Statistics
| Branch: | Tag: | Revision:

root / lib / bootstrap.py @ 5b69bc7c

History | View | Annotate | Download (20.6 kB)

1 a0c9f010 Michael Hanselmann
#
2 a0c9f010 Michael Hanselmann
#
3 a0c9f010 Michael Hanselmann
4 a0c9f010 Michael Hanselmann
# Copyright (C) 2006, 2007, 2008 Google Inc.
5 a0c9f010 Michael Hanselmann
#
6 a0c9f010 Michael Hanselmann
# This program is free software; you can redistribute it and/or modify
7 a0c9f010 Michael Hanselmann
# it under the terms of the GNU General Public License as published by
8 a0c9f010 Michael Hanselmann
# the Free Software Foundation; either version 2 of the License, or
9 a0c9f010 Michael Hanselmann
# (at your option) any later version.
10 a0c9f010 Michael Hanselmann
#
11 a0c9f010 Michael Hanselmann
# This program is distributed in the hope that it will be useful, but
12 a0c9f010 Michael Hanselmann
# WITHOUT ANY WARRANTY; without even the implied warranty of
13 a0c9f010 Michael Hanselmann
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
14 a0c9f010 Michael Hanselmann
# General Public License for more details.
15 a0c9f010 Michael Hanselmann
#
16 a0c9f010 Michael Hanselmann
# You should have received a copy of the GNU General Public License
17 a0c9f010 Michael Hanselmann
# along with this program; if not, write to the Free Software
18 a0c9f010 Michael Hanselmann
# Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
19 a0c9f010 Michael Hanselmann
# 02110-1301, USA.
20 a0c9f010 Michael Hanselmann
21 a0c9f010 Michael Hanselmann
22 a0c9f010 Michael Hanselmann
"""Functions to bootstrap a new cluster.
23 a0c9f010 Michael Hanselmann

24 a0c9f010 Michael Hanselmann
"""
25 a0c9f010 Michael Hanselmann
26 a0c9f010 Michael Hanselmann
import os
27 a0c9f010 Michael Hanselmann
import os.path
28 a0c9f010 Michael Hanselmann
import re
29 b1b6ea87 Iustin Pop
import logging
30 c4415fd5 Michael Hanselmann
import tempfile
31 d693c864 Iustin Pop
import time
32 a0c9f010 Michael Hanselmann
33 a0c9f010 Michael Hanselmann
from ganeti import rpc
34 a0c9f010 Michael Hanselmann
from ganeti import ssh
35 a0c9f010 Michael Hanselmann
from ganeti import utils
36 a0c9f010 Michael Hanselmann
from ganeti import errors
37 a0c9f010 Michael Hanselmann
from ganeti import config
38 a0c9f010 Michael Hanselmann
from ganeti import constants
39 b9eeeb02 Michael Hanselmann
from ganeti import objects
40 a0c9f010 Michael Hanselmann
from ganeti import ssconf
41 a33848a5 Guido Trotter
from ganeti import serializer
42 a5728081 Guido Trotter
from ganeti import hypervisor
43 a0c9f010 Michael Hanselmann
44 e38220e4 Michael Hanselmann
45 531baf8e Iustin Pop
def _InitSSHSetup():
46 a0c9f010 Michael Hanselmann
  """Setup the SSH configuration for the cluster.
47 a0c9f010 Michael Hanselmann

48 a0c9f010 Michael Hanselmann
  This generates a dsa keypair for root, adds the pub key to the
49 a0c9f010 Michael Hanselmann
  permitted hosts and adds the hostkey to its own known hosts.
50 a0c9f010 Michael Hanselmann

51 a0c9f010 Michael Hanselmann
  """
52 a0c9f010 Michael Hanselmann
  priv_key, pub_key, auth_keys = ssh.GetUserFiles(constants.GANETI_RUNAS)
53 a0c9f010 Michael Hanselmann
54 a0c9f010 Michael Hanselmann
  for name in priv_key, pub_key:
55 a0c9f010 Michael Hanselmann
    if os.path.exists(name):
56 a0c9f010 Michael Hanselmann
      utils.CreateBackup(name)
57 a0c9f010 Michael Hanselmann
    utils.RemoveFile(name)
58 a0c9f010 Michael Hanselmann
59 a0c9f010 Michael Hanselmann
  result = utils.RunCmd(["ssh-keygen", "-t", "dsa",
60 a0c9f010 Michael Hanselmann
                         "-f", priv_key,
61 a0c9f010 Michael Hanselmann
                         "-q", "-N", ""])
62 a0c9f010 Michael Hanselmann
  if result.failed:
63 a0c9f010 Michael Hanselmann
    raise errors.OpExecError("Could not generate ssh keypair, error %s" %
64 a0c9f010 Michael Hanselmann
                             result.output)
65 a0c9f010 Michael Hanselmann
66 7a0156dc Luca Bigliardi
  utils.AddAuthorizedKey(auth_keys, utils.ReadFile(pub_key))
67 a0c9f010 Michael Hanselmann
68 a0c9f010 Michael Hanselmann
69 cd34faf2 Michael Hanselmann
def GenerateSelfSignedSslCert(file_name, validity=(365 * 5)):
70 40a97d80 Michael Hanselmann
  """Generates a self-signed SSL certificate.
71 a0c9f010 Michael Hanselmann

72 40a97d80 Michael Hanselmann
  @type file_name: str
73 40a97d80 Michael Hanselmann
  @param file_name: Path to output file
74 40a97d80 Michael Hanselmann
  @type validity: int
75 40a97d80 Michael Hanselmann
  @param validity: Validity for certificate in days
76 a0c9f010 Michael Hanselmann

