Compare commits
58 Commits
tsg-versio
...
tsg-versio
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
93fc4a94b8 | ||
|
|
18410aa84a | ||
|
|
a517b99219 | ||
|
|
2b2cbf4113 | ||
|
|
0f2b89512f | ||
|
|
924df3f5fd | ||
|
|
0aaff59a37 | ||
|
|
451677775d | ||
|
|
0fe01beaf5 | ||
|
|
dc050b2e79 | ||
|
|
a6a13adc07 | ||
|
|
470194eb2d | ||
|
|
9c1e8fb655 | ||
|
|
27f242ec8f | ||
|
|
b2c9836677 | ||
|
|
f1f5f29fe1 | ||
|
|
deeb575b7b | ||
|
|
44885b6f02 | ||
|
|
1a173bddcf | ||
|
|
fe5852ce1c | ||
|
|
f49bc21400 | ||
|
|
88d6fda48f | ||
|
|
de0992db4d | ||
|
|
fcb6118c31 | ||
|
|
d9ebec0f1c | ||
|
|
381ef27011 | ||
|
|
da9b09ad08 | ||
|
|
4ae7c7e329 | ||
|
|
c9abe87819 | ||
|
|
ac1e11b722 | ||
|
|
03b37a86d8 | ||
|
|
5aba47de31 | ||
|
|
b57e742be8 | ||
|
|
4177c779ef | ||
|
|
e522e090b5 | ||
|
|
92ed83217a | ||
|
|
c84cf9fa02 | ||
|
|
37dab8e842 | ||
|
|
05b56cb4ec | ||
|
|
27d3231a6e | ||
|
|
b4735332f4 | ||
|
|
f70cf73628 | ||
|
|
1d0943fdb0 | ||
|
|
1d210d18c4 | ||
|
|
e088bc922b | ||
|
|
845a73e69f | ||
|
|
0f1d3dac47 | ||
|
|
198f0ab8a0 | ||
|
|
4ea95f7201 | ||
|
|
e6fbb265a8 | ||
|
|
e1dc6b5f62 | ||
|
|
e67c3feb23 | ||
|
|
32dca71844 | ||
|
|
a54f8ce853 | ||
|
|
f3076ea577 | ||
|
|
e0d3ff7927 | ||
|
|
829dd78560 | ||
|
|
792ce3da1a |
93
deploy.yml
93
deploy.yml
@@ -1,53 +1,126 @@
|
|||||||
- hosts: Functional_Host
|
- hosts:
|
||||||
|
- adc_mcn0
|
||||||
|
- adc_mcn1
|
||||||
|
- adc_mcn2
|
||||||
|
- adc_mcn3
|
||||||
|
remote_user: root
|
||||||
|
vars_files:
|
||||||
|
- install_config/group_vars/adc_global.yml
|
||||||
roles:
|
roles:
|
||||||
- framework
|
- framework
|
||||||
- kernel-ml
|
- kernel-ml
|
||||||
|
|
||||||
- hosts: blade-00
|
- hosts: adc_mxn
|
||||||
|
remote_user: root
|
||||||
|
roles:
|
||||||
|
# - tsg-env-mxn
|
||||||
|
|
||||||
|
- hosts: adc_mcn0
|
||||||
|
remote_user: root
|
||||||
|
vars_files:
|
||||||
|
- install_config/group_vars/adc_global.yml
|
||||||
|
- install_config/group_vars/adc_mcn0.yml
|
||||||
roles:
|
roles:
|
||||||
# - tsg-env-mcn0
|
# - tsg-env-mcn0
|
||||||
- mrzcpd
|
- mrzcpd
|
||||||
- sapp
|
- sapp
|
||||||
|
- tsg_master
|
||||||
- kni
|
- kni
|
||||||
- firewall
|
- firewall
|
||||||
|
- tsg_app
|
||||||
- http_healthcheck
|
- http_healthcheck
|
||||||
- clotho
|
- packet_dump
|
||||||
- certstore
|
- certstore
|
||||||
- cert-redis
|
- cert-redis
|
||||||
|
- telegraf_statistic
|
||||||
|
# - tsg_device_tag
|
||||||
|
|
||||||
- hosts: blade-01
|
- hosts: adc_mcn1
|
||||||
|
remote_user: root
|
||||||
|
vars_files:
|
||||||
|
- install_config/group_vars/adc_global.yml
|
||||||
|
- install_config/group_vars/adc_mcn1.yml
|
||||||
roles:
|
roles:
|
||||||
# - tsg-env-mcn1
|
# - tsg-env-mcn1
|
||||||
- mrzcpd
|
- mrzcpd
|
||||||
- tfe
|
- tfe
|
||||||
|
|
||||||
- hosts: blade-02
|
- hosts: adc_mcn2
|
||||||
|
remote_user: root
|
||||||
|
vars_files:
|
||||||
|
- install_config/group_vars/adc_global.yml
|
||||||
|
- install_config/group_vars/adc_mcn2.yml
|
||||||
roles:
|
roles:
|
||||||
# - tsg-env-mcn2
|
# - tsg-env-mcn2
|
||||||
- mrzcpd
|
- mrzcpd
|
||||||
- tfe
|
- tfe
|
||||||
|
|
||||||
- hosts: blade-03
|
- hosts: adc_mcn3
|
||||||
|
remote_user: root
|
||||||
|
vars_files:
|
||||||
|
- install_config/group_vars/adc_global.yml
|
||||||
|
- install_config/group_vars/adc_mcn3.yml
|
||||||
roles:
|
roles:
|
||||||
# - tsg-env-mcn3
|
# - tsg-env-mcn3
|
||||||
- mrzcpd
|
- mrzcpd
|
||||||
- tfe
|
- tfe
|
||||||
|
|
||||||
- hosts: blade-mxn
|
- hosts: adc_mcn0
|
||||||
|
remote_user: root
|
||||||
roles:
|
roles:
|
||||||
# - tsg-env-mxn
|
- tsg-diagnose
|
||||||
|
|
||||||
- hosts: pc-as-tun-mode
|
- hosts:
|
||||||
|
- adc_mcn1
|
||||||
|
- adc_mcn2
|
||||||
|
- adc_mcn3
|
||||||
|
remote_user: root
|
||||||
|
roles:
|
||||||
|
- tsg-diagnose_sync_ca
|
||||||
|
|
||||||
|
- hosts: adc_mcn0
|
||||||
|
remote_user: root
|
||||||
|
roles:
|
||||||
|
- tsg-diagnose_stop_sync
|
||||||
|
|
||||||
|
- hosts:
|
||||||
|
- adc_mcn0
|
||||||
|
- adc_mcn1
|
||||||
|
- adc_mcn2
|
||||||
|
- adc_mcn3
|
||||||
|
remote_user: root
|
||||||
|
vars_files:
|
||||||
|
- install_config/group_vars/adc_global.yml
|
||||||
|
roles:
|
||||||
|
- reboot
|
||||||
|
|
||||||
|
- hosts: server-as-tun-mode
|
||||||
|
remote_user: root
|
||||||
|
vars_files:
|
||||||
|
- install_config/group_vars/server_as_tun_mode.yml
|
||||||
roles:
|
roles:
|
||||||
- kernel-ml
|
- kernel-ml
|
||||||
- framework
|
- framework
|
||||||
- mrzcpd
|
- mrzcpd
|
||||||
- tsg-env-tun-mode
|
- tsg-env-tun-mode
|
||||||
- sapp
|
- sapp
|
||||||
|
- tsg_master
|
||||||
- kni
|
- kni
|
||||||
- firewall
|
- firewall
|
||||||
|
- tsg_app
|
||||||
- http_healthcheck
|
- http_healthcheck
|
||||||
- clotho
|
- packet_dump
|
||||||
- certstore
|
- certstore
|
||||||
- cert-redis
|
- cert-redis
|
||||||
- tfe
|
- tfe
|
||||||
|
- telegraf_statistic
|
||||||
|
- proxy_status
|
||||||
|
# - tsg_device_tag
|
||||||
|
- reboot
|
||||||
|
|
||||||
|
- hosts: app_global
|
||||||
|
remote_user: root
|
||||||
|
vars_files:
|
||||||
|
- install_config/group_vars/app_global.yml
|
||||||
|
roles:
|
||||||
|
- app_global
|
||||||
|
|||||||
109
install_config/group_vars/adc_global.yml
Normal file
109
install_config/group_vars/adc_global.yml
Normal file
@@ -0,0 +1,109 @@
|
|||||||
|
#########################################
|
||||||
|
#####1: Inline_device; 2: Allot; 3: ADC_Tun_mode;
|
||||||
|
tsg_access_type: 3
|
||||||
|
#####2: ADC;
|
||||||
|
tsg_running_type: 2
|
||||||
|
|
||||||
|
########################################
|
||||||
|
#Deploy_finished_reboot
|
||||||
|
Deploy_finished_reboot: 1
|
||||||
|
|
||||||
|
########################################
|
||||||
|
#IP Config
|
||||||
|
maat_redis_server:
|
||||||
|
address: "192.168.40.168"
|
||||||
|
port: 7002
|
||||||
|
db: 0
|
||||||
|
|
||||||
|
dynamic_maat_redis_server:
|
||||||
|
address: "192.168.40.168"
|
||||||
|
port: 7002
|
||||||
|
db: 0
|
||||||
|
|
||||||
|
cert_store_server:
|
||||||
|
address: "192.168.100.1"
|
||||||
|
port: 9991
|
||||||
|
|
||||||
|
log_kafkabrokers:
|
||||||
|
address: "1.1.1.1:9092,2.2.2.2:9092"
|
||||||
|
|
||||||
|
monitor_outputs_influxdb:
|
||||||
|
url: "http://192.168.41.182:58086"
|
||||||
|
|
||||||
|
log_minio:
|
||||||
|
address: "192.168.40.168;"
|
||||||
|
port: 9090
|
||||||
|
|
||||||
|
#########################################
|
||||||
|
#Log Level Config
|
||||||
|
#日志等级 10:DEBUG 20:INFO 30:FATAL
|
||||||
|
fw_ftp_log_level: 10
|
||||||
|
fw_mail_log_level: 10
|
||||||
|
fw_http_log_level: 10
|
||||||
|
fw_dns_log_level: 10
|
||||||
|
fw_quic_log_level: 10
|
||||||
|
capture_packet_log_level: 10
|
||||||
|
tsg_log_level: 10
|
||||||
|
tsg_master_log_level: 10
|
||||||
|
kni_log_level: 10
|
||||||
|
|
||||||
|
#日志等级 DEBUG INFO FATAL
|
||||||
|
tfe_log_level: DEBUG
|
||||||
|
tfe_http_log_level: DEBUG
|
||||||
|
pangu_log_level: DEBUG
|
||||||
|
doh_log_level: DEBUG
|
||||||
|
|
||||||
|
certstore_log_level: 10
|
||||||
|
packet_dump_log_level: 10
|
||||||
|
|
||||||
|
#######################################
|
||||||
|
#Sapp Performance Config
|
||||||
|
#Sapp工作在ADC计算板0时,建议使用如下30+8的配置,以保证更高的处理性能
|
||||||
|
sapp:
|
||||||
|
worker_threads: 37
|
||||||
|
send_only_threads_max: 1
|
||||||
|
bind_mask: 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38
|
||||||
|
inbound_route_dir: 1
