root / lib / bootstrap.py @ 87bc7ca8
History | View | Annotate | Download (28.7 kB)
1 | a0c9f010 | Michael Hanselmann | #
|
---|---|---|---|
2 | a0c9f010 | Michael Hanselmann | #
|
3 | a0c9f010 | Michael Hanselmann | |
4 | 87bc7ca8 | Apollon Oikonomopoulos | # Copyright (C) 2006, 2007, 2008, 2010, 2011 Google Inc.
|
5 | a0c9f010 | Michael Hanselmann | #
|
6 | a0c9f010 | Michael Hanselmann | # This program is free software; you can redistribute it and/or modify
|
7 | a0c9f010 | Michael Hanselmann | # it under the terms of the GNU General Public License as published by
|
8 | a0c9f010 | Michael Hanselmann | # the Free Software Foundation; either version 2 of the License, or
|
9 | a0c9f010 | Michael Hanselmann | # (at your option) any later version.
|
10 | a0c9f010 | Michael Hanselmann | #
|
11 | a0c9f010 | Michael Hanselmann | # This program is distributed in the hope that it will be useful, but
|
12 | a0c9f010 | Michael Hanselmann | # WITHOUT ANY WARRANTY; without even the implied warranty of
|
13 | a0c9f010 | Michael Hanselmann | # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
14 | a0c9f010 | Michael Hanselmann | # General Public License for more details.
|
15 | a0c9f010 | Michael Hanselmann | #
|
16 | a0c9f010 | Michael Hanselmann | # You should have received a copy of the GNU General Public License
|
17 | a0c9f010 | Michael Hanselmann | # along with this program; if not, write to the Free Software
|
18 | a0c9f010 | Michael Hanselmann | # Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
|
19 | a0c9f010 | Michael Hanselmann | # 02110-1301, USA.
|
20 | a0c9f010 | Michael Hanselmann | |
21 | a0c9f010 | Michael Hanselmann | |
22 | a0c9f010 | Michael Hanselmann | """Functions to bootstrap a new cluster.
|
23 | a0c9f010 | Michael Hanselmann |
|
24 | a0c9f010 | Michael Hanselmann | """
|
25 | a0c9f010 | Michael Hanselmann | |
26 | a0c9f010 | Michael Hanselmann | import os |
27 | a0c9f010 | Michael Hanselmann | import os.path |
28 | a0c9f010 | Michael Hanselmann | import re |
29 | b1b6ea87 | Iustin Pop | import logging |
30 | d693c864 | Iustin Pop | import time |
31 | a0c9f010 | Michael Hanselmann | |
32 | a0c9f010 | Michael Hanselmann | from ganeti import rpc |
33 | a0c9f010 | Michael Hanselmann | from ganeti import ssh |
34 | a0c9f010 | Michael Hanselmann | from ganeti import utils |
35 | a0c9f010 | Michael Hanselmann | from ganeti import errors |
36 | a0c9f010 | Michael Hanselmann | from ganeti import config |
37 | a0c9f010 | Michael Hanselmann | from ganeti import constants |
38 | b9eeeb02 | Michael Hanselmann | from ganeti import objects |
39 | a0c9f010 | Michael Hanselmann | from ganeti import ssconf |
40 | a33848a5 | Guido Trotter | from ganeti import serializer |
41 | a5728081 | Guido Trotter | from ganeti import hypervisor |
42 | a721e23a | Luca Bigliardi | from ganeti import bdev |
43 | a744b676 | Manuel Franceschini | from ganeti import netutils |
44 | d367b66c | Manuel Franceschini | from ganeti import backend |
45 | 3b6b6129 | Michael Hanselmann | from ganeti import luxi |
46 | 3b6b6129 | Michael Hanselmann | |
47 | a0c9f010 | Michael Hanselmann | |
48 | 88b92fe3 | Guido Trotter | # ec_id for InitConfig's temporary reservation manager
|
49 | 88b92fe3 | Guido Trotter | _INITCONF_ECID = "initconfig-ecid"
|
50 | 88b92fe3 | Guido Trotter | |
51 | 3b6b6129 | Michael Hanselmann | #: After how many seconds daemon must be responsive
|
52 | 3b6b6129 | Michael Hanselmann | _DAEMON_READY_TIMEOUT = 10.0
|
53 | 3b6b6129 | Michael Hanselmann | |
54 | e38220e4 | Michael Hanselmann | |
55 | 531baf8e | Iustin Pop | def _InitSSHSetup(): |
56 | a0c9f010 | Michael Hanselmann | """Setup the SSH configuration for the cluster.
|
57 | a0c9f010 | Michael Hanselmann |
|
58 | a0c9f010 | Michael Hanselmann | This generates a dsa keypair for root, adds the pub key to the
|
59 | a0c9f010 | Michael Hanselmann | permitted hosts and adds the hostkey to its own known hosts.
|
60 | a0c9f010 | Michael Hanselmann |
|
61 | a0c9f010 | Michael Hanselmann | """
|
62 | a0c9f010 | Michael Hanselmann | priv_key, pub_key, auth_keys = ssh.GetUserFiles(constants.GANETI_RUNAS) |
63 | a0c9f010 | Michael Hanselmann | |
64 | a0c9f010 | Michael Hanselmann | for name in priv_key, pub_key: |
65 | a0c9f010 | Michael Hanselmann | if os.path.exists(name):
|
66 | a0c9f010 | Michael Hanselmann | utils.CreateBackup(name) |
67 | a0c9f010 | Michael Hanselmann | utils.RemoveFile(name) |
68 | a0c9f010 | Michael Hanselmann | |
69 | a0c9f010 | Michael Hanselmann | result = utils.RunCmd(["ssh-keygen", "-t", "dsa", |
70 | a0c9f010 | Michael Hanselmann | "-f", priv_key,
|
71 | a0c9f010 | Michael Hanselmann | "-q", "-N", ""]) |
72 | a0c9f010 | Michael Hanselmann | if result.failed:
|
73 | a0c9f010 | Michael Hanselmann | raise errors.OpExecError("Could not generate ssh keypair, error %s" % |
74 | a0c9f010 | Michael Hanselmann | result.output) |
75 | a0c9f010 | Michael Hanselmann | |
76 | 7a0156dc | Luca Bigliardi | utils.AddAuthorizedKey(auth_keys, utils.ReadFile(pub_key)) |
77 | a0c9f010 | Michael Hanselmann | |
78 | a0c9f010 | Michael Hanselmann | |
79 | c008906b | Michael Hanselmann | def GenerateHmacKey(file_name): |
80 | c008906b | Michael Hanselmann | """Writes a new HMAC key.
|
81 | c008906b | Michael Hanselmann |
|
82 | c008906b | Michael Hanselmann | @type file_name: str
|
83 | c008906b | Michael Hanselmann | @param file_name: Path to output file
|
84 | c008906b | Michael Hanselmann |
|
85 | c008906b | Michael Hanselmann | """
|
86 | 43575108 | Michael Hanselmann | utils.WriteFile(file_name, data="%s\n" % utils.GenerateSecret(), mode=0400, |
87 | 43575108 | Michael Hanselmann | backup=True)
|
88 | 43575108 | Michael Hanselmann | |
89 | 43575108 | Michael Hanselmann | |
90 | 6b7d5878 | Michael Hanselmann | def GenerateClusterCrypto(new_cluster_cert, new_rapi_cert, new_confd_hmac_key, |
91 | af2ae1c0 | Iustin Pop | new_cds, rapi_cert_pem=None, cds=None, |
92 | aeefe835 | Iustin Pop | nodecert_file=constants.NODED_CERT_FILE, |
93 | aeefe835 | Iustin Pop | rapicert_file=constants.RAPI_CERT_FILE, |
94 | fc0726b9 | Michael Hanselmann | hmackey_file=constants.CONFD_HMAC_KEY, |
95 | fc0726b9 | Michael Hanselmann | cds_file=constants.CLUSTER_DOMAIN_SECRET_FILE): |
96 | 43575108 | Michael Hanselmann | """Updates the cluster certificates, keys and secrets.
|
97 | 43575108 | Michael Hanselmann |
|
98 | 43575108 | Michael Hanselmann | @type new_cluster_cert: bool
|
99 | 43575108 | Michael Hanselmann | @param new_cluster_cert: Whether to generate a new cluster certificate
|
100 | 43575108 | Michael Hanselmann | @type new_rapi_cert: bool
|
101 | 43575108 | Michael Hanselmann | @param new_rapi_cert: Whether to generate a new RAPI certificate
|
102 | 6b7d5878 | Michael Hanselmann | @type new_confd_hmac_key: bool
|
103 | 6b7d5878 | Michael Hanselmann | @param new_confd_hmac_key: Whether to generate a new HMAC key
|
104 | 3db3eb2a | Michael Hanselmann | @type new_cds: bool
|
105 | 3db3eb2a | Michael Hanselmann | @param new_cds: Whether to generate a new cluster domain secret
|
106 | 43575108 | Michael Hanselmann | @type rapi_cert_pem: string
|
107 | 43575108 | Michael Hanselmann | @param rapi_cert_pem: New RAPI certificate in PEM format
|
108 | 3db3eb2a | Michael Hanselmann | @type cds: string
|
109 | 3db3eb2a | Michael Hanselmann | @param cds: New cluster domain secret
|
110 | aeefe835 | Iustin Pop | @type nodecert_file: string
|
111 | aeefe835 | Iustin Pop | @param nodecert_file: optional override of the node cert file path
|
112 | aeefe835 | Iustin Pop | @type rapicert_file: string
|
113 | aeefe835 | Iustin Pop | @param rapicert_file: optional override of the rapi cert file path
|
114 | aeefe835 | Iustin Pop | @type hmackey_file: string
|
115 | aeefe835 | Iustin Pop | @param hmackey_file: optional override of the hmac key file path
|
116 | 43575108 | Michael Hanselmann |
|
117 | 43575108 | Michael Hanselmann | """
|
118 | 168c1de2 | Michael Hanselmann | # noded SSL certificate
|
119 | aeefe835 | Iustin Pop | cluster_cert_exists = os.path.exists(nodecert_file) |
120 | 43575108 | Michael Hanselmann | if new_cluster_cert or not cluster_cert_exists: |
121 | 43575108 | Michael Hanselmann | if cluster_cert_exists:
|
122 | aeefe835 | Iustin Pop | utils.CreateBackup(nodecert_file) |
123 | 43575108 | Michael Hanselmann | |
124 | aeefe835 | Iustin Pop | logging.debug("Generating new cluster certificate at %s", nodecert_file)
|
125 | af2ae1c0 | Iustin Pop | utils.GenerateSelfSignedSslCert(nodecert_file) |
126 | 43575108 | Michael Hanselmann | |
127 | 6b7d5878 | Michael Hanselmann | # confd HMAC key
|
128 | aeefe835 | Iustin Pop | if new_confd_hmac_key or not os.path.exists(hmackey_file): |
129 | aeefe835 | Iustin Pop | logging.debug("Writing new confd HMAC key to %s", hmackey_file)
|
130 | aeefe835 | Iustin Pop | GenerateHmacKey(hmackey_file) |
131 | 43575108 | Michael Hanselmann | |
132 | 43575108 | Michael Hanselmann | # RAPI
|
133 | aeefe835 | Iustin Pop | rapi_cert_exists = os.path.exists(rapicert_file) |
134 | 43575108 | Michael Hanselmann | |
135 | 43575108 | Michael Hanselmann | if rapi_cert_pem:
|
136 | 43575108 | Michael Hanselmann | # Assume rapi_pem contains a valid PEM-formatted certificate and key
|
137 | aeefe835 | Iustin Pop | logging.debug("Writing RAPI certificate at %s", rapicert_file)
|
138 | aeefe835 | Iustin Pop | utils.WriteFile(rapicert_file, data=rapi_cert_pem, backup=True)
|
139 | 43575108 | Michael Hanselmann | |
140 | 43575108 | Michael Hanselmann | elif new_rapi_cert or not rapi_cert_exists: |
141 | 43575108 | Michael Hanselmann | if rapi_cert_exists:
|
142 | aeefe835 | Iustin Pop | utils.CreateBackup(rapicert_file) |
143 | 43575108 | Michael Hanselmann | |
144 | aeefe835 | Iustin Pop | logging.debug("Generating new RAPI certificate at %s", rapicert_file)
|
145 | af2ae1c0 | Iustin Pop | utils.GenerateSelfSignedSslCert(rapicert_file) |
146 | c008906b | Michael Hanselmann | |
147 | 3db3eb2a | Michael Hanselmann | # Cluster domain secret
|
148 | 3db3eb2a | Michael Hanselmann | if cds:
|
149 | fc0726b9 | Michael Hanselmann | logging.debug("Writing cluster domain secret to %s", cds_file)
|
150 | fc0726b9 | Michael Hanselmann | utils.WriteFile(cds_file, data=cds, backup=True)
|
151 | fc0726b9 | Michael Hanselmann | |
152 | fc0726b9 | Michael Hanselmann | elif new_cds or not os.path.exists(cds_file): |
153 | fc0726b9 | Michael Hanselmann | logging.debug("Generating new cluster domain secret at %s", cds_file)
|
154 | fc0726b9 | Michael Hanselmann | GenerateHmacKey(cds_file) |
155 | 3db3eb2a | Michael Hanselmann | |
156 | c008906b | Michael Hanselmann | |
157 | 8f215968 | Michael Hanselmann | def _InitGanetiServerSetup(master_name): |
158 | 40a97d80 | Michael Hanselmann | """Setup the necessary configuration for the initial node daemon.
|
159 | 40a97d80 | Michael Hanselmann |
|
160 | 40a97d80 | Michael Hanselmann | This creates the nodepass file containing the shared password for
|
161 | 600535f0 | Manuel Franceschini | the cluster, generates the SSL certificate and starts the node daemon.
|
162 | 600535f0 | Manuel Franceschini |
|
163 | 600535f0 | Manuel Franceschini | @type master_name: str
|
164 | 600535f0 | Manuel Franceschini | @param master_name: Name of the master node
|
165 | 40a97d80 | Michael Hanselmann |
|
166 | 40a97d80 | Michael Hanselmann | """
|
167 | 43575108 | Michael Hanselmann | # Generate cluster secrets
|
168 | 3db3eb2a | Michael Hanselmann | GenerateClusterCrypto(True, False, False, False) |
169 | 4a34c5cf | Guido Trotter | |
170 | f154a7a3 | Michael Hanselmann | result = utils.RunCmd([constants.DAEMON_UTIL, "start", constants.NODED])
|
171 | a0c9f010 | Michael Hanselmann | if result.failed:
|
172 | a0c9f010 | Michael Hanselmann | raise errors.OpExecError("Could not start the node daemon, command %s" |
173 | a0c9f010 | Michael Hanselmann | " had exitcode %s and error %s" %
|
174 | a0c9f010 | Michael Hanselmann | (result.cmd, result.exit_code, result.output)) |
175 | a0c9f010 | Michael Hanselmann | |
176 | 5627f375 | Michael Hanselmann | _WaitForNodeDaemon(master_name) |
177 | 5627f375 | Michael Hanselmann | |
178 | 5627f375 | Michael Hanselmann | |
179 | 5627f375 | Michael Hanselmann | def _WaitForNodeDaemon(node_name): |
180 | 5627f375 | Michael Hanselmann | """Wait for node daemon to become responsive.
|
181 | 5627f375 | Michael Hanselmann |
|
182 | 5627f375 | Michael Hanselmann | """
|
183 | d3833ebd | Michael Hanselmann | def _CheckNodeDaemon(): |
184 | 5627f375 | Michael Hanselmann | result = rpc.RpcRunner.call_version([node_name])[node_name] |
185 | d3833ebd | Michael Hanselmann | if result.fail_msg:
|
186 | d3833ebd | Michael Hanselmann | raise utils.RetryAgain()
|
187 | 8f215968 | Michael Hanselmann | |
188 | d3833ebd | Michael Hanselmann | try:
|
189 | 3b6b6129 | Michael Hanselmann | utils.Retry(_CheckNodeDaemon, 1.0, _DAEMON_READY_TIMEOUT)
|
190 | d3833ebd | Michael Hanselmann | except utils.RetryTimeout:
|
191 | 5627f375 | Michael Hanselmann | raise errors.OpExecError("Node daemon on %s didn't answer queries within" |
192 | 3b6b6129 | Michael Hanselmann | " %s seconds" % (node_name, _DAEMON_READY_TIMEOUT))
|
193 | 3b6b6129 | Michael Hanselmann | |
194 | 3b6b6129 | Michael Hanselmann | |
195 | 3b6b6129 | Michael Hanselmann | def _WaitForMasterDaemon(): |
196 | 3b6b6129 | Michael Hanselmann | """Wait for master daemon to become responsive.
|
197 | 3b6b6129 | Michael Hanselmann |
|
198 | 3b6b6129 | Michael Hanselmann | """
|
199 | 3b6b6129 | Michael Hanselmann | def _CheckMasterDaemon(): |
200 | 3b6b6129 | Michael Hanselmann | try:
|
201 | 3b6b6129 | Michael Hanselmann | cl = luxi.Client() |
202 | 3b6b6129 | Michael Hanselmann | (cluster_name, ) = cl.QueryConfigValues(["cluster_name"])
|
203 | 3b6b6129 | Michael Hanselmann | except Exception: |
204 | 3b6b6129 | Michael Hanselmann | raise utils.RetryAgain()
|
205 | 3b6b6129 | Michael Hanselmann | |
206 | 3b6b6129 | Michael Hanselmann | logging.debug("Received cluster name %s from master", cluster_name)
|
207 | 3b6b6129 | Michael Hanselmann | |
208 | 3b6b6129 | Michael Hanselmann | try:
|
209 | 3b6b6129 | Michael Hanselmann | utils.Retry(_CheckMasterDaemon, 1.0, _DAEMON_READY_TIMEOUT)
|
210 | 3b6b6129 | Michael Hanselmann | except utils.RetryTimeout:
|
211 | 3b6b6129 | Michael Hanselmann | raise errors.OpExecError("Master daemon didn't answer queries within" |
212 | 3b6b6129 | Michael Hanselmann | " %s seconds" % _DAEMON_READY_TIMEOUT)
|
213 | 5627f375 | Michael Hanselmann | |
214 | a0c9f010 | Michael Hanselmann | |
215 | 0e3baaf3 | Iustin Pop | def _InitFileStorage(file_storage_dir): |
216 | 0e3baaf3 | Iustin Pop | """Initialize if needed the file storage.
|
217 | 0e3baaf3 | Iustin Pop |
|
218 | 0e3baaf3 | Iustin Pop | @param file_storage_dir: the user-supplied value
|
219 | 0e3baaf3 | Iustin Pop | @return: either empty string (if file storage was disabled at build
|
220 | 0e3baaf3 | Iustin Pop | time) or the normalized path to the storage directory
|
221 | 0e3baaf3 | Iustin Pop |
|
222 | 0e3baaf3 | Iustin Pop | """
|
223 | 0e3baaf3 | Iustin Pop | if not constants.ENABLE_FILE_STORAGE: |
224 | 0e3baaf3 | Iustin Pop | return "" |
225 | 0e3baaf3 | Iustin Pop | |
226 | 0e3baaf3 | Iustin Pop | file_storage_dir = os.path.normpath(file_storage_dir) |
227 | 0e3baaf3 | Iustin Pop | |
228 | 0e3baaf3 | Iustin Pop | if not os.path.isabs(file_storage_dir): |
229 | 0e3baaf3 | Iustin Pop | raise errors.OpPrereqError("The file storage directory you passed is" |
230 | 0e3baaf3 | Iustin Pop | " not an absolute path.", errors.ECODE_INVAL)
|
231 | 0e3baaf3 | Iustin Pop | |
232 | 0e3baaf3 | Iustin Pop | if not os.path.exists(file_storage_dir): |
233 | 0e3baaf3 | Iustin Pop | try:
|
234 | 0e3baaf3 | Iustin Pop | os.makedirs(file_storage_dir, 0750)
|
235 | 0e3baaf3 | Iustin Pop | except OSError, err: |
236 | 0e3baaf3 | Iustin Pop | raise errors.OpPrereqError("Cannot create file storage directory" |
237 | 0e3baaf3 | Iustin Pop | " '%s': %s" % (file_storage_dir, err),
|
238 | 0e3baaf3 | Iustin Pop | errors.ECODE_ENVIRON) |
239 | 0e3baaf3 | Iustin Pop | |
240 | 0e3baaf3 | Iustin Pop | if not os.path.isdir(file_storage_dir): |
241 | 0e3baaf3 | Iustin Pop | raise errors.OpPrereqError("The file storage directory '%s' is not" |
242 | 0e3baaf3 | Iustin Pop | " a directory." % file_storage_dir,
|
243 | 0e3baaf3 | Iustin Pop | errors.ECODE_ENVIRON) |
244 | 0e3baaf3 | Iustin Pop | return file_storage_dir
|
245 | 0e3baaf3 | Iustin Pop | |
246 | 0e3baaf3 | Iustin Pop | |
247 | 87bc7ca8 | Apollon Oikonomopoulos | def _InitSharedFileStorage(shared_file_storage_dir): |
248 | 87bc7ca8 | Apollon Oikonomopoulos | """Initialize if needed the shared file storage.
|
249 | 87bc7ca8 | Apollon Oikonomopoulos |
|
250 | 87bc7ca8 | Apollon Oikonomopoulos | @param shared_file_storage_dir: the user-supplied value
|
251 | 87bc7ca8 | Apollon Oikonomopoulos | @return: either empty string (if file storage was disabled at build
|
252 | 87bc7ca8 | Apollon Oikonomopoulos | time) or the normalized path to the storage directory
|
253 | 87bc7ca8 | Apollon Oikonomopoulos |
|
254 | 87bc7ca8 | Apollon Oikonomopoulos | """
|
255 | 87bc7ca8 | Apollon Oikonomopoulos | if not constants.ENABLE_SHARED_FILE_STORAGE: |
256 | 87bc7ca8 | Apollon Oikonomopoulos | return "" |
257 | 87bc7ca8 | Apollon Oikonomopoulos | |
258 | 87bc7ca8 | Apollon Oikonomopoulos | shared_file_storage_dir = os.path.normpath(shared_file_storage_dir) |
259 | 87bc7ca8 | Apollon Oikonomopoulos | |
260 | 87bc7ca8 | Apollon Oikonomopoulos | if not os.path.isabs(shared_file_storage_dir): |
261 | 87bc7ca8 | Apollon Oikonomopoulos | raise errors.OpPrereqError("The shared file storage directory you" |
262 | 87bc7ca8 | Apollon Oikonomopoulos | " passed is not an absolute path.",
|
263 | 87bc7ca8 | Apollon Oikonomopoulos | errors.ECODE_INVAL) |
264 | 87bc7ca8 | Apollon Oikonomopoulos | |
265 | 87bc7ca8 | Apollon Oikonomopoulos | if not os.path.exists(shared_file_storage_dir): |
266 | 87bc7ca8 | Apollon Oikonomopoulos | try:
|
267 | 87bc7ca8 | Apollon Oikonomopoulos | os.makedirs(shared_file_storage_dir, 0750)
|
268 | 87bc7ca8 | Apollon Oikonomopoulos | except OSError, err: |
269 | 87bc7ca8 | Apollon Oikonomopoulos | raise errors.OpPrereqError("Cannot create file storage directory" |
270 | 87bc7ca8 | Apollon Oikonomopoulos | " '%s': %s" % (shared_file_storage_dir, err),
|
271 | 87bc7ca8 | Apollon Oikonomopoulos | errors.ECODE_ENVIRON) |
272 | 87bc7ca8 | Apollon Oikonomopoulos | |
273 | 87bc7ca8 | Apollon Oikonomopoulos | if not os.path.isdir(shared_file_storage_dir): |
274 | 87bc7ca8 | Apollon Oikonomopoulos | raise errors.OpPrereqError("The file storage directory '%s' is not" |
275 | 87bc7ca8 | Apollon Oikonomopoulos | " a directory." % shared_file_storage_dir,
|
276 | 87bc7ca8 | Apollon Oikonomopoulos | errors.ECODE_ENVIRON) |
277 | 87bc7ca8 | Apollon Oikonomopoulos | return shared_file_storage_dir
|
278 | 87bc7ca8 | Apollon Oikonomopoulos | |
279 | 87bc7ca8 | Apollon Oikonomopoulos | |
280 | 952d7515 | Michael Hanselmann | def InitCluster(cluster_name, mac_prefix, # pylint: disable-msg=R0913 |
281 | 87bc7ca8 | Apollon Oikonomopoulos | master_netdev, file_storage_dir, shared_file_storage_dir, |
282 | 87bc7ca8 | Apollon Oikonomopoulos | candidate_pool_size, secondary_ip=None, vg_name=None, |
283 | 87bc7ca8 | Apollon Oikonomopoulos | beparams=None, nicparams=None, ndparams=None, hvparams=None, |
284 | 6204ee71 | Renรฉ Nussbaumer | enabled_hypervisors=None, modify_etc_hosts=True, |
285 | 6204ee71 | Renรฉ Nussbaumer | modify_ssh_setup=True, maintain_node_health=False, |
286 | 6204ee71 | Renรฉ Nussbaumer | drbd_helper=None, uid_pool=None, default_iallocator=None, |
287 | 3d914585 | Renรฉ Nussbaumer | primary_ip_version=None, prealloc_wipe_disks=False): |
288 | a0c9f010 | Michael Hanselmann | """Initialise the cluster.
