Update Centos 7 devstack images
[releng/builder.git] / jjb / integration / integration-deploy-openstack-run-test.sh
1 #!/bin/bash
2 # Activate robotframework virtualenv
3 # ${ROBOT_VENV} comes from the integration-install-robotframework.sh
4 # script.
5 # shellcheck source=${ROBOT_VENV}/bin/activate disable=SC1091
6 source ${ROBOT_VENV}/bin/activate
7 source /tmp/common-functions.sh ${BUNDLEFOLDER}
8
9 PYTHON="${ROBOT_VENV}/bin/python"
10 SSH="ssh -t -t"
11 ADMIN_PASSWORD="admin"
12 OPENSTACK_MASTER_CLIENTS_VERSION="queens"
13
14 pip install odltools
15 odltools -V
16
17 # TODO: remove this work to run changes.py if/when it's moved higher up to be visible at the Robot level
18 printf "\nshowing recent changes that made it into the distribution used by this job:\n"
19 $PYTHON -m pip install --upgrade urllib3
20 python ${WORKSPACE}/test/tools/distchanges/changes.py -d /tmp/distribution_folder \
21                   -u ${ACTUAL_BUNDLE_URL} -b ${DISTROBRANCH} \
22                   -r ssh://jenkins-${SILO}@git.opendaylight.org:29418 || true
23
24 printf "\nshowing recent changes that made it into integration/test used by this job:\n"
25 cd ${WORKSPACE}/test
26 printf "Hash    Author Date                    Commit Date                    Author               Subject\n"
27 printf "%s\n" "------- ------------------------------ ------------------------------ -------------------- -----------------------------"
28 git --no-pager log --pretty=format:'%h %<(30)%ad %<(30)%cd %<(20,trunc)%an%d %s' -n20
29 printf "\n"
30 cd -
31
32 cat << EOF
33 #################################################
34 ##         Deploy Openstack 3-node             ##
35 #################################################
36 EOF
37
38 # Catch command errors and collect logs.
39 # This ensures logs are collected when script commands fail rather than simply exiting.
40 function trap_handler() {
41     local prog="$0"
42     local lastline="$1"
43     local lasterr="$2"
44     echo "trap_hanlder: ${prog}: line ${lastline}: exit status of last command: ${lasterr}"
45     echo "trap_handler: command: ${BASH_COMMAND}"
46     exit 1
47 } # trap_handler()
48
49 trap 'trap_handler ${LINENO} ${$?}' ERR
50
51 print_job_parameters
52
53 function create_etc_hosts() {
54     NODE_IP=$1
55     CTRL_IP=$2
56     : > ${WORKSPACE}/hosts_file
57     for iter in `seq 1 ${NUM_OPENSTACK_COMPUTE_NODES}`
58     do
59         COMPUTE_IP=OPENSTACK_COMPUTE_NODE_${iter}_IP
60         if [ "${!COMPUTE_IP}" == "${NODE_IP}" ]; then
61            CONTROL_HNAME=$(${SSH}  ${CTRL_IP}  "hostname")
62            echo "${CTRL_IP}   ${CONTROL_HNAME}" >> ${WORKSPACE}/hosts_file
63         else
64            COMPUTE_HNAME=$(${SSH}  ${!COMPUTE_IP}  "hostname")
65            echo "${!COMPUTE_IP}   ${COMPUTE_HNAME}" >> ${WORKSPACE}/hosts_file
66         fi
67     done
68
69     echo "Created the hosts file for ${NODE_IP}:"
70     cat ${WORKSPACE}/hosts_file
71 } # create_etc_hosts()
72
73 #function to install Openstack Clients for Testing
74 #This will pull the latest versions compatiable with the
75 # openstack release
76 function install_openstack_clients_in_robot_vm() {
77     packages=("python-novaclient" "python-neutronclient" "python-openstackclient")
78     local os_plugins
79     os_plugins=$(csv2ssv "${ENABLE_OS_PLUGINS}")
80     for plugin_name in $os_plugins; do
81         if [ "$plugin_name" == "networking-sfc" ]; then
82             packages+=("networking-sfc")
83         fi
84     done
85     openstack_version=$(echo ${OPENSTACK_BRANCH} | cut -d/ -f2)
86     #If the job tests "master", we will use the clients from previous released stable version to avoid failures
87     if [ "${openstack_version}" == "master" ]; then
88        openstack_version=${OPENSTACK_MASTER_CLIENTS_VERSION}
89     fi
90     for package in ${packages[*]}; do
91        echo "Get the current support version of the package ${package}"
92        wget https://raw.githubusercontent.com/openstack/requirements/stable/${openstack_version}/upper-constraints.txt -O /tmp/constraints.txt 2>/dev/null
93        echo "$PYTHON -m pip install --upgrade --no-deps ${package} --no-cache-dir -c /tmp/constraints.txt"
94        $PYTHON -m pip install --upgrade --no-deps ${package} --no-cache-dir -c /tmp/constraints.txt
95        echo "$PYTHON -m pip install ${package} --no-cache-dir -c /tmp/constraints.txt"
96        $PYTHON -m pip install ${package} --no-cache-dir -c /tmp/constraints.txt
97     done
98
99     if [ "${ENABLE_NETWORKING_L2GW}" == "yes" ]; then
100         #networking-l2gw is not officially available in any release yet. Getting the latest stable version.
101         $PYTHON -m pip install networking-l2gw==11.0.0
102     fi
103 }
104
105 function is_openstack_feature_enabled() {
106     local feature=$1
107     for enabled_feature in $(csv2ssv ${ENABLE_OS_SERVICES})
108     do
109         if [ "${enabled_feature}" == "${feature}" ]; then
110            echo 1
111            return
112         fi
113     done
114     echo 0
115 }
116
117 #Function to install rdo release
118 # This will help avoiding installing wrong version of packages which causes
119 # functionality failures
120 function install_rdo_release() {
121     local ip=$1
122     case ${OPENSTACK_BRANCH} in
123        *pike*)
124           ${SSH} ${ip} "sudo yum install -y https://repos.fedorapeople.org/repos/openstack/openstack-pike/rdo-release-pike-1.noarch.rpm"
125           ;;
126
127        *queens*)
128           ${SSH} ${ip} "sudo yum install -y https://repos.fedorapeople.org/repos/openstack/openstack-queens/rdo-release-queens-1.noarch.rpm"
129           ;;
130
131        master)
132           ${SSH} ${ip} "sudo yum install -y https://repos.fedorapeople.org/repos/openstack/openstack-queens/rdo-release-queens-1.noarch.rpm"
133           ;;
134     esac
135 }
136
137 # Involves just setting up the shared directory
138 function setup_live_migration_control() {
139     local control_ip=$1
140     printf "${control_ip}:Setup directory Share with NFS"
141     cat > ${WORKSPACE}/setup_live_migration_control.sh << EOF
142 sudo mkdir --mode=777 /vm_instances
143 sudo chown -R jenkins:jenkins /vm_instances
144 sudo yum install -y nfs-utils
145 printf "/vm_instances *(rw,no_root_squash)" | sudo tee -a /etc/exports
146 sudo systemctl start rpcbind nfs-server
147 sudo exportfs
148 EOF
149     scp ${WORKSPACE}/setup_live_migration_control.sh ${control_ip}:/tmp/setup_live_migration_control.sh
150     ssh ${control_ip} "bash /tmp/setup_live_migration_control.sh"
151 }
152
153 # Involves mounting the share and configuring the libvirtd
154 function setup_live_migration_compute() {
155     local compute_ip=$1
156     local control_ip=$2
157     printf "${compute_ip}:Mount Shared directory from ${control_ip}"
158     printf "${compute_ip}:Configure libvirt in listen mode"
159     cat >  ${WORKSPACE}/setup_live_migration_compute.sh << EOF
