Scott Baker | b63ea79 | 2016-08-11 10:24:48 -0700 | [diff] [blame] | 1 | import commands |
| 2 | import hashlib |
| 3 | from xos.config import Config |
| 4 | from core.models import Controller |
| 5 | |
| 6 | try: |
Scott Baker | 04a37f5 | 2016-08-11 10:52:21 -0700 | [diff] [blame] | 7 | from synchronizers.openstack.client import OpenStackClient |
Scott Baker | b63ea79 | 2016-08-11 10:24:48 -0700 | [diff] [blame] | 8 | has_openstack = True |
| 9 | except: |
| 10 | has_openstack = False |
| 11 | |
| 12 | manager_enabled = Config().api_nova_enabled |
| 13 | |
| 14 | class OpenStackDriver: |
| 15 | |
| 16 | def __init__(self, config = None, client=None): |
| 17 | if config: |
| 18 | self.config = Config(config) |
| 19 | else: |
| 20 | self.config = Config() |
| 21 | |
| 22 | if client: |
| 23 | self.shell = client |
| 24 | |
| 25 | self.enabled = manager_enabled |
| 26 | self.has_openstack = has_openstack |
| 27 | self.controller = None |
| 28 | self.admin_user = None |
| 29 | |
| 30 | def client_driver(self, caller=None, tenant=None, controller=None): |
| 31 | if caller: |
| 32 | auth = {'username': caller.email, |
| 33 | 'password': hashlib.md5(caller.password).hexdigest()[:6], |
| 34 | 'tenant': tenant} |
| 35 | client = OpenStackClient(controller=controller, cacert=self.config.nova_ca_ssl_cert, **auth) |
| 36 | else: |
| 37 | admin_driver = self.admin_driver(tenant=tenant, controller=controller) |
| 38 | client = OpenStackClient(tenant=tenant, controller=admin_driver.controller) |
| 39 | |
| 40 | driver = OpenStackDriver(client=client) |
| 41 | #driver.admin_user = admin_driver.admin_user |
| 42 | #driver.controller = admin_driver.controller |
| 43 | return driver |
| 44 | |
| 45 | def admin_driver(self, tenant=None, controller=None): |
| 46 | if isinstance(controller, int): |
| 47 | controller = Controller.objects.get(id=controller.id) |
| 48 | if not tenant: |
| 49 | tenant = controller.admin_tenant |
| 50 | client = OpenStackClient(tenant=tenant, controller=controller, cacert=self.config.nova_ca_ssl_cert) |
| 51 | driver = OpenStackDriver(client=client) |
| 52 | driver.admin_user = client.keystone.users.find(name=controller.admin_user) |
| 53 | driver.controller = controller |
| 54 | return driver |
| 55 | |
| 56 | def create_role(self, name): |
| 57 | roles = self.shell.keystone.roles.findall(name=name) |
| 58 | roles_title = self.shell.keystone.roles.findall(name=name.title()) |
| 59 | roles_found = roles + roles_title |
| 60 | if not roles_found: |
| 61 | role = self.shell.keystone.roles.create(name) |
| 62 | else: |
| 63 | role = roles_found[0] |
| 64 | return role |
| 65 | |
| 66 | def delete_role(self, filter): |
| 67 | roles = self.shell.keystone.roles.findall(**filter) |
| 68 | for role in roles: |
| 69 | self.shell.keystone.roles.delete(role) |
| 70 | return 1 |
| 71 | |
| 72 | def create_tenant(self, tenant_name, enabled, description): |
| 73 | """Create keystone tenant. Suggested fields: name, description, enabled""" |
| 74 | tenants = self.shell.keystone.tenants.findall(name=tenant_name) |
| 75 | if not tenants: |
| 76 | fields = {'tenant_name': tenant_name, 'enabled': enabled, |
| 77 | 'description': description} |
| 78 | tenant = self.shell.keystone.tenants.create(**fields) |
| 79 | else: |
| 80 | tenant = tenants[0] |
| 81 | |
| 82 | # always give the admin user the admin role to any tenant created |
