diff --git a/.gitignore b/.gitignore index 01db444..0ac2c8f 100644 --- a/.gitignore +++ b/.gitignore @@ -6,3 +6,10 @@ !/deploy/docker/.env.prod.example /deploy/docker/control-api/control-api.docker.yaml /rxprod-compose/.env + +# Live runtime database for the rxprod-compose control-api container. +/rxprod-compose/capi-db/ + +# Generated /graphify knowledge-graph output (viz, JSON, report, cache) — +# regenerate anytime with /graphify, never hand-edited. +/graphify-out/ diff --git a/rxprod-compose/control-api.yaml b/rxprod-compose/control-api.yaml new file mode 100644 index 0000000..c7d17fb --- /dev/null +++ b/rxprod-compose/control-api.yaml @@ -0,0 +1,102 @@ +# Control API configuration. +# +# OpenStack credentials are never set here — only the *names* of the +# environment variables to read them from. The actual values must be +# supplied by the process environment (see deploy/systemd/control-api.service +# and its EnvironmentFile=). + +server: + listen_addr: ":8081" + +database: + path: "/var/lib/cloud-ip-validator/control-api.db" + +openstack: + mode: "real" # "mock" | "real" — mock uses an in-memory + # OpenStack stand-in for local dev/testing + auth_method: "password" # "token" (default) | "password" — see below + + auth_url_env: "OS_AUTH_URL" + project_id_env: "OS_PROJECT_ID" + region_env: "OS_REGION_NAME" + interface_env: "OS_INTERFACE" # optional; empty env value defaults to "public" + + # auth_method: "token" — an admin supplies an already project-scoped + # token directly; it's used as-is for every call, never exchanged for a + # new one. Simplest option, but it can't renew itself: when the token + # expires, control-api starts failing OpenStack calls until the operator + # reissues OS_TOKEN and restarts the process. + token_env: "OS_TOKEN" + + # auth_method: "password" — the client authenticates with a normal + # Keystone username/password and automatically re-authenticates + # (mints a fresh token) whenever the current one is rejected, for as + # long as the process runs. Trade-off: a long-lived password credential + # sits in the environment file instead of a token. + username_env: "OS_USERNAME" + user_domain_name_env: "OS_USER_DOMAIN_NAME" + password_env: "OS_PASSWORD" + +orchestrator: + poll_interval_seconds: 5 + self_check_timeout_seconds: 60 + max_self_check_retries: 3 + checking_window_seconds: 120 + max_retries: 3 + lease_ttl_seconds: 180 + heartbeat_timeout_seconds: 30 + # Pause (seconds) between FIP association and the start of self-check — + # gives the OpenStack data plane time to start forwarding traffic + # through the newly attached floating IP. 0 = no pause (default). + # This is only the one-time seed value used the first time control-api + # starts against an empty database; after that it's managed at runtime + # via PUT /api/v1/admin/config/orchestrator (or the dashboard's + # /settings page) and this field is ignored. Must satisfy + # fip_settle_seconds + self_check_timeout_seconds < lease_ttl_seconds. + fip_settle_seconds: 30 + +aggregation: + missing_counts_as_fail: true + +# Validators are VMs in the service project; os_port_id is the Neutron port +# ID of each validator's primary NIC, used when associating a floating IP. +validators: + +# Inbound (prober) checks are OPTIONAL: list here only the external sites +# you actually run a `prober` on — index is any integer >= 1, no cap on +# how many slots you configure. Leave this list empty to disable inbound +# checks entirely — the overall result is then based on egress checks +# alone, and aggregation doesn't wait on any prober. A partial list (e.g. +# just index 1) only waits on that one site. +sites: + +# Outbound/egress check types the validator-agent runs, and which target +# group (below) each runs against. +check_types: + - name: "https" + enabled: true + targets: ["default-targets"] + - name: "icmp" + enabled: true + targets: ["default-targets"] + +targets: + default-targets: + - "https://hub.docker.com" + - "https://github.com" + - "https://packages.ubuntu.com" + +# Inbound checks the 3 external-site probers run directly against each +# validator's currently-assigned floating IP. Like validators/sites/targets/ +# check_types above, this is only a bootstrap seed for a fresh, empty +# database; after that it's managed at runtime via PUT +# /api/v1/admin/config/inbound-checks (or the dashboard's /settings page) +# and this field is ignored. +inbound_checks: + ports: [22] + icmp: true + +# The pool of public IPv4 addresses to validate, in the order they'll be +# processed (ip_queue.sequence). Every address here is checked through to +# the end of the list. +ip_addresses: