassResourceCleanup(
825 waiters.wait_for_not_found,
826 cls.lb_mem_SGr_client.delete_security_group_rule,
827 cls.lb_mem_SGr_client.show_security_group_rule,
828 SGr['id'])
Michael Johnson031ecca2020-10-29 16:45:32 -0700829 # Create a security group rule to allow 9443 (test webservers)
830 # Used in the pool backend encryption client authentication tests
831 SGr = cls.lb_mem_SGr_client.create_security_group_rule(
832 direction='ingress',
833 security_group_id=cls.lb_member_sec_group['id'],
834 protocol='tcp',
835 ethertype='IPv4',
836 port_range_min=9443,
837 port_range_max=9443)['security_group_rule']
838 cls.addClassResourceCleanup(
839 waiters.wait_for_not_found,
840 cls.lb_mem_SGr_client.delete_security_group_rule,
841 cls.lb_mem_SGr_client.show_security_group_rule,
842 SGr['id'])
Gregory Thiemonge29d17902019-04-30 15:06:17 +0200843 # Create a security group rule to allow UDP 9999 (test webservers)
844 # Port 9999 is used to illustrate health monitor ERRORs on closed
845 # ports.
846 SGr = cls.lb_mem_SGr_client.create_security_group_rule(
847 direction='ingress',
848 security_group_id=cls.lb_member_sec_group['id'],
849 protocol='udp',
850 ethertype='IPv4',
851 port_range_min=9999,
852 port_range_max=9999)['security_group_rule']
853 cls.addClassResourceCleanup(
854 waiters.wait_for_not_found,
855 cls.lb_mem_SGr_client.delete_security_group_rule,
856 cls.lb_mem_SGr_client.show_security_group_rule,
857 SGr['id'])
Adam Harwellcd72b562018-05-07 11:37:22 -0700858 # Create a security group rule to allow 22 (ssh)
859 SGr = cls.lb_mem_SGr_client.create_security_group_rule(
860 direction='ingress',
861 security_group_id=cls.lb_member_sec_group['id'],
862 protocol='tcp',
863 ethertype='IPv4',
864 port_range_min=22,
865 port_range_max=22)['security_group_rule']
866 cls.addClassResourceCleanup(
867 waiters.wait_for_not_found,
868 cls.lb_mem_SGr_client.delete_security_group_rule,
869 cls.lb_mem_SGr_client.show_security_group_rule,
870 SGr['id'])
871 if CONF.load_balancer.test_with_ipv6:
872 # Create a security group rule to allow 80-81 (test webservers)
873 SGr = cls.lb_mem_SGr_client.create_security_group_rule(
874 direction='ingress',
875 security_group_id=cls.lb_member_sec_group['id'],
876 protocol='tcp',
877 ethertype='IPv6',
878 port_range_min=80,
879 port_range_max=81)['security_group_rule']
880 cls.addClassResourceCleanup(
881 waiters.wait_for_not_found,
882 cls.lb_mem_SGr_client.delete_security_group_rule,
883 cls.lb_mem_SGr_client.show_security_group_rule,
884 SGr['id'])
Gregory Thiemonge29d17902019-04-30 15:06:17 +0200885 # Create a security group rule to allow UDP 80-81 (test
886 # webservers)
887 SGr = cls.lb_mem_SGr_client.create_security_group_rule(
888 direction='ingress',
889 security_group_id=cls.lb_member_sec_group['id'],
890 protocol='udp',
891 ethertype='IPv6',
892 port_range_min=80,
893 port_range_max=81)['security_group_rule']
894 cls.addClassResourceCleanup(
895 waiters.wait_for_not_found,
896 cls.lb_mem_SGr_client.delete_security_group_rule,
897 cls.lb_mem_SGr_client.show_security_group_rule,
898 SGr['id'])
Michael Johnson74b6f2f2020-10-29 15:11:39 -0700899 # Create a security group rule to allow 443 (test webservers)
900 SGr = cls.lb_mem_SGr_client.create_security_group_rule(
901 direction='ingress',
902 security_group_id=cls.lb_member_sec_group['id'],
903 protocol='tcp',
904 ethertype='IPv6',
905 port_range_min=443,
