├── LICENSE ├── NOTICE ├── README.md ├── bosh-lite ├── cloud-config.yml └── default-vars.yml ├── cf-mysql-deployment.yml ├── docs └── using-cf-mysql.md ├── githooks └── pre-push ├── operations ├── README.md ├── add-broker.yml ├── add-roadmin.yml ├── add-tls.yml ├── add-xenial-default-stemcell.yml ├── bosh-dns.yml ├── bosh-lite.yml ├── configure-broker-load-balancer.yml ├── disable-broker-route-registrar-cross-deployment-links.yml ├── disable-proxy-consul-cross-deployment-links.yml ├── disable-proxy-route-registrar-cross-deployment-links.yml ├── disable-smoke-tests-cross-deployment-links.yml ├── enable-syslog.yml ├── latest-versions.yml ├── no-arbitrator.yml ├── proxy-consul.yml ├── proxy-elb.yml ├── register-proxy-route.yml ├── syslog-tls.yml ├── test │ ├── enable-remote-admin-access.yml │ └── minimal-mode.yml └── xenial-stemcell.yml └── scripts ├── deploy-cf-mysql-to-bosh-lite └── deploy-cf-mysql-with-broker-to-bosh-lite /LICENSE: -------------------------------------------------------------------------------- 1 | 2 | Apache License 3 | Version 2.0, January 2004 4 | http://www.apache.org/licenses/ 5 | 6 | TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION 7 | 8 | 1. Definitions. 9 | 10 | "License" shall mean the terms and conditions for use, reproduction, 11 | and distribution as defined by Sections 1 through 9 of this document. 12 | 13 | "Licensor" shall mean the copyright owner or entity authorized by 14 | the copyright owner that is granting the License. 15 | 16 | "Legal Entity" shall mean the union of the acting entity and all 17 | other entities that control, are controlled by, or are under common 18 | control with that entity. For the purposes of this definition, 19 | "control" means (i) the power, direct or indirect, to cause the 20 | direction or management of such entity, whether by contract or 21 | otherwise, or (ii) ownership of fifty percent (50%) or more of the 22 | outstanding shares, or (iii) beneficial ownership of such entity. 23 | 24 | "You" (or "Your") shall mean an individual or Legal Entity 25 | exercising permissions granted by this License. 26 | 27 | "Source" form shall mean the preferred form for making modifications, 28 | including but not limited to software source code, documentation 29 | source, and configuration files. 30 | 31 | "Object" form shall mean any form resulting from mechanical 32 | transformation or translation of a Source form, including but 33 | not limited to compiled object code, generated documentation, 34 | and conversions to other media types. 35 | 36 | "Work" shall mean the work of authorship, whether in Source or 37 | Object form, made available under the License, as indicated by a 38 | copyright notice that is included in or attached to the work 39 | (an example is provided in the Appendix below). 40 | 41 | "Derivative Works" shall mean any work, whether in Source or Object 42 | form, that is based on (or derived from) the Work and for which the 43 | editorial revisions, annotations, elaborations, or other modifications 44 | represent, as a whole, an original work of authorship. For the purposes 45 | of this License, Derivative Works shall not include works that remain 46 | separable from, or merely link (or bind by name) to the interfaces of, 47 | the Work and Derivative Works thereof. 48 | 49 | "Contribution" shall mean any work of authorship, including 50 | the original version of the Work and any modifications or additions 51 | to that Work or Derivative Works thereof, that is intentionally 52 | submitted to Licensor for inclusion in the Work by the copyright owner 53 | or by an individual or Legal Entity authorized to submit on behalf of 54 | the copyright owner. For the purposes of this definition, "submitted" 55 | means any form of electronic, verbal, or written communication sent 56 | to the Licensor or its representatives, including but not limited to 57 | communication on electronic mailing lists, source code control systems, 58 | and issue tracking systems that are managed by, or on behalf of, the 59 | Licensor for the purpose of discussing and improving the Work, but 60 | excluding communication that is conspicuously marked or otherwise 61 | designated in writing by the copyright owner as "Not a Contribution." 62 | 63 | "Contributor" shall mean Licensor and any individual or Legal Entity 64 | on behalf of whom a Contribution has been received by Licensor and 65 | subsequently incorporated within the Work. 66 | 67 | 2. Grant of Copyright License. Subject to the terms and conditions of 68 | this License, each Contributor hereby grants to You a perpetual, 69 | worldwide, non-exclusive, no-charge, royalty-free, irrevocable 70 | copyright license to reproduce, prepare Derivative Works of, 71 | publicly display, publicly perform, sublicense, and distribute the 72 | Work and such Derivative Works in Source or Object form. 73 | 74 | 3. Grant of Patent License. Subject to the terms and conditions of 75 | this License, each Contributor hereby grants to You a perpetual, 76 | worldwide, non-exclusive, no-charge, royalty-free, irrevocable 77 | (except as stated in this section) patent license to make, have made, 78 | use, offer to sell, sell, import, and otherwise transfer the Work, 79 | where such license applies only to those patent claims licensable 80 | by such Contributor that are necessarily infringed by their 81 | Contribution(s) alone or by combination of their Contribution(s) 82 | with the Work to which such Contribution(s) was submitted. If You 83 | institute patent litigation against any entity (including a 84 | cross-claim or counterclaim in a lawsuit) alleging that the Work 85 | or a Contribution incorporated within the Work constitutes direct 86 | or contributory patent infringement, then any patent licenses 87 | granted to You under this License for that Work shall terminate 88 | as of the date such litigation is filed. 89 | 90 | 4. Redistribution. You may reproduce and distribute copies of the 91 | Work or Derivative Works thereof in any medium, with or without 92 | modifications, and in Source or Object form, provided that You 93 | meet the following conditions: 94 | 95 | (a) You must give any other recipients of the Work or 96 | Derivative Works a copy of this License; and 97 | 98 | (b) You must cause any modified files to carry prominent notices 99 | stating that You changed the files; and 100 | 101 | (c) You must retain, in the Source form of any Derivative Works 102 | that You distribute, all copyright, patent, trademark, and 103 | attribution notices from the Source form of the Work, 104 | excluding those notices that do not pertain to any part of 105 | the Derivative Works; and 106 | 107 | (d) If the Work includes a "NOTICE" text file as part of its 108 | distribution, then any Derivative Works that You distribute must 109 | include a readable copy of the attribution notices contained 110 | within such NOTICE file, excluding those notices that do not 111 | pertain to any part of the Derivative Works, in at least one 112 | of the following places: within a NOTICE text file distributed 113 | as part of the Derivative Works; within the Source form or 114 | documentation, if provided along with the Derivative Works; or, 115 | within a display generated by the Derivative Works, if and 116 | wherever such third-party notices normally appear. The contents 117 | of the NOTICE file are for informational purposes only and 118 | do not modify the License. You may add Your own attribution 119 | notices within Derivative Works that You distribute, alongside 120 | or as an addendum to the NOTICE text from the Work, provided 121 | that such additional attribution notices cannot be construed 122 | as modifying the License. 