Browse code

Revert "Revert "Use uwsgi for glance-api""

This reverts commit 3410e3e01bdbdbfd360d9baebeac081c33ee0821.

Change-Id: Ic58711311eb8534cb3c4b25c333197c412ffdce5

Matthew Treinish authored on 2017/06/24 07:32:37
Showing 4 changed files
... ...
@@ -275,12 +275,64 @@ function write_uwsgi_config {
275 275
     else
276 276
         local apache_conf=""
277 277
         apache_conf=$(apache_site_config_for $name)
278
-        echo "ProxyPass \"${url}\" \"unix:${socket}|uwsgi://uwsgi-uds-${name}/\" retry=0 " | sudo tee $apache_conf
278
+        echo "SetEnv proxy-sendcl 1" | sudo tee $apache_conf
279
+        echo "ProxyPass \"${url}\" \"unix:${socket}|uwsgi://uwsgi-uds-${name}/\" retry=0 " | sudo tee -a $apache_conf
279 280
         enable_apache_site $name
280 281
         restart_apache_server
281 282
     fi
282 283
 }
283 284
 
285
+# For services using chunked encoding, the only services known to use this
286
+# currently are Glance and Swift, we need to use an http proxy instead of
287
+# mod_proxy_uwsgi because the chunked encoding gets dropped. See:
288
+# https://github.com/unbit/uwsgi/issues/1540 You can workaround this on python2
289
+# but that involves having apache buffer the request before sending it to
290
+# uswgi.
291
+function write_local_uwsgi_http_config {
292
+    local file=$1
293
+    local wsgi=$2
294
+    local url=$3
295
+    name=$(basename $wsgi)
296
+
297
+    # create a home for the sockets; note don't use /tmp -- apache has
298
+    # a private view of it on some platforms.
299
+
300
+    # always cleanup given that we are using iniset here
301
+    rm -rf $file
302
+    iniset "$file" uwsgi wsgi-file "$wsgi"
303
+    port=$(get_random_port)
304
+    iniset "$file" uwsgi http "127.0.0.1:$port"
305
+    iniset "$file" uwsgi processes $API_WORKERS
306
+    # This is running standalone
307
+    iniset "$file" uwsgi master true
308
+    # Set die-on-term & exit-on-reload so that uwsgi shuts down
309
+    iniset "$file" uwsgi die-on-term true
310
+    iniset "$file" uwsgi exit-on-reload true
311
+    iniset "$file" uwsgi enable-threads true
312
+    iniset "$file" uwsgi plugins python
313
+    # uwsgi recommends this to prevent thundering herd on accept.
314
+    iniset "$file" uwsgi thunder-lock true
315
+    # Override the default size for headers from the 4k default.
316
+    iniset "$file" uwsgi buffer-size 65535
317
+    # Make sure the client doesn't try to re-use the connection.
318
+    iniset "$file" uwsgi add-header "Connection: close"
319
+    # This ensures that file descriptors aren't shared between processes.
320
+    iniset "$file" uwsgi lazy-apps true
321
+    iniset "$file" uwsgi chmod-socket 666
322
+    iniset "$file" uwsgi http-raw-body true
323
+    iniset "$file" uwsgi http-chunked-input true
324
+    iniset "$file" uwsgi http-auto-chunked true
325
+
326
+    enable_apache_mod proxy
327
+    enable_apache_mod proxy_http
328
+    local apache_conf=""
329
+    apache_conf=$(apache_site_config_for $name)
330
+    echo "KeepAlive Off" | sudo tee $apache_conf
331
+    echo "ProxyPass \"${url}\" \"http://127.0.0.1:$port\" retry=0 " | sudo tee -a $apache_conf
332
+    enable_apache_site $name
333
+    restart_apache_server
334
+}
335
+
284 336
 function remove_uwsgi_config {
285 337
     local file=$1
286 338
     local wsgi=$2
... ...
@@ -335,7 +335,7 @@ function configure_cinder {
335 335
 
336 336
     iniset $CINDER_CONF DEFAULT osapi_volume_workers "$API_WORKERS"
337 337
 
