Monasca REST API
Go to file
Zuul 37b2111435 Merge "Remove keystone cache dir" 2017-10-19 06:28:09 +00:00
api-ref Prepare foundation for doc migration 2017-07-31 10:43:49 +00:00
common Restore user condition but with zuul 2017-10-19 06:08:28 +02:00
config-generator Config-generator for monasca-api 2017-08-28 06:58:57 +00:00
devstack Remove keystone cache dir 2017-10-19 04:14:15 +00:00
doc Make legacy gates working 2017-10-18 11:01:28 +00:00
docs [doc] Fix incorrect formatting on get alarm count 2017-06-08 07:37:28 +00:00
etc Config-generator for monasca-api 2017-08-28 06:58:57 +00:00
java Add multibyte character support for alarm definition 2017-03-14 15:24:00 +01:00
monasca_api Config-generator for monasca-api 2017-08-28 06:58:57 +00:00
monasca_tempest_tests Fix TestAlarmsCount failure in tempest tests 2017-09-20 07:56:50 +02:00
releasenotes Config-generator for monasca-api 2017-08-28 06:58:57 +00:00
tools Validate all bash files inside devstack 2017-07-12 06:28:07 +00:00
.coveragerc Migrate test run to ostestr 2017-01-14 19:47:29 +00:00
.gitignore Add .stestr.conf . 2017-09-22 13:41:11 +02:00
.gitreview Update .gitreview for new namespace 2015-10-17 22:30:33 +00:00
.stestr.conf Add .stestr.conf . 2017-09-22 13:41:11 +02:00
.testr.conf Migrate test run to ostestr 2017-01-14 19:47:29 +00:00
AUTHORS Config-generator for monasca-api 2017-08-28 06:58:57 +00:00
LICENSE Added license file 2014-05-01 16:22:11 -07:00
README.md Fixed links and typos in README.md 2017-06-02 16:01:33 +02:00
babel.cfg initial python implementation 2014-09-15 13:18:10 -04:00
bindep.txt Add libssl to fix pep8 2017-06-07 15:54:02 -06:00
pom.xml Release version 1.2.1 for Java 2017-02-15 13:47:43 +00:00
requirements.txt Updated from global requirements 2017-10-19 04:14:26 +00:00
run_maven.sh Ensure the same branch is used for common build 2016-02-10 09:11:02 -07:00
setup.cfg Config-generator for monasca-api 2017-08-28 06:58:57 +00:00
setup.py Updated from global requirements 2017-03-02 11:47:00 +00:00
test-requirements.txt Updated from global requirements 2017-09-20 08:38:54 +00:00
tox.ini Make legacy gates working 2017-10-18 11:01:28 +00:00

README.md

Team and repository tags

Team and repository tags

Overview

monasca-api is a RESTful API server that is designed with a layered architecture.

The full API Specification can be found in docs/monasca-api-spec.md

Java Build

Requires monasca-common. First clone this repository and then do mvn install. Then return to monasca-api and:

$ cd java
$ mvn clean package

StackForge Java Build

There is a pom.xml in the base directory that should only be used for the StackForge build. The StackForge build is a rather strange build because of the limitations of the current StackForge java jobs and infrastructure. We have found that the API runs faster if built with maven 3 but the StackForge nodes only have maven 2. This build checks the version of maven and if not maven 3, it downloads a version of maven 3 and uses it. This build depends on jars that are from monasca-common. That StrackForge build uploads the completed jars to http://tarballs.openstack.org/ci/monasca-common, but they are just regular jars, and not in a maven repository and sometimes zuul takes a long time to do the upload. Hence, the first thing the maven build from the base project does is invoke build_common.sh in the common directory. This script clones monasca-common and then invokes maven 3 to build monasca-common in the common directory and install the jars in the local maven repository.

Since this is all rather complex, that part of the build only works on StackForge so follow the simple instruction above if you are building your own monasca-api.

Currently this build is executed on the bare-precise nodes in StackForge and they only have maven 2. So, this build must be kept compatible with Maven 2. If another monasca-common jar is added as a dependency to /java/pom.xml, it must also be added to download/download.sh.

