Minor fix to charmed installer. Expose OSM_HOSTNAME properly
[osm/devops.git] / installers / charmed_install.sh
index bed7a14..e215ef2 100755 (executable)
 
 # set -eux
 
+JUJU_AGENT_VERSION=2.8.8
 K8S_CLOUD_NAME="k8s-cloud"
 KUBECTL="microk8s.kubectl"
+MICROK8S_VERSION=1.19
+OSMCLIENT_VERSION=9.0
 IMAGES_OVERLAY_FILE=~/.osm/images-overlay.yaml
+PATH=/snap/bin:${PATH}
+
+MODEL_NAME=osm
+
+OSM_BUNDLE=cs:osm-54
+OSM_HA_BUNDLE=cs:osm-ha-40
+TAG=9
+
 function check_arguments(){
     while [ $# -gt 0 ] ; do
         case $1 in
@@ -27,8 +38,9 @@ function check_arguments(){
             --lxd) LXD_CLOUD="$2" ;;
             --lxd-cred) LXD_CREDENTIALS="$2" ;;
             --microstack) MICROSTACK=y ;;
-            --ha) BUNDLE="cs:osm-ha-39" ;;
+            --ha) BUNDLE=$OSM_HA_BUNDLE ;;
             --tag) TAG="$2" ;;
+            --registry) REGISTRY_INFO="$2" ;;
         esac
         shift
     done
@@ -38,18 +50,25 @@ function check_arguments(){
 
 function install_snaps(){
     if [ ! -v KUBECFG ]; then
-        sudo snap install microk8s --classic
+        sudo snap install microk8s --classic --channel=${MICROK8S_VERSION}/stable
+        sudo cat /var/snap/microk8s/current/args/kube-apiserver | grep advertise-address || (
+                echo "--advertise-address $DEFAULT_IP" | sudo tee -a /var/snap/microk8s/current/args/kube-apiserver
+                microk8s.stop
+                microk8s.start
+            )
         sudo usermod -a -G microk8s `whoami`
         mkdir -p ~/.kube
         sudo chown -f -R `whoami` ~/.kube
         KUBEGRP="microk8s"
+        sg ${KUBEGRP} -c "microk8s status --wait-ready"
+        KUBECONFIG=~/.osm/microk8s-config.yaml
+        sg ${KUBEGRP} -c "microk8s config" | tee ${KUBECONFIG}
     else
         KUBECTL="kubectl"
         sudo snap install kubectl --classic
         export KUBECONFIG=${KUBECFG}
         KUBEGRP=$(id -g -n)
     fi
-    sleep 10
     sudo snap install juju --classic --channel=2.8/stable
 }
 
@@ -68,6 +87,17 @@ using this command:
    juju destroy-controller --release-storage --destroy-all-models -y ${CONTROLLER_NAME}
 
 Please retry the installation once this conflict has been resolved.
+EOF
+            exit 1
+        fi
+    else
+        CONTROLLER_PRESENT=$(juju controllers 2>/dev/null| grep ${CONTROLLER_NAME} | wc -l)
+        if [ $CONTROLLER_PRESENT -le 0 ]; then
+            cat << EOF
+Threre is no VCA present with the name "${CONTROLLER_NAME}".  Please specify a VCA
+that exists, or remove the --vca ${CONTROLLER_NAME} option.
+
+Please retry the installation with one of the solutions applied.
 EOF
             exit 1
         fi
@@ -77,9 +107,10 @@ EOF
         cat $KUBECFG | juju add-k8s $K8S_CLOUD_NAME $ADD_K8S_OPTS
         [ -v BOOTSTRAP_NEEDED ] && juju bootstrap $K8S_CLOUD_NAME $CONTROLLER_NAME \
             --config controller-service-type=loadbalancer \
-            --agent-version=2.8.3
+            --agent-version=$JUJU_AGENT_VERSION
     else
         sg ${KUBEGRP} -c "echo ${DEFAULT_IP}-${DEFAULT_IP} | microk8s.enable metallb"
+        sg ${KUBEGRP} -c "microk8s.enable ingress"
         sg ${KUBEGRP} -c "microk8s.enable storage dns"
         TIME_TO_WAIT=30
         start_time="$(date -u +%s)"
@@ -100,7 +131,7 @@ EOF
 
