├── LICENSE
├── NOTICE
├── README.md
├── bosh-lite
├── cloud-config.yml
└── default-vars.yml
├── cf-mysql-deployment.yml
├── docs
└── using-cf-mysql.md
├── githooks
└── pre-push
├── operations
├── README.md
├── add-broker.yml
├── add-roadmin.yml
├── add-tls.yml
├── add-xenial-default-stemcell.yml
├── bosh-dns.yml
├── bosh-lite.yml
├── configure-broker-load-balancer.yml
├── disable-broker-route-registrar-cross-deployment-links.yml
├── disable-proxy-consul-cross-deployment-links.yml
├── disable-proxy-route-registrar-cross-deployment-links.yml
├── disable-smoke-tests-cross-deployment-links.yml
├── enable-syslog.yml
├── latest-versions.yml
├── no-arbitrator.yml
├── proxy-consul.yml
├── proxy-elb.yml
├── register-proxy-route.yml
├── syslog-tls.yml
├── test
│ ├── enable-remote-admin-access.yml
│ └── minimal-mode.yml
└── xenial-stemcell.yml
└── scripts
├── deploy-cf-mysql-to-bosh-lite
└── deploy-cf-mysql-with-broker-to-bosh-lite
/LICENSE:
--------------------------------------------------------------------------------
1 |
2 | Apache License
3 | Version 2.0, January 2004
4 | http://www.apache.org/licenses/
5 |
6 | TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
7 |
8 | 1. Definitions.
9 |
10 | "License" shall mean the terms and conditions for use, reproduction,
11 | and distribution as defined by Sections 1 through 9 of this document.
12 |
13 | "Licensor" shall mean the copyright owner or entity authorized by
14 | the copyright owner that is granting the License.
15 |
16 | "Legal Entity" shall mean the union of the acting entity and all
17 | other entities that control, are controlled by, or are under common
18 | control with that entity. For the purposes of this definition,
19 | "control" means (i) the power, direct or indirect, to cause the
20 | direction or management of such entity, whether by contract or
21 | otherwise, or (ii) ownership of fifty percent (50%) or more of the
22 | outstanding shares, or (iii) beneficial ownership of such entity.
23 |
24 | "You" (or "Your") shall mean an individual or Legal Entity
25 | exercising permissions granted by this License.
26 |
27 | "Source" form shall mean the preferred form for making modifications,
28 | including but not limited to software source code, documentation
29 | source, and configuration files.
30 |
31 | "Object" form shall mean any form resulting from mechanical
32 | transformation or translation of a Source form, including but
33 | not limited to compiled object code, generated documentation,
34 | and conversions to other media types.
35 |
36 | "Work" shall mean the work of authorship, whether in Source or
37 | Object form, made available under the License, as indicated by a
38 | copyright notice that is included in or attached to the work
39 | (an example is provided in the Appendix below).
40 |
41 | "Derivative Works" shall mean any work, whether in Source or Object
42 | form, that is based on (or derived from) the Work and for which the
43 | editorial revisions, annotations, elaborations, or other modifications
44 | represent, as a whole, an original work of authorship. For the purposes
45 | of this License, Derivative Works shall not include works that remain
46 | separable from, or merely link (or bind by name) to the interfaces of,
47 | the Work and Derivative Works thereof.
48 |
49 | "Contribution" shall mean any work of authorship, including
50 | the original version of the Work and any modifications or additions
51 | to that Work or Derivative Works thereof, that is intentionally
52 | submitted to Licensor for inclusion in the Work by the copyright owner
53 | or by an individual or Legal Entity authorized to submit on behalf of
54 | the copyright owner. For the purposes of this definition, "submitted"
55 | means any form of electronic, verbal, or written communication sent
56 | to the Licensor or its representatives, including but not limited to
57 | communication on electronic mailing lists, source code control systems,
58 | and issue tracking systems that are managed by, or on behalf of, the
59 | Licensor for the purpose of discussing and improving the Work, but
60 | excluding communication that is conspicuously marked or otherwise
61 | designated in writing by the copyright owner as "Not a Contribution."
62 |
63 | "Contributor" shall mean Licensor and any individual or Legal Entity
64 | on behalf of whom a Contribution has been received by Licensor and
65 | subsequently incorporated within the Work.
66 |
67 | 2. Grant of Copyright License. Subject to the terms and conditions of
68 | this License, each Contributor hereby grants to You a perpetual,
69 | worldwide, non-exclusive, no-charge, royalty-free, irrevocable
70 | copyright license to reproduce, prepare Derivative Works of,
71 | publicly display, publicly perform, sublicense, and distribute the
72 | Work and such Derivative Works in Source or Object form.
73 |
74 | 3. Grant of Patent License. Subject to the terms and conditions of
75 | this License, each Contributor hereby grants to You a perpetual,
76 | worldwide, non-exclusive, no-charge, royalty-free, irrevocable
77 | (except as stated in this section) patent license to make, have made,
78 | use, offer to sell, sell, import, and otherwise transfer the Work,
79 | where such license applies only to those patent claims licensable
80 | by such Contributor that are necessarily infringed by their
81 | Contribution(s) alone or by combination of their Contribution(s)
82 | with the Work to which such Contribution(s) was submitted. If You
83 | institute patent litigation against any entity (including a
84 | cross-claim or counterclaim in a lawsuit) alleging that the Work
85 | or a Contribution incorporated within the Work constitutes direct
86 | or contributory patent infringement, then any patent licenses
87 | granted to You under this License for that Work shall terminate
88 | as of the date such litigation is filed.
89 |
90 | 4. Redistribution. You may reproduce and distribute copies of the
91 | Work or Derivative Works thereof in any medium, with or without
92 | modifications, and in Source or Object form, provided that You
93 | meet the following conditions:
94 |
95 | (a) You must give any other recipients of the Work or
96 | Derivative Works a copy of this License; and
97 |
98 | (b) You must cause any modified files to carry prominent notices
99 | stating that You changed the files; and
100 |
101 | (c) You must retain, in the Source form of any Derivative Works
102 | that You distribute, all copyright, patent, trademark, and
103 | attribution notices from the Source form of the Work,
104 | excluding those notices that do not pertain to any part of
105 | the Derivative Works; and
106 |
107 | (d) If the Work includes a "NOTICE" text file as part of its
108 | distribution, then any Derivative Works that You distribute must
109 | include a readable copy of the attribution notices contained
110 | within such NOTICE file, excluding those notices that do not
111 | pertain to any part of the Derivative Works, in at least one
112 | of the following places: within a NOTICE text file distributed
113 | as part of the Derivative Works; within the Source form or
114 | documentation, if provided along with the Derivative Works; or,
115 | within a display generated by the Derivative Works, if and
116 | wherever such third-party notices normally appear. The contents
117 | of the NOTICE file are for informational purposes only and
118 | do not modify the License. You may add Your own attribution
119 | notices within Derivative Works that You distribute, alongside
120 | or as an addendum to the NOTICE text from the Work, provided
121 | that such additional attribution notices cannot be construed
122 | as modifying the License.
123 |
124 | You may add Your own copyright statement to Your modifications and
125 | may provide additional or different license terms and conditions
126 | for use, reproduction, or distribution of Your modifications, or
127 | for any such Derivative Works as a whole, provided Your use,
128 | reproduction, and distribution of the Work otherwise complies with
129 | the conditions stated in this License.
130 |
131 | 5. Submission of Contributions. Unless You explicitly state otherwise,
132 | any Contribution intentionally submitted for inclusion in the Work
133 | by You to the Licensor shall be under the terms and conditions of
134 | this License, without any additional terms or conditions.
135 | Notwithstanding the above, nothing herein shall supersede or modify
136 | the terms of any separate license agreement you may have executed
137 | with Licensor regarding such Contributions.
138 |
139 | 6. Trademarks. This License does not grant permission to use the trade
140 | names, trademarks, service marks, or product names of the Licensor,
141 | except as required for reasonable and customary use in describing the
142 | origin of the Work and reproducing the content of the NOTICE file.
143 |
144 | 7. Disclaimer of Warranty. Unless required by applicable law or
145 | agreed to in writing, Licensor provides the Work (and each
146 | Contributor provides its Contributions) on an "AS IS" BASIS,
147 | WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
148 | implied, including, without limitation, any warranties or conditions
149 | of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
150 | PARTICULAR PURPOSE. You are solely responsible for determining the
151 | appropriateness of using or redistributing the Work and assume any
152 | risks associated with Your exercise of permissions under this License.
153 |
154 | 8. Limitation of Liability. In no event and under no legal theory,
155 | whether in tort (including negligence), contract, or otherwise,
156 | unless required by applicable law (such as deliberate and grossly
157 | negligent acts) or agreed to in writing, shall any Contributor be
158 | liable to You for damages, including any direct, indirect, special,
159 | incidental, or consequential damages of any character arising as a
160 | result of this License or out of the use or inability to use the
161 | Work (including but not limited to damages for loss of goodwill,
162 | work stoppage, computer failure or malfunction, or any and all
163 | other commercial damages or losses), even if such Contributor
164 | has been advised of the possibility of such damages.
165 |
166 | 9. Accepting Warranty or Additional Liability. While redistributing
167 | the Work or Derivative Works thereof, You may choose to offer,
168 | and charge a fee for, acceptance of support, warranty, indemnity,
169 | or other liability obligations and/or rights consistent with this
170 | License. However, in accepting such obligations, You may act only
171 | on Your own behalf and on Your sole responsibility, not on behalf
172 | of any other Contributor, and only if You agree to indemnify,
173 | defend, and hold each Contributor harmless for any liability
174 | incurred by, or claims asserted against, such Contributor by reason
175 | of your accepting any such warranty or additional liability.
176 |
177 | END OF TERMS AND CONDITIONS
178 |
--------------------------------------------------------------------------------
/NOTICE:
--------------------------------------------------------------------------------
1 | Copyright (c) 2015-Present CloudFoundry.org Foundation, Inc. All Rights Reserved.
2 |
3 | This project is licensed to you under the Apache License, Version 2.0 (the "License").
4 |
5 | You may not use this project except in compliance with the License.
6 |
7 | This project may include a number of subcomponents with separate copyright notices
8 | and license terms. Your use of these subcomponents is subject to the terms and
9 | conditions of the subcomponent's license, as noted in the LICENSE file.
10 |
--------------------------------------------------------------------------------
/README.md:
--------------------------------------------------------------------------------
1 | DEPRECATED: cf-mysql-release is deprecated and this repo is no longer maintained.
2 |
3 | See [pxc-release](https://github.com/cloudfoundry/pxc-release)
4 |
5 | # Cloud Foundry MySQL Bosh Deployment
6 |
7 | ## Table of contents
8 |
9 | [Usage](#usage)
10 |
11 | [Deploying](#deploying)
12 |
13 | [Security Groups](#security-groups)
14 |
15 | [Registering the Service Broker](#registering-broker)
16 |
17 | [Smoke Tests](#smoke-tests)
18 |
19 | [Deregistering the Service Broker](#deregistering-broker)
20 |
21 |
22 | This repo contains a BOSH 2 manifest that defines tested topologies of cf-mysql-release.
23 |
24 | It serves as the reference for the compatible release and stemcell versions.
25 |
26 | This repo takes advantage of new features such as:
27 |
28 | - [cloud config](https://bosh.io/docs/cloud-config.html)
29 | - [job links](https://bosh.io/docs/links.html)
30 | - [new CLI](https://github.com/cloudfoundry/bosh-cli)
31 | - The new BOSH CLI must be installed according to the instructions [here](https://bosh.io/docs/cli-v2.html).
32 |
33 | Please refer to BOSH documentation for more details. If you're having troubles
34 | with the pre-requisites, please contact the BOSH team for help
35 | (perhaps on [slack](https://slack.cloudfoundry.org/)).
36 |
37 |
38 | ## Usage
39 |
40 | ### Prerequisites
41 |
42 | - A deployment of [BOSH](https://github.com/cloudfoundry/bosh)
43 | - A deployment of [Cloud Foundry](https://github.com/cloudfoundry/cf-release), [final release 193](https://github.com/cloudfoundry/cf-release/tree/v193) or greater
44 | - Instructions for installing BOSH and Cloud Foundry can be found at http://docs.cloudfoundry.org/.
45 | - [Routing release](https://github.com/cloudfoundry-incubator/routing-release)
46 | v0.145.0 or later is required to register the proxy and broker routes with
47 | Cloud Foundry:
48 |
49 | ```bash
50 | bosh upload release https://bosh.io/d/github.com/cloudfoundry-incubator/cf-routing-release?v=0.145.0
51 | ```
52 |
53 | Standalone deployments (i.e. deployments that do not interact with Cloud Foundry)
54 | do not require the routing release.
55 |
56 |
57 | ### Upload Stemcell
58 |
59 | The latest final release expects the Ubuntu Trusty (14.04) go_agent stemcell version [2859](https://github.com/cloudfoundry/bosh/blob/master/CHANGELOG.md#2859) by default. Older stemcells are not recommended. Stemcells can be downloaded from http://bosh.io/stemcells; choose the appropriate stemcell for your infrastructure ([vsphere esxi](https://d26ekeud912fhb.cloudfront.net/bosh-stemcell/vsphere/bosh-stemcell-2859-vsphere-esxi-ubuntu-trusty-go_agent.tgz), [aws hvm](https://d26ekeud912fhb.cloudfront.net/bosh-stemcell/aws/light-bosh-stemcell-2859-aws-xen-hvm-ubuntu-trusty-go_agent.tgz), or [openstack kvm](https://d26ekeud912fhb.cloudfront.net/bosh-stemcell/openstack/bosh-stemcell-2859-openstack-kvm-ubuntu-trusty-go_agent.tgz)).
60 |
61 |
62 | ### Upload Release
63 |
64 | You can use a pre-built final release or build a dev release from any of the branches described in Getting the Code.
65 |
66 | Final releases are stable releases created periodically for completed features. They also contain pre-compiled packages, which makes deployment much faster. To deploy the latest final release, simply check out the **master** branch. This will contain the latest final release and accompanying materials to generate a manifest. If you would like to deploy an earlier final release, use `git checkout ` to obtain both the release and corresponding manifest generation materials. It's important that the manifest generation materials are consistent with the release.
67 |
68 | If you'd like to deploy the latest code, build a release yourself from the **develop** branch.
69 |
70 | #### Create and upload a BOSH Release:
71 |
72 | 1. Build the development release.
73 |
74 | ```
75 | $ cd ~/workspace/cf-mysql-release
76 | $ git checkout release-candidate
77 | $ ./scripts/update
78 | $ bosh2 create-release
79 | ```
80 |
81 | 1. Upload the release to your bosh environment:
82 |
83 | ```
84 | $ bosh2 -e YOUR_ENV upload-release
85 | ```
86 |
87 |
88 | ### Create Infrastructure
89 |
90 | #### Define subnets
91 |
92 | Prior to deployment, the operator should define three subnets via their infrastructure provider.
93 | The MySQL release is designed to be deployed across three subnets to ensure availability in the event of a subnet failure.
94 |
95 | #### Create load balancer
96 |
97 | In order to route requests to both proxies, the operator should create a load balancer.
98 | Manifest changes required to configure a load balancer can be found in the
99 | [proxy](https://github.com/cloudfoundry/cf-mysql-release/blob/master/docs/proxy.md#configuring-load-balancer) documentation.
100 | Once a load balancer is configured, the brokers will hand out the address of the load balancer rather than the IP of the first proxy.
101 |
102 | - **Note:** When using an Elastic Load Balancer (ELB) on Amazon, make sure to create the ELB in the same VPC as your cf-mysql deployment
103 | - **Note:** For all load balancers, take special care to configure health checks to use the health_port of the proxies (default 1936). Do not configure the load balancer health check to use port 3306.
104 | - **You must use the IP address(es) of your load balancer in the p-mysql [security group](#security-groups)**, below. Otherwise, applications will not be able to connect to the database.
105 |
106 | There are two ways to configure a load balancer, either automatically through your IaaS or by supplying static IPs for the proxies
107 |
108 | ##### For IaaS native load balancers (AWS elb, GCP target_pool, etc)
109 |
110 | In order for the MySQL deployment to attach the proxy instances to your configured load balancer, you need to use the [proxy-elb.yml](https://github.com/cloudfoundry/cf-mysql-deployment/blob/develop/operations/proxy-elb.yml) opsfile. This opsfile requires a [vm_extension](https://bosh.io/docs/cloud-config.html#vm-extensions) in your [cloud-config](https://bosh.io/docs/cloud-config.html) which references your load balancer and also defines the specific requirements for your IaaS. You'll need to consult your IaaS documentation as well as your BOSH CPI documentation for the specifics of the `cloud_properties` definitions for use in your `vm_extension`. You can read more specifics about configuration of the proxies [here](https://github.com/cloudfoundry/cf-mysql-release/blob/develop/docs/proxy.md).
111 |
112 | ##### For custom load balancers (haproxy, f5, etc)
113 |
114 | If you would like to use a custom load balancer, you can manually configure your proxies to use static IP addresses which your load balancer can point to. To do that, create an operations file that looks like the following, with static IPs that make sense for your network:
115 | ```yaml
116 | - type: replace
117 | path: /instance_groups/name=proxy/networks
118 | value:
119 | - name: default
120 | static_ips:
121 | - 10.10.0.1
122 | - 10.10.0.2
123 | ```
124 |
125 |
126 | ## Deploying
127 | ### Deployment Components
128 |
129 | #### Database nodes
130 |
131 | The number of mysql nodes should always be odd, with a minimum count of three, to avoid [split-brain](http://en.wikipedia.org/wiki/Split-brain\_\(computing\)).
132 | When the failed node comes back online, it will automatically rejoin the cluster and sync data from one of the healthy nodes.
133 |
134 | The MariaDB cluster nodes are configured by default with 10GB of persistent disk. This can be configured using an operations file to change `instance_groups/name=mysql/persistent_disk` and `properties/cf_mysql/mysql/persistent_disk`, however your deployment will fail if this is less than 3GB.
135 |
136 | #### Proxy nodes
137 |
138 | There are two proxy instances. The second proxy is intended to be used in a failover capacity.
139 | In the event the first proxy fails, the second proxy will still be able to route requests to the mysql nodes.
140 |
141 | #### Broker nodes
142 |
143 | There are also two broker instances.
144 | The brokers each register a route with the router, which load balances requests across the brokers.
145 |
146 | ### New deployments
147 |
148 | New deployments will work "out of the box" with little additional configuration.
149 | There are two mechanisms for providing credentials to the deployment:
150 |
151 | - Credentials can be provided with `-l ` (see below for more
152 | information on variable files).
153 | - variables store file should be provided with
154 | `--vars-store ` to let the CLI generate secure passwords
155 | and write them to the provided vars store file.
156 |
157 | By default the deployment manifest will not deploy brokers, nor try to register
158 | routes for the proxies with a Cloud Foundry router. To enable integration with
159 | Cloud Foundry, operations files are provided to
160 | [add brokers](https://github.com/cloudfoundry/cf-mysql-deployment/tree/master/operations/add-broker.yml)
161 | and
162 | [register proxy routes](https://github.com/cloudfoundry/cf-mysql-deployment/tree/master/operations/register-proxy-route.yml).
163 |
164 | If you require static IPs for the proxy instance groups, these IPs should be
165 | added to the `networks` section of the cloud-config as well as to an operations file
166 | which will use these IPs for the proxy instance groups. See below for more
167 | information on operations files.
168 |
169 | ```sh
170 | bosh \
171 | -e my-director \
172 | -d cf-mysql \
173 | deploy \
174 | ~/workspace/cf-mysql-deployment/cf-mysql-deployment.yml \
175 | -o
176 | ```
177 |
178 | ### Upgrading from previous deployment topologies
179 |
180 | If you are upgrading an existing deployment of cf-mysql-release with a manifest
181 | that does not take advantage of these new features, for example if the manifest
182 | was generated via the spiff templates and stubs provided in the cf-mysql-release
183 | repository, then be aware:
184 |
185 | 1. The base manifest refers to AZs called `z1`, `z2`, and `z3`. If your
186 | cloud-config doesn't have those AZs, it will result in an error.
187 | 1. The base manifest will not deploy brokers, nor try to register routes for the proxies with a Cloud Foundry router. If you wish to preserve this behavior you will need to include the [add brokers](https://github.com/cloudfoundry/cf-mysql-deployment/tree/master/operations/add-broker.yml) and [register proxy routes](https://github.com/cloudfoundry/cf-mysql-deployment/tree/master/operations/register-proxy-route.yml) operations files.
188 | 1. Create custom operations files to map any non-default configuration (e.g. the number of maximum connections).
189 | 1. Create a custom operation file to migrate your BOSH 1 `jobs` and static IPs to their new BOSH 2 `instance_groups`. See the section below for [more information](#operations-file-for-migrating-from-bosh-1-style-manifest-to-a-bosh-2-style-manifest).
190 | 1. Create a variables file to contain the credentials of the existing deployment.
191 | - Using `--vars-store` is not recommended as it will result in credentials being rotated which can cause issues.
192 | 1. Run the following command:
193 |
194 | ```sh
195 | bosh \
196 | -e my-director \
197 | -d my-deployment \
198 | deploy \
199 | ~/workspace/cf-mysql-deployment/cf-mysql-deployment.yml \
200 | -o \
201 | [-o ] \
202 | -l \
203 | [-l ]
204 | ```
205 |
206 | #### Operations file for migrating from BOSH 1 style manifest to a BOSH 2 style manifest
207 | Refer to [these docs](https://bosh.io/docs/migrated-from.html) on migrating from a BOSH 1 style manifest, then create an ops file to mix in those migrations into the base deployment manifest. See below for an example:
208 |
209 | ```yaml
210 |
211 | ---
212 | - type: replace
213 | path: /instance_groups/name=mysql/migrated_from?
214 | value:
215 | - name: mysql_z1
216 | az: z1
217 | - name: mysql_z2
218 | az: z2
219 | - name: mysql_z3
220 | az: z3
221 |
222 | - type: replace
223 | path: /instance_groups/name=mysql/networks
224 | value:
225 | - name: default
226 | static_ips:
227 | - 10.10.0.1
228 | - 10.10.0.2
229 | - 10.10.0.3
230 | ```
231 |
232 | ## Operations files
233 |
234 | Additional example operations files used for common configurations of `cf-mysql-release` (e.g. adding a broker for
235 | Cloud Foundry integration) can be found in the [operations](https://github.com/cloudfoundry/cf-mysql-deployment/tree/master/operations)
236 | directory. See the README in that directory for a description of which (combinations) of files to use for enabling each common feature set.
237 |
238 | The [manifest template](https://github.com/cloudfoundry/cf-mysql-deployment/tree/master/cf-mysql-deployment.yml)
239 | is not intended to be modified; any changes you need to make should be added to operations files.
240 |
241 | The syntax for operations files is detailed
242 | [here](http://bosh.io/docs/cli-ops-files.html).
243 |
244 | Operations files can be provided at deploy-time as follows:
245 |
246 | ```sh
247 | bosh \
248 | deploy \
249 | -o
250 | ```
251 |
252 | ### Variables files
253 |
254 | Variables files are a flat-format key-value yaml file which contains sensitive
255 | information such as passwords, ssl keys/certs etc.
256 |
257 | They can be provided at deploy-time as follows:
258 |
259 | ```sh
260 | bosh \
261 | deploy \
262 | -l
263 | ```
264 |
265 | We provide a default set of variables intended for a local bosh-lite environment
266 | [here](https://github.com/cloudfoundry/cf-mysql-deployment/tree/master/bosh-lite/default-vars.yml).
267 |
268 | Use this as an example for your environment-specific variables file.
269 |
270 | ### Cross-deployment links
271 |
272 | By default, this deployment assumes that some variables (e.g. nats) are provided
273 | by cross-deployment links from a deployment named `cf`.
274 | This will be true if Cloud Foundry was deployed via
275 | [cf-deployment](https://github.com/cloudfoundry/cf-deployment).
276 |
277 | If you wish to disable cross-deployment links, use the
278 | `disable-cross-deployment-links.yml` operations file.
279 |
280 | Disabling cross-deployment links will require these values to be provided
281 | manually (e.g. by passing `-v nats={...}` to the `bosh deploy` command).
282 |
283 |
284 | ## Security Groups
285 |
286 | By default, applications cannot to connect to IP addresses on the private network,
287 | preventing applications from connecting to the MySQL service.
288 | To enable access to the service, create a new security group for the IP
289 | configured in your manifest for the property `jobs.cf-mysql-broker.mysql_node.host`.
290 |
291 | Note: This is not required for CF running on bosh-lite, as these application
292 | groups are pre-configured.
293 |
294 | 1. Add the rule to a file in the following json format; multiple rules are supported.
295 |
296 | ```
297 | [
298 | {
299 | "destination": "10.10.163.1-10.10.163.255",
300 | "protocol": "all"
301 | },
302 | {
303 | "destination": "10.10.164.1-10.10.164.255",
304 | "protocol": "all"
305 | },
306 | {
307 | "destination": "10.10.165.1-10.10.165.255",
308 | "protocol": "all"
309 | }
310 | ]
311 | ```
312 |
313 | - Create a security group from the rule file.
314 |
315 | ```shell
316 | $ cf create-security-group p-mysql rule.json
317 | ```
318 |
319 | - Enable the rule for all apps
320 |
321 | ```shell
322 | $ cf bind-running-security-group p-mysql
323 | ```
324 |
325 | Security group changes are only applied to new application containers;
326 | existing apps must be restarted.
327 |
328 |
329 | ## Registering the Service Broker
330 |
331 | After registering the service broker, the MySQL service will be visible in the Services Marketplace; using the [CLI](https://github.com/cloudfoundry/cli), run `cf marketplace`.
332 |
333 | ### BOSH errand
334 |
335 | ```
336 | $ bosh2 -e YOUR_ENV -d cf-mysql run-errand broker-registrar
337 | ```
338 |
339 | ### Manually
340 |
341 | 1. First register the broker using the `cf` CLI. You must be logged in as an admin.
342 |
343 | ```
344 | $ cf create-service-broker p-mysql BROKER_USERNAME BROKER_PASSWORD URL
345 | ```
346 |
347 | `BROKER_USERNAME` and `BROKER_PASSWORD` are the credentials Cloud Foundry will use to authenticate when making API calls to the service broker. Use the values for manifest properties `jobs.cf-mysql-broker.properties.auth_username` and `jobs.cf-mysql-broker.properties.auth_password`.
348 |
349 | `URL` specifies where the Cloud Controller will access the MySQL broker. Use the value of the manifest property `jobs.cf-mysql-broker.properties.external_host`. By default, this value is set to `p-mysql.` (in spiff: `"p-mysql." .properties.domain`).
350 |
351 | For more information, see [Managing Service Brokers](http://docs.cloudfoundry.org/services/managing-service-brokers.html).
352 |
353 | 2. Then [make the service plan public](http://docs.cloudfoundry.org/services/managing-service-brokers.html#make-plans-public).
354 |
355 |
356 |
357 | ## Smoke Tests
358 |
359 | The smoke tests are useful for verifying a deployment.
360 | The MySQL Release contains an "smoke-tests" job which is deployed as a BOSH errand.
361 |
362 | ### Running Smoke Tests via BOSH errand
363 |
364 | Run the smoke tests via bosh errand as follows:
365 |
366 | ```
367 | $ bosh2 -e YOUR_ENV -d cf-mysql run-errand smoke-tests
368 | ```
369 |
370 |
371 | ## De-registering the Service Broker
372 |
373 | The following commands are destructive and are intended to be run in conjuction with deleting your BOSH deployment.
374 | ```
375 | $ bosh2 -e YOUR_ENV -d cf-mysql run-errand deregister-and-purge-instances
376 | ```
377 |
378 | ### Manually
379 |
380 | Run the following:
381 |
382 | ```
383 | $ cf purge-service-offering p-mysql
384 | $ cf delete-service-broker p-mysql
385 | ```
386 |
387 |
--------------------------------------------------------------------------------
/bosh-lite/cloud-config.yml:
--------------------------------------------------------------------------------
1 | azs:
2 | - name: z1
3 | - name: z2
4 | - name: z3
5 | vm_types:
6 | - name: default
7 | cloud_properties:
8 | ephemeral_disk:
9 | size: 1024
10 | type: gp2
11 | - name: micro
12 | cloud_properties:
13 | ephemeral_disk:
14 | size: 1024
15 | type: gp2
16 | compilation:
17 | workers: 4
18 | network: default
19 | az: z1
20 | reuse_compilation_vms: true
21 | vm_type: default
22 | networks:
23 | - name: default
24 | subnets:
25 | - az: z1
26 | range: 10.244.7.0/24
27 | gateway: 10.244.7.1
28 | cloud_properties:
29 | name: random
30 | - az: z2
31 | range: 10.244.8.0/24
32 | gateway: 10.244.8.1
33 | cloud_properties:
34 | name: random
35 | - az: z3
36 | range: 10.244.9.0/24
37 | gateway: 10.244.9.1
38 | cloud_properties:
39 | name: random
40 | vm_extensions:
41 | - name: mysql-proxy-lb
42 | cloud_properties:
43 | ports:
44 | - host: 3306
45 |
--------------------------------------------------------------------------------
/bosh-lite/default-vars.yml:
--------------------------------------------------------------------------------
1 | ---
2 | cf_mysql_external_host: p-mysql.bosh-lite.com
3 | cf_mysql_host: bosh-lite.com
4 | cf_admin_password: REPLACE_WITH_CF_ADMIN_PASSWORD
5 | cf_api_url: https://api.bosh-lite.com
6 | cf_skip_ssl_validation: true
7 | proxy_vm_extension: mysql-proxy-lb
8 |
--------------------------------------------------------------------------------
/cf-mysql-deployment.yml:
--------------------------------------------------------------------------------
1 | name: cf-mysql
2 |
3 | addons:
4 | - name: bpm
5 | jobs:
6 | - name: bpm
7 | release: bpm
8 |
9 | update:
10 | canaries: 1
11 | canary_watch_time: 10000-600000
12 | update_watch_time: 10000-600000
13 | max_in_flight: 1
14 | serial: true
15 |
16 | instance_groups:
17 | - name: mysql
18 | instances: 2
19 | azs: [z1, z2]
20 | networks: [{name: default}]
21 | vm_type: default
22 | stemcell: default
23 | persistent_disk: 10000
24 | jobs:
25 | - name: mysql
26 | release: cf-mysql
27 | properties:
28 | cf_mysql:
29 | mysql:
30 | admin_password: ((cf_mysql_mysql_admin_password))
31 | cluster_health:
32 | password: ((cf_mysql_mysql_cluster_health_password))
33 | galera_healthcheck:
34 | endpoint_password: ((cf_mysql_mysql_galera_healthcheck_endpoint_password))
35 | db_password: ((cf_mysql_mysql_galera_healthcheck_db_password))
36 | - name: smoke-tests-user
37 | release: cf-mysql
38 | properties:
39 | cf_mysql:
40 | smoke_tests:
41 | db_password: ((cf_mysql_smoke_tests_db_password))
42 |
43 | - name: arbitrator
44 | instances: 1
45 | azs: [z3]
46 | networks: [{name: default}]
47 | vm_type: default
48 | stemcell: default
49 | jobs:
50 | - release: cf-mysql
51 | name: arbitrator
52 | properties:
53 | cf_mysql:
54 | mysql:
55 | admin_password: ((cf_mysql_mysql_admin_password))
56 | galera_healthcheck:
57 | endpoint_password: ((cf_mysql_mysql_galera_healthcheck_endpoint_password))
58 |
59 | - name: proxy
60 | instances: 2
61 | azs: [z1, z2]
62 | networks: [{name: default}]
63 | vm_type: default
64 | stemcell: default
65 | jobs:
66 | - name: proxy
67 | release: cf-mysql
68 | properties:
69 | cf_mysql:
70 | proxy:
71 | api_password: ((cf_mysql_proxy_api_password))
72 | provides:
73 | mysql-database:
74 | as: mysql-database
75 | shared: true
76 |
77 | - name: bootstrap-vm
78 | instances: 1
79 | lifecycle: errand
80 | azs: [z1]
81 | networks: [{name: default}]
82 | vm_type: default
83 | stemcell: default
84 | jobs:
85 | - {release: cf-mysql, name: bootstrap}
86 |
87 | - name: rejoin-unsafe-vm
88 | instances: 1
