104 Commits

Author SHA1 Message Date
Zuul
173f1a99db Merge "Use UUIDs of storage devices in fstab" 2019-05-24 08:46:17 +00:00
tpsilva
dc63810cb4 Fix import errors on Nagios check file
After changing the charm runtime to Python 3, some imports are failing
on check_swift_storage.py. This can be fixed by explicitly imporgin the
modules inside the package, instead of just importing the package.

Change-Id: I746071042b669a1725744d4e32ea733eb40b309a
Closes-bug: #1822334
2019-03-29 13:15:10 -03:00
Tytus Kurek
edd00bee63 Use UUIDs of storage devices in fstab
This patchset implements a logic to put UUIDS of storage devices in the
fstab instead of device names.

Change-Id: I2170c54b25ac9b3faacb3fd0b2889d86c531395f
Closes-Bug: 1729478
2019-03-13 21:19:14 +00:00
Alex Kavanagh
fc81200315 Upgrade the charm to py3 runtime
Change-Id: I98f4e6664080407a045ca5e76db59d46ffa9c38a
2018-10-24 14:57:05 +01:00
Andrew McLeod
0598fd20fb Add nofail to fstab options for loop dev
Some machines will not boot if nofail is excluded

Change-Id: Ib978709943c4aec8f7d405c0b71e1c4d81f3764c
Closes-Bug: 1768666
2018-05-21 10:43:42 -06:00
Zuul
b03a8bc5bd Merge "Add support for block device encryption" 2018-05-15 09:56:23 +00:00
Zuul
de60721367 Merge "Updated nrpe check for swift replication lag >1 day" 2018-05-11 09:10:19 +00:00
Zuul
5a7c46f897 Merge "fix a typo" 2018-05-09 12:58:28 +00:00
Zuul
2f60ad0e98 Merge "Using assertIsNone() instead of assertEqual(None)" 2018-05-09 12:51:54 +00:00
James Page
591c084532 Add support for block device encryption
Add new secrets-storage relation to vault, supporting the
use of block device encryption using dm-crypt/vaultlocker.

Prepared devices are now recorded in the local unit kv
store; this information is used to provide a list of
configured block devices to the swift-proxy charm,
rather than the previous best guess provided by
determine_block_devices.  This allows us to use the
dm-crypt device name, rather than the underlying
block device.

Encrypted block devices are unlocked on boot using
vaultlocker-decrypt systemd units (enabled by vaultlocker);
/etc/fstab entries for such devices make use of a
x-systemd.requires option to ensure that the block device
is unlocked prior to attempting to mount it.

Add new storage binding to allow charm to be used with
Juju storage.

Add new ephemeral-unmount configuration option to allow
cloud ephemeral storage to be used for testing purposes;
update functional testing to use this option.  The behaviour
of 'overwrite' was changed to accomodate the use of
encrypted block devices.

Change-Id: I9b3f8cd2de412ee96e0139dba4d4abdf998ecaf2
2018-05-08 12:52:37 +01:00
David Ames
18d0a891db Allow GRE traffic in converged architecture
In a converged architecture with storage and compute on the same
host, UFW can get in the way of tunneled traffic interpreting it as
INVALID. UFW makes solving this more difficult than it needs to be.
See http://northernmost.org/blog/gre-tunnels-and-ufw/index.html for
context.

This change updates /etc/ufw/before.rules to add GRE as an allowed
input.

Also, guarantee ufw is installed for LP #1763716

Please review and merge charm-helpers first:
https://github.com/juju/charm-helpers/pull/170

Change-Id: I789854c33e3af12f7412633dbf7c921beb0ed2b5
Closes-Bug: #1757564
Closes-Bug: #1763716
2018-05-03 21:42:46 +02:00
wangqi
f9a6b36c93 Using assertIsNone() instead of assertEqual(None)
Following OpenStack Style Guidelines:
[1] http://docs.openstack.org/developer/hacking/#unit-tests-and-assertraises
[H203] Unit test assertions tend to give better messages for more specific
assertions. As a result, assertIsNone(...) is preferred over
assertEqual(None, ...) and assertIs(..., None)

Change-Id: Ib5dcf2f389dd76f99d87ad22268695f2a702e6b3
2018-04-20 07:33:26 +00:00
Drew Freiberger
9a5314afad Updated nrpe check for swift replication lag >1 day
Change-Id: Ib1104ea86290cf271e63d1a5aa81e503ed5965c3
Closes-Bug: 1758119
2018-04-11 14:53:12 -05:00
Liam Young
6346a7458b Use the loop device in fstab instead of image file
When adding an fstab entry for a loopback device use the explicit
loopback device name rather than the source image file. This prevents
a new loopback device being created implitcitly when mounting the
image.