160 sudo yum install -y libvirt libvirt-devel nfs-utils
161 sudo crudini --verbose  --set --inplace /etc/libvirt/libvirtd.conf '' listen_tls 0
162 sudo crudini --verbose  --set --inplace /etc/libvirt/libvirtd.conf '' listen_tcp 1
163 sudo crudini --verbose  --set --inplace /etc/libvirt/libvirtd.conf '' auth_tcp '"none"'
164 sudo crudini --verbose  --set --inplace /etc/sysconfig/libvirtd '' LIBVIRTD_ARGS '"--listen"'
165 sudo mkdir --mode=777 -p /var/instances
166 sudo chown -R jenkins:jenkins /var/instances
167 sudo chmod o+x /var/instances
168 sudo systemctl start rpcbind
169 sudo mount -t nfs ${control_ip}:/vm_instances /var/instances
170 sudo mount
171 EOF
172     scp ${WORKSPACE}/setup_live_migration_compute.sh ${compute_ip}:/tmp/setup_live_migration_compute.sh
173     ssh ${compute_ip} "bash /tmp/setup_live_migration_compute.sh"
174 }
175
176 # Add enable_services and disable_services to the local.conf
177 function add_os_services() {
178     local core_services=$1
179     local enable_services=$2
180     local disable_services=$3
181     local local_conf_file_name=$4
182     local enable_network_services=$5
183
184     cat >> ${local_conf_file_name} << EOF
185 enable_service $(csv2ssv "${core_services}")
186 EOF
187     if [ -n "${enable_services}" ]; then
188         cat >> ${local_conf_file_name} << EOF
189 enable_service $(csv2ssv "${enable_services}")
190 EOF
191     fi
192     if [ -n "${disable_services}" ]; then
193         cat >> ${local_conf_file_name} << EOF
194 disable_service $(csv2ssv "${disable_services}")
195 EOF
196     fi
197     if [ -n "${enable_network_services}" ]; then
198         cat >> ${local_conf_file_name} << EOF
199 enable_service $(csv2ssv "${enable_network_services}")
200 EOF
201     fi
202 }
203
204 function create_control_node_local_conf() {
205     HOSTIP=$1
206     MGRIP=$2
207     ODL_OVS_MANAGERS="$3"
208
209     local_conf_file_name=${WORKSPACE}/local.conf_control_${HOSTIP}
210     cat > ${local_conf_file_name} << EOF
211 [[local|localrc]]
212 LOGFILE=stack.sh.log
213 LOG_COLOR=False
214 USE_SYSTEMD=True
215 RECLONE=${RECLONE}
216 # Increase the wait used by stack to poll for services
217 SERVICE_TIMEOUT=120
218
219 disable_all_services
220 EOF
221
222     add_os_services "${CORE_OS_CONTROL_SERVICES}" "${ENABLE_OS_SERVICES}" "${DISABLE_OS_SERVICES}" "${local_conf_file_name}" "${ENABLE_OS_NETWORK_SERVICES}"
223
224     cat >> ${local_conf_file_name} << EOF
225
226 HOST_IP=${HOSTIP}
227 SERVICE_HOST=\$HOST_IP
228 Q_ML2_TENANT_NETWORK_TYPE=${TENANT_NETWORK_TYPE}
229 NEUTRON_CREATE_INITIAL_NETWORKS=${CREATE_INITIAL_NETWORKS}
230
231 ODL_MODE=manual
232 ODL_MGR_IP=${MGRIP}
233 ODL_PORT=${ODL_PORT}
234 ODL_PORT_BINDING_CONTROLLER=${ODL_ML2_PORT_BINDING}
235 ODL_OVS_MANAGERS=${ODL_OVS_MANAGERS}
236
237 MYSQL_HOST=\$SERVICE_HOST
238 RABBIT_HOST=\$SERVICE_HOST
239 GLANCE_HOSTPORT=\$SERVICE_HOST:9292
240 KEYSTONE_AUTH_HOST=\$SERVICE_HOST
241 KEYSTONE_SERVICE_HOST=\$SERVICE_HOST
242
243 ADMIN_PASSWORD=${ADMIN_PASSWORD}
244 DATABASE_PASSWORD=${ADMIN_PASSWORD}
245 RABBIT_PASSWORD=${ADMIN_PASSWORD}
246 SERVICE_TOKEN=${ADMIN_PASSWORD}
247 SERVICE_PASSWORD=${ADMIN_PASSWORD}
248
249 NEUTRON_LBAAS_SERVICE_PROVIDERV2=${LBAAS_SERVICE_PROVIDER} # Only relevant if neutron-lbaas plugin is enabled
250 NEUTRON_SFC_DRIVERS=${ODL_SFC_DRIVER} # Only relevant if networking-sfc plugin is enabled
251 NEUTRON_FLOWCLASSIFIER_DRIVERS=${ODL_SFC_DRIVER} # Only relevant if networking-sfc plugin is enabled
252 ETCD_PORT=2379
253 PUBLIC_BRIDGE=${PUBLIC_BRIDGE}
254 PUBLIC_PHYSICAL_NETWORK=${PUBLIC_PHYSICAL_NETWORK}
255 ML2_VLAN_RANGES=${PUBLIC_PHYSICAL_NETWORK}
256 ODL_PROVIDER_MAPPINGS=${ODL_PROVIDER_MAPPINGS}
257 EOF
258     if [ "${TENANT_NETWORK_TYPE}" == "local" ]; then
259         cat >> ${local_conf_file_name} << EOF
260 ENABLE_TENANT_TUNNELS=false
261 EOF
262     fi
263
264     if [ "${ODL_ML2_DRIVER_VERSION}" == "v2" ]; then
265         echo "ODL_V2DRIVER=True" >> ${local_conf_file_name}
266     fi
267     IFS=,
268     for plugin_name in ${ENABLE_OS_PLUGINS}; do
269         if [ "$plugin_name" == "networking-odl" ]; then
270             ENABLE_PLUGIN_ARGS="${ODL_ML2_DRIVER_REPO} ${ODL_ML2_BRANCH}"
271         elif [ "$plugin_name" == "kuryr-kubernetes" ]; then
272             ENABLE_PLUGIN_ARGS="${DEVSTACK_KUBERNETES_PLUGIN_REPO} master" # note: kuryr-kubernetes only exists in master at the moment
273         elif [ "$plugin_name" == "neutron-lbaas" ]; then
274             ENABLE_PLUGIN_ARGS="${DEVSTACK_LBAAS_PLUGIN_REPO} ${OPENSTACK_BRANCH}"
275             IS_LBAAS_PLUGIN_ENABLED="yes"
276         elif [ "$plugin_name" == "networking-sfc" ]; then
277             ENABLE_PLUGIN_ARGS="${DEVSTACK_NETWORKING_SFC_PLUGIN_REPO} master"
278             IS_SFC_PLUGIN_ENABLED="yes"
279         else
280             echo "Error: Invalid plugin $plugin_name, unsupported"
281             continue
282         fi
283         cat >> ${local_conf_file_name} << EOF
284
285 enable_plugin ${plugin_name} ${ENABLE_PLUGIN_ARGS}
286 EOF
287     done
288     unset IFS
289
290     if [ "${ENABLE_NETWORKING_L2GW}" == "yes" ]; then
291         cat >> ${local_conf_file_name} << EOF
292
293 enable_plugin networking-l2gw ${NETWORKING_L2GW_DRIVER} ${ODL_ML2_BRANCH}
294 NETWORKING_L2GW_SERVICE_DRIVER=L2GW:OpenDaylight:networking_odl.l2gateway.driver_v2.OpenDaylightL2gwDriver:default
295 EOF
296     fi
297
298     if [ "${ODL_ML2_DRIVER_VERSION}" == "v2" ]; then
299        SERVICE_PLUGINS="odl-router_v2"
300     else
301        SERVICE_PLUGINS="odl-router"
302     fi
303     if [ "${ENABLE_NETWORKING_L2GW}" == "yes" ]; then
304         SERVICE_PLUGINS+=", networking_l2gw.services.l2gateway.plugin.L2GatewayPlugin"
305     fi
306     if [ "${IS_LBAAS_PLUGIN_ENABLED}" == "yes" ]; then
307         SERVICE_PLUGINS+=", lbaasv2"
308     fi
309     if [ "${IS_SFC_PLUGIN_ENABLED}" == "yes" ]; then
310         SERVICE_PLUGINS+=", networking_sfc.services.flowclassifier.plugin.FlowClassifierPlugin,networking_sfc.services.sfc.plugin.SfcPlugin"
311     fi
312
313     cat >> ${local_conf_file_name} << EOF
314
315 [[post-config|\$NEUTRON_CONF]]
316 [DEFAULT]
317 service_plugins = ${SERVICE_PLUGINS}
318 log_dir = /opt/stack/logs
319
320 [[post-config|/etc/neutron/plugins/ml2/ml2_conf.ini]]
321 [agent]
322 minimize_polling=True
323
324 [ml2]
325 # Needed for VLAN provider tests - because our provider networks are always encapsulated in VXLAN (br-physnet1)
326 # MTU(1400) + VXLAN(50) + VLAN(4) = 1454 < MTU eth0/br-physnet1(1458)
327 physical_network_mtus = ${PUBLIC_PHYSICAL_NETWORK}:1400
328 path_mtu = 1458
329 EOF
330
331     if [ "${ENABLE_NETWORKING_L2GW}" == "yes" ]; then
332         cat >> ${local_conf_file_name} << EOF
333
334 [ml2_odl]
335 enable_dhcp_service = True
336 EOF
337     fi
338
339     cat >> ${local_conf_file_name} << EOF
340
341 [ml2_odl]
342 # Trigger n-odl full sync every 30 secs.
