Compare commits
19 Commits
Feature-kn
...
master
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
2cdb69e410 | ||
|
|
beb4590a5d | ||
|
|
6e8fd65797 | ||
|
|
0d32f30299 | ||
|
|
f498412f66 | ||
|
|
dbb89f7b7e | ||
|
|
cfca4e5d64 | ||
|
|
bf5a401af9 | ||
|
|
a402dc2e89 | ||
|
|
9e24d4bcdf | ||
|
|
15c49fce50 | ||
|
|
ab27775a69 | ||
|
|
19317a1e47 | ||
|
|
58eef639f2 | ||
|
|
293adcf35a | ||
|
|
fdebea639b | ||
|
|
0ab69f5e22 | ||
|
|
188c794aca | ||
|
|
96da9f88e9 |
@@ -60,7 +60,6 @@ kni:
|
|||||||
enabled: 1
|
enabled: 1
|
||||||
tfe:
|
tfe:
|
||||||
nr_threads: 16
|
nr_threads: 16
|
||||||
kni_ip: 192.168.100.1
|
|
||||||
mc_cache_eth: ens1.100
|
mc_cache_eth: ens1.100
|
||||||
keykeeper:
|
keykeeper:
|
||||||
mode: "normal"
|
mode: "normal"
|
||||||
|
|||||||
10
deploy.yml
10
deploy.yml
@@ -7,8 +7,11 @@
|
|||||||
roles:
|
roles:
|
||||||
- tsg-env-mcn0
|
- tsg-env-mcn0
|
||||||
- mrzcpd
|
- mrzcpd
|
||||||
|
- sapp
|
||||||
- kni
|
- kni
|
||||||
|
- firewall
|
||||||
- certstore
|
- certstore
|
||||||
|
- cert-redis
|
||||||
|
|
||||||
- hosts: blade-01
|
- hosts: blade-01
|
||||||
roles:
|
roles:
|
||||||
@@ -34,8 +37,13 @@
|
|||||||
|
|
||||||
- hosts: pc-as-tun-mode
|
- hosts: pc-as-tun-mode
|
||||||
roles:
|
roles:
|
||||||
- mrzcpd
|
- kernel-ml
|
||||||
- framework
|
- framework
|
||||||
|
- mrzcpd
|
||||||
|
- tsg-env-tun-mode
|
||||||
|
- sapp
|
||||||
- kni
|
- kni
|
||||||
|
- firewall
|
||||||
- certstore
|
- certstore
|
||||||
|
- cert-redis
|
||||||
- tfe
|
- tfe
|
||||||
|
|||||||
@@ -1,60 +0,0 @@
|
|||||||
maat_redis_server:
|
|
||||||
address: "10.4.35.1"
|
|
||||||
port: 6379
|
|
||||||
db: 0
|
|
||||||
|
|
||||||
dynamic_maat_redis_server:
|
|
||||||
address: "10.4.35.1"
|
|
||||||
port: 6379
|
|
||||||
db: 1
|
|
||||||
|
|
||||||
cert_store_server:
|
|
||||||
address: "192.168.100.1"
|
|
||||||
port: 9991
|
|
||||||
|
|
||||||
log_kafkabrokers:
|
|
||||||
address: "10.4.35.7:9092,10.4.35.8:9092,10.4.35.9:9092,10.4.35.10:9092,10.4.35.11:9092"
|
|
||||||
|
|
||||||
log_minio:
|
|
||||||
address: "10.4.35.1;"
|
|
||||||
port: 9000
|
|
||||||
|
|
||||||
fs_remote:
|
|
||||||
switch: 1
|
|
||||||
address: "192.168.100.1"
|
|
||||||
port: 58125
|
|
||||||
|
|
||||||
nic_transparent_mode:
|
|
||||||
enable: 0
|
|
||||||
|
|
||||||
run_as_tun_mode: 0
|
|
||||||
package_source: "local"
|
|
||||||
|
|
||||||
kni:
|
|
||||||
global:
|
|
||||||
log_level: 10
|
|
||||||
tfe_node_count: 3
|
|
||||||
watch_dog:
|
|
||||||
switch: 1
|
|
||||||
send_logger:
|
|
||||||
switch: 1
|
|
||||||
tfe_nodes:
|
|
||||||
- tfe0:
|
|
||||||
enabled: 1
|
|
||||||
- tfe1:
|
|
||||||
enabled: 1
|
|
||||||
- tfe2:
|
|
||||||
enabled: 1
|
|
||||||
tfe:
|
|
||||||
nr_threads: 16
|
|
||||||
keykeeper:
|
|
||||||
mode: "normal"
|
|
||||||
no_cache: 0
|
|
||||||
|
|
||||||
mrzcpd:
|
|
||||||
iocore: 55
|
|
||||||
|
|
||||||
mrtunnat:
|
|
||||||
lcore_id: 54
|
|
||||||
|
|
||||||
|
|
||||||
@@ -1,14 +0,0 @@
|
|||||||
nic_mgr:
|
|
||||||
name: enp7s0
|
|
||||||
nic_data_incoming:
|
|
||||||
name: ens1f4
|
|
||||||
address: 127.0.0.1
|
|
||||||
nic_inner_ctrl:
|
|
||||||
name: ens1.100
|
|
||||||
nic_to_tfe:
|
|
||||||
tfe0:
|
|
||||||
name: ens1f5
|
|
||||||
tfe1:
|
|
||||||
name: ens1f6
|
|
||||||
tfe2:
|
|
||||||
name: ens1f7
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
nic_mgr:
|
|
||||||
name: enp7s0
|
|
||||||
nic_data_incoming:
|
|
||||||
name: ens1f1
|
|
||||||
mac: AA:BB:CC:DD:EE:FF
|
|
||||||
address: 127.0.0.1
|
|
||||||
nic_inner_ctrl:
|
|
||||||
name: ens1.100
|
|
||||||
nic_traffic_mirror:
|
|
||||||
name: ens1f2
|
|
||||||
use_mrzcpd: 1
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
nic_mgr:
|
|
||||||
name: enp7s0
|
|
||||||
nic_data_incoming:
|
|
||||||
name: ens8f1
|
|
||||||
mac: AA:BB:CC:DD:EE:FF
|
|
||||||
nic_inner_ctrl:
|
|
||||||
name: ens8.100
|
|
||||||
nic_traffic_mirror:
|
|
||||||
name: ens8f2
|
|
||||||
use_mrzcpd: 1
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
nic_mgr:
|
|
||||||
name: enp7s0
|
|
||||||
nic_data_incoming:
|
|
||||||
name: ens8f1
|
|
||||||
mac: AA:BB:CC:DD:EE:FF
|
|
||||||
nic_inner_ctrl:
|
|
||||||
name: ens8.100
|
|
||||||
nic_traffic_mirror:
|
|
||||||
name: ens8f2
|
|
||||||
use_mrzcpd: 1
|
|
||||||
@@ -1,100 +0,0 @@
|
|||||||
[all:vars]
|
|
||||||
ansible_user=root
|
|
||||||
|
|
||||||
[blade-mxn]
|
|
||||||
10.4.164.23
|
|
||||||
#10.4.164.24
|
|
||||||
10.4.164.25
|
|
||||||
10.4.164.26
|
|
||||||
10.4.164.27
|
|
||||||
10.4.164.28
|
|
||||||
10.4.164.29
|
|
||||||
|
|
||||||
[blade-00]
|
|
||||||
10.4.39.9
|
|
||||||
#10.4.39.13
|
|
||||||
10.4.39.17
|
|
||||||
10.4.39.21
|
|
||||||
10.4.39.25
|
|
||||||
10.4.39.29
|
|
||||||
10.4.39.33
|
|
||||||
|
|
||||||
[blade-01]
|
|
||||||
10.4.39.10
|
|
||||||
#10.4.39.14
|
|
||||||
10.4.39.18
|
|
||||||
10.4.39.22
|
|
||||||
10.4.39.26
|
|
||||||
