root / lib / bootstrap.py @ fb62843c
History | View | Annotate | Download (40.7 kB)
1 | a0c9f010 | Michael Hanselmann | #
|
---|---|---|---|
2 | a0c9f010 | Michael Hanselmann | #
|
3 | a0c9f010 | Michael Hanselmann | |
4 | 57dc299a | Iustin Pop | # Copyright (C) 2006, 2007, 2008, 2010, 2011, 2012 Google Inc.
|
5 | a0c9f010 | Michael Hanselmann | #
|
6 | a0c9f010 | Michael Hanselmann | # This program is free software; you can redistribute it and/or modify
|
7 | a0c9f010 | Michael Hanselmann | # it under the terms of the GNU General Public License as published by
|
8 | a0c9f010 | Michael Hanselmann | # the Free Software Foundation; either version 2 of the License, or
|
9 | a0c9f010 | Michael Hanselmann | # (at your option) any later version.
|
10 | a0c9f010 | Michael Hanselmann | #
|
11 | a0c9f010 | Michael Hanselmann | # This program is distributed in the hope that it will be useful, but
|
12 | a0c9f010 | Michael Hanselmann | # WITHOUT ANY WARRANTY; without even the implied warranty of
|
13 | a0c9f010 | Michael Hanselmann | # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
14 | a0c9f010 | Michael Hanselmann | # General Public License for more details.
|
15 | a0c9f010 | Michael Hanselmann | #
|
16 | a0c9f010 | Michael Hanselmann | # You should have received a copy of the GNU General Public License
|
17 | a0c9f010 | Michael Hanselmann | # along with this program; if not, write to the Free Software
|
18 | a0c9f010 | Michael Hanselmann | # Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
|
19 | a0c9f010 | Michael Hanselmann | # 02110-1301, USA.
|
20 | a0c9f010 | Michael Hanselmann | |
21 | a0c9f010 | Michael Hanselmann | |
22 | a0c9f010 | Michael Hanselmann | """Functions to bootstrap a new cluster.
|
23 | a0c9f010 | Michael Hanselmann |
|
24 | a0c9f010 | Michael Hanselmann | """
|
25 | a0c9f010 | Michael Hanselmann | |
26 | a0c9f010 | Michael Hanselmann | import os |
27 | a0c9f010 | Michael Hanselmann | import os.path |
28 | a0c9f010 | Michael Hanselmann | import re |
29 | b1b6ea87 | Iustin Pop | import logging |
30 | d693c864 | Iustin Pop | import time |
31 | a698cdbb | Michael Hanselmann | import tempfile |
32 | a0c9f010 | Michael Hanselmann | |
33 | 3039e2dc | Helga Velroyen | from ganeti.cmdlib import cluster |
34 | a0c9f010 | Michael Hanselmann | from ganeti import rpc |
35 | a0c9f010 | Michael Hanselmann | from ganeti import ssh |
36 | a0c9f010 | Michael Hanselmann | from ganeti import utils |
37 | a0c9f010 | Michael Hanselmann | from ganeti import errors |
38 | a0c9f010 | Michael Hanselmann | from ganeti import config |
39 | a0c9f010 | Michael Hanselmann | from ganeti import constants |
40 | b9eeeb02 | Michael Hanselmann | from ganeti import objects |
41 | a0c9f010 | Michael Hanselmann | from ganeti import ssconf |
42 | a33848a5 | Guido Trotter | from ganeti import serializer |
43 | a5728081 | Guido Trotter | from ganeti import hypervisor |
44 | cde49218 | Helga Velroyen | from ganeti.storage import drbd |
45 | 3039e2dc | Helga Velroyen | from ganeti.storage import filestorage |
46 | a744b676 | Manuel Franceschini | from ganeti import netutils |
47 | 3b6b6129 | Michael Hanselmann | from ganeti import luxi |
48 | ff699aa9 | Michael Hanselmann | from ganeti import jstore |
49 | 7ede9c6a | Michael Hanselmann | from ganeti import pathutils |
50 | 3b6b6129 | Michael Hanselmann | |
51 | a0c9f010 | Michael Hanselmann | |
52 | 88b92fe3 | Guido Trotter | # ec_id for InitConfig's temporary reservation manager
|
53 | 88b92fe3 | Guido Trotter | _INITCONF_ECID = "initconfig-ecid"
|
54 | 88b92fe3 | Guido Trotter | |
55 | 3b6b6129 | Michael Hanselmann | #: After how many seconds daemon must be responsive
|
56 | 3b6b6129 | Michael Hanselmann | _DAEMON_READY_TIMEOUT = 10.0
|
57 | 3b6b6129 | Michael Hanselmann | |
58 | e38220e4 | Michael Hanselmann | |
59 | 531baf8e | Iustin Pop | def _InitSSHSetup(): |
60 | a0c9f010 | Michael Hanselmann | """Setup the SSH configuration for the cluster.
|
61 | a0c9f010 | Michael Hanselmann |
|
62 | a0c9f010 | Michael Hanselmann | This generates a dsa keypair for root, adds the pub key to the
|
63 | a0c9f010 | Michael Hanselmann | permitted hosts and adds the hostkey to its own known hosts.
|
64 | a0c9f010 | Michael Hanselmann |
|
65 | a0c9f010 | Michael Hanselmann | """
|
66 | 052783ff | Michael Hanselmann | priv_key, pub_key, auth_keys = ssh.GetUserFiles(constants.SSH_LOGIN_USER) |
67 | a0c9f010 | Michael Hanselmann | |
68 | a0c9f010 | Michael Hanselmann | for name in priv_key, pub_key: |
69 | a0c9f010 | Michael Hanselmann | if os.path.exists(name):
|
70 | a0c9f010 | Michael Hanselmann | utils.CreateBackup(name) |
71 | a0c9f010 | Michael Hanselmann | utils.RemoveFile(name) |
72 | a0c9f010 | Michael Hanselmann | |
73 | a0c9f010 | Michael Hanselmann | result = utils.RunCmd(["ssh-keygen", "-t", "dsa", |
74 | a0c9f010 | Michael Hanselmann | "-f", priv_key,
|
75 | a0c9f010 | Michael Hanselmann | "-q", "-N", ""]) |
76 | a0c9f010 | Michael Hanselmann | if result.failed:
|
77 | a0c9f010 | Michael Hanselmann | raise errors.OpExecError("Could not generate ssh keypair, error %s" % |
78 | a0c9f010 | Michael Hanselmann | result.output) |
79 | a0c9f010 | Michael Hanselmann | |
80 | 7a0156dc | Luca Bigliardi | utils.AddAuthorizedKey(auth_keys, utils.ReadFile(pub_key)) |
81 | a0c9f010 | Michael Hanselmann | |
82 | a0c9f010 | Michael Hanselmann | |
83 | c008906b | Michael Hanselmann | def GenerateHmacKey(file_name): |
84 | c008906b | Michael Hanselmann | """Writes a new HMAC key.
|
85 | c008906b | Michael Hanselmann |
|
86 | c008906b | Michael Hanselmann | @type file_name: str
|
87 | c008906b | Michael Hanselmann | @param file_name: Path to output file
|
88 | c008906b | Michael Hanselmann |
|
89 | c008906b | Michael Hanselmann | """
|
90 | 43575108 | Michael Hanselmann | utils.WriteFile(file_name, data="%s\n" % utils.GenerateSecret(), mode=0400, |
91 | 43575108 | Michael Hanselmann | backup=True)
|
92 | 43575108 | Michael Hanselmann | |
93 | 43575108 | Michael Hanselmann | |
94 | b6267745 | Andrea Spadaccini | def GenerateClusterCrypto(new_cluster_cert, new_rapi_cert, new_spice_cert, |
95 | b6267745 | Andrea Spadaccini | new_confd_hmac_key, new_cds, |
96 | b6267745 | Andrea Spadaccini | rapi_cert_pem=None, spice_cert_pem=None, |
97 | b6267745 | Andrea Spadaccini | spice_cacert_pem=None, cds=None, |
98 | 7ede9c6a | Michael Hanselmann | nodecert_file=pathutils.NODED_CERT_FILE, |
99 | 7ede9c6a | Michael Hanselmann | rapicert_file=pathutils.RAPI_CERT_FILE, |
100 | 7ede9c6a | Michael Hanselmann | spicecert_file=pathutils.SPICE_CERT_FILE, |
101 | 7ede9c6a | Michael Hanselmann | spicecacert_file=pathutils.SPICE_CACERT_FILE, |
102 | 7ede9c6a | Michael Hanselmann | hmackey_file=pathutils.CONFD_HMAC_KEY, |
103 | 7ede9c6a | Michael Hanselmann | cds_file=pathutils.CLUSTER_DOMAIN_SECRET_FILE): |
104 | 43575108 | Michael Hanselmann | """Updates the cluster certificates, keys and secrets.
