blob: 4aaecb9d1c5b93a9f21cf814d4fdd31fb583253c [file] [log] [blame]
sousaedu6248fe62020-10-13 23:46:51 +01001#!/usr/bin/env python3
David Garcia49379ce2021-02-24 13:48:22 +01002# Copyright 2021 Canonical Ltd.
sousaedu6248fe62020-10-13 23:46:51 +01003#
4# Licensed under the Apache License, Version 2.0 (the "License"); you may
5# not use this file except in compliance with the License. You may obtain
6# a copy of the License at
7#
8# http://www.apache.org/licenses/LICENSE-2.0
9#
10# Unless required by applicable law or agreed to in writing, software
11# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
12# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
13# License for the specific language governing permissions and limitations
14# under the License.
15#
16# For those usages not covered by the Apache License, Version 2.0 please
17# contact: legal@canonical.com
18#
19# To get in touch with the maintainers, please contact:
20# osm-charmers@lists.launchpad.net
21##
22
David Garcia49379ce2021-02-24 13:48:22 +010023# pylint: disable=E0213
24
25
David Garcia49379ce2021-02-24 13:48:22 +010026from ipaddress import ip_network
David Garciac753dc52021-03-17 15:28:47 +010027import logging
28from typing import NoReturn, Optional
David Garcia49379ce2021-02-24 13:48:22 +010029from urllib.parse import urlparse
sousaedu6248fe62020-10-13 23:46:51 +010030
David Garciac753dc52021-03-17 15:28:47 +010031
David Garcia4a0db7c2022-02-21 11:48:11 +010032from charms.kafka_k8s.v0.kafka import KafkaEvents, KafkaRequires
sousaedu6248fe62020-10-13 23:46:51 +010033from ops.main import main
David Garcia49379ce2021-02-24 13:48:22 +010034from opslib.osm.charm import CharmedOsmBase, RelationsMissing
David Garciac753dc52021-03-17 15:28:47 +010035from opslib.osm.interfaces.http import HttpServer
David Garciac753dc52021-03-17 15:28:47 +010036from opslib.osm.interfaces.keystone import KeystoneClient
David Garcia49379ce2021-02-24 13:48:22 +010037from opslib.osm.interfaces.mongo import MongoClient
38from opslib.osm.interfaces.prometheus import PrometheusClient
David Garciac753dc52021-03-17 15:28:47 +010039from opslib.osm.pod import (
40 ContainerV3Builder,
41 IngressResourceV3Builder,
David Garcia141d9352021-09-08 17:48:40 +020042 PodRestartPolicy,
David Garciac753dc52021-03-17 15:28:47 +010043 PodSpecV3Builder,
44)
45from opslib.osm.validator import ModelValidator, validator
David Garcia49379ce2021-02-24 13:48:22 +010046
sousaedu6248fe62020-10-13 23:46:51 +010047
sousaedu4df5a462020-11-17 14:30:47 +000048logger = logging.getLogger(__name__)
sousaedu6248fe62020-10-13 23:46:51 +010049
David Garcia49379ce2021-02-24 13:48:22 +010050PORT = 9999
sousaedu6248fe62020-10-13 23:46:51 +010051
52
David Garcia49379ce2021-02-24 13:48:22 +010053class ConfigModel(ModelValidator):
54 enable_test: bool
55 auth_backend: str
56 database_commonkey: str
57 log_level: str
58 max_file_size: int
59 site_url: Optional[str]
sousaedu3cc03162021-04-29 16:53:12 +020060 cluster_issuer: Optional[str]
David Garciad68e0b42021-06-28 16:50:42 +020061 ingress_class: Optional[str]
David Garcia49379ce2021-02-24 13:48:22 +010062 ingress_whitelist_source_range: Optional[str]
63 tls_secret_name: Optional[str]
sousaedu996a5602021-05-03 00:22:43 +020064 mongodb_uri: Optional[str]
sousaedu0dc25b32021-08-30 16:33:33 +010065 image_pull_policy: str
sousaedu540d9372021-09-29 01:53:30 +010066 debug_mode: bool
67 security_context: bool
sousaedu6248fe62020-10-13 23:46:51 +010068
David Garcia49379ce2021-02-24 13:48:22 +010069 @validator("auth_backend")
70 def validate_auth_backend(cls, v):
71 if v not in {"internal", "keystone"}:
72 raise ValueError("value must be 'internal' or 'keystone'")
73 return v
74
75 @validator("log_level")
76 def validate_log_level(cls, v):
77 if v not in {"INFO", "DEBUG"}:
78 raise ValueError("value must be INFO or DEBUG")
79 return v
80
81 @validator("max_file_size")