77 a0c9f010 Michael Hanselmann
  """
78 c4415fd5 Michael Hanselmann
  (fd, tmp_file_name) = tempfile.mkstemp(dir=os.path.dirname(file_name))
79 c4415fd5 Michael Hanselmann
  try:
80 88828491 Michael Hanselmann
    try:
81 88828491 Michael Hanselmann
      # Set permissions before writing key
82 88828491 Michael Hanselmann
      os.chmod(tmp_file_name, 0600)
83 88828491 Michael Hanselmann
84 88828491 Michael Hanselmann
      result = utils.RunCmd(["openssl", "req", "-new", "-newkey", "rsa:1024",
85 88828491 Michael Hanselmann
                             "-days", str(validity), "-nodes", "-x509",
86 88828491 Michael Hanselmann
                             "-keyout", tmp_file_name, "-out", tmp_file_name,
87 88828491 Michael Hanselmann
                             "-batch"])
88 88828491 Michael Hanselmann
      if result.failed:
89 88828491 Michael Hanselmann
        raise errors.OpExecError("Could not generate SSL certificate, command"
90 88828491 Michael Hanselmann
                                 " %s had exitcode %s and error message %s" %
91 88828491 Michael Hanselmann
                                 (result.cmd, result.exit_code, result.output))
92 88828491 Michael Hanselmann
93 88828491 Michael Hanselmann
      # Make read-only
94 88828491 Michael Hanselmann
      os.chmod(tmp_file_name, 0400)
95 88828491 Michael Hanselmann
96 88828491 Michael Hanselmann
      os.rename(tmp_file_name, file_name)
97 88828491 Michael Hanselmann
    finally:
98 88828491 Michael Hanselmann
      utils.RemoveFile(tmp_file_name)
99 c4415fd5 Michael Hanselmann
  finally:
100 88828491 Michael Hanselmann
    os.close(fd)
101 40a97d80 Michael Hanselmann
102 40a97d80 Michael Hanselmann
103 c008906b Michael Hanselmann
def GenerateHmacKey(file_name):
104 c008906b Michael Hanselmann
  """Writes a new HMAC key.
105 c008906b Michael Hanselmann

106 c008906b Michael Hanselmann
  @type file_name: str
107 c008906b Michael Hanselmann
  @param file_name: Path to output file
108 c008906b Michael Hanselmann

109 c008906b Michael Hanselmann
  """
110 c008906b Michael Hanselmann
  utils.WriteFile(file_name, data=utils.GenerateSecret(), mode=0400)
111 c008906b Michael Hanselmann
112 c008906b Michael Hanselmann
113 8f215968 Michael Hanselmann
def _InitGanetiServerSetup(master_name):
114 40a97d80 Michael Hanselmann
  """Setup the necessary configuration for the initial node daemon.
115 40a97d80 Michael Hanselmann

116 40a97d80 Michael Hanselmann
  This creates the nodepass file containing the shared password for
117 40a97d80 Michael Hanselmann
  the cluster and also generates the SSL certificate.
118 40a97d80 Michael Hanselmann

119 40a97d80 Michael Hanselmann
  """
120 cd34faf2 Michael Hanselmann
  GenerateSelfSignedSslCert(constants.SSL_CERT_FILE)
121 a0c9f010 Michael Hanselmann
122 61a08fa3 Michael Hanselmann
  # Don't overwrite existing file
123 61a08fa3 Michael Hanselmann
  if not os.path.exists(constants.RAPI_CERT_FILE):
124 cd34faf2 Michael Hanselmann
    GenerateSelfSignedSslCert(constants.RAPI_CERT_FILE)
125 61a08fa3 Michael Hanselmann
126 4a34c5cf Guido Trotter
  if not os.path.exists(constants.HMAC_CLUSTER_KEY):
127 c008906b Michael Hanselmann
    GenerateHmacKey(constants.HMAC_CLUSTER_KEY)
128 4a34c5cf Guido Trotter
129 f154a7a3 Michael Hanselmann
  result = utils.RunCmd([constants.DAEMON_UTIL, "start", constants.NODED])
130 a0c9f010 Michael Hanselmann
  if result.failed:
131 a0c9f010 Michael Hanselmann
    raise errors.OpExecError("Could not start the node daemon, command %s"
132 a0c9f010 Michael Hanselmann
                             " had exitcode %s and error %s" %
133 a0c9f010 Michael Hanselmann
                             (result.cmd, result.exit_code, result.output))
134 a0c9f010 Michael Hanselmann
135 8f215968 Michael Hanselmann
  # Wait for node daemon to become responsive
136 d3833ebd Michael Hanselmann
  def _CheckNodeDaemon():
137 8f215968 Michael Hanselmann
    result = rpc.RpcRunner.call_version([master_name])[master_name]
138 d3833ebd Michael Hanselmann
    if result.fail_msg:
139 d3833ebd Michael Hanselmann
      raise utils.RetryAgain()
140 8f215968 Michael Hanselmann
141 d3833ebd Michael Hanselmann
  try:
142 d3833ebd Michael Hanselmann
    utils.Retry(_CheckNodeDaemon, 1.0, 10.0)
143 d3833ebd Michael Hanselmann
  except utils.RetryTimeout:
144 d3833ebd Michael Hanselmann
    raise errors.OpExecError("Node daemon didn't answer queries within"
145 d3833ebd Michael Hanselmann
                             " 10 seconds")
146 a0c9f010 Michael Hanselmann
147 ec0652ad Guido Trotter
def InitCluster(cluster_name, mac_prefix,
148 ce735215 Guido Trotter
                master_netdev, file_storage_dir, candidate_pool_size,
149 b6a30b0d Guido Trotter
                secondary_ip=None, vg_name=None, beparams=None,
150 b6a30b0d Guido Trotter
                nicparams=None, hvparams=None, enabled_hypervisors=None,
151 b989b9d9 Ken Wehr
                modify_etc_hosts=True, modify_ssh_setup=True):
152 a0c9f010 Michael Hanselmann
  """Initialise the cluster.
153 a0c9f010 Michael Hanselmann