The unit tests needed updating to reflect that the loopback
device name is used when creating mountpoint names rather than than
the name of the image file. This was pre-existing behaviour.

Change-Id: Ide074310bf7121f1179e0b5237dff6f3da88e24e
Closes-Bug: #1762390
2018-04-10 12:58:05 +00:00
Liam Young
f75bd9762a Fix broken fstab entry
Whitespace between the fstab option is not valid, remove it.

Change-Id: I1be789acc7bf92811f8d4e2c0f0661ebf3be1678
Closes-Bug: #1762105
2018-04-10 11:25:14 +00:00
wangqi
1cc0e5dec5 fix a typo
Change-Id: I1581f783a5fab546019e60b35c1df43a1403cd66
2018-04-02 08:16:47 +00:00
Felipe Reyes
1d28ceb648 Resolve hostnames if needed to allow access in ufw
In some cases juju 1.25 (with maas 1.9) may return a hostname in the
private-address field breaking the assumption that private-address will
always be an IP address. This patch uses get_host_ip() to assure an IP
address is given to ufw.

Change-Id: Ib99852c645517cf316adcd02d04428b248fc9724
Closes-Bug: 1747516
2018-03-05 18:16:57 -03:00
Frode Nordahl
b819bde429 Revert "Resolve hostnames if needed to allow access in ufw"
We need a new proposal that uses get_host_ip from charmhelpers.contrib.network.ip

Reference: https://review.openstack.org/#/c/542381/

This reverts commit 4896ac5b5b98f66cfe79c3945680ac0ac5dbb2bf.

Change-Id: Idd16369be776a10ac6332d7d8b2ce65f9f1ad972
2018-03-01 15:19:49 +00:00
Felipe Reyes
4896ac5b5b Resolve hostnames if needed to allow access in ufw
In some cases juju 1.25 (with maas 1.9) may return a hostname in the
private-address field breaking the assumption that private-address will
always be an IP address. This patch uses socket.getaddrinfo() to assure
an IP address is given to ufw.

Change-Id: I99b0110beed6075164eb549ec2433071af699c04
Closes-Bug: 1747516
2018-02-05 18:32:52 -03:00
Ryan Beisner
af2eaad19b Sync charm-helpers
Notable issues resolved:

openstack_upgrade_available() broken for swift
https://bugs.launchpad.net/charm-swift-proxy/+bug/1743847

haproxy context doesn't consider bindings
https://bugs.launchpad.net/charm-helpers/+bug/1735421

regression in haproxy check
https://bugs.launchpad.net/charm-helpers/+bug/1743287

Change-Id: Ie6b66f56614d81c600b66bfe00cf9b9bb462a20c
2018-01-19 16:13:12 +02:00
David Ames
5368af6302 Swift storage ACLs
Ensure that only the swift-proxy units and swift-storage peers have
access to direct communication with swift storage daemons.

Charm-helpers sync to include ufw module and the ingress_address and
iter_units_for_relation_name functions.

Please review and merge first:
https://github.com/juju/charm-helpers/pull/35

Closes-Bug: #1727463

Change-Id: Id5677edbc40b0b891cbe66867d39d076a94c5436
2017-11-07 10:24:53 -08:00
Zuul
f953a6aa09 Merge "Add statsd metrics support to the swift-storage charm" 2017-11-05 05:27:08 +00:00
James Hebden
0876b4fb73 Add statsd metrics support to the swift-storage charm
By default, statsd metrics can be sent by the swift account,
container and object storage services for diagnostic and
monitoring purposes, but are disabled by default. This change exposes
charm config settings that allow it to be enabled by setting
'statsd_host' to a non-empty value. 'statsd_port' and
'statsd_sample_rate' are also supported for changing the destination
port and rate at which metrics are collected.

