1532 Commits

Author SHA1 Message Date
Mark Goddard
a78569dcb1 Add ussuri prelude to release notes
Change-Id: Ia74fa6a252e1d28eab2193365306e4b1fbba7c77
2020-05-19 13:53:47 +01:00
Zuul
62665da88b Merge "Allow OVS bridges to connect directly to interface" 2020-05-18 11:23:22 +00:00
Pierre Riteau
fc017249c2 Install coreutils package before using configdrive role
On seed hypervisors running CentOS 8, the configdrive role will fail to
install coreutils if coreutils-single is already present:

Error:
 Problem: problem with installed package coreutils-single-8.30-6.el8.x86_64
  - package coreutils-8.30-6.el8_1.1.x86_64 conflicts with coreutils-single provided by coreutils-single-8.30-6.el8.x86_64
  - package coreutils-8.30-6.el8_1.1.x86_64 conflicts with coreutils-single provided by coreutils-single-8.30-6.el8_1.1.x86_64
  - conflicting requests

Until the role handles it, install coreutils using the --allowerasing
option which will remove coreutils-single at the same time. Use a
command task for now since this option has just been added to
ansible:devel [1].

[1] https://github.com/ansible/ansible/pull/48319

Change-Id: I43bbe9dae3d6796e308fbf66cb04d16b57ff5e37
Story: 2007612
Task: 39607
2020-05-13 20:30:08 +00:00
Zuul
93c471406a Merge "CentOS 8: Fix network configuration persistence" 2020-05-13 19:14:56 +00:00
Zuul
840c56167a Merge "Fix multiple CI failures" 2020-05-13 10:49:23 +00:00
Mark Goddard
cd1753d85a Fix multiple CI failures
1. Blacklist Ansible 2.9.8

Ansible 2.9.8 includes a regression on the fileglob plugin [1] that
causes the Kolla Ansible HAProxy role to fail.

This change blacklists Ansible 2.9.8 to work around the issue.

2. Use ensure-docker role instead of install-docker

The install-* roles are being deprecated and renamed to follow the
ensure-* naming convention [2].

[1] https://github.com/ansible/ansible/issues/69450
[2] http://lists.zuul-ci.org/pipermail/zuul-announce/2020-April/000071.html

Change-Id: Iab1d84e6a8c1b3dd81e53279309153687677a061
Story: 2007659
Task: 39748
2020-05-12 19:04:43 +02:00
Mark Goddard
b4de1fd70c CentOS 8: Fix network configuration persistence
See bug in MichaelRigart.interfaces role [1] for details.

[1] https://github.com/michaelrigart/ansible-role-interfaces/issues/68

Change-Id: I6a5275d54c35fdb7bbe8a92309972b9ed7f69395
Story: 2007616
Task: 39626
2020-05-04 11:03:02 +01:00
Pierre Riteau
1a4134419f Improve formatting in release note
Change-Id: I7e90d6f81d8f7a1bf3948f06cf2776a37c801752
2020-04-30 15:59:49 +02:00
Zuul
565a0614dc Merge "Define default variables for Monasca config" 2020-04-29 17:33:48 +00:00
Mark Goddard
2a00b4cc67 Fix ironic inspector rule creation idempotency
Ironic inspector rules are registered both with the seed and (if using)
overcloud ironic inspector services. These tasks often show up as
changed even when no configuration changes have been made that would
affect the rules.

This is caused by inspector returning default values for fields that may
be omitted in the requested rule. This change fixes the issue by
including those defaults in the comparison.

Change-Id: Ia24e328d4531201d76a65b6385e4463bb1f3c5c6
Story: 2007399
Task: 38997
2020-04-28 13:51:35 +00:00
Isaac Prior
39308a4591 Define default variables for Monasca config
Sets 'monasca_install_type: source' to remove need
for kolla-ansible var boilerplate.

Also use default Monasca parameters to configure
Grafana post deploy.