|
105 | 43575108 | Michael Hanselmann |
|
106 | 43575108 | Michael Hanselmann | @type new_cluster_cert: bool
|
107 | 43575108 | Michael Hanselmann | @param new_cluster_cert: Whether to generate a new cluster certificate
|
108 | 43575108 | Michael Hanselmann | @type new_rapi_cert: bool
|
109 | 43575108 | Michael Hanselmann | @param new_rapi_cert: Whether to generate a new RAPI certificate
|
110 | b6267745 | Andrea Spadaccini | @type new_spice_cert: bool
|
111 | b6267745 | Andrea Spadaccini | @param new_spice_cert: Whether to generate a new SPICE certificate
|
112 | 6b7d5878 | Michael Hanselmann | @type new_confd_hmac_key: bool
|
113 | 6b7d5878 | Michael Hanselmann | @param new_confd_hmac_key: Whether to generate a new HMAC key
|
114 | 3db3eb2a | Michael Hanselmann | @type new_cds: bool
|
115 | 3db3eb2a | Michael Hanselmann | @param new_cds: Whether to generate a new cluster domain secret
|
116 | 43575108 | Michael Hanselmann | @type rapi_cert_pem: string
|
117 | 43575108 | Michael Hanselmann | @param rapi_cert_pem: New RAPI certificate in PEM format
|
118 | b6267745 | Andrea Spadaccini | @type spice_cert_pem: string
|
119 | b6267745 | Andrea Spadaccini | @param spice_cert_pem: New SPICE certificate in PEM format
|
120 | b6267745 | Andrea Spadaccini | @type spice_cacert_pem: string
|
121 | b6267745 | Andrea Spadaccini | @param spice_cacert_pem: Certificate of the CA that signed the SPICE
|
122 | b6267745 | Andrea Spadaccini | certificate, in PEM format
|
123 | 3db3eb2a | Michael Hanselmann | @type cds: string
|
124 | 3db3eb2a | Michael Hanselmann | @param cds: New cluster domain secret
|
125 | aeefe835 | Iustin Pop | @type nodecert_file: string
|
126 | aeefe835 | Iustin Pop | @param nodecert_file: optional override of the node cert file path
|
127 | aeefe835 | Iustin Pop | @type rapicert_file: string
|
128 | aeefe835 | Iustin Pop | @param rapicert_file: optional override of the rapi cert file path
|
129 | b6267745 | Andrea Spadaccini | @type spicecert_file: string
|
130 | b6267745 | Andrea Spadaccini | @param spicecert_file: optional override of the spice cert file path
|
131 | b6267745 | Andrea Spadaccini | @type spicecacert_file: string
|
132 | b6267745 | Andrea Spadaccini | @param spicecacert_file: optional override of the spice CA cert file path
|
133 | aeefe835 | Iustin Pop | @type hmackey_file: string
|
134 | aeefe835 | Iustin Pop | @param hmackey_file: optional override of the hmac key file path
|
135 | 43575108 | Michael Hanselmann |
|
136 | 43575108 | Michael Hanselmann | """
|
137 | 168c1de2 | Michael Hanselmann | # noded SSL certificate
|
138 | aeefe835 | Iustin Pop | cluster_cert_exists = os.path.exists(nodecert_file) |
139 | 43575108 | Michael Hanselmann | if new_cluster_cert or not cluster_cert_exists: |
140 | 43575108 | Michael Hanselmann | if cluster_cert_exists:
|
141 | aeefe835 | Iustin Pop | utils.CreateBackup(nodecert_file) |
142 | 43575108 | Michael Hanselmann | |
143 | aeefe835 | Iustin Pop | logging.debug("Generating new cluster certificate at %s", nodecert_file)
|
144 | af2ae1c0 | Iustin Pop | utils.GenerateSelfSignedSslCert(nodecert_file) |
145 | 43575108 | Michael Hanselmann | |
146 | 6b7d5878 | Michael Hanselmann | # confd HMAC key
|
147 | aeefe835 | Iustin Pop | if new_confd_hmac_key or not os.path.exists(hmackey_file): |
148 | aeefe835 | Iustin Pop | logging.debug("Writing new confd HMAC key to %s", hmackey_file)
|
149 | aeefe835 | Iustin Pop | GenerateHmacKey(hmackey_file) |
150 | 43575108 | Michael Hanselmann | |
151 | 43575108 | Michael Hanselmann | # RAPI
|
152 | aeefe835 | Iustin Pop | rapi_cert_exists = os.path.exists(rapicert_file) |
153 | 43575108 | Michael Hanselmann | |
154 | 43575108 | Michael Hanselmann | if rapi_cert_pem:
|
155 | 43575108 | Michael Hanselmann | # Assume rapi_pem contains a valid PEM-formatted certificate and key
|
156 | aeefe835 | Iustin Pop | logging.debug("Writing RAPI certificate at %s", rapicert_file)
|
157 | aeefe835 | Iustin Pop | utils.WriteFile(rapicert_file, data=rapi_cert_pem, backup=True)
|
158 | 43575108 | Michael Hanselmann | |
159 | 43575108 | Michael Hanselmann | elif new_rapi_cert or not rapi_cert_exists: |
160 | 43575108 | Michael Hanselmann | if rapi_cert_exists:
|
161 | aeefe835 | Iustin Pop | utils.CreateBackup(rapicert_file) |
162 | 43575108 | Michael Hanselmann | |
163 | aeefe835 | Iustin Pop | logging.debug("Generating new RAPI certificate at %s", rapicert_file)
|
164 | af2ae1c0 | Iustin Pop | utils.GenerateSelfSignedSslCert(rapicert_file) |
165 | c008906b | Michael Hanselmann | |
166 | b6267745 | Andrea Spadaccini | # SPICE
|
167 | b6267745 | Andrea Spadaccini | spice_cert_exists = os.path.exists(spicecert_file) |
168 | b6267745 | Andrea Spadaccini | spice_cacert_exists = os.path.exists(spicecacert_file) |
169 | b6267745 | Andrea Spadaccini | if spice_cert_pem:
|
170 | b6267745 | Andrea Spadaccini | # spice_cert_pem implies also spice_cacert_pem
|
171 | b6267745 | Andrea Spadaccini | logging.debug("Writing SPICE certificate at %s", spicecert_file)
|
172 | b6267745 | Andrea Spadaccini | utils.WriteFile(spicecert_file, data=spice_cert_pem, backup=True)
|
173 | b6267745 | Andrea Spadaccini | logging.debug("Writing SPICE CA certificate at %s", spicecacert_file)
|
174 | b6267745 | Andrea Spadaccini | utils.WriteFile(spicecacert_file, data=spice_cacert_pem, backup=True)
|
175 | b6267745 | Andrea Spadaccini | elif new_spice_cert or not spice_cert_exists: |
176 | b6267745 | Andrea Spadaccini | if spice_cert_exists:
|
177 | b6267745 | Andrea Spadaccini | utils.CreateBackup(spicecert_file) |
178 | b6267745 | Andrea Spadaccini | if spice_cacert_exists:
|
179 | b6267745 | Andrea Spadaccini | utils.CreateBackup(spicecacert_file) |
180 | b6267745 | Andrea Spadaccini | |
181 | b6267745 | Andrea Spadaccini | logging.debug("Generating new self-signed SPICE certificate at %s",
|
182 | b6267745 | Andrea Spadaccini | spicecert_file) |
183 | b6267745 | Andrea Spadaccini | (_, cert_pem) = utils.GenerateSelfSignedSslCert(spicecert_file) |
184 | b6267745 | Andrea Spadaccini | |
185 | b6267745 | Andrea Spadaccini | # Self-signed certificate -> the public certificate is also the CA public
|
186 | b6267745 | Andrea Spadaccini | # certificate
|
187 | b6267745 | Andrea Spadaccini | logging.debug("Writing the public certificate to %s",
|
188 | b6267745 | Andrea Spadaccini | spicecert_file) |
189 | b6267745 | Andrea Spadaccini | utils.io.WriteFile(spicecacert_file, mode=0400, data=cert_pem)
|
190 | b6267745 | Andrea Spadaccini | |
191 | 3db3eb2a | Michael Hanselmann | # Cluster domain secret
|
192 | 3db3eb2a | Michael Hanselmann | if cds:
|
193 | fc0726b9 | Michael Hanselmann | logging.debug("Writing cluster domain secret to %s", cds_file)
|
194 | fc0726b9 | Michael Hanselmann | utils.WriteFile(cds_file, data=cds, backup=True)
|
195 | fc0726b9 | Michael Hanselmann | |
196 | fc0726b9 | Michael Hanselmann | elif new_cds or not os.path.exists(cds_file): |
197 | fc0726b9 | Michael Hanselmann | logging.debug("Generating new cluster domain secret at %s", cds_file)
|
198 | fc0726b9 | Michael Hanselmann | GenerateHmacKey(cds_file) |
199 | 3db3eb2a | Michael Hanselmann | |
200 | c008906b | Michael Hanselmann | |
201 | 8f215968 | Michael Hanselmann | def _InitGanetiServerSetup(master_name): |
202 | 40a97d80 | Michael Hanselmann | """Setup the necessary configuration for the initial node daemon.
|
203 | 40a97d80 | Michael Hanselmann |
|
204 | 40a97d80 | Michael Hanselmann | This creates the nodepass file containing the shared password for
|
205 | 600535f0 | Manuel Franceschini | the cluster, generates the SSL certificate and starts the node daemon.
|
206 | 600535f0 | Manuel Franceschini |
|
207 | 600535f0 | Manuel Franceschini | @type master_name: str
|
208 | 600535f0 | Manuel Franceschini | @param master_name: Name of the master node
|
209 | 40a97d80 | Michael Hanselmann |
|
210 | 40a97d80 | Michael Hanselmann | """
|
211 | 43575108 | Michael Hanselmann | # Generate cluster secrets
|
212 | b6267745 | Andrea Spadaccini | GenerateClusterCrypto(True, False, False, False, False) |
213 | 4a34c5cf | Guido Trotter | |
214 | 7ede9c6a | Michael Hanselmann | result = utils.RunCmd([pathutils.DAEMON_UTIL, "start", constants.NODED])
|
215 | a0c9f010 | Michael Hanselmann | if result.failed:
|
216 | a0c9f010 | Michael Hanselmann | raise errors.OpExecError("Could not start the node daemon, command %s" |
217 | a0c9f010 | Michael Hanselmann | " had exitcode %s and error %s" %
|
218 | a0c9f010 | Michael Hanselmann | (result.cmd, result.exit_code, result.output)) |
219 | a0c9f010 | Michael Hanselmann | |
220 | 5627f375 | Michael Hanselmann | _WaitForNodeDaemon(master_name) |
221 | 5627f375 | Michael Hanselmann | |
222 | 5627f375 | Michael Hanselmann | |
223 | 5627f375 | Michael Hanselmann | def _WaitForNodeDaemon(node_name): |
224 | 5627f375 | Michael Hanselmann | """Wait for node daemon to become responsive.
|
225 | 5627f375 | Michael Hanselmann |
|
226 | 5627f375 | Michael Hanselmann | """
|
227 | d3833ebd | Michael Hanselmann | def _CheckNodeDaemon(): |
228 | bd6d1202 | Renรฉ Nussbaumer | # Pylint bug <http://www.logilab.org/ticket/35642>
|
229 | bd6d1202 | Renรฉ Nussbaumer | # pylint: disable=E1101
|
230 | db04ce5d | Michael Hanselmann | result = rpc.BootstrapRunner().call_version([node_name])[node_name] |
231 | d3833ebd | Michael Hanselmann | if result.fail_msg:
|
232 | d3833ebd | Michael Hanselmann | raise utils.RetryAgain()
|
233 | 8f215968 | Michael Hanselmann | |
234 | d3833ebd | Michael Hanselmann | try:
|
235 | 3b6b6129 | Michael Hanselmann | utils.Retry(_CheckNodeDaemon, 1.0, _DAEMON_READY_TIMEOUT)
|
236 | d3833ebd | Michael Hanselmann | except utils.RetryTimeout:
|
237 | 5627f375 | Michael Hanselmann | raise errors.OpExecError("Node daemon on %s didn't answer queries within" |
238 | 3b6b6129 | Michael Hanselmann | " %s seconds" % (node_name, _DAEMON_READY_TIMEOUT))
|
239 | 3b6b6129 | Michael Hanselmann | |
240 | 3b6b6129 | Michael Hanselmann | |
241 | 3b6b6129 | Michael Hanselmann | def _WaitForMasterDaemon(): |
242 | 3b6b6129 | Michael Hanselmann | """Wait for master daemon to become responsive.
|
243 | 3b6b6129 | Michael Hanselmann |
|
244 | 3b6b6129 | Michael Hanselmann | """
|
245 | 3b6b6129 | Michael Hanselmann | def _CheckMasterDaemon(): |
246 | 3b6b6129 | Michael Hanselmann | try:
|
247 | 3b6b6129 | Michael Hanselmann | cl = luxi.Client() |
248 | 3b6b6129 | Michael Hanselmann | (cluster_name, ) = cl.QueryConfigValues(["cluster_name"])
|
249 | 3b6b6129 | Michael Hanselmann | except Exception: |
250 | 3b6b6129 | Michael Hanselmann | raise utils.RetryAgain()
|
251 | 3b6b6129 | Michael Hanselmann | |
252 | 3b6b6129 | Michael Hanselmann | logging.debug("Received cluster name %s from master", cluster_name)
|
253 | 3b6b6129 | Michael Hanselmann | |
254 | 3b6b6129 | Michael Hanselmann | try:
|
255 | 3b6b6129 | Michael Hanselmann | utils.Retry(_CheckMasterDaemon, 1.0, _DAEMON_READY_TIMEOUT)
|
256 | 3b6b6129 | Michael Hanselmann | except utils.RetryTimeout:
|
257 | 3b6b6129 | Michael Hanselmann | raise errors.OpExecError("Master daemon didn't answer queries within" |
258 | 3b6b6129 | Michael Hanselmann | " %s seconds" % _DAEMON_READY_TIMEOUT)
|
259 | 5627f375 | Michael Hanselmann | |
260 | a0c9f010 | Michael Hanselmann | |
261 | a5da38fa | Michael Hanselmann | def _WaitForSshDaemon(hostname, port, family): |
262 | a5da38fa | Michael Hanselmann | """Wait for SSH daemon to become responsive.
|
263 | a5da38fa | Michael Hanselmann |
|
264 | a5da38fa | Michael Hanselmann | """
|
265 | a5da38fa | Michael Hanselmann | hostip = netutils.GetHostname(name=hostname, family=family).ip |
266 | a5da38fa | Michael Hanselmann | |
267 | a5da38fa | Michael Hanselmann | def _CheckSshDaemon(): |
268 | a5da38fa | Michael Hanselmann | if netutils.TcpPing(hostip, port, timeout=1.0, live_port_needed=True): |
269 | a5da38fa | Michael Hanselmann | logging.debug("SSH daemon on %s:%s (IP address %s) has become"
|
270 | a5da38fa | Michael Hanselmann | " responsive", hostname, port, hostip)
|
271 | a5da38fa | Michael Hanselmann | else:
|
272 | a5da38fa | Michael Hanselmann | raise utils.RetryAgain()
|
273 | a5da38fa | Michael Hanselmann | |
274 | a5da38fa | Michael Hanselmann | try:
|
275 | a5da38fa | Michael Hanselmann | utils.Retry(_CheckSshDaemon, 1.0, _DAEMON_READY_TIMEOUT)
|
276 | a5da38fa | Michael Hanselmann | except utils.RetryTimeout:
|
277 | a5da38fa | Michael Hanselmann | raise errors.OpExecError("SSH daemon on %s:%s (IP address %s) didn't" |
278 | a5da38fa | Michael Hanselmann | " become responsive within %s seconds" %
|
279 | a5da38fa | Michael Hanselmann | (hostname, port, hostip, _DAEMON_READY_TIMEOUT)) |
280 | a5da38fa | Michael Hanselmann | |
281 | a5da38fa | Michael Hanselmann | |
282 | a698cdbb | Michael Hanselmann | def RunNodeSetupCmd(cluster_name, node, basecmd, debug, verbose, |
283 | a698cdbb | Michael Hanselmann | use_cluster_key, ask_key, strict_host_check, data): |
284 | a698cdbb | Michael Hanselmann | """Runs a command to configure something on a remote machine.