|
289 | a0c9f010 | Michael Hanselmann |
|
290 | ce735215 | Guido Trotter | @type candidate_pool_size: int
|
291 | ce735215 | Guido Trotter | @param candidate_pool_size: master candidate pool size
|
292 | ce735215 | Guido Trotter |
|
293 | a0c9f010 | Michael Hanselmann | """
|
294 | ce735215 | Guido Trotter | # TODO: complete the docstring
|
295 | a0c9f010 | Michael Hanselmann | if config.ConfigWriter.IsCluster():
|
296 | debac808 | Iustin Pop | raise errors.OpPrereqError("Cluster is already initialised", |
297 | debac808 | Iustin Pop | errors.ECODE_STATE) |
298 | a0c9f010 | Michael Hanselmann | |
299 | b119bccb | Guido Trotter | if not enabled_hypervisors: |
300 | b119bccb | Guido Trotter | raise errors.OpPrereqError("Enabled hypervisors list must contain at" |
301 | debac808 | Iustin Pop | " least one member", errors.ECODE_INVAL)
|
302 | b119bccb | Guido Trotter | invalid_hvs = set(enabled_hypervisors) - constants.HYPER_TYPES
|
303 | b119bccb | Guido Trotter | if invalid_hvs:
|
304 | b119bccb | Guido Trotter | raise errors.OpPrereqError("Enabled hypervisors contains invalid" |
305 | debac808 | Iustin Pop | " entries: %s" % invalid_hvs,
|
306 | debac808 | Iustin Pop | errors.ECODE_INVAL) |
307 | b119bccb | Guido Trotter | |
308 | a0c9f010 | Michael Hanselmann | |
309 | 2f20d07b | Manuel Franceschini | ipcls = None
|
310 | 2f20d07b | Manuel Franceschini | if primary_ip_version == constants.IP4_VERSION:
|
311 | 2f20d07b | Manuel Franceschini | ipcls = netutils.IP4Address |
312 | 2f20d07b | Manuel Franceschini | elif primary_ip_version == constants.IP6_VERSION:
|
313 | 2f20d07b | Manuel Franceschini | ipcls = netutils.IP6Address |
314 | 2f20d07b | Manuel Franceschini | else:
|
315 | 2f20d07b | Manuel Franceschini | raise errors.OpPrereqError("Invalid primary ip version: %d." % |
316 | 2f20d07b | Manuel Franceschini | primary_ip_version) |
317 | 2f20d07b | Manuel Franceschini | |
318 | 2f20d07b | Manuel Franceschini | hostname = netutils.GetHostname(family=ipcls.family) |
319 | 2f20d07b | Manuel Franceschini | if not ipcls.IsValid(hostname.ip): |
320 | 2f20d07b | Manuel Franceschini | raise errors.OpPrereqError("This host's IP (%s) is not a valid IPv%d" |
321 | 2f20d07b | Manuel Franceschini | " address." % (hostname.ip, primary_ip_version))
|
322 | 2f20d07b | Manuel Franceschini | |
323 | 2f20d07b | Manuel Franceschini | if ipcls.IsLoopback(hostname.ip):
|
324 | 8b312c1d | Manuel Franceschini | raise errors.OpPrereqError("This host's IP (%s) resolves to a loopback" |
325 | 8b312c1d | Manuel Franceschini | " address. Please fix DNS or %s." %
|
326 | debac808 | Iustin Pop | (hostname.ip, constants.ETC_HOSTS), |
327 | debac808 | Iustin Pop | errors.ECODE_ENVIRON) |
328 | a0c9f010 | Michael Hanselmann | |
329 | 2f20d07b | Manuel Franceschini | if not ipcls.Own(hostname.ip): |
330 | a0c9f010 | Michael Hanselmann | raise errors.OpPrereqError("Inconsistency: this host's name resolves" |
331 | a0c9f010 | Michael Hanselmann | " to %s,\nbut this ip address does not"
|
332 | 7c4c22f5 | Manuel Franceschini | " belong to this host" %
|
333 | debac808 | Iustin Pop | hostname.ip, errors.ECODE_ENVIRON) |
334 | a0c9f010 | Michael Hanselmann | |
335 | 2f20d07b | Manuel Franceschini | clustername = netutils.GetHostname(name=cluster_name, family=ipcls.family) |
336 | a0c9f010 | Michael Hanselmann | |
337 | 2f20d07b | Manuel Franceschini | if netutils.TcpPing(clustername.ip, constants.DEFAULT_NODED_PORT, timeout=5): |
338 | 7c4c22f5 | Manuel Franceschini | raise errors.OpPrereqError("Cluster IP already active", |
339 | debac808 | Iustin Pop | errors.ECODE_NOTUNIQUE) |
340 | a0c9f010 | Michael Hanselmann | |
341 | 2f20d07b | Manuel Franceschini | if not secondary_ip: |
342 | 2f20d07b | Manuel Franceschini | if primary_ip_version == constants.IP6_VERSION:
|
343 | 2f20d07b | Manuel Franceschini | raise errors.OpPrereqError("When using a IPv6 primary address, a valid" |
344 | 7c4c22f5 | Manuel Franceschini | " IPv4 address must be given as secondary",
|
345 | 7c4c22f5 | Manuel Franceschini | errors.ECODE_INVAL) |
346 | b9eeeb02 | Michael Hanselmann | secondary_ip = hostname.ip |
347 | a0c9f010 | Michael Hanselmann | |
348 | 2f20d07b | Manuel Franceschini | if not netutils.IP4Address.IsValid(secondary_ip): |
349 | 2f20d07b | Manuel Franceschini | raise errors.OpPrereqError("Secondary IP address (%s) has to be a valid" |
350 | 2f20d07b | Manuel Franceschini | " IPv4 address." % secondary_ip,
|
351 | 2f20d07b | Manuel Franceschini | errors.ECODE_INVAL) |
352 | 2f20d07b | Manuel Franceschini | |
353 | 2f20d07b | Manuel Franceschini | if not netutils.IP4Address.Own(secondary_ip): |
354 | 2f20d07b | Manuel Franceschini | raise errors.OpPrereqError("You gave %s as secondary IP," |
355 | 2f20d07b | Manuel Franceschini | " but it does not belong to this host." %
|
356 | 2f20d07b | Manuel Franceschini | secondary_ip, errors.ECODE_ENVIRON) |
357 | 2f20d07b | Manuel Franceschini | |
358 | a0c9f010 | Michael Hanselmann | if vg_name is not None: |
359 | a0c9f010 | Michael Hanselmann | # Check if volume group is valid
|
360 | a0c9f010 | Michael Hanselmann | vgstatus = utils.CheckVolumeGroupSize(utils.ListVolumeGroups(), vg_name, |
361 | a0c9f010 | Michael Hanselmann | constants.MIN_VG_SIZE) |
362 | a0c9f010 | Michael Hanselmann | if vgstatus:
|
363 | a0c9f010 | Michael Hanselmann | raise errors.OpPrereqError("Error: %s\nspecify --no-lvm-storage if" |
364 | debac808 | Iustin Pop | " you are not using lvm" % vgstatus,
|
365 | debac808 | Iustin Pop | errors.ECODE_INVAL) |
366 | a0c9f010 | Michael Hanselmann | |
367 | a721e23a | Luca Bigliardi | if drbd_helper is not None: |
368 | a721e23a | Luca Bigliardi | try:
|
369 | a721e23a | Luca Bigliardi | curr_helper = bdev.BaseDRBD.GetUsermodeHelper() |
370 | a721e23a | Luca Bigliardi | except errors.BlockDeviceError, err:
|
371 | a721e23a | Luca Bigliardi | raise errors.OpPrereqError("Error while checking drbd helper" |
372 | a721e23a | Luca Bigliardi | " (specify --no-drbd-storage if you are not"
|
373 | a721e23a | Luca Bigliardi | " using drbd): %s" % str(err), |
374 | a721e23a | Luca Bigliardi | errors.ECODE_ENVIRON) |
375 | a721e23a | Luca Bigliardi | if drbd_helper != curr_helper:
|
376 | a721e23a | Luca Bigliardi | raise errors.OpPrereqError("Error: requiring %s as drbd helper but %s" |
377 | a721e23a | Luca Bigliardi | " is the current helper" % (drbd_helper,
|
378 | a721e23a | Luca Bigliardi | curr_helper), |
379 | a721e23a | Luca Bigliardi | errors.ECODE_INVAL) |
380 | a721e23a | Luca Bigliardi | |
381 | 0e3baaf3 | Iustin Pop | file_storage_dir = _InitFileStorage(file_storage_dir) |
382 | 87bc7ca8 | Apollon Oikonomopoulos | shared_file_storage_dir = _InitSharedFileStorage(shared_file_storage_dir) |
383 | a0c9f010 | Michael Hanselmann | |
384 | a0c9f010 | Michael Hanselmann | if not re.match("^[0-9a-z]{2}:[0-9a-z]{2}:[0-9a-z]{2}$", mac_prefix): |
385 | debac808 | Iustin Pop | raise errors.OpPrereqError("Invalid mac prefix given '%s'" % mac_prefix, |
386 | debac808 | Iustin Pop | errors.ECODE_INVAL) |
387 | a0c9f010 | Michael Hanselmann | |
388 | a0c9f010 | Michael Hanselmann | result = utils.RunCmd(["ip", "link", "show", "dev", master_netdev]) |
