blob: f9b189ee4186708db89a4cf6e5a9707b820efc31 [file] [log] [blame]
azvyagintsevf94ab8c2018-10-12 20:48:59 +03001parameters:
2 _param:
Vasyl Saienko1cc05de2018-11-19 16:49:27 +02003 # Enable barbican integration in other services nova,glance,cinder
4 barbican_integration_enabled: False
azvyagintsev3f736c42018-11-01 20:04:29 +02005 # General
6 cluster_public_protocol: https
7 cluster_internal_protocol: http
Vasyl Saienko71e8c542018-11-16 16:19:17 +02008 openstack_service_hostname: os-ctl-vip
Vasyl Saienkob0931af2019-01-15 15:42:12 +02009 openstack_share_service_hostname: os-share-vip
10 openstack_kmn_service_hostname: os-kmn-vip
11 openstack_telemetry_service_hostname: os-telemetry-vip
Vasyl Saienko71e8c542018-11-16 16:19:17 +020012 openstack_service_host: ${_param:openstack_service_hostname}.${linux:system:domain}
Vasyl Saienkob0931af2019-01-15 15:42:12 +020013 openstack_share_service_host: ${_param:openstack_share_service_hostname}.${linux:system:domain}
14 openstack_kmn_service_host: ${_param:openstack_kmn_service_hostname}.${linux:system:domain}
15 openstack_telemetry_service_host: ${_param:openstack_telemetry_service_hostname}.${linux:system:domain}
azvyagintsevf94ab8c2018-10-12 20:48:59 +030016 # SSL
17 ceilometer_agent_ssl_enabled: False
18 openstack_mysql_x509_enabled: False
19 # for non-ssl use 5672 / for ssl 5671
20 openstack_rabbitmq_port: 5672
21 openstack_rabbitmq_x509_enabled: False
azvyagintsev3f736c42018-11-01 20:04:29 +020022 # Openstack memcache
Oleh Hryhorov26e8d6f2018-11-21 16:18:57 +020023 openstack_memcached_server_bind_address: 0.0.0.0
Oleksandr Bryndzii87f24232018-10-02 09:51:13 +000024 openstack_memcache_security_enabled: False
25 openstack_memcache_security_strategy: 'ENCRYPT'
azvyagintsev3f736c42018-11-01 20:04:29 +020026 openstack_memcached_proto_tcp_enabled: True
27 openstack_memcached_proto_udp_enabled: False
Vasyl Saienko26763162019-01-22 18:55:48 +020028 openstack_version: queens
Mykyta Karpin569ac8f2018-12-11 11:33:55 +020029 openstack_old_version: ${_param:openstack_version}
Mykyta Karpin882dcac2018-11-30 16:37:28 +020030 openstack_upgrade_enabled: False
Oleksandr Bryndzii256f63e2018-10-02 11:36:05 +000031 # Cinder
32 cinder_memcache_security_enabled: ${_param:openstack_memcache_security_enabled}
33 cinder_memcache_secret_key: ''
Mykyta Karpin882dcac2018-11-30 16:37:28 +020034 cinder_old_version: ${_param:openstack_old_version}
35 cinder_version: ${_param:openstack_version}
36 cinder_upgrade_enabled: ${_param:openstack_upgrade_enabled}
Oleksandr Bryndzii48cf31f2018-10-24 16:08:46 +030037 # Nova
38 nova_memcache_security_enabled: ${_param:openstack_memcache_security_enabled}
39 nova_memcache_secret_key: ''
Mykyta Karpin882dcac2018-11-30 16:37:28 +020040 nova_old_version: ${_param:openstack_old_version}
41 nova_version: ${_param:openstack_version}
42 nova_upgrade_enabled: ${_param:openstack_upgrade_enabled}
Vasyl Saienkoe2bad8d2019-02-19 18:36:40 +020043 nova_instance_build_timeout: 3600
Oleksandr Bryndzii61d8db82018-10-24 16:03:12 +030044 # Glance
45 glance_memcache_security_enabled: ${_param:openstack_memcache_security_enabled}
46 glance_memcache_secret_key: ''
Mykyta Karpin882dcac2018-11-30 16:37:28 +020047 glance_old_version: ${_param:openstack_old_version}
48 glance_version: ${_param:openstack_version}
49 glance_upgrade_enabled: ${_param:openstack_upgrade_enabled}
Vasyl Saienkoebe90622018-11-12 11:03:18 +020050 # Allow CORS from horizon, needed for direct upload
51 glance_cors_allowed_origin: '${_param:horizon_public_protocol}://${_param:horizon_public_host}'
Oleksandr Bryndziib7c92172018-10-24 12:02:20 +030052 # Heat
53 heat_memcache_security_enabled: ${_param:openstack_memcache_security_enabled}
54 heat_memcache_secret_key: ''
Mykyta Karpin882dcac2018-11-30 16:37:28 +020055 heat_old_version: ${_param:openstack_old_version}
56 heat_version: ${_param:openstack_version}
57 heat_upgrade_enabled: ${_param:openstack_upgrade_enabled}