|
285 | a698cdbb | Michael Hanselmann |
|
286 | a698cdbb | Michael Hanselmann | @type cluster_name: string
|
287 | a698cdbb | Michael Hanselmann | @param cluster_name: Cluster name
|
288 | a698cdbb | Michael Hanselmann | @type node: string
|
289 | a698cdbb | Michael Hanselmann | @param node: Node name
|
290 | a698cdbb | Michael Hanselmann | @type basecmd: string
|
291 | a698cdbb | Michael Hanselmann | @param basecmd: Base command (path on the remote machine)
|
292 | a698cdbb | Michael Hanselmann | @type debug: bool
|
293 | a698cdbb | Michael Hanselmann | @param debug: Enable debug output
|
294 | a698cdbb | Michael Hanselmann | @type verbose: bool
|
295 | a698cdbb | Michael Hanselmann | @param verbose: Enable verbose output
|
296 | a698cdbb | Michael Hanselmann | @type use_cluster_key: bool
|
297 | a698cdbb | Michael Hanselmann | @param use_cluster_key: See L{ssh.SshRunner.BuildCmd}
|
298 | a698cdbb | Michael Hanselmann | @type ask_key: bool
|
299 | a698cdbb | Michael Hanselmann | @param ask_key: See L{ssh.SshRunner.BuildCmd}
|
300 | a698cdbb | Michael Hanselmann | @type strict_host_check: bool
|
301 | a698cdbb | Michael Hanselmann | @param strict_host_check: See L{ssh.SshRunner.BuildCmd}
|
302 | a698cdbb | Michael Hanselmann | @param data: JSON-serializable input data for script (passed to stdin)
|
303 | a698cdbb | Michael Hanselmann |
|
304 | a698cdbb | Michael Hanselmann | """
|
305 | a698cdbb | Michael Hanselmann | cmd = [basecmd] |
306 | a698cdbb | Michael Hanselmann | |
307 | a698cdbb | Michael Hanselmann | # Pass --debug/--verbose to the external script if set on our invocation
|
308 | a698cdbb | Michael Hanselmann | if debug:
|
309 | a698cdbb | Michael Hanselmann | cmd.append("--debug")
|
310 | a698cdbb | Michael Hanselmann | |
311 | a698cdbb | Michael Hanselmann | if verbose:
|
312 | a698cdbb | Michael Hanselmann | cmd.append("--verbose")
|
313 | a698cdbb | Michael Hanselmann | |
314 | e1874aa7 | Michael Hanselmann | family = ssconf.SimpleStore().GetPrimaryIPFamily() |
315 | e1874aa7 | Michael Hanselmann | srun = ssh.SshRunner(cluster_name, |
316 | e1874aa7 | Michael Hanselmann | ipv6=(family == netutils.IP6Address.family)) |
317 | a698cdbb | Michael Hanselmann | scmd = srun.BuildCmd(node, constants.SSH_LOGIN_USER, |
318 | a698cdbb | Michael Hanselmann | utils.ShellQuoteArgs(cmd), |
319 | a698cdbb | Michael Hanselmann | batch=False, ask_key=ask_key, quiet=False, |
320 | a698cdbb | Michael Hanselmann | strict_host_check=strict_host_check, |
321 | a698cdbb | Michael Hanselmann | use_cluster_key=use_cluster_key) |
322 | a698cdbb | Michael Hanselmann | |
323 | a698cdbb | Michael Hanselmann | tempfh = tempfile.TemporaryFile() |
324 | a698cdbb | Michael Hanselmann | try:
|
325 | a698cdbb | Michael Hanselmann | tempfh.write(serializer.DumpJson(data)) |
326 | a698cdbb | Michael Hanselmann | tempfh.seek(0)
|
327 | a698cdbb | Michael Hanselmann | |
328 | a698cdbb | Michael Hanselmann | result = utils.RunCmd(scmd, interactive=True, input_fd=tempfh)
|
329 | a698cdbb | Michael Hanselmann | finally:
|
330 | a698cdbb | Michael Hanselmann | tempfh.close() |
331 | a698cdbb | Michael Hanselmann | |
332 | a698cdbb | Michael Hanselmann | if result.failed:
|
333 | a698cdbb | Michael Hanselmann | raise errors.OpExecError("Command '%s' failed: %s" % |
334 | a698cdbb | Michael Hanselmann | (result.cmd, result.fail_reason)) |
335 | a698cdbb | Michael Hanselmann | |
336 | a5da38fa | Michael Hanselmann | _WaitForSshDaemon(node, netutils.GetDaemonPort(constants.SSH), family) |
337 | a5da38fa | Michael Hanselmann | |
338 | a698cdbb | Michael Hanselmann | |
339 | 5030cff3 | Helga Velroyen | def _InitFileStorageDir(file_storage_dir): |
340 | 0e3baaf3 | Iustin Pop | """Initialize if needed the file storage.
|
341 | 0e3baaf3 | Iustin Pop |
|
342 | 0e3baaf3 | Iustin Pop | @param file_storage_dir: the user-supplied value
|
343 | 0e3baaf3 | Iustin Pop | @return: either empty string (if file storage was disabled at build
|
344 | 0e3baaf3 | Iustin Pop | time) or the normalized path to the storage directory
|
345 | 0e3baaf3 | Iustin Pop |
|
346 | 0e3baaf3 | Iustin Pop | """
|
347 | 0e3baaf3 | Iustin Pop | file_storage_dir = os.path.normpath(file_storage_dir) |
348 | 0e3baaf3 | Iustin Pop | |
349 | 0e3baaf3 | Iustin Pop | if not os.path.isabs(file_storage_dir): |
350 | 0376655e | Guido Trotter | raise errors.OpPrereqError("File storage directory '%s' is not an absolute" |
351 | 0376655e | Guido Trotter | " path" % file_storage_dir, errors.ECODE_INVAL)
|
352 | 0e3baaf3 | Iustin Pop | |
353 | 0e3baaf3 | Iustin Pop | if not os.path.exists(file_storage_dir): |
354 | 0e3baaf3 | Iustin Pop | try:
|
355 | 0e3baaf3 | Iustin Pop | os.makedirs(file_storage_dir, 0750)
|
356 | 0e3baaf3 | Iustin Pop | except OSError, err: |
357 | 0e3baaf3 | Iustin Pop | raise errors.OpPrereqError("Cannot create file storage directory" |
358 | 0e3baaf3 | Iustin Pop | " '%s': %s" % (file_storage_dir, err),
|
359 | 0e3baaf3 | Iustin Pop | errors.ECODE_ENVIRON) |
360 | 0e3baaf3 | Iustin Pop | |
361 | 0e3baaf3 | Iustin Pop | if not os.path.isdir(file_storage_dir): |
362 | 0e3baaf3 | Iustin Pop | raise errors.OpPrereqError("The file storage directory '%s' is not" |
363 | 0e3baaf3 | Iustin Pop | " a directory." % file_storage_dir,
|
364 | 0e3baaf3 | Iustin Pop | errors.ECODE_ENVIRON) |
365 | 5030cff3 | Helga Velroyen | |
366 | 0e3baaf3 | Iustin Pop | return file_storage_dir
|
367 | 0e3baaf3 | Iustin Pop | |
368 | 0e3baaf3 | Iustin Pop | |
369 | e8b5640e | Helga Velroyen | def _PrepareFileBasedStorage( |
370 | e8b5640e | Helga Velroyen | enabled_disk_templates, file_storage_dir, |
371 | e8b5640e | Helga Velroyen | default_dir, file_disk_template, |
372 | e8b5640e | Helga Velroyen | init_fn=_InitFileStorageDir, acceptance_fn=None):
|
373 | e8b5640e | Helga Velroyen | """Checks if a file-base storage type is enabled and inits the dir.
|
374 | e8b5640e | Helga Velroyen |
|
375 | e8b5640e | Helga Velroyen | @type enabled_disk_templates: list of string
|
376 | e8b5640e | Helga Velroyen | @param enabled_disk_templates: list of enabled disk templates
|
377 | e8b5640e | Helga Velroyen | @type file_storage_dir: string
|
378 | e8b5640e | Helga Velroyen | @param file_storage_dir: the file storage directory
|
379 | e8b5640e | Helga Velroyen | @type default_dir: string
|
380 | e8b5640e | Helga Velroyen | @param default_dir: default file storage directory when C{file_storage_dir}
|
381 | e8b5640e | Helga Velroyen | is 'None'
|
382 | e8b5640e | Helga Velroyen | @type file_disk_template: string
|
383 | e8b5640e | Helga Velroyen | @param file_disk_template: a disk template whose storage type is 'ST_FILE'
|
384 | e8b5640e | Helga Velroyen | @rtype: string
|
385 | e8b5640e | Helga Velroyen | @returns: the name of the actual file storage directory
|
386 | 3039e2dc | Helga Velroyen |
|
387 | 3039e2dc | Helga Velroyen | """
|
388 | e8b5640e | Helga Velroyen | assert (file_disk_template in |
389 | e8b5640e | Helga Velroyen | utils.storage.GetDiskTemplatesOfStorageType(constants.ST_FILE)) |
390 | 3039e2dc | Helga Velroyen | if file_storage_dir is None: |
391 | e8b5640e | Helga Velroyen | file_storage_dir = default_dir |
392 | 3039e2dc | Helga Velroyen | if not acceptance_fn: |
393 | 3039e2dc | Helga Velroyen | acceptance_fn = \ |
394 | 3039e2dc | Helga Velroyen | lambda path: filestorage.CheckFileStoragePathAcceptance(
|
395 | 3039e2dc | Helga Velroyen | path, exact_match_ok=True)
|
396 | 3039e2dc | Helga Velroyen | |
397 | 3039e2dc | Helga Velroyen | cluster.CheckFileStoragePathVsEnabledDiskTemplates( |
398 | 3039e2dc | Helga Velroyen | logging.warning, file_storage_dir, enabled_disk_templates) |
399 | 3039e2dc | Helga Velroyen | |
400 | e8b5640e | Helga Velroyen | file_storage_enabled = file_disk_template in enabled_disk_templates
|
401 | 3039e2dc | Helga Velroyen | if file_storage_enabled:
|
402 | 3039e2dc | Helga Velroyen | try:
|
403 | 3039e2dc | Helga Velroyen | acceptance_fn(file_storage_dir) |
404 | 3039e2dc | Helga Velroyen | except errors.FileStoragePathError as e: |
405 | 3039e2dc | Helga Velroyen | raise errors.OpPrereqError(str(e)) |
406 | 3039e2dc | Helga Velroyen | result_file_storage_dir = init_fn(file_storage_dir) |
407 | 3039e2dc | Helga Velroyen | else:
|
408 | 3039e2dc | Helga Velroyen | result_file_storage_dir = file_storage_dir |
409 | 3039e2dc | Helga Velroyen | return result_file_storage_dir
|
410 | 3039e2dc | Helga Velroyen | |
411 | 3039e2dc | Helga Velroyen | |
412 | e8b5640e | Helga Velroyen | def _PrepareFileStorage( |
413 | e8b5640e | Helga Velroyen | enabled_disk_templates, file_storage_dir, init_fn=_InitFileStorageDir, |
414 | e8b5640e | Helga Velroyen | acceptance_fn=None):
|
415 | e8b5640e | Helga Velroyen | """Checks if file storage is enabled and inits the dir.