389 | a0c9f010 | Michael Hanselmann | if result.failed:
|
390 | a0c9f010 | Michael Hanselmann | raise errors.OpPrereqError("Invalid master netdev given (%s): '%s'" % |
391 | a0c9f010 | Michael Hanselmann | (master_netdev, |
392 | debac808 | Iustin Pop | result.output.strip()), errors.ECODE_INVAL) |
393 | a0c9f010 | Michael Hanselmann | |
394 | 9dae41ad | Guido Trotter | dirs = [(constants.RUN_GANETI_DIR, constants.RUN_DIRS_MODE)] |
395 | 9dae41ad | Guido Trotter | utils.EnsureDirs(dirs) |
396 | 9dae41ad | Guido Trotter | |
397 | a5728081 | Guido Trotter | utils.ForceDictType(beparams, constants.BES_PARAMETER_TYPES) |
398 | b6a30b0d | Guido Trotter | utils.ForceDictType(nicparams, constants.NICS_PARAMETER_TYPES) |
399 | b6a30b0d | Guido Trotter | objects.NIC.CheckParameterSyntax(nicparams) |
400 | b6a30b0d | Guido Trotter | |
401 | 6204ee71 | Renรฉ Nussbaumer | if ndparams is not None: |
402 | 6204ee71 | Renรฉ Nussbaumer | utils.ForceDictType(ndparams, constants.NDS_PARAMETER_TYPES) |
403 | 6204ee71 | Renรฉ Nussbaumer | else:
|
404 | 6204ee71 | Renรฉ Nussbaumer | ndparams = dict(constants.NDC_DEFAULTS)
|
405 | 6204ee71 | Renรฉ Nussbaumer | |
406 | a5728081 | Guido Trotter | # hvparams is a mapping of hypervisor->hvparams dict
|
407 | a5728081 | Guido Trotter | for hv_name, hv_params in hvparams.iteritems(): |
408 | a5728081 | Guido Trotter | utils.ForceDictType(hv_params, constants.HVS_PARAMETER_TYPES) |
409 | a5728081 | Guido Trotter | hv_class = hypervisor.GetHypervisor(hv_name) |
410 | a5728081 | Guido Trotter | hv_class.CheckParameterSyntax(hv_params) |
411 | d4b72030 | Guido Trotter | |
412 | a0c9f010 | Michael Hanselmann | # set up ssh config and /etc/hosts
|
413 | 13998ef2 | Michael Hanselmann | sshline = utils.ReadFile(constants.SSH_HOST_RSA_PUB) |
414 | a0c9f010 | Michael Hanselmann | sshkey = sshline.split(" ")[1] |
415 | a0c9f010 | Michael Hanselmann | |
416 | b86a6bcd | Guido Trotter | if modify_etc_hosts:
|
417 | ea8ac9c9 | Renรฉ Nussbaumer | utils.AddHostToEtcHosts(hostname.name, hostname.ip) |
418 | b86a6bcd | Guido Trotter | |
419 | b989b9d9 | Ken Wehr | if modify_ssh_setup:
|
420 | b989b9d9 | Ken Wehr | _InitSSHSetup() |
421 | a0c9f010 | Michael Hanselmann | |
422 | bf4af505 | Apollon Oikonomopoulos | if default_iallocator is not None: |
423 | bf4af505 | Apollon Oikonomopoulos | alloc_script = utils.FindFile(default_iallocator, |
424 | bf4af505 | Apollon Oikonomopoulos | constants.IALLOCATOR_SEARCH_PATH, |
425 | bf4af505 | Apollon Oikonomopoulos | os.path.isfile) |
426 | bf4af505 | Apollon Oikonomopoulos | if alloc_script is None: |
427 | bf4af505 | Apollon Oikonomopoulos | raise errors.OpPrereqError("Invalid default iallocator script '%s'" |
428 | bf4af505 | Apollon Oikonomopoulos | " specified" % default_iallocator,
|
429 | bf4af505 | Apollon Oikonomopoulos | errors.ECODE_INVAL) |
430 | bf4af505 | Apollon Oikonomopoulos | |
431 | 430b923c | Iustin Pop | now = time.time() |
432 | 430b923c | Iustin Pop | |
433 | a0c9f010 | Michael Hanselmann | # init of cluster config file
|
434 | b9eeeb02 | Michael Hanselmann | cluster_config = objects.Cluster( |
435 | b9eeeb02 | Michael Hanselmann | serial_no=1,
|
436 | b9eeeb02 | Michael Hanselmann | rsahostkeypub=sshkey, |
437 | b9eeeb02 | Michael Hanselmann | highest_used_port=(constants.FIRST_DRBD_PORT - 1),
|
438 | b9eeeb02 | Michael Hanselmann | mac_prefix=mac_prefix, |
439 | b9eeeb02 | Michael Hanselmann | volume_group_name=vg_name, |
440 | b9eeeb02 | Michael Hanselmann | tcpudp_port_pool=set(),
|
441 | f6bd6e98 | Michael Hanselmann | master_node=hostname.name, |
442 | f6bd6e98 | Michael Hanselmann | master_ip=clustername.ip, |
443 | f6bd6e98 | Michael Hanselmann | master_netdev=master_netdev, |
444 | f6bd6e98 | Michael Hanselmann | cluster_name=clustername.name, |
445 | f6bd6e98 | Michael Hanselmann | file_storage_dir=file_storage_dir, |
446 | 53197381 | Apollon Oikonomopoulos | shared_file_storage_dir=shared_file_storage_dir, |
447 | ea3a925f | Alexander Schreiber | enabled_hypervisors=enabled_hypervisors, |
448 | 4ef7f423 | Guido Trotter | beparams={constants.PP_DEFAULT: beparams}, |
449 | b6a30b0d | Guido Trotter | nicparams={constants.PP_DEFAULT: nicparams}, |
450 | 6204ee71 | Renรฉ Nussbaumer | ndparams=ndparams, |
451 | ea3a925f | Alexander Schreiber | hvparams=hvparams, |
452 | ce735215 | Guido Trotter | candidate_pool_size=candidate_pool_size, |
453 | 022c3a0b | Guido Trotter | modify_etc_hosts=modify_etc_hosts, |
454 | b989b9d9 | Ken Wehr | modify_ssh_setup=modify_ssh_setup, |
455 | 39b0f0c2 | Balazs Lecz | uid_pool=uid_pool, |
456 | 430b923c | Iustin Pop | ctime=now, |
457 | 430b923c | Iustin Pop | mtime=now, |
458 | 3953242f | Iustin Pop | maintain_node_health=maintain_node_health, |
459 | a721e23a | Luca Bigliardi | drbd_usermode_helper=drbd_helper, |
460 | bf4af505 | Apollon Oikonomopoulos | default_iallocator=default_iallocator, |
461 | 2f20d07b | Manuel Franceschini | primary_ip_family=ipcls.family, |
462 | 3d914585 | Renรฉ Nussbaumer | prealloc_wipe_disks=prealloc_wipe_disks, |
463 | b9eeeb02 | Michael Hanselmann | ) |
464 | b9eeeb02 | Michael Hanselmann | master_node_config = objects.Node(name=hostname.name, |
465 | b9eeeb02 | Michael Hanselmann | primary_ip=hostname.ip, |
466 | b9222f32 | Guido Trotter | secondary_ip=secondary_ip, |
467 | c044f32c | Guido Trotter | serial_no=1,
|
468 | c044f32c | Guido Trotter | master_candidate=True,
|
469 | af64c0ea | Iustin Pop | offline=False, drained=False, |
470 | 435e4bd6 | Michael Hanselmann | ctime=now, mtime=now, |
471 | c044f32c | Guido Trotter | ) |
472 | 9e1333b9 | Guido Trotter | InitConfig(constants.CONFIG_VERSION, cluster_config, master_node_config) |
473 | d367b66c | Manuel Franceschini | cfg = config.ConfigWriter(offline=True)
|
474 | 9e1333b9 | Guido Trotter | ssh.WriteKnownHostsFile(cfg, constants.SSH_KNOWN_HOSTS_FILE) |
475 | a4eae71f | Michael Hanselmann | cfg.Update(cfg.GetClusterInfo(), logging.error) |
476 | d367b66c | Manuel Franceschini | backend.WriteSsconfFiles(cfg.GetSsconfValues()) |
477 | d367b66c | Manuel Franceschini | |
478 | d367b66c | Manuel Franceschini | # set up the inter-node password and certificate
|
479 | d367b66c | Manuel Franceschini | _InitGanetiServerSetup(hostname.name) |
480 | 827f753e | Guido Trotter | |
481 | 952d7515 | Michael Hanselmann | logging.debug("Starting daemons")
|
482 | 952d7515 | Michael Hanselmann | result = utils.RunCmd([constants.DAEMON_UTIL, "start-all"])
|
483 | 952d7515 | Michael Hanselmann | if result.failed:
|
484 | 952d7515 | Michael Hanselmann | raise errors.OpExecError("Could not start daemons, command %s" |
485 | 952d7515 | Michael Hanselmann | " had exitcode %s and error %s" %
|
486 | 952d7515 | Michael Hanselmann | (result.cmd, result.exit_code, result.output)) |
487 | b3f1cf6f | Iustin Pop | |
488 | 3b6b6129 | Michael Hanselmann | _WaitForMasterDaemon() |
489 | b3f1cf6f | Iustin Pop | |
490 | b1b6ea87 | Iustin Pop | |
491 | 02f99608 | Oleksiy Mishchenko | def InitConfig(version, cluster_config, master_node_config, |
492 | 02f99608 | Oleksiy Mishchenko | cfg_file=constants.CLUSTER_CONF_FILE): |
493 | 7b3a8fb5 | Iustin Pop | """Create the initial cluster configuration.