154 ce735215 Guido Trotter
  @type candidate_pool_size: int
155 ce735215 Guido Trotter
  @param candidate_pool_size: master candidate pool size
156 ce735215 Guido Trotter

157 a0c9f010 Michael Hanselmann
  """
158 ce735215 Guido Trotter
  # TODO: complete the docstring
159 a0c9f010 Michael Hanselmann
  if config.ConfigWriter.IsCluster():
160 debac808 Iustin Pop
    raise errors.OpPrereqError("Cluster is already initialised",
161 debac808 Iustin Pop
                               errors.ECODE_STATE)
162 a0c9f010 Michael Hanselmann
163 b119bccb Guido Trotter
  if not enabled_hypervisors:
164 b119bccb Guido Trotter
    raise errors.OpPrereqError("Enabled hypervisors list must contain at"
165 debac808 Iustin Pop
                               " least one member", errors.ECODE_INVAL)
166 b119bccb Guido Trotter
  invalid_hvs = set(enabled_hypervisors) - constants.HYPER_TYPES
167 b119bccb Guido Trotter
  if invalid_hvs:
168 b119bccb Guido Trotter
    raise errors.OpPrereqError("Enabled hypervisors contains invalid"
169 debac808 Iustin Pop
                               " entries: %s" % invalid_hvs,
170 debac808 Iustin Pop
                               errors.ECODE_INVAL)
171 b119bccb Guido Trotter
172 104f4ca1 Iustin Pop
  hostname = utils.GetHostInfo()
173 a0c9f010 Michael Hanselmann
174 a0c9f010 Michael Hanselmann
  if hostname.ip.startswith("127."):
175 a0c9f010 Michael Hanselmann
    raise errors.OpPrereqError("This host's IP resolves to the private"
176 a0c9f010 Michael Hanselmann
                               " range (%s). Please fix DNS or %s." %
177 debac808 Iustin Pop
                               (hostname.ip, constants.ETC_HOSTS),
178 debac808 Iustin Pop
                               errors.ECODE_ENVIRON)
179 a0c9f010 Michael Hanselmann
180 caad16e2 Iustin Pop
  if not utils.OwnIpAddress(hostname.ip):
181 a0c9f010 Michael Hanselmann
    raise errors.OpPrereqError("Inconsistency: this host's name resolves"
182 a0c9f010 Michael Hanselmann
                               " to %s,\nbut this ip address does not"
183 debac808 Iustin Pop
                               " belong to this host. Aborting." %
184 debac808 Iustin Pop
                               hostname.ip, errors.ECODE_ENVIRON)
185 a0c9f010 Michael Hanselmann
186 104f4ca1 Iustin Pop
  clustername = utils.GetHostInfo(cluster_name)
187 a0c9f010 Michael Hanselmann
188 a0c9f010 Michael Hanselmann
  if utils.TcpPing(clustername.ip, constants.DEFAULT_NODED_PORT,
189 a0c9f010 Michael Hanselmann
                   timeout=5):
190 debac808 Iustin Pop
    raise errors.OpPrereqError("Cluster IP already active. Aborting.",
191 debac808 Iustin Pop
                               errors.ECODE_NOTUNIQUE)
192 a0c9f010 Michael Hanselmann
193 a0c9f010 Michael Hanselmann
  if secondary_ip:
194 a0c9f010 Michael Hanselmann
    if not utils.IsValidIP(secondary_ip):
195 debac808 Iustin Pop
      raise errors.OpPrereqError("Invalid secondary ip given",
196 debac808 Iustin Pop
                                 errors.ECODE_INVAL)
197 a0c9f010 Michael Hanselmann
    if (secondary_ip != hostname.ip and
198 caad16e2 Iustin Pop
        not utils.OwnIpAddress(secondary_ip)):
199 a0c9f010 Michael Hanselmann
      raise errors.OpPrereqError("You gave %s as secondary IP,"
200 a0c9f010 Michael Hanselmann
                                 " but it does not belong to this host." %
201 debac808 Iustin Pop
                                 secondary_ip, errors.ECODE_ENVIRON)
202 b9eeeb02 Michael Hanselmann
  else:
203 b9eeeb02 Michael Hanselmann
    secondary_ip = hostname.ip
204 a0c9f010 Michael Hanselmann
205 a0c9f010 Michael Hanselmann
  if vg_name is not None:
206 a0c9f010 Michael Hanselmann
    # Check if volume group is valid
207 a0c9f010 Michael Hanselmann
    vgstatus = utils.CheckVolumeGroupSize(utils.ListVolumeGroups(), vg_name,
208 a0c9f010 Michael Hanselmann
                                          constants.MIN_VG_SIZE)
209 a0c9f010 Michael Hanselmann
    if vgstatus:
210 a0c9f010 Michael Hanselmann
      raise errors.OpPrereqError("Error: %s\nspecify --no-lvm-storage if"
211 debac808 Iustin Pop
                                 " you are not using lvm" % vgstatus,
212 debac808 Iustin Pop
                                 errors.ECODE_INVAL)
213 a0c9f010 Michael Hanselmann
214 a0c9f010 Michael Hanselmann
  file_storage_dir = os.path.normpath(file_storage_dir)
215 a0c9f010 Michael Hanselmann
216 a0c9f010 Michael Hanselmann
  if not os.path.isabs(file_storage_dir):
217 a0c9f010 Michael Hanselmann
    raise errors.OpPrereqError("The file storage directory you passed is"
218 debac808 Iustin Pop
                               " not an absolute path.", errors.ECODE_INVAL)
219 a0c9f010 Michael Hanselmann
220 a0c9f010 Michael Hanselmann
  if not os.path.exists(file_storage_dir):
221 a0c9f010 Michael Hanselmann
    try:
222 a0c9f010 Michael Hanselmann
      os.makedirs(file_storage_dir, 0750)
223 a0c9f010 Michael Hanselmann
    except OSError, err:
224 a0c9f010 Michael Hanselmann
      raise errors.OpPrereqError("Cannot create file storage directory"
225 debac808 Iustin Pop
                                 " '%s': %s" % (file_storage_dir, err),
226 debac808 Iustin Pop
                                 errors.ECODE_ENVIRON)
227 a0c9f010 Michael Hanselmann
228 a0c9f010 Michael Hanselmann
  if not os.path.isdir(file_storage_dir):
229 a0c9f010 Michael Hanselmann
    raise errors.OpPrereqError("The file storage directory '%s' is not"
230 debac808 Iustin Pop
                               " a directory." % file_storage_dir,
