Matthew Treinish | a970d65 | 2015-03-11 15:39:24 -0400 | [diff] [blame] | 1 | .. _tempest-configuration: |
| 2 | |
Matthew Treinish | bc1b15b | 2015-02-20 15:56:07 -0500 | [diff] [blame] | 3 | Tempest Configuration Guide |
| 4 | =========================== |
| 5 | |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 6 | This guide is a starting point for configuring Tempest. It aims to elaborate |
Matthew Treinish | f640f66 | 2015-03-11 15:13:30 -0400 | [diff] [blame] | 7 | on and explain some of the mandatory and common configuration settings and how |
| 8 | they are used in conjunction. The source of truth on each option is the sample |
Matthew Treinish | f45ba2e | 2015-08-24 15:05:01 -0400 | [diff] [blame] | 9 | config file which explains the purpose of each individual option. You can see |
| 10 | the sample config file here: :ref:`tempest-sampleconf` |
Matthew Treinish | f640f66 | 2015-03-11 15:13:30 -0400 | [diff] [blame] | 11 | |
Andrea Frittoli (andreaf) | dd25070 | 2016-04-29 15:01:22 -0500 | [diff] [blame] | 12 | Test Credentials |
Matthew Treinish | bc1b15b | 2015-02-20 15:56:07 -0500 | [diff] [blame] | 13 | ---------------- |
| 14 | |
Andrea Frittoli (andreaf) | dd25070 | 2016-04-29 15:01:22 -0500 | [diff] [blame] | 15 | Tempest allows for configuring a set of admin credentials in the ``auth`` |
| 16 | section, via the following parameters: |
Matthew Treinish | bc1b15b | 2015-02-20 15:56:07 -0500 | [diff] [blame] | 17 | |
Andrea Frittoli (andreaf) | dd25070 | 2016-04-29 15:01:22 -0500 | [diff] [blame] | 18 | #. ``admin_username`` |
| 19 | #. ``admin_password`` |
| 20 | #. ``admin_project_name`` |
| 21 | #. ``admin_domain_name`` |
| 22 | |
| 23 | Admin credentials are not mandatory to run Tempest, but when provided they |
| 24 | can be used to: |
| 25 | |
| 26 | - Run tests for admin APIs |
| 27 | - Generate test credentials on the fly (see `Dynamic Credentials`_) |
| 28 | |
Andrea Frittoli (andreaf) | 100d18d | 2016-05-05 23:34:52 +0100 | [diff] [blame] | 29 | When keystone uses a policy that requires domain scoped tokens for admin |
| 30 | actions, the flag ``admin_domain_scope`` must be set to ``True``. |
| 31 | The admin user configured, if any, must have a role assigned to the domain to |
| 32 | be usable. |
| 33 | |
Andrea Frittoli (andreaf) | dd25070 | 2016-04-29 15:01:22 -0500 | [diff] [blame] | 34 | Tempest allows for configuring pre-provisioned test credentials as well. |
Matthew Treinish | 40847ac | 2016-01-04 13:16:03 -0500 | [diff] [blame] | 35 | This can be done using the accounts.yaml file (see |
Andrea Frittoli (andreaf) | dd25070 | 2016-04-29 15:01:22 -0500 | [diff] [blame] | 36 | `Pre-Provisioned Credentials`_). This file is used to specify an arbitrary |
| 37 | number of users available to run tests with. |
| 38 | You can specify the location of the file in the ``auth`` section in the |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 39 | tempest.conf file. To see the specific format used in the file please refer to |
Andrea Frittoli (andreaf) | dd25070 | 2016-04-29 15:01:22 -0500 | [diff] [blame] | 40 | the accounts.yaml.sample file included in Tempest. |
| 41 | |
Matthew Treinish | 7909e12 | 2015-04-15 15:43:50 -0400 | [diff] [blame] | 42 | Keystone Connection Info |
| 43 | ^^^^^^^^^^^^^^^^^^^^^^^^ |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 44 | In order for Tempest to be able to talk to your OpenStack deployment you need |
Matthew Treinish | 7909e12 | 2015-04-15 15:43:50 -0400 | [diff] [blame] | 45 | to provide it with information about how it communicates with keystone. |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 46 | This involves configuring the following options in the ``identity`` section: |
Matthew Treinish | 7909e12 | 2015-04-15 15:43:50 -0400 | [diff] [blame] | 47 | |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 48 | #. ``auth_version`` |
| 49 | #. ``uri`` |
| 50 | #. ``uri_v3`` |
Matthew Treinish | 7909e12 | 2015-04-15 15:43:50 -0400 | [diff] [blame] | 51 | |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 52 | The ``auth_version`` option is used to tell Tempest whether it should be using |
Matthew Treinish | 7909e12 | 2015-04-15 15:43:50 -0400 | [diff] [blame] | 53 | keystone's v2 or v3 api for communicating with keystone. (except for the |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 54 | identity api tests which will test a specific version) The two uri options are |