| 83 | # by the driver. |
| 84 | self.add_user_role(self.admin_user.id, tenant.id, 'admin') |
| 85 | return tenant |
| 86 | |
| 87 | def update_tenant(self, id, **kwds): |
| 88 | return self.shell.keystone.tenants.update(id, **kwds) |
| 89 | |
| 90 | def delete_tenant(self, id): |
| 91 | # FIXME: nova_db is commented out in clients.py, throws errors. |
| 92 | # Commenting this out for the time being until actually fixed |
| 93 | |
| 94 | #ctx = self.shell.nova_db.ctx |
| 95 | tenants = self.shell.keystone.tenants.findall(id=id) |
| 96 | for tenant in tenants: |
| 97 | # nova does not automatically delete the tenant's instances |
| 98 | # so we manually delete instances before deleting the tenant |
| 99 | #instances = self.shell.nova_db.instance_get_all_by_filters(ctx, |
| 100 | # {'project_id': tenant.id}, 'id', 'asc') |
| 101 | #client = OpenStackClient(tenant=tenant.name) |
| 102 | #driver = OpenStackDriver(client=client) |
| 103 | #for instance in instances: |
| 104 | # driver.destroy_instance(instance.id) |
| 105 | self.shell.keystone.tenants.delete(tenant) |
| 106 | return 1 |
| 107 | |
| 108 | def create_user(self, name, email, password, enabled): |
| 109 | users = self.shell.keystone.users.findall(email=email) |
| 110 | if not users: |
| 111 | fields = {'name': name, 'email': email, 'password': password, |
| 112 | 'enabled': enabled} |
| 113 | user = self.shell.keystone.users.create(**fields) |
| 114 | else: |
| 115 | user = users[0] |
| 116 | return user |
| 117 | |
| 118 | def delete_user(self, id): |
| 119 | users = self.shell.keystone.users.findall(id=id) |
| 120 | for user in users: |
| 121 | # delete users keys |
| 122 | keys = self.shell.nova.keypairs.findall() |
| 123 | for key in keys: |
| 124 | self.shell.nova.keypairs.delete(key) |
| 125 | self.shell.keystone.users.delete(user) |
| 126 | return 1 |
| 127 | |
| 128 | def get_admin_role(self): |
| 129 | role = None |
| 130 | for admin_role_name in ['admin', 'Admin']: |
| 131 | roles = self.shell.keystone.roles.findall(name=admin_role_name) |
| 132 | if roles: |
| 133 | role = roles[0] |
| 134 | break |
| 135 | return role |
| 136 | |
| 137 | def add_user_role(self, kuser_id, tenant_id, role_name): |
| 138 | user = self.shell.keystone.users.find(id=kuser_id) |
| 139 | tenant = self.shell.keystone.tenants.find(id=tenant_id) |
| 140 | # admin role can be lowercase or title. Look for both |
| 141 | role = None |
| 142 | if role_name.lower() == 'admin': |
| 143 | role = self.get_admin_role() |
| 144 | else: |
| 145 | # look up non admin role or force exception when admin role isnt found |
| 146 | role = self.shell.keystone.roles.find(name=role_name) |
| 147 | |
| 148 | role_found = False |
| 149 | user_roles = user.list_roles(tenant.id) |
| 150 | for user_role in user_roles: |
| 151 | if user_role.name == role.name: |
| 152 | role_found = True |
| 153 | if not role_found: |
| 154 | tenant.add_user(user, role) |
| 155 | |
| 156 | return 1 |
| 157 | |
| 158 | def delete_user_role(self, kuser_id, tenant_id, role_name): |
| 159 | user = self.shell.keystone.users.find(id=kuser_id) |
| 160 | tenant = self.shell.keystone.tenants.find(id=tenant_id) |
| 161 | # admin role can be lowercase or title. Look for both |
| 162 | role = None |
| 163 | if role_name.lower() == 'admin': |
| 164 | role = self.get_admin_role() |