|
416 | e8b5640e | Helga Velroyen |
|
417 | e8b5640e | Helga Velroyen | @see: C{_PrepareFileBasedStorage}
|
418 | e8b5640e | Helga Velroyen |
|
419 | e8b5640e | Helga Velroyen | """
|
420 | e8b5640e | Helga Velroyen | return _PrepareFileBasedStorage(
|
421 | e8b5640e | Helga Velroyen | enabled_disk_templates, file_storage_dir, |
422 | e8b5640e | Helga Velroyen | pathutils.DEFAULT_FILE_STORAGE_DIR, constants.DT_FILE, |
423 | e8b5640e | Helga Velroyen | init_fn=init_fn, acceptance_fn=acceptance_fn) |
424 | e8b5640e | Helga Velroyen | |
425 | e8b5640e | Helga Velroyen | |
426 | e8b5640e | Helga Velroyen | def _PrepareSharedFileStorage( |
427 | e8b5640e | Helga Velroyen | enabled_disk_templates, file_storage_dir, init_fn=_InitFileStorageDir, |
428 | e8b5640e | Helga Velroyen | acceptance_fn=None):
|
429 | e8b5640e | Helga Velroyen | """Checks if shared file storage is enabled and inits the dir.
|
430 | e8b5640e | Helga Velroyen |
|
431 | e8b5640e | Helga Velroyen | @see: C{_PrepareFileBasedStorage}
|
432 | e8b5640e | Helga Velroyen |
|
433 | e8b5640e | Helga Velroyen | """
|
434 | e8b5640e | Helga Velroyen | return _PrepareFileBasedStorage(
|
435 | e8b5640e | Helga Velroyen | enabled_disk_templates, file_storage_dir, |
436 | e8b5640e | Helga Velroyen | pathutils.DEFAULT_SHARED_FILE_STORAGE_DIR, constants.DT_SHARED_FILE, |
437 | e8b5640e | Helga Velroyen | init_fn=init_fn, acceptance_fn=acceptance_fn) |
438 | e8b5640e | Helga Velroyen | |
439 | e8b5640e | Helga Velroyen | |
440 | 5030cff3 | Helga Velroyen | def _InitCheckEnabledDiskTemplates(enabled_disk_templates): |
441 | 5030cff3 | Helga Velroyen | """Checks the sanity of the enabled disk templates.
|
442 | 5030cff3 | Helga Velroyen |
|
443 | 5030cff3 | Helga Velroyen | """
|
444 | 5030cff3 | Helga Velroyen | if not enabled_disk_templates: |
445 | 5030cff3 | Helga Velroyen | raise errors.OpPrereqError("Enabled disk templates list must contain at" |
446 | 5030cff3 | Helga Velroyen | " least one member", errors.ECODE_INVAL)
|
447 | 5030cff3 | Helga Velroyen | invalid_disk_templates = \ |
448 | 5030cff3 | Helga Velroyen | set(enabled_disk_templates) - constants.DISK_TEMPLATES
|
449 | 5030cff3 | Helga Velroyen | if invalid_disk_templates:
|
450 | 5030cff3 | Helga Velroyen | raise errors.OpPrereqError("Enabled disk templates list contains invalid" |
451 | 5030cff3 | Helga Velroyen | " entries: %s" % invalid_disk_templates,
|
452 | 5030cff3 | Helga Velroyen | errors.ECODE_INVAL) |
453 | 5030cff3 | Helga Velroyen | |
454 | 5030cff3 | Helga Velroyen | |
455 | d514e18b | Helga Velroyen | def _RestrictIpolicyToEnabledDiskTemplates(ipolicy, enabled_disk_templates): |
456 | d514e18b | Helga Velroyen | """Restricts the ipolicy's disk templates to the enabled ones.
|
457 | d514e18b | Helga Velroyen |
|
458 | d514e18b | Helga Velroyen | This function clears the ipolicy's list of allowed disk templates from the
|
459 | d514e18b | Helga Velroyen | ones that are not enabled by the cluster.
|
460 | d514e18b | Helga Velroyen |
|
461 | d514e18b | Helga Velroyen | @type ipolicy: dict
|
462 | d514e18b | Helga Velroyen | @param ipolicy: the instance policy
|
463 | d514e18b | Helga Velroyen | @type enabled_disk_templates: list of string
|
464 | d514e18b | Helga Velroyen | @param enabled_disk_templates: the list of cluster-wide enabled disk
|
465 | d514e18b | Helga Velroyen | templates
|
466 | d514e18b | Helga Velroyen |
|
467 | d514e18b | Helga Velroyen | """
|
468 | d514e18b | Helga Velroyen | assert constants.IPOLICY_DTS in ipolicy |
469 | d514e18b | Helga Velroyen | allowed_disk_templates = ipolicy[constants.IPOLICY_DTS] |
470 | d514e18b | Helga Velroyen | restricted_disk_templates = list(set(allowed_disk_templates) |
471 | d514e18b | Helga Velroyen | .intersection(set(enabled_disk_templates)))
|
472 | d514e18b | Helga Velroyen | ipolicy[constants.IPOLICY_DTS] = restricted_disk_templates |
473 | d514e18b | Helga Velroyen | |
474 | d514e18b | Helga Velroyen | |
475 | 18bb6d28 | Agata Murawska | def InitCluster(cluster_name, mac_prefix, # pylint: disable=R0913, R0914 |
476 | 5a8648eb | Andrea Spadaccini | master_netmask, master_netdev, file_storage_dir, |
477 | 5a8648eb | Andrea Spadaccini | shared_file_storage_dir, candidate_pool_size, secondary_ip=None,
|
478 | 5a8648eb | Andrea Spadaccini | vg_name=None, beparams=None, nicparams=None, ndparams=None, |
479 | bc5d0215 | Andrea Spadaccini | hvparams=None, diskparams=None, enabled_hypervisors=None, |
480 | bc5d0215 | Andrea Spadaccini | modify_etc_hosts=True, modify_ssh_setup=True, |
481 | bc5d0215 | Andrea Spadaccini | maintain_node_health=False, drbd_helper=None, uid_pool=None, |
482 | 18bb6d28 | Agata Murawska | default_iallocator=None, primary_ip_version=None, ipolicy=None, |
483 | c4929a8b | Renรฉ Nussbaumer | prealloc_wipe_disks=False, use_external_mip_script=False, |
484 | 3bde79ee | Helga Velroyen | hv_state=None, disk_state=None, enabled_disk_templates=None): |
485 | a0c9f010 | Michael Hanselmann | """Initialise the cluster.
|
486 | a0c9f010 | Michael Hanselmann |
|
487 | ce735215 | Guido Trotter | @type candidate_pool_size: int
|
488 | ce735215 | Guido Trotter | @param candidate_pool_size: master candidate pool size
|
489 | 3bde79ee | Helga Velroyen | @type enabled_disk_templates: list of string
|
490 | 3bde79ee | Helga Velroyen | @param enabled_disk_templates: list of disk_templates to be used in this
|
491 | c074a9e8 | Helga Velroyen | cluster
|
492 | ce735215 | Guido Trotter |
|
493 | a0c9f010 | Michael Hanselmann | """
|
494 | ce735215 | Guido Trotter | # TODO: complete the docstring
|
495 | a0c9f010 | Michael Hanselmann | if config.ConfigWriter.IsCluster():
|
496 | debac808 | Iustin Pop | raise errors.OpPrereqError("Cluster is already initialised", |
497 | debac808 | Iustin Pop | errors.ECODE_STATE) |
498 | a0c9f010 | Michael Hanselmann | |
499 | b119bccb | Guido Trotter | if not enabled_hypervisors: |
500 | b119bccb | Guido Trotter | raise errors.OpPrereqError("Enabled hypervisors list must contain at" |
501 | debac808 | Iustin Pop | " least one member", errors.ECODE_INVAL)
|
502 | b119bccb | Guido Trotter | invalid_hvs = set(enabled_hypervisors) - constants.HYPER_TYPES
|
503 | b119bccb | Guido Trotter | if invalid_hvs:
|
504 | b119bccb | Guido Trotter | raise errors.OpPrereqError("Enabled hypervisors contains invalid" |
505 | debac808 | Iustin Pop | " entries: %s" % invalid_hvs,
|
506 | debac808 | Iustin Pop | errors.ECODE_INVAL) |
507 | b119bccb | Guido Trotter | |
508 | 5030cff3 | Helga Velroyen | _InitCheckEnabledDiskTemplates(enabled_disk_templates) |
509 | c074a9e8 | Helga Velroyen | |
510 | 5a8648eb | Andrea Spadaccini | try:
|
511 | 5a8648eb | Andrea Spadaccini | ipcls = netutils.IPAddress.GetClassFromIpVersion(primary_ip_version) |
512 | 5a8648eb | Andrea Spadaccini | except errors.ProgrammerError:
|
513 | 2f20d07b | Manuel Franceschini | raise errors.OpPrereqError("Invalid primary ip version: %d." % |
514 | 2cfbc784 | Iustin Pop | primary_ip_version, errors.ECODE_INVAL) |
515 | 2f20d07b | Manuel Franceschini | |
516 | 2f20d07b | Manuel Franceschini | hostname = netutils.GetHostname(family=ipcls.family) |
517 | 2f20d07b | Manuel Franceschini | if not ipcls.IsValid(hostname.ip): |
518 | 2f20d07b | Manuel Franceschini | raise errors.OpPrereqError("This host's IP (%s) is not a valid IPv%d" |
519 | 2cfbc784 | Iustin Pop | " address." % (hostname.ip, primary_ip_version),
|
520 | 2cfbc784 | Iustin Pop | errors.ECODE_INVAL) |
521 | 2f20d07b | Manuel Franceschini | |
522 | 2f20d07b | Manuel Franceschini | if ipcls.IsLoopback(hostname.ip):
|
523 | 8b312c1d | Manuel Franceschini | raise errors.OpPrereqError("This host's IP (%s) resolves to a loopback" |
524 | 8b312c1d | Manuel Franceschini | " address. Please fix DNS or %s." %
|
525 | ee045466 | Michael Hanselmann | (hostname.ip, pathutils.ETC_HOSTS), |
526 | debac808 | Iustin Pop | errors.ECODE_ENVIRON) |
527 | a0c9f010 | Michael Hanselmann | |
528 | 2f20d07b | Manuel Franceschini | if not ipcls.Own(hostname.ip): |
529 | a0c9f010 | Michael Hanselmann | raise errors.OpPrereqError("Inconsistency: this host's name resolves" |
530 | a0c9f010 | Michael Hanselmann | " to %s,\nbut this ip address does not"
|
531 | 7c4c22f5 | Manuel Franceschini | " belong to this host" %
|
532 | debac808 | Iustin Pop | hostname.ip, errors.ECODE_ENVIRON) |
533 | a0c9f010 | Michael Hanselmann | |
534 | 2f20d07b | Manuel Franceschini | clustername = netutils.GetHostname(name=cluster_name, family=ipcls.family) |
535 | a0c9f010 | Michael Hanselmann | |
536 | 2f20d07b | Manuel Franceschini | if netutils.TcpPing(clustername.ip, constants.DEFAULT_NODED_PORT, timeout=5): |
537 | 7c4c22f5 | Manuel Franceschini | raise errors.OpPrereqError("Cluster IP already active", |
538 | debac808 | Iustin Pop | errors.ECODE_NOTUNIQUE) |
539 | a0c9f010 | Michael Hanselmann | |
540 | 2f20d07b | Manuel Franceschini | if not secondary_ip: |
541 | 2f20d07b | Manuel Franceschini | if primary_ip_version == constants.IP6_VERSION:
|
542 | 2f20d07b | Manuel Franceschini | raise errors.OpPrereqError("When using a IPv6 primary address, a valid" |
543 | 7c4c22f5 | Manuel Franceschini | " IPv4 address must be given as secondary",
|
544 | 7c4c22f5 | Manuel Franceschini | errors.ECODE_INVAL) |
545 | b9eeeb02 | Michael Hanselmann | secondary_ip = hostname.ip |
546 | a0c9f010 | Michael Hanselmann | |
547 | 2f20d07b | Manuel Franceschini | if not netutils.IP4Address.IsValid(secondary_ip): |
548 | 2f20d07b | Manuel Franceschini | raise errors.OpPrereqError("Secondary IP address (%s) has to be a valid" |
549 | 2f20d07b | Manuel Franceschini | " IPv4 address." % secondary_ip,
|
550 | 2f20d07b | Manuel Franceschini | errors.ECODE_INVAL) |