10.4.39.30
|
|
||||||
10.4.39.34
|
|
||||||
|
|
||||||
[blade-02]
|
|
||||||
10.4.39.11
|
|
||||||
#10.4.39.15
|
|
||||||
10.4.39.19
|
|
||||||
10.4.39.23
|
|
||||||
10.4.39.27
|
|
||||||
10.4.39.31
|
|
||||||
10.4.39.35
|
|
||||||
|
|
||||||
[blade-03]
|
|
||||||
10.4.39.12
|
|
||||||
#10.4.39.16
|
|
||||||
10.4.39.20
|
|
||||||
10.4.39.24
|
|
||||||
10.4.39.28
|
|
||||||
10.4.39.32
|
|
||||||
10.4.39.36
|
|
||||||
|
|
||||||
[astana-adc-3]
|
|
||||||
10.4.164.23
|
|
||||||
10.4.39.9
|
|
||||||
10.4.39.10
|
|
||||||
10.4.39.11
|
|
||||||
10.4.39.12
|
|
||||||
|
|
||||||
[astana-adc-5]
|
|
||||||
10.4.164.25
|
|
||||||
10.4.39.17
|
|
||||||
10.4.39.18
|
|
||||||
10.4.39.19
|
|
||||||
10.4.39.20
|
|
||||||
|
|
||||||
[astana-adc-6]
|
|
||||||
10.4.164.26
|
|
||||||
10.4.39.21
|
|
||||||
10.4.39.22
|
|
||||||
10.4.39.23
|
|
||||||
10.4.39.24
|
|
||||||
|
|
||||||
[astana-adc-7]
|
|
||||||
10.4.164.27
|
|
||||||
10.4.39.25
|
|
||||||
10.4.39.26
|
|
||||||
10.4.39.27
|
|
||||||
10.4.39.28
|
|
||||||
|
|
||||||
[astana-adc-8]
|
|
||||||
10.4.164.28
|
|
||||||
10.4.39.29
|
|
||||||
10.4.39.30
|
|
||||||
10.4.39.31
|
|
||||||
10.4.39.32
|
|
||||||
|
|
||||||
[astana-adc-9]
|
|
||||||
10.4.164.29
|
|
||||||
10.4.39.33
|
|
||||||
10.4.39.34
|
|
||||||
10.4.39.35
|
|
||||||
10.4.39.36
|
|
||||||
|
|
||||||
[Functional_Host:children]
|
|
||||||
blade-00
|
|
||||||
blade-01
|
|
||||||
blade-02
|
|
||||||
blade-03
|
|
||||||
|
|
||||||
[Slave_Host:children]
|
|
||||||
blade-01
|
|
||||||
blade-02
|
|
||||||
blade-03
|
|
||||||
@@ -1,45 +0,0 @@
|
|||||||
maat_redis_server:
|
|
||||||
address: 192.168.100.3
|
|
||||||
port: 7002
|
|
||||||
db: 0
|
|
||||||
|
|
||||||
dynamic_maat_redis_server:
|
|
||||||
address: 192.168.100.3
|
|
||||||
port: 7002
|
|
||||||
db: 0
|
|
||||||
|
|
||||||
cert_store_server:
|
|
||||||
address: 192.168.100.1
|
|
||||||
port: 9991
|
|
||||||
|
|
||||||
log_kafkabrokers:
|
|
||||||
address: "192.168.100.4:9092"
|
|
||||||
|
|
||||||
log_minio:
|
|
||||||
address: "192.168.100.4;"
|
|
||||||
port: 9000
|
|
||||||
|
|
||||||
fs_remote:
|
|
||||||
switch: 0
|
|
||||||
address: "192.168.10.152"
|
|
||||||
port: 8125
|
|
||||||
|
|
||||||
kni:
|
|
||||||
global:
|
|
||||||
log_level: 30
|
|
||||||
tfe_node_count: 3
|
|
||||||
watch_dog:
|
|
||||||
switch: 1
|
|
||||||
tfe_nodes:
|
|
||||||
- tfe0:
|
|
||||||
enabled: 1
|
|
||||||
- tfe1:
|
|
||||||
enabled: 1
|
|
||||||
- tfe2:
|
|
||||||
enabled: 1
|
|
||||||
|
|
||||||
tfe:
|
|
||||||
nr_threads: 32
|
|
||||||
keykeeper:
|
|
||||||
mode: "debug"
|
|
||||||
no_cache: 0
|
|
||||||
@@ -1,13 +0,0 @@
|
|||||||
nic_mgr:
|
|
||||||
name: enp7s0
|
|
||||||
nic_data_incoming:
|
|
||||||
name: ens1f4
|
|
||||||
nic_inner_ctrl:
|
|
||||||
name: ens1.100
|
|
||||||
nic_to_tfe:
|
|
||||||
tfe0:
|
|
||||||
name: ens1f5
|
|
||||||
tfe1:
|
|
||||||
name: ens1f6
|
|
||||||
tfe2:
|
|
||||||
name: ens1f7
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
nic_mgr:
|
|
||||||
name: enp7s0
|
|
||||||
nic_data_incoming:
|
|
||||||
name: ens1f1
|
|
||||||
mac: AA:BB:CC:DD:EE:FF
|
|
||||||
nic_inner_ctrl:
|
|
||||||
name: ens1.100
|
|
||||||
nic_traffic_mirror:
|
|
||||||
name: ens1f2
|
|
||||||
use_mrzcpd: 1
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
nic_mgr:
|
|
||||||
name: enp7s0
|
|
||||||
nic_data_incoming:
|
|
||||||
name: ens8f1
|
|
||||||
mac: AA:BB:CC:DD:EE:FF
|
|
||||||
nic_inner_ctrl:
|
|
||||||
name: ens1.100
|
|
||||||
nic_traffic_mirror:
|
|
||||||
name: ens8f2
|
|
||||||
use_mrzcpd: 1
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
nic_mgr:
|
|
||||||
name: enp7s0
|
|
||||||
nic_data_incoming:
|
|
||||||
name: ens8f1
|
|
||||||
mac: AA:BB:CC:DD:EE:FF
|
|
||||||
nic_inner_ctrl:
|
|
||||||
name: ens1.100
|
|
||||||
nic_traffic_mirror:
|
|
||||||
name: ens8f2
|
|
||||||
use_mrzcpd: 1
|
|
||||||
@@ -1,12 +0,0 @@
|
|||||||
[all:vars]
|
|
||||||
ansible_user=root
|
|
||||||
|
|
||||||
[blade-00]
|
|
||||||
192.168.10.41
|
|
||||||
|
|
||||||
[blade-01]
|
|
||||||
192.168.10.42
|
|
||||||
|
|
||||||
[Functional_Host:children]
|
|
||||||
blade-00
|
|
||||||
blade-01
|
|
||||||
@@ -1,76 +0,0 @@
|
|||||||
maat_redis_server:
|
|
||||||
address: "192.168.40.83"
|
|
||||||
port: 7002
|
|
||||||
db: 0
|
|
||||||
|
|
||||||
dynamic_maat_redis_server:
|
|
||||||
address: "192.168.40.83"
|
|
||||||
port: 7002
|
|
||||||
db: 0
|
|
||||||
|
|
||||||
cert_store_server:
|
|
||||||
address: "127.0.0.1"
|
|
||||||
port: 9991
|
|
||||||
|
|
||||||
log_kafkabrokers:
|
|
||||||
address: "192.168.40.85:9092"
|
|
||||||
|
|
||||||
log_minio:
|
|
||||||
address: "192.168.40.85;"
|
|
||||||
port: 9000
|
|
||||||
|
|
||||||
fs_remote:
|
|
||||||
switch: 1
|
|
||||||
address: "127.0.0.1"
|
|
||||||
port: 8125
|
|
||||||
|
|
||||||
kni:
|
|
||||||
global:
|
|
||||||
log_level: 30
|
|
||||||
tfe_node_count: 3
|
|