|
||||||
|
|
||||||
|
########################################
|
||||||
|
#Kni Config
|
||||||
|
kni:
|
||||||
|
global:
|
||||||
|
tfe_node_count: 3
|
||||||
|
watch_dog:
|
||||||
|
switch: 1
|
||||||
|
maat:
|
||||||
|
readconf_mode: 2
|
||||||
|
send_logger:
|
||||||
|
switch: 1
|
||||||
|
tfe_nodes:
|
||||||
|
tfe0_enabled: 1
|
||||||
|
tfe1_enabled: 1
|
||||||
|
tfe2_enabled: 1
|
||||||
|
|
||||||
|
########################################
|
||||||
|
#Tfe Config
|
||||||
|
tfe:
|
||||||
|
nr_threads: 32
|
||||||
|
mirror_enable: 1
|
||||||
|
|
||||||
|
########################################
|
||||||
|
#Marsio Config
|
||||||
|
#marsio工作在ADC计算板时,建议使用如下配置,以保证更高的处理性能
|
||||||
|
mrzcpd:
|
||||||
|
iocore: 52,53,54,55
|
||||||
|
|
||||||
|
mrtunnat:
|
||||||
|
lcore_id: 48,49,50,51
|
||||||
|
|
||||||
|
#########################################
|
||||||
|
#Tsg_app
|
||||||
|
tsg_app_enable: 0
|
||||||
|
app_global_ip: "1.1.1.1"
|
||||||
|
applog_level: 10
|
||||||
|
app_master_log_level: 10
|
||||||
|
app_sketch_local_log_level: 10
|
||||||
|
app_control_plug_log_level: 10
|
||||||
|
|
||||||
|
|
||||||
|
breakpad_upload_url: http://127.0.0.1/
|
||||||
39
install_config/group_vars/adc_mcn0.yml
Normal file
39
install_config/group_vars/adc_mcn0.yml
Normal file
@@ -0,0 +1,39 @@
|
|||||||
|
#########################################
|
||||||
|
#Mcn0管理口网卡名
|
||||||
|
nic_mgr:
|
||||||
|
name: ens1f3
|
||||||
|
|
||||||
|
#########################################
|
||||||
|
#Mcn0流量接入网卡,固定配置
|
||||||
|
nic_data_incoming:
|
||||||
|
name: ens1f4
|
||||||
|
|
||||||
|
#########################################
|
||||||
|
#Mcn0其他数据口网卡名配置,固定配置
|
||||||
|
nic_inner_ctrl:
|
||||||
|
name: ens1.100
|
||||||
|
nic_to_tfe:
|
||||||
|
tfe0:
|
||||||
|
name: ens1f5
|
||||||
|
tfe1:
|
||||||
|
name: ens1f6
|
||||||
|
tfe2:
|
||||||
|
name: ens1f7
|
||||||
|
|
||||||
|
#########################################
|
||||||
|
#串联设备接入相关配置
|
||||||
|
inline_device_config:
|
||||||
|
keepalive_ip: 192.168.1.30
|
||||||
|
keepalive_mask: 255.255.255.252
|
||||||
|
|
||||||
|
#########################################
|
||||||
|
#Allot接入相关配置
|
||||||
|
AllotAccess:
|
||||||
|
virturlInterface_1: ens1f2.103
|
||||||
|
virturlInterface_2: ens1f2.104
|
||||||
|
virturlID_1: 103
|
||||||
|
virturlID_2: 104
|
||||||
|
vvipv4_mask: 24
|
||||||
|
vvipv6_mask: 64
|
||||||
|
|
||||||
|
bladename: mcn0
|
||||||
19
install_config/group_vars/adc_mcn1.yml
Normal file
19
install_config/group_vars/adc_mcn1.yml
Normal file
@@ -0,0 +1,19 @@
|
|||||||
|
#########################################
|
||||||
|
#Mcn1管理口网卡名
|
||||||
|
nic_mgr:
|
||||||
|
name: ens1f3
|
||||||
|
|
||||||
|
#########################################
|
||||||
|
#Mcn1流量接入网卡,固定配置
|
||||||
|
nic_data_incoming:
|
||||||
|
name: ens1f1
|
||||||
|
|
||||||
|
#########################################
|
||||||
|
#Mcn1其他数据口网卡名配置,固定配置
|
||||||
|
nic_inner_ctrl:
|
||||||
|
name: ens1.100
|
||||||
|
nic_traffic_mirror:
|
||||||
|
name: ens1f2
|
||||||
|
use_mrzcpd: 1
|
||||||
|
|
||||||
|
bladename: mcn1
|
||||||
19
install_config/group_vars/adc_mcn2.yml
Normal file
19
install_config/group_vars/adc_mcn2.yml
Normal file
@@ -0,0 +1,19 @@
|
|||||||
|
#########################################
|
||||||
|
#Mcn2管理口网卡名
|
||||||
|
nic_mgr:
|
||||||
|
name: ens8f3
|
||||||
|
|
||||||
|
#########################################
|
||||||
|
#Mcn2流量接入网卡,固定配置
|
||||||
|
nic_data_incoming:
|
||||||
|
name: ens8f1
|
||||||
|
|
||||||
|
#########################################
|
||||||
|
#Mcn2其他数据口网卡名配置,固定配置
|
||||||
|
nic_inner_ctrl:
|
||||||
|
name: ens8.100
|
||||||
|
nic_traffic_mirror:
|
||||||
|
name: ens8f2
|
||||||
|
use_mrzcpd: 1
|
||||||
|
|
||||||
|
bladename: mcn2
|
||||||
19
install_config/group_vars/adc_mcn3.yml
Normal file
19
install_config/group_vars/adc_mcn3.yml
Normal file
@@ -0,0 +1,19 @@
|
|||||||
|
#########################################
|
||||||
|
#Mcn3管理口网卡名
|
||||||
|
nic_mgr:
|
||||||
|
name: ens8f3
|
||||||
|
|
||||||
|
#########################################
|
||||||
|
#Mcn3流量接入网卡,固定配置
|
||||||
|
nic_data_incoming:
|
||||||
|
name: ens8f1
|
||||||
|
|
||||||
|
#########################################
|
||||||
|
#Mcn3其他数据口网卡名配置,固定配置
|
||||||
|
nic_inner_ctrl:
|
||||||
|
name: ens8.100
|
||||||
|
nic_traffic_mirror:
|
||||||
|
name: ens8f2
|
||||||
|
use_mrzcpd: 1
|
||||||
|
|
||||||
|
bladename: mcn3
|
||||||
@@ -1,76 +0,0 @@
|
|||||||
########################################
|
|
||||||
tsg_access_type: 0
|
|
||||||
|
|
||||||
########################################
|
|
||||||
maat_redis_server:
|
|
||||||
address: "192.168.40.168"
|
|
||||||
port: 7002
|
|
||||||
db: 0
|
|
||||||
|
|
||||||
dynamic_maat_redis_server:
|
|
||||||
address: "192.168.40.168"
|
|
||||||
port: 7002
|
|
||||||
db: 0
|
|
||||||
|
|
||||||
cert_store_server:
|
|
||||||
address: "192.168.100.1"
|
|
||||||
port: 9991
|
|
||||||
|
|
||||||
log_kafkabrokers:
|
|
||||||
address: "192.168.40.169:9092"
|
|
||||||
|
|
||||||
log_minio:
|
|
||||||
address: "192.168.40.168;"
|
|
||||||
port: 9090
|
|
||||||
|
|
||||||
fs_remote:
|
|
||||||
switch: 1
|
|
||||||
address: "192.168.100.1"
|
|
||||||
port: 58125
|
|
||||||
|
|
||||||
########################################
|
|
||||||
sapp:
|
|
||||||
worker_threads: 16
|
|
||||||
bind_mask: 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16
|
|
||||||
|
|
||||||
########################################
|
|
||||||
kni:
|
|
||||||
global:
|
|
||||||
log_level: 30
|
|
||||||
tfe_node_count: 3
|
|
||||||
watch_dog:
|
|
||||||
switch: 1
|
|
||||||
maat:
|
|
||||||
readconf_mode: 2
|
|
||||||
send_logger:
|
|
||||||
switch: 1
|
|
||||||
tfe_nodes:
|
|
||||||
- tfe0:
|
|
||||||
enabled: 1
|
|
||||||
- tfe1:
|
|
||||||
enabled: 1
|
|
||||||
- tfe2:
|
|
||||||
enabled: 1
|
|
||||||
|
|
||||||
########################################
|
|
||||||
tfe:
|
|
||||||
nr_threads: 32
|
|
||||||
mc_cache_eth: lo
|
|
||||||
keykeeper:
|
|
||||||
mode: "normal"
|
|
||||||
no_cache: 0
|
|
||||||
|
|
||||||
########################################
|
|
||||||
mrzcpd:
|
|
||||||
iocore: 39
|
|
||||||
|
|
||||||
mrtunnat:
|
|
||||||
lcore_id: 38
|
|
||||||
|
|
||||||
########################################
|
|
||||||
tsg_tun_mode:
|
|
||||||
ethname: eth0
|
|
||||||
tun_name: eth0.100
|
|
||||||
internal_interface: "eth2"
|
|
||||||
external_interface: "eth3"
|
|
||||||
|
|
||||||
10
install_config/group_vars/app_global.yml
Normal file
10
install_config/group_vars/app_global.yml
Normal file
@@ -0,0 +1,10 @@
|
|||||||
|
#########################################
|
||||||
|
app_sketch_global_log_level: 10
|
||||||
|
|
||||||
|
maat_redis_server:
|
||||||
|
address: "192.168.40.168"
|
||||||
|
port: 7002
|
||||||
|
db: 0
|
||||||
|
|
||||||
|
file_stat_ip: "1.1.1.1"
|
||||||
|
|
||||||
@@ -1,23 +0,0 @@
|
|||||||
nic_mgr:
|
|
||||||
name: enp6s0
|
|
||||||
nic_data_incoming:
|
|
||||||
name: ens1f4
|
|
||||||
ip: 192.168.1.30
|
|
||||||
mask: 255.255.255.252
|
|
||||||
nic_inner_ctrl:
|
|
||||||
name: ens1.100
|
|
||||||
nic_to_tfe:
|
|
||||||
tfe0:
|
|
||||||
name: ens1f5
|
|
||||||
tfe1:
|
|
||||||
name: ens1f6
|
|
||||||
tfe2:
|
|
||||||
name: ens1f7
|
|
||||||
|
|
||||||
AllotAccess:
|
|
||||||
virturlInterface_1: ens1f2.103
|
|
||||||
virturlInterface_2: ens1f2.104