89 | lifecycle: errand
90 | azs: [z1]
91 | networks: [{name: default}]
92 | vm_type: default
93 | stemcell: default
94 | jobs:
95 | - {release: cf-mysql, name: rejoin-unsafe}
96 |
97 | - name: verify-cluster-schemas-vm
98 | instances: 1
99 | lifecycle: errand
100 | azs: [z1]
101 | networks: [{name: default}]
102 | vm_type: default
103 | stemcell: default
104 | jobs:
105 | - name: verify-cluster-schemas
106 | release: cf-mysql
107 | properties:
108 | cf_mysql:
109 | mysql:
110 | admin_password: ((cf_mysql_mysql_admin_password))
111 | galera_healthcheck:
112 | endpoint_password: ((cf_mysql_mysql_galera_healthcheck_endpoint_password))
113 |
114 | - name: smoke-tests-vm
115 | instances: 1
116 | lifecycle: errand
117 | azs: [z1]
118 | networks: [{name: default}]
119 | vm_type: default
120 | stemcell: default
121 | jobs:
122 | - name: smoke-tests
123 | release: cf-mysql
124 | properties:
125 | cf_mysql:
126 | mysql:
127 | admin_password: ((cf_mysql_mysql_admin_password))
128 | proxy:
129 | api_password: ((cf_mysql_proxy_api_password))
130 | smoke_tests:
131 | db_password: ((cf_mysql_smoke_tests_db_password))
132 | standalone_tests_only: true
133 |
134 | variables:
135 | - name: cf_mysql_mysql_admin_password
136 | type: password
137 | - name: cf_mysql_mysql_cluster_health_password
138 | type: password
139 | - name: cf_mysql_mysql_galera_healthcheck_db_password
140 | type: password
141 | - name: cf_mysql_mysql_galera_healthcheck_endpoint_password
142 | type: password
143 | - name: cf_mysql_proxy_api_password
144 | type: password
145 | - name: cf_mysql_smoke_tests_db_password
146 | type: password
147 |
148 | releases:
149 | - name: cf-mysql
150 | url: https://bosh.io/d/github.com/cloudfoundry/cf-mysql-release?v=36.19.0
151 | version: 36.19.0
152 | sha1: 393a018015fdcb48da40259b6a39b8e30fde9d0c
153 | - name: bpm
154 | url: ""
155 | version: latest
156 | sha1: ""
157 | stemcells:
158 | - alias: default
159 | os: ubuntu-trusty
160 | version: "3586.79"
161 |
--------------------------------------------------------------------------------
/docs/using-cf-mysql.md:
--------------------------------------------------------------------------------
1 | # Application Developer's Guide to Using cf-mysql
2 |
3 | ## Connecting to cf-mysql
4 |
5 | ### Binding an App
6 |
7 | You can connect apps that are deployed to Cloud Foundry, via `cf push` using the standard instructions on [Delivering Service Credentials to an Application](https://docs.cloudfoundry.org/devguide/services/application-binding.html).
8 |
9 | cf-mysql does not offer any arbitrary parameters.
10 |
11 | ### Service Keys
12 |
13 | To connect to cf-mysql from an app which has not been deployed to Cloud Foundry, you can follow the instructions for [creating a service key](https://docs.cloudfoundry.org/devguide/services/service-keys.html).
14 |
15 | ### Encryption
16 |
17 | #### Applications Running on Cloud Foundry
18 |
19 | Most applications, save Java and Spring (see below), can be modified to discover the information necessary to connect to cf-mysql using TLS. When inspecting `VCAP_SERVICES` for username and password, if the additional property, `ca_certificate` is available, your application can connect to cf-mysql using TLS.
20 |
21 | Here's a Node.js example:
22 |
23 | ```node
24 | ca_cert = vcap_services["p-mysql"][0]["credentials"]["ca_certificate"] ;
25 | dbClient = mysql.createConnection( {
26 | host : host,
27 | user : user,
28 | password : password,
29 | port : port,
30 | database : database,
31 | ssl : {
32 | ca : ca_cert
33 | },
34 | } ) ;
35 | ```
36 | Some languages automatically check the operating system's [trust store](https://docs.cloudfoundry.org/devguide/deploy-apps/trusted-system-certificates.html). In those cases, it is not necessary to parse `VCAP_SERVICES` for the CA certificate.
37 |
38 | #### Java and Spring Applications
39 |
40 | To enable apps using the [Java buildpack](https://docs.cloudfoundry.org/buildpacks/java/), you'll need to delete the existing binding and create a new one. This will update the `jdbcUrl` to specify an encrypted connection.
41 |
42 | **Note:** Should your deployment of cf-mysql turn off encryption in the future, you'll need to **re-bind** all Java applications that use cf-mysql. That will remove the encryption requirement, allowing apps to connect to an instance that does not offer encryption.
43 |
44 | #### Service Keys
45 |
46 | When using a service key to establish a connection using TLS (aka SSL) you will need the `ca_certificate` from the service key output. See the [service key documentation](https://docs.cloudfoundry.org/devguide/services/service-keys.html#detail) to view the service key JSON.
47 |
48 | Save the CA certificate to a file in PEM format. You'll need to replace the "\n" with newlines.
49 |
50 | To test, you can use any MySQL client. Connect to the hostname given in the service key output with the given credentials. When using the `mysql` CLI, also specify `--ssl-verify-server-cert --ssl-ca=PATH_TO_CA_CERTIFICATE`.
51 |
--------------------------------------------------------------------------------
/githooks/pre-push:
--------------------------------------------------------------------------------
1 | #!/usr/bin/env bash
2 |
3 | branch=$(git rev-parse --abbrev-ref HEAD)
4 |
5 | if [ "${branch}" == "master" ]
6 | then
7 | echo "Refusing to commit to 'master'. Please commit to 'develop' or other branches"
8 | exit 1
9 | fi
10 |
--------------------------------------------------------------------------------
/operations/README.md:
--------------------------------------------------------------------------------
1 | # Operations
2 |
3 | This directory contains a list of commonly-used, tested, operations files.
4 |
5 | Unless otherwise stated, they can be combined in any permutation and in any order.
6 |
7 | ### Registering the proxy route
8 |
9 | [This operations file](https://github.com/cloudfoundry/cf-mysql-deployment/tree/master/operations/register-proxy-route.yml)
10 | registers routes with the Cloud Foundry router which point to the dashboard pages hosted by the proxies deployed as part of `cf-mysql-release`.
11 |
12 |
13 | ### Enabling the Service Broker
14 |
15 | To enable integration of the MySQL database with Cloud Foundry (as a Cloud Foundry service), you should include the
16 | [add a broker](https://github.com/cloudfoundry/cf-mysql-deployment/tree/master/operations/add-broker.yml)
17 | operations file, as well as the [register the proxy route](https://github.com/cloudfoundry/cf-mysql-deployment/tree/master/operations/register-proxy-route.yml)
18 | operations file.
19 |
20 |
21 | ### Disabling cross deployment links
22 |
23 | Used when the dependent deployments (i.e. Cloud Foundry) do not expose properties
24 | via cross-deployment links.
25 |
26 | For example, many configurations of
27 | [cf-release](https://github.com/cloudfoundry/cf-release)
28 | (including the
29 | [provided spiff manifest generation](https://github.com/cloudfoundry/cf-release/blob/master/scripts/generate_deployment_manifest))
30 | do not support cross-deployment links without manual modifications to the manifest,
31 | whereas deploying Cloud Foundry via
32 | [cf-deployment](https://github.com/cloudfoundry/cf-deployment)
33 | exposes properties like NATS config by default.
34 |
35 | Using this operations file will require you to provide your own values for these
36 | properties which would otherwise be provided via links, e.g. NATS.
37 |
38 | Example usage:
39 |
40 | ```
41 | -o disable-smoke-tests-cross-deployment-links.yml \
42 | -o disable-broker-route-registrar-cross-deployment-links.yml \
43 | -o disable-proxy-route-registrar-cross-deployment-links.yml \
44 |
45 | -v nats="{password: some-nats-password, user: nats, port: 4222, machines: [10.0.31.191]}" \
46 | -v admin_username=admin \
47 | -v admin_password=password \
48 | -v api_url=api.mycf.com \
49 | -v app_domains=[mycf.com] \
50 | -v skip_ssl_validation=true \
51 | ```
52 |
53 | ### [configure-broker-load-balancer.yml](https://github.com/cloudfoundry/cf-mysql-deployment/tree/master/operations/configure-broker-load-balancer.yml)
54 |
55 | Provides a value for the property `cf_mysql.host` property, which is host the
56 | broker provides to applications via service instance bindings.
57 |
58 | Typically this is a FQDN pointing to a load balancer or some other mechanism to
59 | achieve HA (e.g. DNS, floating virtual IPs etc).
60 |
61 | Example usage:
62 |
63 | ```
64 | -o configure-broker-load-balancer.yml \
65 |
66 | -v cf_mysql_host=my-load-balancer-url
67 | ```
68 |
--------------------------------------------------------------------------------
/operations/add-broker.yml:
--------------------------------------------------------------------------------
1 | ---
2 | - type: replace
3 | path: /releases/name=routing?
4 | value:
5 | name: routing
6 | version: "0.180.0"
7 | url: https://bosh.io/d/github.com/cloudfoundry-incubator/cf-routing-release?v=0.180.0
8 | sha1: 990c2c319e6063573eec18dbeb7c3631a382db7d
9 | - type: replace
10 | path: /releases/name=bpm?
11 | value:
12 | name: bpm
13 | version: "0.9.0"
14 | url: https://bosh.io/d/github.com/cloudfoundry-incubator/bpm-release?v=0.9.0
15 | sha1: 0cb3242063c95271c95b62de3a6d07072aff0b29
16 |
17 | - type: replace
18 | path: /instance_groups/-
19 | value:
20 | name: broker
21 | instances: 2
22 | azs: [z1,z2,z3]
23 | networks: [{name: default}]
24 | vm_type: default
25 | stemcell: default
26 | jobs:
27 | - name: cf-mysql-broker
28 | release: cf-mysql
29 | properties:
30 | cf:
31 | api_url: ((cf_api_url))
32 | skip_ssl_validation: ((cf_skip_ssl_validation))
33 | cf_mysql:
34 | broker:
35 | auth_password: ((cf_mysql_broker_auth_password))
36 | cookie_secret: ((cf_mysql_broker_cookie_secret))
37 | db_password: ((cf_mysql_broker_db_password))
38 | quota_enforcer:
39 | password: ((cf_mysql_broker_quota_enforcer_password))
40 | services: &broker_services
41 | - name: p-mysql
42 | id: 44b26033-1f54-4087-b7bc-da9652c2a539
43 | dashboard_client:
44 | id: p-mysql
45 | secret: ((cf_mysql_p_mysql_dashboard_secret))
46 | description: MySQL databases on demand
47 | metadata:
48 | displayName: MySQL for Pivotal Cloud Foundry
49 | documentationUrl: https://github.com/cloudfoundry/cf-mysql-release/blob/master/README.md
50 | imageUrl: 
51 | longDescription: Creating a service instance provisions a database. Binding
52 | applications provisions unique credentials for each application to access
53 | the database.
54 | providerDisplayName: Pivotal Software
55 | supportUrl: https://support.pivotal.io
56 | plan_updateable: true
57 | plans:
58 | - description: Shared MySQL Server
59 | id: ab08f1bc-e6fc-4b56-a767-ee0fea6e3f20
60 | max_storage_mb: 10
61 | max_user_connections: 20
62 | name: 10mb
63 | - description: Shared MySQL Server
64 | id: 11d0aa36-dcec-4021-85f5-ea4d9a5c8342
65 | max_storage_mb: 20
66 | max_user_connections: 40
67 | name: 20mb
68 | tags:
69 | - mysql
70 | external_host: ((cf_mysql_external_host))
71 | mysql:
72 | persistent_disk: 10000
73 | - name: route_registrar
74 | release: routing
75 | consumes:
76 | nats: {from: nats, deployment: cf}
77 | properties:
78 | route_registrar:
79 | routes:
80 | - name: cf-mysql-broker
81 | port: 8081 # must match the value of 'cf_mysql.broker.port'
82 | registration_interval: 10s
83 | uris:
84 | - ((cf_mysql_external_host))
85 | health_check:
86 | name: script
87 | script_path: /var/vcap/jobs/cf-mysql-broker/bin/healthcheck.sh
88 |
89 | - type: replace
90 | path: /instance_groups/-
91 | value:
92 | name: broker-registrar-vm
93 | instances: 1
94 | lifecycle: errand
95 | azs: [z1]
96 | networks: [{name: default}]
97 | vm_type: default
98 | stemcell: default
99 | jobs:
100 | - name: broker-registrar
101 | release: cf-mysql
102 | properties:
103 | cf:
104 | admin_username: admin
105 | admin_password: ((cf_admin_password))
106 | api_url: ((cf_api_url))
107 | skip_ssl_validation: ((cf_skip_ssl_validation))
108 | cf_mysql:
109 | broker:
110 | auth_password: ((cf_mysql_broker_auth_password))
111 | services: *broker_services
112 | external_host: ((cf_mysql_external_host))
113 |
114 | - type: replace
115 | path: /instance_groups/-
116 | value:
117 | name: deregister-and-purge-instances-vm
118 | instances: 1
119 | lifecycle: errand
120 | azs: [z1]
121 | networks: [{name: default}]
122 | vm_type: default
123 | stemcell: default
124 | jobs:
125 | - name: deregister-and-purge-instances
126 | release: cf-mysql
127 | properties:
128 | cf:
129 | admin_username: admin
130 | admin_password: ((cf_admin_password))
131 | api_url: ((cf_api_url))
132 | skip_ssl_validation: ((cf_skip_ssl_validation))
133 | cf_mysql:
134 | broker:
135 | services: *broker_services
136 |
137 | - type: replace
138 | path: /instance_groups/name=smoke-tests-vm/jobs/name=smoke-tests/properties/cf?/skip_ssl_validation
139 | value: ((cf_skip_ssl_validation))
140 |
141 | - type: replace
142 | path: /instance_groups/name=smoke-tests-vm/jobs/name=smoke-tests/properties/cf?/admin_username
143 | value: admin
144 |
145 | - type: replace
146 | path: /instance_groups/name=smoke-tests-vm/jobs/name=smoke-tests/properties/cf?/admin_password
147 | value: ((cf_admin_password))
148 |
149 | - type: replace
150 | path: /instance_groups/name=smoke-tests-vm/jobs/name=smoke-tests/properties/cf?/api_url
151 | value: ((cf_api_url))
152 |
153 | - type: replace
154 | path: /instance_groups/name=smoke-tests-vm/jobs/name=smoke-tests/properties/cf_mysql/smoke_tests/standalone_tests_only?
155 | value: false
156 |
157 | - type: replace
158 | path: /instance_groups/name=mysql/jobs/-
159 | value:
160 | name: cf-mysql-broker-user
161 | release: cf-mysql
162 |
163 | - type: remove
164 | path: /instance_groups/name=mysql/jobs/name=smoke-tests-user
165 |
166 | - type: remove
167 | path: /instance_groups/name=smoke-tests-vm/jobs/name=smoke-tests/properties/cf_mysql/smoke_tests/db_password
168 |
169 | - type: replace
170 | path: /instance_groups/name=smoke-tests-vm/jobs/name=smoke-tests/properties/cf_mysql/external_host?
171 | value: ((cf_mysql_external_host))
172 |
173 | - type: replace
174 | path: /instance_groups/name=smoke-tests-vm/jobs/name=smoke-tests/properties/cf_mysql/smoke_tests/password?
175 | value: ((cf_mysql_smoke_tests_password))
176 |
177 | - type: replace
178 | path: /instance_groups/name=smoke-tests-vm/jobs/name=smoke-tests/consumes?