82 def validate_max_file_size(cls, v):
83 if v < 0:
84 raise ValueError("value must be equal or greater than 0")
85 return v
86
87 @validator("site_url")
88 def validate_site_url(cls, v):
89 if v:
90 parsed = urlparse(v)
91 if not parsed.scheme.startswith("http"):
92 raise ValueError("value must start with http")
93 return v
94
95 @validator("ingress_whitelist_source_range")
96 def validate_ingress_whitelist_source_range(cls, v):
97 if v:
98 ip_network(v)
99 return v
sousaedu6248fe62020-10-13 23:46:51 +0100100
sousaedu996a5602021-05-03 00:22:43 +0200101 @validator("mongodb_uri")
102 def validate_mongodb_uri(cls, v):
103 if v and not v.startswith("mongodb://"):
104 raise ValueError("mongodb_uri is not properly formed")
105 return v
106
sousaedu3ddbbd12021-08-24 19:57:24 +0100107 @validator("image_pull_policy")
108 def validate_image_pull_policy(cls, v):
109 values = {
110 "always": "Always",
111 "ifnotpresent": "IfNotPresent",
112 "never": "Never",
113 }
114 v = v.lower()
115 if v not in values.keys():
116 raise ValueError("value must be always, ifnotpresent or never")
117 return values[v]
118
sousaedu6248fe62020-10-13 23:46:51 +0100119
David Garcia49379ce2021-02-24 13:48:22 +0100120class NbiCharm(CharmedOsmBase):
David Garcia4a0db7c2022-02-21 11:48:11 +0100121
122 on = KafkaEvents()
123
sousaedu6248fe62020-10-13 23:46:51 +0100124 def __init__(self, *args) -> NoReturn:
David Garciad680be42021-08-17 11:03:55 +0200125 super().__init__(
126 *args,
127 oci_image="image",
David Garciad680be42021-08-17 11:03:55 +0200128 vscode_workspace=VSCODE_WORKSPACE,
129 )
David Garciacafe31e2021-11-18 16:45:05 +0100130 if self.config.get("debug_mode"):
131 self.enable_debug_mode(
132 pubkey=self.config.get("debug_pubkey"),
133 hostpaths={
134 "NBI": {
135 "hostpath": self.config.get("debug_nbi_local_path"),
136 "container-path": "/usr/lib/python3/dist-packages/osm_nbi",
137 },
138 "osm_common": {
139 "hostpath": self.config.get("debug_common_local_path"),
140 "container-path": "/usr/lib/python3/dist-packages/osm_common",
141 },
142 },
143 )
sousaedu6248fe62020-10-13 23:46:51 +0100144
David Garcia4a0db7c2022-02-21 11:48:11 +0100145 self.kafka = KafkaRequires(self)
146 self.framework.observe(self.on.kafka_available, self.configure_pod)
147 self.framework.observe(self.on.kafka_broken, self.configure_pod)
sousaedu6248fe62020-10-13 23:46:51 +0100148
David Garcia49379ce2021-02-24 13:48:22 +0100149 self.mongodb_client = MongoClient(self, "mongodb")
150 self.framework.observe(self.on["mongodb"].relation_changed, self.configure_pod)
151 self.framework.observe(self.on["mongodb"].relation_broken, self.configure_pod)
sousaedu6248fe62020-10-13 23:46:51 +0100152
David Garcia49379ce2021-02-24 13:48:22 +0100153 self.prometheus_client = PrometheusClient(self, "prometheus")
sousaedu6248fe62020-10-13 23:46:51 +0100154 self.framework.observe(
David Garcia49379ce2021-02-24 13:48:22 +0100155 self.on["prometheus"].relation_changed, self.configure_pod
sousaedu6248fe62020-10-13 23:46:51 +0100156 )
157 self.framework.observe(
David Garcia49379ce2021-02-24 13:48:22 +0100158 self.on["prometheus"].relation_broken, self.configure_pod
sousaedu6248fe62020-10-13 23:46:51 +0100159 )
160
David Garcia49379ce2021-02-24 13:48:22 +0100161 self.keystone_client = KeystoneClient(self, "keystone")
162 self.framework.observe(self.on["keystone"].relation_changed, self.configure_pod)
163 self.framework.observe(self.on["keystone"].relation_broken, self.configure_pod)
sousaedu6248fe62020-10-13 23:46:51 +0100164
David Garcia49379ce2021-02-24 13:48:22 +0100165 self.http_server = HttpServer(self, "nbi")
166 self.framework.observe(self.on["nbi"].relation_joined, self._publish_nbi_info)
sousaedu6248fe62020-10-13 23:46:51 +0100167
David Garcia49379ce2021-02-24 13:48:22 +0100168 def _publish_nbi_info(self, event):
sousaedu6248fe62020-10-13 23:46:51 +0100169 """Publishes NBI information.