| 165 | else: |
| 166 | # look up non admin role or force exception when admin role isnt found |
| 167 | role = self.shell.keystone.roles.find(name=role_name) |
| 168 | |
| 169 | role_found = False |
| 170 | user_roles = user.list_roles(tenant.id) |
| 171 | for user_role in user_roles: |
| 172 | if user_role.name == role.name: |
| 173 | role_found = True |
| 174 | if role_found: |
| 175 | tenant.remove_user(user, role) |
| 176 | |
| 177 | return 1 |
| 178 | |
| 179 | def update_user(self, id, fields): |
| 180 | if 'password' in fields: |
| 181 | self.shell.keystone.users.update_password(id, fields['password']) |
| 182 | if 'enabled' in fields: |
| 183 | self.shell.keystone.users.update_enabled(id, fields['enabled']) |
| 184 | return 1 |
| 185 | |
| 186 | def create_router(self, name, set_gateway=True): |
| 187 | routers = self.shell.neutron.list_routers(name=name)['routers'] |
| 188 | if routers: |
| 189 | router = routers[0] |
| 190 | else: |
| 191 | router = self.shell.neutron.create_router({'router': {'name': name}})['router'] |
| 192 | # add router to external network |
| 193 | if set_gateway: |
| 194 | nets = self.shell.neutron.list_networks()['networks'] |
| 195 | for net in nets: |
| 196 | if net['router:external'] == True: |
| 197 | self.shell.neutron.add_gateway_router(router['id'], |
| 198 | {'network_id': net['id']}) |
| 199 | |
| 200 | return router |
| 201 | |
| 202 | def delete_router(self, id): |
| 203 | routers = self.shell.neutron.list_routers(id=id)['routers'] |
| 204 | for router in routers: |
| 205 | self.shell.neutron.delete_router(router['id']) |
| 206 | # remove router form external network |
| 207 | #nets = self.shell.neutron.list_networks()['networks'] |
| 208 | #for net in nets: |
| 209 | # if net['router:external'] == True: |
| 210 | # self.shell.neutron.remove_gateway_router(router['id']) |
| 211 | |
| 212 | def add_router_interface(self, router_id, subnet_id): |
| 213 | router = self.shell.neutron.show_router(router_id)['router'] |
| 214 | subnet = self.shell.neutron.show_subnet(subnet_id)['subnet'] |
| 215 | if router and subnet: |
| 216 | self.shell.neutron.add_interface_router(router_id, {'subnet_id': subnet_id}) |
| 217 | |
| 218 | def delete_router_interface(self, router_id, subnet_id): |
| 219 | router = self.shell.neutron.show_router(router_id) |
| 220 | subnet = self.shell.neutron.show_subnet(subnet_id) |
| 221 | if router and subnet: |
| 222 | self.shell.neutron.remove_interface_router(router_id, {'subnet_id': subnet_id}) |
| 223 | |
| 224 | def create_network(self, name, shared=False): |
| 225 | nets = self.shell.neutron.list_networks(name=name)['networks'] |
| 226 | if nets: |
| 227 | net = nets[0] |
| 228 | else: |
| 229 | net = self.shell.neutron.create_network({'network': {'name': name, 'shared': shared}})['network'] |
| 230 | return net |
| 231 | |
| 232 | def delete_network(self, id): |
| 233 | nets = self.shell.neutron.list_networks()['networks'] |
| 234 | for net in nets: |
| 235 | if net['id'] == id: |
| 236 | # delete_all ports |
| 237 | self.delete_network_ports(net['id']) |
| 238 | # delete all subnets: |
| 239 | for subnet_id in net['subnets']: |
| 240 | self.delete_subnet(subnet_id) |
| 241 | self.shell.neutron.delete_network(net['id']) |
| 242 | return 1 |
| 243 | |
| 244 | def delete_network_ports(self, network_id): |