338
-    iniset $CINDER_CONF DEFAULT glance_api_servers "${GLANCE_SERVICE_PROTOCOL}://${GLANCE_HOSTPORT}"
338
+    iniset $CINDER_CONF DEFAULT glance_api_servers "$GLANCE_URL"
339 339
     if is_service_enabled tls-proxy; then
340 340
         iniset $CINDER_CONF DEFAULT glance_protocol https
341 341
         iniset $CINDER_CONF DEFAULT glance_ca_certificates_file $SSL_BUNDLE_FILE
... ...
@@ -71,6 +71,16 @@ GLANCE_HOSTPORT=${GLANCE_HOSTPORT:-$GLANCE_SERVICE_HOST:$GLANCE_SERVICE_PORT}
71 71
 GLANCE_SERVICE_PROTOCOL=${GLANCE_SERVICE_PROTOCOL:-$SERVICE_PROTOCOL}
72 72
 GLANCE_REGISTRY_PORT=${GLANCE_REGISTRY_PORT:-9191}
73 73
 GLANCE_REGISTRY_PORT_INT=${GLANCE_REGISTRY_PORT_INT:-19191}
74
+GLANCE_UWSGI=$GLANCE_BIN_DIR/glance-wsgi-api
75
+GLANCE_UWSGI_CONF=$GLANCE_CONF_DIR/glance-uswgi.ini
76
+# If wsgi mode is uwsgi run glance under uwsgi, else default to eventlet
77
+# TODO(mtreinish): Remove the eventlet path here and in all the similar
78
+# conditionals below after the Pike release
79
+if [[ "$WSGI_MODE" == "uwsgi" ]]; then
80
+    GLANCE_URL="$GLANCE_SERVICE_PROTOCOL://$GLANCE_SERVICE_HOST/image"
81
+else
82
+    GLANCE_URL="$GLANCE_SERVICE_PROTOCOL://$GLANCE_HOSTPORT"
83
+fi
74 84
 
75 85
 # Functions
76 86
 # ---------
... ...
@@ -104,16 +114,13 @@ function configure_glance {
104 104
     dburl=`database_connection_url glance`
105 105
     iniset $GLANCE_REGISTRY_CONF database connection $dburl
106 106
     iniset $GLANCE_REGISTRY_CONF DEFAULT use_syslog $SYSLOG
107
-    iniset $GLANCE_REGISTRY_CONF DEFAULT workers "$API_WORKERS"
108 107
     iniset $GLANCE_REGISTRY_CONF paste_deploy flavor keystone
109 108
     configure_auth_token_middleware $GLANCE_REGISTRY_CONF glance $GLANCE_AUTH_CACHE_DIR/registry
110 109
     iniset $GLANCE_REGISTRY_CONF oslo_messaging_notifications driver messagingv2
111 110
     iniset_rpc_backend glance $GLANCE_REGISTRY_CONF
112 111
     iniset $GLANCE_REGISTRY_CONF DEFAULT graceful_shutdown_timeout "$SERVICE_GRACEFUL_SHUTDOWN_TIMEOUT"
113 112
 
114
-    cp $GLANCE_DIR/etc/glance-api.conf $GLANCE_API_CONF
115 113
     iniset $GLANCE_API_CONF DEFAULT debug $ENABLE_DEBUG_LOG_LEVEL
116
-    iniset $GLANCE_API_CONF DEFAULT bind_host $GLANCE_SERVICE_LISTEN_ADDRESS
117 114
     inicomment $GLANCE_API_CONF DEFAULT log_file
118 115
     iniset $GLANCE_API_CONF database connection $dburl
119 116
     iniset $GLANCE_API_CONF DEFAULT use_syslog $SYSLOG
... ...
@@ -141,8 +148,6 @@ function configure_glance {
141 141
     iniset $GLANCE_API_CONF glance_store filesystem_store_datadir $GLANCE_IMAGE_DIR/
142 142
     iniset $GLANCE_API_CONF DEFAULT registry_host $GLANCE_SERVICE_HOST
143 143
 
144
-    iniset $GLANCE_API_CONF DEFAULT workers "$API_WORKERS"
145
-
146 144
     # CORS feature support - to allow calls from Horizon by default
147 145
     if [ -n "$GLANCE_CORS_ALLOWED_ORIGIN" ]; then
148 146
         iniset $GLANCE_API_CONF cors allowed_origin "$GLANCE_CORS_ALLOWED_ORIGIN"
... ...
@@ -181,9 +186,12 @@ function configure_glance {
181 181
         inicomment $GLANCE_API_CONF glance_store swift_store_auth_address
182 182
     fi
183 183
 
184
+    # We need to tell glance what it's public endpoint is so that the version
185
+    # discovery document will be correct
186
+    iniset $GLANCE_API_CONF DEFAULT public_endpoint $GLANCE_URL
187
+
184 188
     if is_service_enabled tls-proxy; then
185 189
         iniset $GLANCE_API_CONF DEFAULT bind_port $GLANCE_SERVICE_PORT_INT
186
-        iniset $GLANCE_API_CONF DEFAULT public_endpoint $GLANCE_SERVICE_PROTOCOL://$GLANCE_HOSTPORT
187 190
         iniset $GLANCE_REGISTRY_CONF DEFAULT bind_port $GLANCE_REGISTRY_PORT_INT
188 191
 
189 192
         iniset $GLANCE_API_CONF keystone_authtoken identity_uri $KEYSTONE_AUTH_URI
... ...
@@ -199,7 +207,6 @@ function configure_glance {
199 199
     setup_logging $GLANCE_REGISTRY_CONF
200 200
 