551 | 2f20d07b | Manuel Franceschini | |
552 | 2f20d07b | Manuel Franceschini | if not netutils.IP4Address.Own(secondary_ip): |
553 | 2f20d07b | Manuel Franceschini | raise errors.OpPrereqError("You gave %s as secondary IP," |
554 | 2f20d07b | Manuel Franceschini | " but it does not belong to this host." %
|
555 | 2f20d07b | Manuel Franceschini | secondary_ip, errors.ECODE_ENVIRON) |
556 | 2f20d07b | Manuel Franceschini | |
557 | 5a8648eb | Andrea Spadaccini | if master_netmask is not None: |
558 | 5a8648eb | Andrea Spadaccini | if not ipcls.ValidateNetmask(master_netmask): |
559 | 5a8648eb | Andrea Spadaccini | raise errors.OpPrereqError("CIDR netmask (%s) not valid for IPv%s " % |
560 | 2cfbc784 | Iustin Pop | (master_netmask, primary_ip_version), |
561 | 2cfbc784 | Iustin Pop | errors.ECODE_INVAL) |
562 | 5a8648eb | Andrea Spadaccini | else:
|
563 | 5a8648eb | Andrea Spadaccini | master_netmask = ipcls.iplen |
564 | 5a8648eb | Andrea Spadaccini | |
565 | 912737ba | Helga Velroyen | if vg_name:
|
566 | a0c9f010 | Michael Hanselmann | # Check if volume group is valid
|
567 | a0c9f010 | Michael Hanselmann | vgstatus = utils.CheckVolumeGroupSize(utils.ListVolumeGroups(), vg_name, |
568 | a0c9f010 | Michael Hanselmann | constants.MIN_VG_SIZE) |
569 | a0c9f010 | Michael Hanselmann | if vgstatus:
|
570 | 912737ba | Helga Velroyen | raise errors.OpPrereqError("Error: %s" % vgstatus, errors.ECODE_INVAL) |
571 | a0c9f010 | Michael Hanselmann | |
572 | a721e23a | Luca Bigliardi | if drbd_helper is not None: |
573 | a721e23a | Luca Bigliardi | try:
|
574 | 47e0abee | Thomas Thrainer | curr_helper = drbd.DRBD8.GetUsermodeHelper() |
575 | a721e23a | Luca Bigliardi | except errors.BlockDeviceError, err:
|
576 | a721e23a | Luca Bigliardi | raise errors.OpPrereqError("Error while checking drbd helper" |
577 | a721e23a | Luca Bigliardi | " (specify --no-drbd-storage if you are not"
|
578 | a721e23a | Luca Bigliardi | " using drbd): %s" % str(err), |
579 | a721e23a | Luca Bigliardi | errors.ECODE_ENVIRON) |
580 | a721e23a | Luca Bigliardi | if drbd_helper != curr_helper:
|
581 | a721e23a | Luca Bigliardi | raise errors.OpPrereqError("Error: requiring %s as drbd helper but %s" |
582 | a721e23a | Luca Bigliardi | " is the current helper" % (drbd_helper,
|
583 | a721e23a | Luca Bigliardi | curr_helper), |
584 | a721e23a | Luca Bigliardi | errors.ECODE_INVAL) |
585 | a721e23a | Luca Bigliardi | |
586 | 32ba31be | Michael Hanselmann | logging.debug("Stopping daemons (if any are running)")
|
587 | 32ba31be | Michael Hanselmann | result = utils.RunCmd([pathutils.DAEMON_UTIL, "stop-all"])
|
588 | 32ba31be | Michael Hanselmann | if result.failed:
|
589 | 32ba31be | Michael Hanselmann | raise errors.OpExecError("Could not stop daemons, command %s" |
590 | 32ba31be | Michael Hanselmann | " had exitcode %s and error '%s'" %
|
591 | 32ba31be | Michael Hanselmann | (result.cmd, result.exit_code, result.output)) |
592 | 32ba31be | Michael Hanselmann | |
593 | 5030cff3 | Helga Velroyen | file_storage_dir = _PrepareFileStorage(enabled_disk_templates, |
594 | 5030cff3 | Helga Velroyen | file_storage_dir) |
595 | e8b5640e | Helga Velroyen | shared_file_storage_dir = _PrepareSharedFileStorage(enabled_disk_templates, |
596 | e8b5640e | Helga Velroyen | shared_file_storage_dir) |
597 | a0c9f010 | Michael Hanselmann | |
598 | a0c9f010 | Michael Hanselmann | if not re.match("^[0-9a-z]{2}:[0-9a-z]{2}:[0-9a-z]{2}$", mac_prefix): |
599 | debac808 | Iustin Pop | raise errors.OpPrereqError("Invalid mac prefix given '%s'" % mac_prefix, |
600 | debac808 | Iustin Pop | errors.ECODE_INVAL) |
601 | a0c9f010 | Michael Hanselmann | |
602 | a0c9f010 | Michael Hanselmann | result = utils.RunCmd(["ip", "link", "show", "dev", master_netdev]) |
603 | a0c9f010 | Michael Hanselmann | if result.failed:
|
604 | a0c9f010 | Michael Hanselmann | raise errors.OpPrereqError("Invalid master netdev given (%s): '%s'" % |
605 | a0c9f010 | Michael Hanselmann | (master_netdev, |
606 | debac808 | Iustin Pop | result.output.strip()), errors.ECODE_INVAL) |
607 | a0c9f010 | Michael Hanselmann | |
608 | 7ede9c6a | Michael Hanselmann | dirs = [(pathutils.RUN_DIR, constants.RUN_DIRS_MODE)] |
609 | 9dae41ad | Guido Trotter | utils.EnsureDirs(dirs) |
610 | 9dae41ad | Guido Trotter | |
611 | b2e233a5 | Guido Trotter | objects.UpgradeBeParams(beparams) |
612 | a5728081 | Guido Trotter | utils.ForceDictType(beparams, constants.BES_PARAMETER_TYPES) |
613 | b6a30b0d | Guido Trotter | utils.ForceDictType(nicparams, constants.NICS_PARAMETER_TYPES) |
614 | 18bb6d28 | Agata Murawska | |
615 | b6a30b0d | Guido Trotter | objects.NIC.CheckParameterSyntax(nicparams) |
616 | 57dc299a | Iustin Pop | |
617 | 2cc673a3 | Iustin Pop | full_ipolicy = objects.FillIPolicy(constants.IPOLICY_DEFAULTS, ipolicy) |
618 | d514e18b | Helga Velroyen | _RestrictIpolicyToEnabledDiskTemplates(full_ipolicy, enabled_disk_templates) |
619 | b6a30b0d | Guido Trotter | |
620 | 6204ee71 | Renรฉ Nussbaumer | if ndparams is not None: |
621 | 6204ee71 | Renรฉ Nussbaumer | utils.ForceDictType(ndparams, constants.NDS_PARAMETER_TYPES) |
622 | 6204ee71 | Renรฉ Nussbaumer | else:
|
623 | 6204ee71 | Renรฉ Nussbaumer | ndparams = dict(constants.NDC_DEFAULTS)
|
624 | 6204ee71 | Renรฉ Nussbaumer | |
625 | c4929a8b | Renรฉ Nussbaumer | # This is ugly, as we modify the dict itself
|
626 | 57dc299a | Iustin Pop | # FIXME: Make utils.ForceDictType pure functional or write a wrapper
|
627 | 57dc299a | Iustin Pop | # around it
|
628 | c4929a8b | Renรฉ Nussbaumer | if hv_state:
|
629 | c4929a8b | Renรฉ Nussbaumer | for hvname, hvs_data in hv_state.items(): |
630 | c4929a8b | Renรฉ Nussbaumer | utils.ForceDictType(hvs_data, constants.HVSTS_PARAMETER_TYPES) |
631 | c4929a8b | Renรฉ Nussbaumer | hv_state[hvname] = objects.Cluster.SimpleFillHvState(hvs_data) |
632 | c4929a8b | Renรฉ Nussbaumer | else:
|
633 | c4929a8b | Renรฉ Nussbaumer | hv_state = dict((hvname, constants.HVST_DEFAULTS)
|
634 | c4929a8b | Renรฉ Nussbaumer | for hvname in enabled_hypervisors) |
635 | c4929a8b | Renรฉ Nussbaumer | |
636 | c4929a8b | Renรฉ Nussbaumer | # FIXME: disk_state has no default values yet
|
637 | c4929a8b | Renรฉ Nussbaumer | if disk_state:
|
638 | c4929a8b | Renรฉ Nussbaumer | for storage, ds_data in disk_state.items(): |
639 | c4929a8b | Renรฉ Nussbaumer | if storage not in constants.DS_VALID_TYPES: |
640 | c4929a8b | Renรฉ Nussbaumer | raise errors.OpPrereqError("Invalid storage type in disk state: %s" % |
641 | c4929a8b | Renรฉ Nussbaumer | storage, errors.ECODE_INVAL) |
642 | c4929a8b | Renรฉ Nussbaumer | for ds_name, state in ds_data.items(): |
643 | c4929a8b | Renรฉ Nussbaumer | utils.ForceDictType(state, constants.DSS_PARAMETER_TYPES) |
644 | c4929a8b | Renรฉ Nussbaumer | ds_data[ds_name] = objects.Cluster.SimpleFillDiskState(state) |
645 | c4929a8b | Renรฉ Nussbaumer | |
646 | a5728081 | Guido Trotter | # hvparams is a mapping of hypervisor->hvparams dict
|
647 | a5728081 | Guido Trotter | for hv_name, hv_params in hvparams.iteritems(): |
648 | a5728081 | Guido Trotter | utils.ForceDictType(hv_params, constants.HVS_PARAMETER_TYPES) |
649 | a5728081 | Guido Trotter | hv_class = hypervisor.GetHypervisor(hv_name) |
650 | a5728081 | Guido Trotter | hv_class.CheckParameterSyntax(hv_params) |
651 | d4b72030 | Guido Trotter | |
652 | bc5d0215 | Andrea Spadaccini | # diskparams is a mapping of disk-template->diskparams dict
|
653 | bc5d0215 | Andrea Spadaccini | for template, dt_params in diskparams.items(): |
654 | bc5d0215 | Andrea Spadaccini | param_keys = set(dt_params.keys())
|
655 | bc5d0215 | Andrea Spadaccini | default_param_keys = set(constants.DISK_DT_DEFAULTS[template].keys())
|
656 | bc5d0215 | Andrea Spadaccini | if not (param_keys <= default_param_keys): |
657 | bc5d0215 | Andrea Spadaccini | unknown_params = param_keys - default_param_keys |
658 | bc5d0215 | Andrea Spadaccini | raise errors.OpPrereqError("Invalid parameters for disk template %s:" |
659 | bc5d0215 | Andrea Spadaccini | " %s" % (template,
|
660 | 2cfbc784 | Iustin Pop | utils.CommaJoin(unknown_params)), |
661 | 2cfbc784 | Iustin Pop | errors.ECODE_INVAL) |
662 | bc5d0215 | Andrea Spadaccini | utils.ForceDictType(dt_params, constants.DISK_DT_TYPES) |
663 | 35c48839 | Michele Tartara | if template == constants.DT_DRBD8 and vg_name is not None: |
664 | 35c48839 | Michele Tartara | # The default METAVG value is equal to the VG name set at init time,
|
665 | 35c48839 | Michele Tartara | # if provided
|
666 | 35c48839 | Michele Tartara | dt_params[constants.DRBD_DEFAULT_METAVG] = vg_name |
667 | 35c48839 | Michele Tartara | |
668 | e4a4391d | Renรฉ Nussbaumer | try:
|
669 | e4a4391d | Renรฉ Nussbaumer | utils.VerifyDictOptions(diskparams, constants.DISK_DT_DEFAULTS) |
670 | e4a4391d | Renรฉ Nussbaumer | except errors.OpPrereqError, err:
|
671 | e4a4391d | Renรฉ Nussbaumer | raise errors.OpPrereqError("While verify diskparam options: %s" % err, |
672 | e4a4391d | Renรฉ Nussbaumer | errors.ECODE_INVAL) |
673 | bc5d0215 | Andrea Spadaccini | |
674 | a0c9f010 | Michael Hanselmann | # set up ssh config and /etc/hosts
|
675 | a9542a4f | Thomas Thrainer | rsa_sshkey = ""
|
676 | a9542a4f | Thomas Thrainer | dsa_sshkey = ""
|
677 | a9542a4f | Thomas Thrainer | if os.path.isfile(pathutils.SSH_HOST_RSA_PUB):
|
678 | a9542a4f | Thomas Thrainer | sshline = utils.ReadFile(pathutils.SSH_HOST_RSA_PUB) |
679 | a9542a4f | Thomas Thrainer | rsa_sshkey = sshline.split(" ")[1] |
680 | a9542a4f | Thomas Thrainer | if os.path.isfile(pathutils.SSH_HOST_DSA_PUB):
|
681 | a9542a4f | Thomas Thrainer | sshline = utils.ReadFile(pathutils.SSH_HOST_DSA_PUB) |