| 55 | used to tell Tempest the url of the keystone endpoint. The ``uri`` option is |
| 56 | used for keystone v2 request and ``uri_v3`` is used for keystone v3. You want to |
| 57 | ensure that which ever version you set for ``auth_version`` has its uri option |
| 58 | defined. |
Matthew Treinish | 7909e12 | 2015-04-15 15:43:50 -0400 | [diff] [blame] | 59 | |
| 60 | |
Matthew Treinish | bc1b15b | 2015-02-20 15:56:07 -0500 | [diff] [blame] | 61 | Credential Provider Mechanisms |
| 62 | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ |
| 63 | |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 64 | Tempest currently also has three different internal methods for providing |
| 65 | authentication to tests: dynamic credentials, locking test accounts, and |
Matthew Treinish | bc1b15b | 2015-02-20 15:56:07 -0500 | [diff] [blame] | 66 | non-locking test accounts. Depending on which one is in use the configuration |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 67 | of Tempest is slightly different. |
Matthew Treinish | bc1b15b | 2015-02-20 15:56:07 -0500 | [diff] [blame] | 68 | |
Andrea Frittoli (andreaf) | 17209bb | 2015-05-22 10:16:57 -0700 | [diff] [blame] | 69 | Dynamic Credentials |
| 70 | """"""""""""""""""" |
| 71 | Dynamic Credentials (formerly known as Tenant isolation) was originally created |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 72 | to enable running Tempest in parallel. For each test class it creates a unique |
| 73 | set of user credentials to use for the tests in the class. It can create up to |
Sean Dague | ed6e586 | 2016-04-04 10:49:13 -0400 | [diff] [blame] | 74 | three sets of username, password, and project names for a primary user, |
| 75 | an admin user, and an alternate user. To enable and use dynamic credentials you |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 76 | only need to configure two things: |
Matthew Treinish | bc1b15b | 2015-02-20 15:56:07 -0500 | [diff] [blame] | 77 | |
| 78 | #. A set of admin credentials with permissions to create users and |
Sean Dague | ed6e586 | 2016-04-04 10:49:13 -0400 | [diff] [blame] | 79 | projects. This is specified in the ``auth`` section with the |
| 80 | ``admin_username``, ``admin_project_name``, ``admin_domain_name`` and |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 81 | ``admin_password`` options |
| 82 | #. To enable dynamic credentials in the ``auth`` section with the |
| 83 | ``use_dynamic_credentials`` option. |
Matthew Treinish | bc1b15b | 2015-02-20 15:56:07 -0500 | [diff] [blame] | 84 | |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 85 | This is also currently the default credential provider enabled by Tempest, due |
| 86 | to its common use and ease of configuration. |
Matthew Treinish | bc1b15b | 2015-02-20 15:56:07 -0500 | [diff] [blame] | 87 | |
Matthew Treinish | 4fae472 | 2015-04-16 21:03:54 -0400 | [diff] [blame] | 88 | It is worth pointing out that depending on your cloud configuration you might |
Andrea Frittoli (andreaf) | 17209bb | 2015-05-22 10:16:57 -0700 | [diff] [blame] | 89 | need to assign a role to each of the users created by Tempest's dynamic |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 90 | credentials. This can be set using the ``tempest_roles`` option. It takes in a |
| 91 | list of role names each of which will be assigned to each of the users created |
| 92 | by dynamic credentials. This option will not have any effect when Tempest is not |
Andrea Frittoli (andreaf) | 17209bb | 2015-05-22 10:16:57 -0700 | [diff] [blame] | 93 | configured to use dynamic credentials. |
Matthew Treinish | 4fae472 | 2015-04-16 21:03:54 -0400 | [diff] [blame] | 94 | |
Andrea Frittoli (andreaf) | 100d18d | 2016-05-05 23:34:52 +0100 | [diff] [blame] | 95 | When the ``admin_domain_scope`` option is set to ``True``, provisioned admin |
| 96 | accounts will be assigned a role on domain configured in |
| 97 | ``default_credentials_domain_name``. This will make the accounts provisioned |
| 98 | usable in a cloud where domain scoped tokens are required by keystone for |
| 99 | admin operations. Note that the the initial pre-provision admin accounts, |
| 100 | configured in tempest.conf, must have a role on the same domain as well, for |
| 101 | Dynamic Credentials to work. |
| 102 | |
Matthew Treinish | 4fae472 | 2015-04-16 21:03:54 -0400 | [diff] [blame] | 103 | |
Andrea Frittoli (andreaf) | dd25070 | 2016-04-29 15:01:22 -0500 | [diff] [blame] | 104 | Pre-Provisioned Credentials |
| 105 | """"""""""""""""""""""""""" |
| 106 | |
Andrea Frittoli (andreaf) | 17209bb | 2015-05-22 10:16:57 -0700 | [diff] [blame] | 107 | For a long time using dynamic credentials was the only method available if you |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 108 | wanted to enable parallel execution of Tempest tests. However, this was |
Matthew Treinish | bc1b15b | 2015-02-20 15:56:07 -0500 | [diff] [blame] | 109 | insufficient for certain use cases because of the admin credentials requirement |
| 110 | to create the credential sets on demand. To get around that the accounts.yaml |
| 111 | file was introduced and with that a new internal credential provider to enable |
| 112 | using the list of credentials instead of creating them on demand. With locking |
| 113 | test accounts each test class will reserve a set of credentials from the |
| 114 | accounts.yaml before executing any of its tests so that each class is isolated |
Andrea Frittoli (andreaf) | 17209bb | 2015-05-22 10:16:57 -0700 | [diff] [blame] | 115 | like with dynamic credentials. |
Matthew Treinish | bc1b15b | 2015-02-20 15:56:07 -0500 | [diff] [blame] | 116 | |
Matthew Treinish | bc1b15b | 2015-02-20 15:56:07 -0500 | [diff] [blame] | 117 | To enable and use locking test accounts you need do a few things: |
| 118 | |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 119 | #. Create an accounts.yaml file which contains the set of pre-existing |
Matthew Treinish | bc1b15b | 2015-02-20 15:56:07 -0500 | [diff] [blame] | 120 | credentials to use for testing. To make sure you don't have a credentials |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 121 | starvation issue when running in parallel make sure you have at least two |
| 122 | times the number of worker processes you are using to execute Tempest |
| 123 | available in the file. (If running serially the worker count is 1.) |
Matthew Treinish | 0fd69e4 | 2015-03-06 00:40:51 -0500 | [diff] [blame] | 124 | |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 125 | You can check the accounts.yaml.sample file packaged in Tempest for the yaml |
| 126 | format. |
| 127 | #. Provide Tempest with the location of your accounts.yaml file with the |
| 128 | ``test_accounts_file`` option in the ``auth`` section |
Matthew Treinish | bc1b15b | 2015-02-20 15:56:07 -0500 | [diff] [blame] | 129 | |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 130 | *NOTE: Be sure to use a full path for the file; otherwise Tempest will |
Matthew Treinish | 84c6d29 | 2015-12-16 17:50:57 -0500 | [diff] [blame] | 131 | likely not find it.* |
| 132 | |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 133 | #. Set ``use_dynamic_credentials = False`` in the ``auth`` group |
Fei Long Wang | 7fee787 | 2015-05-12 11:36:49 +1200 | [diff] [blame] | 134 | |
Matthew Treinish | 9329985 | 2015-04-24 09:58:18 -0400 | [diff] [blame] | 135 | It is worth pointing out that each set of credentials in the accounts.yaml |
Sean Dague | ed6e586 | 2016-04-04 10:49:13 -0400 | [diff] [blame] | 136 | should have a unique project. This is required to provide proper isolation |
Matthew Treinish | 9329985 | 2015-04-24 09:58:18 -0400 | [diff] [blame] | 137 | to the tests using the credentials, and failure to do this will likely cause |
| 138 | unexpected failures in some tests. |
Matthew Treinish | bc1b15b | 2015-02-20 15:56:07 -0500 | [diff] [blame] | 139 | |
Andrea Frittoli (andreaf) | 100d18d | 2016-05-05 23:34:52 +0100 | [diff] [blame] | 140 | When the keystone in the target cloud requires domain scoped tokens to |
| 141 | perform admin actions, all pre-provisioned admin users must have a role |
| 142 | assigned on the domain where test accounts a provisioned. |
| 143 | The option ``admin_domain_scope`` is used to tell tempest that domain scoped |
| 144 | tokens shall be used. ``default_credentials_domain_name`` is the domain where |
| 145 | test accounts are expected to be provisioned if no domain is specified. |
| 146 | |
| 147 | Note that if credentials are pre-provisioned via ``tempest account-generator`` |
| 148 | the role on the domain will be assigned automatically for you, as long as |
| 149 | ``admin_domain_scope`` as ``default_credentials_domain_name`` are configured |
| 150 | properly in tempest.conf. |
| 151 | |
Andrea Frittoli (andreaf) | dd25070 | 2016-04-29 15:01:22 -0500 | [diff] [blame] | 152 | Pre-Provisioned Credentials are also know as accounts.yaml or accounts file. |
