root / lib / bootstrap.py @ d04aaa2f
History | View | Annotate | Download (17.9 kB)
1 | a0c9f010 | Michael Hanselmann | #
|
---|---|---|---|
2 | a0c9f010 | Michael Hanselmann | #
|
3 | a0c9f010 | Michael Hanselmann | |
4 | a0c9f010 | Michael Hanselmann | # Copyright (C) 2006, 2007, 2008 Google Inc.
|
5 | a0c9f010 | Michael Hanselmann | #
|
6 | a0c9f010 | Michael Hanselmann | # This program is free software; you can redistribute it and/or modify
|
7 | a0c9f010 | Michael Hanselmann | # it under the terms of the GNU General Public License as published by
|
8 | a0c9f010 | Michael Hanselmann | # the Free Software Foundation; either version 2 of the License, or
|
9 | a0c9f010 | Michael Hanselmann | # (at your option) any later version.
|
10 | a0c9f010 | Michael Hanselmann | #
|
11 | a0c9f010 | Michael Hanselmann | # This program is distributed in the hope that it will be useful, but
|
12 | a0c9f010 | Michael Hanselmann | # WITHOUT ANY WARRANTY; without even the implied warranty of
|
13 | a0c9f010 | Michael Hanselmann | # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
14 | a0c9f010 | Michael Hanselmann | # General Public License for more details.
|
15 | a0c9f010 | Michael Hanselmann | #
|
16 | a0c9f010 | Michael Hanselmann | # You should have received a copy of the GNU General Public License
|
17 | a0c9f010 | Michael Hanselmann | # along with this program; if not, write to the Free Software
|
18 | a0c9f010 | Michael Hanselmann | # Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
|
19 | a0c9f010 | Michael Hanselmann | # 02110-1301, USA.
|
20 | a0c9f010 | Michael Hanselmann | |
21 | a0c9f010 | Michael Hanselmann | |
22 | a0c9f010 | Michael Hanselmann | """Functions to bootstrap a new cluster.
|
23 | a0c9f010 | Michael Hanselmann |
|
24 | a0c9f010 | Michael Hanselmann | """
|
25 | a0c9f010 | Michael Hanselmann | |
26 | a0c9f010 | Michael Hanselmann | import os |
27 | a0c9f010 | Michael Hanselmann | import os.path |
28 | a0c9f010 | Michael Hanselmann | import re |
29 | b1b6ea87 | Iustin Pop | import logging |
30 | c4415fd5 | Michael Hanselmann | import tempfile |
31 | a0c9f010 | Michael Hanselmann | |
32 | a0c9f010 | Michael Hanselmann | from ganeti import rpc |
33 | a0c9f010 | Michael Hanselmann | from ganeti import ssh |
34 | a0c9f010 | Michael Hanselmann | from ganeti import utils |
35 | a0c9f010 | Michael Hanselmann | from ganeti import errors |
36 | a0c9f010 | Michael Hanselmann | from ganeti import config |
37 | a0c9f010 | Michael Hanselmann | from ganeti import constants |
38 | b9eeeb02 | Michael Hanselmann | from ganeti import objects |
39 | a0c9f010 | Michael Hanselmann | from ganeti import ssconf |
40 | a5728081 | Guido Trotter | from ganeti import hypervisor |
41 | a0c9f010 | Michael Hanselmann | |
42 | e38220e4 | Michael Hanselmann | |
43 | 531baf8e | Iustin Pop | def _InitSSHSetup(): |
44 | a0c9f010 | Michael Hanselmann | """Setup the SSH configuration for the cluster.
|
45 | a0c9f010 | Michael Hanselmann |
|
46 | a0c9f010 | Michael Hanselmann | This generates a dsa keypair for root, adds the pub key to the
|
47 | a0c9f010 | Michael Hanselmann | permitted hosts and adds the hostkey to its own known hosts.
|
48 | a0c9f010 | Michael Hanselmann |
|
49 | a0c9f010 | Michael Hanselmann | """
|
50 | a0c9f010 | Michael Hanselmann | priv_key, pub_key, auth_keys = ssh.GetUserFiles(constants.GANETI_RUNAS) |
51 | a0c9f010 | Michael Hanselmann | |
52 | a0c9f010 | Michael Hanselmann | for name in priv_key, pub_key: |
53 | a0c9f010 | Michael Hanselmann | if os.path.exists(name):
|
54 | a0c9f010 | Michael Hanselmann | utils.CreateBackup(name) |
55 | a0c9f010 | Michael Hanselmann | utils.RemoveFile(name) |
56 | a0c9f010 | Michael Hanselmann | |
57 | a0c9f010 | Michael Hanselmann | result = utils.RunCmd(["ssh-keygen", "-t", "dsa", |
58 | a0c9f010 | Michael Hanselmann | "-f", priv_key,
|
59 | a0c9f010 | Michael Hanselmann | "-q", "-N", ""]) |
60 | a0c9f010 | Michael Hanselmann | if result.failed:
|
61 | a0c9f010 | Michael Hanselmann | raise errors.OpExecError("Could not generate ssh keypair, error %s" % |
62 | a0c9f010 | Michael Hanselmann | result.output) |
63 | a0c9f010 | Michael Hanselmann | |
64 | a0c9f010 | Michael Hanselmann | f = open(pub_key, 'r') |
65 | a0c9f010 | Michael Hanselmann | try:
|
66 | a0c9f010 | Michael Hanselmann | utils.AddAuthorizedKey(auth_keys, f.read(8192))
|
67 | a0c9f010 | Michael Hanselmann | finally:
|
68 | a0c9f010 | Michael Hanselmann | f.close() |
69 | a0c9f010 | Michael Hanselmann | |
70 | a0c9f010 | Michael Hanselmann | |
71 | 40a97d80 | Michael Hanselmann | def _GenerateSelfSignedSslCert(file_name, validity=(365 * 5)): |
72 | 40a97d80 | Michael Hanselmann | """Generates a self-signed SSL certificate.
