5 # Copyright:: 2013, OpenStreetMap Foundation
7 # Licensed under the Apache License, Version 2.0 (the "License");
8 # you may not use this file except in compliance with the License.
9 # You may obtain a copy of the License at
11 # https://www.apache.org/licenses/LICENSE-2.0
13 # Unless required by applicable law or agreed to in writing, software
14 # distributed under the License is distributed on an "AS IS" BASIS,
15 # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
16 # See the License for the specific language governing permissions and
17 # limitations under the License.
20 include_recipe "accounts"
21 include_recipe "apache"
23 include_recipe "munin"
24 include_recipe "nodejs"
25 include_recipe "postgresql"
26 include_recipe "prometheus"
27 include_recipe "python"
28 include_recipe "tools"
30 blocks = data_bag_item("tile", "blocks")
31 web_passwords = data_bag_item("web", "passwords")
35 apache_module "expires"
36 apache_module "headers"
37 apache_module "remoteip"
38 apache_module "rewrite"
40 apache_module "tile" do
44 apache_conf "renderd" do
48 ssl_certificate node[:fqdn] do
49 domains [node[:fqdn], "tile.openstreetmap.org", "render.openstreetmap.org"]
50 notifies :reload, "service[apache2]"
53 remote_file "#{Chef::Config[:file_cache_path]}/fastly-ip-list.json" do
54 source "https://api.fastly.com/public-ip-list"
59 fastlyips = JSON.parse(IO.read("#{Chef::Config[:file_cache_path]}/fastly-ip-list.json"))
61 apache_site "default" do
65 apache_site "tileserver_site" do
69 apache_site "tile.openstreetmap.org" do
71 variables :fastly => fastlyips["addresses"]
74 template "/etc/logrotate.d/apache2" do
75 source "logrotate.apache.erb"
81 directory "/srv/tile.openstreetmap.org" do
89 systemd_service "renderd" do
90 description "Mapnik rendering daemon"
91 after "postgresql.service"
92 wants "postgresql.service"
94 exec_start "/usr/bin/renderd -f"
95 runtime_directory "renderd"
101 protect_system "full"
103 no_new_privileges true
108 action [:enable, :start]
109 subscribes :restart, "systemd_service[renderd]"
112 directory "/srv/tile.openstreetmap.org/tiles" do
118 template "/etc/renderd.conf" do
119 source "renderd.conf.erb"
123 notifies :reload, "service[apache2]"
124 notifies :restart, "service[renderd]"
127 remote_directory "/srv/tile.openstreetmap.org/html" do
137 template "/srv/tile.openstreetmap.org/html/index.html" do
138 source "index.html.erb"
150 python_package "pyotp" do
162 ["NotoSansArabicUI-Regular.ttf", "NotoSansArabicUI-Bold.ttf"].each do |font|
163 remote_file "/usr/share/fonts/truetype/noto/#{font}" do
164 action :create_if_missing
165 source "https://github.com/googlei18n/noto-fonts/raw/master/hinted/#{font}"
172 directory "/srv/tile.openstreetmap.org/cgi-bin" do
178 template "/srv/tile.openstreetmap.org/cgi-bin/export" do
183 variables :blocks => blocks, :totp_key => web_passwords["totp_key"]
186 template "/srv/tile.openstreetmap.org/cgi-bin/debug" do
193 template "/etc/cron.hourly/export" do
194 source "export.cron.erb"
200 directory "/srv/tile.openstreetmap.org/data" do
206 package "mapnik-utils"
208 node[:tile][:data].each_value do |data|
210 file = "/srv/tile.openstreetmap.org/data/#{File.basename(url)}"
213 directory = "/srv/tile.openstreetmap.org/data/#{data[:directory]}"
215 directory directory do
221 directory = "/srv/tile.openstreetmap.org/data"
229 command "tar -zxf #{file} -C #{directory}"
233 elsif file =~ /\.tar\.bz2$/
238 command "tar -jxf #{file} -C #{directory}"
242 elsif file =~ /\.zip$/
247 command "unzip -qq -o #{file} -d #{directory}"
253 execute "#{file}_shapeindex" do
255 command "find #{directory} -type f -iname '*.shp' -print0 | xargs -0 --no-run-if-empty shapeindex --shape_files"
258 subscribes :run, "execute[#{file}]", :immediately
264 use_conditional_get true
267 action :create_if_missing
275 notifies :run, "execute[#{file}]", :immediately
276 notifies :restart, "service[renderd]"
280 nodejs_package "carto"
282 systemd_service "update-lowzoom@" do
283 description "Low zoom tile update service for %i layer"
284 conflicts "render-lowzoom.service"
286 exec_start "/bin/bash /usr/local/bin/update-lowzoom-%i"
287 runtime_directory "update-lowzoom-%i"
291 protect_system "full"
293 no_new_privileges true
297 directory "/srv/tile.openstreetmap.org/styles" do
303 node[:tile][:styles].each do |name, details|
304 style_directory = "/srv/tile.openstreetmap.org/styles/#{name}"
305 tile_directory = "/srv/tile.openstreetmap.org/tiles/#{name}"
307 template "/usr/local/bin/update-lowzoom-#{name}" do
308 source "update-lowzoom.erb"
312 variables :style => name
315 service "update-lowzoom@#{name}" do
317 supports :restart => true
320 directory tile_directory do
326 details[:tile_directories].each do |directory|
327 directory directory[:name] do
333 directory[:min_zoom].upto(directory[:max_zoom]) do |zoom|
334 directory "#{directory[:name]}/#{zoom}" do
340 link "#{tile_directory}/#{zoom}" do
341 to "#{directory[:name]}/#{zoom}"
348 file "#{tile_directory}/planet-import-complete" do