123 | 124 | You may add Your own copyright statement to Your modifications and 125 | may provide additional or different license terms and conditions 126 | for use, reproduction, or distribution of Your modifications, or 127 | for any such Derivative Works as a whole, provided Your use, 128 | reproduction, and distribution of the Work otherwise complies with 129 | the conditions stated in this License. 130 | 131 | 5. Submission of Contributions. Unless You explicitly state otherwise, 132 | any Contribution intentionally submitted for inclusion in the Work 133 | by You to the Licensor shall be under the terms and conditions of 134 | this License, without any additional terms or conditions. 135 | Notwithstanding the above, nothing herein shall supersede or modify 136 | the terms of any separate license agreement you may have executed 137 | with Licensor regarding such Contributions. 138 | 139 | 6. Trademarks. This License does not grant permission to use the trade 140 | names, trademarks, service marks, or product names of the Licensor, 141 | except as required for reasonable and customary use in describing the 142 | origin of the Work and reproducing the content of the NOTICE file. 143 | 144 | 7. Disclaimer of Warranty. Unless required by applicable law or 145 | agreed to in writing, Licensor provides the Work (and each 146 | Contributor provides its Contributions) on an "AS IS" BASIS, 147 | WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or 148 | implied, including, without limitation, any warranties or conditions 149 | of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A 150 | PARTICULAR PURPOSE. You are solely responsible for determining the 151 | appropriateness of using or redistributing the Work and assume any 152 | risks associated with Your exercise of permissions under this License. 153 | 154 | 8. Limitation of Liability. In no event and under no legal theory, 155 | whether in tort (including negligence), contract, or otherwise, 156 | unless required by applicable law (such as deliberate and grossly 157 | negligent acts) or agreed to in writing, shall any Contributor be 158 | liable to You for damages, including any direct, indirect, special, 159 | incidental, or consequential damages of any character arising as a 160 | result of this License or out of the use or inability to use the 161 | Work (including but not limited to damages for loss of goodwill, 162 | work stoppage, computer failure or malfunction, or any and all 163 | other commercial damages or losses), even if such Contributor 164 | has been advised of the possibility of such damages. 165 | 166 | 9. Accepting Warranty or Additional Liability. While redistributing 167 | the Work or Derivative Works thereof, You may choose to offer, 168 | and charge a fee for, acceptance of support, warranty, indemnity, 169 | or other liability obligations and/or rights consistent with this 170 | License. However, in accepting such obligations, You may act only 171 | on Your own behalf and on Your sole responsibility, not on behalf 172 | of any other Contributor, and only if You agree to indemnify, 173 | defend, and hold each Contributor harmless for any liability 174 | incurred by, or claims asserted against, such Contributor by reason 175 | of your accepting any such warranty or additional liability. 176 | 177 | END OF TERMS AND CONDITIONS 178 | -------------------------------------------------------------------------------- /NOTICE: -------------------------------------------------------------------------------- 1 | Copyright (c) 2015-Present CloudFoundry.org Foundation, Inc. All Rights Reserved. 2 | 3 | This project is licensed to you under the Apache License, Version 2.0 (the "License"). 4 | 5 | You may not use this project except in compliance with the License. 6 | 7 | This project may include a number of subcomponents with separate copyright notices 8 | and license terms. Your use of these subcomponents is subject to the terms and 9 | conditions of the subcomponent's license, as noted in the LICENSE file. 10 | -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- 1 | DEPRECATED: cf-mysql-release is deprecated and this repo is no longer maintained. 2 | 3 | See [pxc-release](https://github.com/cloudfoundry/pxc-release) 4 | 5 | # Cloud Foundry MySQL Bosh Deployment 6 | 7 | ## Table of contents 8 | 9 | [Usage](#usage) 10 | 11 | [Deploying](#deploying) 12 | 13 | [Security Groups](#security-groups) 14 | 15 | [Registering the Service Broker](#registering-broker) 16 | 17 | [Smoke Tests](#smoke-tests) 18 | 19 | [Deregistering the Service Broker](#deregistering-broker) 20 | 21 | 22 | This repo contains a BOSH 2 manifest that defines tested topologies of cf-mysql-release. 23 | 24 | It serves as the reference for the compatible release and stemcell versions. 25 | 26 | This repo takes advantage of new features such as: 27 | 28 | - [cloud config](https://bosh.io/docs/cloud-config.html) 29 | - [job links](https://bosh.io/docs/links.html) 30 | - [new CLI](https://github.com/cloudfoundry/bosh-cli) 31 | - The new BOSH CLI must be installed according to the instructions [here](https://bosh.io/docs/cli-v2.html). 32 | 33 | Please refer to BOSH documentation for more details. If you're having troubles 34 | with the pre-requisites, please contact the BOSH team for help 35 | (perhaps on [slack](https://slack.cloudfoundry.org/)). 36 | 37 | 38 | ## Usage 39 | 40 | ### Prerequisites 41 | 42 | - A deployment of [BOSH](https://github.com/cloudfoundry/bosh) 43 | - A deployment of [Cloud Foundry](https://github.com/cloudfoundry/cf-release), [final release 193](https://github.com/cloudfoundry/cf-release/tree/v193) or greater 44 | - Instructions for installing BOSH and Cloud Foundry can be found at http://docs.cloudfoundry.org/. 45 | - [Routing release](https://github.com/cloudfoundry-incubator/routing-release) 46 | v0.145.0 or later is required to register the proxy and broker routes with 47 | Cloud Foundry: 48 | 49 | ```bash 50 | bosh upload release https://bosh.io/d/github.com/cloudfoundry-incubator/cf-routing-release?v=0.145.0 51 | ``` 52 | 53 | Standalone deployments (i.e. deployments that do not interact with Cloud Foundry) 54 | do not require the routing release. 55 | 56 | 57 | ### Upload Stemcell 58 | 59 | The latest final release expects the Ubuntu Trusty (14.04) go_agent stemcell version [2859](https://github.com/cloudfoundry/bosh/blob/master/CHANGELOG.md#2859) by default. Older stemcells are not recommended. Stemcells can be downloaded from http://bosh.io/stemcells; choose the appropriate stemcell for your infrastructure ([vsphere esxi](https://d26ekeud912fhb.cloudfront.net/bosh-stemcell/vsphere/bosh-stemcell-2859-vsphere-esxi-ubuntu-trusty-go_agent.tgz), [aws hvm](https://d26ekeud912fhb.cloudfront.net/bosh-stemcell/aws/light-bosh-stemcell-2859-aws-xen-hvm-ubuntu-trusty-go_agent.tgz), or [openstack kvm](https://d26ekeud912fhb.cloudfront.net/bosh-stemcell/openstack/bosh-stemcell-2859-openstack-kvm-ubuntu-trusty-go_agent.tgz)). 60 | 61 | 62 | ### Upload Release 63 | 64 | You can use a pre-built final release or build a dev release from any of the branches described in Getting the Code. 65 | 66 | Final releases are stable releases created periodically for completed features. They also contain pre-compiled packages, which makes deployment much faster. To deploy the latest final release, simply check out the **master** branch. This will contain the latest final release and accompanying materials to generate a manifest. If you would like to deploy an earlier final release, use `git checkout ` to obtain both the release and corresponding manifest generation materials. It's important that the manifest generation materials are consistent with the release. 67 | 68 | If you'd like to deploy the latest code, build a release yourself from the **develop** branch. 