682 | a9542a4f | Thomas Thrainer | dsa_sshkey = sshline.split(" ")[1] |
683 | a9542a4f | Thomas Thrainer | if not rsa_sshkey and not dsa_sshkey: |
684 | a9542a4f | Thomas Thrainer | raise errors.OpPrereqError("Failed to find SSH public keys", |
685 | a9542a4f | Thomas Thrainer | errors.ECODE_ENVIRON) |
686 | a0c9f010 | Michael Hanselmann | |
687 | b86a6bcd | Guido Trotter | if modify_etc_hosts:
|
688 | ea8ac9c9 | Renรฉ Nussbaumer | utils.AddHostToEtcHosts(hostname.name, hostname.ip) |
689 | b86a6bcd | Guido Trotter | |
690 | b989b9d9 | Ken Wehr | if modify_ssh_setup:
|
691 | b989b9d9 | Ken Wehr | _InitSSHSetup() |
692 | a0c9f010 | Michael Hanselmann | |
693 | bf4af505 | Apollon Oikonomopoulos | if default_iallocator is not None: |
694 | bf4af505 | Apollon Oikonomopoulos | alloc_script = utils.FindFile(default_iallocator, |
695 | bf4af505 | Apollon Oikonomopoulos | constants.IALLOCATOR_SEARCH_PATH, |
696 | bf4af505 | Apollon Oikonomopoulos | os.path.isfile) |
697 | bf4af505 | Apollon Oikonomopoulos | if alloc_script is None: |
698 | bf4af505 | Apollon Oikonomopoulos | raise errors.OpPrereqError("Invalid default iallocator script '%s'" |
699 | bf4af505 | Apollon Oikonomopoulos | " specified" % default_iallocator,
|
700 | bf4af505 | Apollon Oikonomopoulos | errors.ECODE_INVAL) |
701 | d1e9c98d | Iustin Pop | elif constants.HTOOLS:
|
702 | d1e9c98d | Iustin Pop | # htools was enabled at build-time, we default to it
|
703 | d1e9c98d | Iustin Pop | if utils.FindFile(constants.IALLOC_HAIL,
|
704 | d1e9c98d | Iustin Pop | constants.IALLOCATOR_SEARCH_PATH, |
705 | d1e9c98d | Iustin Pop | os.path.isfile): |
706 | d1e9c98d | Iustin Pop | default_iallocator = constants.IALLOC_HAIL |
707 | bf4af505 | Apollon Oikonomopoulos | |
708 | 430b923c | Iustin Pop | now = time.time() |
709 | 430b923c | Iustin Pop | |
710 | a0c9f010 | Michael Hanselmann | # init of cluster config file
|
711 | b9eeeb02 | Michael Hanselmann | cluster_config = objects.Cluster( |
712 | b9eeeb02 | Michael Hanselmann | serial_no=1,
|
713 | a9542a4f | Thomas Thrainer | rsahostkeypub=rsa_sshkey, |
714 | a9542a4f | Thomas Thrainer | dsahostkeypub=dsa_sshkey, |
715 | b9eeeb02 | Michael Hanselmann | highest_used_port=(constants.FIRST_DRBD_PORT - 1),
|
716 | b9eeeb02 | Michael Hanselmann | mac_prefix=mac_prefix, |
717 | b9eeeb02 | Michael Hanselmann | volume_group_name=vg_name, |
718 | b9eeeb02 | Michael Hanselmann | tcpudp_port_pool=set(),
|
719 | f6bd6e98 | Michael Hanselmann | master_ip=clustername.ip, |
720 | 5a8648eb | Andrea Spadaccini | master_netmask=master_netmask, |
721 | f6bd6e98 | Michael Hanselmann | master_netdev=master_netdev, |
722 | f6bd6e98 | Michael Hanselmann | cluster_name=clustername.name, |
723 | f6bd6e98 | Michael Hanselmann | file_storage_dir=file_storage_dir, |
724 | 4b97f902 | Apollon Oikonomopoulos | shared_file_storage_dir=shared_file_storage_dir, |
725 | ea3a925f | Alexander Schreiber | enabled_hypervisors=enabled_hypervisors, |
726 | 4ef7f423 | Guido Trotter | beparams={constants.PP_DEFAULT: beparams}, |
727 | b6a30b0d | Guido Trotter | nicparams={constants.PP_DEFAULT: nicparams}, |
728 | 6204ee71 | Renรฉ Nussbaumer | ndparams=ndparams, |
729 | ea3a925f | Alexander Schreiber | hvparams=hvparams, |
730 | bc5d0215 | Andrea Spadaccini | diskparams=diskparams, |
731 | ce735215 | Guido Trotter | candidate_pool_size=candidate_pool_size, |
732 | 022c3a0b | Guido Trotter | modify_etc_hosts=modify_etc_hosts, |
733 | b989b9d9 | Ken Wehr | modify_ssh_setup=modify_ssh_setup, |
734 | 39b0f0c2 | Balazs Lecz | uid_pool=uid_pool, |
735 | 430b923c | Iustin Pop | ctime=now, |
736 | 430b923c | Iustin Pop | mtime=now, |
737 | 3953242f | Iustin Pop | maintain_node_health=maintain_node_health, |
738 | a721e23a | Luca Bigliardi | drbd_usermode_helper=drbd_helper, |
739 | bf4af505 | Apollon Oikonomopoulos | default_iallocator=default_iallocator, |
740 | 2f20d07b | Manuel Franceschini | primary_ip_family=ipcls.family, |
741 | 3d914585 | Renรฉ Nussbaumer | prealloc_wipe_disks=prealloc_wipe_disks, |
742 | bf689b7a | Andrea Spadaccini | use_external_mip_script=use_external_mip_script, |
743 | 57dc299a | Iustin Pop | ipolicy=full_ipolicy, |
744 | c4929a8b | Renรฉ Nussbaumer | hv_state_static=hv_state, |
745 | c4929a8b | Renรฉ Nussbaumer | disk_state_static=disk_state, |
746 | 3bde79ee | Helga Velroyen | enabled_disk_templates=enabled_disk_templates, |
747 | b9eeeb02 | Michael Hanselmann | ) |
748 | b9eeeb02 | Michael Hanselmann | master_node_config = objects.Node(name=hostname.name, |
749 | b9eeeb02 | Michael Hanselmann | primary_ip=hostname.ip, |
750 | b9222f32 | Guido Trotter | secondary_ip=secondary_ip, |
751 | c044f32c | Guido Trotter | serial_no=1,
|
752 | c044f32c | Guido Trotter | master_candidate=True,
|
753 | af64c0ea | Iustin Pop | offline=False, drained=False, |
754 | 435e4bd6 | Michael Hanselmann | ctime=now, mtime=now, |
755 | c044f32c | Guido Trotter | ) |
756 | 9e1333b9 | Guido Trotter | InitConfig(constants.CONFIG_VERSION, cluster_config, master_node_config) |
757 | d367b66c | Manuel Franceschini | cfg = config.ConfigWriter(offline=True)
|
758 | 7ede9c6a | Michael Hanselmann | ssh.WriteKnownHostsFile(cfg, pathutils.SSH_KNOWN_HOSTS_FILE) |
759 | a4eae71f | Michael Hanselmann | cfg.Update(cfg.GetClusterInfo(), logging.error) |
760 | ee501db1 | Michael Hanselmann | ssconf.WriteSsconfFiles(cfg.GetSsconfValues()) |
761 | d367b66c | Manuel Franceschini | |
762 | d367b66c | Manuel Franceschini | # set up the inter-node password and certificate
|
763 | d367b66c | Manuel Franceschini | _InitGanetiServerSetup(hostname.name) |
764 | 827f753e | Guido Trotter | |
765 | 952d7515 | Michael Hanselmann | logging.debug("Starting daemons")
|
766 | 7ede9c6a | Michael Hanselmann | result = utils.RunCmd([pathutils.DAEMON_UTIL, "start-all"])
|
767 | 952d7515 | Michael Hanselmann | if result.failed:
|
768 | 952d7515 | Michael Hanselmann | raise errors.OpExecError("Could not start daemons, command %s" |
769 | 952d7515 | Michael Hanselmann | " had exitcode %s and error %s" %
|
770 | 952d7515 | Michael Hanselmann | (result.cmd, result.exit_code, result.output)) |
771 | b3f1cf6f | Iustin Pop | |
772 | 3b6b6129 | Michael Hanselmann | _WaitForMasterDaemon() |
773 | b3f1cf6f | Iustin Pop | |
774 | b1b6ea87 | Iustin Pop | |
775 | 02f99608 | Oleksiy Mishchenko | def InitConfig(version, cluster_config, master_node_config, |
776 | 7ede9c6a | Michael Hanselmann | cfg_file=pathutils.CLUSTER_CONF_FILE): |
777 | 7b3a8fb5 | Iustin Pop | """Create the initial cluster configuration.
|
778 | 7b3a8fb5 | Iustin Pop |
|
779 | 7b3a8fb5 | Iustin Pop | It will contain the current node, which will also be the master
|
780 | 7b3a8fb5 | Iustin Pop | node, and no instances.
|
781 | 7b3a8fb5 | Iustin Pop |
|
782 | 7b3a8fb5 | Iustin Pop | @type version: int
|
783 | c41eea6e | Iustin Pop | @param version: configuration version
|
784 | c41eea6e | Iustin Pop | @type cluster_config: L{objects.Cluster}
|
785 | c41eea6e | Iustin Pop | @param cluster_config: cluster configuration
|
786 | c41eea6e | Iustin Pop | @type master_node_config: L{objects.Node}
|
787 | c41eea6e | Iustin Pop | @param master_node_config: master node configuration
|
788 | c41eea6e | Iustin Pop | @type cfg_file: string
|
789 | c41eea6e | Iustin Pop | @param cfg_file: configuration file path
|
790 | c41eea6e | Iustin Pop |
|
791 | 7b3a8fb5 | Iustin Pop | """
|
792 | 88b92fe3 | Guido Trotter | uuid_generator = config.TemporaryReservationManager() |
793 | 88b92fe3 | Guido Trotter | cluster_config.uuid = uuid_generator.Generate([], utils.NewUUID, |
794 | 88b92fe3 | Guido Trotter | _INITCONF_ECID) |
795 | 88b92fe3 | Guido Trotter | master_node_config.uuid = uuid_generator.Generate([], utils.NewUUID, |
796 | 88b92fe3 | Guido Trotter | _INITCONF_ECID) |
797 | 1c3231aa | Thomas Thrainer | cluster_config.master_node = master_node_config.uuid |
798 | 7b3a8fb5 | Iustin Pop | nodes = { |
799 | 1c3231aa | Thomas Thrainer | master_node_config.uuid: master_node_config, |
800 | 7b3a8fb5 | Iustin Pop | } |
801 | 88b92fe3 | Guido Trotter | default_nodegroup = objects.NodeGroup( |
802 | 88b92fe3 | Guido Trotter | uuid=uuid_generator.Generate([], utils.NewUUID, _INITCONF_ECID), |
803 | 75cf411a | Adeodato Simo | name=constants.INITIAL_NODE_GROUP_NAME, |
804 | 1c3231aa | Thomas Thrainer | members=[master_node_config.uuid], |
805 | 99ccf8b9 | Renรฉ Nussbaumer | diskparams={}, |
806 | 88b92fe3 | Guido Trotter | ) |
807 | 88b92fe3 | Guido Trotter | nodegroups = { |
808 | 88b92fe3 | Guido Trotter | default_nodegroup.uuid: default_nodegroup, |
809 | 88b92fe3 | Guido Trotter | } |
810 | d693c864 | Iustin Pop | now = time.time() |
811 | 7b3a8fb5 | Iustin Pop | config_data = objects.ConfigData(version=version, |
812 | 7b3a8fb5 | Iustin Pop | cluster=cluster_config, |
813 | 88b92fe3 | Guido Trotter | nodegroups=nodegroups, |
814 | 7b3a8fb5 | Iustin Pop | nodes=nodes, |
815 | 7b3a8fb5 | Iustin Pop | instances={}, |
816 | eaa4c57c | Dimitris Aragiorgis | networks={}, |
817 | d693c864 | Iustin Pop | serial_no=1,
|
818 | d693c864 | Iustin Pop | ctime=now, mtime=now) |
819 | a33848a5 | Guido Trotter | utils.WriteFile(cfg_file, |
820 | a33848a5 | Guido Trotter | data=serializer.Dump(config_data.ToDict()), |
821 | a33848a5 | Guido Trotter | mode=0600)
|
822 | 02f99608 | Oleksiy Mishchenko | |
823 | 02f99608 | Oleksiy Mishchenko | |
824 | 1c3231aa | Thomas Thrainer | def FinalizeClusterDestroy(master_uuid): |
825 | 140aa4a8 | Iustin Pop | """Execute the last steps of cluster destroy
|
826 | 140aa4a8 | Iustin Pop |
|
827 | 140aa4a8 | Iustin Pop | This function shuts down all the daemons, completing the destroy
|
828 | 140aa4a8 | Iustin Pop | begun in cmdlib.LUDestroyOpcode.