|
|
||||||
virturlID_1: 103
|
|
||||||
virturlID_2: 104
|
|
||||||
vvipv4_mask: 24
|
|
||||||
vvipv6_mask: 64
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
nic_mgr:
|
|
||||||
name: enp6s0
|
|
||||||
nic_data_incoming:
|
|
||||||
name: ens1f1
|
|
||||||
mac: AA:BB:CC:DD:EE:FF
|
|
||||||
address: 127.0.0.1
|
|
||||||
nic_inner_ctrl:
|
|
||||||
name: ens1.100
|
|
||||||
nic_traffic_mirror:
|
|
||||||
name: ens1f2
|
|
||||||
use_mrzcpd: 1
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
nic_mgr:
|
|
||||||
name: enp6s0
|
|
||||||
nic_data_incoming:
|
|
||||||
name: ens8f1
|
|
||||||
mac: AA:BB:CC:DD:EE:FF
|
|
||||||
nic_inner_ctrl:
|
|
||||||
name: ens8.100
|
|
||||||
nic_traffic_mirror:
|
|
||||||
name: ens8f2
|
|
||||||
use_mrzcpd: 1
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
nic_mgr:
|
|
||||||
name: enp6s0
|
|
||||||
nic_data_incoming:
|
|
||||||
name: ens8f1
|
|
||||||
mac: AA:BB:CC:DD:EE:FF
|
|
||||||
nic_inner_ctrl:
|
|
||||||
name: ens8.100
|
|
||||||
nic_traffic_mirror:
|
|
||||||
name: ens8f2
|
|
||||||
use_mrzcpd: 1
|
|
||||||
145
install_config/group_vars/server_as_tun_mode.yml
Normal file
145
install_config/group_vars/server_as_tun_mode.yml
Normal file
@@ -0,0 +1,145 @@
|
|||||||
|
#########################################
|
||||||
|
#####0: Pcap; 1: Inline_device; 4: ATCA_Vlan_Flipping; 5:ATCA_VXLAN;
|
||||||
|
tsg_access_type: 1
|
||||||
|
#####0: Tun_mode; 1: normal;
|
||||||
|
tsg_running_type: 1
|
||||||
|
|
||||||
|
########################################
|
||||||
|
#Deploy_finished_reboot
|
||||||
|
Deploy_finished_reboot: 1
|
||||||
|
|
||||||
|
########################################
|
||||||
|
#Server Basic Config
|
||||||
|
nic_mgr:
|
||||||
|
name: eth0
|
||||||
|
|
||||||
|
nic_inner_ctrl:
|
||||||
|
name: eth0.100
|
||||||
|
|
||||||
|
#########################################
|
||||||
|
#IP Config
|
||||||
|
maat_redis_server:
|
||||||
|
address: "192.168.40.168"
|
||||||
|
port: 7002
|
||||||
|
db: 0
|
||||||
|
|
||||||
|
dynamic_maat_redis_server:
|
||||||
|
address: "192.168.40.168"
|
||||||
|
port: 7002
|
||||||
|
db: 0
|
||||||
|
|
||||||
|
cert_store_server:
|
||||||
|
address: "192.168.100.1"
|
||||||
|
port: 9991
|
||||||
|
|
||||||
|
log_kafkabrokers:
|
||||||
|
address: "1.1.1.1:9092,2.2.2.2:9092"
|
||||||
|
|
||||||
|
log_minio:
|
||||||
|
address: "192.168.40.168;"
|
||||||
|
port: 9090
|
||||||
|
|
||||||
|
#########################################
|
||||||
|
#Log Level Config
|
||||||
|
#日志等级 10:DEBUG 20:INFO 30:FATAL
|
||||||
|
fw_ftp_log_level: 10
|
||||||
|
fw_mail_log_level: 10
|
||||||
|
fw_http_log_level: 10
|
||||||
|
fw_dns_log_level: 10
|
||||||
|
fw_quic_log_level: 10
|
||||||
|
capture_packet_log_level: 10
|
||||||
|
tsg_log_level: 10
|
||||||
|
tsg_master_log_level: 10
|
||||||
|
kni_log_level: 10
|
||||||
|
|
||||||
|
|
||||||
|
#日志等级 DEBUG INFO FATAL
|
||||||
|
tfe_log_level: DEBUG
|
||||||
|
tfe_http_log_level: DEBUG
|
||||||
|
pangu_log_level: DEBUG
|
||||||
|
doh_log_level: DEBUG
|
||||||
|
|
||||||
|
certstore_log_level: 10
|
||||||
|
clotho_log_level: 10
|
||||||
|
|
||||||
|
#########################################
|
||||||
|
#Sapp Performance Config
|
||||||
|
#如果tsg_access_type=0,sapp跑在pcap模式,则以下配置可忽略
|
||||||
|
sapp:
|
||||||
|
worker_threads: 23
|
||||||
|
send_only_threads_max: 1
|
||||||
|
bind_mask: 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24
|
||||||
|
inbound_route_dir: 1
|
||||||
|
|
||||||
|
#########################################
|
||||||
|
#Sapp Double-Arm Config
|
||||||
|
packet_io:
|
||||||
|
internal_interface: eth2
|
||||||
|
external_interface: eth3
|
||||||
|
|
||||||
|
|
||||||
|
#########################################
|
||||||
|
#Kni Config
|
||||||
|
kni:
|
||||||
|
global:
|
||||||
|
tfe_node_count: 1
|
||||||
|
watch_dog:
|
||||||
|
switch: 1
|
||||||
|
maat:
|
||||||
|
readconf_mode: 2
|
||||||
|
send_logger:
|
||||||
|
switch: 1
|
||||||
|
tfe_nodes:
|
||||||
|
tfe0_enabled: 1
|
||||||
|
tfe1_enabled: 0
|
||||||
|
tfe2_enabled: 0
|
||||||
|
|
||||||
|
#########################################
|
||||||
|
#Tfe Config
|
||||||
|
tfe:
|
||||||
|
nr_threads: 32
|
||||||
|
mirror_enable: 1
|
||||||
|
|
||||||
|
#########################################
|
||||||
|
#Marsio Config
|
||||||
|
mrzcpd:
|
||||||
|
iocore: 39
|
||||||
|
|
||||||
|
mrtunnat:
|
||||||
|
lcore_id: 38
|
||||||
|
|
||||||
|
#########################################
|
||||||
|
#Tsg_app
|
||||||
|
tsg_app_enable: 1
|
||||||
|
app_global_ip: "1.1.1.1"
|
||||||
|
applog_level: 10
|
||||||
|
app_master_log_level: 10
|
||||||
|
app_sketch_local_log_level: 10
|
||||||
|
app_control_plug_log_level: 10
|
||||||
|
|
||||||
|
#########################################
|
||||||
|
#ATCA Config
|
||||||
|
#下列配置只在tsg_access_type=4时生效
|
||||||
|
ATCA_data_incoming:
|
||||||
|
ethname: enp1s0
|
||||||
|
vf0_name: enp1s2
|
||||||
|
vf1_name: enp1s2f1
|
||||||
|
vf2_name: enp1s2f2
|
||||||
|
|
||||||
|
ATCA_VlanFlipping:
|
||||||
|
vlanID_1: 100
|
||||||
|
vlanID_2: 101
|
||||||
|
vlanID_3: 103
|
||||||
|
vlanID_4: 104
|
||||||
|
|
||||||
|
#下列配置只在tsg_access_type=5时生效
|
||||||
|
ATCA_VXLAN:
|
||||||
|
keepalive_ip: "10.254.19.1"
|
||||||
|
keepalive_mask: "255.255.255.252"
|
||||||
|
|
||||||
|
#########################################
|
||||||
|
#Inline Device Config
|
||||||
|
inline_device_config:
|
||||||
|
keepalive_ip: 192.168.1.30
|
||||||
|
keepalive_mask: 255.255.255.252
|
||||||
|
data_incoming: eth5
|
||||||
@@ -1,26 +1,41 @@
|
|||||||
[all:vars]
|
###################
|
||||||
ansible_user=root
|
# For example #
|
||||||
package_source=local
|
###################
|
||||||
|
#变量device_id根据设备序号设置即可
|
||||||
|
#变量vvipv4_1、vvipv4_2、vvipv6_1、vvipv6_2为Allot相关配置,其他环境可不填或直接删除变量
|
||||||
|
#
|
||||||
|
#20.09版本新增APP部署
|
||||||
|
#[app_global]
|
||||||
|
#0.0.0.0
|
||||||
|
|
||||||
[pc-as-tun-mode]
|
#[server-as-tun-mode]
|
||||||
|
#1.1.1.1 device_id=device_1
|
||||||
|
#
|
||||||
|
#[adc_mxn]
|
||||||
|
#10.3.72.1
|
||||||
|
#10.3.72.2
|
||||||
|
#
|
||||||
|
#[adc_mcn0]
|
||||||
|
#10.3.73.1 device_id=device_1 vvipv4_1=10.3.61.1 vvipv4_2=10.3.62.1 vvipv6_1=fc00::61:1 vvipv6_2=fc00::62:1
|
||||||
|
#10.3.73.2 device_id=device_2 vvipv4_1=10.3.61.2 vvipv4_2=10.3.62.2 vvipv6_1=fc00::61:2 vvipv6_2=fc00::62:2
|
||||||
|
#
|
||||||
|
#[adc_mcn1]
|
||||||
|
#10.3.74.1 device_id=device_1
|
||||||
|
#10.3.74.2 device_id=device_2
|
||||||
|
#
|
||||||
|
#[adc_mcn2]
|
||||||
|
#10.3.75.1 device_id=device_1
|
||||||
|
#10.3.75.2 device_id=device_2
|
||||||
|
#
|
||||||
|
#[adc_mcn3]
|
||||||
|
#10.3.76.1 device_id=device_1
|
||||||
|
#10.3.76.2 device_id=device_2
|
||||||
|
|
||||||
[blade-mxn]
|
[app_global]
|
||||||
192.168.40.170
|
[server-as-tun-mode]
|
||||||
|
[adc_mxn]
|
||||||
|
[adc_mcn0]
|
||||||
|
[adc_mcn1]
|
||||||
|
[adc_mcn2]
|
||||||
|
[adc_mcn3]
|
||||||
|
|
||||||
[blade-00]
|
|
||||||
192.168.40.166 vvipv4_1= vvipv4_2= vvipv6_1= vvipv6_2=
|
|
||||||
|
|
||||||
[blade-01]
|
|
||||||
192.168.40.167
|
|
||||||
|
|
||||||
[blade-02]
|
|
||||||
192.168.40.168
|
|
||||||
|
|
||||||
[blade-03]
|
|
||||||
192.168.40.169
|
|
||||||
|
|
||||||
[Functional_Host:children]
|
|
||||||
blade-00
|
|
||||||
blade-01
|
|
||||||
blade-02
|
|
||||||
blade-03
|
|
||||||
|
|||||||
Binary file not shown.