69 | 70 | #### Create and upload a BOSH Release: 71 | 72 | 1. Build the development release. 73 | 74 | ``` 75 | $ cd ~/workspace/cf-mysql-release 76 | $ git checkout release-candidate 77 | $ ./scripts/update 78 | $ bosh2 create-release 79 | ``` 80 | 81 | 1. Upload the release to your bosh environment: 82 | 83 | ``` 84 | $ bosh2 -e YOUR_ENV upload-release 85 | ``` 86 | 87 | 88 | ### Create Infrastructure 89 | 90 | #### Define subnets 91 | 92 | Prior to deployment, the operator should define three subnets via their infrastructure provider. 93 | The MySQL release is designed to be deployed across three subnets to ensure availability in the event of a subnet failure. 94 | 95 | #### Create load balancer 96 | 97 | In order to route requests to both proxies, the operator should create a load balancer. 98 | Manifest changes required to configure a load balancer can be found in the 99 | [proxy](https://github.com/cloudfoundry/cf-mysql-release/blob/master/docs/proxy.md#configuring-load-balancer) documentation. 100 | Once a load balancer is configured, the brokers will hand out the address of the load balancer rather than the IP of the first proxy. 101 | 102 | - **Note:** When using an Elastic Load Balancer (ELB) on Amazon, make sure to create the ELB in the same VPC as your cf-mysql deployment 103 | - **Note:** For all load balancers, take special care to configure health checks to use the health_port of the proxies (default 1936). Do not configure the load balancer health check to use port 3306. 104 | - **You must use the IP address(es) of your load balancer in the p-mysql [security group](#security-groups)**, below. Otherwise, applications will not be able to connect to the database. 105 | 106 | There are two ways to configure a load balancer, either automatically through your IaaS or by supplying static IPs for the proxies 107 | 108 | ##### For IaaS native load balancers (AWS elb, GCP target_pool, etc) 109 | 110 | In order for the MySQL deployment to attach the proxy instances to your configured load balancer, you need to use the [proxy-elb.yml](https://github.com/cloudfoundry/cf-mysql-deployment/blob/develop/operations/proxy-elb.yml) opsfile. This opsfile requires a [vm_extension](https://bosh.io/docs/cloud-config.html#vm-extensions) in your [cloud-config](https://bosh.io/docs/cloud-config.html) which references your load balancer and also defines the specific requirements for your IaaS. You'll need to consult your IaaS documentation as well as your BOSH CPI documentation for the specifics of the `cloud_properties` definitions for use in your `vm_extension`. You can read more specifics about configuration of the proxies [here](https://github.com/cloudfoundry/cf-mysql-release/blob/develop/docs/proxy.md). 111 | 112 | ##### For custom load balancers (haproxy, f5, etc) 113 | 114 | If you would like to use a custom load balancer, you can manually configure your proxies to use static IP addresses which your load balancer can point to. To do that, create an operations file that looks like the following, with static IPs that make sense for your network: 115 | ```yaml 116 | - type: replace 117 | path: /instance_groups/name=proxy/networks 118 | value: 119 | - name: default 120 | static_ips: 121 | - 10.10.0.1 122 | - 10.10.0.2 123 | ``` 124 | 125 | 126 | ## Deploying 127 | ### Deployment Components 128 | 129 | #### Database nodes 130 | 131 | The number of mysql nodes should always be odd, with a minimum count of three, to avoid [split-brain](http://en.wikipedia.org/wiki/Split-brain\_\(computing\)). 132 | When the failed node comes back online, it will automatically rejoin the cluster and sync data from one of the healthy nodes. 133 | 134 | The MariaDB cluster nodes are configured by default with 10GB of persistent disk. This can be configured using an operations file to change `instance_groups/name=mysql/persistent_disk` and `properties/cf_mysql/mysql/persistent_disk`, however your deployment will fail if this is less than 3GB. 135 | 136 | #### Proxy nodes 137 | 138 | There are two proxy instances. The second proxy is intended to be used in a failover capacity. 139 | In the event the first proxy fails, the second proxy will still be able to route requests to the mysql nodes. 140 | 141 | #### Broker nodes 142 | 143 | There are also two broker instances. 144 | The brokers each register a route with the router, which load balances requests across the brokers. 145 | 146 | ### New deployments 147 | 148 | New deployments will work "out of the box" with little additional configuration. 149 | There are two mechanisms for providing credentials to the deployment: 150 | 151 | - Credentials can be provided with `-l ` (see below for more 152 | information on variable files). 153 | - variables store file should be provided with 154 | `--vars-store ` to let the CLI generate secure passwords 155 | and write them to the provided vars store file. 156 | 157 | By default the deployment manifest will not deploy brokers, nor try to register 158 | routes for the proxies with a Cloud Foundry router. To enable integration with 159 | Cloud Foundry, operations files are provided to 160 | [add brokers](https://github.com/cloudfoundry/cf-mysql-deployment/tree/master/operations/add-broker.yml) 161 | and 162 | [register proxy routes](https://github.com/cloudfoundry/cf-mysql-deployment/tree/master/operations/register-proxy-route.yml). 163 | 164 | If you require static IPs for the proxy instance groups, these IPs should be 165 | added to the `networks` section of the cloud-config as well as to an operations file 166 | which will use these IPs for the proxy instance groups. See below for more 167 | information on operations files. 168 | 169 | ```sh 170 | bosh \ 171 | -e my-director \ 172 | -d cf-mysql \ 173 | deploy \ 174 | ~/workspace/cf-mysql-deployment/cf-mysql-deployment.yml \ 175 | -o 176 | ``` 177 | 178 | ### Upgrading from previous deployment topologies 179 | 180 | If you are upgrading an existing deployment of cf-mysql-release with a manifest 181 | that does not take advantage of these new features, for example if the manifest 182 | was generated via the spiff templates and stubs provided in the cf-mysql-release 183 | repository, then be aware: 184 | 185 | 1. The base manifest refers to AZs called `z1`, `z2`, and `z3`. If your 186 | cloud-config doesn't have those AZs, it will result in an error. 187 | 1. The base manifest will not deploy brokers, nor try to register routes for the proxies with a Cloud Foundry router. If you wish to preserve this behavior you will need to include the [add brokers](https://github.com/cloudfoundry/cf-mysql-deployment/tree/master/operations/add-broker.yml) and [register proxy routes](https://github.com/cloudfoundry/cf-mysql-deployment/tree/master/operations/register-proxy-route.yml) operations files. 188 | 1. Create custom operations files to map any non-default configuration (e.g. the number of maximum connections). 189 | 1. Create a custom operation file to migrate your BOSH 1 `jobs` and static IPs to their new BOSH 2 `instance_groups`. See the section below for [more information](#operations-file-for-migrating-from-bosh-1-style-manifest-to-a-bosh-2-style-manifest). 190 | 1. Create a variables file to contain the credentials of the existing deployment. 191 | - Using `--vars-store` is not recommended as it will result in credentials being rotated which can cause issues. 