Change-Id: I2b6d62104c9c127cb8f6b4f4930dd695cd00da17
Story: 2007597
Task: 39587
2020-04-28 14:51:26 +01:00
Zuul
5cfca2aa82 Merge "Run kolla-ansible bootstrap-servers as kolla user" 2020-04-27 13:56:54 +00:00
Zuul
c343d4d877 Merge "Docs: Ansible tuning" 2020-04-27 12:05:00 +00:00
Zuul
bf319b71a9 Merge "Support custom Ansible configuration" 2020-04-27 12:04:56 +00:00
Zuul
00b9fa2dbe Merge "Improve SSH known host error messages" 2020-04-27 11:02:24 +00:00
Zuul
316a42e623 Merge "Remove nameservers with any IP in overcloud resolv.conf workaround" 2020-04-27 11:02:19 +00:00
Zuul
0d1de84cb2 Merge "Avoid unconditional fact gathering" 2020-04-27 08:50:19 +00:00
Zuul
558276a8a6 Merge "CI: Add overcloud host configure job" 2020-04-24 00:03:24 +00:00
Zuul
6afc813c83 Merge "Add kolla_enable_openstack_core variable" 2020-04-23 23:44:32 +00:00
Mark Goddard
7890914627 Improve SSH known host error messages
A common failure early on when using Kayobe is during discovery of SSH
known hosts. This happens if a host does not have an IP address
configured on the admin (SSH) network. The failure looks like this:

PLAY [Ensure known hosts are configured]
**********************************************************************
TASK [ssh-known-host : Scan for SSH keys]
**********************************************************************
failed: [compute0 -> localhost] (item=) => {"ansible_loop_var": "item",
    "changed": false, "cmd": ["ssh-keyscan"], "delta": "0:00:00.013855",
    "end": "2020-04-17 10:51:01.857855", "item": "", "msg": "non-zero
        return code", "rc": 1, "start": "2020-04-17 10:51:01.844000",
    "stderr": "usage: ssh-keyscan [-46cDHv] [-f file] [-p port] [-T
        timeout] [-t type]\n\t\t   [host | addrlist namelist]",
    "stderr_lines": ["u sage: ssh-keyscan [-46cDHv] [-f file] [-p port]
        [-T timeout] [-t type]", "\t\t   [host | addrlist namelist]"],
        "stdout": "", "stdout_lines": []}

This happens when ansible_host is an empty string, typically because the
host has no IP address defined in for the admin network in
network-allocation.yml. This is very confusing for a new user. We should
provide a more informative message.

It's not exactly clear how a user gets to this point, since the
ip-allocation.yml playbook runs before ssh-known-host.yml, which should
populate network-allocation.yml.

This change detects this failure mode and provides a message with
information about how to resolve it.

Change-Id: I564b6e4509a30dec7c49a23bb2f75d490be775ed
Story: 2007566
Task: 39456
2020-04-23 19:55:39 +00:00
Zuul
7932314e54 Merge "Use upper constraints when installing Tenks" 2020-04-22 20:11:14 +00:00
Zuul
d0b2f14318 Merge "Cleanup py27 support" 2020-04-22 17:59:29 +00:00
Zuul
1dc5cf0c65 Merge "Fix passwords.yml generation with vault encryption on Python 3" 2020-04-22 17:59:25 +00:00
Zuul
a8f1045842 Merge "Fix seed VM provisioning on a remote seed hypervisor" 2020-04-22 12:38:12 +00:00
Zuul
647b19ae76 Merge "Avoid writing out requirements.txt in kolla-ansible role" 2020-04-22 00:50:45 +00:00
Zuul
eaf511adad Merge "Don't use become for Kolla Ansible" 2020-04-22 00:50:41 +00:00
Zuul
6b19b817cf Merge "CI: Test SSH connectivity to deployed instances" 2020-04-22 00:28:44 +00:00
Zuul
95a4d7e093 Merge "Add support for stopping overcloud services" 2020-04-22 00:28:40 +00:00
Radosław Piliszek
83bc574ba5 Cleanup py27 support
Removes and/or replaces all mentions of py27.

Cleans up obsolete requirements and their lower-constraints.

Update cliff minimum to 3.1.0 in requirements.txt, which has a fix for
story 2005891.

Change-Id: I52cffa2f1aee944f79c4618ea20b779755792f2a
2020-04-20 18:04:19 +00:00
Mark Goddard
dcd5159c17 Remove nameservers with any IP in overcloud resolv.conf workaround
Kayobe has a workaround for CentOS cloud images which contain a bogus
nameserver entry in /etc/resolv.conf. By setting
overcloud_host_image_workaround_resolv_enabled to true, the entry would
be removed. Previously we removed a specific IP address - 10.0.2.3 -
that was present in the CentOS 7 images. However, it seems that CentOS 8
images have a different IP - 192.168.122.1.

This change fixes the issue and becomes resilient to future changes by
matching any IP address. This should be fairly safe, since this
workaround is opt-in.

Change-Id: I9323a38cb2bb627ff56f5713900be00595ea8d4b
Story: 2006574
Task: 39484
2020-04-20 16:06:41 +01:00
Mark Goddard
8bed623571 Fix passwords.yml generation with vault encryption on Python 3
Kayobe generates passwords.yml for Kolla Ansible, and can encrypt it
using the vault password. Previously this was failing on Python 3 due to
passing a string to file.write() which expects bytes.

This change fixes the issue by encoding the password string passed to
file.write().

This allows us to run the ansible role tests under Python 3.

Change-Id: I33813f79984a46f1967ef3aee455dcfbe7eb93da
Story: 2006574
Task: 39481
2020-04-20 15:42:22 +01:00
Pierre Riteau
27779992b1 Use upper constraints when installing Tenks
Backport: train, stein, rocky

This fixes issues seen with a-universe-from-nothing using stable/train.

Change-Id: Ib477de5f3af2e4c182d0c2999c274dbb5553531c
Story: 2007572
Task: 39469
2020-04-19 15:30:36 +02:00
Mark Goddard
28a5b92be5 Docs: fix reference to deprecated external_net_name
Use the modern variable in the documented example.

Change-Id: I24560bf22cea28c1afc488c9abf9ea421a0286ad
2020-04-17 15:43:30 +01:00
Mark Goddard
58db0ed2e0 Avoid writing out requirements.txt in kolla-ansible role
We can use the Ansible pip module's support for specifying a list of
packages with version constraints.

Change-Id: If5d3c7117175732c54e38025692eb4c036053ebc
2020-04-17 11:14:49 +01:00
Mark Goddard
073499f322 Allow OVS bridges to connect directly to interface
Currently we require a Linux bridge to exist between OVS and the
physical interface. This is necessary if you want to set an IP on the
native VLAN of that interface, but that is not always the case.

This change allows the physical interface (or any non-bridge interface)
to be plugged into OVS.

Change-Id: I2172a74f4719605f6ec81fadec46ce49f8310a96
Story: 2007364
Task: 38920
2020-04-17 10:51:13 +01:00
Mark Goddard
97cd65dd63 Docs: Ansible tuning
Adds information on tuning Ansible, including forks, SSH pipelining and
fact caching.

Change-Id: I83d1469c62d63390222750d9d1f6e337e45b2373
Story: 2007492
Task: 39447
2020-04-17 10:00:27 +02:00
Mark Goddard
40e43e235d Run kolla-ansible bootstrap-servers as kolla user
Previously, Kayobe used Kolla Ansible's bootstrap-servers command to
create a user account and Python virtual environment for Kolla Ansible.
In order to do this it used the Kayobe Ansible user and Python
interpreter.

This causes problems for Ansible fact caching, which needs separate
caches for Kayobe and Kolla Ansible, since the different users and
Python interpreters used result in different facts. Bootstrapping
servers with the Kayobe user and interpreter resulted in the Kolla
Ansible fact cache being populated with Kayobe's user and interpreter.

This change disables user creation during Kolla Ansible's
bootstrap-servers command, instead creating the user and virtual
environment in Kayobe prior to running the command. This allows the
bootstrap-servers command to be executed using the normal Kolla Ansible
user and interpreter, which results in the correct facts being gathered.

The downside here is some duplication of code and configuration, but a
nice side effect is that we no longer need to dump configuration in the
CLI for host configure in order to fetch the Ansible user and
interpreter.

Change-Id: I85670be7242bc436f73c689f027670b0938ba031
Story: 2007492
Task: 39444
2020-04-16 20:44:34 +01:00
Mark Goddard
92a437f63c CI: Add overcloud host configure job
Tests various non-default configuration:

* Custom users
* Network interfaces, VLANs, bridges, bonds
* Software RAID
* LVM & docker devicemapper
* timezone
* Package mirrors
* yum-cron / DNF automatic

This improved test coverage allows us to be more confident about these
features working on CentOS 8.

Change-Id: I36148e4356deb7d5ec00d8d3ebeb2d3932ff4f94
Story: 2006574
Task: 38938
2020-04-16 15:44:49 +00:00
Mark Goddard
e0932bd788 Update inventory templates for Ussuri
Sync with kolla-ansible multinode inventory.