179 | value:
180 | cloud_controller: {from: cloud_controller, deployment: cf}
181 |
182 | - type: replace
183 | path: /instance_groups/name=smoke-tests-vm/jobs/name=smoke-tests/properties/cf_mysql/broker?/services
184 | value: *broker_services
185 |
186 | - type: replace
187 | path: /variables/-
188 | value:
189 | name: cf_mysql_broker_auth_password
190 | type: password
191 |
192 | - type: replace
193 | path: /variables/-
194 | value:
195 | name: cf_mysql_broker_cookie_secret
196 | type: password
197 |
198 | - type: replace
199 | path: /variables/-
200 | value:
201 | name: cf_mysql_broker_db_password
202 | type: password
203 |
204 | - type: replace
205 | path: /variables/-
206 | value:
207 | name: cf_mysql_broker_quota_enforcer_password
208 | type: password
209 |
210 | - type: replace
211 | path: /variables/-
212 | value:
213 | name: cf_mysql_p_mysql_dashboard_secret
214 | type: password
215 |
216 | - type: replace
217 | path: /variables/-
218 | value:
219 | name: cf_mysql_smoke_tests_password
220 | type: password
221 |
--------------------------------------------------------------------------------
/operations/add-roadmin.yml:
--------------------------------------------------------------------------------
1 | - type: replace
2 | path: /instance_groups/name=mysql/jobs/name=mysql/properties/cf_mysql/mysql/roadmin_enabled?
3 | value: true
4 |
5 | - type: replace
6 | path: /instance_groups/name=mysql/jobs/name=mysql/properties/cf_mysql/mysql/roadmin_password?
7 | value: ((cf_mysql_mysql_roadmin_password))
8 |
9 | - type: replace
10 | path: /variables/-
11 | value:
12 | name: cf_mysql_mysql_roadmin_password
13 | type: password
14 |
--------------------------------------------------------------------------------
/operations/add-tls.yml:
--------------------------------------------------------------------------------
1 | ---
2 | - type: replace
3 | path: /instance_groups/name=mysql/jobs/name=mysql/properties/cf_mysql/mysql/tls?/ca_certificate
4 | value: ((cf_mysql_mysql_tls_server_certificate.ca))
5 |
6 | - type: replace
7 | path: /instance_groups/name=mysql/jobs/name=mysql/properties/cf_mysql/mysql/tls?/server_certificate
8 | value: ((cf_mysql_mysql_tls_server_certificate.certificate))
9 |
10 | - type: replace
11 | path: /instance_groups/name=mysql/jobs/name=mysql/properties/cf_mysql/mysql/tls?/server_key
12 | value: ((cf_mysql_mysql_tls_server_certificate.private_key))
13 |
14 | - type: replace
15 | path: /variables?/-
16 | value:
17 | name: cf_mysql_mysql_tls_server_certificate
18 | type: certificate
19 | options:
20 | common_name: ((cf_mysql_host))
21 | ca: trusted_cert_for_apps
22 |
--------------------------------------------------------------------------------
/operations/add-xenial-default-stemcell.yml:
--------------------------------------------------------------------------------
1 | ---
2 | - type: replace
3 | path: /stemcells/alias=default
4 | value:
5 | alias: trusty
6 | os: ubuntu-trusty
7 | version: latest
8 |
9 | - type: replace
10 | path: /stemcells/-
11 | value:
12 | alias: default
13 | os: ubuntu-xenial
14 | version: latest
15 |
--------------------------------------------------------------------------------
/operations/bosh-dns.yml:
--------------------------------------------------------------------------------
1 | ---
2 | - type: replace
3 | path: /instance_groups/name=proxy/jobs/name=proxy/properties/cf_mysql/proxy/shutdown_delay?
4 | value: 30
5 |
--------------------------------------------------------------------------------
/operations/bosh-lite.yml:
--------------------------------------------------------------------------------
1 | ---
2 | - type: replace
3 | path: /instance_groups/name=mysql/jobs/name=mysql/properties/cf_mysql/mysql/innodb_buffer_pool_size?
4 | value: 128M
5 |
--------------------------------------------------------------------------------
/operations/configure-broker-load-balancer.yml:
--------------------------------------------------------------------------------
1 | ---
2 | - type: replace
3 | path: /instance_groups/name=broker/jobs/name=cf-mysql-broker/properties/cf_mysql/host?
4 | value: ((cf_mysql_host))
5 |
--------------------------------------------------------------------------------
/operations/disable-broker-route-registrar-cross-deployment-links.yml:
--------------------------------------------------------------------------------
1 | ---
2 | - type: replace
3 | path: /instance_groups/name=broker/jobs/name=route_registrar?/consumes
4 | value:
5 | nats: nil
6 |
7 | - type: replace
8 | path: /instance_groups/name=broker/jobs/name=route_registrar?/properties/nats
9 | value: ((nats))
10 |
--------------------------------------------------------------------------------
/operations/disable-proxy-consul-cross-deployment-links.yml:
--------------------------------------------------------------------------------
1 | - type: replace
2 | path: /instance_groups/name=proxy/jobs/name=consul_agent/consumes?
3 | value:
4 | consul: nil
5 | consul_client: nil
6 | consul_common: nil
7 | consul_server: nil
8 |
9 | - type: replace
10 | path: /instance_groups/name=proxy/jobs/name=consul_agent/properties?/consul
11 | value:
12 | agent:
13 | datacenter:
14 | domain: cf.internal
15 | log_level:
16 | servers:
17 | lan: ((consul_agent_servers_lan))
18 | agent_cert: ((consul_agent_cert))
19 | agent_key: ((consul_agent_key))
20 | ca_cert: ((consul_ca_cert))
21 | encrypt_keys: ((consul_encrypt_keys))
22 | server_cert: ((consul_server_cert))
23 | server_key: ((consul_server_key))
24 |
--------------------------------------------------------------------------------
/operations/disable-proxy-route-registrar-cross-deployment-links.yml:
--------------------------------------------------------------------------------
1 | ---
2 | - type: replace
3 | path: /instance_groups/name=proxy/jobs/name=route_registrar?/consumes
4 | value:
5 | nats: nil
6 |
7 | - type: replace
8 | path: /instance_groups/name=proxy/jobs/name=route_registrar?/properties/nats
9 | value: ((nats))
10 |
--------------------------------------------------------------------------------
/operations/disable-smoke-tests-cross-deployment-links.yml:
--------------------------------------------------------------------------------
1 | ---
2 | - type: replace
3 | path: /instance_groups/name=smoke-tests-vm/jobs/name=smoke-tests/properties/cf?/app_domains
4 | value: ((app_domains))
5 |
6 | - type: replace
7 | path: /instance_groups/name=smoke-tests-vm/jobs/name=smoke-tests/consumes?
8 | value:
9 | cloud_controller: nil
10 |
--------------------------------------------------------------------------------
/operations/enable-syslog.yml:
--------------------------------------------------------------------------------
1 | ---
2 | - type: replace
3 | path: /addons?/-
4 | value:
5 | name: syslog_forwarder
6 | jobs:
7 | - name: syslog_forwarder
8 | release: syslog
9 | properties:
10 | syslog:
11 | address: ((syslog_address))
12 | port: ((syslog_port))
13 | transport: ((syslog_transport))
14 | forward_files: true
15 |
16 | - type: replace
17 | path: /releases/-
18 | value:
19 | name: syslog
20 | url: https://bosh.io/d/github.com/cloudfoundry/syslog-release?v=11
21 | version: '11'
22 | sha1: 332ac15609b220a3fdf5efad0e0aa069d8235788
23 |
--------------------------------------------------------------------------------
/operations/latest-versions.yml:
--------------------------------------------------------------------------------
1 | ---
2 | - type: replace
3 | path: /releases/name=cf-mysql
4 | value:
5 | name: cf-mysql
6 | version: latest
7 |
8 | - type: replace
9 | path: /stemcells/alias=default
10 | value:
11 | alias: default
12 | os: ubuntu-trusty
13 | version: latest
14 |
--------------------------------------------------------------------------------
/operations/no-arbitrator.yml:
--------------------------------------------------------------------------------
1 | ---
2 | - type: remove
3 | path: /instance_groups/name=arbitrator
4 |
5 | - type: replace
6 | path: /instance_groups/name=mysql/instances
7 | value: 3
8 |
9 | - type: replace
10 | path: /instance_groups/name=mysql/azs/-
11 | value: z3
12 |
--------------------------------------------------------------------------------
/operations/proxy-consul.yml:
--------------------------------------------------------------------------------
1 | ---
2 | - type: replace
3 | path: /releases/-
4 | value:
5 | name: consul
6 | version: latest
7 |
8 | - type: replace
9 | path: /instance_groups/name=proxy/jobs/-
10 | value:
11 | release: consul
12 | name: consul_agent
13 | consumes:
14 | consul_common: {from: consul_common_link, deployment: cf}
15 | consul_server: {from: consul_server_link, deployment: cf}
16 | consul_client: {from: consul_client_link, deployment: cf}
17 |
18 | - type: replace
19 | path: /instance_groups/name=proxy/jobs/name=proxy/properties/cf_mysql/proxy/consul_enabled?