192 | 1. Run the following command: 193 | 194 | ```sh 195 | bosh \ 196 | -e my-director \ 197 | -d my-deployment \ 198 | deploy \ 199 | ~/workspace/cf-mysql-deployment/cf-mysql-deployment.yml \ 200 | -o \ 201 | [-o ] \ 202 | -l \ 203 | [-l ] 204 | ``` 205 | 206 | #### Operations file for migrating from BOSH 1 style manifest to a BOSH 2 style manifest 207 | Refer to [these docs](https://bosh.io/docs/migrated-from.html) on migrating from a BOSH 1 style manifest, then create an ops file to mix in those migrations into the base deployment manifest. See below for an example: 208 | 209 | ```yaml 210 | 211 | --- 212 | - type: replace 213 | path: /instance_groups/name=mysql/migrated_from? 214 | value: 215 | - name: mysql_z1 216 | az: z1 217 | - name: mysql_z2 218 | az: z2 219 | - name: mysql_z3 220 | az: z3 221 | 222 | - type: replace 223 | path: /instance_groups/name=mysql/networks 224 | value: 225 | - name: default 226 | static_ips: 227 | - 10.10.0.1 228 | - 10.10.0.2 229 | - 10.10.0.3 230 | ``` 231 | 232 | ## Operations files 233 | 234 | Additional example operations files used for common configurations of `cf-mysql-release` (e.g. adding a broker for 235 | Cloud Foundry integration) can be found in the [operations](https://github.com/cloudfoundry/cf-mysql-deployment/tree/master/operations) 236 | directory. See the README in that directory for a description of which (combinations) of files to use for enabling each common feature set. 237 | 238 | The [manifest template](https://github.com/cloudfoundry/cf-mysql-deployment/tree/master/cf-mysql-deployment.yml) 239 | is not intended to be modified; any changes you need to make should be added to operations files. 240 | 241 | The syntax for operations files is detailed 242 | [here](http://bosh.io/docs/cli-ops-files.html). 243 | 244 | Operations files can be provided at deploy-time as follows: 245 | 246 | ```sh 247 | bosh \ 248 | deploy \ 249 | -o 250 | ``` 251 | 252 | ### Variables files 253 | 254 | Variables files are a flat-format key-value yaml file which contains sensitive 255 | information such as passwords, ssl keys/certs etc. 256 | 257 | They can be provided at deploy-time as follows: 258 | 259 | ```sh 260 | bosh \ 261 | deploy \ 262 | -l 263 | ``` 264 | 265 | We provide a default set of variables intended for a local bosh-lite environment 266 | [here](https://github.com/cloudfoundry/cf-mysql-deployment/tree/master/bosh-lite/default-vars.yml). 267 | 268 | Use this as an example for your environment-specific variables file. 269 | 270 | ### Cross-deployment links 271 | 272 | By default, this deployment assumes that some variables (e.g. nats) are provided 273 | by cross-deployment links from a deployment named `cf`. 274 | This will be true if Cloud Foundry was deployed via 275 | [cf-deployment](https://github.com/cloudfoundry/cf-deployment). 276 | 277 | If you wish to disable cross-deployment links, use the 278 | `disable-cross-deployment-links.yml` operations file. 279 | 280 | Disabling cross-deployment links will require these values to be provided 281 | manually (e.g. by passing `-v nats={...}` to the `bosh deploy` command). 282 | 283 | 284 | ## Security Groups 285 | 286 | By default, applications cannot to connect to IP addresses on the private network, 287 | preventing applications from connecting to the MySQL service. 288 | To enable access to the service, create a new security group for the IP 289 | configured in your manifest for the property `jobs.cf-mysql-broker.mysql_node.host`. 290 | 291 | Note: This is not required for CF running on bosh-lite, as these application 292 | groups are pre-configured. 293 | 294 | 1. Add the rule to a file in the following json format; multiple rules are supported. 295 | 296 | ``` 297 | [ 298 | { 299 | "destination": "10.10.163.1-10.10.163.255", 300 | "protocol": "all" 301 | }, 302 | { 303 | "destination": "10.10.164.1-10.10.164.255", 304 | "protocol": "all" 305 | }, 306 | { 307 | "destination": "10.10.165.1-10.10.165.255", 308 | "protocol": "all" 309 | } 310 | ] 311 | ``` 312 | 313 | - Create a security group from the rule file. 314 | 315 | ```shell 316 | $ cf create-security-group p-mysql rule.json 317 | ``` 318 | 319 | - Enable the rule for all apps 320 | 321 | ```shell 322 | $ cf bind-running-security-group p-mysql 323 | ``` 324 | 325 | Security group changes are only applied to new application containers; 326 | existing apps must be restarted. 327 | 328 | 329 | ## Registering the Service Broker 330 | 331 | After registering the service broker, the MySQL service will be visible in the Services Marketplace; using the [CLI](https://github.com/cloudfoundry/cli), run `cf marketplace`. 332 | 333 | ### BOSH errand 334 | 335 | ``` 336 | $ bosh2 -e YOUR_ENV -d cf-mysql run-errand broker-registrar 337 | ``` 338 | 339 | ### Manually 340 | 341 | 1. First register the broker using the `cf` CLI. You must be logged in as an admin. 342 | 343 | ``` 344 | $ cf create-service-broker p-mysql BROKER_USERNAME BROKER_PASSWORD URL 345 | ``` 346 | 347 | `BROKER_USERNAME` and `BROKER_PASSWORD` are the credentials Cloud Foundry will use to authenticate when making API calls to the service broker. Use the values for manifest properties `jobs.cf-mysql-broker.properties.auth_username` and `jobs.cf-mysql-broker.properties.auth_password`. 348 | 349 | `URL` specifies where the Cloud Controller will access the MySQL broker. Use the value of the manifest property `jobs.cf-mysql-broker.properties.external_host`. By default, this value is set to `p-mysql.` (in spiff: `"p-mysql." .properties.domain`). 350 | 351 | For more information, see [Managing Service Brokers](http://docs.cloudfoundry.org/services/managing-service-brokers.html). 352 | 353 | 2. Then [make the service plan public](http://docs.cloudfoundry.org/services/managing-service-brokers.html#make-plans-public). 354 | 355 | 356 | 357 | ## Smoke Tests 358 | 359 | The smoke tests are useful for verifying a deployment. 360 | The MySQL Release contains an "smoke-tests" job which is deployed as a BOSH errand. 361 | 362 | ### Running Smoke Tests via BOSH errand 363 | 364 | Run the smoke tests via bosh errand as follows: 365 | 366 | ``` 367 | $ bosh2 -e YOUR_ENV -d cf-mysql run-errand smoke-tests 368 | ``` 369 | 370 | 371 | ## De-registering the Service Broker 372 | 373 | The following commands are destructive and are intended to be run in conjuction with deleting your BOSH deployment. 374 | ``` 375 | $ bosh2 -e YOUR_ENV -d cf-mysql run-errand deregister-and-purge-instances 376 | ``` 377 | 378 | ### Manually 379 | 380 | Run the following: 381 | 382 | ``` 383 | $ cf purge-service-offering p-mysql 384 | $ cf delete-service-broker p-mysql 385 | ``` 386 | 387 | -------------------------------------------------------------------------------- /bosh-lite/cloud-config.yml: -------------------------------------------------------------------------------- 1 | azs: 2 | - name: z1 3 | - name: z2 4 | - name: z3 5 | vm_types: 6 | - name: default 7 | cloud_properties: 8 | ephemeral_disk: 9 | size: 1024 10 | type: gp2 11 | - name: micro 12 | cloud_properties: 13 | ephemeral_disk: 14 | size: 1024 15 | type: gp2 16 | compilation: 17 | workers: 4 18 | network: default 19 | az: z1 20 | reuse_compilation_vms: true 21 | vm_type: default 22 | networks: 23 | - name: default 24 | subnets: 25 | - az: z1 26 | range: 10.244.7.0/24 27 | gateway: 10.244.7.1 28 | cloud_properties: 29 | name: random 30 | - az: z2 31 | range: 10.244.8.0/24 32 | gateway: 10.244.8.1 33 | cloud_properties: 34 | name: random 35 | - az: z3 36 | range: 10.244.9.0/24 37 | gateway: 10.244.9.1 38 | cloud_properties: 39 | name: random 40 | vm_extensions: 41 | - name: mysql-proxy-lb 42 | cloud_properties: 43 | ports: 44 | - host: 3306 45 | -------------------------------------------------------------------------------- /bosh-lite/default-vars.yml: -------------------------------------------------------------------------------- 1 | --- 2 | cf_mysql_external_host: p-mysql.bosh-lite.com 3 | cf_mysql_host: bosh-lite.com 4 | cf_admin_password: REPLACE_WITH_CF_ADMIN_PASSWORD 5 | cf_api_url: https://api.bosh-lite.com 6 | cf_skip_ssl_validation: true 7 | proxy_vm_extension: mysql-proxy-lb 8 | -------------------------------------------------------------------------------- /cf-mysql-deployment.yml: -------------------------------------------------------------------------------- 1 | name: cf-mysql 2 | 3 | addons: 4 | - name: bpm 5 | jobs: 6 | - name: bpm 7 | release: bpm 8 | 9 | update: 10 | canaries: 1 11 | canary_watch_time: 10000-600000 12 | update_watch_time: 10000-600000 13 | max_in_flight: 1 14 | serial: true 15 | 16 | instance_groups: 17 | - name: mysql 18 | instances: 2 19 | azs: [z1, z2] 20 | networks: [{name: default}] 21 | vm_type: default 22 | stemcell: default 23 | persistent_disk: 10000 24 | jobs: 25 | - name: mysql 26 | release: cf-mysql 27 | properties: 28 | cf_mysql: 29 | mysql: 30 | admin_password: ((cf_mysql_mysql_admin_password)) 31 | cluster_health: 32 | password: ((cf_mysql_mysql_cluster_health_password)) 33 | galera_healthcheck: 34 | endpoint_password: ((cf_mysql_mysql_galera_healthcheck_endpoint_password)) 35 | db_password: ((cf_mysql_mysql_galera_healthcheck_db_password)) 36 | - name: smoke-tests-user 37 | release: cf-mysql 38 | properties: 39 | cf_mysql: 40 | smoke_tests: 41 | db_password: ((cf_mysql_smoke_tests_db_password)) 42 | 43 | - name: arbitrator 44 | instances: 1 45 | azs: [z3] 46 | networks: [{name: default}] 47 | vm_type: default 48 | stemcell: default 49 | jobs: 50 | - release: cf-mysql 51 | name: arbitrator 52 | properties: 53 | cf_mysql: 54 | mysql: 55 | admin_password: ((cf_mysql_mysql_admin_password)) 56 | galera_healthcheck: 57 | endpoint_password: ((cf_mysql_mysql_galera_healthcheck_endpoint_password)) 58 | 59 | - name: proxy 60 | instances: 2 61 | azs: [z1, z2] 62 | networks: [{name: default}] 63 | vm_type: default 64 | stemcell: default 65 | jobs: 66 | - name: proxy 67 | release: cf-mysql 68 | properties: 69 | cf_mysql: 70 | proxy: 71 | api_password: ((cf_mysql_proxy_api_password)) 72 | provides: 73 | mysql-database: 74 | as: mysql-database 75 | shared: true 76 | 77 | - name: bootstrap-vm 78 | instances: 1 79 | lifecycle: errand 80 | azs: [z1] 81 | networks: [{name: default}] 82 | vm_type: default 83 | stemcell: default 84 | jobs: 85 | - {release: cf-mysql, name: bootstrap} 86 | 87 | - name: rejoin-unsafe-vm 88 | instances: 1 89 | lifecycle: errand 90 | azs: [z1] 91 | networks: [{name: default}] 92 | vm_type: default 93 | stemcell: default 94 | jobs: 95 | - {release: cf-mysql, name: rejoin-unsafe} 96 | 97 | - name: verify-cluster-schemas-vm 98 | instances: 1 99 | lifecycle: errand 100 | azs: [z1] 101 | networks: [{name: default}] 102 | vm_type: default 103 | stemcell: default 104 | jobs: 105 | - name: verify-cluster-schemas 106 | release: cf-mysql 107 | properties: 108 | cf_mysql: 109 | mysql: 110 | admin_password: ((cf_mysql_mysql_admin_password)) 111 | galera_healthcheck: 112 | endpoint_password: ((cf_mysql_mysql_galera_healthcheck_endpoint_password)) 113 | 114 | - name: smoke-tests-vm 115 | instances: 1 116 | lifecycle: errand 117 | azs: [z1] 118 | networks: [{name: default}] 119 | vm_type: default 120 | stemcell: default 121 | jobs: 122 | - name: smoke-tests 123 | release: cf-mysql 124 | properties: 125 | cf_mysql: 126 | mysql: 127 | admin_password: ((cf_mysql_mysql_admin_password)) 128 | proxy: 129 | api_password: ((cf_mysql_proxy_api_password)) 130 | smoke_tests: 131 | db_password: ((cf_mysql_smoke_tests_db_password)) 132 | standalone_tests_only: true 133 | 134 | variables: 135 | - name: cf_mysql_mysql_admin_password 136 | type: password 137 | - name: cf_mysql_mysql_cluster_health_password 138 | type: password 139 | - name: cf_mysql_mysql_galera_healthcheck_db_password 140 | type: password 141 | - name: cf_mysql_mysql_galera_healthcheck_endpoint_password 142 | type: password 143 | - name: cf_mysql_proxy_api_password 144 | type: password 145 | - name: cf_mysql_smoke_tests_db_password 146 | type: password 147 | 148 | releases: 149 | - name: cf-mysql 150 | url: https://bosh.io/d/github.com/cloudfoundry/cf-mysql-release?v=36.19.0 151 | version: 36.19.0 152 | sha1: 393a018015fdcb48da40259b6a39b8e30fde9d0c 153 | - name: bpm 154 | url: "" 155 | version: latest 156 | sha1: "" 157 | stemcells: 158 | - alias: default 159 | os: ubuntu-trusty 160 | version: "3586.79" 161 | -------------------------------------------------------------------------------- /docs/using-cf-mysql.md: -------------------------------------------------------------------------------- 1 | # Application Developer's Guide to Using cf-mysql 2 | 3 | ## Connecting to cf-mysql 4 | 5 | ### Binding an App 6 | 7 | You can connect apps that are deployed to Cloud Foundry, via `cf push` using the standard instructions on [Delivering Service Credentials to an Application](https://docs.cloudfoundry.org/devguide/services/application-binding.html). 8 | 9 | cf-mysql does not offer any arbitrary parameters. 10 | 11 | ### Service Keys 12 | 13 | To connect to cf-mysql from an app which has not been deployed to Cloud Foundry, you can follow the instructions for [creating a service key](https://docs.cloudfoundry.org/devguide/services/service-keys.html). 14 | 15 | ### Encryption 16 | 17 | #### Applications Running on Cloud Foundry 18 | 19 | Most applications, save Java and Spring (see below), can be modified to discover the information necessary to connect to cf-mysql using TLS. When inspecting `VCAP_SERVICES` for username and password, if the additional property, `ca_certificate` is available, your application can connect to cf-mysql using TLS. 20 | 21 | Here's a Node.js example: 22 | 23 | ```node 24 | ca_cert = vcap_services["p-mysql"][0]["credentials"]["ca_certificate"] ; 25 | dbClient = mysql.createConnection( { 26 | host : host, 27 | user : user, 28 | password : password, 29 | port : port, 30 | database : database, 31 | ssl : { 32 | ca : ca_cert 33 | }, 34 | } ) ; 35 | ``` 36 | Some languages automatically check the operating system's [trust store](https://docs.cloudfoundry.org/devguide/deploy-apps/trusted-system-certificates.html). In those cases, it is not necessary to parse `VCAP_SERVICES` for the CA certificate. 37 | 38 | #### Java and Spring Applications 39 | 40 | To enable apps using the [Java buildpack](https://docs.cloudfoundry.org/buildpacks/java/), you'll need to delete the existing binding and create a new one. This will update the `jdbcUrl` to specify an encrypted connection. 41 | 42 | **Note:** Should your deployment of cf-mysql turn off encryption in the future, you'll need to **re-bind** all Java applications that use cf-mysql. That will remove the encryption requirement, allowing apps to connect to an instance that does not offer encryption. 43 | 44 | #### Service Keys 45 | 46 | When using a service key to establish a connection using TLS (aka SSL) you will need the `ca_certificate` from the service key output. See the [service key documentation](https://docs.cloudfoundry.org/devguide/services/service-keys.html#detail) to view the service key JSON. 47 | 48 | Save the CA certificate to a file in PEM format. You'll need to replace the "\n" with newlines. 49 | 50 | To test, you can use any MySQL client. Connect to the hostname given in the service key output with the given credentials. When using the `mysql` CLI, also specify `--ssl-verify-server-cert --ssl-ca=PATH_TO_CA_CERTIFICATE`. 51 | -------------------------------------------------------------------------------- /githooks/pre-push: -------------------------------------------------------------------------------- 1 | #!