| 245 | ports = self.shell.neutron.list_ports()['ports'] |
| 246 | for port in ports: |
| 247 | if port['network_id'] == network_id: |
| 248 | self.shell.neutron.delete_port(port['id']) |
| 249 | return 1 |
| 250 | |
| 251 | def delete_subnet_ports(self, subnet_id): |
| 252 | ports = self.shell.neutron.list_ports()['ports'] |
| 253 | for port in ports: |
| 254 | delete = False |
| 255 | for fixed_ip in port['fixed_ips']: |
| 256 | if fixed_ip['subnet_id'] == subnet_id: |
| 257 | delete=True |
| 258 | break |
| 259 | if delete: |
| 260 | self.shell.neutron.delete_port(port['id']) |
| 261 | return 1 |
| 262 | |
| 263 | def create_subnet(self, name, network_id, cidr_ip, ip_version, start, end): |
| 264 | #nets = self.shell.neutron.list_networks(name=network_name)['networks'] |
| 265 | #if not nets: |
| 266 | # raise Exception, "No such network: %s" % network_name |
| 267 | #net = nets[0] |
| 268 | |
| 269 | subnet = None |
| 270 | subnets = self.shell.neutron.list_subnets()['subnets'] |
| 271 | for snet in subnets: |
| 272 | if snet['cidr'] == cidr_ip and snet['network_id'] == network_id: |
| 273 | subnet = snet |
| 274 | |
| 275 | if not subnet: |
| 276 | # HACK: Add metadata route -- Neutron does not reliably supply this |
| 277 | metadata_ip = cidr_ip.replace("0/24", "3") |
| 278 | |
| 279 | allocation_pools = [{'start': start, 'end': end}] |
| 280 | subnet = {'subnet': {'name': name, |
| 281 | 'network_id': network_id, |
| 282 | 'ip_version': ip_version, |
| 283 | 'cidr': cidr_ip, |
| 284 | #'dns_nameservers': ['8.8.8.8', '8.8.4.4'], |
| 285 | 'host_routes': [{'destination':'169.254.169.254/32','nexthop':metadata_ip}], |
| 286 | 'gateway_ip': None, |
| 287 | 'allocation_pools': allocation_pools}} |
| 288 | subnet = self.shell.neutron.create_subnet(subnet)['subnet'] |
| 289 | # self.add_external_route(subnet) |
| 290 | |
| 291 | return subnet |
| 292 | |
| 293 | def update_subnet(self, id, fields): |
| 294 | return self.shell.neutron.update_subnet(id, fields) |
| 295 | |
| 296 | def delete_subnet(self, id): |
| 297 | #return self.shell.neutron.delete_subnet(id=id) |
| 298 | # inefficient but fault tolerant |
| 299 | subnets = self.shell.neutron.list_subnets()['subnets'] |
| 300 | for subnet in subnets: |
| 301 | if subnet['id'] == id: |
| 302 | self.delete_subnet_ports(subnet['id']) |
| 303 | self.shell.neutron.delete_subnet(id) |
| 304 | self.delete_external_route(subnet) |
| 305 | return 1 |
| 306 | |
| 307 | def get_external_routes(self): |
| 308 | status, output = commands.getstatusoutput('route') |
| 309 | routes = output.split('\n')[3:] |
| 310 | return routes |
| 311 | |
| 312 | def add_external_route(self, subnet, routes=[]): |
| 313 | if not routes: |
| 314 | routes = self.get_external_routes() |
| 315 | |
| 316 | ports = self.shell.neutron.list_ports()['ports'] |
| 317 | |
| 318 | gw_ip = subnet['gateway_ip'] |
| 319 | subnet_id = subnet['id'] |
| 320 | |
| 321 | # 1. Find the port associated with the subnet's gateway |
| 322 | # 2. Find the router associated with that port |
| 323 | # 3. Find the port associated with this router and on the external net |
| 324 | # 4. Set up route to the subnet through the port from step 3 |
| 325 | ip_address = None |
| 326 | for port in ports: |
| 327 | for fixed_ip in port['fixed_ips']: |
| 328 | if fixed_ip['subnet_id'] == subnet_id and fixed_ip['ip_address'] == gw_ip: |
