a239b29baf
This commit uses a keepalived role, available in ansible galaxy, to configure keepalived for haproxy Keepalived makes the haproxy truely HA, by having haproxy's VIP highly available between the hosts defined in the inventory. The keepalived role configuration is fully documented on the upstream role. To configure keepalived on your host, you only have to give it a variable (dict). A template handles the generation of the configuration of keepalived. By default, the variable files defined in vars/configs/ are enough to have a keepalived working for haproxy, with a master-backup configuration. You can define other variable files by setting haproxy_keepalived_(master|backup)_vars in your user_variables. This should point to a "variable template" file like the one you can find in vars/configs/* The haproxy playbook has been changed to rely on the dynamic generation script. It will use the env.d to have haproxy hosts. The first host from the generated inventory will be considered as master, while the others are slaves. The keepalived role will only run if more than haproxy host is found in the inventory. This behaviour can be changed and keepalived can be disabled by the variable: haproxy_use_keepalived. The implemented variables are the following: * haproxy_keepalived_(ext|int)ernal_vip_cidr * haproxy_keepalived_(ext|int)ernal_interface * haproxy_keepalived_(ext|int)ernal_virtual_router_id * haproxy_keepalived_priority_backup * haproxy_keepalived_priority_master * haproxy_keepalived_vars_file In these variables, only the following variables are necessary: keepalived_(ext|int)ernal_vip_cidr However, it's recommended to also configure the keepalived_(ext|int)ernal_interface (to know which interface the vips can bind on) Closes-Bug: 1414397 Change-Id: Ib87a3bb70d6f4b7ac9356e8a28fe4b5936eb9334
74 lines
3.0 KiB
YAML
74 lines
3.0 KiB
YAML
---
|
|
# Copyright 2014, Rackspace US, Inc.
|
|
#
|
|
# Licensed under the Apache License, Version 2.0 (the "License");
|
|
# you may not use this file except in compliance with the License.
|
|
# You may obtain a copy of the License at
|
|
#
|
|
# http://www.apache.org/licenses/LICENSE-2.0
|
|
#
|
|
# Unless required by applicable law or agreed to in writing, software
|
|
# distributed under the License is distributed on an "AS IS" BASIS,
|
|
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
# See the License for the specific language governing permissions and
|
|
# limitations under the License.
|
|
|
|
- hosts: haproxy_hosts
|
|
vars_files:
|
|
- "{{ haproxy_keepalived_vars_file | default('vars/configs/keepalived_haproxy.yml')}}"
|
|
roles:
|
|
- role: "keepalived"
|
|
keepalived_sync_groups: "{{ keepalived_master_sync_groups }}"
|
|
keepalived_scripts: "{{ keepalived_master_scripts }}"
|
|
keepalived_instances: "{{ keepalived_master_instances }}"
|
|
when: >
|
|
haproxy_use_keepalived|bool and
|
|
inventory_hostname in groups['haproxy_hosts'][0]
|
|
- role: "keepalived"
|
|
keepalived_sync_groups: "{{ keepalived_backup_sync_groups }}"
|
|
keepalived_scripts: "{{ keepalived_backup_scripts }}"
|
|
keepalived_instances: "{{ keepalived_backup_instances }}"
|
|
when: >
|
|
haproxy_use_keepalived|bool and
|
|
inventory_hostname in groups['haproxy_hosts'][1:]
|
|
|
|
- name: Install haproxy
|
|
hosts: haproxy_hosts
|
|
max_fail_percentage: 20
|
|
user: root
|
|
pre_tasks:
|
|
- name: Remove legacy haproxy configuration files
|
|
file:
|
|
dest: "/etc/haproxy/conf.d/{{ item }}"
|
|
state: "absent"
|
|
with_items:
|
|
- "keystone_internal"
|
|
when: internal_lb_vip_address == external_lb_vip_address
|
|
tags:
|
|
- haproxy-service-config
|
|
post_tasks:
|
|
- name: Add keystone internal endpoint config
|
|
include: roles/haproxy_server/tasks/haproxy_service_config.yml
|
|
when: internal_lb_vip_address != external_lb_vip_address
|
|
vars_files:
|
|
- vars/configs/haproxy_config.yml
|
|
vars:
|
|
haproxy_service_configs:
|
|
- service:
|
|
haproxy_service_name: keystone_internal
|
|
haproxy_backend_nodes: "{{ groups['keystone_all'] }}"
|
|
haproxy_bind: "{{ internal_lb_vip_address }}"
|
|
haproxy_port: 5000
|
|
haproxy_ssl: "{% if haproxy_ssl | bool and keystone_service_internaluri_proto == 'https' %}true{% else %}false{% endif %}"
|
|
haproxy_balance_type: "{{ (keystone_ssl_internal | bool) | ternary('tcp','http') }}"
|
|
haproxy_balance_alg: "{{ (keystone_ssl_internal | bool) | ternary('source', 'leastconn') }}"
|
|
haproxy_backend_options: "{{ (keystone_ssl_internal | bool) | ternary(haproxy_backend_options_https, haproxy_backend_options_http) }}"
|
|
tags:
|
|
- haproxy-service-config
|
|
roles:
|
|
- { role: "haproxy_server", tags: [ "haproxy-server" ] }
|
|
vars_files:
|
|
- vars/configs/haproxy_config.yml
|
|
vars:
|
|
is_metal: "{{ properties.is_metal|default(false) }}"
|