/usr/bin/env bash 2 | 3 | branch=$(git rev-parse --abbrev-ref HEAD) 4 | 5 | if [ "${branch}" == "master" ] 6 | then 7 | echo "Refusing to commit to 'master'. Please commit to 'develop' or other branches" 8 | exit 1 9 | fi 10 | -------------------------------------------------------------------------------- /operations/README.md: -------------------------------------------------------------------------------- 1 | # Operations 2 | 3 | This directory contains a list of commonly-used, tested, operations files. 4 | 5 | Unless otherwise stated, they can be combined in any permutation and in any order. 6 | 7 | ### Registering the proxy route 8 | 9 | [This operations file](https://github.com/cloudfoundry/cf-mysql-deployment/tree/master/operations/register-proxy-route.yml) 10 | registers routes with the Cloud Foundry router which point to the dashboard pages hosted by the proxies deployed as part of `cf-mysql-release`. 11 | 12 | 13 | ### Enabling the Service Broker 14 | 15 | To enable integration of the MySQL database with Cloud Foundry (as a Cloud Foundry service), you should include the 16 | [add a broker](https://github.com/cloudfoundry/cf-mysql-deployment/tree/master/operations/add-broker.yml) 17 | operations file, as well as the [register the proxy route](https://github.com/cloudfoundry/cf-mysql-deployment/tree/master/operations/register-proxy-route.yml) 18 | operations file. 19 | 20 | 21 | ### Disabling cross deployment links 22 | 23 | Used when the dependent deployments (i.e. Cloud Foundry) do not expose properties 24 | via cross-deployment links. 25 | 26 | For example, many configurations of 27 | [cf-release](https://github.com/cloudfoundry/cf-release) 28 | (including the 29 | [provided spiff manifest generation](https://github.com/cloudfoundry/cf-release/blob/master/scripts/generate_deployment_manifest)) 30 | do not support cross-deployment links without manual modifications to the manifest, 31 | whereas deploying Cloud Foundry via 32 | [cf-deployment](https://github.com/cloudfoundry/cf-deployment) 33 | exposes properties like NATS config by default. 34 | 35 | Using this operations file will require you to provide your own values for these 36 | properties which would otherwise be provided via links, e.g. NATS. 37 | 38 | Example usage: 39 | 40 | ``` 41 | -o disable-smoke-tests-cross-deployment-links.yml \ 42 | -o disable-broker-route-registrar-cross-deployment-links.yml \ 43 | -o disable-proxy-route-registrar-cross-deployment-links.yml \ 44 | 45 | -v nats="{password: some-nats-password, user: nats, port: 4222, machines: [10.0.31.191]}" \ 46 | -v admin_username=admin \ 47 | -v admin_password=password \ 48 | -v api_url=api.mycf.com \ 49 | -v app_domains=[mycf.com] \ 50 | -v skip_ssl_validation=true \ 51 | ``` 52 | 53 | ### [configure-broker-load-balancer.yml](https://github.com/cloudfoundry/cf-mysql-deployment/tree/master/operations/configure-broker-load-balancer.yml) 54 | 55 | Provides a value for the property `cf_mysql.host` property, which is host the 56 | broker provides to applications via service instance bindings. 57 | 58 | Typically this is a FQDN pointing to a load balancer or some other mechanism to 59 | achieve HA (e.g. DNS, floating virtual IPs etc). 60 | 61 | Example usage: 62 | 63 | ``` 64 | -o configure-broker-load-balancer.yml \ 65 | 66 | -v cf_mysql_host=my-load-balancer-url 67 | ``` 68 | -------------------------------------------------------------------------------- /operations/add-broker.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - type: replace 3 | path: /releases/name=routing? 4 | value: 5 | name: routing 6 | version: "0.180.0" 7 | url: https://bosh.io/d/github.com/cloudfoundry-incubator/cf-routing-release?v=0.180.0 8 | sha1: 990c2c319e6063573eec18dbeb7c3631a382db7d 9 | - type: replace 10 | path: /releases/name=bpm? 11 | value: 12 | name: bpm 13 | version: "0.9.0" 14 | url: https://bosh.io/d/github.com/cloudfoundry-incubator/bpm-release?v=0.9.0 15 | sha1: 0cb3242063c95271c95b62de3a6d07072aff0b29 16 | 17 | - type: replace 18 | path: /instance_groups/- 19 | value: 20 | name: broker 21 | instances: 2 22 | azs: [z1,z2,z3] 23 | networks: [{name: default}] 24 | vm_type: default 25 | stemcell: default 26 | jobs: 27 | - name: cf-mysql-broker 28 | release: cf-mysql 29 | properties: 30 | cf: 31 | api_url: ((cf_api_url)) 32 | skip_ssl_validation: ((cf_skip_ssl_validation)) 33 | cf_mysql: 34 | broker: 35 | auth_password: ((cf_mysql_broker_auth_password)) 36 | cookie_secret: ((cf_mysql_broker_cookie_secret)) 37 | db_password: ((cf_mysql_broker_db_password)) 38 | quota_enforcer: 39 | password: ((cf_mysql_broker_quota_enforcer_password)) 40 | services: &broker_services 41 | - name: p-mysql 42 | id: 44b26033-1f54-4087-b7bc-da9652c2a539 43 | dashboard_client: 44 | id: p-mysql 45 | secret: ((cf_mysql_p_mysql_dashboard_secret)) 46 | description: MySQL databases on demand 47 | metadata: 48 | displayName: MySQL for Pivotal Cloud Foundry 49 | documentationUrl: https://github.com/cloudfoundry/cf-mysql-release/blob/master/README.md 50 | imageUrl:  51 | longDescription: Creating a service instance provisions a database. Binding 52 | applications provisions unique credentials for each application to access 53 | the database. 54 | providerDisplayName: Pivotal Software 55 | supportUrl: https://support.pivotal.io 56 | plan_updateable: true 57 | plans: 58 | - description: Shared MySQL Server 59 | id: ab08f1bc-e6fc-4b56-a767-ee0fea6e3f20 60 | max_storage_mb: 10 61 | max_user_connections: 20 62 | name: 10mb 63 | - description: Shared MySQL Server 64 | id: 11d0aa36-dcec-4021-85f5-ea4d9a5c8342 65 | max_storage_mb: 20 66 | max_user_connections: 40 67 | name: 20mb 68 | tags: 69 | - mysql 70 | external_host: ((cf_mysql_external_host)) 71 | mysql: 72 | persistent_disk: 10000 73 | - name: route_registrar 74 | release: routing 75 | consumes: 76 | nats: {from: nats, deployment: cf} 77 | properties: 78 | route_registrar: 79 | routes: 80 | - name: cf-mysql-broker 81 | port: 8081 # must match the value of 'cf_mysql.broker.port' 82 | registration_interval: 10s 83 | uris: 84 | - ((cf_mysql_external_host)) 85 | health_check: 86 | name: script 87 | script_path: /var/vcap/jobs/cf-mysql-broker/bin/healthcheck.sh 88 | 89 | - type: replace 90 | path: /instance_groups/- 91 | value: 92 | name: broker-registrar-vm 93 | instances: 1 94 | lifecycle: errand 95 | azs: [z1] 96 | networks: [{name: default}] 97 | vm_type: default 98 | stemcell: default 99 | jobs: 100 | - name: broker-registrar 101 | release: cf-mysql 102 | properties: 103 | cf: 104 | admin_username: admin 105 | admin_password: ((cf_admin_password)) 106 | api_url: ((cf_api_url)) 107 | skip_ssl_validation: ((cf_skip_ssl_validation)) 108 | cf_mysql: 109 | broker: 110 | auth_password: ((cf_mysql_broker_auth_password)) 111 | services: *broker_services 112 | external_host: ((cf_mysql_external_host)) 113 | 114 | - type: replace 115 | path: /instance_groups/- 116 | value: 117 | name: deregister-and-purge-instances-vm 118 | instances: 1 119 | lifecycle: errand 120 | azs: [z1] 121 | networks: [{name: default}] 122 | vm_type: default 123 | stemcell: default 124 | jobs: 125 | - name: deregister-and-purge-instances 126 | release: cf-mysql 127 | properties: 128 | cf: 129 | admin_username: admin 130 | admin_password: ((cf_admin_password)) 131 | api_url: ((cf_api_url)) 132 | skip_ssl_validation: ((cf_skip_ssl_validation)) 133 | cf_mysql: 134 | broker: 135 | services: *broker_services 136 | 137 | - type: replace 138 | path: /instance_groups/name=smoke-tests-vm/jobs/name=smoke-tests/properties/cf?/skip_ssl_validation 139 | value: ((cf_skip_ssl_validation)) 140 | 141 | - type: replace 142 | path: /instance_groups/name=smoke-tests-vm/jobs/name=smoke-tests/properties/cf?/admin_username 143 | value: admin 144 | 145 | - type: replace 146 | path: /instance_groups/name=smoke-tests-vm/jobs/name=smoke-tests/properties/cf?/admin_password 147 | value: ((cf_admin_password)) 148 | 149 | - type: replace 150 | path: /instance_groups/name=smoke-tests-vm/jobs/name=smoke-tests/properties/cf?