try to resolve differnces between name of admin role at different deployments running...
[plstackapi.git] / planetstack / openstack / driver.py
1 import commands
2 import hashlib
3 from planetstack.config import Config
4
5 try:
6     from openstack.client import OpenStackClient
7     has_openstack = True
8 except:
9     has_openstack = False
10
11 manager_enabled = Config().api_nova_enabled
12
13 class OpenStackDriver:
14
15     def __init__(self, config = None, client=None, deployment=None):
16         if config:
17             self.config = Config(config)
18         else:
19             self.config = Config()
20
21         self.admin_client = OpenStackClient(deployment=deployment)
22         self.admin_user = self.admin_client.keystone.users.find(name=self.admin_client.keystone.username)
23
24         if client:
25             self.shell = client
26         else:
27             self.shell = OpenStackClient(deployment=deployment)
28
29         self.enabled = manager_enabled
30         self.has_openstack = has_openstack
31
32     def client_driver(self, caller=None, tenant=None, deployment=None):
33         if caller:
34             auth = {'username': caller.email,
35                     'password': hashlib.md5(caller.password).hexdigest()[:6],
36                     'tenant': tenant}
37             client = OpenStackClient(deployment=deployment, **auth)
38         else:
39             client = OpenStackClient(tenant=tenant, deployment=deployment)
40
41         driver = OpenStackDriver(client=client, deployment=deployment)
42         return driver
43
44     def admin_driver(self, tenant=None, deployment=None):
45         client = OpenStackClient(tenant=tenant, deployment=deployment)
46         driver = OpenStackDriver(client=client, deployment=deployment)
47         return driver    
48
49     def create_role(self, name):
50         roles = self.shell.keystone.roles.findall(name=name)
51         if not roles:
52             role = self.shell.keystone.roles.create(name)
53         else:
54             role = roles[0]
55         return role
56
57     def delete_role(self, filter):
58         roles = self.shell.keystone.roles.findall(**filter)
59         for role in roles:
60             self.shell.keystone.roles.delete(role)
61         return 1
62
63     def create_tenant(self, tenant_name, enabled, description):
64         """Create keystone tenant. Suggested fields: name, description, enabled"""  
65         tenants = self.shell.keystone.tenants.findall(name=tenant_name)
66         if not tenants:
67             fields = {'tenant_name': tenant_name, 'enabled': enabled, 
68                       'description': description}  
69             tenant = self.shell.keystone.tenants.create(**fields)
70         else:
71             tenant = tenants[0]
72
73         # always give the admin user the admin role to any tenant created 
74         # by the driver. 
75         self.add_user_role(self.admin_user.id, tenant.id, 'admin')
76         return tenant
77
78     def update_tenant(self, id, **kwds):
79         return self.shell.keystone.tenants.update(id, **kwds)
80
81     def delete_tenant(self, id):
82         ctx = self.shell.nova_db.ctx
83         tenants = self.shell.keystone.tenants.findall(id=id)
84         for tenant in tenants:
85             # nova does not automatically delete the tenant's instances
86             # so we manually delete instances before deleteing the tenant   
87             instances = self.shell.nova_db.instance_get_all_by_filters(ctx,
88                        {'project_id': tenant.id}, 'id', 'asc')
89             client = OpenStackClient(tenant=tenant.name)
90             driver = OpenStackDriver(client=client)
91             for instance in instances:
92                 driver.destroy_instance(instance.id)
93             self.shell.keystone.tenants.delete(tenant)
94         return 1
95
96     def create_user(self, name, email, password, enabled):
97         users = self.shell.keystone.users.findall(email=email)
98         if not users:
99             fields = {'name': name, 'email': email, 'password': password,
100                       'enabled': enabled}
101             user = self.shell.keystone.users.create(**fields)
102         else: 
103             user = users[0]
104         return user
105
106     def delete_user(self, id):
107         users = self.shell.keystone.users.findall(id=id)
108         for user in users:
109             # delete users keys
110             keys = self.shell.nova.keypairs.findall()
111             for key in keys:
112                 self.shell.nova.keypairs.delete(key)
113             self.shell.keystone.users.delete(user)
114         return 1 
115
116     def add_user_role(self, kuser_id, tenant_id, role_name):
117         user = self.shell.keystone.users.find(id=kuser_id)
118         tenant = self.shell.keystone.tenants.find(id=tenant_id)
119         # admin role can be lowercase or title. Look for both
120         role = None
121         if role_name.lower() == 'admin':
122             for admin_role_name in ['admin', 'Admin']:
123                 roles = self.shell.keystone.roles.findall(name=admin_role_name)
124                 if roles:
125                     role = roles[0]
126                     break
127         
128         if not role:
129             # look up non admin role or force exception when admin role isnt found 
130             role = self.shell.keystone.roles.find(name=role_name)                   
131
132         role_found = False
133         user_roles = user.list_roles(tenant.id)
134         for user_role in user_roles:
135             if user_role.name == role.name:
136                 role_found = True
137         if not role_found:
138             tenant.add_user(user, role)
139
140         return 1
141
142     def delete_user_role(self, kuser_id, tenant_id, role_name):
143         user = self.shell.keystone.users.find(id=kuser_id)
144         tenant = self.shell.keystone.tenants.find(id=tenant_id)
145         role = self.shell.keystone.roles.find(name=role_name)
146
147         role_found = False
148         user_roles = user.list_roles(tenant.id)
149         for user_role in user_roles:
150             if user_role.name == role.name:
151                 role_found = True
152         if role_found:
153             tenant.remove_user(user, role)
154
155         return 1 
156
157     def update_user(self, id, fields):
158         if 'password' in fields:
159             self.shell.keystone.users.update_password(id, fields['password'])
160         if 'enabled' in fields:
161             self.shell.keystone.users.update_enabled(id, fields['enabled']) 
162         return 1 
163
164     def create_router(self, name, set_gateway=True):
165         routers = self.shell.quantum.list_routers(name=name)['routers']
166         if routers:
167             router = routers[0]
168         else:
169             router = self.shell.quantum.create_router({'router': {'name': name}})['router']
170         # add router to external network
171         if set_gateway:
172             nets = self.shell.quantum.list_networks()['networks']
173             for net in nets:
174                 if net['router:external'] == True: 
175                     self.shell.quantum.add_gateway_router(router['id'],
176                                                           {'network_id': net['id']})
177         
178         return router
179
180     def delete_router(self, id):
181         routers = self.shell.quantum.list_routers(id=id)['routers']
182         for router in routers:
183             self.shell.quantum.delete_router(router['id'])
184             # remove router form external network
185             #nets = self.shell.quantum.list_networks()['networks']
186             #for net in nets:
187             #    if net['router:external'] == True:
188             #        self.shell.quantum.remove_gateway_router(router['id'])
189
190     def add_router_interface(self, router_id, subnet_id):
191         router = self.shell.quantum.show_router(router_id)['router']
192         subnet = self.shell.quantum.show_subnet(subnet_id)['subnet']
193         if router and subnet:
194             self.shell.quantum.add_interface_router(router_id, {'subnet_id': subnet_id})
195
196     def delete_router_interface(self, router_id, subnet_id):
197         router = self.shell.quantum.show_router(router_id)
198         subnet = self.shell.quantum.show_subnet(subnet_id)
199         if router and subnet:
200             self.shell.quantum.remove_interface_router(router_id, {'subnet_id': subnet_id})
201  
202     def create_network(self, name, shared=False):
203         nets = self.shell.quantum.list_networks(name=name)['networks']
204         if nets: 
205             net = nets[0]
206         else:
207             net = self.shell.quantum.create_network({'network': {'name': name, 'shared': shared}})['network']
208         return net
209  
210     def delete_network(self, id):
211         nets = self.shell.quantum.list_networks()['networks']
212         for net in nets:
213             if net['id'] == id:
214                 # delete_all ports
215                 self.delete_network_ports(net['id'])
216                 # delete all subnets:
217                 for subnet_id in net['subnets']:
218                     self.delete_subnet(subnet_id)
219                 self.shell.quantum.delete_network(net['id'])
220         return 1
221
222     def delete_network_ports(self, network_id):
223         ports = self.shell.quantum.list_ports()['ports']
224         for port in ports:
225             if port['network_id'] == network_id:
226                 self.shell.quantum.delete_port(port['id'])
227         return 1         
228
229     def delete_subnet_ports(self, subnet_id):
230         ports = self.shell.quantum.list_ports()['ports']
231         for port in ports:
232             delete = False
233             for fixed_ip in port['fixed_ips']:
234                 if fixed_ip['subnet_id'] == subnet_id:
235                     delete=True
236                     break
237             if delete:
238                 self.shell.quantum.delete_port(port['id'])
