5 # Copyright:: 2013, OpenStreetMap Foundation
 
   7 # Licensed under the Apache License, Version 2.0 (the "License");
 
   8 # you may not use this file except in compliance with the License.
 
   9 # You may obtain a copy of the License at
 
  11 #     https://www.apache.org/licenses/LICENSE-2.0
 
  13 # Unless required by applicable law or agreed to in writing, software
 
  14 # distributed under the License is distributed on an "AS IS" BASIS,
 
  15 # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 
  16 # See the License for the specific language governing permissions and
 
  17 # limitations under the License.
 
  22 include_recipe "accounts"
 
  24 include_recipe "osmosis"
 
  26 include_recipe "tools"
 
  28 db_passwords = data_bag_item("db", "passwords")
 
  30 ## Install required packages
 
  43   gem_binary node[:ruby][:gem]
 
  46 ## Build preload library to flush files
 
  48 remote_directory "/opt/flush" do
 
  58 execute "/opt/flush/Makefile" do
 
  64   subscribes :run, "remote_directory[/opt/flush]"
 
  69 remote_directory "/usr/local/bin" do
 
  70   source "replication-bin"
 
  79 template "/usr/local/bin/users-agreed" do
 
  80   source "users-agreed.erb"
 
  86 template "/usr/local/bin/users-deleted" do
 
  87   source "users-deleted.erb"
 
  93 ## Published deleted users directory
 
  95 remote_directory "/store/planet/users_deleted" do
 
  96   source "users_deleted"
 
 105 ## Published replication directory
 
 107 remote_directory "/store/planet/replication" do
 
 108   source "replication-cgi"
 
 117 ## Configuration directory
 
 119 directory "/etc/replication" do
 
 125 ## Transient state directory
 
 127 systemd_tmpfile "/run/replication" do
 
 134 ## Persistent state directory
 
 136 directory "/var/lib/replication" do
 
 142 ## Temporary directory
 
 144 directory "/store/replication" do
 
 152 template "/etc/replication/users-agreed.conf" do
 
 153   source "users-agreed.conf.erb"
 
 157   variables :password => db_passwords["planetdiff"]
 
 160 systemd_service "users-agreed" do
 
 161   description "Update list of users accepting CTs"
 
 163   exec_start "/usr/local/bin/users-agreed"
 
 167   protect_system "full"
 
 169   restrict_address_families %w[AF_INET AF_INET6]
 
 170   no_new_privileges true
 
 173 systemd_timer "users-agreed" do
 
 174   description "Update list of users accepting CTs"
 
 178 systemd_service "users-deleted" do
 
 179   description "Update list of deleted users"
 
 181   exec_start "/usr/local/bin/users-deleted"
 
 185   protect_system "full"
 
 187   restrict_address_families %w[AF_INET AF_INET6]
 
 188   no_new_privileges true
 
 191 systemd_timer "users-deleted" do
 
 192   description "Update list of deleted users"
 
 196 ## Changeset replication
 
 198 directory "/store/planet/replication/changesets" do
 
 204 template "/etc/replication/changesets.conf" do
 
 205   source "changesets.conf.erb"
 
 209   variables :password => db_passwords["planetdiff"]
 
 212 systemd_service "replication-changesets" do
 
 213   description "Changesets replication"
 
 215   exec_start "/usr/local/bin/replicate-changesets /etc/replication/changesets.conf"
 
 218   protect_system "full"
 
 220   restrict_address_families %w[AF_INET AF_INET6]
 
 221   no_new_privileges true
 
 224 systemd_timer "replication-changesets" do
 
 225   description "Changesets replication"
 
 227   on_unit_active_sec 60
 
 231 ## Minutely replication
 
 233 directory "/store/planet/replication/minute" do
 
 239 directory "/var/lib/replication/minute" do
 
 245 directory "/store/replication/minute" do
 
 253     "host" => node[:web][:database_host],
 
 254     "dbname" => "openstreetmap",
 
 255     "user" => "planetdiff",
 
 256     "password" => db_passwords["planetdiff"],
 
 257     "replication_slot" => "osmdbt"
 
 259   "log_dir" => "/var/lib/replication/minute",
 
 260   "changes_dir" => "/store/planet/replication/minute",
 
 261   "tmp_dir" => "/store/replication/minute",
 
 262   "run_dir" => "/run/replication"
 