/api_url 151 | value: ((cf_api_url)) 152 | 153 | - type: replace 154 | path: /instance_groups/name=smoke-tests-vm/jobs/name=smoke-tests/properties/cf_mysql/smoke_tests/standalone_tests_only? 155 | value: false 156 | 157 | - type: replace 158 | path: /instance_groups/name=mysql/jobs/- 159 | value: 160 | name: cf-mysql-broker-user 161 | release: cf-mysql 162 | 163 | - type: remove 164 | path: /instance_groups/name=mysql/jobs/name=smoke-tests-user 165 | 166 | - type: remove 167 | path: /instance_groups/name=smoke-tests-vm/jobs/name=smoke-tests/properties/cf_mysql/smoke_tests/db_password 168 | 169 | - type: replace 170 | path: /instance_groups/name=smoke-tests-vm/jobs/name=smoke-tests/properties/cf_mysql/external_host? 171 | value: ((cf_mysql_external_host)) 172 | 173 | - type: replace 174 | path: /instance_groups/name=smoke-tests-vm/jobs/name=smoke-tests/properties/cf_mysql/smoke_tests/password? 175 | value: ((cf_mysql_smoke_tests_password)) 176 | 177 | - type: replace 178 | path: /instance_groups/name=smoke-tests-vm/jobs/name=smoke-tests/consumes? 179 | value: 180 | cloud_controller: {from: cloud_controller, deployment: cf} 181 | 182 | - type: replace 183 | path: /instance_groups/name=smoke-tests-vm/jobs/name=smoke-tests/properties/cf_mysql/broker?/services 184 | value: *broker_services 185 | 186 | - type: replace 187 | path: /variables/- 188 | value: 189 | name: cf_mysql_broker_auth_password 190 | type: password 191 | 192 | - type: replace 193 | path: /variables/- 194 | value: 195 | name: cf_mysql_broker_cookie_secret 196 | type: password 197 | 198 | - type: replace 199 | path: /variables/- 200 | value: 201 | name: cf_mysql_broker_db_password 202 | type: password 203 | 204 | - type: replace 205 | path: /variables/- 206 | value: 207 | name: cf_mysql_broker_quota_enforcer_password 208 | type: password 209 | 210 | - type: replace 211 | path: /variables/- 212 | value: 213 | name: cf_mysql_p_mysql_dashboard_secret 214 | type: password 215 | 216 | - type: replace 217 | path: /variables/- 218 | value: 219 | name: cf_mysql_smoke_tests_password 220 | type: password 221 | -------------------------------------------------------------------------------- /operations/add-roadmin.yml: -------------------------------------------------------------------------------- 1 | - type: replace 2 | path: /instance_groups/name=mysql/jobs/name=mysql/properties/cf_mysql/mysql/roadmin_enabled? 3 | value: true 4 | 5 | - type: replace 6 | path: /instance_groups/name=mysql/jobs/name=mysql/properties/cf_mysql/mysql/roadmin_password? 7 | value: ((cf_mysql_mysql_roadmin_password)) 8 | 9 | - type: replace 10 | path: /variables/- 11 | value: 12 | name: cf_mysql_mysql_roadmin_password 13 | type: password 14 | -------------------------------------------------------------------------------- /operations/add-tls.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - type: replace 3 | path: /instance_groups/name=mysql/jobs/name=mysql/properties/cf_mysql/mysql/tls?/ca_certificate 4 | value: ((cf_mysql_mysql_tls_server_certificate.ca)) 5 | 6 | - type: replace 7 | path: /instance_groups/name=mysql/jobs/name=mysql/properties/cf_mysql/mysql/tls?/server_certificate 8 | value: ((cf_mysql_mysql_tls_server_certificate.certificate)) 9 | 10 | - type: replace 11 | path: /instance_groups/name=mysql/jobs/name=mysql/properties/cf_mysql/mysql/tls?/server_key 12 | value: ((cf_mysql_mysql_tls_server_certificate.private_key)) 13 | 14 | - type: replace 15 | path: /variables?/- 16 | value: 17 | name: cf_mysql_mysql_tls_server_certificate 18 | type: certificate 19 | options: 20 | common_name: ((cf_mysql_host)) 21 | ca: trusted_cert_for_apps 22 | -------------------------------------------------------------------------------- /operations/add-xenial-default-stemcell.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - type: replace 3 | path: /stemcells/alias=default 4 | value: 5 | alias: trusty 6 | os: ubuntu-trusty 7 | version: latest 8 | 9 | - type: replace 10 | path: /stemcells/- 11 | value: 12 | alias: default 13 | os: ubuntu-xenial 14 | version: latest 15 | -------------------------------------------------------------------------------- /operations/bosh-dns.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - type: replace 3 | path: /instance_groups/name=proxy/jobs/name=proxy/properties/cf_mysql/proxy/shutdown_delay? 4 | value: 30 5 | -------------------------------------------------------------------------------- /operations/bosh-lite.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - type: replace 3 | path: /instance_groups/name=mysql/jobs/name=mysql/properties/cf_mysql/mysql/innodb_buffer_pool_size? 4 | value: 128M 5 | -------------------------------------------------------------------------------- /operations/configure-broker-load-balancer.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - type: replace 3 | path: /instance_groups/name=broker/jobs/name=cf-mysql-broker/properties/cf_mysql/host? 4 | value: ((cf_mysql_host)) 5 | -------------------------------------------------------------------------------- /operations/disable-broker-route-registrar-cross-deployment-links.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - type: replace 3 | path: /instance_groups/name=broker/jobs/name=route_registrar?/consumes 4 | value: 5 | nats: nil 6 | 7 | - type: replace 8 | path: /instance_groups/name=broker/jobs/name=route_registrar?/properties/nats 9 | value: ((nats)) 10 | -------------------------------------------------------------------------------- /operations/disable-proxy-consul-cross-deployment-links.yml: -------------------------------------------------------------------------------- 1 | - type: replace 2 | path: /instance_groups/name=proxy/jobs/name=consul_agent/consumes? 3 | value: 4 | consul: nil 5 | consul_client: nil 6 | consul_common: nil 7 | consul_server: nil 8 | 9 | - type: replace 10 | path: /instance_groups/name=proxy/jobs/name=consul_agent/properties?/consul 11 | value: 12 | agent: 13 | datacenter: 14 | domain: cf.internal 15 | log_level: 16 | servers: 17 | lan: ((consul_agent_servers_lan)) 18 | agent_cert: ((consul_agent_cert)) 19 | agent_key: ((consul_agent_key)) 20 | ca_cert: ((consul_ca_cert)) 21 | encrypt_keys: ((consul_encrypt_keys)) 22 | server_cert: ((consul_server_cert)) 23 | server_key: ((consul_server_key)) 24 | -------------------------------------------------------------------------------- /operations/disable-proxy-route-registrar-cross-deployment-links.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - type: replace 3 | path: /instance_groups/name=proxy/jobs/name=route_registrar?/consumes 4 | value: 5 | nats: nil 6 | 7 | - type: replace 8 | path: /instance_groups/name=proxy/jobs/name=route_registrar?/properties/nats 9 | value: ((nats)) 10 | -------------------------------------------------------------------------------- /operations/disable-smoke-tests-cross-deployment-links.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - type: replace 3 | path: /instance_groups/name=smoke-tests-vm/jobs/name=smoke-tests/properties/cf?/app_domains 4 | value: ((app_domains)) 5 | 6 | - type: replace 7 | path: /instance_groups/name=smoke-tests-vm/jobs/name=smoke-tests/consumes? 8 | value: 9 | cloud_controller: nil 10 | -------------------------------------------------------------------------------- /operations/enable-syslog.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - type: replace 3 | path: /addons?/- 4 | value: 5 | name: syslog_forwarder 6 | jobs: 7 | - name: syslog_forwarder 8 | release: syslog 9 | properties: 10 | syslog: 11 | address: ((syslog_address)) 12 | port: ((syslog_port)) 13 | transport: ((syslog_transport)) 14 | forward_files: true 15 | 16 | - type: replace 17 | path: /releases/- 18 | value: 19 | name: syslog 20 | url: https://bosh.io/d/github.com/cloudfoundry/syslog-release?v=11 21 | version: '11' 22 | sha1: 332ac15609b220a3fdf5efad0e0aa069d8235788 23 | -------------------------------------------------------------------------------- /operations/latest-versions.