|
73 | a0c9f010 | Michael Hanselmann |
|
74 | 40a97d80 | Michael Hanselmann | @type file_name: str
|
75 | 40a97d80 | Michael Hanselmann | @param file_name: Path to output file
|
76 | 40a97d80 | Michael Hanselmann | @type validity: int
|
77 | 40a97d80 | Michael Hanselmann | @param validity: Validity for certificate in days
|
78 | a0c9f010 | Michael Hanselmann |
|
79 | a0c9f010 | Michael Hanselmann | """
|
80 | c4415fd5 | Michael Hanselmann | (fd, tmp_file_name) = tempfile.mkstemp(dir=os.path.dirname(file_name)) |
81 | c4415fd5 | Michael Hanselmann | try:
|
82 | c4415fd5 | Michael Hanselmann | # Set permissions before writing key
|
83 | c4415fd5 | Michael Hanselmann | os.chmod(tmp_file_name, 0600)
|
84 | c4415fd5 | Michael Hanselmann | |
85 | c4415fd5 | Michael Hanselmann | result = utils.RunCmd(["openssl", "req", "-new", "-newkey", "rsa:1024", |
86 | c4415fd5 | Michael Hanselmann | "-days", str(validity), "-nodes", "-x509", |
87 | c4415fd5 | Michael Hanselmann | "-keyout", tmp_file_name, "-out", tmp_file_name, |
88 | c4415fd5 | Michael Hanselmann | "-batch"])
|
89 | c4415fd5 | Michael Hanselmann | if result.failed:
|
90 | c4415fd5 | Michael Hanselmann | raise errors.OpExecError("Could not generate SSL certificate, command" |
91 | c4415fd5 | Michael Hanselmann | " %s had exitcode %s and error message %s" %
|
92 | c4415fd5 | Michael Hanselmann | (result.cmd, result.exit_code, result.output)) |
93 | c4415fd5 | Michael Hanselmann | |
94 | c4415fd5 | Michael Hanselmann | # Make read-only
|
95 | c4415fd5 | Michael Hanselmann | os.chmod(tmp_file_name, 0400)
|
96 | c4415fd5 | Michael Hanselmann | |
97 | c4415fd5 | Michael Hanselmann | os.rename(tmp_file_name, file_name) |
98 | c4415fd5 | Michael Hanselmann | finally:
|
99 | c4415fd5 | Michael Hanselmann | utils.RemoveFile(tmp_file_name) |
100 | 40a97d80 | Michael Hanselmann | |
101 | 40a97d80 | Michael Hanselmann | |
102 | 40a97d80 | Michael Hanselmann | def _InitGanetiServerSetup(): |
103 | 40a97d80 | Michael Hanselmann | """Setup the necessary configuration for the initial node daemon.
|
104 | 40a97d80 | Michael Hanselmann |
|
105 | 40a97d80 | Michael Hanselmann | This creates the nodepass file containing the shared password for
|
106 | 40a97d80 | Michael Hanselmann | the cluster and also generates the SSL certificate.
|
107 | 40a97d80 | Michael Hanselmann |
|
108 | 40a97d80 | Michael Hanselmann | """
|
109 | 40a97d80 | Michael Hanselmann | _GenerateSelfSignedSslCert(constants.SSL_CERT_FILE) |
110 | a0c9f010 | Michael Hanselmann | |
111 | 61a08fa3 | Michael Hanselmann | # Don't overwrite existing file
|
112 | 61a08fa3 | Michael Hanselmann | if not os.path.exists(constants.RAPI_CERT_FILE): |
113 | 61a08fa3 | Michael Hanselmann | _GenerateSelfSignedSslCert(constants.RAPI_CERT_FILE) |
114 | 61a08fa3 | Michael Hanselmann | |
115 | a0c9f010 | Michael Hanselmann | result = utils.RunCmd([constants.NODE_INITD_SCRIPT, "restart"])
|
116 | a0c9f010 | Michael Hanselmann | |
117 | a0c9f010 | Michael Hanselmann | if result.failed:
|
118 | a0c9f010 | Michael Hanselmann | raise errors.OpExecError("Could not start the node daemon, command %s" |
119 | a0c9f010 | Michael Hanselmann | " had exitcode %s and error %s" %
|
120 | a0c9f010 | Michael Hanselmann | (result.cmd, result.exit_code, result.output)) |
121 | a0c9f010 | Michael Hanselmann | |
122 | a0c9f010 | Michael Hanselmann | |
123 | 4342e89b | Alexander Schreiber | def InitCluster(cluster_name, mac_prefix, def_bridge, |
124 | ce735215 | Guido Trotter | master_netdev, file_storage_dir, candidate_pool_size, |
125 | ce735215 | Guido Trotter | secondary_ip=None, vg_name=None, beparams=None, hvparams=None, |
126 | 02691904 | Alexander Schreiber | enabled_hypervisors=None, default_hypervisor=None): |
127 | a0c9f010 | Michael Hanselmann | """Initialise the cluster.