BIN
roles/app_global/files/emqx-centos7-v4.1.2.x86_64.rpm
Executable file
BIN
roles/app_global/files/emqx-centos7-v4.1.2.x86_64.rpm
Executable file
Binary file not shown.
33
roles/app_global/tasks/main.yml
Normal file
33
roles/app_global/tasks/main.yml
Normal file
@@ -0,0 +1,33 @@
|
|||||||
|
- name: "copy app_global rpm to destination server"
|
||||||
|
copy:
|
||||||
|
src: "{{ role_path }}/files/"
|
||||||
|
dest: /tmp/ansible_deploy/
|
||||||
|
|
||||||
|
- name: "install app rpms from localhost"
|
||||||
|
yum:
|
||||||
|
name:
|
||||||
|
- /tmp/ansible_deploy/emqx-centos7-v4.1.2.x86_64.rpm
|
||||||
|
- /tmp/ansible_deploy/app-sketch-global-1.0.2.20200918.ab44d17-1.el7.x86_64.rpm
|
||||||
|
state: present
|
||||||
|
|
||||||
|
- name: "template the app_sketch_global.conf"
|
||||||
|
template:
|
||||||
|
src: "{{ role_path }}/templates/app_sketch_global.conf.j2"
|
||||||
|
dest: /opt/tsg/app-sketch-global/conf/app_sketch_global.conf
|
||||||
|
|
||||||
|
- name: "template the zlog.conf"
|
||||||
|
template:
|
||||||
|
src: "{{ role_path }}/templates/zlog.conf.j2"
|
||||||
|
dest: /opt/tsg/app-sketch-global/conf/zlog.conf
|
||||||
|
|
||||||
|
- name: "Start emqx"
|
||||||
|
systemd:
|
||||||
|
name: emqx.service
|
||||||
|
state: started
|
||||||
|
enabled: yes
|
||||||
|
|
||||||
|
- name: "Start app-sketch-global"
|
||||||
|
systemd:
|
||||||
|
name: app-sketch-global.service
|
||||||
|
state: started
|
||||||
|
enabled: yes
|
||||||
41
roles/app_global/templates/app_sketch_global.conf.j2
Normal file
41
roles/app_global/templates/app_sketch_global.conf.j2
Normal file
@@ -0,0 +1,41 @@
|
|||||||
|
[SYSTEM]
|
||||||
|
#1:print on screen, 0:don't
|
||||||
|
DEBUG_SWITCH = 1
|
||||||
|
RUN_LOG_PATH = "conf/zlog.conf"
|
||||||
|
|
||||||
|
[breakpad]
|
||||||
|
disable_coredump=0
|
||||||
|
enable_breakpad=1
|
||||||
|
breakpad_minidump_dir=/tmp/app-sketch-global/crashreport
|
||||||
|
enable_breakpad_upload=0
|
||||||
|
breakpad_upload_url={{ breakpad_upload_url }}
|
||||||
|
|
||||||
|
[CONFIG]
|
||||||
|
#Number of running threads
|
||||||
|
thread-nu = 1
|
||||||
|
timeout = 3600
|
||||||
|
address="tcp://127.0.0.1:1883"
|
||||||
|
topic_name="APP_SIGNATURE_ID"
|
||||||
|
client_name="ExampleClientSub"
|
||||||
|
|
||||||
|
[maat]
|
||||||
|
# 0:json 1: redis 2: iris
|
||||||
|
maat_input_mode=1
|
||||||
|
table_info=./resource/table_info.conf
|
||||||
|
json_cfg_file=./resource/gtest.json
|
||||||
|
stat_file=logs/verify-policy.status
|
||||||
|
full_cfg_dir=verify-policy/
|
||||||
|
inc_cfg_dir=verify-policy/
|
||||||
|
|
||||||
|
maat_redis_server={{ maat_redis_server.address }}
|
||||||
|
maat_redis_port_range={{ maat_redis_server.port }}
|
||||||
|
maat_redis_db_index={{ maat_redis_server.db }}
|
||||||
|
effect_interval_s=1
|
||||||
|
accept_tags={"tags":[{"tag":"location","value":"Astana"}]}
|
||||||
|
|
||||||
|
[stat]
|
||||||
|
statsd_server={{ file_stat_ip }}
|
||||||
|
statsd_port=8100
|
||||||
|
statsd_cycle=5
|
||||||
|
# FS_OUTPUT_STATSD=1, FS_OUTPUT_INFLUX_LINE=2
|
||||||
|
statsd_format=2
|
||||||
12
roles/app_global/templates/zlog.conf.j2
Normal file
12
roles/app_global/templates/zlog.conf.j2
Normal file
@@ -0,0 +1,12 @@
|
|||||||
|
[global]
|
||||||
|
default format = "%d(%c), %V, %F, %U, %m%n"
|
||||||
|
[levels]
|
||||||
|
DEBUG=10
|
||||||
|
INFO=20
|
||||||
|
FATAL=30
|
||||||
|
[rules]
|
||||||
|
*.fatal "./logs/error.log.%d(%F)";
|
||||||
|
*.{{ app_sketch_global_log_level }} "./logs/app_sketch_global.log.%d(%F)"
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
@@ -160,7 +160,7 @@ loglevel notice
|
|||||||
# Specify the log file name. Also the empty string can be used to force
|
# Specify the log file name. Also the empty string can be used to force
|
||||||
# Redis to log on the standard output. Note that if you use standard
|
# Redis to log on the standard output. Note that if you use standard
|
||||||
# output for logging but daemonize, logs will be sent to /dev/null
|
# output for logging but daemonize, logs will be sent to /dev/null
|
||||||
logfile "/home/tsg/cert-redis/6379/6379.log"
|
logfile "/opt/tsg/cert-redis/6379/6379.log"
|
||||||
|
|
||||||
# To enable logging to the system logger, just set 'syslog-enabled' to yes,
|
# To enable logging to the system logger, just set 'syslog-enabled' to yes,
|
||||||
# and optionally update the other syslog parameters to suit your needs.
|
# and optionally update the other syslog parameters to suit your needs.
|
||||||
@@ -244,7 +244,7 @@ dbfilename dump.rdb
|
|||||||
# The Append Only File will also be created inside this directory.
|
# The Append Only File will also be created inside this directory.
|
||||||
#
|
#
|
||||||
# Note that you must specify a directory here, not a file name.
|
# Note that you must specify a directory here, not a file name.
|
||||||
dir /home/tsg/cert-redis/6379/
|
dir /opt/tsg/cert-redis/6379/
|
||||||
|
|
||||||
################################# REPLICATION #################################
|
################################# REPLICATION #################################
|
||||||
|
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
#
|
#
|
||||||
|
|
||||||
/usr/local/bin/redis-server /home/tsg/cert-redis/6379/6379.conf
|
/usr/local/bin/redis-server /opt/tsg/cert-redis/6379/6379.conf
|
||||||
|
|||||||
@@ -1,11 +1,11 @@
|
|||||||
- name: "copy cert-redis to destination server"
|
- name: "copy cert-redis to destination server"
|
||||||
copy:
|
copy:
|
||||||
src: "{{ role_path }}/files/"
|
src: "{{ role_path }}/files/"
|
||||||
dest: /home/tsg
|
dest: /opt/tsg
|
||||||
mode: 0755
|
mode: 0755
|
||||||
|
|
||||||
- name: "install cert-redis"
|
- name: "install cert-redis"
|
||||||
shell: cd /home/tsg/cert-redis;sh install.sh
|
shell: cd /opt/tsg/cert-redis;sh install.sh
|
||||||
|
|
||||||
- name: "start cert-redis"
|
- name: "start cert-redis"
|
||||||
systemd:
|
systemd:
|
||||||
|
|||||||
Binary file not shown.
Binary file not shown.