Matthew Treinish | 9329985 | 2015-04-24 09:58:18 -0400 | [diff] [blame] | 153 | |
Matthew Treinish | 7909e12 | 2015-04-15 15:43:50 -0400 | [diff] [blame] | 154 | Compute |
| 155 | ------- |
| 156 | |
| 157 | Flavors |
| 158 | ^^^^^^^ |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 159 | For Tempest to be able to create servers you need to specify flavors that it |
| 160 | can use to boot the servers with. There are two options in the Tempest config |
Matthew Treinish | 7909e12 | 2015-04-15 15:43:50 -0400 | [diff] [blame] | 161 | for doing this: |
| 162 | |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 163 | #. ``flavor_ref`` |
| 164 | #. ``flavor_ref_alt`` |
Matthew Treinish | 7909e12 | 2015-04-15 15:43:50 -0400 | [diff] [blame] | 165 | |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 166 | Both of these options are in the ``compute`` section of the config file and take |
| 167 | in the flavor id (not the name) from nova. The ``flavor_ref`` option is what |
| 168 | will be used for booting almost all of the guests; ``flavor_ref_alt`` is only |
| 169 | used in tests where two different-sized servers are required (for example, a |
| 170 | resize test). |
Matthew Treinish | 7909e12 | 2015-04-15 15:43:50 -0400 | [diff] [blame] | 171 | |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 172 | Using a smaller flavor is generally recommended. When larger flavors are used, |
Matthew Treinish | 7909e12 | 2015-04-15 15:43:50 -0400 | [diff] [blame] | 173 | the extra time required to bring up servers will likely affect total run time |
| 174 | and probably require tweaking timeout values to ensure tests have ample time to |
| 175 | finish. |
| 176 | |
| 177 | Images |
| 178 | ^^^^^^ |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 179 | Just like with flavors, Tempest needs to know which images to use for booting |
| 180 | servers. There are two options in the compute section just like with flavors: |
Matthew Treinish | 7909e12 | 2015-04-15 15:43:50 -0400 | [diff] [blame] | 181 | |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 182 | #. ``image_ref`` |
| 183 | #. ``image_ref_alt`` |
Matthew Treinish | 7909e12 | 2015-04-15 15:43:50 -0400 | [diff] [blame] | 184 | |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 185 | Both options are expecting an image id (not name) from nova. The ``image_ref`` |
| 186 | option is what will be used for booting the majority of servers in Tempest. |
| 187 | ``image_ref_alt`` is used for tests that require two images such as rebuild. If |
| 188 | two images are not available you can set both options to the same image id and |
Matthew Treinish | 7909e12 | 2015-04-15 15:43:50 -0400 | [diff] [blame] | 189 | those tests will be skipped. |
| 190 | |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 191 | There are also options in the ``scenario`` section for images: |
Matthew Treinish | 7909e12 | 2015-04-15 15:43:50 -0400 | [diff] [blame] | 192 | |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 193 | #. ``img_file`` |
| 194 | #. ``img_dir`` |
| 195 | #. ``aki_img_file`` |
| 196 | #. ``ari_img_file`` |
| 197 | #. ``ami_img_file`` |
| 198 | #. ``img_container_format`` |
| 199 | #. ``img_disk_format`` |
Matthew Treinish | 7909e12 | 2015-04-15 15:43:50 -0400 | [diff] [blame] | 200 | |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 201 | However, unlike the other image options, these are used for a very small subset |
Matthew Treinish | 7909e12 | 2015-04-15 15:43:50 -0400 | [diff] [blame] | 202 | of scenario tests which are uploading an image. These options are used to tell |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 203 | Tempest where an image file is located and describe its metadata for when it is |
Matthew Treinish | 7909e12 | 2015-04-15 15:43:50 -0400 | [diff] [blame] | 204 | uploaded. |
| 205 | |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 206 | The behavior of these options is a bit convoluted (which will likely be fixed in |
| 207 | future versions). You first need to specify ``img_dir``, which is the directory |
| 208 | in which Tempest will look for the image files. First it will check if the |
| 209 | filename set for ``img_file`` could be found in ``img_dir``. If it is found then |
| 210 | the ``img_container_format`` and ``img_disk_format`` options are used to upload |
| 211 | that image to glance. However, if it is not found, Tempest will look for the |
| 212 | three uec image file name options as a fallback. If neither is found, the tests |
