5 # Copyright:: 2013, OpenStreetMap Foundation
 
   7 # Licensed under the Apache License, Version 2.0 (the "License");
 
   8 # you may not use this file except in compliance with the License.
 
   9 # You may obtain a copy of the License at
 
  11 #     https://www.apache.org/licenses/LICENSE-2.0
 
  13 # Unless required by applicable law or agreed to in writing, software
 
  14 # distributed under the License is distributed on an "AS IS" BASIS,
 
  15 # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 
  16 # See the License for the specific language governing permissions and
 
  17 # limitations under the License.
 
  22 include_recipe "accounts"
 
  24 include_recipe "osmosis"
 
  26 include_recipe "tools"
 
  28 db_passwords = data_bag_item("db", "passwords")
 
  30 ## Install required packages
 
  43   gem_binary node[:ruby][:gem]
 
  46 ## Build preload library to flush files
 
  48 remote_directory "/opt/flush" do
 
  58 execute "/opt/flush/Makefile" do
 
  64   subscribes :run, "remote_directory[/opt/flush]"
 
  69 remote_directory "/usr/local/bin" do
 
  70   source "replication-bin"
 
  79 template "/usr/local/bin/users-agreed" do
 
  80   source "users-agreed.erb"
 
  86 template "/usr/local/bin/users-deleted" do
 
  87   source "users-deleted.erb"
 
  93 ## Published deleted users directory
 
  95 remote_directory "/store/planet/users_deleted" do
 
  96   source "users_deleted"
 
 105 ## Published replication directory
 
 107 remote_directory "/store/planet/replication" do
 
 108   source "replication-cgi"
 
 117 ## Configuration directory
 
 119 directory "/etc/replication" do
 
 125 ## Transient state directory
 
 127 systemd_tmpfile "/run/replication" do
 
 134 ## Persistent state directory
 
 136 directory "/var/lib/replication" do
 
 142 ## Temporary directory
 
 144 directory "/store/replication" do
 
 152 template "/etc/replication/users-agreed.conf" do
 
 153   source "users-agreed.conf.erb"
 
 157   variables :password => db_passwords["planetdiff"]
 
 160 systemd_service "users-agreed" do
 
 161   description "Update list of users accepting CTs"
 
 163   exec_start "/usr/local/bin/users-agreed"
 
 166   protect_system "full"
 
 168   restrict_address_families %w[AF_INET AF_INET6]
 
 169   no_new_privileges true
 
 172 systemd_timer "users-agreed" do
 
 173   description "Update list of users accepting CTs"
 
 177 systemd_service "users-deleted" do
 
 178   description "Update list of deleted users"
 
 180   exec_start "/usr/local/bin/users-deleted"
 
 183   protect_system "full"
 
 185   restrict_address_families %w[AF_INET AF_INET6]
 
 186   no_new_privileges true
 
 189 systemd_timer "users-deleted" do
 
 190   description "Update list of deleted users"
 
 194 ## Changeset replication
 
 196 directory "/store/planet/replication/changesets" do
 
 202 template "/etc/replication/changesets.conf" do
 
 203   source "changesets.conf.erb"
 
 207   variables :password => db_passwords["planetdiff"]
 
 210 systemd_service "replication-changesets" do
 
 211   description "Changesets replication"
 
 213   exec_start "/usr/local/bin/replicate-changesets /etc/replication/changesets.conf"
 
 216   protect_system "full"
 
 218   restrict_address_families %w[AF_INET AF_INET6]
 
 219   no_new_privileges true
 
 222 systemd_timer "replication-changesets" do
 
 223   description "Changesets replication"
 
 225   on_unit_active_sec 60
 
 229 ## Minutely replication
 
 231 directory "/store/planet/replication/minute" do
 
 237 directory "/var/lib/replication/minute" do
 
 243 directory "/store/replication/minute" do
 
 251     "host" => node[:web][:database_host],
 
 252     "dbname" => "openstreetmap",
 
 253     "user" => "planetdiff",
 
 254     "password" => db_passwords["planetdiff"],
 
 255     "replication_slot" => "osmdbt"
 
 257   "log_dir" => "/var/lib/replication/minute",
 
 258   "changes_dir" => "/store/planet/replication/minute",
 
 259   "tmp_dir" => "/store/replication/minute",
 
 260   "run_dir" => "/run/replication"
 