906 port_range_max=443)['security_group_rule']
907 cls.addClassResourceCleanup(
908 waiters.wait_for_not_found,
909 cls.lb_mem_SGr_client.delete_security_group_rule,
910 cls.lb_mem_SGr_client.show_security_group_rule,
911 SGr['id'])
Michael Johnson031ecca2020-10-29 16:45:32 -0700912 # Create a security group rule to allow 9443 (test webservers)
913 # Used in the pool encryption client authentication tests
914 SGr = cls.lb_mem_SGr_client.create_security_group_rule(
915 direction='ingress',
916 security_group_id=cls.lb_member_sec_group['id'],
917 protocol='tcp',
918 ethertype='IPv6',
919 port_range_min=9443,
920 port_range_max=9443)['security_group_rule']
921 cls.addClassResourceCleanup(
922 waiters.wait_for_not_found,
923 cls.lb_mem_SGr_client.delete_security_group_rule,
924 cls.lb_mem_SGr_client.show_security_group_rule,
925 SGr['id'])
Adam Harwellcd72b562018-05-07 11:37:22 -0700926 # Create a security group rule to allow 22 (ssh)
927 SGr = cls.lb_mem_SGr_client.create_security_group_rule(
928 direction='ingress',
929 security_group_id=cls.lb_member_sec_group['id'],
930 protocol='tcp',
931 ethertype='IPv6',
932 port_range_min=22,
933 port_range_max=22)['security_group_rule']
934 cls.addClassResourceCleanup(
935 waiters.wait_for_not_found,
936 cls.lb_mem_SGr_client.delete_security_group_rule,
937 cls.lb_mem_SGr_client.show_security_group_rule,
938 SGr['id'])
939
Michael Johnson77b8bae2024-11-08 01:39:29 +0000940 LOG.info('lb_member_sec_group: %s', cls.lb_member_sec_group)
Adam Harwellcd72b562018-05-07 11:37:22 -0700941
Michael Johnsonbaf12e02020-10-27 16:10:28 -0700942 # Setup backend member reencryption PKI
943 cls._create_backend_reencryption_pki()
944
Adam Harwellcd72b562018-05-07 11:37:22 -0700945 # Create webserver 1 instance
946 server_details = cls._create_webserver('lb_member_webserver1',
947 cls.lb_member_1_net)
948
949 cls.lb_member_webserver1 = server_details['server']
950 cls.webserver1_ip = server_details.get('ipv4_address')
951 cls.webserver1_ipv6 = server_details.get('ipv6_address')
952 cls.webserver1_public_ip = server_details['public_ipv4_address']
953
Michael Johnson77b8bae2024-11-08 01:39:29 +0000954 LOG.debug('Octavia Setup: lb_member_webserver1 = %s',
955 cls.lb_member_webserver1[const.ID])
956 LOG.debug('Octavia Setup: webserver1_ip = %s', cls.webserver1_ip)
957 LOG.debug('Octavia Setup: webserver1_ipv6 = %s', cls.webserver1_ipv6)
958 LOG.debug('Octavia Setup: webserver1_public_ip = %s',
959 cls.webserver1_public_ip)
Adam Harwellcd72b562018-05-07 11:37:22 -0700960
961 # Create webserver 2 instance
962 server_details = cls._create_webserver('lb_member_webserver2',
963 cls.lb_member_2_net)
964
965 cls.lb_member_webserver2 = server_details['server']
966 cls.webserver2_ip = server_details.get('ipv4_address')
967 cls.webserver2_ipv6 = server_details.get('ipv6_address')
968 cls.webserver2_public_ip = server_details['public_ipv4_address']
969
Michael Johnson77b8bae2024-11-08 01:39:29 +0000970 LOG.debug('Octavia Setup: lb_member_webserver2 = %s',
971 cls.lb_member_webserver2[const.ID])
972 LOG.debug('Octavia Setup: webserver2_ip = %s', cls.webserver2_ip)
973 LOG.debug('Octavia Setup: webserver2_ipv6 = %s', cls.webserver2_ipv6)
974 LOG.debug('Octavia Setup: webserver2_public_ip = %s',
975 cls.webserver2_public_ip)
Adam Harwellcd72b562018-05-07 11:37:22 -0700976
Ilya Bumarskoveff9bae2023-03-16 14:12:09 +0400977 if (CONF.load_balancer.test_with_ipv6 and not