343 maintenance_interval = 30
344
345 [[post-config|/etc/neutron/dhcp_agent.ini]]
346 [DEFAULT]
347 force_metadata = True
348 enable_isolated_metadata = True
349 log_dir = /opt/stack/logs
350
351 [[post-config|/etc/nova/nova.conf]]
352 [DEFAULT]
353 force_config_drive = False
354 force_raw_images = False
355 log_dir = /opt/stack/logs
356
357 [scheduler]
358 discover_hosts_in_cells_interval = 30
359 EOF
360
361     echo "Control local.conf created:"
362     cat ${local_conf_file_name}
363 } # create_control_node_local_conf()
364
365 function create_compute_node_local_conf() {
366     HOSTIP=$1
367     SERVICEHOST=$2
368     MGRIP=$3
369     ODL_OVS_MANAGERS="$4"
370
371     local_conf_file_name=${WORKSPACE}/local.conf_compute_${HOSTIP}
372     cat > ${local_conf_file_name} << EOF
373 [[local|localrc]]
374 LOGFILE=stack.sh.log
375 LOG_COLOR=False
376 USE_SYSTEMD=True
377 RECLONE=${RECLONE}
378 # Increase the wait used by stack to poll for the nova service on the control node
379 NOVA_READY_TIMEOUT=1800
380
381 disable_all_services
382 EOF
383
384     add_os_services "${CORE_OS_COMPUTE_SERVICES}" "${ENABLE_OS_COMPUTE_SERVICES}" "${DISABLE_OS_SERVICES}" "${local_conf_file_name}"
385
386     cat >> ${local_conf_file_name} << EOF
387 HOST_IP=${HOSTIP}
388 SERVICE_HOST=${SERVICEHOST}
389 Q_ML2_TENANT_NETWORK_TYPE=${TENANT_NETWORK_TYPE}
390
391 ODL_MODE=manual
392 ODL_MGR_IP=${MGRIP}
393 ODL_PORT=${ODL_PORT}
394 ODL_PORT_BINDING_CONTROLLER=${ODL_ML2_PORT_BINDING}
395 ODL_OVS_MANAGERS=${ODL_OVS_MANAGERS}
396
397 Q_HOST=\$SERVICE_HOST
398 MYSQL_HOST=\$SERVICE_HOST
399 RABBIT_HOST=\$SERVICE_HOST
400 GLANCE_HOSTPORT=\$SERVICE_HOST:9292
401 KEYSTONE_AUTH_HOST=\$SERVICE_HOST
402 KEYSTONE_SERVICE_HOST=\$SERVICE_HOST
403
404 ADMIN_PASSWORD=${ADMIN_PASSWORD}
405 DATABASE_PASSWORD=${ADMIN_PASSWORD}
406 RABBIT_PASSWORD=${ADMIN_PASSWORD}
407 SERVICE_TOKEN=${ADMIN_PASSWORD}
408 SERVICE_PASSWORD=${ADMIN_PASSWORD}
409
410 PUBLIC_BRIDGE=${PUBLIC_BRIDGE}
411 PUBLIC_PHYSICAL_NETWORK=${PUBLIC_PHYSICAL_NETWORK}
412 ODL_PROVIDER_MAPPINGS=${ODL_PROVIDER_MAPPINGS}
413 Q_L3_ENABLED=True
414 ODL_L3=${ODL_L3}
415 EOF
416
417     if [[ "${ENABLE_OS_PLUGINS}" =~ networking-odl ]]; then
418         cat >> ${local_conf_file_name} << EOF
419
420 enable_plugin networking-odl ${ODL_ML2_DRIVER_REPO} ${ODL_ML2_BRANCH}
421 EOF
422     fi
423
424     cat >> ${local_conf_file_name} << EOF
425
426 [[post-config|/etc/nova/nova.conf]]
427 [api]
428 auth_strategy = keystone
429 [DEFAULT]
430 use_neutron = True
431 force_raw_images = False
432 log_dir = /opt/stack/logs
433 [libvirt]
434 live_migration_uri = qemu+tcp://%s/system
435 virt_type = qemu
436 EOF
437
438     echo "Compute local.conf created:"
439     cat ${local_conf_file_name}
440 } # create_compute_node_local_conf()
441
442 function configure_haproxy_for_neutron_requests() {
443     MGRIP=$1
444     # shellcheck disable=SC2206
445     ODL_IPS=(${2//,/ })
446
447     cat > ${WORKSPACE}/install_ha_proxy.sh<< EOF
448 sudo systemctl stop firewalld
449 sudo yum -y install policycoreutils-python haproxy
450 EOF
451
452 cat > ${WORKSPACE}/haproxy.cfg << EOF
453 global
454   daemon
455   group  haproxy
456   log  /dev/log local0
457   maxconn  20480
458   pidfile  /tmp/haproxy.pid
459   user  haproxy
460
461 defaults
462   log  global
463   maxconn  4096
464   mode  tcp
465   retries  3
466   timeout  http-request 10s
467   timeout  queue 1m
468   timeout  connect 10s
469   timeout  client 1m
470   timeout  server 1m
471   timeout  check 10s
472
473 listen opendaylight
474   bind ${MGRIP}:8080
475   balance source
476
477 listen opendaylight_rest
478   bind ${MGRIP}:8181
479   balance source
480
481 listen opendaylight_websocket
482   bind ${MGRIP}:8185
483   balance source
484
485 EOF
486
487     odlindex=1
488     for odlip in ${ODL_IPS[*]}; do
489         sed -i "/listen opendaylight$/a server controller-${odlindex} ${odlip}:8080 check fall 5 inter 2000 rise 2" ${WORKSPACE}/haproxy.cfg
490         sed -i "/listen opendaylight_rest$/a server controller-rest-${odlindex} ${odlip}:8181 check fall 5 inter 2000 rise 2" ${WORKSPACE}/haproxy.cfg
491         sed -i "/listen opendaylight_websocket$/a server controller-websocket-${odlindex} ${odlip}:8185 check fall 5 inter 2000 rise 2" ${WORKSPACE}/haproxy.cfg
492         odlindex=$((odlindex+1))
493     done
494
495
496     echo "Dump haproxy.cfg"
497     cat ${WORKSPACE}/haproxy.cfg
498
499     cat > ${WORKSPACE}/deploy_ha_proxy.sh<< EOF
500 sudo chown haproxy:haproxy /tmp/haproxy.cfg
501 sudo sed -i 's/\\/etc\\/haproxy\\/haproxy.cfg/\\/tmp\\/haproxy.cfg/g' /usr/lib/systemd/system/haproxy.service
502 sudo /usr/sbin/semanage permissive -a haproxy_t
503 sudo systemctl restart haproxy
504 sleep 3
505 sudo netstat -tunpl
506 sudo systemctl status haproxy
507 true
508 EOF
509
510     scp ${WORKSPACE}/install_ha_proxy.sh ${MGRIP}:/tmp
511     ${SSH} ${MGRIP} "sudo bash /tmp/install_ha_proxy.sh"
512     scp ${WORKSPACE}/haproxy.cfg ${MGRIP}:/tmp
513     scp ${WORKSPACE}/deploy_ha_proxy.sh ${MGRIP}:/tmp
514     ${SSH} ${MGRIP} "sudo bash /tmp/deploy_ha_proxy.sh"
515 } # configure_haproxy_for_neutron_requests()
516
517 # Following three functions are debugging helpers when debugging devstack changes.