Closes-Bug: #1729770

Change-Id: If1bf3ced8a9ed07af81f352eb0263659d147e3aa
2017-11-05 15:23:38 +11:00
James Page
b32f68af0f Add network-space support for swift-storage relation
Resolve correct private-address for use on the swift-storage
relation, supporting 'prefer-ipv6' as well as Juju 2.0 network
spaces.

Change-Id: I3ee111c6abdd028c2c29e80dceb99178443da45a
Closes-Bug: 1697491
2017-09-29 11:33:48 +01:00
Edward Hope-Morley
656e79da18 Catch blkid error when device is not yet formatted
When a new device is added to the ring we first try to
identify whether the device is already in the ring by
polling for an fs uuid. If the device has never been
used this is expected to fail so lets catch the error.

Also fixes log message.

Change-Id: I20354dedfa27a6b8dec92828cabb50a20d0d8838
Closes-Bug: 1567198
2017-09-14 13:22:25 -06:00
zhangyangyang
f87d83b1ab Change assert(Not)Equals to assert(Not)Equal
According to http://docs.python.org/2/library/unittest.html
assert(Not)Equals is a deprecated alias of assert(Not)Equal.

Change-Id: I4b9e966f4c7cd3df6440f38b56785a38a812e002
Closes-Bug: #1329757
2017-09-11 19:19:52 +08:00
Jenkins
56cf0e8210 Merge "Support null values on recon/replication module" 2017-08-16 16:32:32 +00:00
Alvaro Uria
d59759259e Support null values on recon/replication module
Update on nrpe check check_swift_storage:
 * Refactor check_replication function
 * Raise STATUS_CRIT on null values
 * Clean code per flake8 and previous review
 * Add unit_test for nrpe check check_swift_storage.py

Change-Id: Ie076b8ea56f66c1e15a9bfe2e400b49f968fa4ed
Closes-Bug: #1673441
Signed-off-by: Alvaro Uria <alvaro.uria@canonical.com>
2017-08-11 19:24:24 -07:00
Xav Paice
18419a87c5 Add object-rsync-timeout option
Adds the rsync_timeout option to to object-server.conf, so we can adjust
it away from the default of 900s.

If there are a number of large partitions needing replication,
occasionally one needs to adjust the timeout in order to allow the rsync
to complete rather than timeout and retry.

Change-Id: I2d895741cb0528836a675deb6399005a5bf59ab5
Closes-bug: 1702039
2017-07-04 07:57:22 +12:00
Billy Olsen
d6061caa2c Only change owner/permissions of new devices
Do not change owner and permissions of already existing
devices in the setup_storage() function as this runs
during every config-changed hook invocation.

Change-Id: I21f23aee34d315ccb4df303527b4d791fc043f58
Closes-Bug: #1676728
2017-06-08 16:03:16 -07:00
Chris MacNaughton
47a4ac6e48 Remove /srv/node from updatedb
This stops updatedb from indexing the storage locations

Change-Id: I6ca6b8667fb06d3b52cedd151531fc0033cf2526
Closes-bug: 1520226
2017-01-25 09:21:31 -05:00
Luong Anh Tuan
bca8efdcd5 Replace assertEquals with assertEqual
The method assertEquals has been deprecated since python 2.7.
http://docs.python.org/2/library/unittest.html#deprecated-aliases

Also in Python 3, a deprecated warning is raised when using assertEquals
therefore we should use assertEqual instead.

Change-Id: If7a404da609eb3cae22627f3b9d71292b8865674
Closes-Bug: #1218185
2016-11-22 10:23:25 +07:00
vnathan
b268ef82fa Fixed handling duplicate block devices specified in config
Change-Id: I5c96c49d47b762fecc16c8700ef6ed65bcd39bf5
closes-bug: 1582317
2016-11-14 22:13:57 +05:30
James Page
cae0a2c4f5 Add support for application version
Juju 2.0 provides support for display of the version of
an application deployed by a charm in juju status.

Insert the os_application_version_set function into the
existing assess_status function - this gets called after
all hook executions, and periodically after that, so any
changes in package versions due to normal system updates
will also be reflected in the status output.

