Add option for HAProxy (non-HA) container to log to stdout/stderr
This adds the option to get the HAProxy container to log to stdout. The option is disabled by default. If enabled, It also adds a sidecar container that reads from syslog and outputs what it gets to stdout. bp logging-stdout-rsyslog Change-Id: Ica819713aa50352ba04a748c463534d982e00538
This commit is contained in:
parent
97f9a01f79
commit
32d5e0cd77
|
@ -107,6 +107,9 @@ resources:
|
||||||
RoleName: {get_param: RoleName}
|
RoleName: {get_param: RoleName}
|
||||||
RoleParameters: {get_param: RoleParameters}
|
RoleParameters: {get_param: RoleParameters}
|
||||||
|
|
||||||
|
HAProxyLogging:
|
||||||
|
type: OS::TripleO::Services::Logging::HAProxy
|
||||||
|
|
||||||
outputs:
|
outputs:
|
||||||
role_data:
|
role_data:
|
||||||
description: Role data for the HAproxy role.
|
description: Role data for the HAproxy role.
|
||||||
|
@ -115,6 +118,7 @@ outputs:
|
||||||
config_settings:
|
config_settings:
|
||||||
map_merge:
|
map_merge:
|
||||||
- get_attr: [HAProxyBase, role_data, config_settings]
|
- get_attr: [HAProxyBase, role_data, config_settings]
|
||||||
|
- get_attr: [HAProxyLogging, config_settings]
|
||||||
- tripleo::haproxy::haproxy_service_manage: false
|
- tripleo::haproxy::haproxy_service_manage: false
|
||||||
# NOTE(jaosorior): We disable the CRL since we have no way to restart haproxy
|
# NOTE(jaosorior): We disable the CRL since we have no way to restart haproxy
|
||||||
# when this is updated
|
# when this is updated
|
||||||
|
@ -169,71 +173,76 @@ outputs:
|
||||||
optional: true
|
optional: true
|
||||||
docker_config:
|
docker_config:
|
||||||
step_1:
|
step_1:
|
||||||
haproxy_firewall:
|
map_merge:
|
||||||
detach: false
|
- get_attr: [HAProxyLogging, docker_config, step_1]
|
||||||
image: {get_param: DockerHAProxyImage}
|
- haproxy_firewall:
|
||||||
net: host
|
start_order: 0
|
||||||
user: root
|
detach: false
|
||||||
privileged: true
|
image: {get_param: DockerHAProxyImage}
|
||||||
command:
|
net: host
|
||||||
- '/bin/bash'
|
user: root
|
||||||
- '-c'
|
privileged: true
|
||||||
- str_replace:
|
command:
|
||||||
template:
|
- '/bin/bash'
|
||||||
list_join:
|
- '-c'
|
||||||
- '; '
|
- str_replace:
|
||||||
- - "cp -a /tmp/puppet-etc/* /etc/puppet; echo '{\"step\": 1}' > /etc/puppet/hieradata/docker.json"
|
template:
|
||||||
- "FACTER_uuid=docker puppet apply --tags TAGS -v -e 'CONFIG'"
|
list_join:
|
||||||
params:
|
- '; '
|
||||||
TAGS: 'tripleo::firewall::rule'
|
- - "cp -a /tmp/puppet-etc/* /etc/puppet; echo '{\"step\": 1}' > /etc/puppet/hieradata/docker.json"
|
||||||
CONFIG:
|
- "FACTER_uuid=docker puppet apply --tags TAGS -v -e 'CONFIG'"
|
||||||
get_attr: [HAProxyBase, role_data, step_config]
|
params:
|
||||||
volumes:
|
TAGS: 'tripleo::firewall::rule'
|
||||||
list_concat:
|
CONFIG:
|
||||||
- {get_attr: [ContainersCommon, volumes]}
|
get_attr: [HAProxyBase, role_data, step_config]
|
||||||
-
|
volumes:
|
||||||
- /var/lib/kolla/config_files/haproxy.json:/var/lib/kolla/config_files/config.json:ro
|
list_concat:
|
||||||
- /var/lib/config-data/puppet-generated/haproxy/:/var/lib/kolla/config_files/src:ro
|
- {get_attr: [ContainersCommon, volumes]}
|
||||||
# puppet saves iptables rules in /etc/sysconfig
|
-
|
||||||
- /etc/sysconfig:/etc/sysconfig:rw
|
- /var/lib/kolla/config_files/haproxy.json:/var/lib/kolla/config_files/config.json:ro
|
||||||
# saving rules require accessing /usr/libexec/iptables/iptables.init, just bind-mount
|
- /var/lib/config-data/puppet-generated/haproxy/:/var/lib/kolla/config_files/src:ro
|
||||||
# the necessary bit and prevent systemd to try to reload the service in the container
|
# puppet saves iptables rules in /etc/sysconfig
|
||||||
- /usr/libexec/iptables:/usr/libexec/iptables:ro
|
- /etc/sysconfig:/etc/sysconfig:rw
|
||||||
- /usr/libexec/initscripts/legacy-actions:/usr/libexec/initscripts/legacy-actions:ro
|
# saving rules require accessing /usr/libexec/iptables/iptables.init, just bind-mount
|
||||||
- /etc/puppet:/tmp/puppet-etc:ro
|
# the necessary bit and prevent systemd to try to reload the service in the container
|
||||||
- /usr/share/openstack-puppet/modules:/usr/share/openstack-puppet/modules:ro
|
- /usr/libexec/iptables:/usr/libexec/iptables:ro
|
||||||
environment:
|
- /usr/libexec/initscripts/legacy-actions:/usr/libexec/initscripts/legacy-actions:ro
|
||||||
- KOLLA_CONFIG_STRATEGY=COPY_ALWAYS
|
- /etc/puppet:/tmp/puppet-etc:ro
|
||||||
haproxy:
|
- /usr/share/openstack-puppet/modules:/usr/share/openstack-puppet/modules:ro
|
||||||
image: {get_param: DockerHAProxyImage}
|
environment:
|
||||||
net: host
|
- KOLLA_CONFIG_STRATEGY=COPY_ALWAYS
|
||||||
restart: always
|
haproxy:
|
||||||
volumes:
|
start_order: 1
|
||||||
list_concat:
|
image: {get_param: DockerHAProxyImage}
|
||||||
- {get_attr: [ContainersCommon, volumes]}
|
net: host
|
||||||
-
|
restart: always
|
||||||
- /var/lib/kolla/config_files/haproxy.json:/var/lib/kolla/config_files/config.json:ro
|
volumes:
|
||||||
- /var/lib/config-data/puppet-generated/haproxy/:/var/lib/kolla/config_files/src:ro
|
list_concat:
|
||||||
- if:
|
- {get_attr: [ContainersCommon, volumes]}
|
||||||
- public_tls_enabled
|
- {get_attr: [HAProxyLogging, volumes]}
|
||||||
- - list_join:
|
-
|
||||||
- ':'
|
- /var/lib/kolla/config_files/haproxy.json:/var/lib/kolla/config_files/config.json:ro
|
||||||
- - {get_param: DeployedSSLCertificatePath}
|
- /var/lib/config-data/puppet-generated/haproxy/:/var/lib/kolla/config_files/src:ro
|
||||||
- {get_param: DeployedSSLCertificatePath}
|
- if:
|
||||||
- 'ro'
|
- public_tls_enabled
|
||||||
- null
|
- - list_join:
|
||||||
-
|
- ':'
|
||||||
if:
|
- - {get_param: DeployedSSLCertificatePath}
|
||||||
- internal_tls_enabled
|
- {get_param: DeployedSSLCertificatePath}
|
||||||
- - /etc/pki/tls/certs/haproxy:/var/lib/kolla/config_files/src-tls/etc/pki/tls/certs/haproxy:ro
|
- 'ro'
|
||||||
- /etc/pki/tls/private/haproxy:/var/lib/kolla/config_files/src-tls/etc/pki/tls/private/haproxy:ro
|
|
||||||
- list_join:
|
|
||||||
- ':'
|
|
||||||
- - {get_param: InternalTLSCAFile}
|
|
||||||
- {get_param: InternalTLSCAFile}
|
|
||||||
- 'ro'
|
|
||||||
- null
|
- null
|
||||||
environment:
|
-
|
||||||
- KOLLA_CONFIG_STRATEGY=COPY_ALWAYS
|
if:
|
||||||
|
- internal_tls_enabled
|
||||||
|
- - /etc/pki/tls/certs/haproxy:/var/lib/kolla/config_files/src-tls/etc/pki/tls/certs/haproxy:ro
|
||||||
|
- /etc/pki/tls/private/haproxy:/var/lib/kolla/config_files/src-tls/etc/pki/tls/private/haproxy:ro
|
||||||
|
- list_join:
|
||||||
|
- ':'
|
||||||
|
- - {get_param: InternalTLSCAFile}
|
||||||
|
- {get_param: InternalTLSCAFile}
|
||||||
|
- 'ro'
|
||||||
|
- null
|
||||||
|
environment:
|
||||||
|
- KOLLA_CONFIG_STRATEGY=COPY_ALWAYS
|
||||||
metadata_settings:
|
metadata_settings:
|
||||||
get_attr: [HAProxyBase, role_data, metadata_settings]
|
get_attr: [HAProxyBase, role_data, metadata_settings]
|
||||||
|
|
|
@ -0,0 +1,23 @@
|
||||||
|
heat_template_version: pike
|
||||||
|
|
||||||
|
description: >
|
||||||
|
OpenStack containerized HAProxy API service
|
||||||
|
|
||||||
|
outputs:
|
||||||
|
config_settings:
|
||||||
|
description: Extra hieradata needed to log to files in the host.
|
||||||
|
value: null
|
||||||
|
volumes:
|
||||||
|
description: The volumes needed to log to files in the host.
|
||||||
|
# NOTE(jaosorior): Currently all containers mount /dev/log. Once we
|
||||||
|
# have a more complete proportion of containers using the pluggable
|
||||||
|
# interface. we'll remove that and mount it explicitly here.
|
||||||
|
# - /dev/log:/dev/log
|
||||||
|
value: null
|
||||||
|
docker_config:
|
||||||
|
description: Extra containers needed for logging to files in the host.
|
||||||
|
value:
|
||||||
|
step_1: {}
|
||||||
|
host_prep_tasks:
|
||||||
|
description: Extra ansible tasks needed for logging to files in the host.
|
||||||
|
value: null
|
|
@ -0,0 +1,37 @@
|
||||||
|
heat_template_version: pike
|
||||||
|
|
||||||
|
description: >
|
||||||
|
OpenStack containerized HAProxy API service
|
||||||
|
|
||||||
|
parameters:
|
||||||
|
DockerRsyslogSidecarImage:
|
||||||
|
description: image
|
||||||
|
type: string
|
||||||
|
|
||||||
|
outputs:
|
||||||
|
config_settings:
|
||||||
|
description: Extra hieradata needed to log to stdout.
|
||||||
|
value:
|
||||||
|
tripleo::haproxy::haproxy_log_address: '/sockets/log'
|
||||||
|
docker_config:
|
||||||
|
description: Extra containers needed for logging to stdout or a sidecar container.
|
||||||
|
value:
|
||||||
|
step_1:
|
||||||
|
haproxy_logs:
|
||||||
|
start_order: 0
|
||||||
|
image: {get_param: DockerRsyslogSidecarImage}
|
||||||
|
user: root
|
||||||
|
restart: always
|
||||||
|
volumes:
|
||||||
|
- /var/lib/kolla/config_files/rsyslog_sidecar.json:/var/lib/kolla/config_files/config.json:ro
|
||||||
|
- /var/lib/config-data/puppet-generated/rsyslog_sidecar/:/var/lib/kolla/config_files/src:ro
|
||||||
|
- HAProxyLogs:/sockets/
|
||||||
|
environment:
|
||||||
|
- KOLLA_CONFIG_STRATEGY=COPY_ALWAYS
|
||||||
|
volumes:
|
||||||
|
description: The volumes needed to log to stdout or a sidecar container.
|
||||||
|
value:
|
||||||
|
- HAProxyLogs:/sockets/
|
||||||
|
host_prep_tasks:
|
||||||
|
description: Extra ansible tasks needed for logging to files in the host.
|
||||||
|
value: null
|
|
@ -2,6 +2,7 @@ resource_registry:
|
||||||
OS::TripleO::Services::RsyslogSidecar: ../docker/services/rsyslog-sidecar.yaml
|
OS::TripleO::Services::RsyslogSidecar: ../docker/services/rsyslog-sidecar.yaml
|
||||||
|
|
||||||
OS::TripleO::Services::Logging::GlanceApi: ../docker/services/logging/stdout/glance-api.yaml
|
OS::TripleO::Services::Logging::GlanceApi: ../docker/services/logging/stdout/glance-api.yaml
|
||||||
|
OS::TripleO::Services::Logging::HAProxy: ../docker/services/logging/stdout/haproxy.yaml
|
||||||
OS::TripleO::Services::Logging::HeatApi: ../docker/services/logging/stdout/heat-api.yaml
|
OS::TripleO::Services::Logging::HeatApi: ../docker/services/logging/stdout/heat-api.yaml
|
||||||
OS::TripleO::Services::Logging::HeatApiCfn: ../docker/services/logging/stdout/heat-api-cfn.yaml
|
OS::TripleO::Services::Logging::HeatApiCfn: ../docker/services/logging/stdout/heat-api-cfn.yaml
|
||||||
OS::TripleO::Services::Logging::HeatEngine: ../docker/services/logging/stdout/heat-engine.yaml
|
OS::TripleO::Services::Logging::HeatEngine: ../docker/services/logging/stdout/heat-engine.yaml
|
||||||
|
|
|
@ -305,6 +305,7 @@ resource_registry:
|
||||||
|
|
||||||
# Logging
|
# Logging
|
||||||
OS::TripleO::Services::Logging::GlanceApi: docker/services/logging/files/glance-api.yaml
|
OS::TripleO::Services::Logging::GlanceApi: docker/services/logging/files/glance-api.yaml
|
||||||
|
OS::TripleO::Services::Logging::HAProxy: docker/services/logging/files/haproxy.yaml
|
||||||
OS::TripleO::Services::Logging::HeatApi: docker/services/logging/files/heat-api.yaml
|
OS::TripleO::Services::Logging::HeatApi: docker/services/logging/files/heat-api.yaml
|
||||||
OS::TripleO::Services::Logging::HeatApiCfn: docker/services/logging/files/heat-api-cfn.yaml
|
OS::TripleO::Services::Logging::HeatApiCfn: docker/services/logging/files/heat-api-cfn.yaml
|
||||||
OS::TripleO::Services::Logging::HeatEngine: docker/services/logging/files/heat-engine.yaml
|
OS::TripleO::Services::Logging::HeatEngine: docker/services/logging/files/heat-engine.yaml
|
||||||
|
|
Loading…
Reference in New Issue