 265 file "/etc/replication/osmdbt-config.yaml" do
 
 269   content YAML.dump(osmdbt_config)
 
 272 systemd_service "replication-minutely" do
 
 273   description "Minutely replication"
 
 275   working_directory "/etc/replication"
 
 276   exec_start "/usr/local/bin/replicate-minute"
 
 279   protect_system "full"
 
 281   restrict_address_families %w[AF_INET AF_INET6]
 
 282   no_new_privileges true
 
 285 systemd_timer "replication-minutely" do
 
 286   description "Minutely replication"
 
 288   on_unit_active_sec 60
 
 292 ## Hourly replication
 
 294 directory "/store/planet/replication/hour" do
 
 300 directory "/var/lib/replication/hour" do
 
 306 link "/var/lib/replication/hour/data" do
 
 307   to "/store/planet/replication/hour"
 
 310 template "/var/lib/replication/hour/configuration.txt" do
 
 311   source "replication.config.erb"
 
 315   variables :base => "minute", :interval => 3600
 
 318 systemd_service "replication-hourly" do
 
 319   description "Hourly replication"
 
 321   exec_start "/usr/local/bin/osmosis -q --merge-replication-files workingDirectory=/var/lib/replication/hour"
 
 322   environment "LD_PRELOAD" => "/opt/flush/flush.so"
 
 325   protect_system "full"
 
 327   restrict_address_families %w[AF_INET AF_INET6]
 
 328   no_new_privileges true
 
 331 systemd_timer "replication-hourly" do
 
 332   description "Daily replication"
 
 333   on_calendar "*-*-* *:02/15:00"
 
 338 directory "/store/planet/replication/day" do
 
 344 directory "/var/lib/replication/day" do
 
 350 link "/var/lib/replication/day/data" do
 
 351   to "/store/planet/replication/day"
 
 354 template "/var/lib/replication/day/configuration.txt" do
 
 355   source "replication.config.erb"
 
 359   variables :base => "hour", :interval => 86400
 
 362 systemd_service "replication-daily" do
 
 363   description "Daily replication"
 
 365   exec_start "/usr/local/bin/osmosis -q --merge-replication-files workingDirectory=/var/lib/replication/day"
 
 366   environment "LD_PRELOAD" => "/opt/flush/flush.so"
 
 369   protect_system "full"
 
 371   restrict_address_families %w[AF_INET AF_INET6]
 
 372   no_new_privileges true
 
 375 systemd_timer "replication-daily" do
 
 376   description "Daily replication"
 
 377   on_calendar "*-*-* *:02/15:00"
 
 380 ## Replication cleanup
 
 382 systemd_service "replication-cleanup" do
 
 383   description "Cleanup replication"
 
 385   exec_start "/usr/local/bin/replicate-cleanup"
 
 389   protect_system "full"
 
 391   no_new_privileges true
 
 394 systemd_timer "replication-cleanup" do
 
 395   description "Cleanup replication"
 
 397   on_unit_active_sec 86400
 
 401 ## Enable/disable feeds
 
 403 if node[:planet][:replication] == "enabled"
 
 404   service "users-agreed.timer" do
 
 405     action [:enable, :start]
 
 408   service "users-deleted.timer" do
 
 409     action [:enable, :start]
 
 412   service "replication-changesets.timer" do
 
 413     action [:enable, :start]
 
 416   service "replication-minutely.timer" do
 
 417     action [:enable, :start]
 
 420   service "replication-hourly.timer" do
 
 421     action [:enable, :start]
 
 424   service "replication-daily.timer" do
 
 425     action [:enable, :start]
 
 428   service "replication-cleanup.timer" do
 
 429     action [:enable, :start]
 
 432   service "users-agreed.timer" do
 
 433     action [:stop, :disable]
 
 436   service "users-deleted.timer" do
 
 437     action [:stop, :disable]
 
 440   service "replication-changesets.timer" do
 
 441     action [:stop, :disable]
 
 444   service "replication-minutely.timer" do
 
 445     action [:stop, :disable]
 
 448   service "replication-hourly.timer" do
 
 449     action [:stop, :disable]
 
 452   service "replication-daily.timer" do
 
 453     action [:stop, :disable]
 
 456   service "replication-cleanup.timer" do
 
 457     action [:stop, :disable]