|
128 | a0c9f010 | Michael Hanselmann |
|
129 | ce735215 | Guido Trotter | @type candidate_pool_size: int
|
130 | ce735215 | Guido Trotter | @param candidate_pool_size: master candidate pool size
|
131 | ce735215 | Guido Trotter |
|
132 | a0c9f010 | Michael Hanselmann | """
|
133 | ce735215 | Guido Trotter | # TODO: complete the docstring
|
134 | a0c9f010 | Michael Hanselmann | if config.ConfigWriter.IsCluster():
|
135 | a0c9f010 | Michael Hanselmann | raise errors.OpPrereqError("Cluster is already initialised") |
136 | a0c9f010 | Michael Hanselmann | |
137 | a0c9f010 | Michael Hanselmann | hostname = utils.HostInfo() |
138 | a0c9f010 | Michael Hanselmann | |
139 | a0c9f010 | Michael Hanselmann | if hostname.ip.startswith("127."): |
140 | a0c9f010 | Michael Hanselmann | raise errors.OpPrereqError("This host's IP resolves to the private" |
141 | a0c9f010 | Michael Hanselmann | " range (%s). Please fix DNS or %s." %
|
142 | a0c9f010 | Michael Hanselmann | (hostname.ip, constants.ETC_HOSTS)) |
143 | a0c9f010 | Michael Hanselmann | |
144 | caad16e2 | Iustin Pop | if not utils.OwnIpAddress(hostname.ip): |
145 | a0c9f010 | Michael Hanselmann | raise errors.OpPrereqError("Inconsistency: this host's name resolves" |
146 | a0c9f010 | Michael Hanselmann | " to %s,\nbut this ip address does not"
|
147 | a0c9f010 | Michael Hanselmann | " belong to this host."
|
148 | a0c9f010 | Michael Hanselmann | " Aborting." % hostname.ip)
|
149 | a0c9f010 | Michael Hanselmann | |
150 | a0c9f010 | Michael Hanselmann | clustername = utils.HostInfo(cluster_name) |
151 | a0c9f010 | Michael Hanselmann | |
152 | a0c9f010 | Michael Hanselmann | if utils.TcpPing(clustername.ip, constants.DEFAULT_NODED_PORT,
|
153 | a0c9f010 | Michael Hanselmann | timeout=5):
|
154 | a0c9f010 | Michael Hanselmann | raise errors.OpPrereqError("Cluster IP already active. Aborting.") |
155 | a0c9f010 | Michael Hanselmann | |
156 | a0c9f010 | Michael Hanselmann | if secondary_ip:
|
157 | a0c9f010 | Michael Hanselmann | if not utils.IsValidIP(secondary_ip): |
158 | a0c9f010 | Michael Hanselmann | raise errors.OpPrereqError("Invalid secondary ip given") |
159 | a0c9f010 | Michael Hanselmann | if (secondary_ip != hostname.ip and |
160 | caad16e2 | Iustin Pop | not utils.OwnIpAddress(secondary_ip)):
|
161 | a0c9f010 | Michael Hanselmann | raise errors.OpPrereqError("You gave %s as secondary IP," |
162 | a0c9f010 | Michael Hanselmann | " but it does not belong to this host." %
|
163 | a0c9f010 | Michael Hanselmann | secondary_ip) |
164 | b9eeeb02 | Michael Hanselmann | else:
|
165 | b9eeeb02 | Michael Hanselmann | secondary_ip = hostname.ip |
166 | a0c9f010 | Michael Hanselmann | |
167 | a0c9f010 | Michael Hanselmann | if vg_name is not None: |
168 | a0c9f010 | Michael Hanselmann | # Check if volume group is valid
|
169 | a0c9f010 | Michael Hanselmann | vgstatus = utils.CheckVolumeGroupSize(utils.ListVolumeGroups(), vg_name, |
170 | a0c9f010 | Michael Hanselmann | constants.MIN_VG_SIZE) |
171 | a0c9f010 | Michael Hanselmann | if vgstatus:
|
172 | a0c9f010 | Michael Hanselmann | raise errors.OpPrereqError("Error: %s\nspecify --no-lvm-storage if" |
173 | a0c9f010 | Michael Hanselmann | " you are not using lvm" % vgstatus)
|
174 | a0c9f010 | Michael Hanselmann | |
175 | a0c9f010 | Michael Hanselmann | file_storage_dir = os.path.normpath(file_storage_dir) |
176 | a0c9f010 | Michael Hanselmann | |
177 | a0c9f010 | Michael Hanselmann | if not os.path.isabs(file_storage_dir): |
178 | a0c9f010 | Michael Hanselmann | raise errors.OpPrereqError("The file storage directory you passed is" |
179 | a0c9f010 | Michael Hanselmann | " not an absolute path.")