349 action :create_if_missing
355 git style_directory do
357 repository details[:repository]
358 revision details[:revision]
363 link "#{style_directory}/data" do
364 to "/srv/tile.openstreetmap.org/data"
369 execute "#{style_directory}/project.mml" do
371 command "carto -a 3.0.0 project.mml > project.xml"
375 subscribes :run, "git[#{style_directory}]"
376 notifies :restart, "service[renderd]", :immediately
377 notifies :restart, "service[update-lowzoom@#{name}]"
381 postgresql_version = node[:tile][:database][:cluster].split("/").first
382 postgis_version = node[:tile][:database][:postgis]
384 package "postgresql-#{postgresql_version}-postgis-#{postgis_version}"
386 postgresql_user "jburgess" do
387 cluster node[:tile][:database][:cluster]
391 postgresql_user "tomh" do
392 cluster node[:tile][:database][:cluster]
396 postgresql_user "tile" do
397 cluster node[:tile][:database][:cluster]
400 postgresql_user "www-data" do
401 cluster node[:tile][:database][:cluster]
404 postgresql_database "gis" do
405 cluster node[:tile][:database][:cluster]
409 postgresql_extension "postgis" do
410 cluster node[:tile][:database][:cluster]
414 postgresql_extension "hstore" do
415 cluster node[:tile][:database][:cluster]
417 only_if { node[:tile][:database][:hstore] }
420 %w[geography_columns planet_osm_nodes planet_osm_rels planet_osm_ways raster_columns raster_overviews spatial_ref_sys].each do |table|
421 postgresql_table table do
422 cluster node[:tile][:database][:cluster]
425 permissions "tile" => :all
429 %w[geometry_columns planet_osm_line planet_osm_point planet_osm_polygon planet_osm_roads].each do |table|
430 postgresql_table table do
431 cluster node[:tile][:database][:cluster]
434 permissions "tile" => :all, "www-data" => :select
444 if node[:tile][:database][:external_data_script]
445 execute node[:tile][:database][:external_data_script] do
446 command "#{node[:tile][:database][:external_data_script]} -R www-data"
447 cwd "/srv/tile.openstreetmap.org"
453 postgresql_munin "gis" do
454 cluster node[:tile][:database][:cluster]
458 directory File.dirname(node[:tile][:database][:node_file]) do
465 file node[:tile][:database][:node_file] do
471 directory "/var/log/tile" do
485 remote_directory "/usr/local/bin" do
495 template "/usr/local/bin/expire-tiles" do
496 source "expire-tiles.erb"
502 directory "/var/lib/replicate" do
508 directory "/var/lib/replicate/expire-queue" do
514 template "/usr/local/bin/replicate" do
515 source "replicate.erb"
519 variables :postgresql_version => postgresql_version.to_f
522 systemd_service "expire-tiles" do
523 description "Tile dirtying service"
526 exec_start "/usr/local/bin/expire-tiles"
527 standard_output "null"
530 protect_system "full"
532 no_new_privileges true
535 systemd_path "expire-tiles" do
536 description "Tile dirtying trigger"
537 directory_not_empty "/var/lib/replicate/expire-queue"
540 service "expire-tiles.path" do
541 action [:enable, :start]
542 subscribes :restart, "systemd_path[expire-tiles]"
545 systemd_service "replicate" do
546 description "Rendering database replication service"
547 after "postgresql.service"
548 wants "postgresql.service"
550 exec_start "/usr/local/bin/replicate"
553 protect_system "full"
555 no_new_privileges true
559 service "replicate" do
560 action [:enable, :start]
561 subscribes :restart, "template[/usr/local/bin/replicate]"
562 subscribes :restart, "systemd_service[replicate]"
565 template "/etc/logrotate.d/replicate" do
566 source "replicate.logrotate.erb"
572 template "/usr/local/bin/render-lowzoom" do
573 source "render-lowzoom.erb"
579 systemd_service "render-lowzoom" do
580 description "Render low zoom tiles"
581 condition_path_exists_glob "!/run/update-lowzoom-*"
583 exec_start "/usr/local/bin/render-lowzoom"
587 protect_system "full"
589 no_new_privileges true
592 systemd_timer "render-lowzoom" do
593 description "Render low zoom tiles"
594 on_calendar "Sun *-*~07/1 01:00:00"
597 service "render-lowzoom.timer" do
598 action [:enable, :start]
601 package "liblockfile-simple-perl"
602 package "libfilesys-df-perl"
604 template "/usr/local/bin/cleanup-tiles" do
605 source "cleanup-tiles.erb"
611 tile_directories = node[:tile][:styles].collect do |_, style|
612 style[:tile_directories].collect { |directory| directory[:name] }
613 end.flatten.sort.uniq
615 tile_directories.each do |directory|
616 label = directory.gsub("/", "-")
618 cron_d "cleanup-tiles#{label}" do
621 command "ionice -c 3 /usr/local/bin/cleanup-tiles #{directory}"
622 mailto "admins@openstreetmap.org"
626 munin_plugin "mod_tile_fresh"
627 munin_plugin "mod_tile_latency"
628 munin_plugin "mod_tile_response"
629 munin_plugin "mod_tile_zoom"
631 munin_plugin "renderd_processed"
632 munin_plugin "renderd_queue"
633 munin_plugin "renderd_queue_time"
634 munin_plugin "renderd_zoom"
635 munin_plugin "renderd_zoom_time"
637 munin_plugin "replication_delay"
639 prometheus_exporter "modtile" do
643 prometheus_exporter "renderd" do