518 # Keeping them for now so we can simply call them when needed.
519 ctrlhn=""
520 comp1hn=""
521 comp2hn=""
522 function get_hostnames () {
523     set +e
524     local ctrlip=${OPENSTACK_CONTROL_NODE_1_IP}
525     local comp1ip=${OPENSTACK_COMPUTE_NODE_1_IP}
526     local comp2ip=${OPENSTACK_COMPUTE_NODE_2_IP}
527     ctrlhn=$(${SSH} ${ctrlip} "hostname")
528     comp1hn=$(${SSH} ${comp1ip} "hostname")
529     comp2hn=$(${SSH} ${comp2ip} "hostname")
530     echo "hostnames: ${ctrlhn}, ${comp1hn}, ${comp2hn}"
531     set -e
532 }
533
534 function check_firewall() {
535     set +e
536     echo $-
537     local ctrlip=${OPENSTACK_CONTROL_NODE_1_IP}
538     local comp1ip=${OPENSTACK_COMPUTE_NODE_1_IP}
539     local comp2ip=${OPENSTACK_COMPUTE_NODE_2_IP}
540
541     echo "check_firewall on control"
542     ${SSH} ${ctrlip} "
543         sudo systemctl status firewalld
544         sudo systemctl -l status iptables
545         sudo iptables --line-numbers -nvL
546     " || true
547     echo "check_firewall on compute 1"
548     ${SSH} ${comp1ip} "
549         sudo systemctl status firewalld
550         sudo systemctl -l status iptables
551         sudo iptables --line-numbers -nvL
552     " || true
553     echo "check_firewall on compute 2"
554     ${SSH} ${comp2ip} "
555         sudo systemctl status firewalld
556         sudo systemctl -l status iptables
557         sudo iptables --line-numbers -nvL
558     " || true
559 }
560
561 function get_service () {
562     set +e
563     local iter=$1
564     #local idx=$2
565     local ctrlip=${OPENSTACK_CONTROL_NODE_1_IP}
566     local comp1ip=${OPENSTACK_COMPUTE_NODE_1_IP}
567
568     #if [ ${idx} -eq 1 ]; then
569         if [ ${iter} -eq 1 ] || [ ${iter} -gt 16 ]; then
570             curl http://${ctrlip}:5000
571             curl http://${ctrlip}:35357
572             curl http://${ctrlip}/identity
573             ${SSH} ${ctrlip} "
574                 source /opt/stack/devstack/openrc admin admin;
575                 env
576                 openstack configuration show --unmask;
577                 openstack service list
578                 openstack --os-cloud devstack-admin --os-region RegionOne compute service list
579                 openstack hypervisor list;
580             " || true
581             check_firewall
582         fi
583     #fi
584     set -e
585 }
586
587 # Check if rabbitmq is ready by looking for a pid in it's status.
588 # The function returns the status of the grep command which callers can check.
589 function is_rabbitmq_ready() {
590     local -r ip=${1}
591     local grepfor="nova_cell1"
592     rm -f rabbit.txt
593     ${SSH} ${ip} "sudo rabbitmqctl list_vhosts" > rabbit.txt
594     grep ${grepfor} rabbit.txt
595 }
596
597 # retry the given command ($3) until success for a number of iterations ($1)
598 # sleeping ($2) between tries.
599 function retry() {
600     local -r -i max_tries=${1}
601     local -r -i sleep_time=${2}
602     local -r cmd=${3}
603     local -i retries=1
604     local -i rc=1
605     while true; do
606         echo "retry ${cmd}: attempt: ${retries}"
607         ${cmd}
608         rc=$?
609         if ((${rc} == 0)); then
610             break;
611         else
612             if ((${retries} == ${max_tries})); then
613                 break
614             else
615                 ((retries++))
616                 sleep ${sleep_time}
617             fi
618         fi
619     done
620     return ${rc}
621 }
622
623 ODL_PROVIDER_MAPPINGS="\${PUBLIC_PHYSICAL_NETWORK}:${PUBLIC_BRIDGE}"
624 ODL_L3=False
625 RECLONE=False
626 ODL_PORT=8181
627
628 # Always compare the lists below against the devstack upstream ENABLED_SERVICES in
629 # https://github.com/openstack-dev/devstack/blob/master/stackrc#L52
630 # ODL CSIT does not use vnc, cinder, q-agt, q-l3 or horizon so they are not included below.
631 # collect performance stats
632 CORE_OS_CONTROL_SERVICES="dstat"
633 # Glance
634 CORE_OS_CONTROL_SERVICES+=",g-api,g-reg"
635 # Keystone
636 CORE_OS_CONTROL_SERVICES+=",key"
637 # Nova - services to support libvirt
638 CORE_OS_CONTROL_SERVICES+=",n-api,n-api-meta,n-cauth,n-cond,n-crt,n-obj,n-sch"
639 # ODL - services to connect to ODL
640 CORE_OS_CONTROL_SERVICES+=",odl-compute,odl-neutron"
641 # Additional services
642 CORE_OS_CONTROL_SERVICES+=",mysql,rabbit"
643
644 # collect performance stats
645 CORE_OS_COMPUTE_SERVICES="dstat"
646 # computes only need nova and odl
647 CORE_OS_COMPUTE_SERVICES+=",n-cpu,odl-compute"
648
649 cat > ${WORKSPACE}/disable_firewall.sh << EOF
650 sudo systemctl stop firewalld
651 # Open these ports to match the tutorial vms
652 # http/https (80/443), samba (445), netbios (137,138,139)
653 sudo iptables -I INPUT -p tcp -m multiport --dports 80,443,139,445 -j ACCEPT
654 sudo iptables -I INPUT -p udp -m multiport --dports 137,138 -j ACCEPT
655 # OpenStack services as well as vxlan tunnel ports 4789 and 9876
656 # identity public/admin (5000/35357), ampq (5672), vnc (6080), nova (8774), glance (9292), neutron (9696)
657 sudo sudo iptables -I INPUT -p tcp -m multiport --dports 5000,5672,6080,8774,9292,9696,35357 -j ACCEPT
658 sudo sudo iptables -I INPUT -p udp -m multiport --dports 4789,9876 -j ACCEPT
659 sudo iptables-save > /etc/sysconfig/iptables
660 sudo systemctl restart iptables
661 sudo iptables --line-numbers -nvL
662 true
663 EOF
664
665 cat > ${WORKSPACE}/get_devstack.sh << EOF
666 sudo systemctl stop firewalld
667 sudo yum install bridge-utils python-pip -y
668 #sudo systemctl stop  NetworkManager
669 #Disable NetworkManager and kill dhclient and dnsmasq
670 sudo systemctl stop NetworkManager
671 sudo killall dhclient
672 sudo killall dnsmasq
673 #Workaround for mysql failure
674 echo "127.0.0.1   localhost \${HOSTNAME}" >> /tmp/hosts
675 echo "::1         localhost \${HOSTNAME}" >> /tmp/hosts
676 sudo mv /tmp/hosts /etc/hosts
677 sudo mkdir /opt/stack
678 echo "Create RAM disk for /opt/stack"
679 sudo mount -t tmpfs -o size=2G tmpfs /opt/stack
680 sudo chmod 777 /opt/stack
681 cd /opt/stack