|
829 | 140aa4a8 | Iustin Pop |
|
830 | 140aa4a8 | Iustin Pop | """
|
831 | b989b9d9 | Ken Wehr | cfg = config.ConfigWriter() |
832 | b989b9d9 | Ken Wehr | modify_ssh_setup = cfg.GetClusterInfo().modify_ssh_setup |
833 | 7c74bbe0 | Andrea Spadaccini | runner = rpc.BootstrapRunner() |
834 | 7c74bbe0 | Andrea Spadaccini | |
835 | 1c3231aa | Thomas Thrainer | master_name = cfg.GetNodeName(master_uuid) |
836 | 1c3231aa | Thomas Thrainer | |
837 | f9d20654 | Andrea Spadaccini | master_params = cfg.GetMasterNetworkParameters() |
838 | 1c3231aa | Thomas Thrainer | master_params.uuid = master_uuid |
839 | 57c7bc57 | Andrea Spadaccini | ems = cfg.GetUseExternalMipScript() |
840 | 1c3231aa | Thomas Thrainer | result = runner.call_node_deactivate_master_ip(master_name, master_params, |
841 | 1c3231aa | Thomas Thrainer | ems) |
842 | c79198a0 | Andrea Spadaccini | |
843 | 7c74bbe0 | Andrea Spadaccini | msg = result.fail_msg |
844 | 7c74bbe0 | Andrea Spadaccini | if msg:
|
845 | 7c74bbe0 | Andrea Spadaccini | logging.warning("Could not disable the master IP: %s", msg)
|
846 | 7c74bbe0 | Andrea Spadaccini | |
847 | 1c3231aa | Thomas Thrainer | result = runner.call_node_stop_master(master_name) |
848 | 3cebe102 | Michael Hanselmann | msg = result.fail_msg |
849 | 6c00d19a | Iustin Pop | if msg:
|
850 | 099c52ad | Iustin Pop | logging.warning("Could not disable the master role: %s", msg)
|
851 | 7c74bbe0 | Andrea Spadaccini | |
852 | 1c3231aa | Thomas Thrainer | result = runner.call_node_leave_cluster(master_name, modify_ssh_setup) |
853 | 3cebe102 | Michael Hanselmann | msg = result.fail_msg |
854 | 0623d351 | Iustin Pop | if msg:
|
855 | 0623d351 | Iustin Pop | logging.warning("Could not shutdown the node daemon and cleanup"
|
856 | 0623d351 | Iustin Pop | " the node: %s", msg)
|
857 | 140aa4a8 | Iustin Pop | |
858 | 140aa4a8 | Iustin Pop | |
859 | 7b8ba235 | Michael Hanselmann | def SetupNodeDaemon(opts, cluster_name, node): |
860 | 827f753e | Guido Trotter | """Add a node to the cluster.
|
861 | 827f753e | Guido Trotter |
|
862 | b1b6ea87 | Iustin Pop | This function must be called before the actual opcode, and will ssh
|
863 | b1b6ea87 | Iustin Pop | to the remote node, copy the needed files, and start ganeti-noded,
|
864 | b1b6ea87 | Iustin Pop | allowing the master to do the rest via normal rpc calls.
|
865 | 827f753e | Guido Trotter |
|
866 | 87622829 | Iustin Pop | @param cluster_name: the cluster name
|
867 | 87622829 | Iustin Pop | @param node: the name of the new node
|
868 | 827f753e | Guido Trotter |
|
869 | 827f753e | Guido Trotter | """
|
870 | 7b8ba235 | Michael Hanselmann | data = { |
871 | 7b8ba235 | Michael Hanselmann | constants.NDS_CLUSTER_NAME: cluster_name, |
872 | 7b8ba235 | Michael Hanselmann | constants.NDS_NODE_DAEMON_CERTIFICATE: |
873 | 7b8ba235 | Michael Hanselmann | utils.ReadFile(pathutils.NODED_CERT_FILE), |
874 | 7b8ba235 | Michael Hanselmann | constants.NDS_SSCONF: ssconf.SimpleStore().ReadAll(), |
875 | 7b8ba235 | Michael Hanselmann | constants.NDS_START_NODE_DAEMON: True,
|
876 | 7b8ba235 | Michael Hanselmann | } |
877 | 7b8ba235 | Michael Hanselmann | |
878 | 7b8ba235 | Michael Hanselmann | RunNodeSetupCmd(cluster_name, node, pathutils.NODE_DAEMON_SETUP, |
879 | 7b8ba235 | Michael Hanselmann | opts.debug, opts.verbose, |
880 | 7b8ba235 | Michael Hanselmann | True, opts.ssh_key_check, opts.ssh_key_check, data)
|
881 | 827f753e | Guido Trotter | |
882 | 5627f375 | Michael Hanselmann | _WaitForNodeDaemon(node) |
883 | 5627f375 | Michael Hanselmann | |
884 | b1b6ea87 | Iustin Pop | |
885 | 8e2524c3 | Guido Trotter | def MasterFailover(no_voting=False): |
886 | b1b6ea87 | Iustin Pop | """Failover the master node.
|
887 | b1b6ea87 | Iustin Pop |
|
888 | b1b6ea87 | Iustin Pop | This checks that we are not already the master, and will cause the
|
889 | b1b6ea87 | Iustin Pop | current master to cease being master, and the non-master to become
|
890 | b1b6ea87 | Iustin Pop | new master.
|
891 | b1b6ea87 | Iustin Pop |
|
892 | 8e2524c3 | Guido Trotter | @type no_voting: boolean
|
893 | 8e2524c3 | Guido Trotter | @param no_voting: force the operation without remote nodes agreement
|
894 | 8e2524c3 | Guido Trotter | (dangerous)
|
895 | 8e2524c3 | Guido Trotter |
|
896 | b1b6ea87 | Iustin Pop | """
|
897 | 8135a2db | Iustin Pop | sstore = ssconf.SimpleStore() |
898 | b1b6ea87 | Iustin Pop | |
899 | 8135a2db | Iustin Pop | old_master, new_master = ssconf.GetMasterAndMyself(sstore) |
900 | 1c3231aa | Thomas Thrainer | node_names = sstore.GetNodeList() |
901 | 8135a2db | Iustin Pop | mc_list = sstore.GetMasterCandidates() |
902 | b1b6ea87 | Iustin Pop | |
903 | b1b6ea87 | Iustin Pop | if old_master == new_master:
|
904 | b1b6ea87 | Iustin Pop | raise errors.OpPrereqError("This commands must be run on the node" |
905 | b1b6ea87 | Iustin Pop | " where you want the new master to be."
|
906 | b1b6ea87 | Iustin Pop | " %s is already the master" %
|
907 | debac808 | Iustin Pop | old_master, errors.ECODE_INVAL) |
908 | d5927e48 | Iustin Pop | |
909 | 8135a2db | Iustin Pop | if new_master not in mc_list: |
910 | 8135a2db | Iustin Pop | mc_no_master = [name for name in mc_list if name != old_master] |
911 | 8135a2db | Iustin Pop | raise errors.OpPrereqError("This node is not among the nodes marked" |
912 | 8135a2db | Iustin Pop | " as master candidates. Only these nodes"
|
913 | 8135a2db | Iustin Pop | " can become masters. Current list of"
|
914 | 8135a2db | Iustin Pop | " master candidates is:\n"
|
915 | 3ccb3a64 | Michael Hanselmann | "%s" % ("\n".join(mc_no_master)), |
916 | debac808 | Iustin Pop | errors.ECODE_STATE) |
917 | 8135a2db | Iustin Pop | |
918 | 8e2524c3 | Guido Trotter | if not no_voting: |
919 | 1c3231aa | Thomas Thrainer | vote_list = GatherMasterVotes(node_names) |
920 | 8e2524c3 | Guido Trotter | |
921 | 8e2524c3 | Guido Trotter | if vote_list:
|
922 | 8e2524c3 | Guido Trotter | voted_master = vote_list[0][0] |
923 | 8e2524c3 | Guido Trotter | if voted_master is None: |
924 | 8e2524c3 | Guido Trotter | raise errors.OpPrereqError("Cluster is inconsistent, most nodes did" |
925 | debac808 | Iustin Pop | " not respond.", errors.ECODE_ENVIRON)
|
926 | 8e2524c3 | Guido Trotter | elif voted_master != old_master:
|
927 | 8e2524c3 | Guido Trotter | raise errors.OpPrereqError("I have a wrong configuration, I believe" |
928 | 8e2524c3 | Guido Trotter | " the master is %s but the other nodes"
|
929 | 8e2524c3 | Guido Trotter | " voted %s. Please resync the configuration"
|
930 | 8e2524c3 | Guido Trotter | " of this node." %
|
931 | debac808 | Iustin Pop | (old_master, voted_master), |
932 | debac808 | Iustin Pop | errors.ECODE_STATE) |
933 | b1b6ea87 | Iustin Pop | # end checks
|
934 | b1b6ea87 | Iustin Pop | |
935 | b1b6ea87 | Iustin Pop | rcode = 0
|
936 | b1b6ea87 | Iustin Pop | |
937 | d5927e48 | Iustin Pop | logging.info("Setting master to %s, old master: %s", new_master, old_master)
|
938 | b1b6ea87 | Iustin Pop | |
939 | 21004460 | Iustin Pop | try:
|
940 | 21004460 | Iustin Pop | # instantiate a real config writer, as we now know we have the
|
941 | 21004460 | Iustin Pop | # configuration data
|
942 | eb180fe2 | Iustin Pop | cfg = config.ConfigWriter(accept_foreign=True)
|
943 | 21004460 | Iustin Pop | |
944 | 1c3231aa | Thomas Thrainer | old_master_node = cfg.GetNodeInfoByName(old_master) |
945 | 1c3231aa | Thomas Thrainer | if old_master_node is None: |
946 | 1c3231aa | Thomas Thrainer | raise errors.OpPrereqError("Could not find old master node '%s' in" |
947 | 1c3231aa | Thomas Thrainer | " cluster configuration." % old_master,
|
948 | 1c3231aa | Thomas Thrainer | errors.ECODE_NOENT) |
949 | 1c3231aa | Thomas Thrainer | |
950 | 21004460 | Iustin Pop | cluster_info = cfg.GetClusterInfo() |
951 | 1c3231aa | Thomas Thrainer | new_master_node = cfg.GetNodeInfoByName(new_master) |
952 | 1c3231aa | Thomas Thrainer | if new_master_node is None: |
953 | 1c3231aa | Thomas Thrainer | raise errors.OpPrereqError("Could not find new master node '%s' in" |
954 | 1c3231aa | Thomas Thrainer | " cluster configuration." % new_master,
|
955 | 1c3231aa | Thomas Thrainer | errors.ECODE_NOENT) |
956 | 1c3231aa | Thomas Thrainer | |
957 | 1c3231aa | Thomas Thrainer | cluster_info.master_node = new_master_node.uuid |
958 | 21004460 | Iustin Pop | # this will also regenerate the ssconf files, since we updated the
|
959 | 21004460 | Iustin Pop | # cluster info
|
960 | 21004460 | Iustin Pop | cfg.Update(cluster_info, logging.error) |
961 | 21004460 | Iustin Pop | except errors.ConfigurationError, err:
|
962 | 21004460 | Iustin Pop | logging.error("Error while trying to set the new master: %s",
|
963 | 21004460 | Iustin Pop | str(err))
|
964 | 21004460 | Iustin Pop | return 1 |
965 | 21004460 | Iustin Pop | |
966 | 21004460 | Iustin Pop | # if cfg.Update worked, then it means the old master daemon won't be
|
967 | 21004460 | Iustin Pop | # able now to write its own config file (we rely on locking in both
|
968 | 21004460 | Iustin Pop | # backend.UploadFile() and ConfigWriter._Write(); hence the next
|
969 | 21004460 | Iustin Pop | # step is to kill the old master
|
970 | 21004460 | Iustin Pop | |
971 | 21004460 | Iustin Pop | logging.info("Stopping the master daemon on node %s", old_master)
|
972 | 21004460 | Iustin Pop | |
973 | 7c74bbe0 | Andrea Spadaccini | runner = rpc.BootstrapRunner() |
974 | f9d20654 | Andrea Spadaccini | master_params = cfg.GetMasterNetworkParameters() |
975 | 1c3231aa | Thomas Thrainer | master_params.uuid = old_master_node.uuid |
976 | 57c7bc57 | Andrea Spadaccini | ems = cfg.GetUseExternalMipScript() |
977 | 1c3231aa | Thomas Thrainer | result = runner.call_node_deactivate_master_ip(old_master, |
978 | 57c7bc57 | Andrea Spadaccini | master_params, ems) |
979 | c79198a0 | Andrea Spadaccini | |
980 | 7c74bbe0 | Andrea Spadaccini | msg = result.fail_msg |
981 | 7c74bbe0 | Andrea Spadaccini | if msg:
|
982 | 7c74bbe0 | Andrea Spadaccini | logging.warning("Could not disable the master IP: %s", msg)
|
983 | 7c74bbe0 | Andrea Spadaccini | |
984 | 7c74bbe0 | Andrea Spadaccini | result = runner.call_node_stop_master(old_master) |
985 | 3cebe102 | Michael Hanselmann | msg = result.fail_msg |
986 | 6c00d19a | Iustin Pop | if msg:
|
987 | d5927e48 | Iustin Pop | logging.error("Could not disable the master role on the old master"
|
988 | 5ae4945a | Iustin Pop | " %s, please disable manually: %s", old_master, msg)
|
989 | b1b6ea87 | Iustin Pop | |
990 | 21004460 | Iustin Pop | logging.info("Checking master IP non-reachability...")
