1 # Project Clearwater - IMS in the Cloud
2 # Copyright (C) 2015 Metaswitch Networks Ltd
4 # This program is free software: you can redistribute it and/or modify it
5 # under the terms of the GNU General Public License as published by the
6 # Free Software Foundation, either version 3 of the License, or (at your
7 # option) any later version, along with the "Special Exception" for use of
8 # the program along with SSL, set forth below. This program is distributed
9 # in the hope that it will be useful, but WITHOUT ANY WARRANTY;
10 # without even the implied warranty of MERCHANTABILITY or FITNESS FOR
11 # A PARTICULAR PURPOSE. See the GNU General Public License for more
12 # details. You should have received a copy of the GNU General Public
13 # License along with this program. If not, see
14 # <http://www.gnu.org/licenses/>.
16 # The author can be reached by email at clearwater@metaswitch.com or by
17 # post at Metaswitch Networks Ltd, 100 Church St, Enfield EN2 6BQ, UK
20 # Metaswitch Networks Ltd grants you permission to copy, modify,
21 # propagate, and distribute a work formed by combining OpenSSL with The
22 # Software, or a work derivative of such a combination, even if such
23 # copying, modification, propagation, or distribution would otherwise
24 # violate the terms of the GPL. You must comply with the GPL in all
25 # respects for all of the code used other than OpenSSL.
26 # "OpenSSL" means OpenSSL toolkit software distributed by the OpenSSL
27 # Project and licensed under the OpenSSL Licenses, or a work based on such
28 # software and licensed under the OpenSSL Licenses.
29 # "OpenSSL Licenses" means the OpenSSL License and Original SSLeay License
30 # under which the OpenSSL Project distributes the OpenSSL toolkit software,
31 # as those licenses appear in the file LICENSE-OPENSSL.
33 heat_template_version: 2013-05-23
36 DNS server exposing dynamic DNS using DNSSEC
42 description: The VNF ID provided by ONAP
46 description: The VNF module ID provided by ONAP
49 description: ID of public network
51 - custom_constraint: neutron.network
52 description: Must be a valid network ID
55 description: Flavor to use
57 - custom_constraint: nova.flavor
58 description: Must be a valid flavor name
61 description: Name of image to use
64 description: Name of keypair to assign
66 - custom_constraint: nova.keypair
67 description: Must be a valid keypair name
70 # description: ID of security group for DNS nodes
77 description: DNSSEC private key (Base64-encoded)
81 type: OS::Nova::Server
83 name: { str_replace: { params: { __zone__: { get_param: zone } }, template: ns.__zone__ } }
84 image: { get_param: dns_image_name }
85 flavor: { get_param: dns_flavor_name }
86 key_name: { get_param: key_name }
88 - network: { get_param: public_net_id }
89 metadata: {vnf_id: { get_param: vnf_id }, vf_module_id: { get_param: vf_module_id }}
94 __zone__: { get_param: zone }
95 __dnssec_key__: { get_param: dnssec_key }
99 # Log all output to file.
100 exec > >(tee -a /var/log/clearwater-heat-dns.log) 2>&1
105 DEBIAN_FRONTEND=noninteractive apt-get install bind9 --yes
107 # Get the public IP address from eth0
108 sudo apt-get install ipcalc
109 ADDR=`ip addr show eth0 | awk '/inet /{print $2}'`
110 PUBLIC_ADDR=`ipcalc -n -b $ADDR | awk '/Address:/{print $2}'`
112 # Update BIND configuration with the specified zone and key.
113 cat >> /etc/bind/named.conf.local << EOF
115 algorithm "HMAC-MD5";
116 secret "__dnssec_key__";
121 file "/var/lib/bind/db.__zone__";
128 # Function to give DNS record type and IP address for specified IP address
130 if echo $1 | grep -q -e '[^0-9.]' ; then
137 # Create basic zone configuration.
138 cat > /var/lib/bind/db.__zone__ << EOF
141 @ IN SOA ns admin\@__zone__. ( $(date +%Y%m%d%H) 1d 2h 1w 30s )
143 ns $(ip2rr $PUBLIC_ADDR)
145 chown root:bind /var/lib/bind/db.__zone__
147 # Now that BIND configuration is correct, kick it to reload.
152 description: IP address of DNS server
153 value: { get_attr: [ server, accessIPv4 ] }
155 description: DNS zone
156 value: { get_param: zone }
158 description: DNSSEC private key (Base64-encoded)
159 value: { get_param: dnssec_key }