682 echo "git clone https://git.openstack.org/openstack-dev/devstack --branch ${OPENSTACK_BRANCH}"
683 git clone https://git.openstack.org/openstack-dev/devstack --branch ${OPENSTACK_BRANCH}
684 cd devstack
685 if [ -n "${DEVSTACK_HASH}" ]; then
686     echo "git checkout ${DEVSTACK_HASH}"
687     git checkout ${DEVSTACK_HASH}
688 fi
689 git --no-pager log --pretty=format:'%h %<(13)%ar%<(13)%cr %<(20,trunc)%an%d %s%b' -n20
690 echo
691
692 echo "workaround: do not upgrade openvswitch"
693 sudo yum install -y yum-plugin-versionlock
694 sudo yum versionlock add openvswitch
695
696 #Install qemu-img command in Control Node for Pike
697 echo "Install qemu-img application"
698 sudo yum install -y qemu-img
699 EOF
700
701 cat > "${WORKSPACE}/setup_host_cell_mapping.sh" << EOF
702 sudo nova-manage cell_v2 map_cell0
703 sudo nova-manage cell_v2 simple_cell_setup
704 sudo nova-manage db sync
705 sudo nova-manage cell_v2 discover_hosts
706 EOF
707
708 NUM_OPENSTACK_SITES=${NUM_OPENSTACK_SITES:-1}
709 compute_index=1
710 odl_index=1
711 os_node_list=()
712 os_interval=$(( ${NUM_OPENSTACK_SYSTEM} / ${NUM_OPENSTACK_SITES} ))
713 ha_proxy_index=${os_interval}
714
715 for i in `seq 1 ${NUM_OPENSTACK_SITES}`; do
716     if [ "${ENABLE_HAPROXY_FOR_NEUTRON}" == "yes" ]; then
717         echo "Configure HAProxy"
718         ODL_HAPROXYIP_PARAM=OPENSTACK_HAPROXY_${i}_IP
719         ha_proxy_index=$(( $ha_proxy_index + $os_interval ))
720         odl_index=$(((i - 1) * 3 + 1))
721         ODL_IP_PARAM1=ODL_SYSTEM_$((odl_index++))_IP
722         ODL_IP_PARAM2=ODL_SYSTEM_$((odl_index++))_IP
723         ODL_IP_PARAM3=ODL_SYSTEM_$((odl_index++))_IP
724         ODLMGRIP[$i]=${!ODL_HAPROXYIP_PARAM} # ODL Northbound uses HAProxy VIP
725         ODL_OVS_MGRS[$i]="${!ODL_IP_PARAM1},${!ODL_IP_PARAM2},${!ODL_IP_PARAM3}" # OVSDB connects to all ODL IPs
726         configure_haproxy_for_neutron_requests ${!ODL_HAPROXYIP_PARAM} "${ODL_OVS_MGRS[$i]}"
727     else
728         ODL_IP_PARAM=ODL_SYSTEM_${i}_IP
729         ODL_OVS_MGRS[$i]="${!ODL_IP_PARAM}" # ODL Northbound uses ODL IP
730         ODLMGRIP[$i]=${!ODL_IP_PARAM} # OVSDB connects to ODL IP
731     fi
732 done
733
734 # Begin stacking the nodes, starting with the controller(s) and then the compute(s)
735
736 for i in `seq 1 ${NUM_OPENSTACK_CONTROL_NODES}`; do
737     CONTROLIP=OPENSTACK_CONTROL_NODE_${i}_IP
738     echo "Configure the stack of the control node ${i} of ${NUM_OPENSTACK_CONTROL_NODES}: ${!CONTROLIP}"
739     scp ${WORKSPACE}/disable_firewall.sh ${!CONTROLIP}:/tmp
740     ${SSH} ${!CONTROLIP} "sudo bash /tmp/disable_firewall.sh"
741     create_etc_hosts ${!CONTROLIP}
742     scp ${WORKSPACE}/hosts_file ${!CONTROLIP}:/tmp/hosts
743     scp ${WORKSPACE}/get_devstack.sh ${!CONTROLIP}:/tmp
744     # devstack Master is yet to migrate fully to lib/neutron, there are some ugly hacks that is
745     # affecting the stacking.
746     # Workaround For Queens, Make the physical Network as physnet1 in lib/neutron
747     # In Queens the neutron new libs are used and do not have the following options from Pike and earlier:
748     # Q_ML2_PLUGIN_FLAT_TYPE_OPTIONS could be used for the flat_networks
749     # and Q_ML2_PLUGIN_VLAN_TYPE_OPTIONS could be used for the ml2_type_vlan
750     ${SSH} ${!CONTROLIP} "bash /tmp/get_devstack.sh > /tmp/get_devstack.sh.txt 2>&1"
751     if [ "${ODL_ML2_BRANCH}" == "stable/queens" ]; then
752        ssh ${!CONTROLIP} "sed -i 's/flat_networks public/flat_networks public,physnet1/' /opt/stack/devstack/lib/neutron"
753        ssh ${!CONTROLIP} "sed -i '186i iniset \$NEUTRON_CORE_PLUGIN_CONF ml2_type_vlan network_vlan_ranges public:1:4094,physnet1:1:4094' /opt/stack/devstack/lib/neutron"
754     fi
755     create_control_node_local_conf ${!CONTROLIP} ${ODLMGRIP[$i]} "${ODL_OVS_MGRS[$i]}"
756     scp ${WORKSPACE}/local.conf_control_${!CONTROLIP} ${!CONTROLIP}:/opt/stack/devstack/local.conf
757     echo "Install rdo release to avoid incompatible Package versions"
758     install_rdo_release ${!CONTROLIP}
759     setup_live_migration_control ${!CONTROLIP}
760     echo "Stack the control node ${i} of ${NUM_OPENSTACK_CONTROL_NODES}: ${CONTROLIP}"
761     ssh ${!CONTROLIP} "cd /opt/stack/devstack; nohup ./stack.sh > /opt/stack/devstack/nohup.out 2>&1 &"
762     ssh ${!CONTROLIP} "ps -ef | grep stack.sh"
763     ssh ${!CONTROLIP} "ls -lrt /opt/stack/devstack/nohup.out"
764     os_node_list+=("${!CONTROLIP}")
765 done
766
767 # This is a backup to the CELLSV2_SETUP=singleconductor workaround. Keeping it here as an easy lookup
768 # if needed.
769 # Let the control node get started to avoid a race condition where the computes start and try to access
770 # the nova_cell1 on the control node before it is created. If that happens, the nova-compute service on the
771 # compute exits and does not attempt to restart.
772 # 180s is chosen because in test runs the control node usually finished in 17-20 minutes and the computes finished
773 # in 17 minutes, so take the max difference of 3 minutes and the jobs should still finish around the same time.
774 # one of the following errors is seen in the compute n-cpu.log:
775 # Unhandled error: NotAllowed: Connection.open: (530) NOT_ALLOWED - access to vhost 'nova_cell1' refused for user 'stackrabbit'
776 # AccessRefused: (0, 0): (403) ACCESS_REFUSED - Login was refused using authentication mechanism AMQPLAIN. For details see the broker logfile.
777 # Compare that timestamp to this log in the control stack.log: sudo rabbitmqctl set_permissions -p nova_cell1 stackrabbit
778 # If the n-cpu.log is earlier than the control stack.log timestamp then the failure condition is likely hit.
779 if [ ${NUM_OPENSTACK_COMPUTE_NODES} -gt 0 ]; then
780     WAIT_FOR_RABBITMQ_MINUTES=60
781     echo "Wait a maximum of ${WAIT_FOR_RABBITMQ_MINUTES}m until rabbitmq is ready and nova_cell1 created to allow the controller to create nova_cell1 before the computes need it"
782     set +e
783     retry ${WAIT_FOR_RABBITMQ_MINUTES} 60 "is_rabbitmq_ready ${OPENSTACK_CONTROL_NODE_1_IP}"
784     rc=$?