20 | value: true
21 | - type: replace
22 | path: /instance_groups/name=proxy/jobs/name=proxy/properties/cf_mysql/proxy/consul_service_name?
23 | value: mysql
24 |
--------------------------------------------------------------------------------
/operations/proxy-elb.yml:
--------------------------------------------------------------------------------
1 | ---
2 | - type: replace
3 | path: /instance_groups/name=proxy/vm_extensions?/-
4 | value: ((proxy_vm_extension))
5 |
6 | - type: replace
7 | path: /instance_groups/name=smoke-tests-vm/jobs/name=smoke-tests/properties/cf_mysql/host?
8 | value: ((cf_mysql_host))
9 |
--------------------------------------------------------------------------------
/operations/register-proxy-route.yml:
--------------------------------------------------------------------------------
1 | ---
2 | - type: replace
3 | path: /releases/name=routing?
4 | value:
5 | name: routing
6 | version: "0.180.0"
7 | url: https://bosh.io/d/github.com/cloudfoundry-incubator/cf-routing-release?v=0.180.0
8 | sha1: 990c2c319e6063573eec18dbeb7c3631a382db7d
9 |
10 | - type: replace
11 | path: /releases/name=bpm?
12 | value:
13 | name: "bpm"
14 | version: "0.12.2"
15 | url: "https://bosh.io/d/github.com/cloudfoundry-incubator/bpm-release?v=0.12.2"
16 | sha1: "f2edbf3d1417a253205338c9941ca989cd2f8331"
17 |
18 | - type: replace
19 | path: /instance_groups/name=proxy/jobs/-
20 | value:
21 | release: routing
22 | name: route_registrar
23 | consumes:
24 | nats: {from: nats, deployment: cf}
25 | properties:
26 | route_registrar:
27 | routes:
28 | - name: cf-mysql-proxy
29 | port: 8080 # must match the value of 'cf_mysql.proxy.api_port'
30 | registration_interval: 10s
31 | uris:
32 | - &proxy_base_uri proxy-((cf_mysql_external_host))
33 | prepend_instance_index: true
34 | - name: cf-mysql-proxy-aggregator
35 | port: 8082 # must match the value of 'cf_mysql.proxy.api_aggregator_port'
36 | registration_interval: 10s
37 | uris:
38 | - *proxy_base_uri
39 | # The switchboard aggregator page assumes there is only a single route registered for the proxies
40 |
41 | # make sure to match what the route_registrar is registering above in cf-mysql-proxy route
42 | - type: replace
43 | path: /instance_groups/name=proxy/jobs/name=proxy/properties/cf_mysql/proxy/api_uri?
44 | value: *proxy_base_uri
45 |
--------------------------------------------------------------------------------
/operations/syslog-tls.yml:
--------------------------------------------------------------------------------
1 | ---
2 | - type: replace
3 | path: /addons/name=syslog_forwarder/jobs/name=syslog_forwarder/properties/syslog/tls_enabled?
4 | value: true
5 |
6 | - type: replace
7 | path: /addons/name=syslog_forwarder/jobs/name=syslog_forwarder/properties/syslog/permitted_peer?
8 | value: ((syslog_permitted_peer))
9 |
--------------------------------------------------------------------------------
/operations/test/enable-remote-admin-access.yml:
--------------------------------------------------------------------------------
1 | ---
2 | - type: replace
3 | path: /instance_groups/name=mysql/jobs/name=mysql/properties/cf_mysql/mysql/remote_admin_access?
4 | value: true
5 |
--------------------------------------------------------------------------------
/operations/test/minimal-mode.yml:
--------------------------------------------------------------------------------
1 | ---
2 | - type: replace
3 | path: /instance_groups/name=arbitrator/instances
4 | value: 0
5 | - type: replace
6 | path: /instance_groups/name=mysql/instances
7 | value: 1
8 | - type: replace
9 | path: /instance_groups/name=proxy/instances
10 | value: 1
11 |
12 |
--------------------------------------------------------------------------------
/operations/xenial-stemcell.yml:
--------------------------------------------------------------------------------
1 | ---
2 | - type: replace
3 | path: /stemcells/os=ubuntu-trusty
4 | value:
5 | alias: default
6 | os: ubuntu-xenial
7 | version: latest
8 |
9 |
--------------------------------------------------------------------------------
/scripts/deploy-cf-mysql-to-bosh-lite:
--------------------------------------------------------------------------------
1 | #!/bin/bash
2 |
3 | set -eux
4 |
5 | my_dir="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )"
6 | root_dir="$( cd "${my_dir}/.." && pwd )"
7 |
8 | export BOSH_ENVIRONMENT="${BOSH_ENVIRONMENT:-192.168.50.6}"
9 | export BOSH_DEPLOYMENT="${BOSH_DEPLOYMENT:-cf-mysql}"
10 |
11 | # Strip "api." prefix from the endpoint.
12 | root_endpoint=${CF_API_ENDPOINT#"api."}
13 |
14 | cf_mysql_host="${root_endpoint}"
15 | cf_mysql_external_host="p-mysql.${root_endpoint}"
16 |
17 | pushd "${root_dir}" > /dev/null
18 | bosh \
19 | deploy \
20 | "${root_dir}/cf-mysql-deployment.yml" \
21 | -o "${root_dir}/operations/bosh-lite.yml" \
22 | -o "${root_dir}/operations/xenial-stemcell.yml" \
23 | -l "${root_dir}/bosh-lite/default-vars.yml" \
24 | -v cf_mysql_external_host="${cf_mysql_external_host}" \
25 | -v cf_mysql_host="${cf_mysql_host}" \
26 | -v cf_api_url="https://${CF_API_ENDPOINT}" \
27 | --no-redact \
28 | "$@"
29 | popd > /dev/null
30 |
--------------------------------------------------------------------------------
/scripts/deploy-cf-mysql-with-broker-to-bosh-lite:
--------------------------------------------------------------------------------
1 | #!/bin/bash
2 |
3 | set -eu
4 |
5 | my_dir="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )"
6 | root_dir="$( cd "${my_dir}/.." && pwd )"
7 |
8 | if [[ -z "${CF_API_ENDPOINT}" ]]; then
9 | echo "\$CF_API_ENDPOINT is not set. You probably forgot to target your environment."
10 | echo "These BOSH variables may need to be changed:"
11 | echo " cf_mysql_external_host, cf_mysql_host, cf_api_url"
12 | fi
13 |
14 | # Strip "api." prefix from the endpoint.
15 | root_endpoint=${CF_API_ENDPOINT#"api."}
16 |
17 | cf_mysql_host="${root_endpoint}"
18 | cf_mysql_external_host="p-mysql.${root_endpoint}"
19 |
20 | "${my_dir}/deploy-cf-mysql-to-bosh-lite" \
21 | -o "${root_dir}/operations/add-broker.yml" \
22 | -o "${root_dir}/operations/register-proxy-route.yml" \
23 | -v cf_mysql_external_host="${cf_mysql_external_host}" \
24 | -v cf_mysql_host="${cf_mysql_host}" \
25 | -v cf_api_url="https://${CF_API_ENDPOINT}" \
26 | "$@"
27 |
--------------------------------------------------------------------------------