|
494 | 7b3a8fb5 | Iustin Pop |
|
495 | 7b3a8fb5 | Iustin Pop | It will contain the current node, which will also be the master
|
496 | 7b3a8fb5 | Iustin Pop | node, and no instances.
|
497 | 7b3a8fb5 | Iustin Pop |
|
498 | 7b3a8fb5 | Iustin Pop | @type version: int
|
499 | c41eea6e | Iustin Pop | @param version: configuration version
|
500 | c41eea6e | Iustin Pop | @type cluster_config: L{objects.Cluster}
|
501 | c41eea6e | Iustin Pop | @param cluster_config: cluster configuration
|
502 | c41eea6e | Iustin Pop | @type master_node_config: L{objects.Node}
|
503 | c41eea6e | Iustin Pop | @param master_node_config: master node configuration
|
504 | c41eea6e | Iustin Pop | @type cfg_file: string
|
505 | c41eea6e | Iustin Pop | @param cfg_file: configuration file path
|
506 | c41eea6e | Iustin Pop |
|
507 | 7b3a8fb5 | Iustin Pop | """
|
508 | 88b92fe3 | Guido Trotter | uuid_generator = config.TemporaryReservationManager() |
509 | 88b92fe3 | Guido Trotter | cluster_config.uuid = uuid_generator.Generate([], utils.NewUUID, |
510 | 88b92fe3 | Guido Trotter | _INITCONF_ECID) |
511 | 88b92fe3 | Guido Trotter | master_node_config.uuid = uuid_generator.Generate([], utils.NewUUID, |
512 | 88b92fe3 | Guido Trotter | _INITCONF_ECID) |
513 | 7b3a8fb5 | Iustin Pop | nodes = { |
514 | 7b3a8fb5 | Iustin Pop | master_node_config.name: master_node_config, |
515 | 7b3a8fb5 | Iustin Pop | } |
516 | 88b92fe3 | Guido Trotter | default_nodegroup = objects.NodeGroup( |
517 | 88b92fe3 | Guido Trotter | uuid=uuid_generator.Generate([], utils.NewUUID, _INITCONF_ECID), |
518 | 75cf411a | Adeodato Simo | name=constants.INITIAL_NODE_GROUP_NAME, |
519 | 88b92fe3 | Guido Trotter | members=[master_node_config.name], |
520 | 88b92fe3 | Guido Trotter | ) |
521 | 88b92fe3 | Guido Trotter | nodegroups = { |
522 | 88b92fe3 | Guido Trotter | default_nodegroup.uuid: default_nodegroup, |
523 | 88b92fe3 | Guido Trotter | } |
524 | d693c864 | Iustin Pop | now = time.time() |
525 | 7b3a8fb5 | Iustin Pop | config_data = objects.ConfigData(version=version, |
526 | 7b3a8fb5 | Iustin Pop | cluster=cluster_config, |
527 | 88b92fe3 | Guido Trotter | nodegroups=nodegroups, |
528 | 7b3a8fb5 | Iustin Pop | nodes=nodes, |
529 | 7b3a8fb5 | Iustin Pop | instances={}, |
530 | d693c864 | Iustin Pop | serial_no=1,
|
531 | d693c864 | Iustin Pop | ctime=now, mtime=now) |
532 | a33848a5 | Guido Trotter | utils.WriteFile(cfg_file, |
533 | a33848a5 | Guido Trotter | data=serializer.Dump(config_data.ToDict()), |
534 | a33848a5 | Guido Trotter | mode=0600)
|
535 | 02f99608 | Oleksiy Mishchenko | |
536 | 02f99608 | Oleksiy Mishchenko | |
537 | 140aa4a8 | Iustin Pop | def FinalizeClusterDestroy(master): |
538 | 140aa4a8 | Iustin Pop | """Execute the last steps of cluster destroy
|
539 | 140aa4a8 | Iustin Pop |
|
540 | 140aa4a8 | Iustin Pop | This function shuts down all the daemons, completing the destroy
|
541 | 140aa4a8 | Iustin Pop | begun in cmdlib.LUDestroyOpcode.
|
542 | 140aa4a8 | Iustin Pop |
|
543 | 140aa4a8 | Iustin Pop | """
|
544 | b989b9d9 | Ken Wehr | cfg = config.ConfigWriter() |
545 | b989b9d9 | Ken Wehr | modify_ssh_setup = cfg.GetClusterInfo().modify_ssh_setup |
546 | 781de953 | Iustin Pop | result = rpc.RpcRunner.call_node_stop_master(master, True)
|
547 | 3cebe102 | Michael Hanselmann | msg = result.fail_msg |
548 | 6c00d19a | Iustin Pop | if msg:
|
549 | 099c52ad | Iustin Pop | logging.warning("Could not disable the master role: %s", msg)
|
550 | b989b9d9 | Ken Wehr | result = rpc.RpcRunner.call_node_leave_cluster(master, modify_ssh_setup) |
551 | 3cebe102 | Michael Hanselmann | msg = result.fail_msg |
552 | 0623d351 | Iustin Pop | if msg:
|
553 | 0623d351 | Iustin Pop | logging.warning("Could not shutdown the node daemon and cleanup"
|
554 | 0623d351 | Iustin Pop | " the node: %s", msg)
|
555 | 140aa4a8 | Iustin Pop | |
556 | 140aa4a8 | Iustin Pop | |
557 | 87622829 | Iustin Pop | def SetupNodeDaemon(cluster_name, node, ssh_key_check): |
558 | 827f753e | Guido Trotter | """Add a node to the cluster.
|
559 | 827f753e | Guido Trotter |
|
560 | b1b6ea87 | Iustin Pop | This function must be called before the actual opcode, and will ssh
|
561 | b1b6ea87 | Iustin Pop | to the remote node, copy the needed files, and start ganeti-noded,
|
562 | b1b6ea87 | Iustin Pop | allowing the master to do the rest via normal rpc calls.
