It has been requested that we provide programmatic access to the elasticsearch API in addition to the Kibana web UI. Do this by reverse proxying http://logstash.openstack.org/elasticearch/$API_REQUEST to http://elasticsearch.openstack.org:9200/$API_REQUEST. The only values for $API_REQUEST that will be passed through are _aliases, _status, and _search. Change-Id: Ib41f6d91e2e59d493218074a67155af450ec8c93 Reviewed-on: https://review.openstack.org/33316 Reviewed-by: James E. Blair <corvus@inaugust.com> Reviewed-by: Jeremy Stanley <fungi@yuggoth.org> Approved: Clark Boylan <clark.boylan@gmail.com> Reviewed-by: Clark Boylan <clark.boylan@gmail.com> Tested-by: Jenkins
98 lines
2.9 KiB
98 lines
2.9 KiB
# Copyright 2013 Hewlett-Packard Development Company, L.P.
# Licensed under the Apache License, Version 2.0 (the "License"); you may
# not use this file except in compliance with the License. You may obtain
# a copy of the License at
# http://www.apache.org/licenses/LICENSE-2.0
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
# License for the specific language governing permissions and limitations
# under the License.
# Logstash web frontend glue class.
class openstack_project::logstash (
$elasticsearch_masters = [],
$gearman_workers = [],
$sysadmins = []
) {
$iptables_es_rule = regsubst ($elasticsearch_masters, '^(.*)$', '-m state --state NEW -m tcp -p tcp --dport 9200:9400 -s \1 -j ACCEPT')
$iptables_gm_rule = regsubst ($gearman_workers, '^(.*)$', '-m state --state NEW -m tcp -p tcp --dport 4730 -s \1 -j ACCEPT')
$iptables_rule = flatten([$iptables_es_rule, $iptables_gm_rule])
class { 'openstack_project::server':
iptables_public_tcp_ports => [22, 80],
iptables_rules6 => $iptables_rule,
iptables_rules4 => $iptables_rule,
sysadmins => $sysadmins,
class { 'logstash::web':
frontend => 'kibana',
elasticsearch_host => 'elasticsearch.openstack.org',
proxy_elasticsearch => true,
package { 'python-daemon':
ensure => present,
package { 'python-zmq':
ensure => present,
package { 'python-yaml':
ensure => present,
include pip
package { 'gear':
ensure => latest,
provider => 'pip',
require => Class['pip'],
file { '/usr/local/bin/log-gearman-client.py':
ensure => present,
owner => 'root',
group => 'root',
mode => '0755',
source => 'puppet:///modules/openstack_project/logstash/log-gearman-client.py',
require => [
file { '/etc/logstash/jenkins-log-client.yaml':
ensure => present,
owner => 'root',
group => 'root',
mode => '0555',
source => 'puppet:///modules/openstack_project/logstash/jenkins-log-client.yaml',
file { '/etc/init.d/jenkins-log-client':
ensure => present,
owner => 'root',
group => 'root',
mode => '0555',
source => 'puppet:///modules/openstack_project/logstash/jenkins-log-client.init',
require => [
service { 'jenkins-log-client':
enable => true,
hasrestart => true,
subscribe => File['/etc/logstash/jenkins-log-client.yaml'],
require => File['/etc/init.d/jenkins-log-client'],