| 329 | gw_port = port |
| 330 | router_id = gw_port['device_id'] |
| 331 | router = self.shell.neutron.show_router(router_id)['router'] |
| 332 | if router and router.get('external_gateway_info'): |
| 333 | ext_net = router['external_gateway_info']['network_id'] |
| 334 | for port in ports: |
| 335 | if port['device_id'] == router_id and port['network_id'] == ext_net: |
| 336 | ip_address = port['fixed_ips'][0]['ip_address'] |
| 337 | |
| 338 | if ip_address: |
| 339 | # check if external route already exists |
| 340 | route_exists = False |
| 341 | if routes: |
| 342 | for route in routes: |
| 343 | if subnet['cidr'] in route and ip_address in route: |
| 344 | route_exists = True |
| 345 | if not route_exists: |
| 346 | cmd = "route add -net %s dev br-ex gw %s" % (subnet['cidr'], ip_address) |
| 347 | s, o = commands.getstatusoutput(cmd) |
| 348 | #print cmd, "\n", s, o |
| 349 | |
| 350 | return 1 |
| 351 | |
| 352 | def delete_external_route(self, subnet): |
| 353 | ports = self.shell.neutron.list_ports()['ports'] |
| 354 | |
| 355 | gw_ip = subnet['gateway_ip'] |
| 356 | subnet_id = subnet['id'] |
| 357 | |
| 358 | # 1. Find the port associated with the subnet's gateway |
| 359 | # 2. Find the router associated with that port |
| 360 | # 3. Find the port associated with this router and on the external net |
| 361 | # 4. Set up route to the subnet through the port from step 3 |
| 362 | ip_address = None |
| 363 | for port in ports: |
| 364 | for fixed_ip in port['fixed_ips']: |
| 365 | if fixed_ip['subnet_id'] == subnet_id and fixed_ip['ip_address'] == gw_ip: |
| 366 | gw_port = port |
| 367 | router_id = gw_port['device_id'] |
| 368 | router = self.shell.neutron.show_router(router_id)['router'] |
| 369 | ext_net = router['external_gateway_info']['network_id'] |
| 370 | for port in ports: |
| 371 | if port['device_id'] == router_id and port['network_id'] == ext_net: |
| 372 | ip_address = port['fixed_ips'][0]['ip_address'] |
| 373 | |
| 374 | if ip_address: |
| 375 | cmd = "route delete -net %s" % (subnet['cidr']) |
| 376 | commands.getstatusoutput(cmd) |
| 377 | |
| 378 | return 1 |
| 379 | |
| 380 | def create_keypair(self, name, public_key): |
| 381 | keys = self.shell.nova.keypairs.findall(name=name) |
| 382 | if keys: |
| 383 | key = keys[0] |
| 384 | # update key |
| 385 | if key.public_key != public_key: |
| 386 | self.delete_keypair(key.id) |
| 387 | key = self.shell.nova.keypairs.create(name=name, public_key=public_key) |
| 388 | else: |
| 389 | key = self.shell.nova.keypairs.create(name=name, public_key=public_key) |
| 390 | return key |
| 391 | |
| 392 | def delete_keypair(self, id): |
| 393 | keys = self.shell.nova.keypairs.findall(id=id) |
| 394 | for key in keys: |
| 395 | self.shell.nova.keypairs.delete(key) |
| 396 | return 1 |
| 397 | |
| 398 | def get_private_networks(self, tenant=None): |
| 399 | if not tenant: |
| 400 | tenant = self.shell.nova.tenant |
| 401 | tenant = self.shell.keystone.tenants.find(name=tenant) |
| 402 | search_opts = {"tenant_id": tenant.id, "shared": False} |
| 403 | private_networks = self.shell.neutron.list_networks(**search_opts) |
| 404 | return private_networks |
| 405 | |
| 406 | def get_shared_networks(self): |
| 407 | search_opts = {"shared": True} |
| 408 | shared_networks = self.shell.neutron.list_networks(**search_opts) |