|
563 | 827f753e | Guido Trotter |
|
564 | 87622829 | Iustin Pop | @param cluster_name: the cluster name
|
565 | 87622829 | Iustin Pop | @param node: the name of the new node
|
566 | 87622829 | Iustin Pop | @param ssh_key_check: whether to do a strict key check
|
567 | 827f753e | Guido Trotter |
|
568 | 827f753e | Guido Trotter | """
|
569 | b43dcc5a | Manuel Franceschini | family = ssconf.SimpleStore().GetPrimaryIPFamily() |
570 | b43dcc5a | Manuel Franceschini | sshrunner = ssh.SshRunner(cluster_name, |
571 | 72729d6e | Michael Hanselmann | ipv6=(family == netutils.IP6Address.family)) |
572 | 827f753e | Guido Trotter | |
573 | b43dcc5a | Manuel Franceschini | bind_address = constants.IP4_ADDRESS_ANY |
574 | b43dcc5a | Manuel Franceschini | if family == netutils.IP6Address.family:
|
575 | b43dcc5a | Manuel Franceschini | bind_address = constants.IP6_ADDRESS_ANY |
576 | b43dcc5a | Manuel Franceschini | |
577 | 827f753e | Guido Trotter | # set up inter-node password and certificate and restarts the node daemon
|
578 | 827f753e | Guido Trotter | # and then connect with ssh to set password and start ganeti-noded
|
579 | 827f753e | Guido Trotter | # note that all the below variables are sanitized at this point,
|
580 | 827f753e | Guido Trotter | # either by being constants or by the checks above
|
581 | 9294514d | Renรฉ Nussbaumer | sshrunner.CopyFileToNode(node, constants.NODED_CERT_FILE) |
582 | 9294514d | Renรฉ Nussbaumer | sshrunner.CopyFileToNode(node, constants.RAPI_CERT_FILE) |
583 | 9294514d | Renรฉ Nussbaumer | sshrunner.CopyFileToNode(node, constants.CONFD_HMAC_KEY) |
584 | 72729d6e | Michael Hanselmann | mycommand = ("%s stop-all; %s start %s -b %s" %
|
585 | 72729d6e | Michael Hanselmann | (constants.DAEMON_UTIL, constants.DAEMON_UTIL, constants.NODED, |
586 | 72729d6e | Michael Hanselmann | utils.ShellQuote(bind_address))) |
587 | 827f753e | Guido Trotter | |
588 | c4b6c29c | Michael Hanselmann | result = sshrunner.Run(node, 'root', mycommand, batch=False, |
589 | c4b6c29c | Michael Hanselmann | ask_key=ssh_key_check, |
590 | 9294514d | Renรฉ Nussbaumer | use_cluster_key=True,
|
591 | c4b6c29c | Michael Hanselmann | strict_host_check=ssh_key_check) |
592 | 827f753e | Guido Trotter | if result.failed:
|
593 | 827f753e | Guido Trotter | raise errors.OpExecError("Remote command on node %s, error: %s," |
594 | 827f753e | Guido Trotter | " output: %s" %
|
595 | 827f753e | Guido Trotter | (node, result.fail_reason, result.output)) |
596 | 827f753e | Guido Trotter | |
597 | 5627f375 | Michael Hanselmann | _WaitForNodeDaemon(node) |
598 | 5627f375 | Michael Hanselmann | |
599 | b1b6ea87 | Iustin Pop | |
600 | 8e2524c3 | Guido Trotter | def MasterFailover(no_voting=False): |
601 | b1b6ea87 | Iustin Pop | """Failover the master node.
|
602 | b1b6ea87 | Iustin Pop |
|
603 | b1b6ea87 | Iustin Pop | This checks that we are not already the master, and will cause the
|
604 | b1b6ea87 | Iustin Pop | current master to cease being master, and the non-master to become
|
605 | b1b6ea87 | Iustin Pop | new master.
|
606 | b1b6ea87 | Iustin Pop |
|
607 | 8e2524c3 | Guido Trotter | @type no_voting: boolean
|
608 | 8e2524c3 | Guido Trotter | @param no_voting: force the operation without remote nodes agreement
|
609 | 8e2524c3 | Guido Trotter | (dangerous)
|
610 | 8e2524c3 | Guido Trotter |
|
611 | b1b6ea87 | Iustin Pop | """
|
612 | 8135a2db | Iustin Pop | sstore = ssconf.SimpleStore() |
613 | b1b6ea87 | Iustin Pop | |
614 | 8135a2db | Iustin Pop | old_master, new_master = ssconf.GetMasterAndMyself(sstore) |
615 | 8135a2db | Iustin Pop | node_list = sstore.GetNodeList() |
616 | 8135a2db | Iustin Pop | mc_list = sstore.GetMasterCandidates() |
617 | b1b6ea87 | Iustin Pop | |
618 | b1b6ea87 | Iustin Pop | if old_master == new_master:
|
619 | b1b6ea87 | Iustin Pop | raise errors.OpPrereqError("This commands must be run on the node" |
620 | b1b6ea87 | Iustin Pop | " where you want the new master to be."
|
621 | b1b6ea87 | Iustin Pop | " %s is already the master" %
|
622 | debac808 | Iustin Pop | old_master, errors.ECODE_INVAL) |
623 | d5927e48 | Iustin Pop | |
624 | 8135a2db | Iustin Pop | if new_master not in mc_list: |
625 | 8135a2db | Iustin Pop | mc_no_master = [name for name in mc_list if name != old_master] |
626 | 8135a2db | Iustin Pop | raise errors.OpPrereqError("This node is not among the nodes marked" |
627 | 8135a2db | Iustin Pop | " as master candidates. Only these nodes"
|
628 | 8135a2db | Iustin Pop | " can become masters. Current list of"
|
629 | 8135a2db | Iustin Pop | " master candidates is:\n"
|
630 | debac808 | Iustin Pop | "%s" % ('\n'.join(mc_no_master)), |
631 | debac808 | Iustin Pop | errors.ECODE_STATE) |
632 | 8135a2db | Iustin Pop | |
633 | 8e2524c3 | Guido Trotter | if not no_voting: |
634 | 8e2524c3 | Guido Trotter | vote_list = GatherMasterVotes(node_list) |
635 | 8e2524c3 | Guido Trotter | |
636 | 8e2524c3 | Guido Trotter | if vote_list:
|
637 | 8e2524c3 | Guido Trotter | voted_master = vote_list[0][0] |
638 | 8e2524c3 | Guido Trotter | if voted_master is None: |
639 | 8e2524c3 | Guido Trotter | raise errors.OpPrereqError("Cluster is inconsistent, most nodes did" |
640 | debac808 | Iustin Pop | " not respond.", errors.ECODE_ENVIRON)
|
641 | 8e2524c3 | Guido Trotter | elif voted_master != old_master:
|
642 | 8e2524c3 | Guido Trotter | raise errors.OpPrereqError("I have a wrong configuration, I believe" |
643 | 8e2524c3 | Guido Trotter | " the master is %s but the other nodes"
|
644 | 8e2524c3 | Guido Trotter | " voted %s. Please resync the configuration"
|
645 | 8e2524c3 | Guido Trotter | " of this node." %
|
646 | debac808 | Iustin Pop | (old_master, voted_master), |
647 | debac808 | Iustin Pop | errors.ECODE_STATE) |
648 | b1b6ea87 | Iustin Pop | # end checks
|
649 | b1b6ea87 | Iustin Pop | |
650 | b1b6ea87 | Iustin Pop | rcode = 0
|
651 | b1b6ea87 | Iustin Pop | |
652 | d5927e48 | Iustin Pop | logging.info("Setting master to %s, old master: %s", new_master, old_master)
|
653 | b1b6ea87 | Iustin Pop | |
654 | 21004460 | Iustin Pop | try:
|
655 | 21004460 | Iustin Pop | # instantiate a real config writer, as we now know we have the
|
656 | 21004460 | Iustin Pop | # configuration data
|
657 | eb180fe2 | Iustin Pop | cfg = config.ConfigWriter(accept_foreign=True)
|
658 | 21004460 | Iustin Pop | |
659 | 21004460 | Iustin Pop | cluster_info = cfg.GetClusterInfo() |
660 | 21004460 | Iustin Pop | cluster_info.master_node = new_master |
661 | 21004460 | Iustin Pop | # this will also regenerate the ssconf files, since we updated the
|
662 | 21004460 | Iustin Pop | # cluster info
|
663 | 21004460 | Iustin Pop | cfg.Update(cluster_info, logging.error) |
664 | 21004460 | Iustin Pop | except errors.ConfigurationError, err:
|
665 | 21004460 | Iustin Pop | logging.error("Error while trying to set the new master: %s",
|
666 | 21004460 | Iustin Pop | str(err))
|
667 | 21004460 | Iustin Pop | return 1 |
668 | 21004460 | Iustin Pop | |
669 | 21004460 | Iustin Pop | # if cfg.Update worked, then it means the old master daemon won't be
|
670 | 21004460 | Iustin Pop | # able now to write its own config file (we rely on locking in both
|
671 | 21004460 | Iustin Pop | # backend.UploadFile() and ConfigWriter._Write(); hence the next
|
672 | 21004460 | Iustin Pop | # step is to kill the old master
|
673 | 21004460 | Iustin Pop | |
674 | 21004460 | Iustin Pop | logging.info("Stopping the master daemon on node %s", old_master)
|
675 | 21004460 | Iustin Pop | |
676 | 781de953 | Iustin Pop | result = rpc.RpcRunner.call_node_stop_master(old_master, True)
|
677 | 3cebe102 | Michael Hanselmann | msg = result.fail_msg |
678 | 6c00d19a | Iustin Pop | if msg:
|
679 | d5927e48 | Iustin Pop | logging.error("Could not disable the master role on the old master"
|
680 | 6c00d19a | Iustin Pop | " %s, please disable manually: %s", old_master, msg)
|
681 | b1b6ea87 | Iustin Pop | |
682 | 21004460 | Iustin Pop | logging.info("Checking master IP non-reachability...")