||||||
watch_dog:
|
|
||||||
switch: 1
|
|
||||||
tfe_nodes:
|
|
||||||
- tfe0:
|
|
||||||
enabled: 1
|
|
||||||
- tfe1:
|
|
||||||
enabled: 1
|
|
||||||
- tfe2:
|
|
||||||
enabled: 1
|
|
||||||
tfe:
|
|
||||||
nr_threads: 32
|
|
||||||
keykeeper:
|
|
||||||
mode: "normal"
|
|
||||||
no_cache: 0
|
|
||||||
|
|
||||||
mrzcpd:
|
|
||||||
iocore: 47
|
|
||||||
|
|
||||||
mrtunnat:
|
|
||||||
lcore_id: 46
|
|
||||||
|
|
||||||
nic_mgr:
|
|
||||||
name: eth0
|
|
||||||
nic_data_incoming:
|
|
||||||
name: tun_kni
|
|
||||||
address: 127.0.0.1
|
|
||||||
nic_inner_ctrl:
|
|
||||||
name: lo
|
|
||||||
nic_to_tfe:
|
|
||||||
tfe0:
|
|
||||||
name: lo
|
|
||||||
tfe1:
|
|
||||||
name: lo
|
|
||||||
tfe2:
|
|
||||||
name: lo
|
|
||||||
nic_traffic_mirror:
|
|
||||||
name: lo
|
|
||||||
use_mrzcpd: 0
|
|
||||||
|
|
||||||
nic_transparent_mode:
|
|
||||||
enable: 1
|
|
||||||
mode: pcap
|
|
||||||
internel_interface: "enp0s20f0u3"
|
|
||||||
external_interface: "enp0s20f0u4"
|
|
||||||
|
|
||||||
run_as_tun_mode: 1
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
[all:vars]
|
|
||||||
ansible_user=root
|
|
||||||
package_source=local
|
|
||||||
|
|
||||||
[pc-as-tun-mode]
|
|
||||||
192.168.40.85
|
|
||||||
@@ -1,55 +0,0 @@
|
|||||||
maat_redis_server:
|
|
||||||
address: "192.168.40.120"
|
|
||||||
port: 7002
|
|
||||||
db: 0
|
|
||||||
|
|
||||||
dynamic_maat_redis_server:
|
|
||||||
address: "192.168.40.120"
|
|
||||||
port: 7002
|
|
||||||
db: 1
|
|
||||||
|
|
||||||
cert_store_server:
|
|
||||||
address: "192.168.40.161"
|
|
||||||
port: 9991
|
|
||||||
|
|
||||||
log_kafkabrokers:
|
|
||||||
address: "192.168.40.119:9092"
|
|
||||||
|
|
||||||
log_minio:
|
|
||||||
address: "192.168.40.223;"
|
|
||||||
port: 9000
|
|
||||||
|
|
||||||
fs_remote:
|
|
||||||
switch: 1
|
|
||||||
address: "192.168.100.1"
|
|
||||||
port: 8125
|
|
||||||
|
|
||||||
nic_transparent_mode:
|
|
||||||
enable: 0
|
|
||||||
|
|
||||||
kni:
|
|
||||||
global:
|
|
||||||
log_level: 30
|
|
||||||
tfe_node_count: 3
|
|
||||||
watch_dog:
|
|
||||||
switch: 1
|
|
||||||
tfe_nodes:
|
|
||||||
- tfe0:
|
|
||||||
enabled: 1
|
|
||||||
- tfe1:
|
|
||||||
enabled: 1
|
|
||||||
- tfe2:
|
|
||||||
enabled: 1
|
|
||||||
tfe:
|
|
||||||
nr_threads: 32
|
|
||||||
keykeeper:
|
|
||||||
mode: "normal"
|
|
||||||
no_cache: 0
|
|
||||||
|
|
||||||
mrzcpd:
|
|
||||||
iocore: 47
|
|
||||||
|
|
||||||
mrtunnat:
|
|
||||||
lcore_id: 46
|
|
||||||
|
|
||||||
run_as_tun_mode: 1
|
|
||||||
@@ -1,14 +0,0 @@
|
|||||||
nic_mgr:
|
|
||||||
name: enp6s0
|
|
||||||
nic_data_incoming:
|
|
||||||
name: ens1f4
|
|
||||||
address: 127.0.0.1
|
|
||||||
nic_inner_ctrl:
|
|
||||||
name: ens1.100
|
|
||||||
nic_to_tfe:
|
|
||||||
tfe0:
|
|
||||||
name: ens1f5
|
|
||||||
tfe1:
|
|
||||||
name: ens1f6
|
|
||||||
tfe2:
|
|
||||||
name: ens1f7
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
nic_mgr:
|
|
||||||
name: enp6s0
|
|
||||||
nic_data_incoming:
|
|
||||||
name: ens1f1
|
|
||||||
mac: AA:BB:CC:DD:EE:FF
|
|
||||||
address: 127.0.0.1
|
|
||||||
nic_inner_ctrl:
|
|
||||||
name: ens1.100
|
|
||||||
nic_traffic_mirror:
|
|
||||||
name: ens1f2
|
|
||||||
use_mrzcpd: 1
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
nic_mgr:
|
|
||||||
name: enp6s0
|
|
||||||
nic_data_incoming:
|
|
||||||
name: ens8f1
|
|
||||||
mac: AA:BB:CC:DD:EE:FF
|
|
||||||
nic_inner_ctrl:
|
|
||||||
name: ens8.100
|
|
||||||
nic_traffic_mirror:
|
|
||||||
name: ens8f2
|
|
||||||
use_mrzcpd: 1
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
nic_mgr:
|
|
||||||
name: enp6s0
|
|
||||||
nic_data_incoming:
|
|
||||||
name: ens8f1
|
|
||||||
mac: AA:BB:CC:DD:EE:FF
|
|
||||||
nic_inner_ctrl:
|
|
||||||
name: ens8.100
|
|
||||||
nic_traffic_mirror:
|
|
||||||
name: ens8f2
|
|
||||||
use_mrzcpd: 1
|
|
||||||
@@ -1,24 +0,0 @@
|
|||||||
[all:vars]
|
|
||||||
ansible_user=root
|
|
||||||
package_source=pulp
|
|
||||||
|
|
||||||
[blade-mxn]
|
|
||||||
192.168.40.25
|
|
||||||
|
|
||||||
[blade-00]
|
|
||||||
192.168.40.21
|
|
||||||
|
|
||||||
[blade-01]
|
|
||||||
192.168.40.22
|
|
||||||
|
|
||||||
[blade-02]
|
|
||||||
192.168.40.23
|
|
||||||
|
|
||||||
[blade-03]
|
|
||||||
192.168.40.24
|
|
||||||
|
|
||||||
[Functional_Host:children]
|
|
||||||
blade-00
|
|
||||||
blade-01
|
|
||||||
blade-02
|
|
||||||
blade-03
|
|
||||||
@@ -1,10 +1,10 @@
|
|||||||
maat_redis_server:
|
maat_redis_server:
|
||||||
address: "192.168.40.83"
|
address: "192.168.40.168"
|
||||||
port: 7002
|
port: 7002
|
||||||
db: 0
|
db: 0
|
||||||
|
|
||||||
dynamic_maat_redis_server:
|
dynamic_maat_redis_server:
|
||||||
address: "192.168.40.83"
|
address: "192.168.40.168"
|
||||||
port: 7002
|
port: 7002
|
||||||
db: 0
|
db: 0
|
||||||
|
|
||||||
@@ -13,10 +13,10 @@ cert_store_server:
|
|||||||
port: 9991
|
port: 9991
|
||||||
|
|
||||||
log_kafkabrokers:
|
log_kafkabrokers:
|
||||||
address: "192.168.40.85:9092"
|
address: "192.168.40.169:9092"
|
||||||
|
|
||||||
log_minio:
|
log_minio:
|
||||||
address: "192.168.40.85;"
|
address: "192.168.40.168;"
|
||||||
port: 9090
|
port: 9090
|
||||||
|
|
||||||
fs_remote:
|
fs_remote:
|
||||||
@@ -35,6 +35,9 @@ install_fw_http_plug_debug: "yes"
|
|||||||
install_fw_mail_plug_debug: "yes"
|
install_fw_mail_plug_debug: "yes"
|
||||||
install_tsg_master: "yes"
|
install_tsg_master: "yes"
|
||||||
|
|
||||||
|
sapp:
|
||||||
|
worker_threads: 16
|
||||||
|
|
||||||
kni:
|
kni:
|
||||||
global:
|
global:
|
||||||
log_level: 30
|
log_level: 30
|
||||||
@@ -54,6 +57,7 @@ kni:
|
|||||||
enabled: 1
|
enabled: 1
|
||||||
tfe:
|
tfe:
|
||||||
nr_threads: 32
|
nr_threads: 32
|
||||||
|
mc_cache_eth: lo
|
||||||
keykeeper:
|
keykeeper:
|
||||||
mode: "normal"
|
mode: "normal"
|
||||||
no_cache: 0
|
no_cache: 0
|
||||||
@@ -70,14 +74,7 @@ nic_data_incoming:
|
|||||||
name: tun_kni
|
name: tun_kni
|
||||||
address: 127.0.0.1
|
address: 127.0.0.1
|
||||||
nic_inner_ctrl:
|
nic_inner_ctrl:
|
||||||
name: lo
|
name: eth0.100
|
||||||
nic_to_tfe:
|
|
||||||
tfe0:
|
|
||||||
name: lo
|
|
||||||
tfe1:
|
|
||||||
name: lo
|
|
||||||
tfe2:
|
|
||||||
name: lo
|
|
||||||
nic_traffic_mirror:
|
nic_traffic_mirror:
|
||||||
name: lo
|
name: lo
|
||||||
use_mrzcpd: 0
|
use_mrzcpd: 0
|
||||||
|
|||||||
@@ -3,4 +3,4 @@ ansible_user=root
|
|||||||
package_source=local
|
package_source=local
|
||||||
|
|
||||||
[pc-as-tun-mode]
|
[pc-as-tun-mode]
|
||||||
192.168.40.139
|
192.168.40.138
|
||||||
|
|||||||
13
rc.local
13
rc.local
@@ -1,13 +0,0 @@
|
|||||||
#!/bin/bash
|
|
||||||
# THIS FILE IS ADDED FOR COMPATIBILITY PURPOSES
|
|
||||||
#
|
|
||||||
# It is highly advisable to create own systemd services or udev rules
|
|
||||||
# to run scripts during boot instead of using this file.
|
|
||||||
#
|
|
||||||
# In contrast to previous versions due to parallel execution during boot
|
|
||||||
# this script will NOT be run after all other services.
|
|
||||||
#
|
|
||||||
# Please note that you must run 'chmod +x /etc/rc.d/rc.local' to ensure
|
|
||||||
# that this script will be executed during boot.
|
|
||||||
|
|
||||||
touch /var/lock/subsys/local
|
|
||||||
1052
roles/cert-redis/files/cert-redis/6379/6379.conf
Normal file
1052
roles/cert-redis/files/cert-redis/6379/6379.conf
Normal file
File diff suppressed because it is too large
Load Diff
BIN
roles/cert-redis/files/cert-redis/6379/dump.rdb
Normal file
BIN
roles/cert-redis/files/cert-redis/6379/dump.rdb
Normal file
Binary file not shown.
16
roles/cert-redis/files/cert-redis/cert-redis.service
Normal file
16
roles/cert-redis/files/cert-redis/cert-redis.service
Normal file
@@ -0,0 +1,16 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=Redis persistent key-value database
|
||||||
|
After=network.target
|
||||||
|
After=network-online.target
|
||||||
|
Wants=network-online.target
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
ExecStart=/usr/local/bin/start-cert-redis
|
||||||
|
ExecStop=killall redis-server
|
||||||
|
Type=forking
|
||||||
|
RuntimeDirectory=redis
|
||||||
|
RuntimeDirectoryMode=0755
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
|
|
||||||
6
roles/cert-redis/files/cert-redis/install.sh
Executable file
6
roles/cert-redis/files/cert-redis/install.sh
Executable file
@@ -0,0 +1,6 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
#
|
||||||
|
cp -rf redis-server /usr/local/bin/
|
||||||
|
cp -rf redis-cli /usr/local/bin
|
||||||
|
cp -rf cert-redis.service /usr/lib/systemd/system/
|
||||||
|
cp -rf start-cert-redis /usr/local/bin
|
||||||
BIN
roles/cert-redis/files/cert-redis/redis-cli
Executable file
BIN
roles/cert-redis/files/cert-redis/redis-cli
Executable file
Binary file not shown.
BIN
roles/cert-redis/files/cert-redis/redis-server
Executable file
BIN
roles/cert-redis/files/cert-redis/redis-server
Executable file
Binary file not shown.
4
roles/cert-redis/files/cert-redis/start-cert-redis
Executable file
4
roles/cert-redis/files/cert-redis/start-cert-redis
Executable file
@@ -0,0 +1,4 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
#
|
||||||
|
|
||||||
|
/usr/local/bin/redis-server /home/tsg/cert-redis/6379/6379.conf
|
||||||
15
roles/cert-redis/tasks/main.yml
Normal file
15
roles/cert-redis/tasks/main.yml
Normal file
@@ -0,0 +1,15 @@
|
|||||||
|
- name: "copy cert-redis to destination server"
|
||||||
|
copy:
|
||||||
|
src: "{{ role_path }}/files/"
|
||||||
|
dest: /home/tsg
|
||||||
|
mode: 0755
|
||||||
|
|
||||||
|
- name: "install cert-redis"
|
||||||
|
shell: cd /home/tsg/cert-redis;sh install.sh
|
||||||
|
|
||||||
|
- name: "start cert-redis"
|
||||||
|
systemd:
|
||||||
|
name: cert-redis.service
|
||||||
|
state: started
|
||||||
|
daemon_reload: yes
|
||||||
|
enabled: yes
|
||||||
Binary file not shown.