Gleb Zimin64613402023-11-22 13:06:14 +0100978 config.is_tungstenfabric_backend_enabled()):
Michael Johnsonbf916df2018-10-17 10:59:28 -0700979 # Enable the IPv6 nic in webserver 1
980 cls._enable_ipv6_nic_webserver(
981 cls.webserver1_public_ip, cls.lb_member_keypair['private_key'],
982 cls.webserver1_ipv6, cls.lb_member_1_subnet_prefix)
983
984 # Enable the IPv6 nic in webserver 2
985 cls._enable_ipv6_nic_webserver(
986 cls.webserver2_public_ip, cls.lb_member_keypair['private_key'],
987 cls.webserver2_ipv6, cls.lb_member_2_subnet_prefix)
988
Adam Harwellcd72b562018-05-07 11:37:22 -0700989 # Set up serving on webserver 1
990 cls._install_start_webserver(cls.webserver1_public_ip,
Adam Harwelle029af22018-05-24 17:13:28 -0700991 cls.lb_member_keypair['private_key'],
992 cls.webserver1_response)
Adam Harwellcd72b562018-05-07 11:37:22 -0700993
994 # Validate webserver 1
Adam Harwelle029af22018-05-24 17:13:28 -0700995 cls._validate_webserver(cls.webserver1_public_ip,
996 cls.webserver1_response)
Adam Harwellcd72b562018-05-07 11:37:22 -0700997
Gregory Thiemonge29d17902019-04-30 15:06:17 +0200998 # Validate udp server 1
999 cls._validate_udp_server(cls.webserver1_public_ip,
1000 cls.webserver1_response)
1001
Adam Harwellcd72b562018-05-07 11:37:22 -07001002 # Set up serving on webserver 2
1003 cls._install_start_webserver(cls.webserver2_public_ip,
Adam Harwelle029af22018-05-24 17:13:28 -07001004 cls.lb_member_keypair['private_key'],
Michael Johnsonbaf12e02020-10-27 16:10:28 -07001005 cls.webserver2_response, revoke_cert=True)
Adam Harwellcd72b562018-05-07 11:37:22 -07001006
1007 # Validate webserver 2
Adam Harwelle029af22018-05-24 17:13:28 -07001008 cls._validate_webserver(cls.webserver2_public_ip,
1009 cls.webserver2_response)
Adam Harwellcd72b562018-05-07 11:37:22 -07001010
Gregory Thiemonge29d17902019-04-30 15:06:17 +02001011 # Validate udp server 2
1012 cls._validate_udp_server(cls.webserver2_public_ip,
1013 cls.webserver2_response)
1014
Adam Harwellcd72b562018-05-07 11:37:22 -07001015 @classmethod
1016 def _create_networks(cls):
1017 super(LoadBalancerBaseTestWithCompute, cls)._create_networks()
Jude Cross986e3f52017-07-24 14:57:20 -07001018 # Create a router for the subnets (required for the floating IP)
1019 router_name = data_utils.rand_name("lb_member_router")
1020 result = cls.lb_mem_routers_client.create_router(
1021 name=router_name, admin_state_up=True,
1022 external_gateway_info=dict(
1023 network_id=CONF.network.public_network_id))
1024 cls.lb_member_router = result['router']
Michael Johnson77b8bae2024-11-08 01:39:29 +00001025 LOG.info('lb_member_router: %s', cls.lb_member_router)
Jude Cross986e3f52017-07-24 14:57:20 -07001026 cls.addClassResourceCleanup(
1027 waiters.wait_for_not_found,
1028 cls.lb_mem_routers_client.delete_router,
1029 cls.lb_mem_routers_client.show_router,
1030 cls.lb_member_router['id'])
1031
1032 # Add VIP subnet to router
1033 cls.lb_mem_routers_client.add_router_interface(
1034 cls.lb_member_router['id'],
1035 subnet_id=cls.lb_member_vip_subnet['id'])
1036 cls.addClassResourceCleanup(
1037 waiters.wait_for_not_found,
1038 cls.lb_mem_routers_client.remove_router_interface,
1039 cls.lb_mem_routers_client.remove_router_interface,
1040 cls.lb_member_router['id'],
1041 subnet_id=cls.lb_member_vip_subnet['id'])
1042
Gregory Thiemonge54225ad2021-02-04 15:25:17 +01001043 if (CONF.load_balancer.test_with_ipv6 and
1044 CONF.load_balancer.default_router and
1045 cls.lb_member_vip_ipv6_subnet_use_subnetpool):
1046
1047 router_name = CONF.load_balancer.default_router
1048 # if lb_member_vip_ipv6_subnet uses devstack's subnetpool,
1049 # plug the subnet into the default router
1050 router = cls.os_admin.routers_client.list_routers(
1051 name=router_name)['routers']
1052
1053 if len(router) == 1:
1054 router = router[0]
1055
1056 # Add IPv6 VIP subnet to router1
1057 cls.os_admin_routers_client.add_router_interface(
1058 router['id'],
1059 subnet_id=cls.lb_member_vip_ipv6_subnet['id'])
1060 cls.addClassResourceCleanup(
1061 waiters.wait_for_not_found,
1062 cls.os_admin_routers_client.remove_router_interface,
1063 cls.os_admin_routers_client.remove_router_interface,
1064 router['id'],
1065 subnet_id=cls.lb_member_vip_ipv6_subnet['id'])
1066
Jude Cross986e3f52017-07-24 14:57:20 -07001067 # Add member subnet 1 to router
1068 cls.lb_mem_routers_client.add_router_interface(
1069 cls.lb_member_router['id'],
1070 subnet_id=cls.lb_member_1_subnet['id'])
1071 cls.addClassResourceCleanup(
1072 waiters.wait_for_not_found,
Jude Cross986e3f52017-07-24 14:57:20 -07001073 cls.lb_mem_routers_client.remove_router_interface,
1074 cls.lb_mem_routers_client.remove_router_interface,
1075 cls.lb_member_router['id'], subnet_id=cls.lb_member_1_subnet['id'])
1076
1077 # Add member subnet 2 to router
1078 cls.lb_mem_routers_client.add_router_interface(
1079 cls.lb_member_router['id'],
1080 subnet_id=cls.lb_member_2_subnet['id'])
1081 cls.addClassResourceCleanup(
1082 waiters.wait_for_not_found,
1083 cls.lb_mem_routers_client.remove_router_interface,
1084 cls.lb_mem_routers_client.remove_router_interface,
1085 cls.lb_member_router['id'], subnet_id=cls.lb_member_2_subnet['id'])
1086
1087 @classmethod
1088 def _create_webserver(cls, name, network):
1089 """Creates a webserver with two ports.
1090
1091 webserver_details dictionary contains:
1092 server - The compute server object
1093 ipv4_address - The IPv4 address for the server (optional)
1094 ipv6_address - The IPv6 address for the server (optional)
1095 public_ipv4_address - The publicly accessible IPv4 address for the
1096 server, this may be a floating IP (optional)
1097
1098 :param name: The name of the server to create.
1099 :param network: The network to boot the server on.
1100 :returns: webserver_details dictionary.
1101 """
1102 server_kwargs = {
1103 'name': data_utils.rand_name(name),
1104 'flavorRef': CONF.compute.flavor_ref,
1105 'imageRef': CONF.compute.image_ref,
1106 'key_name': cls.lb_member_keypair['name']}
1107 if (CONF.load_balancer.enable_security_groups and
1108 CONF.network_feature_enabled.port_security):
1109 server_kwargs['security_groups'] = [
1110 {'name': cls.lb_member_sec_group['name']}]
1111 if not CONF.load_balancer.disable_boot_network:
1112 server_kwargs['networks'] = [{'uuid': network['id']}]
1113
1114 # Replace the name for clouds that have limitations
1115 if CONF.load_balancer.random_server_name_length:
1116 r = random.SystemRandom()
1117 server_kwargs['name'] = "m{}".format("".join(
1118 [r.choice(string.ascii_uppercase + string.digits)
1119 for _ in range(
1120 CONF.load_balancer.random_server_name_length - 1)]
1121 ))
1122 if CONF.load_balancer.availability_zone:
1123 server_kwargs['availability_zone'] = (
1124 CONF.load_balancer.availability_zone)
1125