785     set -e
786     if ((${rc} == 0)); then
787       echo "rabbitmq is ready, starting ${NUM_OPENSTACK_COMPUTE_NODES} compute(s)"
788     else
789       echo "rabbitmq was not ready in ${WAIT_FOR_RABBITMQ_MINUTES}m"
790       exit 1
791     fi
792 fi
793
794 for i in `seq 1 ${NUM_OPENSTACK_COMPUTE_NODES}`; do
795     NUM_COMPUTES_PER_SITE=$((NUM_OPENSTACK_COMPUTE_NODES / NUM_OPENSTACK_SITES))
796     SITE_INDEX=$((((i - 1) / NUM_COMPUTES_PER_SITE) + 1)) # We need the site index to infer the control node IP for this compute
797     COMPUTEIP=OPENSTACK_COMPUTE_NODE_${i}_IP
798     CONTROLIP=OPENSTACK_CONTROL_NODE_${SITE_INDEX}_IP
799     echo "Configure the stack of the compute node ${i} of ${NUM_OPENSTACK_COMPUTE_NODES}: ${!COMPUTEIP}"
800     scp ${WORKSPACE}/disable_firewall.sh "${!COMPUTEIP}:/tmp"
801     ${SSH} "${!COMPUTEIP}" "sudo bash /tmp/disable_firewall.sh"
802     create_etc_hosts ${!COMPUTEIP} ${!CONTROLIP}
803     scp ${WORKSPACE}/hosts_file ${!COMPUTEIP}:/tmp/hosts
804     scp ${WORKSPACE}/get_devstack.sh  ${!COMPUTEIP}:/tmp
805     ${SSH} ${!COMPUTEIP} "bash /tmp/get_devstack.sh > /tmp/get_devstack.sh.txt 2>&1"
806     create_compute_node_local_conf ${!COMPUTEIP} ${!CONTROLIP} ${ODLMGRIP[$SITE_INDEX]} "${ODL_OVS_MGRS[$SITE_INDEX]}"
807     scp ${WORKSPACE}/local.conf_compute_${!COMPUTEIP} ${!COMPUTEIP}:/opt/stack/devstack/local.conf
808     echo "Install rdo release to avoid incompatible Package versions"
809     install_rdo_release ${!COMPUTEIP}
810     setup_live_migration_compute ${!COMPUTEIP} ${!CONTROLIP}
811     echo "Stack the compute node ${i} of ${NUM_OPENSTACK_COMPUTE_NODES}: ${COMPUTEIP}"
812     ssh ${!COMPUTEIP} "cd /opt/stack/devstack; nohup ./stack.sh > /opt/stack/devstack/nohup.out 2>&1 &"
813     ssh ${!COMPUTEIP} "ps -ef | grep stack.sh"
814     os_node_list+=("${!COMPUTEIP}")
815 done
816
817 echo "nodelist: ${os_node_list[*]}"
818
819 # This script runs on the openstack nodes. It greps for a string that devstack writes when stacking is complete.
820 # The script then writes a status depending on the grep output that is later scraped by the robot vm to control
821 # the status polling.
822 cat > ${WORKSPACE}/check_stacking.sh << EOF
823 > /tmp/stack_progress
824 ps -ef | grep "stack.sh" | grep -v grep
825 ret=\$?
826 if [ \${ret} -eq 1 ]; then
827     grep "This is your host IP address:" /opt/stack/devstack/nohup.out
828     if [ \$? -eq 0 ]; then
829         echo "Stacking Complete" > /tmp/stack_progress
830     else
831         echo "Stacking Failed" > /tmp/stack_progress
832     fi
833 elif [ \${ret} -eq 0 ]; then
834     echo "Still Stacking" > /tmp/stack_progress
835 fi
836 EOF
837
838 # devstack debugging
839 # get_hostnames
840
841 # Check if the stacking is finished. Poll all nodes every 60s for one hour.
842 iteration=0
843 in_progress=1
844 while [ ${in_progress} -eq 1 ]; do
845     iteration=$(($iteration + 1))
846     for index in "${!os_node_list[@]}"; do
847         echo "node $index ${os_node_list[index]}: checking stacking status attempt ${iteration} of 60"
848         scp ${WORKSPACE}/check_stacking.sh  ${os_node_list[index]}:/tmp
849         ${SSH} ${os_node_list[index]} "bash /tmp/check_stacking.sh"
850         scp ${os_node_list[index]}:/tmp/stack_progress .
851         cat stack_progress
852         stacking_status=`cat stack_progress`
853         # devstack debugging
854         # get_service "${iteration}" "${index}"
855         if [ "$stacking_status" == "Still Stacking" ]; then
856             continue
857         elif [ "$stacking_status" == "Stacking Failed" ]; then
858             echo "node $index ${os_node_list[index]}: stacking has failed"
859             exit 1
860         elif [ "$stacking_status" == "Stacking Complete" ]; then
861             echo "node $index ${os_node_list[index]}: stacking complete"
862             unset 'os_node_list[index]'
863             if  [ ${#os_node_list[@]} -eq 0 ]; then
864                 in_progress=0
865             fi
866         fi
867     done
868     echo "sleep for a minute before the next check"
869     sleep 60
870     if [ ${iteration} -eq 60 ]; then
871         echo "stacking has failed - took longer than 60m"
872         exit 1
873     fi
874 done
875
876 # Further configuration now that stacking is complete.
877 NUM_COMPUTES_PER_SITE=$((NUM_OPENSTACK_COMPUTE_NODES / NUM_OPENSTACK_SITES))
878 for i in `seq 1 ${NUM_OPENSTACK_SITES}`; do
879     echo "Configure the Control Node"
880     CONTROLIP=OPENSTACK_CONTROL_NODE_${i}_IP
881     # Gather Compute IPs for the site
882     for j in `seq 1 ${NUM_COMPUTES_PER_SITE}`; do
883         COMPUTE_INDEX=$(((i-1) * NUM_COMPUTES_PER_SITE + j))
884         IP_VAR=OPENSTACK_COMPUTE_NODE_${COMPUTE_INDEX}_IP
885         COMPUTE_IPS[$((j-1))]=${!IP_VAR}
886     done
887
888     echo "sleep for 60s and print hypervisor-list"
889     sleep 60
890     ${SSH} ${!CONTROLIP} "cd /opt/stack/devstack; source openrc admin admin; nova hypervisor-list"
891     # in the case that we are doing openstack (control + compute) all in one node, then the number of hypervisors
892     # will be the same as the number of openstack systems. However, if we are doing multinode openstack then the
893     # assumption is we have a single control node and the rest are compute nodes, so the number of expected hypervisors
894     # is one less than the total number of openstack systems
895     if [ $((NUM_OPENSTACK_SYSTEM / NUM_OPENSTACK_SITES)) -eq 1 ]; then
896         expected_num_hypervisors=1
897     else
898         expected_num_hypervisors=${NUM_COMPUTES_PER_SITE}
899     fi
900     num_hypervisors=$(${SSH} ${!CONTROLIP} "cd /opt/stack/devstack; source openrc admin admin; openstack hypervisor list -f value | wc -l" | tail -1 | tr -d "\r")
901     if ! [ "${num_hypervisors}" ] || ! [ ${num_hypervisors} -eq ${expected_num_hypervisors} ]; then
902         echo "Error: Only $num_hypervisors hypervisors detected, expected $expected_num_hypervisors"
903         exit 1
904     fi
905
906     # Gather Compute IPs for the site
907     for j in `seq 1 ${NUM_COMPUTES_PER_SITE}`; do
908         COMPUTE_INDEX=$(((i-1) * NUM_COMPUTES_PER_SITE + j))
909         IP_VAR=OPENSTACK_COMPUTE_NODE_${COMPUTE_INDEX}_IP
910         COMPUTE_IPS[$((j-1))]=${!IP_VAR}
911     done
912
913     # External Network
914     echo "prepare external networks by adding vxlan tunnels between all nodes on a separate bridge..."