|
683 | 21004460 | Iustin Pop | |
684 | 425f0f54 | Iustin Pop | master_ip = sstore.GetMasterIP() |
685 | 425f0f54 | Iustin Pop | total_timeout = 30
|
686 | d23ef431 | Michael Hanselmann | # Here we have a phase where no master should be running
|
687 | 425f0f54 | Iustin Pop | def _check_ip(): |
688 | a744b676 | Manuel Franceschini | if netutils.TcpPing(master_ip, constants.DEFAULT_NODED_PORT):
|
689 | 425f0f54 | Iustin Pop | raise utils.RetryAgain()
|
690 | 425f0f54 | Iustin Pop | |
691 | 425f0f54 | Iustin Pop | try:
|
692 | 425f0f54 | Iustin Pop | utils.Retry(_check_ip, (1, 1.5, 5), total_timeout) |
693 | 425f0f54 | Iustin Pop | except utils.RetryTimeout:
|
694 | 425f0f54 | Iustin Pop | logging.warning("The master IP is still reachable after %s seconds,"
|
695 | 425f0f54 | Iustin Pop | " continuing but activating the master on the current"
|
696 | 425f0f54 | Iustin Pop | " node will probably fail", total_timeout)
|
697 | b1b6ea87 | Iustin Pop | |
698 | 21004460 | Iustin Pop | logging.info("Starting the master daemons on the new master")
|
699 | d5927e48 | Iustin Pop | |
700 | 3583908a | Guido Trotter | result = rpc.RpcRunner.call_node_start_master(new_master, True, no_voting)
|
701 | 3cebe102 | Michael Hanselmann | msg = result.fail_msg |
702 | b726aff0 | Iustin Pop | if msg:
|
703 | d5927e48 | Iustin Pop | logging.error("Could not start the master role on the new master"
|
704 | b726aff0 | Iustin Pop | " %s, please check: %s", new_master, msg)
|
705 | b1b6ea87 | Iustin Pop | rcode = 1
|
706 | b1b6ea87 | Iustin Pop | |
707 | 21004460 | Iustin Pop | logging.info("Master failed over from %s to %s", old_master, new_master)
|
708 | b1b6ea87 | Iustin Pop | return rcode
|
709 | d7cdb55d | Iustin Pop | |
710 | d7cdb55d | Iustin Pop | |
711 | 8eb148ae | Iustin Pop | def GetMaster(): |
712 | 8eb148ae | Iustin Pop | """Returns the current master node.
|
713 | 8eb148ae | Iustin Pop |
|
714 | 8eb148ae | Iustin Pop | This is a separate function in bootstrap since it's needed by
|
715 | 8eb148ae | Iustin Pop | gnt-cluster, and instead of importing directly ssconf, it's better
|
716 | 8eb148ae | Iustin Pop | to abstract it in bootstrap, where we do use ssconf in other
|
717 | 8eb148ae | Iustin Pop | functions too.
|
718 | 8eb148ae | Iustin Pop |
|
719 | 8eb148ae | Iustin Pop | """
|
720 | 8eb148ae | Iustin Pop | sstore = ssconf.SimpleStore() |
721 | 8eb148ae | Iustin Pop | |
722 | 8eb148ae | Iustin Pop | old_master, _ = ssconf.GetMasterAndMyself(sstore) |
723 | 8eb148ae | Iustin Pop | |
724 | 8eb148ae | Iustin Pop | return old_master
|
725 | 8eb148ae | Iustin Pop | |
726 | 8eb148ae | Iustin Pop | |
727 | d7cdb55d | Iustin Pop | def GatherMasterVotes(node_list): |
728 | d7cdb55d | Iustin Pop | """Check the agreement on who is the master.
|
729 | d7cdb55d | Iustin Pop |
|
730 | d7cdb55d | Iustin Pop | This function will return a list of (node, number of votes), ordered
|
731 | d7cdb55d | Iustin Pop | by the number of votes. Errors will be denoted by the key 'None'.
|
732 | d7cdb55d | Iustin Pop |
|
733 | d7cdb55d | Iustin Pop | Note that the sum of votes is the number of nodes this machine
|
734 | d7cdb55d | Iustin Pop | knows, whereas the number of entries in the list could be different
|
735 | d7cdb55d | Iustin Pop | (if some nodes vote for another master).
|
736 | d7cdb55d | Iustin Pop |
|
737 | d7cdb55d | Iustin Pop | We remove ourselves from the list since we know that (bugs aside)
|
738 | d7cdb55d | Iustin Pop | since we use the same source for configuration information for both
|
739 | d7cdb55d | Iustin Pop | backend and boostrap, we'll always vote for ourselves.
|
740 | d7cdb55d | Iustin Pop |
|
741 | d7cdb55d | Iustin Pop | @type node_list: list
|
742 | d7cdb55d | Iustin Pop | @param node_list: the list of nodes to query for master info; the current
|
743 | 5bbd3f7f | Michael Hanselmann | node will be removed if it is in the list
|
744 | d7cdb55d | Iustin Pop | @rtype: list
|
745 | d7cdb55d | Iustin Pop | @return: list of (node, votes)
|
746 | d7cdb55d | Iustin Pop |
|
747 | d7cdb55d | Iustin Pop | """
|
748 | b705c7a6 | Manuel Franceschini | myself = netutils.Hostname.GetSysName() |
749 | d7cdb55d | Iustin Pop | try:
|
750 | d7cdb55d | Iustin Pop | node_list.remove(myself) |
751 | d7cdb55d | Iustin Pop | except ValueError: |
752 | d7cdb55d | Iustin Pop | pass
|
753 | d7cdb55d | Iustin Pop | if not node_list: |
754 | d7cdb55d | Iustin Pop | # no nodes left (eventually after removing myself)
|
755 | d7cdb55d | Iustin Pop | return []
|
756 | d7cdb55d | Iustin Pop | results = rpc.RpcRunner.call_master_info(node_list) |
757 | d7cdb55d | Iustin Pop | if not isinstance(results, dict): |
758 | d7cdb55d | Iustin Pop | # this should not happen (unless internal error in rpc)
|
759 | d7cdb55d | Iustin Pop | logging.critical("Can't complete rpc call, aborting master startup")
|
760 | d7cdb55d | Iustin Pop | return [(None, len(node_list))] |
761 | d7cdb55d | Iustin Pop | votes = {} |
762 | d7cdb55d | Iustin Pop | for node in results: |
763 | 781de953 | Iustin Pop | nres = results[node] |
764 | 2a52a064 | Iustin Pop | data = nres.payload |
765 | 3cebe102 | Michael Hanselmann | msg = nres.fail_msg |
766 | 2a52a064 | Iustin Pop | fail = False
|
767 | 2a52a064 | Iustin Pop | if msg:
|
768 | 2a52a064 | Iustin Pop | logging.warning("Error contacting node %s: %s", node, msg)
|
769 | 2a52a064 | Iustin Pop | fail = True
|
770 | d8e0caa6 | Manuel Franceschini | # for now we accept both length 3 and 4 (data[3] is primary ip version)
|
771 | 2a52a064 | Iustin Pop | elif not isinstance(data, (tuple, list)) or len(data) < 3: |
772 | 2a52a064 | Iustin Pop | logging.warning("Invalid data received from node %s: %s", node, data)
|
773 | 2a52a064 | Iustin Pop | fail = True
|
774 | 2a52a064 | Iustin Pop | if fail:
|
775 | d7cdb55d | Iustin Pop | if None not in votes: |
776 | d7cdb55d | Iustin Pop | votes[None] = 0 |
777 | d7cdb55d | Iustin Pop | votes[None] += 1 |
778 | d7cdb55d | Iustin Pop | continue
|
779 | 781de953 | Iustin Pop | master_node = data[2]
|
780 | d7cdb55d | Iustin Pop | if master_node not in votes: |
781 | d7cdb55d | Iustin Pop | votes[master_node] = 0
|
782 | d7cdb55d | Iustin Pop | votes[master_node] += 1
|
783 | d7cdb55d | Iustin Pop | |
784 | d7cdb55d | Iustin Pop | vote_list = [v for v in votes.items()] |
785 | d7cdb55d | Iustin Pop | # sort first on number of votes then on name, since we want None
|
786 | d7cdb55d | Iustin Pop | # sorted later if we have the half of the nodes not responding, and
|
787 | d7cdb55d | Iustin Pop | # half voting all for the same master
|
788 | d7cdb55d | Iustin Pop | vote_list.sort(key=lambda x: (x[1], x[0]), reverse=True) |
789 | d7cdb55d | Iustin Pop | |
790 | d7cdb55d | Iustin Pop | return vote_list |