1126 server = cls.lb_mem_servers_client.create_server(
1127 **server_kwargs)['server']
1128 cls.addClassResourceCleanup(
1129 waiters.wait_for_not_found,
1130 cls.lb_mem_servers_client.delete_server,
1131 cls.lb_mem_servers_client.show_server,
1132 server['id'])
1133 server = waiters.wait_for_status(
1134 cls.lb_mem_servers_client.show_server,
1135 server['id'], 'status', 'ACTIVE',
1136 CONF.load_balancer.build_interval,
1137 CONF.load_balancer.build_timeout,
1138 root_tag='server')
1139 webserver_details = {'server': server}
Michael Johnson77b8bae2024-11-08 01:39:29 +00001140 LOG.info('Created server: %s', server)
Jude Cross986e3f52017-07-24 14:57:20 -07001141
1142 addresses = server['addresses']
1143 if CONF.load_balancer.disable_boot_network:
1144 instance_network = addresses.values()[0]
1145 else:
1146 instance_network = addresses[network['name']]
1147 for addr in instance_network:
1148 if addr['version'] == 4:
1149 webserver_details['ipv4_address'] = addr['addr']
1150 if addr['version'] == 6:
1151 webserver_details['ipv6_address'] = addr['addr']
1152
1153 if CONF.validation.connect_method == 'floating':
1154 result = cls.lb_mem_ports_client.list_ports(
1155 network_id=network['id'],
1156 mac_address=instance_network[0]['OS-EXT-IPS-MAC:mac_addr'])
1157 port_id = result['ports'][0]['id']
Gleb Zimin64613402023-11-22 13:06:14 +01001158 if config.is_tungstenfabric_backend_enabled():
Ilya Bumarskoveff9bae2023-03-16 14:12:09 +04001159 port = result['ports'][0]
1160 fixed_ip = None
1161 for ip in port["fixed_ips"]:
1162 if (type(ipaddress.ip_address(ip["ip_address"])) is
1163 ipaddress.IPv4Address):
1164 fixed_ip = ip["ip_address"]
1165 break
1166 assert fixed_ip is not None, (f"Port doesn't have ipv4 "
1167 f"address: {port['fixed_ips']}")
1168 result = cls.lb_mem_float_ip_client.create_floatingip(
1169 floating_network_id=CONF.network.public_network_id,
1170 port_id=port_id,
1171 fixed_ip_address=fixed_ip)
1172 else:
1173 result = cls.lb_mem_float_ip_client.create_floatingip(
1174 floating_network_id=CONF.network.public_network_id,
1175 port_id=port_id)
Jude Cross986e3f52017-07-24 14:57:20 -07001176 floating_ip = result['floatingip']
Michael Johnson77b8bae2024-11-08 01:39:29 +00001177 LOG.info('webserver1_floating_ip: %s', floating_ip)
Jude Cross986e3f52017-07-24 14:57:20 -07001178 cls.addClassResourceCleanup(
1179 waiters.wait_for_not_found,
1180 cls.lb_mem_float_ip_client.delete_floatingip,
1181 cls.lb_mem_float_ip_client.show_floatingip,
1182 floatingip_id=floating_ip['id'])
1183 webserver_details['public_ipv4_address'] = (
1184 floating_ip['floating_ip_address'])
1185 else:
1186 webserver_details['public_ipv4_address'] = (
1187 instance_network[0]['addr'])
1188
1189 return webserver_details
1190
1191 @classmethod
Gregory Thiemongea2c234e2021-11-02 17:08:29 +01001192 def _get_openssh_version(cls):
1193 p = subprocess.Popen(["ssh", "-V"],
1194 stdout=subprocess.PIPE,
1195 stderr=subprocess.PIPE)
1196 output = p.communicate()[1]
1197
1198 try:
1199 m = re.match(r"OpenSSH_(\d+)\.(\d+)", output.decode('utf-8'))
1200 version_maj = int(m.group(1))
1201 version_min = int(m.group(2))
1202 return version_maj, version_min
1203 except Exception:
1204 return None, None
1205
1206 @classmethod
1207 def _need_scp_protocol(cls):
1208 # When using scp >= 8.7, force the use of the SCP protocol,
1209 # the new default (SFTP protocol) doesn't work with
1210 # cirros VMs.