| 213 | requiring an image to upload will fail. |
Matthew Treinish | 7909e12 | 2015-04-15 15:43:50 -0400 | [diff] [blame] | 214 | |
| 215 | It is worth pointing out that using `cirros`_ is a very good choice for running |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 216 | Tempest. It's what is used for upstream testing, they boot quickly and have a |
Matthew Treinish | 7909e12 | 2015-04-15 15:43:50 -0400 | [diff] [blame] | 217 | small footprint. |
| 218 | |
| 219 | .. _cirros: https://launchpad.net/cirros |
| 220 | |
Matthew Treinish | 2b7f048 | 2015-04-10 12:49:01 -0400 | [diff] [blame] | 221 | Networking |
| 222 | ---------- |
| 223 | OpenStack has a myriad of different networking configurations possible and |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 224 | depending on which of the two network backends, nova-network or neutron, you are |
Matthew Treinish | 2b7f048 | 2015-04-10 12:49:01 -0400 | [diff] [blame] | 225 | using things can vary drastically. Due to this complexity Tempest has to provide |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 226 | a certain level of flexibility in its configuration to ensure it will work |
Matthew Treinish | 2b7f048 | 2015-04-10 12:49:01 -0400 | [diff] [blame] | 227 | against any cloud. This ends up causing a large number of permutations in |
| 228 | Tempest's config around network configuration. |
| 229 | |
| 230 | |
| 231 | Enabling Remote Access to Created Servers |
| 232 | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ |
Matthew Treinish | 275f178 | 2016-06-07 12:19:34 -0400 | [diff] [blame] | 233 | Network Creation/Usage for Servers |
| 234 | """""""""""""""""""""""""""""""""" |
Matthew Treinish | 2b7f048 | 2015-04-10 12:49:01 -0400 | [diff] [blame] | 235 | When Tempest creates servers for testing, some tests require being able to |
| 236 | connect those servers. Depending on the configuration of the cloud, the methods |
| 237 | for doing this can be different. In certain configurations it is required to |
| 238 | specify a single network with server create calls. Accordingly, Tempest provides |
| 239 | a few different methods for providing this information in configuration to try |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 240 | and ensure that regardless of the cloud's configuration it'll still be able to |
Matthew Treinish | 2b7f048 | 2015-04-10 12:49:01 -0400 | [diff] [blame] | 241 | run. This section covers the different methods of configuring Tempest to provide |
| 242 | a network when creating servers. |
| 243 | |
| 244 | Fixed Network Name |
Matthew Treinish | 275f178 | 2016-06-07 12:19:34 -0400 | [diff] [blame] | 245 | '''''''''''''''''' |
Matthew Treinish | 2b7f048 | 2015-04-10 12:49:01 -0400 | [diff] [blame] | 246 | This is the simplest method of specifying how networks should be used. You can |
| 247 | just specify a single network name/label to use for all server creations. The |
Sean Dague | ed6e586 | 2016-04-04 10:49:13 -0400 | [diff] [blame] | 248 | limitation with this is that all projects and users must be able to see |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 249 | that network name/label if they are to perform a network list and be able to use |
| 250 | it. |
Matthew Treinish | 2b7f048 | 2015-04-10 12:49:01 -0400 | [diff] [blame] | 251 | |
| 252 | If no network name is assigned in the config file and none of the below |
| 253 | alternatives are used, then Tempest will not specify a network on server |
| 254 | creations, which depending on the cloud configuration might prevent them from |
| 255 | booting. |
| 256 | |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 257 | To set a fixed network name simply: |
Matthew Treinish | 2b7f048 | 2015-04-10 12:49:01 -0400 | [diff] [blame] | 258 | |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 259 | #. Set the ``fixed_network_name`` option in the ``compute`` group |
Matthew Treinish | 2b7f048 | 2015-04-10 12:49:01 -0400 | [diff] [blame] | 260 | |
| 261 | In the case that the configured fixed network name can not be found by a user |
| 262 | network list call, it will be treated like one was not provided except that a |
| 263 | warning will be logged stating that it couldn't be found. |
| 264 | |
| 265 | |
| 266 | Accounts File |
Matthew Treinish | 275f178 | 2016-06-07 12:19:34 -0400 | [diff] [blame] | 267 | ''''''''''''' |
Matthew Treinish | 2b7f048 | 2015-04-10 12:49:01 -0400 | [diff] [blame] | 268 | If you are using an accounts file to provide credentials for running Tempest |