|
180 | a0c9f010 | Michael Hanselmann | |
181 | a0c9f010 | Michael Hanselmann | if not os.path.exists(file_storage_dir): |
182 | a0c9f010 | Michael Hanselmann | try:
|
183 | a0c9f010 | Michael Hanselmann | os.makedirs(file_storage_dir, 0750)
|
184 | a0c9f010 | Michael Hanselmann | except OSError, err: |
185 | a0c9f010 | Michael Hanselmann | raise errors.OpPrereqError("Cannot create file storage directory" |
186 | a0c9f010 | Michael Hanselmann | " '%s': %s" %
|
187 | a0c9f010 | Michael Hanselmann | (file_storage_dir, err)) |
188 | a0c9f010 | Michael Hanselmann | |
189 | a0c9f010 | Michael Hanselmann | if not os.path.isdir(file_storage_dir): |
190 | a0c9f010 | Michael Hanselmann | raise errors.OpPrereqError("The file storage directory '%s' is not" |
191 | a0c9f010 | Michael Hanselmann | " a directory." % file_storage_dir)
|
192 | a0c9f010 | Michael Hanselmann | |
193 | a0c9f010 | Michael Hanselmann | if not re.match("^[0-9a-z]{2}:[0-9a-z]{2}:[0-9a-z]{2}$", mac_prefix): |
194 | a0c9f010 | Michael Hanselmann | raise errors.OpPrereqError("Invalid mac prefix given '%s'" % mac_prefix) |
195 | a0c9f010 | Michael Hanselmann | |
196 | a0c9f010 | Michael Hanselmann | result = utils.RunCmd(["ip", "link", "show", "dev", master_netdev]) |
197 | a0c9f010 | Michael Hanselmann | if result.failed:
|
198 | a0c9f010 | Michael Hanselmann | raise errors.OpPrereqError("Invalid master netdev given (%s): '%s'" % |
199 | a0c9f010 | Michael Hanselmann | (master_netdev, |
200 | a0c9f010 | Michael Hanselmann | result.output.strip())) |
201 | a0c9f010 | Michael Hanselmann | |
202 | a0c9f010 | Michael Hanselmann | if not (os.path.isfile(constants.NODE_INITD_SCRIPT) and |
203 | a0c9f010 | Michael Hanselmann | os.access(constants.NODE_INITD_SCRIPT, os.X_OK)): |
204 | a0c9f010 | Michael Hanselmann | raise errors.OpPrereqError("Init.d script '%s' missing or not" |
205 | a0c9f010 | Michael Hanselmann | " executable." % constants.NODE_INITD_SCRIPT)
|
206 | a0c9f010 | Michael Hanselmann | |
207 | 9dae41ad | Guido Trotter | dirs = [(constants.RUN_GANETI_DIR, constants.RUN_DIRS_MODE)] |
208 | 9dae41ad | Guido Trotter | utils.EnsureDirs(dirs) |
209 | 9dae41ad | Guido Trotter | |
210 | a5728081 | Guido Trotter | utils.ForceDictType(beparams, constants.BES_PARAMETER_TYPES) |
211 | a5728081 | Guido Trotter | # hvparams is a mapping of hypervisor->hvparams dict
|
212 | a5728081 | Guido Trotter | for hv_name, hv_params in hvparams.iteritems(): |
213 | a5728081 | Guido Trotter | utils.ForceDictType(hv_params, constants.HVS_PARAMETER_TYPES) |
214 | a5728081 | Guido Trotter | hv_class = hypervisor.GetHypervisor(hv_name) |
215 | a5728081 | Guido Trotter | hv_class.CheckParameterSyntax(hv_params) |
216 | d4b72030 | Guido Trotter | |
217 | a0c9f010 | Michael Hanselmann | # set up the inter-node password and certificate
|
218 | d23ef431 | Michael Hanselmann | _InitGanetiServerSetup() |
219 | a0c9f010 | Michael Hanselmann | |
220 | a0c9f010 | Michael Hanselmann | # set up ssh config and /etc/hosts
|
221 | a0c9f010 | Michael Hanselmann | f = open(constants.SSH_HOST_RSA_PUB, 'r') |
222 | a0c9f010 | Michael Hanselmann | try:
|
223 | a0c9f010 | Michael Hanselmann | sshline = f.read() |
224 | a0c9f010 | Michael Hanselmann | finally:
|
225 | a0c9f010 | Michael Hanselmann | f.close() |
226 | a0c9f010 | Michael Hanselmann | sshkey = sshline.split(" ")[1] |
227 | a0c9f010 | Michael Hanselmann | |
228 | a0c9f010 | Michael Hanselmann | utils.AddHostToEtcHosts(hostname.name) |
229 | 531baf8e | Iustin Pop | _InitSSHSetup() |
230 | a0c9f010 | Michael Hanselmann | |
231 | a0c9f010 | Michael Hanselmann | # init of cluster config file
|
232 | b9eeeb02 | Michael Hanselmann | cluster_config = objects.Cluster( |
233 | b9eeeb02 | Michael Hanselmann | serial_no=1,
|
234 | b9eeeb02 | Michael Hanselmann | rsahostkeypub=sshkey, |
235 | b9eeeb02 | Michael Hanselmann | highest_used_port=(constants.FIRST_DRBD_PORT - 1),
|
236 | b9eeeb02 | Michael Hanselmann | mac_prefix=mac_prefix, |
237 | b9eeeb02 | Michael Hanselmann | volume_group_name=vg_name, |
238 | b9eeeb02 | Michael Hanselmann | default_bridge=def_bridge, |
239 | b9eeeb02 | Michael Hanselmann | tcpudp_port_pool=set(),
|
240 | f6bd6e98 | Michael Hanselmann | master_node=hostname.name, |
241 | f6bd6e98 | Michael Hanselmann | master_ip=clustername.ip, |
242 | f6bd6e98 | Michael Hanselmann | master_netdev=master_netdev, |
243 | f6bd6e98 | Michael Hanselmann | cluster_name=clustername.name, |
244 | f6bd6e98 | Michael Hanselmann | file_storage_dir=file_storage_dir, |
245 | ea3a925f | Alexander Schreiber | enabled_hypervisors=enabled_hypervisors, |
246 | 02691904 | Alexander Schreiber | default_hypervisor=default_hypervisor, |
247 | ea3a925f | Alexander Schreiber | beparams={constants.BEGR_DEFAULT: beparams}, |
248 | ea3a925f | Alexander Schreiber | hvparams=hvparams, |
249 | ce735215 | Guido Trotter | candidate_pool_size=candidate_pool_size, |
250 | b9eeeb02 | Michael Hanselmann | ) |
251 | b9eeeb02 | Michael Hanselmann | master_node_config = objects.Node(name=hostname.name, |
252 | b9eeeb02 | Michael Hanselmann | primary_ip=hostname.ip, |
253 | b9222f32 | Guido Trotter | secondary_ip=secondary_ip, |
254 | c044f32c | Guido Trotter | serial_no=1,
|
255 | c044f32c | Guido Trotter | master_candidate=True,
|
256 | af64c0ea | Iustin Pop | offline=False, drained=False, |
257 | c044f32c | Guido Trotter | ) |
258 | a0c9f010 | Michael Hanselmann | |
259 | 05cc153f | Guido Trotter | sscfg = InitConfig(constants.CONFIG_VERSION, |
260 | 05cc153f | Guido Trotter | cluster_config, master_node_config) |
261 | 05cc153f | Guido Trotter | ssh.WriteKnownHostsFile(sscfg, constants.SSH_KNOWN_HOSTS_FILE) |
262 | 05cc153f | Guido Trotter | cfg = config.ConfigWriter() |
263 | 05cc153f | Guido Trotter | cfg.Update(cfg.GetClusterInfo()) |
264 | 827f753e | Guido Trotter | |
265 | b3f1cf6f | Iustin Pop | # start the master ip
|
266 | b3f1cf6f | Iustin Pop | # TODO: Review rpc call from bootstrap
|
267 | fda5f19f | Michael Hanselmann | rpc.RpcRunner.call_node_start_master(hostname.name, True)
|
268 | b3f1cf6f | Iustin Pop | |
269 | b1b6ea87 | Iustin Pop | |
270 | 02f99608 | Oleksiy Mishchenko | def InitConfig(version, cluster_config, master_node_config, |
271 | 02f99608 | Oleksiy Mishchenko | cfg_file=constants.CLUSTER_CONF_FILE): |
272 | 7b3a8fb5 | Iustin Pop | """Create the initial cluster configuration.
|
273 | 7b3a8fb5 | Iustin Pop |
|
274 | 7b3a8fb5 | Iustin Pop | It will contain the current node, which will also be the master
|
275 | 7b3a8fb5 | Iustin Pop | node, and no instances.
|
276 | 7b3a8fb5 | Iustin Pop |
|
277 | 7b3a8fb5 | Iustin Pop | @type version: int
|
278 | c41eea6e | Iustin Pop | @param version: configuration version
|
279 | c41eea6e | Iustin Pop | @type cluster_config: L{objects.Cluster}
|
280 | c41eea6e | Iustin Pop | @param cluster_config: cluster configuration
|
281 | c41eea6e | Iustin Pop | @type master_node_config: L{objects.Node}
|
282 | c41eea6e | Iustin Pop | @param master_node_config: master node configuration
|
283 | c41eea6e | Iustin Pop | @type cfg_file: string
|
284 | c41eea6e | Iustin Pop | @param cfg_file: configuration file path
|
285 | c41eea6e | Iustin Pop |
|
286 | c41eea6e | Iustin Pop | @rtype: L{ssconf.SimpleConfigWriter}
|
287 | 5fcc718f | Iustin Pop | @return: initialized config instance
|
288 | 7b3a8fb5 | Iustin Pop |
|
289 | 7b3a8fb5 | Iustin Pop | """
|
290 | 7b3a8fb5 | Iustin Pop | nodes = { |
291 | 7b3a8fb5 | Iustin Pop | master_node_config.name: master_node_config, |
292 | 7b3a8fb5 | Iustin Pop | } |
293 | 7b3a8fb5 | Iustin Pop | |
294 | 7b3a8fb5 | Iustin Pop | config_data = objects.ConfigData(version=version, |
295 | 7b3a8fb5 | Iustin Pop | cluster=cluster_config, |
296 | 7b3a8fb5 | Iustin Pop | nodes=nodes, |
297 | 7b3a8fb5 | Iustin Pop | instances={}, |
298 | 7b3a8fb5 | Iustin Pop | serial_no=1)
|
299 | 7b3a8fb5 | Iustin Pop | cfg = ssconf.SimpleConfigWriter.FromDict(config_data.ToDict(), cfg_file) |
300 | 7b3a8fb5 | Iustin Pop | cfg.Save() |
301 | 7b3a8fb5 | Iustin Pop | |
302 | 7b3a8fb5 | Iustin Pop | return cfg
|
303 | 02f99608 | Oleksiy Mishchenko | |
304 | 02f99608 | Oleksiy Mishchenko | |
305 | 140aa4a8 | Iustin Pop | def FinalizeClusterDestroy(master): |
306 | 140aa4a8 | Iustin Pop | """Execute the last steps of cluster destroy
|
307 | 140aa4a8 | Iustin Pop |
|
308 | 140aa4a8 | Iustin Pop | This function shuts down all the daemons, completing the destroy
|
309 | 140aa4a8 | Iustin Pop | begun in cmdlib.LUDestroyOpcode.
|
310 | 140aa4a8 | Iustin Pop |
|
311 | 140aa4a8 | Iustin Pop | """
|
312 | 781de953 | Iustin Pop | result = rpc.RpcRunner.call_node_stop_master(master, True)
|
313 | 781de953 | Iustin Pop | if result.failed or not result.data: |
314 | 140aa4a8 | Iustin Pop | logging.warning("Could not disable the master role")
|
315 | 781de953 | Iustin Pop | result = rpc.RpcRunner.call_node_leave_cluster(master) |
316 | 781de953 | Iustin Pop | if result.failed or not result.data: |
317 | 140aa4a8 | Iustin Pop | logging.warning("Could not shutdown the node daemon and cleanup the node")
|
318 | 140aa4a8 | Iustin Pop | |
319 | 140aa4a8 | Iustin Pop | |
320 | 87622829 | Iustin Pop | def SetupNodeDaemon(cluster_name, node, ssh_key_check): |
321 | 827f753e | Guido Trotter | """Add a node to the cluster.