Oleksandr Bryndziic72982c2018-10-24 11:50:20 +030058 # Aodh
59 aodh_memcache_security_enabled: ${_param:openstack_memcache_security_enabled}
60 aodh_memcache_secret_key: ''
Mykyta Karpin882dcac2018-11-30 16:37:28 +020061 aodh_old_version: ${_param:openstack_old_version}
62 aodh_version: ${_param:openstack_version}
63 aodh_upgrade_enabled: ${_param:openstack_upgrade_enabled}
64 # Ceilometer
65 ceilometer_old_version: ${_param:openstack_old_version}
66 ceilometer_version: ${_param:openstack_version}
67 ceilometer_upgrade_enabled: ${_param:openstack_upgrade_enabled}
Oleksandr Bryndzii0b5809e2018-11-01 18:23:35 +020068 # Gnocchi
69 gnocchi_memcache_security_enabled: ${_param:openstack_memcache_security_enabled}
70 gnocchi_memcache_secret_key: ''
Mykyta Karpin882dcac2018-11-30 16:37:28 +020071 gnocchi_version: 4.0
Mykyta Karpin569ac8f2018-12-11 11:33:55 +020072 gnocchi_old_version: ${_param:gnocchi_version}
Mykyta Karpin882dcac2018-11-30 16:37:28 +020073 gnocchi_upgrade_enabled: ${_param:openstack_upgrade_enabled}
Oleksandr Bryndzii0bf966d2018-11-01 18:36:54 +020074 # Panko
75 panko_memcache_security_enabled: ${_param:openstack_memcache_security_enabled}
76 panko_memcache_secret_key: ''
Mykyta Karpin882dcac2018-11-30 16:37:28 +020077 panko_old_version: ${_param:openstack_old_version}
78 panko_version: ${_param:openstack_version}
79 panko_upgrade_enabled: ${_param:openstack_upgrade_enabled}
Oleksandr Bryndzii43fed5f2018-11-01 19:26:19 +020080 # Barbican
81 barbican_memcache_security_enabled: ${_param:openstack_memcache_security_enabled}
82 barbican_memcache_secret_key: ''
Mykyta Karpin882dcac2018-11-30 16:37:28 +020083 barbican_old_version: ${_param:openstack_old_version}
84 barbican_version: ${_param:openstack_version}
85 barbican_upgrade_enabled: ${_param:openstack_upgrade_enabled}
86 # Designate
87 designate_old_version: ${_param:openstack_old_version}
88 designate_version: ${_param:openstack_version}
89 designate_upgrade_enabled: ${_param:openstack_upgrade_enabled}
Oleksandr Bryndzii242b2d12018-11-07 13:49:15 +020090 # Ironic
91 ironic_memcache_security_enabled: ${_param:openstack_memcache_security_enabled}
92 ironic_memcache_secret_key: ''
Vasyl Saienko07730452019-01-31 11:04:48 +020093 ironic_console_enabled: true
Oleksii Grudev2399a032019-02-07 14:04:11 +020094 ironic_old_version: ${_param:openstack_old_version}
95 ironic_version: ${_param:openstack_version}
96 ironic_upgrade_enabled: ${_param:openstack_upgrade_enabled}
Mykyta Karpin882dcac2018-11-30 16:37:28 +020097 # Keystone
98 keystone_old_version: ${_param:openstack_old_version}
99 keystone_version: ${_param:openstack_version}
100 keystone_upgrade_enabled: ${_param:openstack_upgrade_enabled}
101 # Manila
102 manila_old_version: ${_param:openstack_old_version}
103 manila_version: ${_param:openstack_version}
104 manila_upgrade_enabled: ${_param:openstack_upgrade_enabled}
105 # Neutron
106 neutron_old_version: ${_param:openstack_old_version}
107 neutron_version: ${_param:openstack_version}
108 neutron_upgrade_enabled: ${_param:openstack_upgrade_enabled}
Oleksandr Bryndzii1d423492018-11-06 10:35:02 +0200109 # Apache mods defaults
Oleksandr Bryndzii955e67a12018-12-13 23:31:28 +0000110 # Stacklight uses /server-status endpoint to monitor apache
Oleksandr Bryndzii1d423492018-11-06 10:35:02 +0200111 apache_mods_status_enabled: True
Oleksandr Bryndzii955e67a12018-12-13 23:31:28 +0000112 apache_mods_status_status: 'enabled'
Oleksandr Bryndziida2c7832018-12-18 12:58:36 +0000113 apache_mods_status_host_address: '127.0.0.1'
114 apache_mods_status_host_port: 80
Oleh Hryhorov1b5be042018-11-29 19:04:34 +0200115 apache_horizon_listen_address: '0.0.0.0'
Mykyta Karpin3ed24aa2018-12-21 10:58:30 +0200116 # Apache proxies for openstack aren't used as HA proxies, they are
117 # simply ssl terminators in case of setup of ssl on internal endpoints
118 # for services which don't support running under apache and wsgi.
119 # So retry parameter is set 0, to eliminate maintenance mode for backend
120 # which is 60 seconds by default.
121 apache_proxy_openstack_api_retry: 0
122 apache_proxy_openstack_cinder_retry: ${_param:apache_proxy_openstack_api_retry}
123 apache_proxy_openstack_designate_retry: ${_param:apache_proxy_openstack_api_retry}
124 apache_proxy_openstack_glance_retry: ${_param:apache_proxy_openstack_api_retry}
125 apache_proxy_openstack_heat_retry: ${_param:apache_proxy_openstack_api_retry}
126 apache_proxy_openstack_ironic_retry: ${_param:apache_proxy_openstack_api_retry}
127 apache_proxy_openstack_nova_retry: ${_param:apache_proxy_openstack_api_retry}
128 apache_proxy_openstack_neutron_retry: ${_param:apache_proxy_openstack_api_retry}
129 apache_proxy_openstack_aodh_retry: ${_param:apache_proxy_openstack_api_retry}
130 apache_proxy_openstack_placement_retry: ${_param:apache_proxy_openstack_api_retry}
Vasyl Saienko6a26e282019-01-28 11:38:28 +0200131 apache_proxy_openstack_octavia_retry: ${_param:apache_proxy_openstack_api_retry}
Vasyl Saienko0e5c1052018-11-06 17:35:51 +0200132 # Horizon
133 # 'direct' mode will require cors on glance side to be enabled.
Vasyl Saienkoebe90622018-11-12 11:03:18 +0200134 horizon_images_upload_mode: 'direct'
135 # TODO (vsaineko): switch to openstack_cluster_public_host
136 horizon_public_host: ${_param:cluster_public_host}
137 horizon_public_port: 443
138 horizon_public_protocol: https
Oleh Hryhorov2368cdb2018-12-04 14:43:44 +0200139 horizon_server_bind_address: ${_param:single_address}
Mykyta Karpin882dcac2018-11-30 16:37:28 +0200140 horizon_old_version: ${_param:openstack_old_version}
141 horizon_version: ${_param:openstack_version}
142 horizon_upgrade_enabled: ${_param:openstack_upgrade_enabled}
Ann Kamyshnikova119d3ec2018-11-28 14:32:29 +0400143 # Octavia
144 octavia_health_manager_node01_address: 192.168.10.10
145 octavia_health_manager_node02_address: 192.168.10.11
146 octavia_health_manager_node03_address: 192.168.10.12
azvyagintsev2ecced22019-01-21 18:46:02 +0200147 #
148 amphora_image_name: amphora-x64-haproxy
azvyagintsevfcdf5fe2019-01-22 18:12:00 +0200149 amphora_image_url: "${_param:mcp_binary_registry}/mirantis/openstack/octavia/images/${_param:mcp_version}/${_param:openstack_version}/amphora-x64-haproxy.qcow2"
Oleh Hryhorov81c4c212018-11-23 17:23:15 +0200150 # HAproxy
151 haproxy_openstack_web_bind_port: ${_param:horizon_public_port}
152 #
153 # haproxy_openstack_web_sticks_params is defined for SSL by default
154 # if cluster_protocolr HTTP is going to be used then haproxy_openstack_web_sticks_params
155 # should be redefined peroperly. For example empty list.
156 #
157 haproxy_openstack_web_sticks_params:
158 - stick-table type binary len 32 size 30k expire 30m
159 - acl clienthello req_ssl_hello_type 1
160 - acl serverhello rep_ssl_hello_type 2
161 - tcp-request inspect-delay 5s
162 - tcp-request content accept if clienthello
163 - tcp-response content accept if serverhello
164 - stick on payload_lv(43,1) if clienthello
165 - stick store-response payload_lv(43,1) if serverhello