231 debac808 Iustin Pop
                               errors.ECODE_ENVIRON)
232 a0c9f010 Michael Hanselmann
233 a0c9f010 Michael Hanselmann
  if not re.match("^[0-9a-z]{2}:[0-9a-z]{2}:[0-9a-z]{2}$", mac_prefix):
234 debac808 Iustin Pop
    raise errors.OpPrereqError("Invalid mac prefix given '%s'" % mac_prefix,
235 debac808 Iustin Pop
                               errors.ECODE_INVAL)
236 a0c9f010 Michael Hanselmann
237 a0c9f010 Michael Hanselmann
  result = utils.RunCmd(["ip", "link", "show", "dev", master_netdev])
238 a0c9f010 Michael Hanselmann
  if result.failed:
239 a0c9f010 Michael Hanselmann
    raise errors.OpPrereqError("Invalid master netdev given (%s): '%s'" %
240 a0c9f010 Michael Hanselmann
                               (master_netdev,
241 debac808 Iustin Pop
                                result.output.strip()), errors.ECODE_INVAL)
242 a0c9f010 Michael Hanselmann
243 9dae41ad Guido Trotter
  dirs = [(constants.RUN_GANETI_DIR, constants.RUN_DIRS_MODE)]
244 9dae41ad Guido Trotter
  utils.EnsureDirs(dirs)
245 9dae41ad Guido Trotter
246 a5728081 Guido Trotter
  utils.ForceDictType(beparams, constants.BES_PARAMETER_TYPES)
247 b6a30b0d Guido Trotter
  utils.ForceDictType(nicparams, constants.NICS_PARAMETER_TYPES)
248 b6a30b0d Guido Trotter
  objects.NIC.CheckParameterSyntax(nicparams)
249 b6a30b0d Guido Trotter
250 a5728081 Guido Trotter
  # hvparams is a mapping of hypervisor->hvparams dict
251 a5728081 Guido Trotter
  for hv_name, hv_params in hvparams.iteritems():
252 a5728081 Guido Trotter
    utils.ForceDictType(hv_params, constants.HVS_PARAMETER_TYPES)
253 a5728081 Guido Trotter
    hv_class = hypervisor.GetHypervisor(hv_name)
254 a5728081 Guido Trotter
    hv_class.CheckParameterSyntax(hv_params)
255 d4b72030 Guido Trotter
256 a0c9f010 Michael Hanselmann
  # set up the inter-node password and certificate
257 8f215968 Michael Hanselmann
  _InitGanetiServerSetup(hostname.name)
258 a0c9f010 Michael Hanselmann
259 a0c9f010 Michael Hanselmann
  # set up ssh config and /etc/hosts
260 13998ef2 Michael Hanselmann
  sshline = utils.ReadFile(constants.SSH_HOST_RSA_PUB)
261 a0c9f010 Michael Hanselmann
  sshkey = sshline.split(" ")[1]
262 a0c9f010 Michael Hanselmann
263 b86a6bcd Guido Trotter
  if modify_etc_hosts:
264 b86a6bcd Guido Trotter
    utils.AddHostToEtcHosts(hostname.name)
265 b86a6bcd Guido Trotter
266 b989b9d9 Ken Wehr
  if modify_ssh_setup:
267 b989b9d9 Ken Wehr
    _InitSSHSetup()
268 a0c9f010 Michael Hanselmann
269 430b923c Iustin Pop
  now = time.time()
270 430b923c Iustin Pop
271 a0c9f010 Michael Hanselmann
  # init of cluster config file
272 b9eeeb02 Michael Hanselmann
  cluster_config = objects.Cluster(
273 b9eeeb02 Michael Hanselmann
    serial_no=1,
274 b9eeeb02 Michael Hanselmann
    rsahostkeypub=sshkey,
275 b9eeeb02 Michael Hanselmann
    highest_used_port=(constants.FIRST_DRBD_PORT - 1),
276 b9eeeb02 Michael Hanselmann
    mac_prefix=mac_prefix,
277 b9eeeb02 Michael Hanselmann
    volume_group_name=vg_name,
278 b9eeeb02 Michael Hanselmann
    tcpudp_port_pool=set(),
279 f6bd6e98 Michael Hanselmann
    master_node=hostname.name,
280 f6bd6e98 Michael Hanselmann
    master_ip=clustername.ip,
281 f6bd6e98 Michael Hanselmann
    master_netdev=master_netdev,
282 f6bd6e98 Michael Hanselmann
    cluster_name=clustername.name,
283 f6bd6e98 Michael Hanselmann
    file_storage_dir=file_storage_dir,
284 ea3a925f Alexander Schreiber
    enabled_hypervisors=enabled_hypervisors,
285 4ef7f423 Guido Trotter
    beparams={constants.PP_DEFAULT: beparams},
286 b6a30b0d Guido Trotter
    nicparams={constants.PP_DEFAULT: nicparams},
287 ea3a925f Alexander Schreiber
    hvparams=hvparams,
288 ce735215 Guido Trotter
    candidate_pool_size=candidate_pool_size,
289 022c3a0b Guido Trotter
    modify_etc_hosts=modify_etc_hosts,
290 b989b9d9 Ken Wehr
    modify_ssh_setup=modify_ssh_setup,
291 430b923c Iustin Pop
    ctime=now,
292 430b923c Iustin Pop
    mtime=now,
293 430b923c Iustin Pop
    uuid=utils.NewUUID(),
294 b9eeeb02 Michael Hanselmann
    )
295 b9eeeb02 Michael Hanselmann
  master_node_config = objects.Node(name=hostname.name,
296 b9eeeb02 Michael Hanselmann
                                    primary_ip=hostname.ip,
297 b9222f32 Guido Trotter
                                    secondary_ip=secondary_ip,
298 c044f32c Guido Trotter
                                    serial_no=1,
299 c044f32c Guido Trotter
                                    master_candidate=True,
300 af64c0ea Iustin Pop
                                    offline=False, drained=False,
301 c044f32c Guido Trotter
                                    )
302 9e1333b9 Guido Trotter
  InitConfig(constants.CONFIG_VERSION, cluster_config, master_node_config)
303 05cc153f Guido Trotter
  cfg = config.ConfigWriter()
304 9e1333b9 Guido Trotter
  ssh.WriteKnownHostsFile(cfg, constants.SSH_KNOWN_HOSTS_FILE)
305 a4eae71f Michael Hanselmann
  cfg.Update(cfg.GetClusterInfo(), logging.error)
306 827f753e Guido Trotter
307 b3f1cf6f Iustin Pop
  # start the master ip
308 b3f1cf6f Iustin Pop
  # TODO: Review rpc call from bootstrap
309 b726aff0 Iustin Pop
  # TODO: Warn on failed start master
310 3583908a Guido Trotter
  rpc.RpcRunner.call_node_start_master(hostname.name, True, False)
311 b3f1cf6f Iustin Pop
312 b1b6ea87 Iustin Pop
313 02f99608 Oleksiy Mishchenko
def InitConfig(version, cluster_config, master_node_config,
314 02f99608 Oleksiy Mishchenko
               cfg_file=constants.CLUSTER_CONF_FILE):
315 7b3a8fb5 Iustin Pop
  """Create the initial cluster configuration.
316 7b3a8fb5 Iustin Pop

