#!/usr/bin/env python3
-# Copyright 2020 Canonical Ltd.
+# Copyright 2021 Canonical Ltd.
#
# Licensed under the Apache License, Version 2.0 (the "License"); you may
# not use this file except in compliance with the License. You may obtain
# osm-charmers@lists.launchpad.net
##
-import logging
-from typing import Any, Dict, NoReturn
-
-from ops.charm import CharmBase, CharmEvents
-from ops.framework import EventBase, EventSource, StoredState
-from ops.main import main
-from ops.model import ActiveStatus, BlockedStatus, MaintenanceStatus
-from oci_image import OCIImageResource, OCIImageResourceError
-
-from pod_spec import make_pod_spec
-
-LOGGER = logging.getLogger(__name__)
-
-MON_PORT = 8000
-
+# pylint: disable=E0213
-class ConfigurePodEvent(EventBase):
- """Configure Pod event"""
- pass
-
-
-class MonEvents(CharmEvents):
- """MON Events"""
+import base64
+import logging
+from typing import NoReturn, Optional
- configure_pod = EventSource(ConfigurePodEvent)
+from ops.main import main
+from opslib.osm.charm import CharmedOsmBase, RelationsMissing
+from opslib.osm.interfaces.kafka import KafkaClient
+from opslib.osm.interfaces.keystone import KeystoneClient
+from opslib.osm.interfaces.mongo import MongoClient
+from opslib.osm.interfaces.prometheus import PrometheusClient
+from opslib.osm.pod import (
+ ContainerV3Builder,
+ FilesV3Builder,
+ PodRestartPolicy,
+ PodSpecV3Builder,
+)
+from opslib.osm.validator import ModelValidator, validator
+
+
+logger = logging.getLogger(__name__)
+
+PORT = 8000
+
+
+def _check_certificate_data(name: str, content: str):
+ if not name or not content:
+ raise ValueError("certificate name and content must be a non-empty string")
+
+
+def _extract_certificates(certs_config: str):
+ certificates = {}
+ if certs_config:
+ cert_list = certs_config.split(",")
+ for cert in cert_list:
+ name, content = cert.split(":")
+ _check_certificate_data(name, content)
+ certificates[name] = content
+ return certificates
+
+
+def decode(content: str):
+ return base64.b64decode(content.encode("utf-8")).decode("utf-8")
+
+
+class ConfigModel(ModelValidator):
+ keystone_enabled: bool
+ vca_host: str
+ vca_user: str
+ vca_secret: str
+ vca_cacert: str
+ database_commonkey: str
+ mongodb_uri: Optional[str]
+ log_level: str
+ openstack_default_granularity: int
+ global_request_timeout: int
+ collector_interval: int
+ evaluator_interval: int
+ grafana_url: str
+ grafana_user: str
+ grafana_password: str
+ certificates: Optional[str]
+ image_pull_policy: str
+ debug_mode: bool
+ security_context: bool
+
+ @validator("log_level")
+ def validate_log_level(cls, v):
+ if v not in {"INFO", "DEBUG"}:
+ raise ValueError("value must be INFO or DEBUG")
+ return v
+
+ @validator("certificates")
+ def validate_certificates(cls, v):
+ # Raises an exception if it cannot extract the certificates
+ _extract_certificates(v)
+ return v
+
+ @validator("mongodb_uri")
+ def validate_mongodb_uri(cls, v):
+ if v and not v.startswith("mongodb://"):
+ raise ValueError("mongodb_uri is not properly formed")
+ return v
+
+ @validator("image_pull_policy")
+ def validate_image_pull_policy(cls, v):
+ values = {
+ "always": "Always",
+ "ifnotpresent": "IfNotPresent",
+ "never": "Never",
+ }
+ v = v.lower()
+ if v not in values.keys():
+ raise ValueError("value must be always, ifnotpresent or never")
+ return values[v]
-class MonCharm(CharmBase):
- """MON Charm."""