| 409 | return shared_networks |
| 410 | |
| 411 | def get_network_subnet(self, network_id): |
| 412 | subnet_id = None |
| 413 | subnet = None |
| 414 | if network_id: |
| 415 | os_networks = self.shell.neutron.list_networks(id=network_id)["networks"] |
| 416 | if os_networks: |
| 417 | os_network = os_networks[0] |
| 418 | if os_network['subnets']: |
| 419 | subnet_id = os_network['subnets'][0] |
| 420 | os_subnets = self.shell.neutron.list_subnets(id=subnet_id)['subnets'] |
| 421 | if os_subnets: |
| 422 | subnet = os_subnets[0]['cidr'] |
| 423 | |
| 424 | return (subnet_id, subnet) |
| 425 | |
| 426 | def spawn_instance(self, name, key_name=None, availability_zone=None, hostname=None, image_id=None, security_group=None, pubkeys=[], nics=None, metadata=None, userdata=None, flavor_name=None): |
| 427 | if not flavor_name: |
| 428 | flavor_name = self.config.nova_default_flavor |
| 429 | |
| 430 | flavor = self.shell.nova.flavors.find(name=flavor_name) |
| 431 | |
| 432 | if not security_group: |
| 433 | security_group = self.config.nova_default_security_group |
| 434 | |
| 435 | files = {} |
| 436 | #if pubkeys: |
| 437 | # files["/root/.ssh/authorized_keys"] = "\n".join(pubkeys).encode('base64') |
| 438 | hints = {} |
| 439 | |
| 440 | # determine availability zone and compute host |
| 441 | availability_zone_filter = None |
| 442 | if availability_zone is None or not availability_zone: |
| 443 | availability_zone_filter = 'nova' |
| 444 | else: |
| 445 | availability_zone_filter = availability_zone |
| 446 | if hostname: |
| 447 | availability_zone_filter += ':%s' % hostname |
| 448 | |
| 449 | server = self.shell.nova.servers.create( |
| 450 | name=name, |
| 451 | key_name = key_name, |
| 452 | flavor=flavor.id, |
| 453 | image=image_id, |
| 454 | security_group = security_group, |
| 455 | #files = files, |
| 456 | scheduler_hints=hints, |
| 457 | availability_zone=availability_zone_filter, |
| 458 | nics=nics, |
| 459 | networks=nics, |
| 460 | meta=metadata, |
| 461 | userdata=userdata) |
| 462 | return server |
| 463 | |
| 464 | def destroy_instance(self, id): |
| 465 | if (self.shell.nova.tenant=="admin"): |
| 466 | # findall() is implemented as a list() followed by a python search of the |
| 467 | # list. Since findall() doesn't accept "all_tenants", we do this using |
| 468 | # list() ourselves. This allows us to delete an instance as admin. |
| 469 | servers = self.shell.nova.servers.list(search_opts={"all_tenants": True}) |
| 470 | else: |
| 471 | servers = self.shell.nova.servers.list() |
| 472 | for server in servers: |
| 473 | if server.id == id: |
| 474 | result=self.shell.nova.servers.delete(server) |
| 475 | |
| 476 | def update_instance_metadata(self, id, metadata): |
| 477 | servers = self.shell.nova.servers.findall(id=id) |
| 478 | for server in servers: |
| 479 | self.shell.nova.servers.set_meta(server, metadata) |
| 480 | # note: set_meta() returns a broken Server() object. Don't try to |
| 481 | # print it in the shell or it will fail in __repr__. |
| 482 | |
| 483 | def delete_instance_metadata(self, id, metadata): |
| 484 | # note: metadata is a dict. Only the keys matter, not the values. |
| 485 | servers = self.shell.nova.servers.findall(id=id) |
| 486 | for server in servers: |
| 487 | self.shell.nova.servers.delete_meta(server, metadata) |
| 488 | |