317 7b3a8fb5 Iustin Pop
  It will contain the current node, which will also be the master
318 7b3a8fb5 Iustin Pop
  node, and no instances.
319 7b3a8fb5 Iustin Pop

320 7b3a8fb5 Iustin Pop
  @type version: int
321 c41eea6e Iustin Pop
  @param version: configuration version
322 c41eea6e Iustin Pop
  @type cluster_config: L{objects.Cluster}
323 c41eea6e Iustin Pop
  @param cluster_config: cluster configuration
324 c41eea6e Iustin Pop
  @type master_node_config: L{objects.Node}
325 c41eea6e Iustin Pop
  @param master_node_config: master node configuration
326 c41eea6e Iustin Pop
  @type cfg_file: string
327 c41eea6e Iustin Pop
  @param cfg_file: configuration file path
328 c41eea6e Iustin Pop

329 7b3a8fb5 Iustin Pop
  """
330 7b3a8fb5 Iustin Pop
  nodes = {
331 7b3a8fb5 Iustin Pop
    master_node_config.name: master_node_config,
332 7b3a8fb5 Iustin Pop
    }
333 7b3a8fb5 Iustin Pop
334 d693c864 Iustin Pop
  now = time.time()
335 7b3a8fb5 Iustin Pop
  config_data = objects.ConfigData(version=version,
336 7b3a8fb5 Iustin Pop
                                   cluster=cluster_config,
337 7b3a8fb5 Iustin Pop
                                   nodes=nodes,
338 7b3a8fb5 Iustin Pop
                                   instances={},
339 d693c864 Iustin Pop
                                   serial_no=1,
340 d693c864 Iustin Pop
                                   ctime=now, mtime=now)
341 a33848a5 Guido Trotter
  utils.WriteFile(cfg_file,
342 a33848a5 Guido Trotter
                  data=serializer.Dump(config_data.ToDict()),
343 a33848a5 Guido Trotter
                  mode=0600)
344 02f99608 Oleksiy Mishchenko
345 02f99608 Oleksiy Mishchenko
346 140aa4a8 Iustin Pop
def FinalizeClusterDestroy(master):
347 140aa4a8 Iustin Pop
  """Execute the last steps of cluster destroy
348 140aa4a8 Iustin Pop

349 140aa4a8 Iustin Pop
  This function shuts down all the daemons, completing the destroy
350 140aa4a8 Iustin Pop
  begun in cmdlib.LUDestroyOpcode.
351 140aa4a8 Iustin Pop

352 140aa4a8 Iustin Pop
  """
353 b989b9d9 Ken Wehr
  cfg = config.ConfigWriter()
354 b989b9d9 Ken Wehr
  modify_ssh_setup = cfg.GetClusterInfo().modify_ssh_setup
355 781de953 Iustin Pop
  result = rpc.RpcRunner.call_node_stop_master(master, True)
356 3cebe102 Michael Hanselmann
  msg = result.fail_msg
357 6c00d19a Iustin Pop
  if msg:
358 099c52ad Iustin Pop
    logging.warning("Could not disable the master role: %s", msg)
359 b989b9d9 Ken Wehr
  result = rpc.RpcRunner.call_node_leave_cluster(master, modify_ssh_setup)
360 3cebe102 Michael Hanselmann
  msg = result.fail_msg
361 0623d351 Iustin Pop
  if msg:
362 0623d351 Iustin Pop
    logging.warning("Could not shutdown the node daemon and cleanup"
363 0623d351 Iustin Pop
                    " the node: %s", msg)
364 140aa4a8 Iustin Pop
365 140aa4a8 Iustin Pop
366 87622829 Iustin Pop
def SetupNodeDaemon(cluster_name, node, ssh_key_check):
367 827f753e Guido Trotter
  """Add a node to the cluster.
368 827f753e Guido Trotter