Change-Id: I30bd5286c4783fce544c41e726efc5f800d6f56a
2020-04-16 16:44:23 +01:00
Zuul
c31870591d Merge "Prevent openrc files from using wrong OS_CACERT value" 2020-04-15 17:27:33 +00:00
Zuul
ca2dc0e585 Merge "CentOS 8: seed VM & bifrost" 2020-04-15 16:28:47 +00:00
Zuul
bac385ad9e Merge "Docs: Configure firewall to allow testing of baremetal" 2020-04-15 16:23:36 +00:00
Zuul
c069d95099 Merge "Update documentation for release tasks" 2020-04-15 16:23:32 +00:00
Zuul
9d5a671f3c Merge "Filter out switch port descriptions on Ruckus switches" 2020-04-09 15:33:41 +00:00
Mark Goddard
51b84b6001 CentOS 8: seed VM & bifrost
* Change default seed VM image to CentOS 8
* Change default bifrost deploy image to CentOS 8
* Workaround DIB bug
  https://bugs.launchpad.net/diskimage-builder/+bug/1866847 by setting
  DIB_DISABLE_KERNEL_CLEANUP to 1
* Install iptables on seed for SNAT - missing on CentOS 8
* Fix provider network MTU lookup for empty string
* Bump stackhpc.libvirt-host to 1.7.0 for CentOS 8 support
* Bump stackhpc.libvirt-vm to 1.13.0 for CentOS 8 support
* Bump jriguera.configdrive for Python 3 support

Change-Id: Ie0edf6a924a914395c6502e2d5cf1139bce14a48
Story: 2006574
Task: 39000
2020-04-09 14:04:22 +00:00
Pierre Riteau
010681d7d9 Filter out switch port descriptions on Ruckus switches
Some Ruckus switches, e.g. the Ruckus ICX 7150, advertise switch
interface names as switch port descriptions. Unlike Dell switches, there
is no space character between port type and port number. For example:
GigabitEthernet1/1/9.

Update regular expression to match both styles.

Change-Id: I359b07abadc8665ff0a8c3407ca0fc5effc504cf
Story: 2007532
Task: 39343
2020-04-09 08:35:45 +02:00
Pierre Riteau
cc3d27e2e1 Fix seed VM provisioning on a remote seed hypervisor
The seed VM will fail to provision if the Ansible control host and the
seed hypervisor are not the same hosts.

This is because Kayobe creates the seed-vm-user-data file on the
seed-hypervisor host. It then invokes the jriguera.configdrive role
which uses a copy task without remote_src, which fails to find the
source file locally on the Ansible control host.

Instead we create a local temporary file for seed VM user data.

Change-Id: Iabbe4c624b9ad02bb82c323070f99c16e5822966
Story: 2007530
Task: 39338
2020-04-08 19:02:19 +02:00
Mark Goddard
e924c99c52 Avoid unconditional fact gathering
One way to improve the performance of Ansible is through fact caching.
Rather than gather facts in every play, we can configure Ansible to
cache them in a persistent store. An example Ansible configuration for
doing this is as follows:

[defaults]
gathering = smart
fact_caching = jsonfile
fact_caching_connection = ./facts
fact_caching_timeout = 86400

While this mostly just works, there are a few places where we
unconditionally gather facts using the setup module. This change
modifies these to only gather facts when necessary.

We no longer execute the MichaelRigart.interfaces role using become:
true, since it may gather facts and we do not want it to do so as root.
The role uses become where necessary.

Change-Id: I9984a187fc6c0496ada489bb8eef36e44d695aac
Story: 2007492
Task: 39216
2020-04-08 16:56:32 +00:00
Mark Goddard
9475e05e30 Add kolla_enable_openstack_core variable
Adds a new variable, 'kolla_enable_openstack_core', which can be set a
default value for whether the default OpenStack services are enabled.
This includes Glance, Heat, Horizon, Ironic, Keystone, Neutron and Nova.
It is 'true' by default.

Change-Id: I7768d3a92272d4353522dbf1a96f124225f4d73d
Story: 2007524
Task: 39315
2020-04-06 16:32:42 +00:00
Pierre Riteau
ce212cc23c Prevent openrc files from using wrong OS_CACERT value
Kolla Ansible sets kolla_{external,internal}_fqdn_cacert variables with
default values compatible with the use of `kolla-ansible certificates`.

However, when these variables are left unset in Kayobe, which is
generally the case when using trusted certificates, we end up with
openrc files setting OS_CACERT to a file that does not exist:

    ${KOLLA_CONFIG_PATH}/certificates/haproxy-ca.crt

Instead we allow null cacert variables to be passed to kolla-ansible,
which results in openrc files without the bogus OS_CACERT entry.

Change-Id: Ifa615888b6d8d54c9e6314fd90f3fc4872fc6e5a
Story: 2007516
Task: 39299
2020-04-03 17:17:24 +02:00