170
171 Args:
David Garcia49379ce2021-02-24 13:48:22 +0100172 event (EventBase): RO relation event.
sousaedu6248fe62020-10-13 23:46:51 +0100173 """
David Garcia49379ce2021-02-24 13:48:22 +0100174 if self.unit.is_leader():
175 self.http_server.publish_info(self.app.name, PORT)
sousaedu6248fe62020-10-13 23:46:51 +0100176
David Garcia49379ce2021-02-24 13:48:22 +0100177 def _check_missing_dependencies(self, config: ConfigModel):
178 missing_relations = []
sousaedu6248fe62020-10-13 23:46:51 +0100179
David Garcia4a0db7c2022-02-21 11:48:11 +0100180 if not self.kafka.host or not self.kafka.port:
David Garcia49379ce2021-02-24 13:48:22 +0100181 missing_relations.append("kafka")
sousaedu996a5602021-05-03 00:22:43 +0200182 if not config.mongodb_uri and self.mongodb_client.is_missing_data_in_unit():
David Garcia49379ce2021-02-24 13:48:22 +0100183 missing_relations.append("mongodb")
184 if self.prometheus_client.is_missing_data_in_app():
185 missing_relations.append("prometheus")
186 if config.auth_backend == "keystone":
187 if self.keystone_client.is_missing_data_in_app():
188 missing_relations.append("keystone")
sousaedu6248fe62020-10-13 23:46:51 +0100189
David Garcia49379ce2021-02-24 13:48:22 +0100190 if missing_relations:
191 raise RelationsMissing(missing_relations)
sousaedu6248fe62020-10-13 23:46:51 +0100192
David Garcia49379ce2021-02-24 13:48:22 +0100193 def build_pod_spec(self, image_info):
194 # Validate config
195 config = ConfigModel(**dict(self.config))
sousaedu996a5602021-05-03 00:22:43 +0200196
197 if config.mongodb_uri and not self.mongodb_client.is_missing_data_in_unit():
198 raise Exception("Mongodb data cannot be provided via config and relation")
199
David Garcia49379ce2021-02-24 13:48:22 +0100200 # Check relations
201 self._check_missing_dependencies(config)
sousaedu996a5602021-05-03 00:22:43 +0200202
sousaedu540d9372021-09-29 01:53:30 +0100203 security_context_enabled = (
204 config.security_context if not config.debug_mode else False
205 )
206
David Garcia49379ce2021-02-24 13:48:22 +0100207 # Create Builder for the PodSpec
sousaedu540d9372021-09-29 01:53:30 +0100208 pod_spec_builder = PodSpecV3Builder(
209 enable_security_context=security_context_enabled
210 )
sousaedu996a5602021-05-03 00:22:43 +0200211
David Garcia141d9352021-09-08 17:48:40 +0200212 # Add secrets to the pod
213 mongodb_secret_name = f"{self.app.name}-mongodb-secret"
214 pod_spec_builder.add_secret(
215 mongodb_secret_name,
216 {
217 "uri": config.mongodb_uri or self.mongodb_client.connection_string,
218 "commonkey": config.database_commonkey,
219 },
220 )
221
David Garcia49379ce2021-02-24 13:48:22 +0100222 # Build Init Container
223 pod_spec_builder.add_init_container(
224 {
225 "name": "init-check",
226 "image": "alpine:latest",
227 "command": [
228 "sh",
229 "-c",
David Garcia4a0db7c2022-02-21 11:48:11 +0100230 f"until (nc -zvw1 {self.kafka.host} {self.kafka.port} ); do sleep 3; done; exit 0",
David Garcia49379ce2021-02-24 13:48:22 +0100231 ],
232 }
233 )
sousaedu996a5602021-05-03 00:22:43 +0200234
David Garcia49379ce2021-02-24 13:48:22 +0100235 # Build Container
sousaedu3ddbbd12021-08-24 19:57:24 +0100236 container_builder = ContainerV3Builder(