+ @property
+ def certificates_dict(cls):
+ return _extract_certificates(cls.certificates) if cls.certificates else {}
- state = StoredState()
- on = MonEvents()
+class MonCharm(CharmedOsmBase):
def __init__(self, *args) -> NoReturn:
- """MON Charm constructor."""
- super().__init__(*args)
-
- # Internal state initialization
- self.state.set_default(pod_spec=None)
-
- # Message bus data initialization
- self.state.set_default(message_host=None)
- self.state.set_default(message_port=None)
-
- # Database data initialization
- self.state.set_default(database_uri=None)
-
- # Prometheus data initialization
- self.state.set_default(prometheus_host=None)
- self.state.set_default(prometheus_port=None)
-
- self.port = MON_PORT
- self.image = OCIImageResource(self, "image")
-
- # Registering regular events
- self.framework.observe(self.on.start, self.configure_pod)
- self.framework.observe(self.on.config_changed, self.configure_pod)
- self.framework.observe(self.on.upgrade_charm, self.configure_pod)
-
- # Registering custom internal events
- self.framework.observe(self.on.configure_pod, self.configure_pod)
-
- # Registering required relation events
- self.framework.observe(
- self.on.kafka_relation_changed, self._on_kafka_relation_changed
- )
- self.framework.observe(
- self.on.mongodb_relation_changed, self._on_mongodb_relation_changed
- )
- self.framework.observe(
- self.on.prometheus_relation_changed, self._on_prometheus_relation_changed
+ super().__init__(
+ *args,
+ oci_image="image",
+ vscode_workspace=VSCODE_WORKSPACE,
)
+ if self.config.get("debug_mode"):
+ self.enable_debug_mode(
+ pubkey=self.config.get("debug_pubkey"),
+ hostpaths={
+ "MON": {
+ "hostpath": self.config.get("debug_mon_local_path"),
+ "container-path": "/usr/lib/python3/dist-packages/osm_mon",
+ },
+ "N2VC": {
+ "hostpath": self.config.get("debug_n2vc_local_path"),
+ "container-path": "/usr/lib/python3/dist-packages/n2vc",
+ },
+ "osm_common": {
+ "hostpath": self.config.get("debug_common_local_path"),
+ "container-path": "/usr/lib/python3/dist-packages/osm_common",
+ },
+ },
+ )
+ self.kafka_client = KafkaClient(self, "kafka")
+ self.framework.observe(self.on["kafka"].relation_changed, self.configure_pod)
+ self.framework.observe(self.on["kafka"].relation_broken, self.configure_pod)
- # Registering required relation departed events
- self.framework.observe(
- self.on.kafka_relation_departed, self._on_kafka_relation_departed
- )
+ self.mongodb_client = MongoClient(self, "mongodb")
+ self.framework.observe(self.on["mongodb"].relation_changed, self.configure_pod)
+ self.framework.observe(self.on["mongodb"].relation_broken, self.configure_pod)
+
+ self.prometheus_client = PrometheusClient(self, "prometheus")
self.framework.observe(
- self.on.mongodb_relation_departed, self._on_mongodb_relation_departed
+ self.on["prometheus"].relation_changed, self.configure_pod
)
self.framework.observe(
- self.on.prometheus_relation_departed, self._on_prometheus_relation_departed
+ self.on["prometheus"].relation_broken, self.configure_pod
)
- def _on_kafka_relation_changed(self, event: EventBase) -> NoReturn:
- """Reads information about the kafka relation.
+ self.keystone_client = KeystoneClient(self, "keystone")
+ self.framework.observe(self.on["keystone"].relation_changed, self.configure_pod)
+ self.framework.observe(self.on["keystone"].relation_broken, self.configure_pod)
- Args:
- event (EventBase): Kafka relation event.
- """
- message_host = event.relation.data[event.unit].get("host")
- message_port = event.relation.data[event.unit].get("port")
+ def _check_missing_dependencies(self, config: ConfigModel):
+ missing_relations = []
if (
- message_host
- and message_port
- and (
- self.state.message_host != message_host
- or self.state.message_port != message_port
- )
- ):
- self.state.message_host = message_host
- self.state.message_port = message_port
- self.on.configure_pod.emit()
-
- def _on_kafka_relation_departed(self, event: EventBase) -> NoReturn:
- """Clear kafka relation data.