369 b1b6ea87 Iustin Pop
  This function must be called before the actual opcode, and will ssh
370 b1b6ea87 Iustin Pop
  to the remote node, copy the needed files, and start ganeti-noded,
371 b1b6ea87 Iustin Pop
  allowing the master to do the rest via normal rpc calls.
372 827f753e Guido Trotter

373 87622829 Iustin Pop
  @param cluster_name: the cluster name
374 87622829 Iustin Pop
  @param node: the name of the new node
375 87622829 Iustin Pop
  @param ssh_key_check: whether to do a strict key check
376 827f753e Guido Trotter

377 827f753e Guido Trotter
  """
378 87622829 Iustin Pop
  sshrunner = ssh.SshRunner(cluster_name)
379 5557b04c Michael Hanselmann
380 5557b04c Michael Hanselmann
  noded_cert = utils.ReadFile(constants.SSL_CERT_FILE)
381 2438c157 Michael Hanselmann
  rapi_cert = utils.ReadFile(constants.RAPI_CERT_FILE)
382 77b076ca Guido Trotter
  hmac_key = utils.ReadFile(constants.HMAC_CLUSTER_KEY)
383 5557b04c Michael Hanselmann
384 827f753e Guido Trotter
  # in the base64 pem encoding, neither '!' nor '.' are valid chars,
385 827f753e Guido Trotter
  # so we use this to detect an invalid certificate; as long as the
386 827f753e Guido Trotter
  # cert doesn't contain this, the here-document will be correctly
387 77b076ca Guido Trotter
  # parsed by the shell sequence below. HMAC keys are hexadecimal strings,
388 77b076ca Guido Trotter
  # so the same restrictions apply.
389 77b076ca Guido Trotter
  for content in (noded_cert, rapi_cert, hmac_key):
390 77b076ca Guido Trotter
    if re.search('^!EOF\.', content, re.MULTILINE):
391 77b076ca Guido Trotter
      raise errors.OpExecError("invalid SSL certificate or HMAC key")
392 5557b04c Michael Hanselmann
393 5557b04c Michael Hanselmann
  if not noded_cert.endswith("\n"):
394 5557b04c Michael Hanselmann
    noded_cert += "\n"
395 2438c157 Michael Hanselmann
  if not rapi_cert.endswith("\n"):
396 2438c157 Michael Hanselmann
    rapi_cert += "\n"
397 77b076ca Guido Trotter
  if not hmac_key.endswith("\n"):
398 77b076ca Guido Trotter
    hmac_key += "\n"
399 827f753e Guido Trotter
400 827f753e Guido Trotter
  # set up inter-node password and certificate and restarts the node daemon
401 827f753e Guido Trotter
  # and then connect with ssh to set password and start ganeti-noded
402 827f753e Guido Trotter
  # note that all the below variables are sanitized at this point,
403 827f753e Guido Trotter
  # either by being constants or by the checks above
404 827f753e Guido Trotter
  mycommand = ("umask 077 && "
405 827f753e Guido Trotter
               "cat > '%s' << '!EOF.' && \n"
406 2438c157 Michael Hanselmann
               "%s!EOF.\n"
407 2438c157 Michael Hanselmann
               "cat > '%s' << '!EOF.' && \n"
408 2438c157 Michael Hanselmann
               "%s!EOF.\n"
409 77b076ca Guido Trotter
               "cat > '%s' << '!EOF.' && \n"
410 77b076ca Guido Trotter
               "%s!EOF.\n"
411 77b076ca Guido Trotter
               "chmod 0400 %s %s %s && "
412 f154a7a3 Michael Hanselmann
               "%s start %s" %
413 5557b04c Michael Hanselmann
               (constants.SSL_CERT_FILE, noded_cert,
414 2438c157 Michael Hanselmann
                constants.RAPI_CERT_FILE, rapi_cert,
415 77b076ca Guido Trotter
                constants.HMAC_CLUSTER_KEY, hmac_key,
416 5b099da9 Michael Hanselmann
                constants.SSL_CERT_FILE, constants.RAPI_CERT_FILE,
417 77b076ca Guido Trotter
                constants.HMAC_CLUSTER_KEY,
418 f154a7a3 Michael Hanselmann
                constants.DAEMON_UTIL, constants.NODED))
419 827f753e Guido Trotter
420 c4b6c29c Michael Hanselmann
  result = sshrunner.Run(node, 'root', mycommand, batch=False,
421 c4b6c29c Michael Hanselmann
                         ask_key=ssh_key_check,
422 c4b6c29c Michael Hanselmann
                         use_cluster_key=False,
423 c4b6c29c Michael Hanselmann
                         strict_host_check=ssh_key_check)
424 827f753e Guido Trotter
  if result.failed:
425 827f753e Guido Trotter
    raise errors.OpExecError("Remote command on node %s, error: %s,"
426 827f753e Guido Trotter
                             " output: %s" %
427 827f753e Guido Trotter
                             (node, result.fail_reason, result.output))
428 827f753e Guido Trotter
429 b1b6ea87 Iustin Pop
430 8e2524c3 Guido Trotter
def MasterFailover(no_voting=False):
431 b1b6ea87 Iustin Pop
  """Failover the master node.
432 b1b6ea87 Iustin Pop