@@ -3,20 +3,25 @@
|
|||||||
src: "{{ role_path }}/files/"
|
src: "{{ role_path }}/files/"
|
||||||
dest: "/tmp/ansible_deploy/"
|
dest: "/tmp/ansible_deploy/"
|
||||||
|
|
||||||
- name: Ensures /home/tsg exists
|
- name: Ensures /opt/tsg exists
|
||||||
file: path=/home/tsg state=directory
|
file: path=/opt/tsg state=directory
|
||||||
tags: mkdir
|
tags: mkdir
|
||||||
|
|
||||||
- name: install certstore
|
- name: install certstore
|
||||||
yum:
|
yum:
|
||||||
name:
|
name:
|
||||||
- /tmp/ansible_deploy/certstore-v20.04.3989072-1.el7.x86_64.rpm
|
- /tmp/ansible_deploy/certstore-2.1.2.20200923.a36312c-1.el7.x86_64.rpm
|
||||||
state: present
|
state: present
|
||||||
|
|
||||||
- name: template certstore configure file
|
- name: template certstore configure file
|
||||||
template:
|
template:
|
||||||
src: "{{ role_path }}/templates/cert_store.ini.j2"
|
src: "{{ role_path }}/templates/cert_store.ini.j2"
|
||||||
dest: /home/tsg/certstore/conf/cert_store.ini
|
dest: /opt/tsg/certstore/conf/cert_store.ini
|
||||||
|
|
||||||
|
- name: template certstore zlog file
|
||||||
|
template:
|
||||||
|
src: "{{ role_path }}/templates/zlog.conf.j2"
|
||||||
|
dest: /opt/tsg/certstore/conf/zlog.conf
|
||||||
|
|
||||||
- name: "start certstore"
|
- name: "start certstore"
|
||||||
systemd:
|
systemd:
|
||||||
|
|||||||
@@ -1,9 +1,15 @@
|
|||||||
[SYSTEM]
|
[SYSTEM]
|
||||||
#1:print on screen, 0:don't
|
#1:print on screen, 0:don't
|
||||||
DEBUG_SWITCH = 1
|
DEBUG_SWITCH = 1
|
||||||
#10:DEBUG, 20:INFO, 30:FATAL
|
RUN_LOG_PATH = "conf/zlog.conf"
|
||||||
RUN_LOG_LEVEL = 10
|
|
||||||
RUN_LOG_PATH = ./logs
|
[breakpad]
|
||||||
|
disable_coredump=0
|
||||||
|
enable_breakpad=1
|
||||||
|
breakpad_minidump_dir=/tmp/certstore/crashreport
|
||||||
|
enable_breakpad_upload=0
|
||||||
|
breakpad_upload_url= {{ breakpad_upload_url }}
|
||||||
|
|
||||||
[CONFIG]
|
[CONFIG]
|
||||||
#Number of running threads
|
#Number of running threads
|
||||||
thread-nu = 4
|
thread-nu = 4
|
||||||
@@ -14,8 +20,9 @@ expire_after = 30
|
|||||||
#Local default root certificate path
|
#Local default root certificate path
|
||||||
local_debug = 1
|
local_debug = 1
|
||||||
ca_path = ./cert/tango-ca-v3-trust-ca.pem
|
ca_path = ./cert/tango-ca-v3-trust-ca.pem
|
||||||
untrusted_ca_path = ./cert/mesalab-ca-untrust.pem
|
untrusted_ca_path = ./cert/tango-ca-v3-untrust-ca.pem
|
||||||
[NTC_MAAT]
|
|
||||||
|
[MAAT]
|
||||||
#Configure the load mode,
|
#Configure the load mode,
|
||||||
#0: using the configuration distribution network
|
#0: using the configuration distribution network
|
||||||
#1: using local json
|
#1: using local json
|
||||||
@@ -31,15 +38,21 @@ inc_cfg_dir=./rule/inc/index
|
|||||||
full_cfg_dir=./rule/full/index
|
full_cfg_dir=./rule/full/index
|
||||||
#Json file path when json schema is used
|
#Json file path when json schema is used
|
||||||
pxy_obj_keyring=./conf/pxy_obj_keyring.json
|
pxy_obj_keyring=./conf/pxy_obj_keyring.json
|
||||||
|
|
||||||
[LIBEVENT]
|
[LIBEVENT]
|
||||||
#Local monitor port number, default is 9991
|
#Local monitor port number, default is 9991
|
||||||
port = 9991
|
port = 9991
|
||||||
|
|
||||||
[CERTSTORE_REDIS]
|
[CERTSTORE_REDIS]
|
||||||
#The Redis server IP address and port number where the certificate is stored locally
|
#The Redis server IP address and port number where the certificate is stored locally
|
||||||
ip = 127.0.0.1
|
ip = 127.0.0.1
|
||||||
port = 6379
|
port = 6379
|
||||||
|
|
||||||
[MAAT_REDIS]
|
[MAAT_REDIS]
|
||||||
#Maat monitors the Redsi server IP address and port number
|
#Maat monitors the Redsi server IP address and port number
|
||||||
ip = {{ maat_redis_server.address }}
|
ip = {{ maat_redis_server.address }}
|
||||||
port = {{ maat_redis_server.port }}
|
port = {{ maat_redis_server.port }}
|
||||||
dbindex = {{ maat_redis_server.db }}
|
dbindex = {{ maat_redis_server.db }}
|
||||||
|
[stat]
|
||||||
|
statsd_server=127.0.0.1
|
||||||
|
statsd_port=58100
|
||||||
|
|||||||
10
roles/certstore/templates/zlog.conf.j2
Normal file
10
roles/certstore/templates/zlog.conf.j2
Normal file
@@ -0,0 +1,10 @@
|
|||||||
|
[global]
|
||||||
|
default format = "%d(%c), %V, %F, %U, %m%n"
|
||||||
|
[levels]
|
||||||
|
DEBUG=10
|
||||||
|
INFO=20
|
||||||
|
FATAL=30
|
||||||
|
[rules]
|
||||||
|
*.fatal "./logs/error.log.%d(%F)";
|
||||||
|
*.{{ certstore_log_level }} "./logs/certstore.log.%d(%F)"
|
||||||
|
|
||||||
Binary file not shown.
@@ -1,13 +0,0 @@
|
|||||||
[Unit]
|
|
||||||
Description=clotho
|
|
||||||
After=network.target
|
|
||||||
After=network-online.target
|
|
||||||
Wants=network-online.target
|
|
||||||
|
|
||||||
[Service]
|
|
||||||
ExecStart=/home/mesasoft/clotho/clotho
|
|
||||||
ExecStop=killall clotho
|
|
||||||
Type=forking
|
|
||||||
|
|
||||||
[Install]
|
|
||||||
WantedBy=multi-user.target
|
|
||||||
@@ -1,29 +0,0 @@
|
|||||||
- name: "copy clotho rpm to destination server"
|
|
||||||
copy:
|
|
||||||
src: "{{ role_path }}/files/clotho-debug-1.0.0.-1.el7.x86_64.rpm"
|
|
||||||
dest: /tmp/ansible_deploy/
|
|
||||||
|
|
||||||
- name: "copy clotho.service to destination server"
|
|
||||||
copy:
|
|
||||||
src: "{{ role_path }}/files/clotho.service"
|
|
||||||
dest: /usr/lib/systemd/system
|
|
||||||
mode: 0755
|
|
||||||
|
|
||||||
- name: "install clotho rpm from localhost"
|
|
||||||
yum:
|
|
||||||
name:
|
|
||||||
- /tmp/ansible_deploy/clotho-debug-1.0.0.-1.el7.x86_64.rpm
|
|
||||||
state: present
|
|
||||||
|
|
||||||
- name: "Template the clotho.conf"
|
|
||||||
template:
|
|
||||||
src: "{{ role_path }}/templates/clotho.conf.j2"
|
|
||||||
dest: /home/mesasoft/clotho/conf/clotho.conf
|
|
||||||
tags: template
|
|
||||||
|
|
||||||
- name: "start clotho"
|
|
||||||
systemd:
|
|
||||||
name: clotho.service
|
|
||||||
enabled: yes
|
|
||||||
daemon_reload: yes
|
|
||||||
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
[KAFKA]
|
|
||||||
BROKER_LIST={{ log_kafkabrokers.address }}
|
|
||||||
|
|
||||||
[SYSTEM]
|
|
||||||
{% if tsg_access_type == 0 %}
|
|
||||||
NIC_NAME={{ tsg_tun_mode.ethname }}
|
|
||||||
{% else %}
|
|
||||||
NIC_NAME={{ nic_mgr.name }}
|
|
||||||
{% endif %}
|
|
||||||
LOG_LEVEL=10
|
|
||||||
LOG_PATH=log/clotho
|
|
||||||
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
BIN
roles/firewall/files/dns-2.0.9.b639626-2.el7.x86_64.rpm
Normal file
BIN
roles/firewall/files/dns-2.0.9.b639626-2.el7.x86_64.rpm
Normal file
Binary file not shown.
Binary file not shown.
BIN
roles/firewall/files/ftp-1.0.8.13d5fda-2.el7.x86_64.rpm
Normal file
BIN
roles/firewall/files/ftp-1.0.8.13d5fda-2.el7.x86_64.rpm
Normal file
Binary file not shown.
BIN
roles/firewall/files/fw_dns_plug-3.0.2.dab58fa-2.el7.x86_64.rpm
Normal file
BIN
roles/firewall/files/fw_dns_plug-3.0.2.dab58fa-2.el7.x86_64.rpm
Normal file
Binary file not shown.
Binary file not shown.
Binary file not shown.
BIN
roles/firewall/files/fw_ftp_plug-3.0.1.0a78573-2.el7.x86_64.rpm
Normal file
BIN
roles/firewall/files/fw_ftp_plug-3.0.1.0a78573-2.el7.x86_64.rpm
Normal file
Binary file not shown.
Binary file not shown.
BIN
roles/firewall/files/fw_http_plug-3.0.1.0c7e082-2.el7.x86_64.rpm
Normal file
BIN
roles/firewall/files/fw_http_plug-3.0.1.0c7e082-2.el7.x86_64.rpm
Normal file
Binary file not shown.
Binary file not shown.
BIN
roles/firewall/files/fw_mail_plug-3.0.1.02465eb-2.el7.x86_64.rpm
Normal file
BIN
roles/firewall/files/fw_mail_plug-3.0.1.02465eb-2.el7.x86_64.rpm
Normal file
Binary file not shown.
BIN
roles/firewall/files/fw_quic_plug-3.0.1.b790ee1-2.el7.x86_64.rpm
Normal file
BIN
roles/firewall/files/fw_quic_plug-3.0.1.b790ee1-2.el7.x86_64.rpm
Normal file
Binary file not shown.
Binary file not shown.
BIN
roles/firewall/files/fw_ssl_plug-3.0.4.a0b19ee-2.el7.x86_64.rpm
Normal file
BIN
roles/firewall/files/fw_ssl_plug-3.0.4.a0b19ee-2.el7.x86_64.rpm
Normal file
Binary file not shown.
Binary file not shown.
BIN
roles/firewall/files/http-2.0.5.c61ad9a-2.el7.x86_64.rpm
Normal file
BIN
roles/firewall/files/http-2.0.5.c61ad9a-2.el7.x86_64.rpm
Normal file
Binary file not shown.
Binary file not shown.
BIN
roles/firewall/files/mail-1.0.9.c1d3bde-2.el7.x86_64.rpm
Normal file
BIN
roles/firewall/files/mail-1.0.9.c1d3bde-2.el7.x86_64.rpm
Normal file
Binary file not shown.
BIN
roles/firewall/files/quic-1.1.10.c2b90a0-2.el7.x86_64.rpm
Normal file
BIN
roles/firewall/files/quic-1.1.10.c2b90a0-2.el7.x86_64.rpm
Normal file
Binary file not shown.
BIN
roles/firewall/files/radius-1.0.2.7bddf74-2.el7.x86_64.rpm
Normal file
BIN
roles/firewall/files/radius-1.0.2.7bddf74-2.el7.x86_64.rpm
Normal file
Binary file not shown.
Binary file not shown.
BIN
roles/firewall/files/ssl-1.0.9.69f3742-2.el7.x86_64.rpm
Normal file
BIN
roles/firewall/files/ssl-1.0.9.69f3742-2.el7.x86_64.rpm
Normal file
Binary file not shown.
Binary file not shown.
Binary file not shown.
BIN
roles/firewall/files/tsg_master-3.3.0.5fcfdae-2.el7.x86_64.rpm
Normal file
BIN
roles/firewall/files/tsg_master-3.3.0.5fcfdae-2.el7.x86_64.rpm
Normal file
Binary file not shown.
@@ -8,21 +8,24 @@
|
|||||||
yum:
|
yum:
|
||||||
name: "{{ fw_packages }}"
|
name: "{{ fw_packages }}"
|
||||||
state: present
|
state: present
|
||||||
|
skip_broken: yes
|
||||||
vars:
|
vars:
|
||||||
fw_packages:
|
fw_packages:
|
||||||
- /tmp/ansible_deploy/dns-2.0.2.5effe72-2.el7.x86_64.rpm
|
- /tmp/ansible_deploy/capture_packet_plug-3.0.4.42574b7-2.el7.x86_64.rpm
|
||||||
- /tmp/ansible_deploy/ftp-1.0.4.5d3a283-2.el7.x86_64.rpm
|
- /tmp/ansible_deploy/conn_telemetry-1.0.2.8d6da43-2.el7.x86_64.rpm
|
||||||
- /tmp/ansible_deploy/http-2.0.1.e8f12ee-2.el7.x86_64.rpm
|
- /tmp/ansible_deploy/dns-2.0.9.b639626-2.el7.x86_64.rpm
|
||||||
- /tmp/ansible_deploy/mail-1.0.3.cbc6034-2.el7.x86_64.rpm
|
- /tmp/ansible_deploy/ftp-1.0.8.13d5fda-2.el7.x86_64.rpm
|
||||||
- /tmp/ansible_deploy/ssl-1.0.0.73e5273-2.el7.x86_64.rpm
|
- /tmp/ansible_deploy/fw_dns_plug-3.0.2.dab58fa-2.el7.x86_64.rpm
|
||||||
- /tmp/ansible_deploy/tsg_conn_record-1.0.0.2155660-1.el7.centos.x86_64.rpm
|
- /tmp/ansible_deploy/fw_ftp_plug-3.0.1.0a78573-2.el7.x86_64.rpm
|
||||||
- /tmp/ansible_deploy/fw_dns_plug-debug-1.0.3.ea8e0f6-1.el7.centos.x86_64.rpm
|
- /tmp/ansible_deploy/fw_http_plug-3.0.1.0c7e082-2.el7.x86_64.rpm
|
||||||
- /tmp/ansible_deploy/fw_ftp_plug-1.0.3.73372b5-2.el7.x86_64.rpm
|
- /tmp/ansible_deploy/fw_mail_plug-3.0.1.02465eb-2.el7.x86_64.rpm
|
||||||
- /tmp/ansible_deploy/fw_ssl_plug-1.0.3.30fcf35-2.el7.x86_64.rpm
|
- /tmp/ansible_deploy/fw_quic_plug-3.0.1.b790ee1-2.el7.x86_64.rpm
|
||||||
- /tmp/ansible_deploy/fw_mail_plug-1.0.4.03e1b53-2.el7.x86_64.rpm
|
- /tmp/ansible_deploy/fw_ssl_plug-3.0.4.a0b19ee-2.el7.x86_64.rpm
|
||||||
- /tmp/ansible_deploy/fw_http_plug-1.0.14.2f3b011-2.el7.x86_64.rpm
|
- /tmp/ansible_deploy/http-2.0.5.c61ad9a-2.el7.x86_64.rpm
|
||||||
- /tmp/ansible_deploy/capture_packet_plug-debug-1.0.0.-1.el7.x86_64.rpm
|
- /tmp/ansible_deploy/mail-1.0.9.c1d3bde-2.el7.x86_64.rpm
|
||||||
- /tmp/ansible_deploy/clotho-debug-1.0.0.-1.el7.x86_64.rpm
|
- /tmp/ansible_deploy/quic-1.1.10.c2b90a0-2.el7.x86_64.rpm
|
||||||
|
- /tmp/ansible_deploy/ssl-1.0.9.69f3742-2.el7.x86_64.rpm
|
||||||
|
- /tmp/ansible_deploy/tsg_conn_sketch-2.0.6.abb4f4d-2.el7.x86_64.rpm
|
||||||
|
|
||||||
- name: "Template the tsgconf/main.conf"
|
- name: "Template the tsgconf/main.conf"
|
||||||
template:
|
template:
|
||||||
|
|||||||
@@ -15,15 +15,11 @@ INC_CFG_DIR=capture_packet_rule/inc/index/
|
|||||||
FULL_CFG_DIR=capture_packet_rule/full/index/
|
FULL_CFG_DIR=capture_packet_rule/full/index/
|
||||||
|
|
||||||
[LOG]
|
[LOG]
|
||||||
{% if tsg_access_type == 0 %}
|
|
||||||
NIC_NAME={{ tsg_tun_mode.ethname }}
|
|
||||||
{% else %}
|
|
||||||
NIC_NAME={{ nic_mgr.name }}
|
NIC_NAME={{ nic_mgr.name }}
|
||||||
{% endif %}
|
|
||||||
BROKER_LIST={{ log_kafkabrokers.address }}
|
BROKER_LIST={{ log_kafkabrokers.address }}
|
||||||
FIELD_FILE=conf/capture_packet_log_field.conf
|
FIELD_FILE=conf/capture_packet_log_field.conf
|
||||||
|
|
||||||
[SYSTEM]
|
[SYSTEM]
|
||||||
LOG_LEVEL=10
|
LOG_LEVEL={{ capture_packet_log_level }}
|
||||||
LOG_PATH=./tsglog/capture_packet_plug/capture_packet
|
LOG_PATH=./tsglog/capture_packet_plug/capture_packet
|
||||||
|
|
||||||
|
|||||||
@@ -1,4 +1,5 @@
|
|||||||
[STATIC]
|
[STATIC]
|
||||||
|
###0:location 1:json 2:redis
|
||||||
MAAT_MODE=2
|
MAAT_MODE=2
|
||||||
STAT_SWITCH=1
|
STAT_SWITCH=1
|
||||||
PERF_SWITCH=1
|
PERF_SWITCH=1
|
||||||
@@ -14,6 +15,7 @@ INC_CFG_DIR=tsgrule/inc/index/
|
|||||||
FULL_CFG_DIR=tsgrule/full/index/
|
FULL_CFG_DIR=tsgrule/full/index/
|
||||||
|
|
||||||
[DYNAMIC]
|
[DYNAMIC]
|
||||||
|
###0:location 1:json 2:redis
|
||||||
MAAT_MODE=2
|
MAAT_MODE=2
|
||||||
STAT_SWITCH=1
|
STAT_SWITCH=1
|
||||||
PERF_SWITCH=1
|
PERF_SWITCH=1
|
||||||
|
|||||||
@@ -1,55 +1,57 @@
|
|||||||
[FTP_PLUG]
|
[FTP_PLUG]
|
||||||
LOG_PATH=./tsglog/fw_ftp_plug/fw_ftp_plug
|
LOG_PATH="./tsglog/fw_ftp_plug/fw_ftp_plug"
|
||||||
LOG_LEVEL=10
|
LOG_LEVEL={{ fw_ftp_log_level }}
|
||||||
TIMEOUT=600
|
TIMEOUT=600
|
||||||
|
|
||||||
[MAIL_PLUG]
|
[MAIL_PLUG]
|
||||||
LOG_PATH=./tsglog/fw_mail_plug/fw_mail_plug
|
LOG_PATH="./tsglog/fw_mail_plug/fw_mail_plug"
|
||||||
LOG_LEVEL=10
|
LOG_LEVEL={{ fw_mail_log_level }}
|
||||||
TIMEOUT=600
|
TIMEOUT=600
|
||||||
|
|
||||||
[HTTP_PLUG]
|
[HTTP_PLUG]
|
||||||
LOG_PATH=./tsglog/fw_http_plug/fw_http_plug
|
LOG_PATH="./tsglog/fw_http_plug/fw_http_plug"
|
||||||
LOG_LEVEL=10
|
LOG_LEVEL={{ fw_http_log_level }}
|
||||||
|
|
||||||
[DNS_PLUG]
|
[DNS_PLUG]
|
||||||
LOG_PATH=./tsglog/fw_dns_plug/fw_dns_plug
|
LOG_PATH="./tsglog/fw_dns_plug/fw_dns_plug"
|
||||||
LOG_LEVEL=10
|
LOG_LEVEL={{ fw_dns_log_level }}
|
||||||
|
|
||||||
|
[QUIC_PLUG]
|
||||||
|
LOG_PATH="./tsglog/fw_quic_plug/fw_quic_plug"
|
||||||
|
LOG_LEVEL={{ fw_quic_log_level }}
|
||||||
|
|
||||||
[MAAT]
|
[MAAT]
|
||||||
PROFILE=./tsgconf/maat.conf
|
PROFILE="./tsgconf/maat.conf"
|
||||||
SUBSCRIBER_ID_TABLE=TSG_OBJ_SUBSCRIBER_ID
|
SUBSCRIBER_ID_TABLE="TSG_OBJ_SUBSCRIBER_ID"
|
||||||
CB_SUBSCRIBER_IP_TABLE=TSG_DYN_SUBSCRIBER_IP
|
CB_SUBSCRIBER_IP_TABLE="TSG_DYN_SUBSCRIBER_IP"
|
||||||
IP_ADDR_TABLE=TSG_SECURITY_ADDR
|
IP_ADDR_TABLE="TSG_SECURITY_ADDR"
|
||||||
|
|
||||||
[TSG_LOG]
|
[TSG_LOG]
|
||||||
MODE=1
|
MODE=1
|
||||||
{% if tsg_access_type == 0 %}
|
NIC_NAME="{{ nic_mgr.name }}"
|
||||||
NIC_NAME={{ tsg_tun_mode.ethname }}
|
|
||||||
{% else %}
|
|
||||||
NIC_NAME={{ nic_mgr.name }}
|
|
||||||
{% endif %}
|
|
||||||
MAX_SERVICE=1
|
MAX_SERVICE=1
|
||||||
LOG_LEVEL=10
|
LOG_LEVEL={{ tsg_log_level }}
|
||||||
LOG_PATH=./tsglog/tsglog
|
LOG_PATH="./tsglog/tsglog"
|
||||||
BROKER_LIST={{ log_kafkabrokers.address }}
|
BROKER_LIST="{{ log_kafkabrokers.address }}"
|
||||||
COMMON_FIELD_FILE=tsgconf/tsg_log_field.conf
|
COMMON_FIELD_FILE="tsgconf/tsg_log_field.conf"
|
||||||
|
|
||||||
[STATISTIC]
|
[STATISTIC]
|
||||||
CYCLE=0
|
CYCLE=5
|
||||||
TELEGRAF_PORT=8100
|
TELEGRAF_PORT=8100
|
||||||
TELEGRAF_IP=127.0.0.1
|
TELEGRAF_IP="127.0.0.1"
|
||||||
OUTPUT_PATH=./tsg_statistic.log
|
OUTPUT_PATH="./tsg_statistic.log"
|
||||||
APP_NAME=statistic
|
APP_NAME="statistic"
|
||||||
|
|
||||||
[FIELD_STAT]
|
[FIELD_STAT]
|
||||||
CYCLE=3
|
CYCLE=5
|
||||||
TELEGRAF_PORT=8125
|
TELEGRAF_PORT=8100
|
||||||
TELEGRAF_IP=127.0.0.1
|
TELEGRAF_IP="127.0.0.1"
|
||||||
OUTPUT_PATH=./tsg_stat.log
|
OUTPUT_PATH="./tsg_stat.log"
|
||||||
APP_NAME=tsg_master
|
APP_NAME="tsg_master"
|
||||||
|
|
||||||
[SYSTEM]
|
[SYSTEM]
|
||||||
LOG_LEVEL=10
|
ENTRANCE_ID={{ tsg_master_entrance_id }}
|
||||||
LOG_PATH=./tsglog/tsg_master
|
LOG_LEVEL={{ tsg_master_log_level }}
|
||||||
POLICY_PRIORITY_LABEL=POLICY_PRIORITY
|
LOG_PATH="./tsglog/tsg_master"
|
||||||
|
POLICY_PRIORITY_LABEL="POLICY_PRIORITY"
|
||||||
|
DEVICE_ID_COMMAND="hostname | awk -F'-' '{print $3}'| awk -F'ADC' '{print $2}'"
|
||||||
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
BIN
roles/framework/files/libWiredLB-2.0.5.4629165-2.el7.x86_64.rpm
Normal file
BIN
roles/framework/files/libWiredLB-2.0.5.4629165-2.el7.x86_64.rpm
Normal file
Binary file not shown.
