a9da212d7d
Even though we're setting memcached::logfile: '/var/log/memcached/memcached.log' there are no logs created in /var/log/containers/memcached. The reason for this is that memcached::logfile in puppet-memcached simply adds a shell redirect to a file. These redirecs are passed by tht and kolla to the memcached process invocation as parameters of memcached and so are not read being read by the shell process and nothing gets redirected. That is why we observe that on a broken container the redirections are arguments to memcached: [root@controller-0 ~]# ps aux | grep memcache | grep -v containers 42457 358189 0.0 0.0 744088 10960 ? Sl 15:21 0:00 /usr/bin/memcached -p 11211 -u memcached -m 16000 -c 8192 -vv -l 172.17.1.138 -U 0 -X -t 8 >> /var/log/memcached/memcached.log 2>&1 Fix this by forcing memcached to log on stdout and at the same time creating the redirect on the shell parameters that invoke memcached. Tested on a Train environment and I correctly get: 1) Proper logging [root@controller-0 ~]# ls -l /var/log/containers/memcached/memcached.log -rw-r--r--. 1 42457 42457 29086 Nov 4 18:00 /var/log/containers/memcached/memcached.log 2) No unused redirections inside the memcached process: [root@controller-0 ~]# podman exec -it -uroot memcached ps -ef UID PID PPID C STIME TTY TIME CMD memcach+ 1 0 0 18:47 ? 00:00:00 dumb-init --single-child -- kolla_start memcach+ 6 1 0 18:47 ? 00:00:00 /usr/bin/memcached -p 11211 -u memcached -m 9953 -c 8192 -vv -l 172.17.1.50 -U 0 -X -t 4 Co-Authored-By: Damien Ciabrini <dciabrin@redhat.com> Resolves: #1902922 Change-Id: If5487c9be745ebd6bc3ebe172e28dc59e6855188
278 lines
10 KiB
YAML
278 lines
10 KiB
YAML
heat_template_version: rocky
|
|
|
|
description: >
|
|
OpenStack containerized Memcached services
|
|
|
|
parameters:
|
|
ContainerMemcachedImage:
|
|
description: image
|
|
type: string
|
|
ContainerMemcachedConfigImage:
|
|
description: The container image to use for the memcached config_volume
|
|
type: string
|
|
EndpointMap:
|
|
default: {}
|
|
description: Mapping of service endpoint -> protocol. Typically set
|
|
via parameter_defaults in the resource registry.
|
|
type: json
|
|
ServiceData:
|
|
default: {}
|
|
description: Dictionary packing service data
|
|
type: json
|
|
ServiceNetMap:
|
|
default: {}
|
|
description: Mapping of service_name -> network name. Typically set
|
|
via parameter_defaults in the resource registry. This
|
|
mapping overrides those in ServiceNetMapDefaults.
|
|
type: json
|
|
DefaultPasswords:
|
|
default: {}
|
|
type: json
|
|
RoleName:
|
|
default: ''
|
|
description: Role name on which the service is applied
|
|
type: string
|
|
RoleParameters:
|
|
default: {}
|
|
description: Parameters specific to the role
|
|
type: json
|
|
MemcachedMaxMemory:
|
|
default: '50%'
|
|
description: The maximum amount of memory for memcached to be configured
|
|
to use when installed. This can be either a percentage ('50%')
|
|
or a fixed value ('2048').
|
|
type: string
|
|
MonitoringSubscriptionMemcached:
|
|
default: 'overcloud-memcached'
|
|
type: string
|
|
Debug:
|
|
default: false
|
|
description: Set to True to enable debugging on all services.
|
|
type: boolean
|
|
MemcachedDebug:
|
|
default: ''
|
|
description: Set to True to enable debugging Memcached service.
|
|
type: string
|
|
constraints:
|
|
- allowed_values: [ '', 'true', 'True', 'TRUE', 'false', 'False', 'FALSE']
|
|
MemcachedIpSubnet:
|
|
default: ''
|
|
description: IP address/subnet on the memcached network. If empty (default), MemcachedNetwork
|
|
will be taken. Useful in the case where an operator wants to open Memcached outside
|
|
of the internal network. Use this parameter with caution and be aware of
|
|
opening memcached to external network can be dangerous.
|
|
type: string
|
|
MemcachedTLS:
|
|
default: false
|
|
description: Set to True to enable TLS on Memcached service.
|
|
type: boolean
|
|
|
|
conditions:
|
|
internal_tls_enabled: {equals: [{get_param: MemcachedTLS}, true]}
|
|
memcached_network_unset: {equals : [{get_param: MemcachedIpSubnet}, '']}
|
|
service_debug:
|
|
or:
|
|
- equals: [{get_param: MemcachedDebug}, 'true']
|
|
- equals: [{get_param: MemcachedDebug}, 'True']
|
|
- equals: [{get_param: Debug}, true]
|
|
is_ipv6:
|
|
equals:
|
|
- {get_param: [ServiceData, net_ip_version_map, {get_param: [ServiceNetMap, MemcachedNetwork]}]}
|
|
- 6
|
|
|
|
resources:
|
|
|
|
ContainersCommon:
|
|
type: ../containers-common.yaml
|
|
|
|
outputs:
|
|
role_data:
|
|
description: Role data for the Memcached API role.
|
|
value:
|
|
service_name: memcached
|
|
firewall_rules:
|
|
# https://access.redhat.com/security/cve/cve-2018-1000115
|
|
# Only accept TCP to avoid spoofed traffic amplification DoS on UDP.
|
|
# Memcached traffic shouldn't be open on the internet.
|
|
# Even if binding is configured on internal_api network, enforce it
|
|
# via firewall as well.
|
|
if:
|
|
- memcached_network_unset
|
|
- map_merge:
|
|
repeat:
|
|
for_each:
|
|
<%net_cidr%>:
|
|
get_param:
|
|
- ServiceData
|
|
- net_cidr_map
|
|
- {get_param: [ServiceNetMap, MemcachedNetwork]}
|
|
template:
|
|
'121 memcached <%net_cidr%>':
|
|
dport: 11211
|
|
proto: 'tcp'
|
|
source: <%net_cidr%>
|
|
- '121 memcached':
|
|
dport: 11211
|
|
proto: 'tcp'
|
|
source: {get_param: MemcachedIpSubnet}
|
|
monitoring_subscription: {get_param: MonitoringSubscriptionMemcached}
|
|
config_settings:
|
|
map_merge:
|
|
-
|
|
# NOTE: bind IP is found in hiera replacing the network name with the local node IP
|
|
# for the given network; replacement examples (eg. for internal_api):
|
|
# internal_api -> IP
|
|
# internal_api_uri -> [IP]
|
|
# internal_api_subnet - > IP/CIDR
|
|
memcached::listen_ip:
|
|
- if:
|
|
- is_ipv6
|
|
- '::1'
|
|
- '127.0.0.1'
|
|
- str_replace:
|
|
template:
|
|
"%{hiera('$NETWORK')}"
|
|
params:
|
|
$NETWORK: {get_param: [ServiceNetMap, MemcachedNetwork]}
|
|
memcached::listen_ip_uri:
|
|
- if:
|
|
- is_ipv6
|
|
- '::1'
|
|
- '127.0.0.1'
|
|
- str_replace:
|
|
template:
|
|
"%{hiera('$NETWORK_uri')}"
|
|
params:
|
|
$NETWORK: {get_param: [ServiceNetMap, MemcachedNetwork]}
|
|
memcached::max_memory: {get_param: MemcachedMaxMemory}
|
|
# https://access.redhat.com/security/cve/cve-2018-1000115
|
|
# Only accept TCP to avoid spoofed traffic amplification DoS on UDP.
|
|
memcached::udp_port: 0
|
|
memcached::verbosity:
|
|
list_join:
|
|
- ''
|
|
- - 'v'
|
|
- if:
|
|
- service_debug
|
|
- 'v'
|
|
- ''
|
|
memcached::disable_cachedump: true
|
|
memcached::logstdout: true
|
|
tripleo::profile::base::memcached::enable_internal_memcached_tls: {get_param: MemcachedTLS}
|
|
-
|
|
if:
|
|
- internal_tls_enabled
|
|
- generate_service_certificates: true
|
|
tripleo::memcached::service_certificate: '/etc/pki/tls/certs/memcached.crt'
|
|
tripleo::profile::base::memcached::certificate_specs:
|
|
service_certificate: '/etc/pki/tls/certs/memcached.crt'
|
|
service_key: '/etc/pki/tls/private/memcached.key'
|
|
hostname:
|
|
str_replace:
|
|
template: "%{hiera('fqdn_$NETWORK')}"
|
|
params:
|
|
$NETWORK: {get_param: [ServiceNetMap, MemcachedNetwork]}
|
|
principal:
|
|
str_replace:
|
|
template: "memcached/%{hiera('fqdn_$NETWORK')}"
|
|
params:
|
|
$NETWORK: {get_param: [ServiceNetMap, MemcachedNetwork]}
|
|
postsave_cmd: "/usr/bin/certmonger-memcached-refresh.sh"
|
|
- {}
|
|
service_config_settings:
|
|
collectd:
|
|
tripleo.collectd.plugins.memcached:
|
|
- memcached
|
|
collectd::plugin::memcached::instances:
|
|
local:
|
|
host: "%{hiera('memcached::listen_ip_uri')}"
|
|
port: 11211
|
|
# BEGIN DOCKER SETTINGS
|
|
puppet_config:
|
|
config_volume: 'memcached'
|
|
puppet_tags: 'file'
|
|
step_config: |
|
|
include tripleo::profile::base::memcached
|
|
config_image: {get_param: ContainerMemcachedConfigImage}
|
|
kolla_config:
|
|
/var/lib/kolla/config_files/memcached.json:
|
|
command: bash -c $* -- eval source /etc/sysconfig/memcached; exec /usr/bin/memcached -p ${PORT} -u ${USER} -m ${CACHESIZE} -c ${MAXCONN} $OPTIONS >> /var/log/memcached/memcached.log 2>&1
|
|
config_files:
|
|
- source: "/var/lib/kolla/config_files/src/*"
|
|
dest: "/"
|
|
merge: true
|
|
preserve_properties: true
|
|
- source: "/var/lib/kolla/config_files/src-tls/*"
|
|
dest: "/"
|
|
merge: true
|
|
preserve_properties: true
|
|
optional: true
|
|
permissions:
|
|
- path: /var/log/memcached
|
|
owner: memcached:memcached
|
|
recurse: true
|
|
- path: /etc/pki/tls/certs/memcached.crt
|
|
owner: memcached:memcached
|
|
optional: true
|
|
- path: /etc/pki/tls/private/memcached.key
|
|
owner: memcached:memcached
|
|
optional: true
|
|
docker_config:
|
|
step_1:
|
|
memcached:
|
|
start_order: 0
|
|
image: {get_param: ContainerMemcachedImage}
|
|
net: host
|
|
privileged: false
|
|
restart: always
|
|
healthcheck:
|
|
test: /openstack/healthcheck
|
|
volumes:
|
|
list_concat:
|
|
- {get_attr: [ContainersCommon, volumes]}
|
|
-
|
|
- /var/lib/kolla/config_files/memcached.json:/var/lib/kolla/config_files/config.json:ro
|
|
- /var/lib/config-data/puppet-generated/memcached:/var/lib/kolla/config_files/src:rw,z
|
|
- /var/log/containers/memcached:/var/log/memcached:rw
|
|
- if:
|
|
- internal_tls_enabled
|
|
-
|
|
- /etc/pki/tls/certs/memcached.crt:/var/lib/kolla/config_files/src-tls/etc/pki/tls/certs/memcached.crt:ro
|
|
- /etc/pki/tls/private/memcached.key:/var/lib/kolla/config_files/src-tls/etc/pki/tls/private/memcached.key:ro
|
|
- null
|
|
environment:
|
|
KOLLA_CONFIG_STRATEGY: COPY_ALWAYS
|
|
metadata_settings:
|
|
if:
|
|
- internal_tls_enabled
|
|
-
|
|
- service: memcached
|
|
network: {get_param: [ServiceNetMap, MemcachedNetwork]}
|
|
type: node
|
|
- null
|
|
host_prep_tasks:
|
|
- name: create persistent directories
|
|
file:
|
|
path: "{{ item.path }}"
|
|
state: directory
|
|
setype: "{{ item.setype }}"
|
|
mode: "{{ item.mode }}"
|
|
with_items:
|
|
- { 'path': /var/log/containers/memcached, 'setype': container_file_t, 'mode': '0750' }
|
|
upgrade_tasks: []
|
|
external_upgrade_tasks:
|
|
- when:
|
|
- step|int == 1
|
|
tags:
|
|
- never
|
|
- system_upgrade_transfer_data
|
|
- system_upgrade_stop_services
|
|
block:
|
|
- name: Stop memcached container
|
|
import_role:
|
|
name: tripleo_container_stop
|
|
vars:
|
|
tripleo_containers_to_stop:
|
|
- memcached
|
|
tripleo_delegate_to: "{{ groups['memcached'] | default([]) }}"
|