433 b1b6ea87 Iustin Pop
  This checks that we are not already the master, and will cause the
434 b1b6ea87 Iustin Pop
  current master to cease being master, and the non-master to become
435 b1b6ea87 Iustin Pop
  new master.
436 b1b6ea87 Iustin Pop

437 8e2524c3 Guido Trotter
  @type no_voting: boolean
438 8e2524c3 Guido Trotter
  @param no_voting: force the operation without remote nodes agreement
439 8e2524c3 Guido Trotter
                      (dangerous)
440 8e2524c3 Guido Trotter

441 b1b6ea87 Iustin Pop
  """
442 8135a2db Iustin Pop
  sstore = ssconf.SimpleStore()
443 b1b6ea87 Iustin Pop
444 8135a2db Iustin Pop
  old_master, new_master = ssconf.GetMasterAndMyself(sstore)
445 8135a2db Iustin Pop
  node_list = sstore.GetNodeList()
446 8135a2db Iustin Pop
  mc_list = sstore.GetMasterCandidates()
447 b1b6ea87 Iustin Pop
448 b1b6ea87 Iustin Pop
  if old_master == new_master:
449 b1b6ea87 Iustin Pop
    raise errors.OpPrereqError("This commands must be run on the node"
450 b1b6ea87 Iustin Pop
                               " where you want the new master to be."
451 b1b6ea87 Iustin Pop
                               " %s is already the master" %
452 debac808 Iustin Pop
                               old_master, errors.ECODE_INVAL)
453 d5927e48 Iustin Pop
454 8135a2db Iustin Pop
  if new_master not in mc_list:
455 8135a2db Iustin Pop
    mc_no_master = [name for name in mc_list if name != old_master]
456 8135a2db Iustin Pop
    raise errors.OpPrereqError("This node is not among the nodes marked"
457 8135a2db Iustin Pop
                               " as master candidates. Only these nodes"
458 8135a2db Iustin Pop
                               " can become masters. Current list of"
459 8135a2db Iustin Pop
                               " master candidates is:\n"
460 debac808 Iustin Pop
                               "%s" % ('\n'.join(mc_no_master)),
461 debac808 Iustin Pop
                               errors.ECODE_STATE)
462 8135a2db Iustin Pop
463 8e2524c3 Guido Trotter
  if not no_voting:
464 8e2524c3 Guido Trotter
    vote_list = GatherMasterVotes(node_list)
465 8e2524c3 Guido Trotter
466 8e2524c3 Guido Trotter
    if vote_list:
467 8e2524c3 Guido Trotter
      voted_master = vote_list[0][0]
468 8e2524c3 Guido Trotter
      if voted_master is None:
469 8e2524c3 Guido Trotter
        raise errors.OpPrereqError("Cluster is inconsistent, most nodes did"
470 debac808 Iustin Pop
                                   " not respond.", errors.ECODE_ENVIRON)
471 8e2524c3 Guido Trotter
      elif voted_master != old_master:
472 8e2524c3 Guido Trotter
        raise errors.OpPrereqError("I have a wrong configuration, I believe"
473 8e2524c3 Guido Trotter
                                   " the master is %s but the other nodes"
474 8e2524c3 Guido Trotter
                                   " voted %s. Please resync the configuration"
475 8e2524c3 Guido Trotter
                                   " of this node." %
476 debac808 Iustin Pop
                                   (old_master, voted_master),
477 debac808 Iustin Pop
                                   errors.ECODE_STATE)
478 b1b6ea87 Iustin Pop
  # end checks
479 b1b6ea87 Iustin Pop
480 b1b6ea87 Iustin Pop
  rcode = 0
481 b1b6ea87 Iustin Pop
482 d5927e48 Iustin Pop
  logging.info("Setting master to %s, old master: %s", new_master, old_master)
483 b1b6ea87 Iustin Pop
484 781de953 Iustin Pop
  result = rpc.RpcRunner.call_node_stop_master(old_master, True)
485 3cebe102 Michael Hanselmann
  msg = result.fail_msg
486 6c00d19a Iustin Pop
  if msg:
487 d5927e48 Iustin Pop
    logging.error("Could not disable the master role on the old master"
488 6c00d19a Iustin Pop
                 " %s, please disable manually: %s", old_master, msg)
489 b1b6ea87 Iustin Pop
490 d23ef431 Michael Hanselmann
  # Here we have a phase where no master should be running
491 b1b6ea87 Iustin Pop
492 bbe19c17 Iustin Pop
  # instantiate a real config writer, as we now know we have the
493 bbe19c17 Iustin Pop
  # configuration data
494 bbe19c17 Iustin Pop
  cfg = config.ConfigWriter()
495 b1b6ea87 Iustin Pop
496 bbe19c17 Iustin Pop
  cluster_info = cfg.GetClusterInfo()
497 bbe19c17 Iustin Pop
  cluster_info.master_node = new_master
498 bbe19c17 Iustin Pop
  # this will also regenerate the ssconf files, since we updated the
499 bbe19c17 Iustin Pop
  # cluster info
500 a4eae71f Michael Hanselmann
  cfg.Update(cluster_info, logging.error)
501 d5927e48 Iustin Pop
502 3583908a Guido Trotter
  result = rpc.RpcRunner.call_node_start_master(new_master, True, no_voting)
503 3cebe102 Michael Hanselmann
  msg = result.fail_msg
504 b726aff0 Iustin Pop
  if msg:
505 d5927e48 Iustin Pop
    logging.error("Could not start the master role on the new master"
506 b726aff0 Iustin Pop
                  " %s, please check: %s", new_master, msg)
507 b1b6ea87 Iustin Pop
    rcode = 1
508 b1b6ea87 Iustin Pop
509 b1b6ea87 Iustin Pop
  return rcode
510 d7cdb55d Iustin Pop
511 d7cdb55d Iustin Pop
512 8eb148ae Iustin Pop
def GetMaster():
513 8eb148ae Iustin Pop
  """Returns the current master node.
514 8eb148ae Iustin Pop