201 201
     cp -p $GLANCE_DIR/etc/glance-registry-paste.ini $GLANCE_REGISTRY_PASTE_INI
202
-
203 202
     cp -p $GLANCE_DIR/etc/glance-api-paste.ini $GLANCE_API_PASTE_INI
204 203
 
205 204
     cp $GLANCE_DIR/etc/glance-cache.conf $GLANCE_CACHE_CONF
... ...
@@ -232,6 +239,13 @@ function configure_glance {
232 232
         iniset $GLANCE_API_CONF DEFAULT cinder_endpoint_template "https://$CINDER_SERVICE_HOST:$CINDER_SERVICE_PORT/v1/%(project_id)s"
233 233
         iniset $GLANCE_CACHE_CONF DEFAULT cinder_endpoint_template "https://$CINDER_SERVICE_HOST:$CINDER_SERVICE_PORT/v1/%(project_id)s"
234 234
     fi
235
+
236
+    if [[ "$WSGI_MODE" == "uwsgi" ]]; then
237
+        write_local_uwsgi_http_config "$GLANCE_UWSGI_CONF" "$GLANCE_UWSGI" "/image"
238
+    else
239
+        iniset $GLANCE_API_CONF DEFAULT bind_host $GLANCE_SERVICE_LISTEN_ADDRESS
240
+        iniset $GLANCE_API_CONF DEFAULT workers "$API_WORKERS"
241
+    fi
235 242
 }
236 243
 
237 244
 # create_glance_accounts() - Set up common required glance accounts
... ...
@@ -256,7 +270,7 @@ function create_glance_accounts {
256 256
         get_or_create_endpoint \
257 257
             "image" \
258 258
             "$REGION_NAME" \
259
-            "$GLANCE_SERVICE_PROTOCOL://$GLANCE_HOSTPORT"
259
+            "$GLANCE_URL"
260 260
 
261 261
         # Note(frickler): Crude workaround for https://bugs.launchpad.net/glance-store/+bug/1620999
262 262
         service_domain_id=$(get_or_create_domain $SERVICE_DOMAIN_NAME)
... ...
@@ -323,15 +337,21 @@ function install_glance {
323 323
 function start_glance {
324 324
     local service_protocol=$GLANCE_SERVICE_PROTOCOL
325 325
     if is_service_enabled tls-proxy; then
326
-        start_tls_proxy glance-service '*' $GLANCE_SERVICE_PORT $GLANCE_SERVICE_HOST $GLANCE_SERVICE_PORT_INT
326
+        if [[ "$WSGI_MODE" != "uwsgi" ]]; then
327
+            start_tls_proxy glance-service '*' $GLANCE_SERVICE_PORT $GLANCE_SERVICE_HOST $GLANCE_SERVICE_PORT_INT
328
+        fi
327 329
         start_tls_proxy glance-registry '*' $GLANCE_REGISTRY_PORT $GLANCE_SERVICE_HOST $GLANCE_REGISTRY_PORT_INT
328 330
     fi
329 331
 
330 332
     run_process g-reg "$GLANCE_BIN_DIR/glance-registry --config-file=$GLANCE_CONF_DIR/glance-registry.conf"
331
-    run_process g-api "$GLANCE_BIN_DIR/glance-api --config-file=$GLANCE_CONF_DIR/glance-api.conf"
333
+    if [[ "$WSGI_MODE" == "uwsgi" ]]; then
334
+        run_process g-api "$GLANCE_BIN_DIR/uwsgi --ini $GLANCE_UWSGI_CONF"
335
+    else
336
+        run_process g-api "$GLANCE_BIN_DIR/glance-api --config-file=$GLANCE_CONF_DIR/glance-api.conf"
337
+    fi
332 338
 
333
-    echo "Waiting for g-api ($GLANCE_HOSTPORT) to start..."
334
-    if ! wait_for_service $SERVICE_TIMEOUT $GLANCE_SERVICE_PROTOCOL://$GLANCE_HOSTPORT; then
339
+    echo "Waiting for g-api ($GLANCE_SERVICE_HOST) to start..."
340
+    if ! wait_for_service $SERVICE_TIMEOUT $GLANCE_URL; then
335 341
         die $LINENO "g-api did not start"
336 342
     fi
337 343
 }
... ...
@@ -575,7 +575,7 @@ function create_nova_conf {
575 575
     # enable notifications, but it will allow them to function when enabled.
576 576
     iniset $NOVA_CONF oslo_messaging_notifications driver "messagingv2"
577 577
     iniset_rpc_backend nova $NOVA_CONF
578
-    iniset $NOVA_CONF glance api_servers "${GLANCE_SERVICE_PROTOCOL}://${GLANCE_HOSTPORT}"
578
+    iniset $NOVA_CONF glance api_servers "$GLANCE_URL"
579 579
 
580 580
     iniset $NOVA_CONF DEFAULT osapi_compute_workers "$API_WORKERS"
581 581
     iniset $NOVA_CONF DEFAULT metadata_workers "$API_WORKERS"