X-Git-Url: https://git.openstreetmap.org./chef.git/blobdiff_plain/22430d66328dc1d5e794386b88184050341138c1..6e80972a94a18fc0b3d7911574460680d483f2d9:/cookbooks/planet/recipes/replication.rb diff --git a/cookbooks/planet/recipes/replication.rb b/cookbooks/planet/recipes/replication.rb index 2a5867bc5..5c07ae231 100644 --- a/cookbooks/planet/recipes/replication.rb +++ b/cookbooks/planet/recipes/replication.rb @@ -25,6 +25,8 @@ include_recipe "osmosis" db_passwords = data_bag_item("db", "passwords") +## Install required packages + package %w[ postgresql-client ruby @@ -32,12 +34,15 @@ package %w[ ruby-libxml make gcc + libc6-dev libpq-dev osmdbt ] gem_package "pg" +## Build preload library to flush files + remote_directory "/opt/flush" do source "flush" owner "root" @@ -57,6 +62,8 @@ execute "/opt/flush/Makefile" do subscribes :run, "remote_directory[/opt/flush]" end +## Install scripts + remote_directory "/usr/local/bin" do source "replication-bin" owner "root" @@ -67,13 +74,6 @@ remote_directory "/usr/local/bin" do files_mode "755" end -template "/usr/local/bin/replicate-minute" do - source "replicate-minute.erb" - owner "root" - group "root" - mode "755" -end - template "/usr/local/bin/users-agreed" do source "users-agreed.erb" owner "root" @@ -88,6 +88,8 @@ template "/usr/local/bin/users-deleted" do mode "755" end +## Published deleted users directory + remote_directory "/store/planet/users_deleted" do source "users_deleted" owner "planet" @@ -98,6 +100,8 @@ remote_directory "/store/planet/users_deleted" do files_mode "644" end +## Published replication directory + remote_directory "/store/planet/replication" do source "replication-cgi" owner "root" @@ -108,105 +112,85 @@ remote_directory "/store/planet/replication" do files_mode "755" end -directory "/store/planet/replication/changesets" do - owner "planet" - group "planet" - mode "755" -end +## Configuration directory -directory "/store/planet/replication/day" do - owner "planet" - group "planet" +directory "/etc/replication" do + owner "root" + group "root" mode "755" end -directory "/store/planet/replication/hour" do - owner "planet" - group "planet" - mode "755" -end +## Transient state directory -directory "/store/planet/replication/minute" do +systemd_tmpfile "/run/replication" do + type "d" owner "planet" group "planet" mode "755" end -directory "/store/planet/replication/test" do - owner "planet" - group "planet" - mode "755" -end +## Persistent state directory -directory "/store/planet/replication/test/day" do +directory "/var/lib/replication" do owner "planet" group "planet" mode "755" end -directory "/store/planet/replication/test/hour" do - owner "planet" - group "planet" - mode "755" -end +## Temporary directory -directory "/store/planet/replication/test/minute" do +directory "/store/replication" do owner "planet" group "planet" mode "755" end -directory "/store/replication" do - owner "planet" +## Users replication + +template "/etc/replication/users-agreed.conf" do + source "users-agreed.conf.erb" + user "planet" group "planet" - mode "755" + mode "600" + variables :password => db_passwords["planetdiff"] end -directory "/store/replication/minute" do +## Changeset replication + +directory "/store/planet/replication/changesets" do owner "planet" group "planet" mode "755" end -systemd_tmpfile "/run/replication" do - type "d" - owner "planet" +template "/etc/replication/changesets.conf" do + source "changesets.conf.erb" + user "root" group "planet" - mode "755" + mode "640" + variables :password => db_passwords["planetdiff"] end -directory "/etc/replication" do - owner "root" - group "root" - mode "755" -end +## Minutely replication -directory "/var/run/lock/changeset-replication/" do +directory "/store/planet/replication/minute" do owner "planet" group "planet" - mode "750" + mode "755" end -directory "/var/lib/replication" do +directory "/var/lib/replication/minute" do owner "planet" group "planet" mode "755" end -directory "/var/lib/replication/test" do +directory "/store/replication/minute" do owner "planet" group "planet" mode "755" end -template "/etc/replication/auth.conf" do - source "replication.auth.erb" - user "root" - group "planet" - mode "640" - variables :password => db_passwords["planetdiff"] -end - osmdbt_config = { "database" => { "host" => node[:web][:database_host], @@ -216,7 +200,7 @@ osmdbt_config = { "replication_slot" => "osmdbt" }, "log_dir" => "/var/lib/replication/minute", - "changes_dir" => "/store/planet/replication/test/minute", + "changes_dir" => "/store/planet/replication/minute", "tmp_dir" => "/store/replication/minute", "run_dir" => "/run/replication" } @@ -248,28 +232,36 @@ systemd_timer "replication-minutely" do accuracy_sec 5 end -directory "/var/lib/replication/test/hour" do +## Hourly replication + +directory "/store/planet/replication/hour" do owner "planet" group "planet" mode "755" end -template "/var/lib/replication/test/hour/configuration.txt" do - source "replication.config.erb" +directory "/var/lib/replication/hour" do owner "planet" group "planet" - mode "644" - variables :base => "test/minute", :interval => 3600 + mode "755" end -link "/var/lib/replication/test/hour/data" do - to "/store/planet/replication/test/hour" +link "/var/lib/replication/hour/data" do + to "/store/planet/replication/hour" +end + +template "/var/lib/replication/hour/configuration.txt" do + source "replication.config.erb" + owner "planet" + group "planet" + mode "644" + variables :base => "minute", :interval => 3600 end systemd_service "replication-hourly" do description "Hourly replication" user "planet" - exec_start "/usr/local/bin/osmosis -q --merge-replication-files workingDirectory=/var/lib/replication/test/hour" + exec_start "/usr/local/bin/osmosis -q --merge-replication-files workingDirectory=/var/lib/replication/hour" private_tmp true private_devices true protect_system "full" @@ -283,28 +275,36 @@ systemd_timer "replication-hourly" do on_calendar "*-*-* *:02/15:00" end -directory "/var/lib/replication/test/day" do +## Daily replication + +directory "/store/planet/replication/day" do owner "planet" group "planet" mode "755" end -template "/var/lib/replication/test/day/configuration.txt" do - source "replication.config.erb" +directory "/var/lib/replication/day" do owner "planet" group "planet" - mode "644" - variables :base => "test/hour", :interval => 86400 + mode "755" end -link "/var/lib/replication/test/day/data" do - to "/store/planet/replication/test/day" +link "/var/lib/replication/day/data" do + to "/store/planet/replication/day" +end + +template "/var/lib/replication/day/configuration.txt" do + source "replication.config.erb" + owner "planet" + group "planet" + mode "644" + variables :base => "hour", :interval => 86400 end systemd_service "replication-daily" do description "Daily replication" user "planet" - exec_start "/usr/local/bin/osmosis -q --merge-replication-files workingDirectory=/var/lib/replication/test/day" + exec_start "/usr/local/bin/osmosis -q --merge-replication-files workingDirectory=/var/lib/replication/day" private_tmp true private_devices true protect_system "full" @@ -318,63 +318,28 @@ systemd_timer "replication-daily" do on_calendar "*-*-* *:02/15:00" end -template "/etc/replication/changesets.conf" do - source "changesets.conf.erb" - user "root" - group "planet" - mode "640" - variables :password => db_passwords["planetdiff"] -end +## Replication cleanup -template "/etc/replication/users-agreed.conf" do - source "users-agreed.conf.erb" +systemd_service "replication-cleanup" do + description "Cleanup replication" user "planet" - group "planet" - mode "600" - variables :password => db_passwords["planetdiff"] -end - -directory "/var/lib/replication/minute" do - owner "planet" - group "planet" - mode "755" -end - -directory "/var/lib/replication/hour" do - owner "planet" - group "planet" - mode "755" -end - -template "/var/lib/replication/hour/configuration.txt" do - source "replication.config.erb" - owner "planet" - group "planet" - mode "644" - variables :base => "minute", :interval => 3600 -end - -link "/var/lib/replication/hour/data" do - to "/store/planet/replication/hour" -end - -directory "/var/lib/replication/day" do - owner "planet" - group "planet" - mode "755" + exec_start "/usr/local/bin/replicate-cleanup" + private_tmp true + private_devices true + private_network true + protect_system "full" + protect_home true + no_new_privileges true end -template "/var/lib/replication/day/configuration.txt" do - source "replication.config.erb" - owner "planet" - group "planet" - mode "644" - variables :base => "hour", :interval => 86400 +systemd_timer "replication-cleanup" do + description "Cleanup replication" + on_boot_sec 60 + on_unit_active_sec 86400 + accuracy_sec 1800 end -link "/var/lib/replication/day/data" do - to "/store/planet/replication/day" -end +## Enable/disable feeds if node[:planet][:replication] == "enabled" cron_d "users-agreed" do @@ -411,27 +376,8 @@ if node[:planet][:replication] == "enabled" action [:enable, :start] end - cron_d "replication-minutely" do - user "planet" - command "/usr/local/bin/osmosis -q --replicate-apidb authFile=/etc/replication/auth.conf validateSchemaVersion=false --write-replication workingDirectory=/store/planet/replication/minute" - mailto "brett@bretth.com" - environment "LD_PRELOAD" => "/opt/flush/flush.so" - end - - cron_d "replication-hourly" do - minute "2,7,12,17" - user "planet" - command "/usr/local/bin/osmosis -q --merge-replication-files workingDirectory=/var/lib/replication/hour" - mailto "brett@bretth.com" - environment "LD_PRELOAD" => "/opt/flush/flush.so" - end - - cron_d "replication-daily" do - minute "5,10,15,20" - user "planet" - command "/usr/local/bin/osmosis -q --merge-replication-files workingDirectory=/var/lib/replication/day" - mailto "brett@bretth.com" - environment "LD_PRELOAD" => "/opt/flush/flush.so" + service "replication-cleanup.timer" do + action [:enable, :start] end else cron_d "users-agreed" do @@ -458,15 +404,7 @@ else action [:stop, :disable] end - cron_d "replication-minutely" do - action :delete - end - - cron_d "replication-hourly" do - action :delete - end - - cron_d "replication-daily" do - action :delete + service "replication-cleanup.timer" do + action [:stop, :disable] end end