515 8eb148ae Iustin Pop
  This is a separate function in bootstrap since it's needed by
516 8eb148ae Iustin Pop
  gnt-cluster, and instead of importing directly ssconf, it's better
517 8eb148ae Iustin Pop
  to abstract it in bootstrap, where we do use ssconf in other
518 8eb148ae Iustin Pop
  functions too.
519 8eb148ae Iustin Pop

520 8eb148ae Iustin Pop
  """
521 8eb148ae Iustin Pop
  sstore = ssconf.SimpleStore()
522 8eb148ae Iustin Pop
523 8eb148ae Iustin Pop
  old_master, _ = ssconf.GetMasterAndMyself(sstore)
524 8eb148ae Iustin Pop
525 8eb148ae Iustin Pop
  return old_master
526 8eb148ae Iustin Pop
527 8eb148ae Iustin Pop
528 d7cdb55d Iustin Pop
def GatherMasterVotes(node_list):
529 d7cdb55d Iustin Pop
  """Check the agreement on who is the master.
530 d7cdb55d Iustin Pop

531 d7cdb55d Iustin Pop
  This function will return a list of (node, number of votes), ordered
532 d7cdb55d Iustin Pop
  by the number of votes. Errors will be denoted by the key 'None'.
533 d7cdb55d Iustin Pop

534 d7cdb55d Iustin Pop
  Note that the sum of votes is the number of nodes this machine
535 d7cdb55d Iustin Pop
  knows, whereas the number of entries in the list could be different
536 d7cdb55d Iustin Pop
  (if some nodes vote for another master).
537 d7cdb55d Iustin Pop

538 d7cdb55d Iustin Pop
  We remove ourselves from the list since we know that (bugs aside)
539 d7cdb55d Iustin Pop
  since we use the same source for configuration information for both
540 d7cdb55d Iustin Pop
  backend and boostrap, we'll always vote for ourselves.
541 d7cdb55d Iustin Pop

542 d7cdb55d Iustin Pop
  @type node_list: list
543 d7cdb55d Iustin Pop
  @param node_list: the list of nodes to query for master info; the current
544 5bbd3f7f Michael Hanselmann
      node will be removed if it is in the list
545 d7cdb55d Iustin Pop
  @rtype: list
546 d7cdb55d Iustin Pop
  @return: list of (node, votes)
547 d7cdb55d Iustin Pop

548 d7cdb55d Iustin Pop
  """
549 d7cdb55d Iustin Pop
  myself = utils.HostInfo().name
550 d7cdb55d Iustin Pop
  try:
551 d7cdb55d Iustin Pop
    node_list.remove(myself)
552 d7cdb55d Iustin Pop
  except ValueError:
553 d7cdb55d Iustin Pop
    pass
554 d7cdb55d Iustin Pop
  if not node_list:
555 d7cdb55d Iustin Pop
    # no nodes left (eventually after removing myself)
556 d7cdb55d Iustin Pop
    return []
557 d7cdb55d Iustin Pop
  results = rpc.RpcRunner.call_master_info(node_list)
558 d7cdb55d Iustin Pop
  if not isinstance(results, dict):
559 d7cdb55d Iustin Pop
    # this should not happen (unless internal error in rpc)
560 d7cdb55d Iustin Pop
    logging.critical("Can't complete rpc call, aborting master startup")
561 d7cdb55d Iustin Pop
    return [(None, len(node_list))]
562 d7cdb55d Iustin Pop
  votes = {}
563 d7cdb55d Iustin Pop
  for node in results:
564 781de953 Iustin Pop
    nres = results[node]
565 2a52a064 Iustin Pop
    data = nres.payload
566 3cebe102 Michael Hanselmann
    msg = nres.fail_msg
567 2a52a064 Iustin Pop
    fail = False
568 2a52a064 Iustin Pop
    if msg:
569 2a52a064 Iustin Pop
      logging.warning("Error contacting node %s: %s", node, msg)
570 2a52a064 Iustin Pop
      fail = True
571 2a52a064 Iustin Pop
    elif not isinstance(data, (tuple, list)) or len(data) < 3:
572 2a52a064 Iustin Pop
      logging.warning("Invalid data received from node %s: %s", node, data)
573 2a52a064 Iustin Pop
      fail = True
574 2a52a064 Iustin Pop
    if fail:
575 d7cdb55d Iustin Pop
      if None not in votes:
576 d7cdb55d Iustin Pop
        votes[None] = 0
577 d7cdb55d Iustin Pop
      votes[None] += 1
578 d7cdb55d Iustin Pop
      continue
579 781de953 Iustin Pop
    master_node = data[2]
580 d7cdb55d Iustin Pop
    if master_node not in votes:
581 d7cdb55d Iustin Pop
      votes[master_node] = 0
582 d7cdb55d Iustin Pop
    votes[master_node] += 1
583 d7cdb55d Iustin Pop
584 d7cdb55d Iustin Pop
  vote_list = [v for v in votes.items()]
585 d7cdb55d Iustin Pop
  # sort first on number of votes then on name, since we want None
586 d7cdb55d Iustin Pop
  # sorted later if we have the half of the nodes not responding, and
587 d7cdb55d Iustin Pop
  # half voting all for the same master
588 d7cdb55d Iustin Pop
  vote_list.sort(key=lambda x: (x[1], x[0]), reverse=True)
589 d7cdb55d Iustin Pop
590 d7cdb55d Iustin Pop
  return vote_list