summaryrefslogtreecommitdiffstats
path: root/robot/assets/asdc/base_clearwater/dns.yaml
blob: f257d24093dffe5049c96690873c4aefa26c4c1b (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
# Project Clearwater - IMS in the Cloud
# Copyright (C) 2015  Metaswitch Networks Ltd
#
# This program is free software: you can redistribute it and/or modify it
# under the terms of the GNU General Public License as published by the
# Free Software Foundation, either version 3 of the License, or (at your
# option) any later version, along with the "Special Exception" for use of
# the program along with SSL, set forth below. This program is distributed
# in the hope that it will be useful, but WITHOUT ANY WARRANTY;
# without even the implied warranty of MERCHANTABILITY or FITNESS FOR
# A PARTICULAR PURPOSE.  See the GNU General Public License for more
# details. You should have received a copy of the GNU General Public
# License along with this program.  If not, see
# <http://www.gnu.org/licenses/>.
#
# The author can be reached by email at clearwater@metaswitch.com or by
# post at Metaswitch Networks Ltd, 100 Church St, Enfield EN2 6BQ, UK
#
# Special Exception
# Metaswitch Networks Ltd  grants you permission to copy, modify,
# propagate, and distribute a work formed by combining OpenSSL with The
# Software, or a work derivative of such a combination, even if such
# copying, modification, propagation, or distribution would otherwise
# violate the terms of the GPL. You must comply with the GPL in all
# respects for all of the code used other than OpenSSL.
# "OpenSSL" means OpenSSL toolkit software distributed by the OpenSSL
# Project and licensed under the OpenSSL Licenses, or a work based on such
# software and licensed under the OpenSSL Licenses.
# "OpenSSL Licenses" means the OpenSSL License and Original SSLeay License
# under which the OpenSSL Project distributes the OpenSSL toolkit software,
# as those licenses appear in the file LICENSE-OPENSSL.

heat_template_version: 2013-05-23

description: >
  DNS server exposing dynamic DNS using DNSSEC

parameters:
  vnf_id:
    type: string
    label: VNF ID
    description: The VNF ID provided by ONAP
  vf_module_id:
    type: string
    label: VNF module ID
    description: The VNF module ID provided by ONAP
  public_net_id:
    type: string
    description: ID of public network
    constraints:
      - custom_constraint: neutron.network
        description: Must be a valid network ID
  dns_flavor_name:
    type: string
    description: Flavor to use
    constraints:
      - custom_constraint: nova.flavor
        description: Must be a valid flavor name
  dns_image_name:
    type: string
    description: Name of image to use
  key_name:
    type: string
    description: Name of keypair to assign
    constraints:
      - custom_constraint: nova.keypair
        description: Must be a valid keypair name
# dns_security_group:
#   type: string
#   description: ID of security group for DNS nodes
  zone:
    type: string
    description: DNS zone
    default: example.com
  dnssec_key:
    type: string
    description: DNSSEC private key (Base64-encoded)

resources:
  server:
    type: OS::Nova::Server
    properties:
      name: { str_replace: { params: { __zone__: { get_param: zone } }, template: ns.__zone__ } }
      image: { get_param: dns_image_name }
      flavor: { get_param: dns_flavor_name }
      key_name: { get_param: key_name }
      networks:
        - network: { get_param: public_net_id }
      metadata: {vnf_id: { get_param: vnf_id }, vf_module_id: { get_param: vf_module_id }}
      user_data_format: RAW
      user_data:
        str_replace:
          params:
            __zone__: { get_param: zone }
            __dnssec_key__: { get_param: dnssec_key }
          template: |
            #!/bin/bash

            # Log all output to file.
            exec > >(tee -a /var/log/clearwater-heat-dns.log) 2>&1
            set -x

            # Install BIND.
            apt-get update
            DEBIAN_FRONTEND=noninteractive apt-get install bind9 --yes

            # Get the public IP address from eth0
            sudo apt-get install ipcalc
            ADDR=`ip addr show eth0 | awk '/inet /{print $2}'`
            PUBLIC_ADDR=`ipcalc -n -b $ADDR | awk '/Address:/{print $2}'`

            # Update BIND configuration with the specified zone and key.
            cat >> /etc/bind/named.conf.local << EOF
            key __zone__. {
              algorithm "HMAC-MD5";
              secret "__dnssec_key__";
            };

            zone "__zone__" IN {
              type master;
              file "/var/lib/bind/db.__zone__";
              allow-update {
                key __zone__.;
              };
            };
            EOF

            # Function to give DNS record type and IP address for specified IP address
            ip2rr() {
              if echo $1 | grep -q -e '[^0-9.]' ; then
                echo AAAA $1
              else
                echo A $1
              fi
            }

            # Create basic zone configuration.
            cat > /var/lib/bind/db.__zone__ << EOF
            \$ORIGIN __zone__.
            \$TTL 1h
            @ IN SOA ns admin\@__zone__. ( $(date +%Y%m%d%H) 1d 2h 1w 30s )
            @ NS ns
            ns $(ip2rr $PUBLIC_ADDR)
            EOF
            chown root:bind /var/lib/bind/db.__zone__

            # Now that BIND configuration is correct, kick it to reload.
            service bind9 reload

outputs:
  dns_ip:
    description: IP address of DNS server
    value: { get_attr: [ server, accessIPv4 ] }
  zone:
    description: DNS zone
    value: { get_param: zone }
  dnssec_key:
    description: DNSSEC private key (Base64-encoded)
    value: { get_param: dnssec_key }