915     # FIXME Should there be a unique gateway IP and devstack index for each site?
916     devstack_index=1
917     for ip in ${!CONTROLIP} ${COMPUTE_IPS[*]}; do
918         # FIXME - Workaround, ODL (new netvirt) currently adds PUBLIC_BRIDGE as a port in br-int since it doesn't see such a bridge existing when we stack
919         ${SSH} $ip "sudo ovs-vsctl --if-exists del-port br-int $PUBLIC_BRIDGE"
920         ${SSH} $ip "sudo ovs-vsctl --may-exist add-br $PUBLIC_BRIDGE -- set bridge $PUBLIC_BRIDGE other-config:disable-in-band=true other_config:hwaddr=f6:00:00:ff:01:0$((devstack_index++))"
921     done
922
923     # ipsec support
924     if [ "${IPSEC_VXLAN_TUNNELS_ENABLED}" == "yes" ]; then
925         # shellcheck disable=SC2206
926         ALL_NODES=(${!CONTROLIP} ${COMPUTE_IPS[*]})
927         for ((inx_ip1=0; inx_ip1<$((${#ALL_NODES[@]} - 1)); inx_ip1++)); do
928             for ((inx_ip2=$((inx_ip1 + 1)); inx_ip2<${#ALL_NODES[@]}; inx_ip2++)); do
929                 KEY1=0x$(dd if=/dev/urandom count=32 bs=1 2> /dev/null| xxd -p -c 64)
930                 KEY2=0x$(dd if=/dev/urandom count=32 bs=1 2> /dev/null| xxd -p -c 64)
931                 ID=0x$(dd if=/dev/urandom count=4 bs=1 2> /dev/null| xxd -p -c 8)
932                 ip1=${ALL_NODES[$inx_ip1]}
933                 ip2=${ALL_NODES[$inx_ip2]}
934                 ${SSH} $ip1 "sudo ip xfrm state add src $ip1 dst $ip2 proto esp spi $ID reqid $ID mode transport auth sha256 $KEY1 enc aes $KEY2"
935                 ${SSH} $ip1 "sudo ip xfrm state add src $ip2 dst $ip1 proto esp spi $ID reqid $ID mode transport auth sha256 $KEY1 enc aes $KEY2"
936                 ${SSH} $ip1 "sudo ip xfrm policy add src $ip1 dst $ip2 proto udp dir out tmpl src $ip1 dst $ip2 proto esp reqid $ID mode transport"
937                 ${SSH} $ip1 "sudo ip xfrm policy add src $ip2 dst $ip1 proto udp dir in tmpl src $ip2 dst $ip1 proto esp reqid $ID mode transport"
938
939                 ${SSH} $ip2 "sudo ip xfrm state add src $ip2 dst $ip1 proto esp spi $ID reqid $ID mode transport auth sha256 $KEY1 enc aes $KEY2"
940                 ${SSH} $ip2 "sudo ip xfrm state add src $ip1 dst $ip2 proto esp spi $ID reqid $ID mode transport auth sha256 $KEY1 enc aes $KEY2"
941                 ${SSH} $ip2 "sudo ip xfrm policy add src $ip2 dst $ip1 proto udp dir out tmpl src $ip2 dst $ip1 proto esp reqid $ID mode transport"
942                 ${SSH} $ip2 "sudo ip xfrm policy add src $ip1 dst $ip2 proto udp dir in tmpl src $ip1 dst $ip2 proto esp reqid $ID mode transport"
943             done
944         done
945
946         for ip in ${!CONTROLIP} ${COMPUTE_IPS[*]}; do
947             echo "ip xfrm configuration for node $ip:"
948             ${SSH} $ip "sudo ip xfrm policy list"
949             ${SSH} $ip "sudo ip xfrm state list"
950         done
951     fi
952
953     # Control Node - PUBLIC_BRIDGE will act as the external router
954     # Parameter values below are used in integration/test - changing them requires updates in intergration/test as well
955     EXTNET_GATEWAY_IP="10.10.10.250"
956     EXTNET_INTERNET_IP="10.9.9.9"
957     EXTNET_PNF_IP="10.10.10.253"
958     ${SSH} ${!CONTROLIP} "sudo ifconfig ${PUBLIC_BRIDGE} up ${EXTNET_GATEWAY_IP}/24"
959
960     # Control Node - external net PNF simulation
961     ${SSH} ${!CONTROLIP} "
962         sudo ip netns add pnf_ns;
963         sudo ip link add pnf_veth0 type veth peer name pnf_veth1;
964         sudo ip link set pnf_veth1 netns pnf_ns;
965         sudo ip link set pnf_veth0 up;
966         sudo ip netns exec pnf_ns ifconfig pnf_veth1 up ${EXTNET_PNF_IP}/24;
967         sudo ovs-vsctl add-port ${PUBLIC_BRIDGE} pnf_veth0;
968     "
969
970     # Control Node - external net internet address simulation
971     ${SSH} ${!CONTROLIP} "
972         sudo ip tuntap add dev internet_tap mode tap;
973         sudo ifconfig internet_tap up ${EXTNET_INTERNET_IP}/24;
974     "
975
976     # Computes
977     compute_index=1
978     for compute_ip in ${COMPUTE_IPS[*]}; do
979         # Tunnel from controller to compute
980         COMPUTEPORT=compute$(( compute_index++ ))_vxlan
981         ${SSH} ${!CONTROLIP} "
982             sudo ovs-vsctl add-port $PUBLIC_BRIDGE $COMPUTEPORT -- set interface $COMPUTEPORT type=vxlan options:local_ip=${!CONTROLIP} options:remote_ip=$compute_ip options:dst_port=9876 options:key=flow
983         "
984         # Tunnel from compute to controller
985         CONTROLPORT="control_vxlan"
986         ${SSH} $compute_ip "
987             sudo ovs-vsctl add-port $PUBLIC_BRIDGE $CONTROLPORT -- set interface $CONTROLPORT type=vxlan options:local_ip=$compute_ip options:remote_ip=${!CONTROLIP} options:dst_port=9876 options:key=flow
988         "
989     done
990 done
991
992 if [ "${ENABLE_HAPROXY_FOR_NEUTRON}" == "yes" ]; then
993     odlmgrip=OPENSTACK_HAPROXY_1_IP
994     HA_PROXY_IP=${!odlmgrip}
995     HA_PROXY_1_IP=${!odlmgrip}
996     odlmgrip2=OPENSTACK_HAPROXY_2_IP
997     HA_PROXY_2_IP=${!odlmgrip2}
998     odlmgrip3=OPENSTACK_HAPROXY_1_IP
999     HA_PROXY_3_IP=${!odlmgrip3}
1000 else
1001     HA_PROXY_IP=${ODL_SYSTEM_IP}
1002     HA_PROXY_1_IP=${ODL_SYSTEM_1_IP}
1003     HA_PROXY_2_IP=${ODL_SYSTEM_2_IP}
1004     HA_PROXY_3_IP=${ODL_SYSTEM_3_IP}
1005 fi
1006
1007 echo "Locating test plan to use..."
1008 testplan_filepath="${WORKSPACE}/test/csit/testplans/${STREAMTESTPLAN}"
1009 if [ ! -f "${testplan_filepath}" ]; then
1010     testplan_filepath="${WORKSPACE}/test/csit/testplans/${TESTPLAN}"
1011 fi
1012
1013 echo "Changing the testplan path..."
1014 cat "${testplan_filepath}" | sed "s:integration:${WORKSPACE}:" > testplan.txt
1015 cat testplan.txt
1016
1017 # Use the testplan if specific SUITES are not defined.
1018 if [ -z "${SUITES}" ]; then
1019     SUITES=`egrep -v '(^[[:space:]]*#|^[[:space:]]*$)' testplan.txt | tr '\012' ' '`
1020 else
1021     newsuites=""
1022     workpath="${WORKSPACE}/test/csit/suites"
1023     for suite in ${SUITES}; do
1024         fullsuite="${workpath}/${suite}"
1025         if [ -z "${newsuites}" ]; then
1026             newsuites+=${fullsuite}
1027         else
1028             newsuites+=" "${fullsuite}
1029         fi
1030     done
1031     SUITES=${newsuites}
1032 fi
1033
1034 #install all client versions required for this job testing
1035 install_openstack_clients_in_robot_vm
1036
1037 # TODO: run openrc on control node and then scrape the vars from it
1038 # Environment Variables Needed to execute Openstack Client for NetVirt Jobs
1039 cat > /tmp/os_netvirt_client_rc << EOF
1040 export OS_USERNAME=admin
1041 export OS_PASSWORD=admin
1042 export OS_PROJECT_NAME=admin
1043 export OS_USER_DOMAIN_NAME=default
1044 export OS_PROJECT_DOMAIN_NAME=default
1045 export OS_AUTH_URL="http://${!CONTROLIP}/identity"
1046 export OS_IDENTITY_API_VERSION=3
1047 export OS_IMAGE_API_VERSION=2
1048 export OS_TENANT_NAME=admin
1049 unset OS_CLOUD
1050 EOF
1051
1052 source /tmp/os_netvirt_client_rc
1053
1054 echo "Get all versions before executing pybot"
1055 echo "openstack --version"
1056 which openstack
1057 openstack --version
1058 echo "nova --version"
1059 which nova
1060 nova --version
1061 echo "neutron --version"
1062 which neutron
1063 neutron --version
1064
1065 echo "Starting Robot test suites ${SUITES} ..."
1066 # please add pybot -v arguments on a single line and alphabetized
1067 suite_num=0
1068 for suite in ${SUITES}; do
1069     # prepend an incremental counter to the suite name so that the full robot log combining all the suites as is done
1070     # in the rebot step below will list all the suites in chronological order as rebot seems to alphabetize them
1071     let "suite_num = suite_num + 1"
1072     suite_index="$(printf %02d ${suite_num})"
1073     suite_name="$(basename ${suite} | cut -d. -f1)"
1074     log_name="${suite_index}_${suite_name}"
1075     pybot -N ${log_name} \
1076     -c critical -e exclude -e skip_if_${DISTROSTREAM} \
1077     --log log_${log_name}.html --report None --output output_${log_name}.xml \
1078     --removekeywords wuks \
1079     --removekeywords name:SetupUtils.Setup_Utils_For_Setup_And_Teardown \
1080     --removekeywords name:SetupUtils.Setup_Test_With_Logging_And_Without_Fast_Failing \
1081     --removekeywords name:OpenStackOperations.Add_OVS_Logging_On_All_OpenStack_Nodes \
1082     -v BUNDLEFOLDER:${BUNDLEFOLDER} \
1083     -v BUNDLE_URL:${ACTUAL_BUNDLE_URL} \
1084     -v CONTROLLERFEATURES:"${CONTROLLERFEATURES}" \
1085     -v CONTROLLER_USER:${USER} \
1086     -v DEVSTACK_DEPLOY_PATH:/opt/stack/devstack \
1087     -v ENABLE_ITM_DIRECT_TUNNELS:${ENABLE_ITM_DIRECT_TUNNELS} \
1088     -v HA_PROXY_IP:${HA_PROXY_IP} \
1089     -v HA_PROXY_1_IP:${HA_PROXY_1_IP} \
1090     -v HA_PROXY_2_IP:${HA_PROXY_2_IP} \
1091     -v HA_PROXY_3_IP:${HA_PROXY_3_IP} \
1092     -v JDKVERSION:${JDKVERSION} \
1093     -v JENKINS_WORKSPACE:${WORKSPACE} \
1094     -v NEXUSURL_PREFIX:${NEXUSURL_PREFIX} \
1095     -v NUM_ODL_SYSTEM:${NUM_ODL_SYSTEM} \
1096     -v NUM_OPENSTACK_SITES:${NUM_OPENSTACK_SITES} \
1097     -v NUM_OS_SYSTEM:${NUM_OPENSTACK_SYSTEM} \
1098     -v NUM_TOOLS_SYSTEM:${NUM_TOOLS_SYSTEM} \
1099     -v ODL_SNAT_MODE:${ODL_SNAT_MODE} \
1100     -v ODL_STREAM:${DISTROSTREAM} \
1101     -v ODL_SYSTEM_IP:${ODL_SYSTEM_IP} \
1102     -v ODL_SYSTEM_1_IP:${ODL_SYSTEM_1_IP} \
1103     -v ODL_SYSTEM_2_IP:${ODL_SYSTEM_2_IP} \
1104     -v ODL_SYSTEM_3_IP:${ODL_SYSTEM_3_IP} \
1105     -v ODL_SYSTEM_4_IP:${ODL_SYSTEM_4_IP} \
1106     -v ODL_SYSTEM_5_IP:${ODL_SYSTEM_5_IP} \
1107     -v ODL_SYSTEM_6_IP:${ODL_SYSTEM_6_IP} \
1108     -v ODL_SYSTEM_7_IP:${ODL_SYSTEM_7_IP} \
1109     -v ODL_SYSTEM_8_IP:${ODL_SYSTEM_8_IP} \
1110     -v ODL_SYSTEM_9_IP:${ODL_SYSTEM_9_IP} \
1111     -v OS_CONTROL_NODE_IP:${OPENSTACK_CONTROL_NODE_1_IP} \
1112     -v OS_CONTROL_NODE_1_IP:${OPENSTACK_CONTROL_NODE_1_IP} \
1113     -v OS_CONTROL_NODE_2_IP:${OPENSTACK_CONTROL_NODE_2_IP} \
1114     -v OS_CONTROL_NODE_3_IP:${OPENSTACK_CONTROL_NODE_3_IP} \
1115     -v OPENSTACK_BRANCH:${OPENSTACK_BRANCH} \
1116     -v OS_COMPUTE_1_IP:${OPENSTACK_COMPUTE_NODE_1_IP} \
1117     -v OS_COMPUTE_2_IP:${OPENSTACK_COMPUTE_NODE_2_IP} \
1118     -v OS_COMPUTE_3_IP:${OPENSTACK_COMPUTE_NODE_3_IP} \
1119     -v OS_COMPUTE_4_IP:${OPENSTACK_COMPUTE_NODE_4_IP} \
1120     -v OS_COMPUTE_5_IP:${OPENSTACK_COMPUTE_NODE_5_IP} \
1121     -v OS_COMPUTE_6_IP:${OPENSTACK_COMPUTE_NODE_6_IP} \
1122     -v CMP_INSTANCES_SHARED_PATH:/var/instances \
1123     -v OS_USER:${USER} \
1124     -v PUBLIC_PHYSICAL_NETWORK:${PUBLIC_PHYSICAL_NETWORK} \
1125     -v SECURITY_GROUP_MODE:${SECURITY_GROUP_MODE} \
1126     -v TOOLS_SYSTEM_IP:${TOOLS_SYSTEM_1_IP} \
1127     -v TOOLS_SYSTEM_1_IP:${TOOLS_SYSTEM_1_IP} \
1128     -v TOOLS_SYSTEM_2_IP:${TOOLS_SYSTEM_2_IP} \
1129     -v USER_HOME:${HOME} \
1130     -v WORKSPACE:/tmp \
1131     ${TESTOPTIONS} ${suite} || true
1132 done
1133 #rebot exit codes seem to be different
1134 rebot --output ${WORKSPACE}/output.xml --log log_full.html --report None -N openstack output_*.xml || true
1135
1136 echo "Examining the files in data/log and checking file size"
1137 ssh ${ODL_SYSTEM_IP} "ls -altr /tmp/${BUNDLEFOLDER}/data/log/"
1138 ssh ${ODL_SYSTEM_IP} "du -hs /tmp/${BUNDLEFOLDER}/data/log/*"
1139
1140 echo "Tests Executed"
1141
1142 true  # perhaps Jenkins is testing last exit code
1143 # vim: ts=4 sw=4 sts=4 et ft=sh :