| 269 | then you can leverage it to also specify which network should be used with |
Sean Dague | ed6e586 | 2016-04-04 10:49:13 -0400 | [diff] [blame] | 270 | server creations on a per project and user pair basis. This provides |
Matthew Treinish | 2b7f048 | 2015-04-10 12:49:01 -0400 | [diff] [blame] | 271 | the necessary flexibility to work with more intricate networking configurations |
| 272 | by enabling the user to specify exactly which network to use for which |
Sean Dague | ed6e586 | 2016-04-04 10:49:13 -0400 | [diff] [blame] | 273 | projects. You can refer to the accounts.yaml.sample file included in |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 274 | the Tempest repo for the syntax around specifying networks in the file. |
Matthew Treinish | 2b7f048 | 2015-04-10 12:49:01 -0400 | [diff] [blame] | 275 | |
| 276 | However, specifying a network is not required when using an accounts file. If |
| 277 | one is not specified you can use a fixed network name to specify the network to |
| 278 | use when creating servers just as without an accounts file. However, any network |
| 279 | specified in the accounts file will take precedence over the fixed network name |
| 280 | provided. If no network is provided in the accounts file and a fixed network |
| 281 | name is not set then no network will be included in create server requests. |
| 282 | |
| 283 | If a fixed network is provided and the accounts.yaml file also contains networks |
| 284 | this has the benefit of enabling a couple more tests which require a static |
| 285 | network to perform operations like server lists with a network filter. If a |
| 286 | fixed network name is not provided these tests are skipped. Additionally, if a |
| 287 | fixed network name is provided it will serve as a fallback in case of a |
| 288 | misconfiguration or a missing network in the accounts file. |
| 289 | |
| 290 | |
Andrea Frittoli (andreaf) | 17209bb | 2015-05-22 10:16:57 -0700 | [diff] [blame] | 291 | With Dynamic Credentials |
Matthew Treinish | 275f178 | 2016-06-07 12:19:34 -0400 | [diff] [blame] | 292 | '''''''''''''''''''''''' |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 293 | With dynamic credentials enabled and using nova-network, your only option for |
lanoux | 63bb903 | 2016-03-21 03:16:18 -0700 | [diff] [blame] | 294 | configuration is to either set a fixed network name or not. However, in most |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 295 | cases it shouldn't matter because nova-network should have no problem booting a |
| 296 | server with multiple networks. If this is not the case for your cloud then using |
| 297 | an accounts file is recommended because it provides the necessary flexibility to |
| 298 | describe your configuration. Dynamic credentials is not able to dynamically |
| 299 | allocate things as necessary if neutron is not enabled. |
Matthew Treinish | 2b7f048 | 2015-04-10 12:49:01 -0400 | [diff] [blame] | 300 | |
Andrea Frittoli (andreaf) | 17209bb | 2015-05-22 10:16:57 -0700 | [diff] [blame] | 301 | With neutron and dynamic credentials enabled there should not be any additional |
Matthew Treinish | 2b7f048 | 2015-04-10 12:49:01 -0400 | [diff] [blame] | 302 | configuration necessary to enable Tempest to create servers with working |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 303 | networking, assuming you have properly configured the ``network`` section to |
| 304 | work for your cloud. Tempest will dynamically create the neutron resources |
| 305 | necessary to enable using servers with that network. Also, just as with the |
| 306 | accounts file, if you specify a fixed network name while using neutron and |
| 307 | dynamic credentials it will enable running tests which require a static network |
| 308 | and it will additionally be used as a fallback for server creation. However, |
| 309 | unlike accounts.yaml this should never be triggered. |
Matthew Treinish | 3220cad | 2015-04-15 16:25:48 -0400 | [diff] [blame] | 310 | |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 311 | However, there is an option ``create_isolated_networks`` to disable dynamic |
| 312 | credentials's automatic provisioning of network resources. If this option is set |
| 313 | to False you will have to either rely on there only being a single/default |
| 314 | network available for the server creation, or use ``fixed_network_name`` to |