         [ ! -v BOOTSTRAP_NEEDED ] && sg ${KUBEGRP} -c "microk8s.config" | juju add-k8s $K8S_CLOUD_NAME $ADD_K8S_OPTS
         [ -v BOOTSTRAP_NEEDED ] && sg ${KUBEGRP} -c \
-            "juju bootstrap microk8s $CONTROLLER_NAME --config controller-service-type=loadbalancer --agent-version=2.8.1" \
+            "juju bootstrap microk8s $CONTROLLER_NAME --config controller-service-type=loadbalancer --agent-version=$JUJU_AGENT_VERSION" \
             && K8S_CLOUD_NAME=microk8s
     fi
 
@@ -119,7 +150,6 @@ EOF
         # Install LXD snap
         sudo apt-get remove --purge -y liblxc1 lxc-common lxcfs lxd lxd-client
         sudo snap install lxd
-        sudo apt-get install zfsutils-linux -y
         # Configure LXD
         sudo usermod -a -G lxd `whoami`
         cat /usr/share/osm-devops/installers/lxd-preseed.conf | sed 's/^config: {}/config:\n  core.https_address: '$LXDENDPOINT':8443/' | sg lxd -c "lxd init --preseed"
@@ -160,7 +190,6 @@ EOF
     juju add-cloud -c $CONTROLLER_NAME lxd-cloud $LXD_CLOUD --force
     juju add-credential -c $CONTROLLER_NAME lxd-cloud -f $LXD_CREDENTIALS
     sg lxd -c "lxd waitready"
-    #juju add-model test lxd-cloud || true
     juju controller-config features=[k8s-operators]
 }
 
@@ -177,7 +206,7 @@ function wait_for_port(){
             exit 1
         fi
 
-        if [ $(sg ${KUBEGRP} -c "${KUBECTL} get ingress -n osm -o json | jq -r '.items[$INDEX].metadata.name'") == ${SERVICE} ] ; then
+        if [ $(sg ${KUBEGRP} -c "${KUBECTL} get ingresses.networking -n osm -o json | jq -r '.items[$INDEX].metadata.name'") == ${SERVICE} ] ; then
             break
         fi
         sleep 1
@@ -185,27 +214,51 @@ function wait_for_port(){
 }
 
 function deploy_charmed_osm(){
+    if [ -v REGISTRY_INFO ] ; then
+        registry_parts=(${REGISTRY_INFO//@/ })
+        if [ ${#registry_parts[@]} -eq 1 ] ; then
+            # No credentials supplied
+            REGISTRY_USERNAME=""
+            REGISTRY_PASSWORD=""
+            REGISTRY_URL=${registry_parts[0]}
+        else
+            credentials=${registry_parts[0]}
+            credential_parts=(${credentials//:/ })
+            REGISTRY_USERNAME=${credential_parts[0]}
+            REGISTRY_PASSWORD=${credential_parts[1]}
+            REGISTRY_URL=${registry_parts[1]}
+        fi
+        # Ensure the URL ends with a /
+        case $REGISTRY_URL in
+            */) ;;
+            *) REGISTRY_URL=${REGISTRY_URL}/
+        esac
+    fi
+
     create_overlay
     echo "Creating OSM model"
     if [ -v KUBECFG ]; then
-        juju add-model osm $K8S_CLOUD_NAME
+        juju add-model $MODEL_NAME $K8S_CLOUD_NAME
     else
-        sg ${KUBEGRP} -c "juju add-model osm $K8S_CLOUD_NAME"
+        sg ${KUBEGRP} -c "juju add-model $MODEL_NAME $K8S_CLOUD_NAME"
     fi
     echo "Deploying OSM with charms"
     images_overlay=""
+    if [ -v REGISTRY_URL ]; then
+       [ ! -v TAG ] && TAG='latest'
+    fi
     [ -v TAG ] && generate_images_overlay && images_overlay="--overlay $IMAGES_OVERLAY_FILE"
+
     if [ -v BUNDLE ]; then
-        juju deploy $BUNDLE --overlay ~/.osm/vca-overlay.yaml $images_overlay
+        juju deploy -m $MODEL_NAME $BUNDLE --overlay ~/.osm/vca-overlay.yaml $images_overlay
     else
-        juju deploy cs:osm-49 --overlay ~/.osm/vca-overlay.yaml $images_overlay
+        juju deploy -m $MODEL_NAME $OSM_BUNDLE --overlay ~/.osm/vca-overlay.yaml $images_overlay
     fi
 
     echo "Waiting for deployment to finish..."
     check_osm_deployed
     echo "OSM with charms deployed"
     if [ ! -v KUBECFG ]; then
-        sg ${KUBEGRP} -c "microk8s.enable ingress"
         API_SERVER=${DEFAULT_IP}
     else
         API_SERVER=$(kubectl config view --minify | grep server | cut -f 2- -d ":" | tr -d " ")
@@ -216,34 +269,33 @@ function deploy_charmed_osm(){
         API_SERVER="$(echo $hostport | sed -e 's,:.*,,g')"
     fi
 
-    juju config nbi-k8s juju-external-hostname=nbi.${API_SERVER}.xip.io
-    juju expose nbi-k8s
-
-    wait_for_port nbi-k8s 0
-    sg ${KUBEGRP} -c "${KUBECTL} get ingress -n osm -o json | jq '.items[0].metadata.annotations += {\"nginx.ingress.kubernetes.io/backend-protocol\": \"HTTPS\"}' | ${KUBECTL} --validate=false replace -f -"
-    sg ${KUBEGRP} -c "${KUBECTL} get ingress -n osm -o json | jq '.items[0].metadata.annotations += {\"nginx.ingress.kubernetes.io/proxy-body-size\": \"0\"}' | ${KUBECTL} replace -f -"
-
-    juju config ng-ui juju-external-hostname=ui.${API_SERVER}.xip.io
-    juju expose ng-ui
+    # Expose OSM services
+    # Expose NBI
+    juju config -m $MODEL_NAME nbi site_url=https://nbi.${API_SERVER}.xip.io
+    juju config -m $MODEL_NAME ng-ui site_url=https://ui.${API_SERVER}.xip.io
 
-    wait_for_port ng-ui 1
-    sg ${KUBEGRP} -c "${KUBECTL} get ingress -n osm -o json | jq '.items[2].metadata.annotations += {\"nginx.ingress.kubernetes.io/proxy-body-size\": \"0\"}' | ${KUBECTL} --validate=false replace -f -"
+    # Expose Grafana
+    juju config -m $MODEL_NAME grafana-k8s juju-external-hostname=grafana.${API_SERVER}.xip.io
+    juju expose -m $MODEL_NAME grafana-k8s
+    wait_for_port grafana-k8s 0
 
-    juju config ui-k8s juju-external-hostname=osm.${API_SERVER}.xip.io
-    juju expose ui-k8s
+    # Expose Prometheus
+    juju config -m $MODEL_NAME prometheus-k8s juju-external-hostname=prometheus.${API_SERVER}.xip.io
+    juju expose -m $MODEL_NAME prometheus-k8s
+    wait_for_port prometheus-k8s 1
 
-    wait_for_port ui-k8s 2
-    sg ${KUBEGRP} -c "${KUBECTL} get ingress -n osm -o json | jq '.items[1].metadata.annotations += {\"nginx.ingress.kubernetes.io/proxy-body-size\": \"0\"}' | ${KUBECTL} --validate=false replace -f -"
+    # Apply annotations
+    sg ${KUBEGRP} -c "${KUBECTL} annotate ingresses.networking nginx.ingress.kubernetes.io/proxy-body-size=0 -n osm -l juju-app=ng-ui"
 }
 
 function check_osm_deployed() {
     TIME_TO_WAIT=600
     start_time="$(date -u +%s)"
-    total_service_count=15
+    total_service_count=14
     previous_count=0
     while true
     do
-        service_count=$(juju status | grep kubernetes | grep active | wc -l)
+        service_count=$(juju status -m $MODEL_NAME | grep kubernetes | grep active | wc -l)
         echo "$service_count / $total_service_count services active"
         if [ $service_count -eq $total_service_count ]; then
             break
@@ -263,18 +315,16 @@ function check_osm_deployed() {
 
 function create_overlay() {
     sudo snap install jq
-    sudo apt install python3-pip -y
-    python3 -m pip install yq
-    PATH=$PATH:$HOME/.local/bin  # make yq command available
+    sudo snap install yq
     local HOME=/home/$USER
-    local vca_user=$(cat $HOME/.local/share/juju/accounts.yaml | yq --arg CONTROLLER_NAME $CONTROLLER_NAME '.controllers[$CONTROLLER_NAME].user')
-    local vca_password=$(cat $HOME/.local/share/juju/accounts.yaml | yq --arg CONTROLLER_NAME $CONTROLLER_NAME '.controllers[$CONTROLLER_NAME].password')
-    local vca_host=$(cat $HOME/.local/share/juju/controllers.yaml | yq --arg CONTROLLER_NAME $CONTROLLER_NAME '.controllers[$CONTROLLER_NAME]["api-endpoints"][0]' --raw-output | cut -d ":" -f 1)
-    local vca_port=$(cat $HOME/.local/share/juju/controllers.yaml | yq --arg CONTROLLER_NAME $CONTROLLER_NAME '.controllers[$CONTROLLER_NAME]["api-endpoints"][0]' --raw-output | cut -d ":" -f 2)
+    local vca_user=$(cat $HOME/.local/share/juju/accounts.yaml | yq e .controllers.$CONTROLLER_NAME.user - )
+    local vca_password=$(cat $HOME/.local/share/juju/accounts.yaml | yq e .controllers.$CONTROLLER_NAME.password - )
+    local vca_host=$(cat $HOME/.local/share/juju/controllers.yaml | yq e .controllers.$CONTROLLER_NAME.api-endpoints[0] - | cut -d ":" -f 1)
+    local vca_port=$(cat $HOME/.local/share/juju/controllers.yaml | yq e .controllers.$CONTROLLER_NAME.api-endpoints[0] - | cut -d ":" -f 2)
     local vca_pubkey=\"$(cat $HOME/.local/share/juju/ssh/juju_id_rsa.pub)\"
     local vca_cloud="lxd-cloud"
     # Get the VCA Certificate
-    local vca_cacert=$(cat $HOME/.local/share/juju/controllers.yaml | yq --arg CONTROLLER_NAME $CONTROLLER_NAME '.controllers[$CONTROLLER_NAME]["ca-cert"]' --raw-output | base64 | tr -d \\n)
+    local vca_cacert=$(cat $HOME/.local/share/juju/controllers.yaml | yq e .controllers.$CONTROLLER_NAME.ca-cert - | base64 | tr -d \\n)
 
     # Calculate the default route of this machine
     local DEFAULT_IF=`ip route list match 0.0.0.0 | awk '{print $5}'`
@@ -304,70 +354,141 @@ EOF
 }
 