Binary file not shown.
BIN
roles/framework/files/libcjson-1.7.10.ab2896f-2.el7.x86_64.rpm
Normal file
BIN
roles/framework/files/libcjson-1.7.10.ab2896f-2.el7.x86_64.rpm
Normal file
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
BIN
roles/framework/files/librulescan-2.2.1.1716a7b-2.el7.x86_64.rpm
Normal file
BIN
roles/framework/files/librulescan-2.2.1.1716a7b-2.el7.x86_64.rpm
Normal file
Binary file not shown.
BIN
roles/framework/files/libtsglua-1.0.8.0dbf2e6-2.el7.x86_64.rpm
Normal file
BIN
roles/framework/files/libtsglua-1.0.8.0dbf2e6-2.el7.x86_64.rpm
Normal file
Binary file not shown.
Binary file not shown.
BIN
roles/framework/files/libwiredcfg-2.0.6.67ae0ab-2.el7.x86_64.rpm
Normal file
BIN
roles/framework/files/libwiredcfg-2.0.6.67ae0ab-2.el7.x86_64.rpm
Normal file
Binary file not shown.
@@ -10,19 +10,21 @@
|
|||||||
skip_broken: yes
|
skip_broken: yes
|
||||||
vars:
|
vars:
|
||||||
packages:
|
packages:
|
||||||
- /tmp/ansible_deploy/libMESA_field_stat-1.0.1.852c2df-1.el7.x86_64.rpm
|
- /tmp/ansible_deploy/libcjson-1.7.10.ab2896f-2.el7.x86_64.rpm
|
||||||
- /tmp/ansible_deploy/libMESA_field_stat2-2.8.6.c183ed6-1.el7.x86_64.rpm
|
- /tmp/ansible_deploy/libdocumentanalyze-2.0.6.2d1abe0-2.el7.x86_64.rpm
|
||||||
- /tmp/ansible_deploy/libMESA_handle_logger-1.0.8.bd5f0ac-1.el7.x86_64.rpm
|
- /tmp/ansible_deploy/libmaatframe-3.1.3.4fbcf21-2.el7.x86_64.rpm
|
||||||
- /tmp/ansible_deploy/libMESA_htable-3.10.11.6275308-1.el7.x86_64.rpm
|
- /tmp/ansible_deploy/libMESA_field_stat-1.0.2.6d45eed-2.el7.x86_64.rpm
|
||||||
- /tmp/ansible_deploy/libMESA_prof_load-1.0.5.bf755de-1.el7.x86_64.rpm
|
- /tmp/ansible_deploy/libMESA_field_stat2-2.9.4.4e2dd78-2.el7.x86_64.rpm
|
||||||
- /tmp/ansible_deploy/libWiredLB-2.0.3.c7d131b-1.el7.x86_64.rpm
|
- /tmp/ansible_deploy/libMESA_handle_logger-2.0.7.cb4ad71-2.el7.x86_64.rpm
|
||||||
- /tmp/ansible_deploy/libcjson-1.7.8.542ad7f-1.el7.x86_64.rpm
|
- /tmp/ansible_deploy/libMESA_htable-3.10.12.cf4ccfc-2.el7.x86_64.rpm
|
||||||
- /tmp/ansible_deploy/libdocumentanalyze-2.0.4.efdfc29-1.el7.x86_64.rpm
|
- /tmp/ansible_deploy/libMESA_prof_load-1.0.6.c6da36a-2.el7.x86_64.rpm
|
||||||
- /tmp/ansible_deploy/libmaatframe-2.8.1.8729ebf-2.el7.x86_64.rpm
|
|
||||||
- /tmp/ansible_deploy/librulescan-2.1.7.c27f70d-1.el7.x86_64.rpm
|
|
||||||
- /tmp/ansible_deploy/libwiredcfg-2.0.2.7ce1eea-1.el7.x86_64.rpm
|
|
||||||
- /tmp/ansible_deploy/lz4-1.7.5-3.el7.x86_64.rpm
|
|
||||||
- /tmp/ansible_deploy/librdkafka-0.11.4-1.el7.x86_64.rpm
|
- /tmp/ansible_deploy/librdkafka-0.11.4-1.el7.x86_64.rpm
|
||||||
|
- /tmp/ansible_deploy/librulescan-2.2.1.1716a7b-2.el7.x86_64.rpm
|
||||||
|
- /tmp/ansible_deploy/libtsglua-1.0.8.0dbf2e6-2.el7.x86_64.rpm
|
||||||
|
- /tmp/ansible_deploy/libwiredcfg-2.0.6.67ae0ab-2.el7.x86_64.rpm
|
||||||
|
- /tmp/ansible_deploy/libWiredLB-2.0.5.4629165-2.el7.x86_64.rpm
|
||||||
|
- /tmp/ansible_deploy/lz4-1.7.5-3.el7.x86_64.rpm
|
||||||
|
- /tmp/ansible_deploy/libbreakpad_mini-1.0.2.a56ef00-2.el7.x86_64.rpm
|
||||||
|
|
||||||
- name: "mkdir /etc/ld.so.conf.d/"
|
- name: "mkdir /etc/ld.so.conf.d/"
|
||||||
file:
|
file:
|
||||||
|
|||||||
Binary file not shown.
8
roles/kernel-ml/files/grub
Normal file
8
roles/kernel-ml/files/grub
Normal file
@@ -0,0 +1,8 @@
|
|||||||
|
GRUB_TIMEOUT=5
|
||||||
|
GRUB_DISTRIBUTOR="$(sed 's, release .*$,,g' /etc/system-release)"
|
||||||
|
GRUB_DEFAULT=saved
|
||||||
|
GRUB_DISABLE_SUBMENU=true
|
||||||
|
GRUB_TERMINAL="serial console"
|
||||||
|
GRUB_SERIAL_COMMAND="serial --speed=115200"
|
||||||
|
GRUB_CMDLINE_LINUX="crashkernel=auto console=ttyS0,115200 intel_iommu=on iommu=pt pci=realloc,assign-busses"
|
||||||
|
GRUB_DISABLE_RECOVERY="true"
|
||||||
BIN
roles/kernel-ml/files/pkgconfig-0.27.1-4.el7.x86_64.rpm
Normal file
BIN
roles/kernel-ml/files/pkgconfig-0.27.1-4.el7.x86_64.rpm
Normal file
Binary file not shown.
BIN
roles/kernel-ml/files/zlib-devel-1.2.7-17.el7.x86_64.rpm
Normal file
BIN
roles/kernel-ml/files/zlib-devel-1.2.7-17.el7.x86_64.rpm
Normal file
Binary file not shown.
@@ -7,6 +7,9 @@
|
|||||||
- name: "install kernels-ml"
|
- name: "install kernels-ml"
|
||||||
yum:
|
yum:
|
||||||
name:
|
name:
|
||||||
|
- /tmp/ansible_deploy/pkgconfig-0.27.1-4.el7.x86_64.rpm
|
||||||
|
- /tmp/ansible_deploy/zlib-devel-1.2.7-17.el7.x86_64.rpm
|
||||||
|
- /tmp/ansible_deploy/elfutils-libelf-devel-0.168-8.el7.x86_64.rpm
|
||||||
- /tmp/ansible_deploy/kernel/kernel-ml-5.1.8-1.el7.elrepo.x86_64.rpm
|
- /tmp/ansible_deploy/kernel/kernel-ml-5.1.8-1.el7.elrepo.x86_64.rpm
|
||||||
- /tmp/ansible_deploy/kernel/kernel-ml-devel-5.1.8-1.el7.elrepo.x86_64.rpm
|
- /tmp/ansible_deploy/kernel/kernel-ml-devel-5.1.8-1.el7.elrepo.x86_64.rpm
|
||||||
- /tmp/ansible_deploy/dkms-2.7.1-1.el7.noarch.rpm
|
- /tmp/ansible_deploy/dkms-2.7.1-1.el7.noarch.rpm
|
||||||
@@ -17,6 +20,26 @@
|
|||||||
command: /usr/sbin/grub2-set-default 0
|
command: /usr/sbin/grub2-set-default 0
|
||||||
when: t_kernel_ml.changed
|
when: t_kernel_ml.changed
|
||||||
|
|
||||||
- name: "reboot"
|
- name: "copy /etc/default/grub"
|
||||||
reboot:
|
copy:
|
||||||
when: t_kernel_ml.changed
|
src: "{{ role_path }}/files/grub"
|
||||||
|
dest: "/etc/default"
|
||||||
|
when:
|
||||||
|
- tsg_access_type == 4
|
||||||
|
- t_kernel_ml.changed
|
||||||
|
|
||||||
|
- name: "BIOS:grub2-mkconfig"
|
||||||
|
shell: grub2-mkconfig -o /boot/grub2/grub.cfg
|
||||||
|
when:
|
||||||
|
- tsg_access_type == 4
|
||||||
|
- t_kernel_ml.changed
|
||||||
|
|
||||||
|
- name: "UEFI:grub2-mkconfig"
|
||||||
|
shell: grub2-mkconfig -o /boot/efi/EFI/centos/grub.cfg
|
||||||
|
when:
|
||||||
|
- tsg_access_type == 4
|
||||||
|
- t_kernel_ml.changed
|
||||||
|
|
||||||
|
#- name: "reboot"
|
||||||
|
# reboot:
|
||||||
|
# when: t_kernel_ml.changed
|
||||||
|
|||||||
Binary file not shown.