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - type: replace 3 | path: /releases/name=cf-mysql 4 | value: 5 | name: cf-mysql 6 | version: latest 7 | 8 | - type: replace 9 | path: /stemcells/alias=default 10 | value: 11 | alias: default 12 | os: ubuntu-trusty 13 | version: latest 14 | -------------------------------------------------------------------------------- /operations/no-arbitrator.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - type: remove 3 | path: /instance_groups/name=arbitrator 4 | 5 | - type: replace 6 | path: /instance_groups/name=mysql/instances 7 | value: 3 8 | 9 | - type: replace 10 | path: /instance_groups/name=mysql/azs/- 11 | value: z3 12 | -------------------------------------------------------------------------------- /operations/proxy-consul.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - type: replace 3 | path: /releases/- 4 | value: 5 | name: consul 6 | version: latest 7 | 8 | - type: replace 9 | path: /instance_groups/name=proxy/jobs/- 10 | value: 11 | release: consul 12 | name: consul_agent 13 | consumes: 14 | consul_common: {from: consul_common_link, deployment: cf} 15 | consul_server: {from: consul_server_link, deployment: cf} 16 | consul_client: {from: consul_client_link, deployment: cf} 17 | 18 | - type: replace 19 | path: /instance_groups/name=proxy/jobs/name=proxy/properties/cf_mysql/proxy/consul_enabled? 20 | value: true 21 | - type: replace 22 | path: /instance_groups/name=proxy/jobs/name=proxy/properties/cf_mysql/proxy/consul_service_name? 23 | value: mysql 24 | -------------------------------------------------------------------------------- /operations/proxy-elb.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - type: replace 3 | path: /instance_groups/name=proxy/vm_extensions?/- 4 | value: ((proxy_vm_extension)) 5 | 6 | - type: replace 7 | path: /instance_groups/name=smoke-tests-vm/jobs/name=smoke-tests/properties/cf_mysql/host? 8 | value: ((cf_mysql_host)) 9 | -------------------------------------------------------------------------------- /operations/register-proxy-route.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - type: replace 3 | path: /releases/name=routing? 4 | value: 5 | name: routing 6 | version: "0.180.0" 7 | url: https://bosh.io/d/github.com/cloudfoundry-incubator/cf-routing-release?v=0.180.0 8 | sha1: 990c2c319e6063573eec18dbeb7c3631a382db7d 9 | 10 | - type: replace 11 | path: /releases/name=bpm? 12 | value: 13 | name: "bpm" 14 | version: "0.12.2" 15 | url: "https://bosh.io/d/github.com/cloudfoundry-incubator/bpm-release?v=0.12.2" 16 | sha1: "f2edbf3d1417a253205338c9941ca989cd2f8331" 17 | 18 | - type: replace 19 | path: /instance_groups/name=proxy/jobs/- 20 | value: 21 | release: routing 22 | name: route_registrar 23 | consumes: 24 | nats: {from: nats, deployment: cf} 25 | properties: 26 | route_registrar: 27 | routes: 28 | - name: cf-mysql-proxy 29 | port: 8080 # must match the value of 'cf_mysql.proxy.api_port' 30 | registration_interval: 10s 31 | uris: 32 | - &proxy_base_uri proxy-((cf_mysql_external_host)) 33 | prepend_instance_index: true 34 | - name: cf-mysql-proxy-aggregator 35 | port: 8082 # must match the value of 'cf_mysql.proxy.api_aggregator_port' 36 | registration_interval: 10s 37 | uris: 38 | - *proxy_base_uri 39 | # The switchboard aggregator page assumes there is only a single route registered for the proxies 40 | 41 | # make sure to match what the route_registrar is registering above in cf-mysql-proxy route 42 | - type: replace 43 | path: /instance_groups/name=proxy/jobs/name=proxy/properties/cf_mysql/proxy/api_uri? 44 | value: *proxy_base_uri 45 | -------------------------------------------------------------------------------- /operations/syslog-tls.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - type: replace 3 | path: /addons/name=syslog_forwarder/jobs/name=syslog_forwarder/properties/syslog/tls_enabled? 4 | value: true 5 | 6 | - type: replace 7 | path: /addons/name=syslog_forwarder/jobs/name=syslog_forwarder/properties/syslog/permitted_peer? 8 | value: ((syslog_permitted_peer)) 9 | -------------------------------------------------------------------------------- /operations/test/enable-remote-admin-access.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - type: replace 3 | path: /instance_groups/name=mysql/jobs/name=mysql/properties/cf_mysql/mysql/remote_admin_access? 4 | value: true 5 | -------------------------------------------------------------------------------- /operations/test/minimal-mode.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - type: replace 3 | path: /instance_groups/name=arbitrator/instances 4 | value: 0 5 | - type: replace 6 | path: /instance_groups/name=mysql/instances 7 | value: 1 8 | - type: replace 9 | path: /instance_groups/name=proxy/instances 10 | value: 1 11 | 12 | -------------------------------------------------------------------------------- /operations/xenial-stemcell.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - type: replace 3 | path: /stemcells/os=ubuntu-trusty 4 | value: 5 | alias: default 6 | os: ubuntu-xenial 7 | version: latest 8 | 9 | -------------------------------------------------------------------------------- /scripts/deploy-cf-mysql-to-bosh-lite: -------------------------------------------------------------------------------- 1 | #!/bin/bash 2 | 3 | set -eux 4 | 5 | my_dir="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )" 6 | root_dir="$( cd "${my_dir}/.." && pwd )" 7 | 8 | export BOSH_ENVIRONMENT="${BOSH_ENVIRONMENT:-192.168.50.6}" 9 | export BOSH_DEPLOYMENT="${BOSH_DEPLOYMENT:-cf-mysql}" 10 | 11 | # Strip "api." prefix from the endpoint. 12 | root_endpoint=${CF_API_ENDPOINT#"api."} 13 | 14 | cf_mysql_host="${root_endpoint}" 15 | cf_mysql_external_host="p-mysql.${root_endpoint}" 16 | 17 | pushd "${root_dir}" > /dev/null 18 | bosh \ 19 | deploy \ 20 | "${root_dir}/cf-mysql-deployment.yml" \ 21 | -o "${root_dir}/operations/bosh-lite.yml" \ 22 | -o "${root_dir}/operations/xenial-stemcell.yml" \ 23 | -l "${root_dir}/bosh-lite/default-vars.yml" \ 24 | -v cf_mysql_external_host="${cf_mysql_external_host}" \ 25 | -v cf_mysql_host="${cf_mysql_host}" \ 26 | -v cf_api_url="https://${CF_API_ENDPOINT}" \ 27 | --no-redact \ 28 | "$@" 29 | popd > /dev/null 30 | -------------------------------------------------------------------------------- /scripts/deploy-cf-mysql-with-broker-to-bosh-lite: -------------------------------------------------------------------------------- 1 | #!/bin/bash 2 | 3 | set -eu 4 | 5 | my_dir="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )" 6 | root_dir="$( cd "${my_dir}/.." && pwd )" 7 | 8 | if [[ -z "${CF_API_ENDPOINT}" ]]; then 9 | echo "\$CF_API_ENDPOINT is not set. You probably forgot to target your environment." 10 | echo "These BOSH variables may need to be changed:" 11 | echo " cf_mysql_external_host, cf_mysql_host, cf_api_url" 12 | fi 13 | 14 | # Strip "api." prefix from the endpoint. 15 | root_endpoint=${CF_API_ENDPOINT#"api."} 16 | 17 | cf_mysql_host="${root_endpoint}" 18 | cf_mysql_external_host="p-mysql.${root_endpoint}" 19 | 20 | "${my_dir}/deploy-cf-mysql-to-bosh-lite" \ 21 | -o "${root_dir}/operations/add-broker.yml" \ 22 | -o "${root_dir}/operations/register-proxy-route.yml" \ 23 | -v cf_mysql_external_host="${cf_mysql_external_host}" \ 24 | -v cf_mysql_host="${cf_mysql_host}" \ 25 | -v cf_api_url="https://${CF_API_ENDPOINT}" \ 26 | "$@" 27 | --------------------------------------------------------------------------------