X-Git-Url: https://git.openstreetmap.org./chef.git/blobdiff_plain/d1b835abf6c54e768ead54dd0056011554ba0b71..2bfb0ef07fb64314f5c4ded641a8c280df9c1d0b:/cookbooks/planet/recipes/replication.rb diff --git a/cookbooks/planet/recipes/replication.rb b/cookbooks/planet/recipes/replication.rb index 76b014867..a31f98288 100644 --- a/cookbooks/planet/recipes/replication.rb +++ b/cookbooks/planet/recipes/replication.rb @@ -17,22 +17,33 @@ # limitations under the License. # +require "yaml" + include_recipe "accounts" +include_recipe "apt" include_recipe "osmosis" +include_recipe "ruby" +include_recipe "tools" db_passwords = data_bag_item("db", "passwords") -package "postgresql-client" +## Install required packages -package "ruby" -package "ruby-dev" -package "ruby-libxml" +package %w[ + postgresql-client + ruby-libxml + make + gcc + libc6-dev + libpq-dev + osmdbt +] -package "make" -package "gcc" -package "libpq-dev" +gem_package "pg" do + gem_binary node[:ruby][:gem] +end -gem_package "pg" +## Build preload library to flush files remote_directory "/opt/flush" do source "flush" @@ -53,6 +64,8 @@ execute "/opt/flush/Makefile" do subscribes :run, "remote_directory[/opt/flush]" end +## Install scripts + remote_directory "/usr/local/bin" do source "replication-bin" owner "root" @@ -77,6 +90,8 @@ template "/usr/local/bin/users-deleted" do mode "755" end +## Published deleted users directory + remote_directory "/store/planet/users_deleted" do source "users_deleted" owner "planet" @@ -87,6 +102,8 @@ remote_directory "/store/planet/users_deleted" do files_mode "644" end +## Published replication directory + remote_directory "/store/planet/replication" do source "replication-cgi" owner "root" @@ -97,67 +114,182 @@ remote_directory "/store/planet/replication" do files_mode "755" end -directory "/store/planet/replication/changesets" do - owner "planet" - group "planet" +## Configuration directory + +directory "/etc/replication" do + owner "root" + group "root" mode "755" end -directory "/store/planet/replication/day" do +## Transient state directory + +systemd_tmpfile "/run/replication" do + type "d" owner "planet" group "planet" mode "755" end -directory "/store/planet/replication/hour" do +## Persistent state directory + +directory "/var/lib/replication" do owner "planet" group "planet" mode "755" end -directory "/store/planet/replication/minute" do +## Temporary directory + +directory "/store/replication" do owner "planet" group "planet" mode "755" end -directory "/etc/replication" do - owner "root" - group "root" - mode "755" +## Users replication + +template "/etc/replication/users-agreed.conf" do + source "users-agreed.conf.erb" + user "planet" + group "planet" + mode "600" + variables :password => db_passwords["planetdiff"] end -directory "/var/run/lock/changeset-replication/" do +systemd_service "users-agreed" do + description "Update list of users accepting CTs" + user "planet" + exec_start "/usr/local/bin/users-agreed" + private_tmp true + private_devices true + protect_system "full" + protect_home true + restrict_address_families %w[AF_INET AF_INET6] + no_new_privileges true +end + +systemd_timer "users-agreed" do + description "Update list of users accepting CTs" + on_calendar "7:00" +end + +systemd_service "users-deleted" do + description "Update list of deleted users" + user "planet" + exec_start "/usr/local/bin/users-deleted" + private_tmp true + private_devices true + protect_system "full" + protect_home true + restrict_address_families %w[AF_INET AF_INET6] + no_new_privileges true +end + +systemd_timer "users-deleted" do + description "Update list of deleted users" + on_calendar "17:00" +end + +## Changeset replication + +directory "/store/planet/replication/changesets" do owner "planet" group "planet" - mode "750" + mode "755" end -template "/etc/replication/auth.conf" do - source "replication.auth.erb" +template "/etc/replication/changesets.conf" do + source "changesets.conf.erb" user "root" group "planet" mode "640" variables :password => db_passwords["planetdiff"] end -template "/etc/replication/changesets.conf" do - source "changesets.conf.erb" +systemd_service "replication-changesets" do + description "Changesets replication" + user "planet" + exec_start "/usr/local/bin/replicate-changesets /etc/replication/changesets.conf" + private_tmp true + private_devices true + protect_system "full" + protect_home true + restrict_address_families %w[AF_INET AF_INET6] + no_new_privileges true +end + +systemd_timer "replication-changesets" do + description "Changesets replication" + on_boot_sec 60 + on_unit_active_sec 60 + accuracy_sec 5 +end + +## Minutely replication + +directory "/store/planet/replication/minute" do + owner "planet" + group "planet" + mode "755" +end + +directory "/var/lib/replication/minute" do + owner "planet" + group "planet" + mode "755" +end + +directory "/store/replication/minute" do + owner "planet" + group "planet" + mode "755" +end + +osmdbt_config = { + "database" => { + "host" => node[:web][:database_host], + "dbname" => "openstreetmap", + "user" => "planetdiff", + "password" => db_passwords["planetdiff"], + "replication_slot" => "osmdbt" + }, + "log_dir" => "/var/lib/replication/minute", + "changes_dir" => "/store/planet/replication/minute", + "tmp_dir" => "/store/replication/minute", + "run_dir" => "/run/replication" +} + +file "/etc/replication/osmdbt-config.yaml" do user "root" group "planet" mode "640" - variables :password => db_passwords["planetdiff"] + content YAML.dump(osmdbt_config) end -template "/etc/replication/users-agreed.conf" do - source "users-agreed.conf.erb" +systemd_service "replication-minutely" do + description "Minutely replication" user "planet" - group "planet" - mode "600" - variables :password => db_passwords["planetdiff"] + working_directory "/etc/replication" + exec_start "/usr/local/bin/replicate-minute" + private_tmp true + private_devices true + protect_system "full" + protect_home true + restrict_address_families %w[AF_INET AF_INET6] + no_new_privileges true end -directory "/var/lib/replication" do +systemd_timer "replication-minutely" do + description "Minutely replication" + on_boot_sec 60 + on_unit_active_sec 60 + accuracy_sec 5 +end + +## Hourly replication + +directory "/store/planet/replication/hour" do owner "planet" group "planet" mode "755" @@ -169,6 +301,10 @@ directory "/var/lib/replication/hour" do mode "755" end +link "/var/lib/replication/hour/data" do + to "/store/planet/replication/hour" +end + template "/var/lib/replication/hour/configuration.txt" do source "replication.config.erb" owner "planet" @@ -177,8 +313,30 @@ template "/var/lib/replication/hour/configuration.txt" do variables :base => "minute", :interval => 3600 end -link "/var/lib/replication/hour/data" do - to "/store/planet/replication/hour" +systemd_service "replication-hourly" do + description "Hourly replication" + user "planet" + exec_start "/usr/local/bin/osmosis -q --merge-replication-files workingDirectory=/var/lib/replication/hour" + environment "LD_PRELOAD" => "/opt/flush/flush.so" + private_tmp true + private_devices true + protect_system "full" + protect_home true + restrict_address_families %w[AF_INET AF_INET6] + no_new_privileges true +end + +systemd_timer "replication-hourly" do + description "Daily replication" + on_calendar "*-*-* *:02/15:00" +end + +## Daily replication + +directory "/store/planet/replication/day" do + owner "planet" + group "planet" + mode "755" end directory "/var/lib/replication/day" do @@ -187,6 +345,10 @@ directory "/var/lib/replication/day" do mode "755" end +link "/var/lib/replication/day/data" do + to "/store/planet/replication/day" +end + template "/var/lib/replication/day/configuration.txt" do source "replication.config.erb" owner "planet" @@ -195,112 +357,101 @@ template "/var/lib/replication/day/configuration.txt" do variables :base => "hour", :interval => 86400 end -link "/var/lib/replication/day/data" do - to "/store/planet/replication/day" +systemd_service "replication-daily" do + description "Daily replication" + user "planet" + exec_start "/usr/local/bin/osmosis -q --merge-replication-files workingDirectory=/var/lib/replication/day" + environment "LD_PRELOAD" => "/opt/flush/flush.so" + private_tmp