| 315 | inform Tempest which network to use. |
Matthew Treinish | 2219d38 | 2015-04-24 10:33:04 -0400 | [diff] [blame] | 316 | |
Matthew Treinish | 275f178 | 2016-06-07 12:19:34 -0400 | [diff] [blame] | 317 | SSH Connection Configuration |
| 318 | """""""""""""""""""""""""""" |
| 319 | There are also several different ways to actually establish a connection and |
| 320 | authenticate/login on the server. After a server is booted with a provided |
| 321 | network there are still details needed to know how to actually connect to |
| 322 | the server. The ``validation`` group gathers all the options regarding |
| 323 | connecting to and remotely accessing the created servers. |
| 324 | |
| 325 | To enable remote access to servers, there are 3 options at a minimum that are used: |
| 326 | |
| 327 | #. ``run_validation`` |
| 328 | #. ``connect_method`` |
| 329 | #. ``auth_method`` |
| 330 | |
| 331 | The ``run_validation`` is used to enable or disable ssh connectivity for |
| 332 | all tests (with the exception of scenario tests which do not have a flag for |
| 333 | enabling or disabling ssh) To enable ssh connectivity this needs be set to ``true``. |
| 334 | |
| 335 | The ``connect_method`` option is used to tell tempest what kind of IP to use for |
| 336 | establishing a connection to the server. Two methods are available: ``fixed`` |
| 337 | and ``floating``, the later being set by default. If this is set to floating |
| 338 | tempest will create a floating ip for the server before attempted to connect |
| 339 | to it. The IP for the floating ip is what is used for the connection. |
| 340 | |
| 341 | For the ``auth_method`` option there is currently, only one valid option, |
| 342 | ``keypair``. With this set to ``keypair`` tempest will create an ssh keypair |
| 343 | and use that for authenticating against the created server. |
| 344 | |
Matthew Treinish | f96ab3a | 2015-04-15 19:11:31 -0400 | [diff] [blame] | 345 | Configuring Available Services |
| 346 | ------------------------------ |
| 347 | OpenStack is really a constellation of several different projects which |
| 348 | are running together to create a cloud. However which projects you're running |
| 349 | is not set in stone, and which services are running is up to the deployer. |
| 350 | Tempest however needs to know which services are available so it can figure |
| 351 | out which tests it is able to run and certain setup steps which differ based |
| 352 | on the available services. |
| 353 | |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 354 | The ``service_available`` section of the config file is used to set which |
Matthew Treinish | f96ab3a | 2015-04-15 19:11:31 -0400 | [diff] [blame] | 355 | services are available. It contains a boolean option for each service (except |
| 356 | for keystone which is a hard requirement) set it to True if the service is |
| 357 | available or False if it is not. |
| 358 | |
| 359 | Service Catalog |
| 360 | ^^^^^^^^^^^^^^^ |
| 361 | Each project which has its own REST API contains an entry in the service |
| 362 | catalog. Like most things in OpenStack this is also completely configurable. |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 363 | However, for Tempest to be able to figure out which endpoints should get REST |
| 364 | API calls for each service, it needs to know how that project is defined in the |
| 365 | service catalog. There are three options for each service section to accomplish |
Matthew Treinish | f96ab3a | 2015-04-15 19:11:31 -0400 | [diff] [blame] | 366 | this: |
| 367 | |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 368 | #. ``catalog_type`` |
| 369 | #. ``endpoint_type`` |
| 370 | #. ``region`` |
Matthew Treinish | f96ab3a | 2015-04-15 19:11:31 -0400 | [diff] [blame] | 371 | |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 372 | Setting ``catalog_type`` and ``endpoint_type`` should normally give Tempest |
| 373 | enough information to determine which endpoint it should pull from the service |
| 374 | catalog to use for talking to that particular service. However, if your cloud |
| 375 | has multiple regions available and you need to specify a particular one to use a |
| 376 | service you can set the ``region`` option in that service's section. |
Matthew Treinish | f96ab3a | 2015-04-15 19:11:31 -0400 | [diff] [blame] | 377 | |
| 378 | It should also be noted that the default values for these options are set |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 379 | to what devstack uses (which is a de facto standard for service catalog |