239         return 1
240  
241     def create_subnet(self, name, network_id, cidr_ip, ip_version, start, end):
242         #nets = self.shell.quantum.list_networks(name=network_name)['networks']
243         #if not nets:
244         #    raise Exception, "No such network: %s" % network_name   
245         #net = nets[0]
246
247         subnet = None 
248         subnets = self.shell.quantum.list_subnets()['subnets']
249         for snet in subnets:
250             if snet['cidr'] == cidr_ip and snet['network_id'] == network_id:
251                 subnet = snet
252
253         if not subnet:
254             allocation_pools = [{'start': start, 'end': end}]
255             subnet = {'subnet': {'name': name,
256                                  'network_id': network_id,
257                                  'ip_version': ip_version,
258                                  'cidr': cidr_ip,
259                                  'dns_nameservers': ['8.8.8.8', '8.8.4.4'],
260                                  'allocation_pools': allocation_pools}}
261             subnet = self.shell.quantum.create_subnet(subnet)['subnet']
262             self.add_external_route(subnet)
263         # TODO: Add route to external network
264         # e.g. #  route add -net 10.0.3.0/24 dev br-ex gw 10.100.0.5 
265         return subnet
266
267     def update_subnet(self, id, fields):
268         return self.shell.quantum.update_subnet(id, fields)
269
270     def delete_subnet(self, id):
271         #return self.shell.quantum.delete_subnet(id=id)
272         # inefficient but fault tolerant
273         subnets = self.shell.quantum.list_subnets()['subnets']
274         for subnet in subnets:
275             if subnet['id'] == id:
276                 self.delete_subnet_ports(subnet['id'])
277                 self.shell.quantum.delete_subnet(id)
278                 self.delete_external_route(subnet)
279         return 1
280
281     def get_external_routes(self):
282         status, output = commands.getstatusoutput('route')
283         routes = output.split('\n')[3:]
284         return routes
285
286     def add_external_route(self, subnet, routes=[]):
287         if not routes:
288             routes = self.get_external_routes()
289  
290         ports = self.shell.quantum.list_ports()['ports']
291
292         gw_ip = subnet['gateway_ip']
293         subnet_id = subnet['id']
294
295         # 1. Find the port associated with the subnet's gateway
296         # 2. Find the router associated with that port
297         # 3. Find the port associated with this router and on the external net
298         # 4. Set up route to the subnet through the port from step 3
299         ip_address = None
300         for port in ports:
301             for fixed_ip in port['fixed_ips']:
302                 if fixed_ip['subnet_id'] == subnet_id and fixed_ip['ip_address'] == gw_ip:
303                     gw_port = port
304                     router_id = gw_port['device_id']
305                     router = self.shell.quantum.show_router(router_id)['router']
306                     if router and router.get('external_gateway_info'):
307                         ext_net = router['external_gateway_info']['network_id']
308                         for port in ports:
309                             if port['device_id'] == router_id and port['network_id'] == ext_net:
310                                 ip_address = port['fixed_ips'][0]['ip_address']
311
312         if ip_address:
313             # check if external route already exists
314             route_exists = False
315             if routes:
316                 for route in routes:
317                     if subnet['cidr'] in route and ip_address in route:
318                         route_exists = True
319             if not route_exists:
320                 cmd = "route add -net %s dev br-ex gw %s" % (subnet['cidr'], ip_address)
321                 s, o = commands.getstatusoutput(cmd)
322                 #print cmd, "\n", s, o
323
324         return 1
325
326     def delete_external_route(self, subnet):
327         ports = self.shell.quantum.list_ports()['ports']
328
329         gw_ip = subnet['gateway_ip']
330         subnet_id = subnet['id']
331
332         # 1. Find the port associated with the subnet's gateway
333         # 2. Find the router associated with that port
334         # 3. Find the port associated with this router and on the external net
335         # 4. Set up route to the subnet through the port from step 3
336         ip_address = None
337         for port in ports:
338             for fixed_ip in port['fixed_ips']:
339                 if fixed_ip['subnet_id'] == subnet_id and fixed_ip['ip_address'] == gw_ip:
340                     gw_port = port
341                     router_id = gw_port['device_id']
342                     router = self.shell.quantum.show_router(router_id)['router']
343                     ext_net = router['external_gateway_info']['network_id']
344                     for port in ports:
345                         if port['device_id'] == router_id and port['network_id'] == ext_net:
346                             ip_address = port['fixed_ips'][0]['ip_address']
347
348         if ip_address:
349             cmd = "route delete -net %s" % (subnet['cidr'])
350             commands.getstatusoutput(cmd)
351              
352         return 1
353     
354     def create_keypair(self, name, public_key):
355         keys = self.shell.nova.keypairs.findall(name=name)
356         if keys:
357             key = keys[0]
358             # update key     
359             if key.public_key != public_key:
360                 self.delete_keypair(key.id)
361                 key = self.shell.nova.keypairs.create(name=name, public_key=public_key)
362         else:
363             key = self.shell.nova.keypairs.create(name=name, public_key=public_key)
364         return key
365
366     def delete_keypair(self, id):
367         keys = self.shell.nova.keypairs.findall(id=id)
368         for key in keys:
369             self.shell.nova.keypairs.delete(key) 
370         return 1
371
372     def get_private_networks(self, tenant=None):
373         if not tenant:
374             tenant = self.shell.nova.tenant
375         tenant = self.shell.keystone.tenants.find(name=tenant)
376         search_opts = {"tenant_id": tenant.id, "shared": False}
377         private_networks = self.shell.quantum.list_networks(**search_opts)
378         return private_networks
379
380     def get_shared_networks(self):
381         search_opts = {"shared": True}
382         shared_networks = self.shell.quantum.list_networks(**search_opts)
383         return shared_networks
384
385     def get_network_subnet(self, network_id):
386         subnet_id = None
387         subnet = None
388         if network_id:
389             os_networks = self.shell.quantum.list_networks(id=network_id)["networks"]
390             if os_networks:
391                 os_network = os_networks[0]
392                 if os_network['subnets']:
393                     subnet_id = os_network['subnets'][0]
394                     os_subnets = self.shell.quantum.list_subnets(id=subnet_id)['subnets']
395                     if os_subnets:
396                         subnet = os_subnets[0]['cidr']
397
398         return (subnet_id, subnet)
399
400     def spawn_instance(self, name, key_name=None, hostname=None, image_id=None, security_group=None, pubkeys=[], nics=None, metadata=None):
401         flavor_name = self.config.nova_default_flavor
402         flavor = self.shell.nova.flavors.find(name=flavor_name)
403         #if not image:
404         #    image = self.config.nova_default_imave
405         if not security_group:
406             security_group = self.config.nova_default_security_group
407
408         files = {}
409         if pubkeys:
410             files['/root/.ssh/authorized_keys'] = "\n".join(pubkeys)
411         hints = {}
412         availability_zone = None
413         if hostname:
414             availability_zone = 'nova:%s' % hostname
415         server = self.shell.nova.servers.create(
416                                             name=name,
417                                             key_name = key_name,
418                                             flavor=flavor.id,
419                                             image=image_id,
420                                             security_group = security_group,
421                                             files=files,
422                                             scheduler_hints=hints,
423                                             availability_zone=availability_zone,
424                                             nics=nics,
425                                             meta=metadata)
426         return server
427
428     def destroy_instance(self, id):
429         if (self.shell.nova.tenant=="admin"):
430             # findall() is implemented as a list() followed by a python search of the
431             # list. Since findall() doesn't accept "all_tenants", we do this using
432             # list() ourselves. This allows us to delete an instance as admin.
433             servers = self.shell.nova.servers.list(search_opts={"all_tenants": True})
434         else:
435             servers = self.shell.nova.servers.list()
436         for server in servers:
437             if server.id == id:
438                 result=self.shell.nova.servers.delete(server)
439
440     def update_instance_metadata(self, id, metadata):
441         servers = self.shell.nova.servers.findall(id=id)
442         for server in servers:
443             self.shell.nova.servers.set_meta(server, metadata)
444             # note: set_meta() returns a broken Server() object. Don't try to
445             # print it in the shell or it will fail in __repr__.
446
447     def delete_instance_metadata(self, id, metadata):
448         # note: metadata is a dict. Only the keys matter, not the values.
449         servers = self.shell.nova.servers.findall(id=id)
450         for server in servers:
451             self.shell.nova.servers.delete_meta(server, metadata)
452