BIN
roles/kni/files/kni-20.10.20201014.6d458ba-1.el7.x86_64.rpm
Normal file
BIN
roles/kni/files/kni-20.10.20201014.6d458ba-1.el7.x86_64.rpm
Normal file
Binary file not shown.
@@ -7,7 +7,7 @@
|
|||||||
- name: "install kni rpms from localhost"
|
- name: "install kni rpms from localhost"
|
||||||
yum:
|
yum:
|
||||||
name:
|
name:
|
||||||
- /tmp/ansible_deploy/kni-20.04-1.el7.x86_64.rpm
|
- /tmp/ansible_deploy/kni-20.10.20201014.6d458ba-1.el7.x86_64.rpm
|
||||||
state: present
|
state: present
|
||||||
|
|
||||||
- name: Template the kni.conf
|
- name: Template the kni.conf
|
||||||
|
|||||||
@@ -1,13 +1,9 @@
|
|||||||
[global]
|
[global]
|
||||||
log_path = ./log/kni/kni.log
|
log_path = ./log/kni/kni.log
|
||||||
log_level = {{ kni.global.log_level }}
|
log_level = {{ kni_log_level }}
|
||||||
tfe_node_count = {{ kni.global.tfe_node_count }}
|
tfe_node_count = {{ kni.global.tfe_node_count }}
|
||||||
{% if tsg_access_type == 0 %}
|
|
||||||
manage_eth = {{ tsg_tun_mode.ethname }}
|
|
||||||
{% else %}
|
|
||||||
manage_eth = {{ nic_mgr.name }}
|
manage_eth = {{ nic_mgr.name }}
|
||||||
{% endif %}
|
{% if tsg_running_type != 2 %}
|
||||||
{% if tsg_access_type == 0 %}
|
|
||||||
deploy_mode = tun
|
deploy_mode = tun
|
||||||
{% else %}
|
{% else %}
|
||||||
deploy_mode = normal
|
deploy_mode = normal
|
||||||
@@ -15,39 +11,35 @@ deploy_mode = normal
|
|||||||
tun_name = tun_kni
|
tun_name = tun_kni
|
||||||
src_mac_addr = 00:0e:c6:d6:72:c1
|
src_mac_addr = 00:0e:c6:d6:72:c1
|
||||||
dst_mac_addr = fe:65:b7:03:50:bd
|
dst_mac_addr = fe:65:b7:03:50:bd
|
||||||
{% if tsg_access_type == 0 %}
|
{% if tsg_access_type == 4 %}
|
||||||
{% else %}
|
|
||||||
[tfe0]
|
[tfe0]
|
||||||
enabled = 1
|
enabled = 1
|
||||||
|
dev_eth_symbol = {{ ATCA_data_incoming.vf1_name }}
|
||||||
|
ip_addr = 192.168.100.1
|
||||||
|
{% elif tsg_running_type == 2 %}
|
||||||
|
[tfe0]
|
||||||
|
enabled = {{ kni.tfe_nodes.tfe0_enabled }}
|
||||||
dev_eth_symbol = {{ nic_to_tfe.tfe0.name }}
|
dev_eth_symbol = {{ nic_to_tfe.tfe0.name }}
|
||||||
ip_addr = 192.168.100.2
|
ip_addr = 192.168.100.2
|
||||||
|
|
||||||
[tfe1]
|
[tfe1]
|
||||||
enabled = 1
|
enabled = {{ kni.tfe_nodes.tfe1_enabled }}
|
||||||
dev_eth_symbol = {{ nic_to_tfe.tfe1.name }}
|
dev_eth_symbol = {{ nic_to_tfe.tfe1.name }}
|
||||||
ip_addr = 192.168.100.3
|
ip_addr = 192.168.100.3
|
||||||
|
|
||||||
[tfe2]
|
[tfe2]
|
||||||
enabled = 1
|
enabled = {{ kni.tfe_nodes.tfe2_enabled }}
|
||||||
dev_eth_symbol = {{ nic_to_tfe.tfe2.name }}
|
dev_eth_symbol = {{ nic_to_tfe.tfe2.name }}
|
||||||
ip_addr = 192.168.100.4
|
ip_addr = 192.168.100.4
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
||||||
[tfe_cmsg_receiver]
|
[tfe_cmsg_receiver]
|
||||||
{% if tsg_access_type == 0 %}
|
|
||||||
listen_eth = {{ tsg_tun_mode.tun_name }}
|
|
||||||
{% else %}
|
|
||||||
listen_eth = {{ nic_inner_ctrl.name }}
|
listen_eth = {{ nic_inner_ctrl.name }}
|
||||||
{% endif %}
|
|
||||||
listen_port = 2475
|
listen_port = 2475
|
||||||
|
|
||||||
[watch_dog]
|
[watch_dog]
|
||||||
switch = {{ kni.watch_dog.switch }}
|
switch = {{ kni.watch_dog.switch }}
|
||||||
{% if tsg_access_type == 0 %}
|
|
||||||
listen_eth = {{ tsg_tun_mode.tun_name }}
|
|
||||||
{% else %}
|
|
||||||
listen_eth = {{ nic_inner_ctrl.name }}
|
listen_eth = {{ nic_inner_ctrl.name }}
|
||||||
{% endif %}
|
|
||||||
listen_port = 2476
|
listen_port = 2476
|
||||||
keepalive_idle = 2
|
keepalive_idle = 2
|
||||||
keepalive_intvl = 1
|
keepalive_intvl = 1
|
||||||
@@ -72,7 +64,7 @@ mho_hash_max_element_num = 2560000
|
|||||||
mho_expire_time = 30
|
mho_expire_time = 30
|
||||||
mho_eliminate_type = LRU
|
mho_eliminate_type = LRU
|
||||||
|
|
||||||
//per thread
|
#per thread
|
||||||
[tuple2stream_htable]
|
[tuple2stream_htable]
|
||||||
mho_screen_print_ctrl = 0
|
mho_screen_print_ctrl = 0
|
||||||
mho_thread_safe = 0
|
mho_thread_safe = 0
|
||||||
@@ -83,9 +75,70 @@ mho_expire_time = 0
|
|||||||
mho_eliminate_type = LRU
|
mho_eliminate_type = LRU
|
||||||
|
|
||||||
[field_stat]
|
[field_stat]
|
||||||
remote_switch = {{ fs_remote.switch }}
|
remote_switch = 1
|
||||||
remote_ip = {{ fs_remote.address }}
|
remote_ip = 127.0.0.1
|
||||||
remote_port = {{ fs_remote.port }}
|
remote_port = 58100
|
||||||
local_path = ./fs2_kni.status
|
local_path = ./fs2_kni.status
|
||||||
stat_cycle = 1
|
stat_cycle = 1
|
||||||
print_mode = 1
|
print_mode = 1
|
||||||
|
# 1:FS_OUTPUT_STATSD; 2:FS_OUTPUT_INFLUX_LINE
|
||||||
|
statsd_format = 2
|
||||||
|
APP_NAME = fs2_kni
|
||||||
|
|
||||||
|
#self test Shunt rules security policy id
|
||||||
|
[tsg_diagnose]
|
||||||
|
enabled = 1
|
||||||
|
security_policy_id = 3,10
|
||||||
|
|
||||||
|
|
||||||
|
[ssl_dynamic_bypass]
|
||||||
|
enabled = 1
|
||||||
|
|
||||||
|
#kni dynamic bypass
|
||||||
|
[traceid2sslinfo_htable]
|
||||||
|
mho_screen_print_ctrl = 0
|
||||||
|
mho_thread_safe = 1
|
||||||
|
mho_mutex_num = 160
|
||||||
|
mho_hash_slot_size = 80000
|
||||||
|
mho_hash_max_element_num = 320000
|
||||||
|
mho_expire_time = 300
|
||||||
|
mho_eliminate_type = FIFO
|
||||||
|
|
||||||
|
[sslinfo2bypass_htable]
|
||||||
|
mho_screen_print_ctrl = 0
|
||||||
|
mho_thread_safe = 1
|
||||||
|
mho_mutex_num = 160
|
||||||
|
mho_hash_slot_size = 640000
|
||||||
|
mho_hash_max_element_num = 2560000
|
||||||
|
mho_expire_time = 300
|
||||||
|
mho_eliminate_type = FIFO
|
||||||
|
|
||||||
|
[proxy_tcp_option]
|
||||||
|
enabled = 1
|
||||||
|
maat_table_compile = PXY_TCP_OPTION_COMPILE
|
||||||
|
maat_table_addr = PXY_TCP_OPTION_ADDR
|
||||||
|
maat_table_fqdn = PXY_TCP_OPTION_SERVER_FQDN
|
||||||
|
enable_override = 0
|
||||||
|
client_tcp_maxseg_enable = 0
|
||||||
|
client_tcp_maxseg = 1460
|
||||||
|
client_tcp_nodelay = 1
|
||||||
|
client_tcp_ttl = 70
|
||||||
|
client_tcp_keepalive_enable = 1
|
||||||
|
client_tcp_keepalive_keepcnt = 8
|
||||||
|
client_tcp_keepalive_keepidle = 30
|
||||||
|
client_tcp_keepalive_keepintvl = 15
|
||||||
|
client_tcp_user_timeout = 600
|
||||||
|
server_tcp_maxseg_enable = 0
|
||||||
|
server_tcp_maxseg = 1460
|
||||||
|
server_tcp_nodelay = 1
|
||||||
|
server_tcp_ttl = 75
|
||||||
|
server_tcp_keepalive_enable = 1
|
||||||
|
server_tcp_keepalive_keepcnt = 8
|
||||||
|
server_tcp_keepalive_keepidle = 30
|
||||||
|
server_tcp_keepalive_keepintvl = 15
|
||||||
|
server_tcp_user_timeout = 600
|
||||||
|
bypass_duplicated_packet = 0
|
||||||
|
tcp_passthrough = 0
|
||||||
|
|
||||||
|
[share_session_attribute]
|
||||||
|
SESSION_ATTRIBUTE_LABEL=TSG_MASTER_INTERNAL_LABEL
|
||||||
|
|||||||
BIN
roles/mrzcpd/files/mrzcpd-4.3.19.f936069-1.el7.x86_64.rpm → roles/mrzcpd/files/mrzcpd-4.3.28.2d13de4-1.el7.x86_64.rpm
Executable file → Normal file
BIN
roles/mrzcpd/files/mrzcpd-4.3.19.f936069-1.el7.x86_64.rpm → roles/mrzcpd/files/mrzcpd-4.3.28.2d13de4-1.el7.x86_64.rpm
Executable file → Normal file
Binary file not shown.
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user