| 380 | entries). So often nothing actually needs to be set on these options to enable |
Matthew Treinish | f96ab3a | 2015-04-15 19:11:31 -0400 | [diff] [blame] | 381 | communication to a particular service. It is only if you are either not using |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 382 | the same ``catalog_type`` as devstack or you want Tempest to talk to a different |
Matthew Treinish | f96ab3a | 2015-04-15 19:11:31 -0400 | [diff] [blame] | 383 | endpoint type instead of publicURL for a service that these need to be changed. |
| 384 | |
ghanshyam | 571dfac | 2015-10-30 11:21:28 +0900 | [diff] [blame] | 385 | .. note:: |
| 386 | |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 387 | Tempest does not serve all kinds of fancy URLs in the service catalog. The |
| 388 | service catalog should be in a standard format (which is going to be |
| 389 | standardized at the keystone level). |
| 390 | Tempest expects URLs in the Service catalog in the following format: |
Masayuki Igawa | e63cf0f | 2016-05-25 10:25:21 +0900 | [diff] [blame] | 391 | |
| 392 | * ``http://example.com:1234/<version-info>`` |
| 393 | |
ghanshyam | 571dfac | 2015-10-30 11:21:28 +0900 | [diff] [blame] | 394 | Examples: |
Masayuki Igawa | e63cf0f | 2016-05-25 10:25:21 +0900 | [diff] [blame] | 395 | |
| 396 | * Good - ``http://example.com:1234/v2.0`` |
| 397 | * Wouldn’t work - ``http://example.com:1234/xyz/v2.0/`` |
| 398 | (adding prefix/suffix around version etc) |
Matthew Treinish | f96ab3a | 2015-04-15 19:11:31 -0400 | [diff] [blame] | 399 | |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 400 | Service Feature Configuration |
Matthew Treinish | 3220cad | 2015-04-15 16:25:48 -0400 | [diff] [blame] | 401 | ----------------------------- |
| 402 | |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 403 | OpenStack provides its deployers a myriad of different configuration options to |
| 404 | enable anyone deploying it to create a cloud tailor-made for any individual use |
| 405 | case. It provides options for several different backend types, databases, |
Matthew Treinish | 3220cad | 2015-04-15 16:25:48 -0400 | [diff] [blame] | 406 | message queues, etc. However, the downside to this configurability is that |
| 407 | certain operations and features aren't supported depending on the configuration. |
| 408 | These features may or may not be discoverable from the API so the burden is |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 409 | often on the user to figure out what is supported by the cloud they're talking |
| 410 | to. Besides the obvious interoperability issues with this it also leaves |
| 411 | Tempest in an interesting situation trying to figure out which tests are |
| 412 | expected to work. However, Tempest tests do not rely on dynamic API discovery |
| 413 | for a feature (assuming one exists). Instead Tempest has to be explicitly |
| 414 | configured as to which optional features are enabled. This is in order to |
| 415 | prevent bugs in the discovery mechanisms from masking failures. |
Matthew Treinish | 3220cad | 2015-04-15 16:25:48 -0400 | [diff] [blame] | 416 | |
| 417 | The service feature-enabled config sections are how Tempest addresses the |
| 418 | optional feature question. Each service that has tests for optional features |
| 419 | contains one of these sections. The only options in it are boolean options |
| 420 | with the name of a feature which is used. If it is set to false any test which |
| 421 | depends on that functionality will be skipped. For a complete list of all these |
| 422 | options refer to the sample config file. |
| 423 | |
| 424 | |
| 425 | API Extensions |
| 426 | ^^^^^^^^^^^^^^ |
Eric Fried | e0cfc3e | 2015-12-14 16:10:49 -0600 | [diff] [blame] | 427 | The service feature-enabled sections often contain an ``api-extensions`` option |
| 428 | (or in the case of swift a ``discoverable_apis`` option). This is used to tell |
| 429 | Tempest which api extensions (or configurable middleware) is used in your |
| 430 | deployment. It has two valid config states: either it contains a single value |
| 431 | ``all`` (which is the default) which means that every api extension is assumed |
Matthew Treinish | 3220cad | 2015-04-15 16:25:48 -0400 | [diff] [blame] | 432 | to be enabled, or it is set to a list of each individual extension that is |
| 433 | enabled for that service. |