 function generate_images_overlay(){
+    cat << EOF > /tmp/nbi_registry.yaml
+registrypath: ${REGISTRY_URL}opensourcemano/nbi:$TAG
+EOF
+    cat << EOF > /tmp/ng_ui_registry.yaml
+registrypath: ${REGISTRY_URL}opensourcemano/ng-ui:$TAG
+EOF
+    if [ ! -z "$REGISTRY_USERNAME" ] ; then
+        REGISTRY_CREDENTIALS=$(cat <<EOF
+
+      image_username: $REGISTRY_USERNAME
+      image_password: $REGISTRY_PASSWORD
+EOF
+    );
+    echo username: $REGISTRY_USERNAME >> /tmp/nbi_registry.yaml
+    echo password: $REGISTRY_PASSWORD >> /tmp/nbi_registry.yaml
+    echo username: $REGISTRY_USERNAME >> /tmp/ng_ui_registry.yaml
+    echo password: $REGISTRY_PASSWORD >> /tmp/ng_ui_registry.yaml
+fi
+
     cat << EOF > /tmp/images-overlay.yaml
 applications:
   lcm-k8s:
     options:
-      image: opensourcemano/lcm:$TAG
+      image: ${REGISTRY_URL}opensourcemano/lcm:$TAG ${REGISTRY_CREDENTIALS}
   mon-k8s:
     options:
-      image: opensourcemano/mon:$TAG
+      image: ${REGISTRY_URL}opensourcemano/mon:$TAG ${REGISTRY_CREDENTIALS}
   ro-k8s:
     options:
-      image: opensourcemano/ro:$TAG
-  nbi-k8s:
-    options:
-      image: opensourcemano/nbi:$TAG
+      image: ${REGISTRY_URL}opensourcemano/ro:$TAG ${REGISTRY_CREDENTIALS}
+  nbi:
+    resources:
+      image: /tmp/nbi_registry.yaml
   pol-k8s:
     options:
-      image: opensourcemano/pol:$TAG
-  ui-k8s:
-    options:
-      image: opensourcemano/light-ui:$TAG
+      image: ${REGISTRY_URL}opensourcemano/pol:$TAG ${REGISTRY_CREDENTIALS}
   pla:
     options:
-      image: opensourcemano/pla:$TAG
+      image: ${REGISTRY_URL}opensourcemano/pla:8 ${REGISTRY_CREDENTIALS}
   ng-ui:
+    resources:
+      image: /tmp/ng_ui_registry.yaml
+  keystone:
     options:
-      image: opensourcemano/ng-ui:$TAG
-
+      image: ${REGISTRY_URL}opensourcemano/keystone:$TAG ${REGISTRY_CREDENTIALS}
 EOF
     mv /tmp/images-overlay.yaml $IMAGES_OVERLAY_FILE
 }
 
+function refresh_osmclient_snap() {
+    osmclient_snap_install_refresh refresh
+}
+
+function install_osm_client_snap() {
+    osmclient_snap_install_refresh install
+}
+
+function osmclient_snap_install_refresh() {
+    channel_preference="stable candidate beta edge"
+    for channel in $channel_preference; do
+        echo "Trying to install osmclient from channel $OSMCLIENT_VERSION/$channel"
+        sudo snap $1 osmclient --channel $OSMCLIENT_VERSION/$channel 2> /dev/null && echo osmclient snap installed && break
+    done
+}
 function install_osmclient() {
-    sudo snap install osmclient
-    sudo snap alias osmclient.osm osm
+    snap info osmclient | grep -E ^installed: && refresh_osmclient_snap || install_osm_client_snap
 }
 
+function add_local_k8scluster() {
+    osm --all-projects vim-create \
+      --name _system-osm-vim \
+      --account_type dummy \
+      --auth_url http://dummy \
+      --user osm --password osm --tenant osm \
+      --description "dummy" \
+      --config '{management_network_name: mgmt}'
+    tmpfile=$(mktemp --tmpdir=${HOME})
+    cp ${KUBECONFIG} ${tmpfile}
+    osm --all-projects k8scluster-add \
+      --creds ${tmpfile} \
+      --vim _system-osm-vim \
+      --k8s-nets '{"net1": null}' \
+      --version '1.19' \
+      --description "OSM Internal Cluster" \
+      _system-osm-k8s
+    rm -f ${tmpfile}
+}
 