BIN
roles/certstore/files/certstore-base-online-20200119.tar.gz
Normal file
BIN
roles/certstore/files/certstore-base-online-20200119.tar.gz
Normal file
Binary file not shown.
Binary file not shown.
@@ -4,26 +4,13 @@
|
|||||||
src: "{{ role_path }}/files/"
|
src: "{{ role_path }}/files/"
|
||||||
dest: "/tmp/ansible_deploy/"
|
dest: "/tmp/ansible_deploy/"
|
||||||
|
|
||||||
#- name: "install redis"
|
|
||||||
# yum:
|
|
||||||
# name:
|
|
||||||
# - /tmp/ansible_deploy/jemalloc-3.6.0-1.el7.x86_64.rpm
|
|
||||||
# - /tmp/ansible_deploy/redis-3.2.12-2.el7.x86_64.rpm
|
|
||||||
# state: present
|
|
||||||
|
|
||||||
#- name: "enable redis"
|
|
||||||
# systemd:
|
|
||||||
# name: redis
|
|
||||||
# enabled: yes
|
|
||||||
# state: started
|
|
||||||
|
|
||||||
- name: Ensures /home/tsg exists
|
- name: Ensures /home/tsg exists
|
||||||
file: path=/home/tsg state=directory
|
file: path=/home/tsg state=directory
|
||||||
tags: mkdir
|
tags: mkdir
|
||||||
|
|
||||||
- name: install certstore
|
- name: install certstore
|
||||||
unarchive:
|
unarchive:
|
||||||
src: "{{ role_path }}/files/certstore-base-online-20200108.tar.gz"
|
src: "{{ role_path }}/files/certstore-base-online-20200119.tar.gz"
|
||||||
dest: /home/tsg
|
dest: /home/tsg
|
||||||
|
|
||||||
- name: template certstore configure file
|
- name: template certstore configure file
|
||||||
|
|||||||
89
roles/firewall/tasks/main.yml
Normal file
89
roles/firewall/tasks/main.yml
Normal file
@@ -0,0 +1,89 @@
|
|||||||
|
---
|
||||||
|
- name: "copy firewall rpms to destination server"
|
||||||
|
copy:
|
||||||
|
src: "{{ role_path }}/files/"
|
||||||
|
dest: /tmp/ansible_deploy/
|
||||||
|
|
||||||
|
- name: "install dns-debug rpms from localhost"
|
||||||
|
yum:
|
||||||
|
name:
|
||||||
|
- /tmp/ansible_deploy/dns-debug-1.0.0.-1.el7.x86_64.rpm
|
||||||
|
state: present
|
||||||
|
when: install_dns_debug == "yes"
|
||||||
|
|
||||||
|
- name: "install ftp-debug rpms from localhost"
|
||||||
|
yum:
|
||||||
|
name:
|
||||||
|
- /tmp/ansible_deploy/ftp-debug-1.0.0.-1.el7.x86_64.rpm
|
||||||
|
state: present
|
||||||
|
when: install_ftp_debug == "yes"
|
||||||
|
|
||||||
|
- name: "install http-debug rpms from localhost"
|
||||||
|
yum:
|
||||||
|
name:
|
||||||
|
- /tmp/ansible_deploy/http-debug-1.0.0.-1.el7.x86_64.rpm
|
||||||
|
state: present
|
||||||
|
when: install_http_debug == "yes"
|
||||||
|
|
||||||
|
- name: "install mail-debug rpms from localhost"
|
||||||
|
yum:
|
||||||
|
name:
|
||||||
|
- /tmp/ansible_deploy/mail-debug-1.0.0.-1.el7.x86_64.rpm
|
||||||
|
state: present
|
||||||
|
when: install_mail_debug == "yes"
|
||||||
|
|
||||||
|
- name: "install ssl-debug rpms from localhost"
|
||||||
|
yum:
|
||||||
|
name:
|
||||||
|
- /tmp/ansible_deploy/ssl-debug-1.0.0.-1.el7.x86_64.rpm
|
||||||
|
state: present
|
||||||
|
when: install_ssl_debug == "yes"
|
||||||
|
|
||||||
|
- name: "install fw_dns_plug-debug rpms from localhost"
|
||||||
|
yum:
|
||||||
|
name:
|
||||||
|
- /tmp/ansible_deploy/fw_dns_plug-debug-1.0.2.1c9d36d-1.el7.centos.x86_64.rpm
|
||||||
|
state: present
|
||||||
|
when: install_fw_dns_plug_debug == "yes"
|
||||||
|
|
||||||
|
- name: "install fw_ftp_plug-debug rpms from localhost"
|
||||||
|
yum:
|
||||||
|
name:
|
||||||
|
- /tmp/ansible_deploy/fw_ftp_plug-debug-1.0.0.bd656e4-1.el7.centos.x86_64.rpm
|
||||||
|
state: present
|
||||||
|
when: install_fw_ftp_plug_debug == "yes"
|
||||||
|
|
||||||
|
- name: "install fw_http_plug-debug rpms from localhost"
|
||||||
|
yum:
|
||||||
|
name:
|
||||||
|
- /tmp/ansible_deploy/fw_http_plug-debug-1.0.3.3c95e78-1.el7.centos.x86_64.rpm
|
||||||
|
state: present
|
||||||
|
when: install_fw_http_plug_debug == "yes"
|
||||||
|
|
||||||
|
- name: "install fw_mail_plug-debug rpms from localhost"
|
||||||
|
yum:
|
||||||
|
name:
|
||||||
|
- /tmp/ansible_deploy/fw_mail_plug-debug-1.0.1.8792ed8-1.el7.centos.x86_64.rpm
|
||||||
|
state: present
|
||||||
|
when: install_fw_mail_plug_debug == "yes"
|
||||||
|
|
||||||
|
- name: "install tsg-master rpms from localhost"
|
||||||
|
yum:
|
||||||
|
name:
|
||||||
|
- /tmp/ansible_deploy/tsg_master-debug-1.0.1.f624b67-1.el7.centos.x86_64.rpm
|
||||||
|
state: present
|
||||||
|
when: install_tsg_master == "yes"
|
||||||
|
|
||||||
|
- name: Template the tsgconf/main.conf
|
||||||
|
template:
|
||||||
|
src: "{{ role_path }}/templates/main.conf.j2"
|
||||||
|
dest: /home/mesasoft/sapp_run/tsgconf/main.conf
|
||||||
|
tags: template
|
||||||
|
|
||||||
|
|
||||||
|
- name: Template the tsgconf/maat.conf
|
||||||
|
template:
|
||||||
|
src: "{{ role_path }}/templates/maat.conf.j2"
|
||||||
|
dest: /home/mesasoft/sapp_run/tsgconf/maat.conf
|
||||||
|
tags: template
|
||||||
|
|
||||||
30
roles/firewall/templates/maat.conf.j2
Normal file
30
roles/firewall/templates/maat.conf.j2
Normal file
@@ -0,0 +1,30 @@
|
|||||||
|
[STATIC]
|
||||||
|
MAAT_MODE=2
|
||||||
|
STAT_SWITCH=1
|
||||||
|
PERF_SWITCH=1
|
||||||
|
TABLE_INFO=tsgconf/tsg_static_tableinfo.conf
|
||||||
|
STAT_FILE=tsg_static_maat.status
|
||||||
|
EFFECT_INTERVAL_S=1
|
||||||
|
REDIS_IP={{ maat_redis_server.address }}
|
||||||
|
REDIS_PORT_NUM=1
|
||||||
|
REDIS_PORT=7002
|
||||||
|
REDIS_INDEX=0
|
||||||
|
JSON_CFG_FILE=tsgconf/tsg_maat.json
|
||||||
|