1211 ssh_version = cls._get_openssh_version()
Michael Johnson77b8bae2024-11-08 01:39:29 +00001212 LOG.debug("ssh_version = %s", ssh_version)
Gregory Thiemongea2c234e2021-11-02 17:08:29 +01001213 return (ssh_version[0] > 8 or
1214 (ssh_version[0] == 8 and ssh_version[1] >= 7))
1215
1216 @classmethod
Michael Johnsonbaf12e02020-10-27 16:10:28 -07001217 def _install_start_webserver(cls, ip_address, ssh_key, start_id,
1218 revoke_cert=False):
Michael Johnson27357352020-11-13 13:55:09 -08001219 local_file = CONF.load_balancer.test_server_path
Adam Harwellcd72b562018-05-07 11:37:22 -07001220
1221 linux_client = remote_client.RemoteClient(
Ade Leed0ea4062021-09-06 15:33:27 -04001222 ip_address, CONF.validation.image_ssh_user, pkey=ssh_key,
Gregory Thiemongeb0da4f32022-02-04 08:58:06 +01001223 **cls.remote_client_args())
Adam Harwellcd72b562018-05-07 11:37:22 -07001224 linux_client.validate_authentication()
1225
1226 with tempfile.NamedTemporaryFile() as key:
1227 key.write(ssh_key.encode('utf-8'))
1228 key.flush()
Gregory Thiemongea2c234e2021-11-02 17:08:29 +01001229 ssh_extra_args = (
1230 "-o PubkeyAcceptedKeyTypes=+ssh-rsa")
1231 if cls._need_scp_protocol():
1232 ssh_extra_args += " -O"
Adam Harwellcd72b562018-05-07 11:37:22 -07001233 cmd = ("scp -v -o UserKnownHostsFile=/dev/null "
Gregory Thiemongea2c234e2021-11-02 17:08:29 +01001234 "{7} "
Adam Harwellcd72b562018-05-07 11:37:22 -07001235 "-o StrictHostKeyChecking=no "
1236 "-o ConnectTimeout={0} -o ConnectionAttempts={1} "
1237 "-i {2} {3} {4}@{5}:{6}").format(
1238 CONF.load_balancer.scp_connection_timeout,
1239 CONF.load_balancer.scp_connection_attempts,
1240 key.name, local_file, CONF.validation.image_ssh_user,
Gregory Thiemongea2c234e2021-11-02 17:08:29 +01001241 ip_address, const.TEST_SERVER_BINARY,
1242 ssh_extra_args)
Adam Harwellcd72b562018-05-07 11:37:22 -07001243 args = shlex.split(cmd)
1244 subprocess_args = {'stdout': subprocess.PIPE,
1245 'stderr': subprocess.STDOUT,
1246 'cwd': None}
1247 proc = subprocess.Popen(args, **subprocess_args)
1248 stdout, stderr = proc.communicate()
1249 if proc.returncode != 0:
1250 raise exceptions.CommandFailed(proc.returncode, cmd,
1251 stdout, stderr)
Gregory Thiemongef72a8862019-08-06 17:25:42 +02001252
Michael Johnsonbaf12e02020-10-27 16:10:28 -07001253 cls._load_member_pki_content(ip_address, key,
1254 revoke_cert=revoke_cert)
1255
Gregory Thiemongef72a8862019-08-06 17:25:42 +02001256 # Enabling memory overcommit allows to run golang static binaries
1257 # compiled with a recent golang toolchain (>=1.11). Those binaries
1258 # allocate a large amount of virtual memory at init time, and this
1259 # allocation fails in tempest's nano flavor (64MB of RAM)
1260 # (golang issue reported in https://github.com/golang/go/issues/28114,
1261 # follow-up: https://github.com/golang/go/issues/28081)
1262 # TODO(gthiemonge): Remove this call when golang issue is resolved.