true + private_devices true + protect_system "full" + protect_home true + restrict_address_families %w[AF_INET AF_INET6] + no_new_privileges true +end + +systemd_timer "replication-daily" do + description "Daily replication" + on_calendar "*-*-* *:02/15:00" end +## Replication cleanup + +systemd_service "replication-cleanup" do + description "Cleanup replication" + user "planet" + exec_start "/usr/local/bin/replicate-cleanup" + private_tmp true + private_devices true + private_network true + protect_system "full" + protect_home true + no_new_privileges true +end + +systemd_timer "replication-cleanup" do + description "Cleanup replication" + on_boot_sec 60 + on_unit_active_sec 86400 + accuracy_sec 1800 +end + +## Enable/disable feeds + if node[:planet][:replication] == "enabled" - cron_d "users-agreed" do - minute "0" - hour "7" - user "planet" - command "/usr/local/bin/users-agreed" - mailto "zerebubuth@gmail.com" + service "users-agreed.timer" do + action [:enable, :start] end - cron_d "users-deleted" do - minute "0" - hour "17" - user "planet" - command "/usr/local/bin/users-deleted" - mailto "zerebubuth@gmail.com" + service "users-deleted.timer" do + action [:enable, :start] end - cron_d "replication-changesets" do - user "planet" - command "/usr/local/bin/replicate-changesets /etc/replication/changesets.conf" - mailto "zerebubuth@gmail.com" + service "replication-changesets.timer" do + action [:enable, :start] end - cron_d "replication-minutely" do - user "planet" - command "/usr/local/bin/osmosis -q --replicate-apidb authFile=/etc/replication/auth.conf validateSchemaVersion=false --write-replication workingDirectory=/store/planet/replication/minute" - mailto "brett@bretth.com" - environment "LD_PRELOAD" => "/opt/flush/flush.so" + service "replication-minutely.timer" do + action [:enable, :start] end - cron_d "replication-hourly" do - minute "2,7,12,17" - user "planet" - command "/usr/local/bin/osmosis -q --merge-replication-files workingDirectory=/var/lib/replication/hour" - mailto "brett@bretth.com" - environment "LD_PRELOAD" => "/opt/flush/flush.so" + service "replication-hourly.timer" do + action [:enable, :start] end - cron_d "replication-daily" do - minute "5,10,15,20" - user "planet" - command "/usr/local/bin/osmosis -q --merge-replication-files workingDirectory=/var/lib/replication/day" - mailto "brett@bretth.com" - environment "LD_PRELOAD" => "/opt/flush/flush.so" + service "replication-daily.timer" do + action [:enable, :start] + end + + service "replication-cleanup.timer" do + action [:enable, :start] end else - cron_d "users-agreed" do - action :delete + service "users-agreed.timer" do + action [:stop, :disable] end - cron_d "users-deleted" do - action :delete + service "users-deleted.timer" do + action [:stop, :disable] end - cron_d "replication-changesets" do - action :delete + service "replication-changesets.timer" do + action [:stop, :disable] end - cron_d "replication-minutely" do - action :delete + service "replication-minutely.timer" do + action [:stop, :disable] end - cron_d "replication-hourly" do - action :delete + service "replication-hourly.timer" do + action [:stop, :disable] end - cron_d "replication-daily" do - action :delete + service "replication-daily.timer" do + action [:stop, :disable] end -end -# directory "/var/lib/replication/streaming" do -# owner "planet" -# group "planet" -# mode 0o755 -# end -# -# directory "/var/log/replication" do -# owner "planet" -# group "planet" -# mode 0o755 -# end -# -# ["streaming-replicator", "streaming-server"].each do |name| -# template "/etc/init.d/#{name}" do -# source "streaming.init.erb" -# owner "root" -# group "root" -# mode 0o755 -# variables :service => name -# end -# -# if node[:planet][:replication] == "enabled" -# service name do -# action [:enable, :start] -# supports :restart => true, :status => true -# subscribes :restart, "template[/etc/init.d/#{name}]" -# end -# else -# service name do -# action [:disable, :stop] -# supports :restart => true, :status => true -# end -# end -# end + service "replication-cleanup.timer" do + action [:stop, :disable] + end +end