This review also includes a resync of charm-helpers to
pickup hookenv and contrib.openstack support for this
feature.

Change-Id: I75009a66ce9c9d43e234f9c5acbb185ac4a66ba5
2016-09-20 13:32:28 +01:00
James Page
ab35249f38 Re-license charm as Apache-2.0
All contributions to this charm where made under Canonical
copyright; switch to Apache-2.0 license as agreed so we
can move forward with official project status.

Change-Id: I97206ee8be76220cb0937a09be3230432e04535a
2016-07-01 18:15:00 +01:00
James Page
fc1943af8f Use JUJU_MODEL_UUID for Juju 2.0
Juju 2.0 renames the environment variable JUJU_ENV_UUID
to JUJU_MODEL_UUID; use this environment variable as a
fallback if JUJU_ENV_UUID is not set to support Juju 2.0,
whilst continuing to provide support for Juju < 2.0.

Change-Id: I0e9ebbe59032e3d15864ee1f9bd49b404b339a3b
Closes-Bug: 1572575
2016-05-24 15:19:44 +01:00
Chris Glass
30c3fb9353 Resolve links before using path as block device
If the charm code is passed symlinks to block devices (as is often the
case with newer MAAS substrate versions), resolve links before
attempting to use the block device for storage.

Charmhelpers were updated as well.

Testing done:

- Unit tests pass
- Tests pass
- Multiple Openstack Autopilot deployments pass

Change-Id: If966239502d0752c86e46f3f0aee96f43828aa08
Closes-Bug: 1577408
Signed-off-by: Chris Glass <chris.glass@canonical.com>
2016-05-06 15:25:34 +00:00
Edward Hope-Morley
6ab28b3639 Add hardening support
Add charmhelpers.contrib.hardening and calls to install,
config-changed, upgrade-charm and update-status hooks.
Also add new config option to allow one or more hardening
modules to be applied at runtime.

Change-Id: If0d1e10b58ed506e0aca659f30120b8d5c96c04f
2016-03-24 11:11:58 +00:00
Edward Hope-Morley
e7bf2f910e Allow devices to be added post-install
Track devices that have been added to the ring and allow
devices to be added to the ring post-install (currently
only allowed within the install hook). Devices added to
the ring prior to this patch existing will be migrated
to the tracking store of devices to avoid conflicts.

Change-Id: Id268dc6369041a4d2db6f30a997dfa0c0d73b93f
Closes-Bug: 1383390
2016-03-07 22:25:29 +00:00
James Page
2ceda02a08 Resync charm-helpers
Resolve single unit deployment failure with default configuration;
update unit tests to ensure that mkdir is called for /srv/node.

Change-Id: Id5518a2144ec3bdc6341f6dfc85835ae342f490e
2016-03-03 11:50:13 +00:00
James Page
5dd12f71d8 Tidy lint 2016-02-09 10:29:16 +00:00
James Page
9d042778d2 Resync helpers, refactor code to use cpu calcs from charmhelpers 2016-01-30 13:37:50 +01:00
billy.olsen@canonical.com
aaf6c037bc [niedbalski, r=freyes,billy-olsen] Fix fstab entry for loopback devices.
Closes-Bug: 1510666
2015-11-16 13:56:57 -07:00
Jorge Niedbalski
2e98fc7d8f Added unit tests 2015-11-09 11:35:46 -03:00
Corey Bryant
9b178924d7 [james-pages,r=corey.bryant] Add tox support for lint and unit tests. 2015-11-03 17:08:12 +00:00
James Page
f3bebc3fc4 Add tox support 2015-11-03 14:03:25 +00:00
Corey Bryant
acd500f953 [corey.bryant,trivial] Revert "Enable multiple devices per node when config changed" 2015-10-15 15:05:42 -04:00
David Ames
0802f55959 Update swift-storage relation when block-device changes. Associated with fix for LP Bug#1479938 2015-10-13 12:05:02 -07:00
David Ames
902fcd0251 [corey.bryant, r=thedac] Workload Status 2015-10-13 10:18:25 -07:00
Corey Bryant
dc86794721 Unit test update 2015-10-13 11:22:28 +00:00