1263 linux_client.exec_command('sudo sh -c "echo 1 > '
1264 '/proc/sys/vm/overcommit_memory"')
1265
Michael Johnsonbaf12e02020-10-27 16:10:28 -07001266 # The initial process also supports HTTPS and HTTPS with client auth
1267 linux_client.exec_command(
1268 'sudo screen -d -m {0} -port 80 -id {1} -https_port 443 -cert {2} '
1269 '-key {3} -https_client_auth_port 9443 -client_ca {4}'.format(
1270 const.TEST_SERVER_BINARY, start_id, const.TEST_SERVER_CERT,
1271 const.TEST_SERVER_KEY, const.TEST_SERVER_CLIENT_CA))
1272
Adam Harwellcd72b562018-05-07 11:37:22 -07001273 linux_client.exec_command('sudo screen -d -m {0} -port 81 '
Michael Johnsonbaf12e02020-10-27 16:10:28 -07001274 '-id {1}'.format(const.TEST_SERVER_BINARY,
1275 start_id + 1))
Adam Harwellcd72b562018-05-07 11:37:22 -07001276
Michael Johnsonbf916df2018-10-17 10:59:28 -07001277 # Cirros does not configure the assigned IPv6 address by default
1278 # so enable it manually like tempest does here:
1279 # tempest/scenario/test_netowrk_v6.py turn_nic6_on()
1280 @classmethod
1281 def _enable_ipv6_nic_webserver(cls, ip_address, ssh_key,
1282 ipv6_address, ipv6_prefix):
1283 linux_client = remote_client.RemoteClient(
Ade Leed0ea4062021-09-06 15:33:27 -04001284 ip_address, CONF.validation.image_ssh_user, pkey=ssh_key,
Gregory Thiemongeb0da4f32022-02-04 08:58:06 +01001285 **cls.remote_client_args())
Michael Johnsonbf916df2018-10-17 10:59:28 -07001286 linux_client.validate_authentication()
1287
1288 linux_client.exec_command('sudo ip address add {0}/{1} dev '
1289 'eth0'.format(ipv6_address, ipv6_prefix))
1290
Adam Harwellcd72b562018-05-07 11:37:22 -07001291 @classmethod
Jude Cross986e3f52017-07-24 14:57:20 -07001292 def _validate_webserver(cls, ip_address, start_id):
1293 URL = 'http://{0}'.format(ip_address)
Michael Johnson89bdbcd2020-03-19 15:59:19 -07001294 cls.validate_URL_response(URL, expected_body=str(start_id))
Jude Cross986e3f52017-07-24 14:57:20 -07001295 URL = 'http://{0}:81'.format(ip_address)
Michael Johnson89bdbcd2020-03-19 15:59:19 -07001296 cls.validate_URL_response(URL, expected_body=str(start_id + 1))
Jude Cross986e3f52017-07-24 14:57:20 -07001297
Gregory Thiemonge29d17902019-04-30 15:06:17 +02001298 @classmethod
1299 def _validate_udp_server(cls, ip_address, start_id):
Michael Johnson89bdbcd2020-03-19 15:59:19 -07001300 res = cls.make_udp_request(ip_address, 80)
Gregory Thiemonge29d17902019-04-30 15:06:17 +02001301 if res != str(start_id):
1302 raise Exception("Response from test server doesn't match the "
1303 "expected value ({0} != {1}).".format(
1304 res, str(start_id)))
1305
Michael Johnson89bdbcd2020-03-19 15:59:19 -07001306 res = cls.make_udp_request(ip_address, 81)
Gregory Thiemonge29d17902019-04-30 15:06:17 +02001307 if res != str(start_id + 1):
1308 raise Exception("Response from test server doesn't match the "
1309 "expected value ({0} != {1}).".format(
1310 res, str(start_id + 1)))
Michael Johnsonbaf12e02020-10-27 16:10:28 -07001311
1312 @classmethod
1313 def _create_backend_reencryption_pki(cls):
1314 # Create a CA self-signed cert and key for the member test servers
1315 cls.member_ca_cert, cls.member_ca_key = (
1316 cert_utils.generate_ca_cert_and_key())
1317
1318 LOG.debug('Member CA Cert: %s', cls.member_ca_cert.public_bytes(
1319 serialization.Encoding.PEM))
1320 LOG.debug('Member CA private Key: %s', cls.member_ca_key.private_bytes(
1321 encoding=serialization.Encoding.PEM,
1322 format=serialization.PrivateFormat.TraditionalOpenSSL,
1323 encryption_algorithm=serialization.NoEncryption()))
1324 LOG.debug('Member CA public Key: %s',
1325 cls.member_ca_key.public_key().public_bytes(
1326 encoding=serialization.Encoding.PEM,
1327 format=serialization.PublicFormat.SubjectPublicKeyInfo))
1328
1329 # Create the member client authentication CA
1330 cls.member_client_ca_cert, member_client_ca_key = (
1331 cert_utils.generate_ca_cert_and_key())
1332
1333 # Create client cert and key
1334 cls.member_client_cn = uuidutils.generate_uuid()
1335 cls.member_client_cert, cls.member_client_key = (
1336 cert_utils.generate_client_cert_and_key(
1337 cls.member_client_ca_cert, member_client_ca_key,
1338 cls.member_client_cn))
1339 # Note: We are not revoking a client cert here as we don't need to
1340 # test the backend web server CRL checking.