|
322 | 827f753e | Guido Trotter |
|
323 | b1b6ea87 | Iustin Pop | This function must be called before the actual opcode, and will ssh
|
324 | b1b6ea87 | Iustin Pop | to the remote node, copy the needed files, and start ganeti-noded,
|
325 | b1b6ea87 | Iustin Pop | allowing the master to do the rest via normal rpc calls.
|
326 | 827f753e | Guido Trotter |
|
327 | 87622829 | Iustin Pop | @param cluster_name: the cluster name
|
328 | 87622829 | Iustin Pop | @param node: the name of the new node
|
329 | 87622829 | Iustin Pop | @param ssh_key_check: whether to do a strict key check
|
330 | 827f753e | Guido Trotter |
|
331 | 827f753e | Guido Trotter | """
|
332 | 87622829 | Iustin Pop | sshrunner = ssh.SshRunner(cluster_name) |
333 | 5557b04c | Michael Hanselmann | |
334 | 5557b04c | Michael Hanselmann | noded_cert = utils.ReadFile(constants.SSL_CERT_FILE) |
335 | 2438c157 | Michael Hanselmann | rapi_cert = utils.ReadFile(constants.RAPI_CERT_FILE) |
336 | 5557b04c | Michael Hanselmann | |
337 | 827f753e | Guido Trotter | # in the base64 pem encoding, neither '!' nor '.' are valid chars,
|
338 | 827f753e | Guido Trotter | # so we use this to detect an invalid certificate; as long as the
|
339 | 827f753e | Guido Trotter | # cert doesn't contain this, the here-document will be correctly
|
340 | 827f753e | Guido Trotter | # parsed by the shell sequence below
|
341 | 2438c157 | Michael Hanselmann | if (re.search('^!EOF\.', noded_cert, re.MULTILINE) or |
342 | 2438c157 | Michael Hanselmann | re.search('^!EOF\.', rapi_cert, re.MULTILINE)):
|
343 | 827f753e | Guido Trotter | raise errors.OpExecError("invalid PEM encoding in the SSL certificate") |
344 | 5557b04c | Michael Hanselmann | |
345 | 5557b04c | Michael Hanselmann | if not noded_cert.endswith("\n"): |
346 | 5557b04c | Michael Hanselmann | noded_cert += "\n"
|
347 | 2438c157 | Michael Hanselmann | if not rapi_cert.endswith("\n"): |
348 | 2438c157 | Michael Hanselmann | rapi_cert += "\n"
|
349 | 827f753e | Guido Trotter | |
350 | 827f753e | Guido Trotter | # set up inter-node password and certificate and restarts the node daemon
|
351 | 827f753e | Guido Trotter | # and then connect with ssh to set password and start ganeti-noded
|
352 | 827f753e | Guido Trotter | # note that all the below variables are sanitized at this point,
|
353 | 827f753e | Guido Trotter | # either by being constants or by the checks above
|
354 | 827f753e | Guido Trotter | mycommand = ("umask 077 && "
|
355 | 827f753e | Guido Trotter | "cat > '%s' << '!EOF.' && \n"
|
356 | 2438c157 | Michael Hanselmann | "%s!EOF.\n"
|
357 | 2438c157 | Michael Hanselmann | "cat > '%s' << '!EOF.' && \n"
|
358 | 2438c157 | Michael Hanselmann | "%s!EOF.\n"
|
359 | 5b099da9 | Michael Hanselmann | "chmod 0400 %s %s && "
|
360 | 2438c157 | Michael Hanselmann | "%s restart" %
|
361 | 5557b04c | Michael Hanselmann | (constants.SSL_CERT_FILE, noded_cert, |
362 | 2438c157 | Michael Hanselmann | constants.RAPI_CERT_FILE, rapi_cert, |
363 | 5b099da9 | Michael Hanselmann | constants.SSL_CERT_FILE, constants.RAPI_CERT_FILE, |
364 | 827f753e | Guido Trotter | constants.NODE_INITD_SCRIPT)) |
365 | 827f753e | Guido Trotter | |
366 | c4b6c29c | Michael Hanselmann | result = sshrunner.Run(node, 'root', mycommand, batch=False, |
367 | c4b6c29c | Michael Hanselmann | ask_key=ssh_key_check, |
368 | c4b6c29c | Michael Hanselmann | use_cluster_key=False,
|
369 | c4b6c29c | Michael Hanselmann | strict_host_check=ssh_key_check) |
370 | 827f753e | Guido Trotter | if result.failed:
|
371 | 827f753e | Guido Trotter | raise errors.OpExecError("Remote command on node %s, error: %s," |
372 | 827f753e | Guido Trotter | " output: %s" %
|
373 | 827f753e | Guido Trotter | (node, result.fail_reason, result.output)) |
374 | 827f753e | Guido Trotter | |
375 | b1b6ea87 | Iustin Pop | |
376 | b1b6ea87 | Iustin Pop | def MasterFailover(): |
377 | b1b6ea87 | Iustin Pop | """Failover the master node.
|
378 | b1b6ea87 | Iustin Pop |
|
379 | b1b6ea87 | Iustin Pop | This checks that we are not already the master, and will cause the
|
380 | b1b6ea87 | Iustin Pop | current master to cease being master, and the non-master to become
|
381 | b1b6ea87 | Iustin Pop | new master.