Combining monasca-common, monasca-thresh, monasca-api and monasca-persister into one build would vastly simplify the builds but that is a future task.`

Usage

$ java -jar target/monasca-api.jar server config-file.yml

Keystone Configuration

For secure operation of the Monasca API, the API must be configured to use Keystone in the configuration file under the middleware section. Monasca only works with a Keystone v3 server. The important parts of the configuration are explained below:

  • serverVIP - This is the hostname or IP Address of the Keystone server
  • serverPort - The port for the Keystone server
  • useHttps - Whether to use https when making requests of the Keystone API
  • truststore - If useHttps is true and the Keystone server is not using a certificate signed by a public CA recognized by Java, the CA certificate can be placed in a truststore so the Monasca API will trust it, otherwise it will reject the https connection. This must be a JKS truststore
  • truststorePassword - The password for the above truststore
  • connSSLClientAuth - If the Keystone server requires the SSL client used by the Monasca server to have a specific client certificate, this should be true, false otherwise
  • keystore - The keystore holding the SSL Client certificate if connSSLClientAuth is true
  • keystorePassword - The password for the keystore
  • defaultAuthorizedRoles - An array of roles that authorize a user to access the complete Monasca API. User must have at least one of these roles. See below
  • readOnlyAuthorizedRoles - An array of roles that authorize a user to only GET (but not POST, PUT...) metrics. See Keystone Roles below
  • agentAuthorizedRoles - An array of roles that authorize only the posting of metrics. See Keystone Roles below
  • adminAuthMethod - "password" if the Monasca API should adminUser and adminPassword to login to the Keystone server to check the user's token, "token" if the Monasca API should use adminToken
  • adminUser - Admin user name
  • adminPassword - Admin user password
  • adminProjectId - Specify the project ID the api should use to request an admin token. Defaults to the admin user's default project. The adminProjectId option takes precedence over adminProjectName.
  • adminProjectName - Specify the project name the api should use to request an admin token. Defaults to the admin user's default project. The adminProjectId option takes precedence over adminProjectName.
  • adminToken - A valid admin user token if adminAuthMethod is token
  • timeToCacheToken - How long the Monasca API should cache the user's token before checking it again

Keystone Roles

The Monasca API has two levels of access:

  • Full access - user can read/write metrics and Alarm Definitions and Alarms
  • Agent access - user can only write metrics

The reason for the "Agent access" level is because the Monasca Agent must be configured to use a Keystone user. Since the user and password are configured on all of the systems running the Monasca Agent, this user is most in danger of being compromised. If this user is limited to only writing metrics, then the damage can be limited.

To configure the user to have full access, the user must have a role that is listed in defaultAuthorizedRoles. To configure a user to have only "Agent access", the user must have a role in agentAuthorizedRoles and none of the roles in defaultAuthorizedRoles.

If you want to give users the ability to only view data, configure one or more roles in the readOnlyAuthorizedRoles list.

Design Overview

Architectural layers

Requests flow through the following architectural layers from top to bottom:

  • Resource
    • Serves as the entrypoint into the service.
    • Responsible for handling web service requests, and performing structural request validation.
  • Application
    • Responsible for providing application level implementations for specific use cases.
  • Domain
    • Contains the technology agnostic core domain model and domain service definitions.
    • Responsible for upholding invariants and defining state transitions.
  • Infrastructure
    • Contains technology specific implementations of domain services.

Documentation

python monasca api implementation

To install the python api implementation, git clone the source and run the following command::

$ sudo python setup.py install

If it installs successfully, you will need to make changes to the following two files to reflect your system settings, especially where kafka server is located::

/etc/monasca/api-config.ini
/etc/monasca/api-config.conf
/etc/monasca/api-logging.conf

Once the configuration files are modified to match your environment, you can start up the server by following the following instructions.

To start the server, run the following command:

Running the server in foreground mode
$ gunicorn -k eventlet --worker-connections=2000 --backlog=1000 --paste /etc/monasca/api-config.ini

Running the server as daemons
$ gunicorn -k eventlet --worker-connections=2000 --backlog=1000 --paste /etc/monasca/api-config.ini -D

To check if the code follows python coding style, run the following command from the root directory of this project

$ tox -e pep8

To run all the unit test cases, run the following command from the root directory of this project

$ tox -e py27

Start the Server -- for Apache

To start the server using Apache: create a modwsgi file, create a modwsgi configuration file, and enable the wsgi module in Apache.

The modwsgi configuration file may look something like this, and the site will need to be enabled:

    Listen 8070

    <VirtualHost *:8070>

        WSGIDaemonProcess monasca-api processes=4 threads=1 socket-timeout=120 user=mon-api group=monasca python-path=/usr/local/lib/python2.7/site-packages
        WSGIProcessGroup monasca-api
        WSGIApplicationGroup monasca-api
        WSGIScriptAlias / /usr/local/lib/python2.7/site-packages/monasca_api/api/wsgi/monasca_api.py

        WSGIPassAuthorization On

        LogLevel info
        ErrorLog /var/log/monasca-api/wsgi.log
        CustomLog /var/log/monasca-api/wsgi-access.log combined

        <Directory /usr/local/lib/python2.7/site-packages/monasca_api>
          Require all granted
        </Directory>

        SetEnv no-gzip 1

    </VirtualHost>

The wsgi file may look something like this:


    from monasca_api.api import server

    application = server.get_wsgi_app(config_base_path='/etc/monasca')

License

Copyright (c) 2014 Hewlett-Packard Development Company, L.P.

Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.