 function install_microstack() {
-    sudo snap install microstack --classic --beta
-    sudo microstack.init --auto
-    wget https://cloud-images.ubuntu.com/releases/16.04/release/ubuntu-16.04-server-cloudimg-amd64-disk1.img -P ~/.osm/
-    microstack.openstack image create \
-    --public \
-    --disk-format qcow2 \
-    --container-format bare \
-    --file ~/.osm/ubuntu-16.04-server-cloudimg-amd64-disk1.img \
-    ubuntu1604
-    ssh-keygen -t rsa -N "" -f ~/.ssh/microstack
-    microstack.openstack keypair create --public-key ~/.ssh/microstack.pub microstack
-    export OSM_HOSTNAME=`juju status --format json | jq -rc '.applications."nbi-k8s".address'`
-    osm vim-create --name microstack-site \
-    --user admin \
-    --password keystone \
-    --auth_url http://10.20.20.1:5000/v3 \
-    --tenant admin \
-    --account_type openstack \
-    --config='{security_groups: default,
-        keypair: microstack,
-        project_name: admin,
-        user_domain_name: default,
-        region_name: microstack,
-        insecure: True,
-        availability_zone: nova,
-    version: 3}'
+    # Install and init microstack
+    sudo snap install microstack --channel beta --devmode
+    sudo snap set microstack config.network.ports.dashboard=8080
+    sudo microstack.init --auto --control
+
+    # Basic configuration
+    microstack.openstack network create --enable --no-share osm-ext
+    microstack.openstack subnet create osm-ext-subnet --network osm-ext --dns-nameserver 8.8.8.8 --subnet-range 172.16.0.0/24
+    microstack.openstack router create external-router
+    microstack.openstack router add subnet external-router osm-ext-subnet
+    microstack.openstack router set --external-gateway external external-router
+    for i in $(microstack.openstack security group list | awk '/default/{ print $2 }'); do
+        microstack.openstack security group rule create $i --protocol icmp --remote-ip 0.0.0.0/0
+        microstack.openstack security group rule create $i --protocol tcp --remote-ip 0.0.0.0/0
+    done
+    KEYPAIR_PATH=~/.ssh/microstack
+    if ! test -f $KEYPAIR_PATH; then
+        echo "Generating ssh keypair for microstack"
+        ssh-keygen -t rsa -N "" -f $KEYPAIR_PATH
+    fi
+    microstack.openstack keypair create --public-key $KEYPAIR_PATH.pub microstack
+
+    # Add xenial, bionic, and focal images to microstack
+    echo "curl https://cloud-images.ubuntu.com/xenial/current/xenial-server-cloudimg-amd64-disk1.img | microstack.openstack image create --public --container-format=bare --disk-format=qcow2 ubuntu16.04"
+    echo "curl https://cloud-images.ubuntu.com/bionic/current/bionic-server-cloudimg-amd64.img | microstack.openstack image create --public --container-format=bare --disk-format=qcow2 ubuntu18.04"
+    echo "curl https://cloud-images.ubuntu.com/focal/current/focal-server-cloudimg-amd64.img | microstack.openstack image create --public --container-format=bare --disk-format=qcow2 ubuntu20.04"
+
+    # Load ENV variables
+    . /var/snap/microstack/common/etc/microstack.rc
+    osm vim-create  --name microstack \
+                    --user "$OS_USERNAME" \
+                    --password "$OS_PASSWORD" \
+                    --auth_url "$OS_AUTH_URL/v3" \
+                    --tenant "$OS_USERNAME" \
+                    --account_type openstack \
+                    --config='{
+                        use_floating_ip: True,
+                        management_network_name: osm-ext,
+                        keypair: microstack,
+                        project_name: admin,
+                        user_domain_name: default,
+                        region_name: microstack,
+                        insecure: True,
+                        availability_zone: nova,
+                        version: 3
+                    }'
 }
 
 DEFAULT_IF=`ip route list match 0.0.0.0 | awk '{print $5}'`
@@ -379,11 +500,13 @@ install_snaps
 bootstrap_k8s_lxd
 deploy_charmed_osm
 install_osmclient
+export OSM_HOSTNAME=$(juju config nbi site_url | sed "s/http.*\?:\/\///"):443
+add_local_k8scluster
+
 if [ -v MICROSTACK ]; then
     install_microstack
 fi
 
-OSM_HOSTNAME=$(juju config nbi-k8s juju-external-hostname):443
 
 echo "Your installation is now complete, follow these steps for configuring the osmclient:"
 echo