|
382 | b1b6ea87 | Iustin Pop |
|
383 | b1b6ea87 | Iustin Pop | """
|
384 | 8135a2db | Iustin Pop | sstore = ssconf.SimpleStore() |
385 | b1b6ea87 | Iustin Pop | |
386 | 8135a2db | Iustin Pop | old_master, new_master = ssconf.GetMasterAndMyself(sstore) |
387 | 8135a2db | Iustin Pop | node_list = sstore.GetNodeList() |
388 | 8135a2db | Iustin Pop | mc_list = sstore.GetMasterCandidates() |
389 | b1b6ea87 | Iustin Pop | |
390 | b1b6ea87 | Iustin Pop | if old_master == new_master:
|
391 | b1b6ea87 | Iustin Pop | raise errors.OpPrereqError("This commands must be run on the node" |
392 | b1b6ea87 | Iustin Pop | " where you want the new master to be."
|
393 | b1b6ea87 | Iustin Pop | " %s is already the master" %
|
394 | b1b6ea87 | Iustin Pop | old_master) |
395 | d5927e48 | Iustin Pop | |
396 | 8135a2db | Iustin Pop | if new_master not in mc_list: |
397 | 8135a2db | Iustin Pop | mc_no_master = [name for name in mc_list if name != old_master] |
398 | 8135a2db | Iustin Pop | raise errors.OpPrereqError("This node is not among the nodes marked" |
399 | 8135a2db | Iustin Pop | " as master candidates. Only these nodes"
|
400 | 8135a2db | Iustin Pop | " can become masters. Current list of"
|
401 | 8135a2db | Iustin Pop | " master candidates is:\n"
|
402 | 8135a2db | Iustin Pop | "%s" % ('\n'.join(mc_no_master))) |
403 | 8135a2db | Iustin Pop | |
404 | d5927e48 | Iustin Pop | vote_list = GatherMasterVotes(node_list) |
405 | d5927e48 | Iustin Pop | |
406 | d5927e48 | Iustin Pop | if vote_list:
|
407 | d5927e48 | Iustin Pop | voted_master = vote_list[0][0] |
408 | d5927e48 | Iustin Pop | if voted_master is None: |
409 | d5927e48 | Iustin Pop | raise errors.OpPrereqError("Cluster is inconsistent, most nodes did not" |
410 | d5927e48 | Iustin Pop | " respond.")
|
411 | d5927e48 | Iustin Pop | elif voted_master != old_master:
|
412 | d5927e48 | Iustin Pop | raise errors.OpPrereqError("I have wrong configuration, I believe the" |
413 | d5927e48 | Iustin Pop | " master is %s but the other nodes voted for"
|
414 | d5927e48 | Iustin Pop | " %s. Please resync the configuration of"
|
415 | d5927e48 | Iustin Pop | " this node." % (old_master, voted_master))
|
416 | b1b6ea87 | Iustin Pop | # end checks
|
417 | b1b6ea87 | Iustin Pop | |
418 | b1b6ea87 | Iustin Pop | rcode = 0
|
419 | b1b6ea87 | Iustin Pop | |
420 | d5927e48 | Iustin Pop | logging.info("Setting master to %s, old master: %s", new_master, old_master)
|
421 | b1b6ea87 | Iustin Pop | |
422 | 781de953 | Iustin Pop | result = rpc.RpcRunner.call_node_stop_master(old_master, True)
|
423 | 781de953 | Iustin Pop | if result.failed or not result.data: |
424 | d5927e48 | Iustin Pop | logging.error("Could not disable the master role on the old master"
|
425 | b1b6ea87 | Iustin Pop | " %s, please disable manually", old_master)
|
426 | b1b6ea87 | Iustin Pop | |
427 | d23ef431 | Michael Hanselmann | # Here we have a phase where no master should be running
|
428 | b1b6ea87 | Iustin Pop | |
429 | bbe19c17 | Iustin Pop | # instantiate a real config writer, as we now know we have the
|
430 | bbe19c17 | Iustin Pop | # configuration data
|
431 | bbe19c17 | Iustin Pop | cfg = config.ConfigWriter() |
432 | b1b6ea87 | Iustin Pop | |
433 | bbe19c17 | Iustin Pop | cluster_info = cfg.GetClusterInfo() |
434 | bbe19c17 | Iustin Pop | cluster_info.master_node = new_master |
435 | bbe19c17 | Iustin Pop | # this will also regenerate the ssconf files, since we updated the
|
436 | bbe19c17 | Iustin Pop | # cluster info
|
437 | bbe19c17 | Iustin Pop | cfg.Update(cluster_info) |
438 | d5927e48 | Iustin Pop | |
439 | 781de953 | Iustin Pop | result = rpc.RpcRunner.call_node_start_master(new_master, True)
|
440 | 781de953 | Iustin Pop | if result.failed or not result.data: |
441 | d5927e48 | Iustin Pop | logging.error("Could not start the master role on the new master"
|
442 | b1b6ea87 | Iustin Pop | " %s, please check", new_master)
|
443 | b1b6ea87 | Iustin Pop | rcode = 1
|
444 | b1b6ea87 | Iustin Pop | |
445 | b1b6ea87 | Iustin Pop | return rcode
|
446 | d7cdb55d | Iustin Pop | |
447 | d7cdb55d | Iustin Pop | |
448 | 8eb148ae | Iustin Pop | def GetMaster(): |
449 | 8eb148ae | Iustin Pop | """Returns the current master node.