|
991 | 21004460 | Iustin Pop | |
992 | 425f0f54 | Iustin Pop | master_ip = sstore.GetMasterIP() |
993 | 425f0f54 | Iustin Pop | total_timeout = 30
|
994 | e687ec01 | Michael Hanselmann | |
995 | d23ef431 | Michael Hanselmann | # Here we have a phase where no master should be running
|
996 | 425f0f54 | Iustin Pop | def _check_ip(): |
997 | a744b676 | Manuel Franceschini | if netutils.TcpPing(master_ip, constants.DEFAULT_NODED_PORT):
|
998 | 425f0f54 | Iustin Pop | raise utils.RetryAgain()
|
999 | 425f0f54 | Iustin Pop | |
1000 | 425f0f54 | Iustin Pop | try:
|
1001 | 425f0f54 | Iustin Pop | utils.Retry(_check_ip, (1, 1.5, 5), total_timeout) |
1002 | 425f0f54 | Iustin Pop | except utils.RetryTimeout:
|
1003 | 425f0f54 | Iustin Pop | logging.warning("The master IP is still reachable after %s seconds,"
|
1004 | 425f0f54 | Iustin Pop | " continuing but activating the master on the current"
|
1005 | 425f0f54 | Iustin Pop | " node will probably fail", total_timeout)
|
1006 | b1b6ea87 | Iustin Pop | |
1007 | ff699aa9 | Michael Hanselmann | if jstore.CheckDrainFlag():
|
1008 | ff699aa9 | Michael Hanselmann | logging.info("Undraining job queue")
|
1009 | ff699aa9 | Michael Hanselmann | jstore.SetDrainFlag(False)
|
1010 | ff699aa9 | Michael Hanselmann | |
1011 | 21004460 | Iustin Pop | logging.info("Starting the master daemons on the new master")
|
1012 | d5927e48 | Iustin Pop | |
1013 | db04ce5d | Michael Hanselmann | result = rpc.BootstrapRunner().call_node_start_master_daemons(new_master, |
1014 | db04ce5d | Michael Hanselmann | no_voting) |
1015 | 3cebe102 | Michael Hanselmann | msg = result.fail_msg |
1016 | b726aff0 | Iustin Pop | if msg:
|
1017 | d5927e48 | Iustin Pop | logging.error("Could not start the master role on the new master"
|
1018 | b726aff0 | Iustin Pop | " %s, please check: %s", new_master, msg)
|
1019 | b1b6ea87 | Iustin Pop | rcode = 1
|
1020 | b1b6ea87 | Iustin Pop | |
1021 | 21004460 | Iustin Pop | logging.info("Master failed over from %s to %s", old_master, new_master)
|
1022 | b1b6ea87 | Iustin Pop | return rcode
|
1023 | d7cdb55d | Iustin Pop | |
1024 | d7cdb55d | Iustin Pop | |
1025 | 8eb148ae | Iustin Pop | def GetMaster(): |
1026 | 8eb148ae | Iustin Pop | """Returns the current master node.
|
1027 | 8eb148ae | Iustin Pop |
|
1028 | 8eb148ae | Iustin Pop | This is a separate function in bootstrap since it's needed by
|
1029 | 8eb148ae | Iustin Pop | gnt-cluster, and instead of importing directly ssconf, it's better
|
1030 | 8eb148ae | Iustin Pop | to abstract it in bootstrap, where we do use ssconf in other
|
1031 | 8eb148ae | Iustin Pop | functions too.
|
1032 | 8eb148ae | Iustin Pop |
|
1033 | 8eb148ae | Iustin Pop | """
|
1034 | 8eb148ae | Iustin Pop | sstore = ssconf.SimpleStore() |
1035 | 8eb148ae | Iustin Pop | |
1036 | 8eb148ae | Iustin Pop | old_master, _ = ssconf.GetMasterAndMyself(sstore) |
1037 | 8eb148ae | Iustin Pop | |
1038 | 8eb148ae | Iustin Pop | return old_master
|
1039 | 8eb148ae | Iustin Pop | |
1040 | 8eb148ae | Iustin Pop | |
1041 | 1c3231aa | Thomas Thrainer | def GatherMasterVotes(node_names): |
1042 | d7cdb55d | Iustin Pop | """Check the agreement on who is the master.
|
1043 | d7cdb55d | Iustin Pop |
|
1044 | d7cdb55d | Iustin Pop | This function will return a list of (node, number of votes), ordered
|
1045 | d7cdb55d | Iustin Pop | by the number of votes. Errors will be denoted by the key 'None'.
|
1046 | d7cdb55d | Iustin Pop |
|
1047 | d7cdb55d | Iustin Pop | Note that the sum of votes is the number of nodes this machine
|
1048 | d7cdb55d | Iustin Pop | knows, whereas the number of entries in the list could be different
|
1049 | d7cdb55d | Iustin Pop | (if some nodes vote for another master).
|
1050 | d7cdb55d | Iustin Pop |
|
1051 | d7cdb55d | Iustin Pop | We remove ourselves from the list since we know that (bugs aside)
|
1052 | d7cdb55d | Iustin Pop | since we use the same source for configuration information for both
|
1053 | d7cdb55d | Iustin Pop | backend and boostrap, we'll always vote for ourselves.
|
1054 | d7cdb55d | Iustin Pop |
|
1055 | 1c3231aa | Thomas Thrainer | @type node_names: list
|
1056 | 1c3231aa | Thomas Thrainer | @param node_names: the list of nodes to query for master info; the current
|
1057 | 5bbd3f7f | Michael Hanselmann | node will be removed if it is in the list
|
1058 | d7cdb55d | Iustin Pop | @rtype: list
|
1059 | d7cdb55d | Iustin Pop | @return: list of (node, votes)
|
1060 | d7cdb55d | Iustin Pop |
|
1061 | d7cdb55d | Iustin Pop | """
|
1062 | b705c7a6 | Manuel Franceschini | myself = netutils.Hostname.GetSysName() |
1063 | d7cdb55d | Iustin Pop | try:
|
1064 | 1c3231aa | Thomas Thrainer | node_names.remove(myself) |
1065 | d7cdb55d | Iustin Pop | except ValueError: |
1066 | d7cdb55d | Iustin Pop | pass
|
1067 | 1c3231aa | Thomas Thrainer | if not node_names: |
1068 | d7cdb55d | Iustin Pop | # no nodes left (eventually after removing myself)
|
1069 | d7cdb55d | Iustin Pop | return []
|
1070 | 1c3231aa | Thomas Thrainer | results = rpc.BootstrapRunner().call_master_info(node_names) |
1071 | d7cdb55d | Iustin Pop | if not isinstance(results, dict): |
1072 | d7cdb55d | Iustin Pop | # this should not happen (unless internal error in rpc)
|
1073 | d7cdb55d | Iustin Pop | logging.critical("Can't complete rpc call, aborting master startup")
|
1074 | 1c3231aa | Thomas Thrainer | return [(None, len(node_names))] |
1075 | d7cdb55d | Iustin Pop | votes = {} |
1076 | 1c3231aa | Thomas Thrainer | for node_name in results: |
1077 | 1c3231aa | Thomas Thrainer | nres = results[node_name] |
1078 | 2a52a064 | Iustin Pop | data = nres.payload |
1079 | 3cebe102 | Michael Hanselmann | msg = nres.fail_msg |
1080 | 2a52a064 | Iustin Pop | fail = False
|
1081 | 2a52a064 | Iustin Pop | if msg:
|
1082 | 1c3231aa | Thomas Thrainer | logging.warning("Error contacting node %s: %s", node_name, msg)
|
1083 | 2a52a064 | Iustin Pop | fail = True
|
1084 | 909b3a0e | Andrea Spadaccini | # for now we accept both length 3, 4 and 5 (data[3] is primary ip version
|
1085 | 909b3a0e | Andrea Spadaccini | # and data[4] is the master netmask)
|
1086 | 2a52a064 | Iustin Pop | elif not isinstance(data, (tuple, list)) or len(data) < 3: |
1087 | 1c3231aa | Thomas Thrainer | logging.warning("Invalid data received from node %s: %s",
|
1088 | 1c3231aa | Thomas Thrainer | node_name, data) |
1089 | 2a52a064 | Iustin Pop | fail = True
|
1090 | 2a52a064 | Iustin Pop | if fail:
|
1091 | d7cdb55d | Iustin Pop | if None not in votes: |
1092 | d7cdb55d | Iustin Pop | votes[None] = 0 |
1093 | d7cdb55d | Iustin Pop | votes[None] += 1 |
1094 | d7cdb55d | Iustin Pop | continue
|
1095 | 781de953 | Iustin Pop | master_node = data[2]
|
1096 | d7cdb55d | Iustin Pop | if master_node not in votes: |
1097 | d7cdb55d | Iustin Pop | votes[master_node] = 0
|
1098 | d7cdb55d | Iustin Pop | votes[master_node] += 1
|
1099 | d7cdb55d | Iustin Pop | |
1100 | d7cdb55d | Iustin Pop | vote_list = [v for v in votes.items()] |
1101 | d7cdb55d | Iustin Pop | # sort first on number of votes then on name, since we want None
|
1102 | d7cdb55d | Iustin Pop | # sorted later if we have the half of the nodes not responding, and
|
1103 | d7cdb55d | Iustin Pop | # half voting all for the same master
|
1104 | d7cdb55d | Iustin Pop | vote_list.sort(key=lambda x: (x[1], x[0]), reverse=True) |
1105 | d7cdb55d | Iustin Pop | |
1106 | d7cdb55d | Iustin Pop | return vote_list |