1341
1342 @classmethod
1343 def _load_member_pki_content(cls, ip_address, ssh_key, revoke_cert=False):
1344 # Create webserver certificate and key
1345 cert, key = cert_utils.generate_server_cert_and_key(
1346 cls.member_ca_cert, cls.member_ca_key, ip_address)
1347
1348 LOG.debug('%s Cert: %s', ip_address, cert.public_bytes(
1349 serialization.Encoding.PEM))
1350 LOG.debug('%s private Key: %s', ip_address, key.private_bytes(
1351 encoding=serialization.Encoding.PEM,
1352 format=serialization.PrivateFormat.TraditionalOpenSSL,
1353 encryption_algorithm=serialization.NoEncryption()))
1354 public_key = key.public_key()
1355 LOG.debug('%s public Key: %s', ip_address, public_key.public_bytes(
1356 encoding=serialization.Encoding.PEM,
1357 format=serialization.PublicFormat.SubjectPublicKeyInfo))
1358
1359 # Create a CRL with a revoked certificate
1360 if revoke_cert:
1361 # Create a CRL with webserver 2 revoked
1362 cls.member_crl = cert_utils.generate_certificate_revocation_list(
1363 cls.member_ca_cert, cls.member_ca_key, cert)
1364
1365 # Load the certificate, key, and client CA certificate into the
1366 # test server.
1367 with tempfile.TemporaryDirectory() as tmpdir:
1368 os.umask(0)
1369 files_to_send = []
1370 cert_filename = os.path.join(tmpdir, const.CERT_PEM)
1371 files_to_send.append(cert_filename)
1372 with open(os.open(cert_filename, os.O_CREAT | os.O_WRONLY,
1373 0o700), 'w') as fh:
1374 fh.write(cert.public_bytes(
1375 serialization.Encoding.PEM).decode('utf-8'))
1376 fh.flush()
1377 key_filename = os.path.join(tmpdir, const.KEY_PEM)
1378 files_to_send.append(key_filename)
1379 with open(os.open(key_filename, os.O_CREAT | os.O_WRONLY,
1380 0o700), 'w') as fh:
1381 fh.write(key.private_bytes(
1382 encoding=serialization.Encoding.PEM,
1383 format=serialization.PrivateFormat.TraditionalOpenSSL,
1384 encryption_algorithm=serialization.NoEncryption()).decode(
1385 'utf-8'))
1386 fh.flush()
1387 client_ca_filename = os.path.join(tmpdir, const.CLIENT_CA_PEM)
1388 files_to_send.append(client_ca_filename)
1389 with open(os.open(client_ca_filename, os.O_CREAT | os.O_WRONLY,
1390 0o700), 'w') as fh:
1391 fh.write(cls.member_client_ca_cert.public_bytes(
1392 serialization.Encoding.PEM).decode('utf-8'))
1393 fh.flush()
1394
1395 # For security, we don't want to use a shell that can glob
1396 # the file names, so iterate over them.
1397 subprocess_args = {'stdout': subprocess.PIPE,
1398 'stderr': subprocess.STDOUT,
1399 'cwd': None}
Gregory Thiemongea2c234e2021-11-02 17:08:29 +01001400 ssh_extra_args = (
1401 "-o PubkeyAcceptedKeyTypes=+ssh-rsa")
1402 if cls._need_scp_protocol():
1403 ssh_extra_args += " -O"
Michael Johnsonbaf12e02020-10-27 16:10:28 -07001404 cmd = ("scp -v -o UserKnownHostsFile=/dev/null "
Gregory Thiemongea2c234e2021-11-02 17:08:29 +01001405 "{9} "
Michael Johnsonbaf12e02020-10-27 16:10:28 -07001406 "-o StrictHostKeyChecking=no "
1407 "-o ConnectTimeout={0} -o ConnectionAttempts={1} "
1408 "-i {2} {3} {4} {5} {6}@{7}:{8}").format(
1409 CONF.load_balancer.scp_connection_timeout,
1410 CONF.load_balancer.scp_connection_attempts,
1411 ssh_key.name, cert_filename, key_filename, client_ca_filename,
Gregory Thiemongea2c234e2021-11-02 17:08:29 +01001412 CONF.validation.image_ssh_user, ip_address, const.DEV_SHM_PATH,
1413 ssh_extra_args)
Michael Johnsonbaf12e02020-10-27 16:10:28 -07001414 args = shlex.split(cmd)
1415 proc = subprocess.Popen(args, **subprocess_args)
1416 stdout, stderr = proc.communicate()
1417 if proc.returncode != 0:
1418 raise exceptions.CommandFailed(proc.returncode, cmd,
1419 stdout, stderr)