INC_CFG_DIR=tsgrule/inc/index/
|
||||||
|
FULL_CFG_DIR=tsgrule/full/index/
|
||||||
|
|
||||||
|
[DYNAMIC]
|
||||||
|
MAAT_MODE=2
|
||||||
|
STAT_SWITCH=1
|
||||||
|
PERF_SWITCH=1
|
||||||
|
TABLE_INFO=tsgconf/tsg_dynamic_tableinfo.conf
|
||||||
|
STAT_FILE=tsg_dynamic_maat.status
|
||||||
|
EFFECT_INTERVAL_S=1
|
||||||
|
REDIS_IP={{ dynamic_maat_redis_server.address }}
|
||||||
|
REDIS_PORT_NUM=1
|
||||||
|
REDIS_PORT=7002
|
||||||
|
REDIS_INDEX=1
|
||||||
|
JSON_CFG_FILE=tsgconf/tsg_maat.json
|
||||||
|
INC_CFG_DIR=tsgrule/inc/index/
|
||||||
|
FULL_CFG_DIR=tsgrule/full/index/
|
||||||
|
|
||||||
47
roles/firewall/templates/main.conf.j2
Normal file
47
roles/firewall/templates/main.conf.j2
Normal file
@@ -0,0 +1,47 @@
|
|||||||
|
[FTP_PLUG]
|
||||||
|
LOG_PATH=./tsglog/fw_ftp_plug/fw_ftp_plug
|
||||||
|
LOG_LEVEL=10
|
||||||
|
TIMEOUT=600
|
||||||
|
[MAIL_PLUG]
|
||||||
|
LOG_PATH=./tsglog/fw_mail_plug/fw_mail_plug
|
||||||
|
LOG_LEVEL=10
|
||||||
|
TIMEOUT=600
|
||||||
|
[HTTP_PLUG]
|
||||||
|
LOG_PATH=./tsglog/fw_http_plug/fw_http_plug
|
||||||
|
LOG_LEVEL=10
|
||||||
|
[DNS_PLUG]
|
||||||
|
LOG_PATH=./tsglog/fw_dns_plug/fw_dns_plug
|
||||||
|
LOG_LEVEL=10
|
||||||
|
[MAAT]
|
||||||
|
PROFILE=./tsgconf/maat.conf
|
||||||
|
IP_ADDR_TABLE=TSG_OBJ_IP_ADDR
|
||||||
|
SUBSCRIBER_ID_TABLE=TSG_OBJ_SUBSCRIBER_ID
|
||||||
|
CB_SUBSCRIBER_IP_TABLE=TSG_DYN_SUBSCRIBER_IP
|
||||||
|
|
||||||
|
[TSG_LOG]
|
||||||
|
MODE=1
|
||||||
|
NIC_NAME={{ nic_mgr.name }}
|
||||||
|
MAX_SERVICE=1
|
||||||
|
LOG_LEVEL=10
|
||||||
|
LOG_PATH=./tsglog/tsglog
|
||||||
|
BROKER_LIST={{ log_kafkabrokers.address }}
|
||||||
|
COMMON_FIELD_FILE=tsgconf/tsg_log_field.conf
|
||||||
|
|
||||||
|
[STATISTIC]
|
||||||
|
CYCLE=0
|
||||||
|
TELEGRAF_PORT=8100
|
||||||
|
TELEGRAF_IP=127.0.0.1
|
||||||
|
OUTPUT_PATH=./tsg_statistic.log
|
||||||
|
APP_NAME=statistic
|
||||||
|
|
||||||
|
[FIELD_STAT]
|
||||||
|
CYCLE=3
|
||||||
|
TELEGRAF_PORT=8125
|
||||||
|
TELEGRAF_IP=127.0.0.1
|
||||||
|
OUTPUT_PATH=./tsg_stat.log
|
||||||
|
APP_NAME=tsg_master
|
||||||
|
|
||||||
|
[SYSTEM]
|
||||||
|
LOG_LEVEL=10
|
||||||
|
LOG_PATH=./tsglog/tsg_master
|
||||||
|
POLICY_PRIORITY_LABEL=POLICY_PRIORITY
|
||||||
Binary file not shown.
BIN
roles/kni/files/kni-3.0.2.57bfa41-1.el7.x86_64.rpm
Normal file
BIN
roles/kni/files/kni-3.0.2.57bfa41-1.el7.x86_64.rpm
Normal file
Binary file not shown.
Binary file not shown.
BIN
roles/kni/files/kni-debuginfo-3.0.2.57bfa41-1.el7.x86_64.rpm
Normal file
BIN
roles/kni/files/kni-debuginfo-3.0.2.57bfa41-1.el7.x86_64.rpm
Normal file
Binary file not shown.
@@ -7,7 +7,7 @@
|
|||||||
- name: "install kni rpms from localhost"
|
- name: "install kni rpms from localhost"
|
||||||
yum:
|
yum:
|
||||||
name:
|
name:
|
||||||
- /tmp/ansible_deploy/kni-debug-3.0.1.f81dd69-1.el7.x86_64.rpm
|
- /tmp/ansible_deploy/kni-3.0.2.57bfa41-1.el7.x86_64.rpm
|
||||||
state: present
|
state: present
|
||||||
|
|
||||||
- name: Template the kni.conf
|
- name: Template the kni.conf
|
||||||
@@ -15,76 +15,6 @@
|
|||||||
src: "{{ role_path }}/templates/kni.conf.j2"
|
src: "{{ role_path }}/templates/kni.conf.j2"
|
||||||
dest: /home/mesasoft/sapp_run/etc/kni/kni.conf
|
dest: /home/mesasoft/sapp_run/etc/kni/kni.conf
|
||||||
tags: template
|
tags: template
|
||||||
|
|
||||||
- name: "install dns-debug rpms from localhost"
|
|
||||||
yum:
|
|
||||||
name:
|
|
||||||
- /tmp/ansible_deploy/dns-debug-1.0.0.-1.el7.x86_64.rpm
|
|
||||||
state: present
|
|
||||||
when: install_dns_debug == "yes"
|
|
||||||
|
|
||||||
- name: "install ftp-debug rpms from localhost"
|
|
||||||
yum:
|
|
||||||
name:
|
|
||||||
- /tmp/ansible_deploy/ftp-debug-1.0.0.-1.el7.x86_64.rpm
|
|
||||||
state: present
|
|
||||||
when: install_ftp_debug == "yes"
|
|
||||||
|
|
||||||
- name: "install http-debug rpms from localhost"
|
|
||||||
yum:
|
|
||||||
name:
|
|
||||||
- /tmp/ansible_deploy/http-debug-1.0.0.-1.el7.x86_64.rpm
|
|
||||||
state: present
|
|
||||||
when: install_http_debug == "yes"
|
|
||||||
|
|
||||||
- name: "install mail-debug rpms from localhost"
|
|
||||||
yum:
|
|
||||||
name:
|
|
||||||
- /tmp/ansible_deploy/mail-debug-1.0.0.-1.el7.x86_64.rpm
|
|
||||||
state: present
|
|
||||||
when: install_mail_debug == "yes"
|
|
||||||
|
|
||||||
- name: "install ssl-debug rpms from localhost"
|
|
||||||
yum:
|
|
||||||
name:
|
|
||||||
- /tmp/ansible_deploy/ssl-debug-1.0.0.-1.el7.x86_64.rpm
|
|
||||||
state: present
|
|
||||||
when: install_ssl_debug == "yes"
|
|
||||||
|
|
||||||
- name: "install fw_dns_plug-debug rpms from localhost"
|
|
||||||
yum:
|
|
||||||
name:
|
|
||||||
- /tmp/ansible_deploy/fw_dns_plug-debug-1.0.2.1c9d36d-1.el7.centos.x86_64.rpm
|
|
||||||
state: present
|
|
||||||
when: install_fw_dns_plug_debug == "yes"
|
|
||||||
|
|
||||||
- name: "install fw_ftp_plug-debug rpms from localhost"
|
|
||||||
yum:
|
|
||||||
name:
|
|
||||||
- /tmp/ansible_deploy/fw_ftp_plug-debug-1.0.0.bd656e4-1.el7.centos.x86_64.rpm
|
|
||||||
state: present
|
|
||||||
when: install_fw_ftp_plug_debug == "yes"
|
|
||||||
|
|
||||||
- name: "install fw_http_plug-debug rpms from localhost"
|
|
||||||
yum:
|
|
||||||
name:
|
|
||||||
- /tmp/ansible_deploy/fw_http_plug-debug-1.0.3.3c95e78-1.el7.centos.x86_64.rpm
|
|
||||||
state: present
|
|
||||||
when: install_fw_http_plug_debug == "yes"
|
|
||||||
|
|
||||||
- name: "install fw_mail_plug-debug rpms from localhost"
|
|
||||||
yum:
|
|
||||||
name:
|
|
||||||
- /tmp/ansible_deploy/fw_mail_plug-debug-1.0.1.8792ed8-1.el7.centos.x86_64.rpm
|
|
||||||
state: present
|
|
||||||
when: install_fw_mail_plug_debug == "yes"
|
|
||||||
|
|
||||||
- name: "install tsg-master rpms from localhost"
|
|
||||||
yum:
|
|
||||||
name:
|
|
||||||
- /tmp/ansible_deploy/tsg_master-debug-1.0.1.f624b67-1.el7.centos.x86_64.rpm
|
|
||||||
state: present
|
|
||||||
when: install_tsg_master == "yes"
|
|
||||||
|
|
||||||
- name: "enable sapp"
|
- name: "enable sapp"
|
||||||
systemd:
|
systemd:
|
||||||
|
|||||||
@@ -11,7 +11,8 @@ deploy_mode = normal
|
|||||||
tun_name = tun_kni
|
tun_name = tun_kni
|
||||||
src_mac_addr = 00:0e:c6:d6:72:c1
|
src_mac_addr = 00:0e:c6:d6:72:c1
|
||||||
dst_mac_addr = fe:65:b7:03:50:bd
|
dst_mac_addr = fe:65:b7:03:50:bd
|
||||||
|
{% if run_as_tun_mode %}
|
||||||
|
{% else %}
|
||||||
[tfe0]
|
[tfe0]
|
||||||
enabled = 1
|
enabled = 1
|
||||||
dev_eth_symbol = {{ nic_to_tfe.tfe0.name }}
|
dev_eth_symbol = {{ nic_to_tfe.tfe0.name }}
|
||||||
@@ -26,6 +27,7 @@ ip_addr = 192.168.100.3
|
|||||||
enabled = 1
|
enabled = 1
|
||||||
dev_eth_symbol = {{ nic_to_tfe.tfe2.name }}
|
dev_eth_symbol = {{ nic_to_tfe.tfe2.name }}
|
||||||
ip_addr = 192.168.100.4
|
ip_addr = 192.168.100.4
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
[tfe_cmsg_receiver]
|
[tfe_cmsg_receiver]
|
||||||
listen_eth = {{ nic_inner_ctrl.name }}
|
listen_eth = {{ nic_inner_ctrl.name }}
|
||||||
|
|||||||
@@ -10,6 +10,11 @@
|
|||||||
- /tmp/ansible_deploy/sapp-4.0.5.3385992-1.el7.x86_64.rpm
|
- /tmp/ansible_deploy/sapp-4.0.5.3385992-1.el7.x86_64.rpm
|
||||||
state: present
|
state: present
|
||||||
|
|
||||||
|
- name: make dir
|
||||||
|
file:
|
||||||
|
path: /home/mesasoft/sapp_run/tsgconf
|
||||||
|
state: directory
|
||||||
|
|
||||||
- name: Template the sapp.toml
|
- name: Template the sapp.toml
|
||||||
template:
|
template:
|
||||||
src: "{{ role_path }}/templates/sapp.toml.j2"
|
src: "{{ role_path }}/templates/sapp.toml.j2"
|
||||||
|
|||||||
@@ -9,10 +9,17 @@
|
|||||||
instance_name = "sapp4"
|
instance_name = "sapp4"
|
||||||
|
|
||||||
[CPU]
|
[CPU]
|
||||||
worker_threads=16
|
{% if run_as_tun_mode %}
|
||||||
|
worker_threads=1
|
||||||
|
{% else %}
|
||||||
|
worker_threads={{ sapp.worker_threads }}
|
||||||
|
{% endif %}
|
||||||
### note, bind_mask, if you do not want to bind thread to special CPU core, keep it empty as []
|
### note, bind_mask, if you do not want to bind thread to special CPU core, keep it empty as []
|
||||||
|
{% if run_as_tun_mode %}
|
||||||
|
bind_mask=[]
|
||||||
|
{% else %}
|
||||||
bind_mask=[1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16]
|
bind_mask=[1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16]
|
||||||
#bind_mask=[]
|
{% endif %}
|
||||||
|
|
||||||
[PACKET_IO]
|
[PACKET_IO]
|
||||||
### note, BSD_packet_filter, if you do not want to set any filter rule, keep it empty as ""
|
### note, BSD_packet_filter, if you do not want to set any filter rule, keep it empty as ""
|
||||||
|
|||||||
@@ -6,6 +6,6 @@ TFE_LOCAL_IP_DATA_INCOMING=172.16.241.2
|
|||||||
TFE_PEER_IP_DATA_INCOMING=172.16.241.1
|
TFE_PEER_IP_DATA_INCOMING=172.16.241.1
|
||||||
|
|
||||||
{% if run_as_tun_mode %}
|
{% if run_as_tun_mode %}
|
||||||
TFE_WATCHDOG_DEVICE=lo
|
TFE_WATCHDOG_DEVICE={{ nic_inner_ctrl.name }}
|
||||||
TFE_WATCHDOG_IP=127.0.0.1
|
TFE_WATCHDOG_IP=192.168.100.1
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|||||||
@@ -6,7 +6,7 @@ breakpad_minidump_dir=/run/tfe/crashreport/
|
|||||||
breakpad_upload_url=http://127.0.0.1:9000/
|
breakpad_upload_url=http://127.0.0.1:9000/
|
||||||
|
|
||||||
[kni]
|
[kni]
|
||||||
ip={{ tfe.kni_ip }}
|
ip=192.168.100.1
|
||||||
scm_port=2475
|
scm_port=2475
|
||||||
watchdog_switch=1
|
watchdog_switch=1
|
||||||
watchdog_port=2476
|
watchdog_port=2476
|
||||||
@@ -30,7 +30,7 @@ service_cache_expire_seconds=600
|
|||||||
# default 0
|
# default 0
|
||||||
mc_cache_enable=1
|
mc_cache_enable=1
|
||||||
# default eth0
|
# default eth0
|
||||||
mc_cache_eth={{ tfe.mc_cache_eth }}
|
mc_cache_eth={{ nic_inner_ctrl.name }}
|
||||||
# default NULL
|
# default NULL
|
||||||
mc_cache_broker_list={{ log_kafkabrokers.address }}
|
mc_cache_broker_list={{ log_kafkabrokers.address }}
|
||||||
# default PXY-EXCH-INTERMEDIA-CERT
|
# default PXY-EXCH-INTERMEDIA-CERT
|
||||||
|
|||||||
15
roles/tsg-env-tun-mode/files/tsg-env-tun-mode.service
Normal file
15
roles/tsg-env-tun-mode/files/tsg-env-tun-mode.service
Normal file
@@ -0,0 +1,15 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=tsg tun mode env init
|
||||||
|
Requires=network.target
|
||||||
|
After=network.target
|
||||||
|
Before=mrenv.service
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
ExecStart=/opt/tsg/env/setup
|
||||||
|
ExecStop=/opt/tsg/env/tsg-env_stop
|
||||||
|
Type=oneshot
|
||||||
|
RemainAfterExit=yes
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
|
RequiredBy=mrenv.service
|
||||||
BIN
roles/tsg-env-tun-mode/files/vconfig-1.9-16.el7.x86_64.rpm
Executable file
BIN
roles/tsg-env-tun-mode/files/vconfig-1.9-16.el7.x86_64.rpm
Executable file
Binary file not shown.