|
450 | 8eb148ae | Iustin Pop |
|
451 | 8eb148ae | Iustin Pop | This is a separate function in bootstrap since it's needed by
|
452 | 8eb148ae | Iustin Pop | gnt-cluster, and instead of importing directly ssconf, it's better
|
453 | 8eb148ae | Iustin Pop | to abstract it in bootstrap, where we do use ssconf in other
|
454 | 8eb148ae | Iustin Pop | functions too.
|
455 | 8eb148ae | Iustin Pop |
|
456 | 8eb148ae | Iustin Pop | """
|
457 | 8eb148ae | Iustin Pop | sstore = ssconf.SimpleStore() |
458 | 8eb148ae | Iustin Pop | |
459 | 8eb148ae | Iustin Pop | old_master, _ = ssconf.GetMasterAndMyself(sstore) |
460 | 8eb148ae | Iustin Pop | |
461 | 8eb148ae | Iustin Pop | return old_master
|
462 | 8eb148ae | Iustin Pop | |
463 | 8eb148ae | Iustin Pop | |
464 | d7cdb55d | Iustin Pop | def GatherMasterVotes(node_list): |
465 | d7cdb55d | Iustin Pop | """Check the agreement on who is the master.
|
466 | d7cdb55d | Iustin Pop |
|
467 | d7cdb55d | Iustin Pop | This function will return a list of (node, number of votes), ordered
|
468 | d7cdb55d | Iustin Pop | by the number of votes. Errors will be denoted by the key 'None'.
|
469 | d7cdb55d | Iustin Pop |
|
470 | d7cdb55d | Iustin Pop | Note that the sum of votes is the number of nodes this machine
|
471 | d7cdb55d | Iustin Pop | knows, whereas the number of entries in the list could be different
|
472 | d7cdb55d | Iustin Pop | (if some nodes vote for another master).
|
473 | d7cdb55d | Iustin Pop |
|
474 | d7cdb55d | Iustin Pop | We remove ourselves from the list since we know that (bugs aside)
|
475 | d7cdb55d | Iustin Pop | since we use the same source for configuration information for both
|
476 | d7cdb55d | Iustin Pop | backend and boostrap, we'll always vote for ourselves.
|
477 | d7cdb55d | Iustin Pop |
|
478 | d7cdb55d | Iustin Pop | @type node_list: list
|
479 | d7cdb55d | Iustin Pop | @param node_list: the list of nodes to query for master info; the current
|
480 | d7cdb55d | Iustin Pop | node wil be removed if it is in the list
|
481 | d7cdb55d | Iustin Pop | @rtype: list
|
482 | d7cdb55d | Iustin Pop | @return: list of (node, votes)
|
483 | d7cdb55d | Iustin Pop |
|
484 | d7cdb55d | Iustin Pop | """
|
485 | d7cdb55d | Iustin Pop | myself = utils.HostInfo().name |
486 | d7cdb55d | Iustin Pop | try:
|
487 | d7cdb55d | Iustin Pop | node_list.remove(myself) |
488 | d7cdb55d | Iustin Pop | except ValueError: |
489 | d7cdb55d | Iustin Pop | pass
|
490 | d7cdb55d | Iustin Pop | if not node_list: |
491 | d7cdb55d | Iustin Pop | # no nodes left (eventually after removing myself)
|
492 | d7cdb55d | Iustin Pop | return []
|
493 | d7cdb55d | Iustin Pop | results = rpc.RpcRunner.call_master_info(node_list) |
494 | d7cdb55d | Iustin Pop | if not isinstance(results, dict): |
495 | d7cdb55d | Iustin Pop | # this should not happen (unless internal error in rpc)
|
496 | d7cdb55d | Iustin Pop | logging.critical("Can't complete rpc call, aborting master startup")
|
497 | d7cdb55d | Iustin Pop | return [(None, len(node_list))] |
498 | d7cdb55d | Iustin Pop | votes = {} |
499 | d7cdb55d | Iustin Pop | for node in results: |
500 | 781de953 | Iustin Pop | nres = results[node] |
501 | 781de953 | Iustin Pop | data = nres.data |
502 | 781de953 | Iustin Pop | if nres.failed or not isinstance(data, (tuple, list)) or len(data) < 3: |
503 | d7cdb55d | Iustin Pop | # here the rpc layer should have already logged errors
|
504 | d7cdb55d | Iustin Pop | if None not in votes: |
505 | d7cdb55d | Iustin Pop | votes[None] = 0 |
506 | d7cdb55d | Iustin Pop | votes[None] += 1 |
507 | d7cdb55d | Iustin Pop | continue
|
508 | 781de953 | Iustin Pop | master_node = data[2]
|
509 | d7cdb55d | Iustin Pop | if master_node not in votes: |
510 | d7cdb55d | Iustin Pop | votes[master_node] = 0
|
511 | d7cdb55d | Iustin Pop | votes[master_node] += 1
|
512 | d7cdb55d | Iustin Pop | |
513 | d7cdb55d | Iustin Pop | vote_list = [v for v in votes.items()] |
514 | d7cdb55d | Iustin Pop | # sort first on number of votes then on name, since we want None
|
515 | d7cdb55d | Iustin Pop | # sorted later if we have the half of the nodes not responding, and
|
516 | d7cdb55d | Iustin Pop | # half voting all for the same master
|
517 | d7cdb55d | Iustin Pop | vote_list.sort(key=lambda x: (x[1], x[0]), reverse=True) |
518 | d7cdb55d | Iustin Pop | |
519 | d7cdb55d | Iustin Pop | return vote_list |