 263 file "/etc/replication/osmdbt-config.yaml" do
 
 267   content YAML.dump(osmdbt_config)
 
 270 systemd_service "replication-minutely" do
 
 271   description "Minutely replication"
 
 273   working_directory "/etc/replication"
 
 274   exec_start "/usr/local/bin/replicate-minute"
 
 277   protect_system "full"
 
 279   restrict_address_families %w[AF_INET AF_INET6]
 
 280   no_new_privileges true
 
 283 systemd_timer "replication-minutely" do
 
 284   description "Minutely replication"
 
 286   on_unit_active_sec 60
 
 290 ## Hourly replication
 
 292 directory "/store/planet/replication/hour" do
 
 298 directory "/var/lib/replication/hour" do
 
 304 link "/var/lib/replication/hour/data" do
 
 305   to "/store/planet/replication/hour"
 
 308 template "/var/lib/replication/hour/configuration.txt" do
 
 309   source "replication.config.erb"
 
 313   variables :base => "minute", :interval => 3600
 
 316 systemd_service "replication-hourly" do
 
 317   description "Hourly replication"
 
 319   exec_start "/usr/local/bin/osmosis -q --merge-replication-files workingDirectory=/var/lib/replication/hour"
 
 320   environment "LD_PRELOAD" => "/opt/flush/flush.so"
 
 323   protect_system "full"
 
 325   restrict_address_families %w[AF_INET AF_INET6]
 
 326   no_new_privileges true
 
 329 systemd_timer "replication-hourly" do
 
 330   description "Daily replication"
 
 331   on_calendar "*-*-* *:02/15:00"
 
 336 directory "/store/planet/replication/day" do
 
 342 directory "/var/lib/replication/day" do
 
 348 link "/var/lib/replication/day/data" do
 
 349   to "/store/planet/replication/day"
 
 352 template "/var/lib/replication/day/configuration.txt" do
 
 353   source "replication.config.erb"
 
 357   variables :base => "hour", :interval => 86400
 
 360 systemd_service "replication-daily" do
 
 361   description "Daily replication"
 
 363   exec_start "/usr/local/bin/osmosis -q --merge-replication-files workingDirectory=/var/lib/replication/day"
 
 364   environment "LD_PRELOAD" => "/opt/flush/flush.so"
 
 367   protect_system "full"
 
 369   restrict_address_families %w[AF_INET AF_INET6]
 
 370   no_new_privileges true
 
 373 systemd_timer "replication-daily" do
 
 374   description "Daily replication"
 
 375   on_calendar "*-*-* *:02/15:00"
 
 378 ## Replication cleanup
 
 380 systemd_service "replication-cleanup" do
 
 381   description "Cleanup replication"
 
 383   exec_start "/usr/local/bin/replicate-cleanup"
 
 387   protect_system "full"
 
 389   no_new_privileges true
 
 392 systemd_timer "replication-cleanup" do
 
 393   description "Cleanup replication"
 
 395   on_unit_active_sec 86400
 
 399 ## Enable/disable feeds
 
 401 if node[:planet][:replication] == "enabled"
 
 402   service "users-agreed.timer" do
 
 403     action [:enable, :start]
 
 406   service "users-deleted.timer" do
 
 407     action [:enable, :start]
 
 410   service "replication-changesets.timer" do
 
 411     action [:enable, :start]
 
 414   service "replication-minutely.timer" do
 
 415     action [:enable, :start]
 
 418   service "replication-hourly.timer" do
 
 419     action [:enable, :start]
 
 422   service "replication-daily.timer" do
 
 423     action [:enable, :start]
 
 426   service "replication-cleanup.timer" do
 
 427     action [:enable, :start]
 
 430   service "users-agreed.timer" do
 
 431     action [:stop, :disable]
 
 434   service "users-deleted.timer" do
 
 435     action [:stop, :disable]
 
 438   service "replication-changesets.timer" do
 
 439     action [:stop, :disable]
 
 442   service "replication-minutely.timer" do
 
 443     action [:stop, :disable]
 
 446   service "replication-hourly.timer" do
 
 447     action [:stop, :disable]
 
 450   service "replication-daily.timer" do
 
 451     action [:stop, :disable]
 
 454   service "replication-cleanup.timer" do
 
 455     action [:stop, :disable]