-
- Args:
- event (EventBase): Kafka relation event.
- """
- self.state.message_host = None
- self.state.message_port = None
- self.on.configure_pod.emit()
-
- def _on_mongodb_relation_changed(self, event: EventBase) -> NoReturn:
- """Reads information about the DB relation.
-
- Args:
- event (EventBase): DB relation event.
- """
- database_uri = event.relation.data[event.unit].get("connection_string")
-
- if database_uri and self.state.database_uri != database_uri:
- self.state.database_uri = database_uri
- self.on.configure_pod.emit()
-
- def _on_mongodb_relation_departed(self, event: EventBase) -> NoReturn:
- """Clear mongodb relation data.
-
- Args:
- event (EventBase): DB relation event.
- """
- self.state.database_uri = None
- self.on.configure_pod.emit()
-
- def _on_prometheus_relation_changed(self, event: EventBase) -> NoReturn:
- """Reads information about the prometheus relation.
-
- Args:
- event (EventBase): Prometheus relation event.
- """
- prometheus_host = event.relation.data[event.unit].get("hostname")
- prometheus_port = event.relation.data[event.unit].get("port")
-
- if (
- prometheus_host
- and prometheus_port
- and (
- self.state.prometheus_host != prometheus_host
- or self.state.prometheus_port != prometheus_port
- )
+ self.kafka_client.is_missing_data_in_unit()
+ and self.kafka_client.is_missing_data_in_app()
):
- self.state.prometheus_host = prometheus_host
- self.state.prometheus_port = prometheus_port
- self.on.configure_pod.emit()
-
- def _on_prometheus_relation_departed(self, event: EventBase) -> NoReturn:
- """Clear prometheus relation data.
-
- Args:
- event (EventBase): Prometheus relation event.
- """
- self.state.prometheus_host = None
- self.state.prometheus_port = None
- self.on.configure_pod.emit()
-
- def _missing_relations(self) -> str:
- """Checks if there missing relations.
-
- Returns:
- str: string with missing relations
- """
- data_status = {
- "kafka": self.state.message_host,
- "mongodb": self.state.database_uri,
- "prometheus": self.state.prometheus_host,
- }
-
- missing_relations = [k for k, v in data_status.items() if not v]
-
- return ", ".join(missing_relations)
+ missing_relations.append("kafka")
+ if not config.mongodb_uri and self.mongodb_client.is_missing_data_in_unit():
+ missing_relations.append("mongodb")
+ if self.prometheus_client.is_missing_data_in_app():
+ missing_relations.append("prometheus")
+ if config.keystone_enabled:
+ if self.keystone_client.is_missing_data_in_app():
+ missing_relations.append("keystone")
+
+ if missing_relations:
+ raise RelationsMissing(missing_relations)
+
+ def _build_cert_files(
+ self,
+ config: ConfigModel,
+ ):
+ cert_files_builder = FilesV3Builder()
+ for name, content in config.certificates_dict.items():
+ cert_files_builder.add_file(name, decode(content), mode=0o600)
+ return cert_files_builder.build()
+
+ def build_pod_spec(self, image_info):
+ # Validate config
+ config = ConfigModel(**dict(self.config))
+
+ if config.mongodb_uri and not self.mongodb_client.is_missing_data_in_unit():
+ raise Exception("Mongodb data cannot be provided via config and relation")
+
+ # Check relations
+ self._check_missing_dependencies(config)
+
+ security_context_enabled = (
+ config.security_context if not config.debug_mode else False
+ )
- @property
- def relation_state(self) -> Dict[str, Any]:
- """Collects relation state configuration for pod spec assembly.
-
- Returns:
- Dict[str, Any]: relation state information.
- """
- relation_state = {
- "message_host": self.state.message_host,
- "message_port": self.state.message_port,
- "database_uri": self.state.database_uri,
- "prometheus_host": self.state.prometheus_host,
- "prometheus_port": self.state.prometheus_port,
- }
+ # Create Builder for the PodSpec
+ pod_spec_builder = PodSpecV3Builder(
+ enable_security_context=security_context_enabled
+ )
- return relation_state
+ # Add secrets to the pod
+ mongodb_secret_name = f"{self.app.name}-mongodb-secret"
+ pod_spec_builder.add_secret(
+ mongodb_secret_name,
+ {
+ "uri": config.mongodb_uri or self.mongodb_client.connection_string,
+ "commonkey": config.database_commonkey,
+ },
+ )
+ grafana_secret_name = f"{self.app.name}-grafana-secret"
+ pod_spec_builder.add_secret(
+ grafana_secret_name,
+ {
+ "url": config.grafana_url,
+ "user": config.grafana_user,
+ "password": config.grafana_password,
+ },
+ )
- def configure_pod(self, event: EventBase) -> NoReturn:
- """Assemble the pod spec and apply it, if possible.
+ vca_secret_name = f"{self.app.name}-vca-secret"
+ pod_spec_builder.add_secret(
+ vca_secret_name,
+ {
+ "host": config.vca_host,
+ "user": config.vca_user,
+ "secret": config.vca_secret,
+ "cacert": config.vca_cacert,
+ },
+ )
- Args:
- event (EventBase): Hook or Relation event that started the
- function.
- """
- if missing := self._missing_relations():
- self.unit.status = BlockedStatus(
- "Waiting for {0} relation{1}".format(
- missing, "s" if "," in missing else ""
- )
+ # Build Container
+ container_builder = ContainerV3Builder(
+ self.app.name,
+ image_info,
+ config.image_pull_policy,
+ run_as_non_root=security_context_enabled,
+ )
+ certs_files = self._build_cert_files(config)
+
+ if certs_files:
+ container_builder.add_volume_config("certs", "/certs", certs_files)
+
+ container_builder.add_port(name=self.app.name, port=PORT)
+ container_builder.add_envs(
+ {
+ # General configuration
+ "ALLOW_ANONYMOUS_LOGIN": "yes",
+ "OSMMON_OPENSTACK_DEFAULT_GRANULARITY": config.openstack_default_granularity,
+ "OSMMON_GLOBAL_REQUEST_TIMEOUT": config.global_request_timeout,
+ "OSMMON_GLOBAL_LOGLEVEL": config.log_level,
+ "OSMMON_COLLECTOR_INTERVAL": config.collector_interval,
+ "OSMMON_EVALUATOR_INTERVAL": config.evaluator_interval,
+ # Kafka configuration
+ "OSMMON_MESSAGE_DRIVER": "kafka",
+ "OSMMON_MESSAGE_HOST": self.kafka_client.host,
+ "OSMMON_MESSAGE_PORT": self.kafka_client.port,
+ # Database configuration
+ "OSMMON_DATABASE_DRIVER": "mongo",
+ # Prometheus configuration
+ "OSMMON_PROMETHEUS_URL": f"http://{self.prometheus_client.hostname}:{self.prometheus_client.port}",
+ }
+ )
+ prometheus_user = self.prometheus_client.user
+ prometheus_password = self.prometheus_client.password
+ if prometheus_user and prometheus_password:
+ container_builder.add_envs(
+ {
+ "OSMMON_PROMETHEUS_USER": prometheus_user,
+ "OSMMON_PROMETHEUS_PASSWORD": prometheus_password,
+ }
)
- return
-
- if not self.unit.is_leader():
- self.unit.status = ActiveStatus("ready")
- return
-
- self.unit.status = MaintenanceStatus("Assembling pod spec")
-
- # Fetch image information
- try:
- self.unit.status = MaintenanceStatus("Fetching image information")
- image_info = self.image.fetch()
- except OCIImageResourceError:
- self.unit.status = BlockedStatus("Error fetching image information")
- return
-
- try:
- pod_spec = make_pod_spec(
- image_info,
- self.model.config,
- self.relation_state,
- self.model.app.name,
- self.port,
+ container_builder.add_secret_envs(
+ secret_name=mongodb_secret_name,
+ envs={
+ "OSMMON_DATABASE_URI": "uri",
+ "OSMMON_DATABASE_COMMONKEY": "commonkey",
+ },
+ )
+ container_builder.add_secret_envs(
+ secret_name=vca_secret_name,
+ envs={
+ "OSMMON_VCA_HOST": "host",
+ "OSMMON_VCA_USER": "user",
+ "OSMMON_VCA_SECRET": "secret",
+ "OSMMON_VCA_CACERT": "cacert",
+ },
+ )
+ container_builder.add_secret_envs(
+ secret_name=grafana_secret_name,
+ envs={
+ "OSMMON_GRAFANA_URL": "url",
+ "OSMMON_GRAFANA_USER": "user",
+ "OSMMON_GRAFANA_PASSWORD": "password",
+ },
+ )
+ if config.keystone_enabled:
+ keystone_secret_name = f"{self.app.name}-keystone-secret"
+ pod_spec_builder.add_secret(
+ keystone_secret_name,
+ {
+ "url": self.keystone_client.host,
+ "user_domain": self.keystone_client.user_domain_name,
+ "project_domain": self.keystone_client.project_domain_name,
+ "service_username": self.keystone_client.username,
+ "service_password": self.keystone_client.password,
+ "service_project": self.keystone_client.service,
+ },
)
- except ValueError as exc:
- LOGGER.exception("Config/Relation data validation error")
- self.unit.status = BlockedStatus(str(exc))
- return
-
- if self.state.pod_spec != pod_spec:
- self.model.pod.set_spec(pod_spec)
- self.state.pod_spec = pod_spec
-
- self.unit.status = ActiveStatus("ready")
-
-
+ container_builder.add_env("OSMMON_KEYSTONE_ENABLED", True)
+ container_builder.add_secret_envs(
+ secret_name=keystone_secret_name,
+ envs={
+ "OSMMON_KEYSTONE_URL": "url",
+ "OSMMON_KEYSTONE_DOMAIN_NAME": "user_domain",
+ "OSMMON_KEYSTONE_PROJECT_DOMAIN_NAME": "project_domain",
+ "OSMMON_KEYSTONE_SERVICE_USER": "service_username",
+ "OSMMON_KEYSTONE_SERVICE_PASSWORD": "service_password",
+ "OSMMON_KEYSTONE_SERVICE_PROJECT": "service_project",
+ },
+ )
+ container = container_builder.build()
+
+ # Add restart policy
+ restart_policy = PodRestartPolicy()
+ restart_policy.add_secrets()
+ pod_spec_builder.set_restart_policy(restart_policy)
+
+ # Add container to pod spec
+ pod_spec_builder.add_container(container)
+
+ return pod_spec_builder.build()
+
+
+VSCODE_WORKSPACE = {
+ "folders": [
+ {"path": "/usr/lib/python3/dist-packages/osm_mon"},
+ {"path": "/usr/lib/python3/dist-packages/osm_common"},
+ {"path": "/usr/lib/python3/dist-packages/n2vc"},
+ ],
+ "settings": {},
+ "launch": {
+ "version": "0.2.0",
+ "configurations": [
+ {
+ "name": "MON Server",
+ "type": "python",
+ "request": "launch",
+ "module": "osm_mon.cmd.mon_server",
+ "justMyCode": False,
+ },
+ {
+ "name": "MON evaluator",
+ "type": "python",
+ "request": "launch",
+ "module": "osm_mon.cmd.mon_evaluator",
+ "justMyCode": False,
+ },
+ {
+ "name": "MON collector",
+ "type": "python",
+ "request": "launch",
+ "module": "osm_mon.cmd.mon_collector",
+ "justMyCode": False,
+ },
+ {
+ "name": "MON dashboarder",
+ "type": "python",
+ "request": "launch",
+ "module": "osm_mon.cmd.mon_dashboarder",
+ "justMyCode": False,
+ },
+ ],
+ },
+}
if __name__ == "__main__":
main(MonCharm)