sousaedu540d9372021-09-29 01:53:30 +0100237 self.app.name,
238 image_info,
239 config.image_pull_policy,
240 run_as_non_root=security_context_enabled,
sousaedu3ddbbd12021-08-24 19:57:24 +0100241 )
David Garcia49379ce2021-02-24 13:48:22 +0100242 container_builder.add_port(name=self.app.name, port=PORT)
243 container_builder.add_tcpsocket_readiness_probe(
244 PORT,
245 initial_delay_seconds=5,
246 timeout_seconds=5,
247 )
248 container_builder.add_tcpsocket_liveness_probe(
249 PORT,
250 initial_delay_seconds=45,
251 timeout_seconds=10,
252 )
253 container_builder.add_envs(
254 {
255 # General configuration
256 "ALLOW_ANONYMOUS_LOGIN": "yes",
257 "OSMNBI_SERVER_ENABLE_TEST": config.enable_test,
258 "OSMNBI_STATIC_DIR": "/app/osm_nbi/html_public",
259 # Kafka configuration
David Garcia4a0db7c2022-02-21 11:48:11 +0100260 "OSMNBI_MESSAGE_HOST": self.kafka.host,
David Garcia49379ce2021-02-24 13:48:22 +0100261 "OSMNBI_MESSAGE_DRIVER": "kafka",
David Garcia4a0db7c2022-02-21 11:48:11 +0100262 "OSMNBI_MESSAGE_PORT": self.kafka.port,
David Garcia49379ce2021-02-24 13:48:22 +0100263 # Database configuration
264 "OSMNBI_DATABASE_DRIVER": "mongo",
David Garcia49379ce2021-02-24 13:48:22 +0100265 # Storage configuration
266 "OSMNBI_STORAGE_DRIVER": "mongo",
267 "OSMNBI_STORAGE_PATH": "/app/storage",
268 "OSMNBI_STORAGE_COLLECTION": "files",
David Garcia49379ce2021-02-24 13:48:22 +0100269 # Prometheus configuration
270 "OSMNBI_PROMETHEUS_HOST": self.prometheus_client.hostname,
271 "OSMNBI_PROMETHEUS_PORT": self.prometheus_client.port,
272 # Log configuration
273 "OSMNBI_LOG_LEVEL": config.log_level,
274 }
275 )
David Garcia141d9352021-09-08 17:48:40 +0200276 container_builder.add_secret_envs(
277 secret_name=mongodb_secret_name,
278 envs={
279 "OSMNBI_DATABASE_URI": "uri",
280 "OSMNBI_DATABASE_COMMONKEY": "commonkey",
281 "OSMNBI_STORAGE_URI": "uri",
282 },
283 )
David Garcia49379ce2021-02-24 13:48:22 +0100284 if config.auth_backend == "internal":
285 container_builder.add_env("OSMNBI_AUTHENTICATION_BACKEND", "internal")
286 elif config.auth_backend == "keystone":
David Garcia141d9352021-09-08 17:48:40 +0200287 keystone_secret_name = f"{self.app.name}-keystone-secret"
288 pod_spec_builder.add_secret(
289 keystone_secret_name,
sousaedu6248fe62020-10-13 23:46:51 +0100290 {
David Garcia141d9352021-09-08 17:48:40 +0200291 "url": self.keystone_client.host,
292 "port": self.keystone_client.port,
293 "user_domain": self.keystone_client.user_domain_name,
294 "project_domain": self.keystone_client.project_domain_name,
295 "service_username": self.keystone_client.username,
296 "service_password": self.keystone_client.password,
297 "service_project": self.keystone_client.service,
298 },
299 )
300 container_builder.add_env("OSMNBI_AUTHENTICATION_BACKEND", "keystone")
301 container_builder.add_secret_envs(
302 secret_name=keystone_secret_name,
303 envs={
304 "OSMNBI_AUTHENTICATION_AUTH_URL": "url",
305 "OSMNBI_AUTHENTICATION_AUTH_PORT": "port",
306 "OSMNBI_AUTHENTICATION_USER_DOMAIN_NAME": "user_domain",
307 "OSMNBI_AUTHENTICATION_PROJECT_DOMAIN_NAME": "project_domain",
308 "OSMNBI_AUTHENTICATION_SERVICE_USERNAME": "service_username",
309 "OSMNBI_AUTHENTICATION_SERVICE_PASSWORD": "service_password",
310 "OSMNBI_AUTHENTICATION_SERVICE_PROJECT": "service_project",
311 },
sousaedu6248fe62020-10-13 23:46:51 +0100312 )
David Garcia49379ce2021-02-24 13:48:22 +0100313 container = container_builder.build()
sousaedu996a5602021-05-03 00:22:43 +0200314
David Garcia49379ce2021-02-24 13:48:22 +0100315 # Add container to pod spec
316 pod_spec_builder.add_container(container)
sousaedu996a5602021-05-03 00:22:43 +0200317
David Garcia49379ce2021-02-24 13:48:22 +0100318 # Add ingress resources to pod spec if site url exists
319 if config.site_url:
320 parsed = urlparse(config.site_url)
321 annotations = {
322 "nginx.ingress.kubernetes.io/proxy-body-size": "{}".format(
323 str(config.max_file_size) + "m"
324 if config.max_file_size > 0
325 else config.max_file_size
326 ),
327 "nginx.ingress.kubernetes.io/backend-protocol": "HTTPS",
328 }
David Garciad68e0b42021-06-28 16:50:42 +0200329 if config.ingress_class:
330 annotations["kubernetes.io/ingress.class"] = config.ingress_class
David Garcia49379ce2021-02-24 13:48:22 +0100331 ingress_resource_builder = IngressResourceV3Builder(
332 f"{self.app.name}-ingress", annotations
sousaedu6248fe62020-10-13 23:46:51 +0100333 )
sousaedu6248fe62020-10-13 23:46:51 +0100334
David Garcia49379ce2021-02-24 13:48:22 +0100335 if config.ingress_whitelist_source_range:
336 annotations[
337 "nginx.ingress.kubernetes.io/whitelist-source-range"
338 ] = config.ingress_whitelist_source_range
sousaedu6248fe62020-10-13 23:46:51 +0100339
sousaedu3cc03162021-04-29 16:53:12 +0200340 if config.cluster_issuer:
341 annotations["cert-manager.io/cluster-issuer"] = config.cluster_issuer
342
David Garcia49379ce2021-02-24 13:48:22 +0100343 if parsed.scheme == "https":
344 ingress_resource_builder.add_tls(
345 [parsed.hostname], config.tls_secret_name
346 )
347 else:
348 annotations["nginx.ingress.kubernetes.io/ssl-redirect"] = "false"
sousaedu6248fe62020-10-13 23:46:51 +0100349
David Garcia49379ce2021-02-24 13:48:22 +0100350 ingress_resource_builder.add_rule(parsed.hostname, self.app.name, PORT)
351 ingress_resource = ingress_resource_builder.build()
352 pod_spec_builder.add_ingress_resource(ingress_resource)
sousaedu996a5602021-05-03 00:22:43 +0200353
David Garcia141d9352021-09-08 17:48:40 +0200354 # Add restart policy
355 restart_policy = PodRestartPolicy()
356 restart_policy.add_secrets()
357 pod_spec_builder.set_restart_policy(restart_policy)
sousaedu996a5602021-05-03 00:22:43 +0200358
David Garcia49379ce2021-02-24 13:48:22 +0100359 return pod_spec_builder.build()
sousaedu6248fe62020-10-13 23:46:51 +0100360
361
David Garciad680be42021-08-17 11:03:55 +0200362VSCODE_WORKSPACE = {
363 "folders": [
364 {"path": "/usr/lib/python3/dist-packages/osm_nbi"},
365 {"path": "/usr/lib/python3/dist-packages/osm_common"},
366 {"path": "/usr/lib/python3/dist-packages/osm_im"},
367 ],
368 "settings": {},
369 "launch": {
370 "version": "0.2.0",
371 "configurations": [
372 {
373 "name": "NBI",
374 "type": "python",
375 "request": "launch",
376 "module": "osm_nbi.nbi",
377 "justMyCode": False,
378 }
379 ],
380 },
381}
382
383
sousaedu6248fe62020-10-13 23:46:51 +0100384if __name__ == "__main__":
385 main(NbiCharm)