41
roles/tsg-env-tun-mode/tasks/main.yml
Normal file
41
roles/tsg-env-tun-mode/tasks/main.yml
Normal file
@@ -0,0 +1,41 @@
|
|||||||
|
---
|
||||||
|
- name: "copy vconfig-1.9-16.el7.x86_64.rpm"
|
||||||
|
copy:
|
||||||
|
src: "{{ role_path }}/files/vconfig-1.9-16.el7.x86_64.rpm"
|
||||||
|
dest: /tmp
|
||||||
|
|
||||||
|
- name: "create /opt/tsg/env"
|
||||||
|
file:
|
||||||
|
path: /opt/tsg/env
|
||||||
|
state: directory
|
||||||
|
|
||||||
|
- name: "template setup script"
|
||||||
|
template:
|
||||||
|
src: "{{ role_path }}/templates/setup.j2"
|
||||||
|
dest: "/opt/tsg/env/setup"
|
||||||
|
mode: 0755
|
||||||
|
|
||||||
|
- name: "copy tsg-env-tun-mode.service"
|
||||||
|
copy:
|
||||||
|
src: "{{ role_path }}/files/tsg-env-tun-mode.service"
|
||||||
|
dest: "/usr/lib/systemd/system/"
|
||||||
|
mode: 0644
|
||||||
|
|
||||||
|
- name: "template tsg-env_stop"
|
||||||
|
template:
|
||||||
|
src: "{{ role_path }}/templates/tsg-env_stop.j2"
|
||||||
|
dest: "/opt/tsg/env/tsg-env_stop"
|
||||||
|
mode: 0755
|
||||||
|
|
||||||
|
- name: "install vconfig rpms from localhost"
|
||||||
|
yum:
|
||||||
|
name:
|
||||||
|
- /tmp/vconfig-1.9-16.el7.x86_64.rpm
|
||||||
|
state: present
|
||||||
|
|
||||||
|
- name: "enable tsg-env-tun-mode"
|
||||||
|
systemd:
|
||||||
|
name: tsg-env-tun-mode
|
||||||
|
enabled: yes
|
||||||
|
daemon_reload: yes
|
||||||
|
|
||||||
5
roles/tsg-env-tun-mode/templates/setup.j2
Normal file
5
roles/tsg-env-tun-mode/templates/setup.j2
Normal file
@@ -0,0 +1,5 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
modprobe 8021q
|
||||||
|
vconfig add {{ nic_mgr.name }} 100
|
||||||
|
vconfig set_flag {{ nic_mgr.name }}.100 1 1
|
||||||
|
ifconfig {{ nic_mgr.name }}.100 192.168.100.1 netmask 255.255.255.0 up
|
||||||
5
roles/tsg-env-tun-mode/templates/tsg-env_stop.j2
Normal file
5
roles/tsg-env-tun-mode/templates/tsg-env_stop.j2
Normal file
@@ -0,0 +1,5 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
#
|
||||||
|
echo 0 >/sys/class/net/ens1/device/sriov_numvfs
|
||||||
|
ifconfig {{ nic_mgr.name }}.100 down
|
||||||
|
vconfig rem {{ nic_mgr.name }}.100
|
||||||
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
@@ -1,48 +0,0 @@
|
|||||||
- hosts: all
|
|
||||||
tasks:
|
|
||||||
- name: "empty rc.local"
|
|
||||||
copy:
|
|
||||||
src: rc.local
|
|
||||||
dest: /etc/rc.d/rc.local
|
|
||||||
mode: 755
|
|
||||||
|
|
||||||
- hosts: Functional_Host
|
|
||||||
tasks:
|
|
||||||
- name: "remove framework rpms"
|
|
||||||
yum:
|
|
||||||
name: framework
|
|
||||||
state: absent
|
|
||||||
- name: "remove framework files"
|
|
||||||
file:
|
|
||||||
path: /opt/MESA/
|
|
||||||
state: absent
|
|
||||||
force: 1
|
|
||||||
|
|
||||||
- hosts: blade-00
|
|
||||||
tasks:
|
|
||||||
- name: "remove certstore"
|
|
||||||
file:
|
|
||||||
path: /home/tsg/certstore-base/
|
|
||||||
state: absent
|
|
||||||
force: 1
|
|
||||||
|
|
||||||
- name: "remove kni"
|
|
||||||
file:
|
|
||||||
path: /home/tsg/kni/
|
|
||||||
state: absent
|
|
||||||
force: 1
|
|
||||||
|
|
||||||
- hosts: Slave_Host
|
|
||||||
tasks:
|
|
||||||
- name: "remove tfe rpms"
|
|
||||||
yum:
|
|
||||||
name:
|
|
||||||
- tfe
|
|
||||||
- tfe-kmod
|
|
||||||
state: absent
|
|
||||||
|
|
||||||
- name: "remove tfe"
|
|
||||||
file:
|
|
||||||
path: /home/tsg/tfe
|
|
||||||
state: absent
|
|
||||||
force: 1
|
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
- hosts: blade-00:blade-01:blade-02:blade-03
|
|
||||||
tasks:
|
|
||||||
- name: "restart mrzcpd"
|
|
||||||
systemd:
|
|
||||||
name: mrzcpd
|
|
||||||
daemon_reload: 1
|
|
||||||
state: restarted
|
|
||||||
|
|
||||||
#- hosts: blade-01:blade-02:blade-03
|
|
||||||
# tasks:
|
|
||||||
# - name: "restart tfe"
|
|
||||||
# systemd:
|
|
||||||
# name: tfe
|
|
||||||
# daemon_reload: 1
|
|
||||||
# state: restarted
|
|
||||||
Reference in New Issue
Block a user