![Damien Ciabrini](/assets/img/avatar_default.png)
When a service connects to the database VIP from the node hosting this VIP, the resulting TCP socket has a src address which is by default bound to the VIP as well. If the VIP is failed over to another node while the socket's Send-Q is not empty, TCP keepalive won't engage and the service will become unavailable for a very long time (by default more than 10m). To prevent failover issues, DB connections should have the src address of their TCP socket bound to the IP of the network interface used for MySQL traffic. This is achieved by passing a new option to the database connection URIs. This option is available starting from PyMySQL 0.7.9-2. We use a new intermediate variable in hiera to hold the IP to be used as a source address for all DB connections. All services adapt their database URI accordingly. Moreover, a new YAML validation check is added to guarantee that new services will construct their database URI appropriately. Change-Id: Ic69de63acbfb992314ea30a3a9b17c0b5341c035 Closes-Bug: #1643487
130 lines
4.7 KiB
YAML
130 lines
4.7 KiB
YAML
heat_template_version: 2016-10-14
|
|
|
|
description: >
|
|
OpenStack Nova base service. Shared for all Nova services.
|
|
|
|
parameters:
|
|
ServiceNetMap:
|
|
default: {}
|
|
description: Mapping of service_name -> network name. Typically set
|
|
via parameter_defaults in the resource registry. This
|
|
mapping overrides those in ServiceNetMapDefaults.
|
|
type: json
|
|
DefaultPasswords:
|
|
default: {}
|
|
type: json
|
|
EndpointMap:
|
|
default: {}
|
|
description: Mapping of service endpoint -> protocol. Typically set
|
|
via parameter_defaults in the resource registry.
|
|
type: json
|
|
NovaPassword:
|
|
description: The password for the nova service and db account, used by nova-api.
|
|
type: string
|
|
hidden: true
|
|
NeutronPassword:
|
|
description: The password for the neutron service and db account, used by neutron agents.
|
|
type: string
|
|
hidden: true
|
|
NovaOVSBridge:
|
|
default: 'br-int'
|
|
description: Name of integration bridge used by Open vSwitch
|
|
type: string
|
|
RabbitPassword:
|
|
description: The password for RabbitMQ
|
|
type: string
|
|
hidden: true
|
|
RabbitUserName:
|
|
default: guest
|
|
description: The username for RabbitMQ
|
|
type: string
|
|
RabbitClientUseSSL:
|
|
default: false
|
|
description: >
|
|
Rabbit client subscriber parameter to specify
|
|
an SSL connection to the RabbitMQ host.
|
|
type: string
|
|
RabbitClientPort:
|
|
default: 5672
|
|
description: Set rabbit subscriber port, change this if using SSL
|
|
type: number
|
|
Debug:
|
|
type: string
|
|
default: ''
|
|
description: Set to True to enable debugging on all services.
|
|
EnableConfigPurge:
|
|
type: boolean
|
|
default: true
|
|
description: >
|
|
Remove configuration that is not generated by TripleO. Setting
|
|
to false may result in configuration remnants after updates/upgrades.
|
|
NovaIPv6:
|
|
default: false
|
|
description: Enable IPv6 features in Nova
|
|
type: boolean
|
|
UpgradeLevelNovaCompute:
|
|
type: string
|
|
description: Nova Compute upgrade level
|
|
default: ''
|
|
conditions:
|
|
|
|
compute_upgrade_level_empty: {equals : [{get_param: UpgradeLevelNovaCompute}, '']}
|
|
|
|
outputs:
|
|
role_data:
|
|
description: Role data for the Nova base service.
|
|
value:
|
|
service_name: nova_base
|
|
config_settings:
|
|
map_merge:
|
|
- nova::rabbit_password: {get_param: RabbitPassword}
|
|
nova::rabbit_userid: {get_param: RabbitUserName}
|
|
nova::rabbit_use_ssl: {get_param: RabbitClientUseSSL}
|
|
nova::rabbit_port: {get_param: RabbitClientPort}
|
|
nova::database_connection:
|
|
list_join:
|
|
- ''
|
|
- - {get_param: [EndpointMap, MysqlInternal, protocol]}
|
|
- '://nova:'
|
|
- {get_param: NovaPassword}
|
|
- '@'
|
|
- {get_param: [EndpointMap, MysqlInternal, host]}
|
|
- '/nova'
|
|
- '?bind_address='
|
|
- "%{hiera('tripleo::profile::base::database::mysql::client_bind_address')}"
|
|
nova::api_database_connection:
|
|
list_join:
|
|
- ''
|
|
- - {get_param: [EndpointMap, MysqlInternal, protocol]}
|
|
- '://nova_api:'
|
|
- {get_param: NovaPassword}
|
|
- '@'
|
|
- {get_param: [EndpointMap, MysqlInternal, host]}
|
|
- '/nova_api'
|
|
- '?bind_address='
|
|
- "%{hiera('tripleo::profile::base::database::mysql::client_bind_address')}"
|
|
nova::debug: {get_param: Debug}
|
|
nova::purge_config: {get_param: EnableConfigPurge}
|
|
nova::network::neutron::neutron_project_name: 'service'
|
|
nova::network::neutron::neutron_username: 'neutron'
|
|
nova::network::neutron::dhcp_domain: ''
|
|
nova::network::neutron::neutron_password: {get_param: NeutronPassword}
|
|
nova::network::neutron::neutron_url: {get_param: [EndpointMap, NeutronInternal, uri]}
|
|
nova::network::neutron::neutron_auth_url: {get_param: [EndpointMap, KeystoneV3Admin, uri]}
|
|
nova::rabbit_heartbeat_timeout_threshold: 60
|
|
nova::cinder_catalog_info: 'volumev2:cinderv2:internalURL'
|
|
nova::host: '%{::fqdn}'
|
|
nova::notify_on_state_change: 'vm_and_task_state'
|
|
nova::notification_driver: messagingv2
|
|
nova::network::neutron::neutron_auth_type: 'v3password'
|
|
nova::db::database_db_max_retries: -1
|
|
nova::db::database_max_retries: -1
|
|
nova::glance_api_servers: {get_param: [EndpointMap, GlanceInternal, uri]}
|
|
nova::use_ipv6: {get_param: NovaIPv6}
|
|
nova::network::neutron::neutron_ovs_bridge: {get_param: NovaOVSBridge}
|
|
-
|
|
if:
|
|
- compute_upgrade_level_empty
|
|
- {}
|
|
- nova::upgrade_level_compute: {get_param: UpgradeLevelNovaCompute}
|