step_0: ovn_cluster_north_db_server: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS image: registry.redhat.io/rhosp-rhel9/openstack-ovn-nb-db-server:17.1 net: host privileged: false restart: always start_order: 0 volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/ovn_cluster_north_db_server.json:/var/lib/kolla/config_files/config.json:ro - /lib/modules:/lib/modules:ro - /var/lib/openvswitch/ovn:/var/lib/openvswitch:shared,z - /var/lib/openvswitch/ovn:/run/openvswitch:shared,z - /var/log/containers/openvswitch:/var/log/openvswitch:z - /var/lib/openvswitch/ovn:/var/lib/ovn:shared,z - /var/lib/openvswitch/ovn:/etc/openvswitch:shared,z - /var/lib/openvswitch/ovn:/etc/ovn:shared,z - /var/lib/openvswitch/ovn:/run/ovn:shared,z - /var/log/containers/openvswitch:/var/log/ovn:z - /var/lib/config-data/ansible-generated/ovn:/var/lib/kolla/config_files/src:ro - /etc/pki/tls/private/ovn_dbs.key:/var/lib/kolla/config_files/src-tls/etc/pki/tls/private/ovn_dbs.key:ro - /etc/pki/tls/certs/ovn_dbs.crt:/var/lib/kolla/config_files/src-tls/etc/pki/tls/certs/ovn_dbs.crt:ro ovn_cluster_northd: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-ovn-northd:17.1 net: host privileged: false restart: always start_order: 2 volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/ovn_cluster_northd.json:/var/lib/kolla/config_files/config.json:ro - /lib/modules:/lib/modules:ro - /var/lib/openvswitch/ovn:/run/openvswitch:shared,z - /var/log/containers/openvswitch:/var/log/openvswitch:z - /var/lib/openvswitch/ovn:/run/ovn:shared,z - /var/log/containers/openvswitch:/var/log/ovn:z - /var/lib/config-data/ansible-generated/ovn:/var/lib/kolla/config_files/src:ro - /etc/pki/tls/private/ovn_dbs.key:/var/lib/kolla/config_files/src-tls/etc/pki/tls/private/ovn_dbs.key:ro - /etc/pki/tls/certs/ovn_dbs.crt:/var/lib/kolla/config_files/src-tls/etc/pki/tls/certs/ovn_dbs.crt:ro ovn_cluster_south_db_server: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS image: registry.redhat.io/rhosp-rhel9/openstack-ovn-sb-db-server:17.1 net: host privileged: false restart: always start_order: 0 volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/ovn_cluster_south_db_server.json:/var/lib/kolla/config_files/config.json:ro - /lib/modules:/lib/modules:ro - /var/lib/openvswitch/ovn:/var/lib/openvswitch:shared,z - /var/lib/openvswitch/ovn:/run/openvswitch:shared,z - /var/log/containers/openvswitch:/var/log/openvswitch:z - /var/lib/openvswitch/ovn:/var/lib/ovn:shared,z - /var/lib/openvswitch/ovn:/etc/openvswitch:shared,z - /var/lib/openvswitch/ovn:/etc/ovn:shared,z - /var/lib/openvswitch/ovn:/run/ovn:shared,z - /var/log/containers/openvswitch:/var/log/ovn:z - /var/lib/config-data/ansible-generated/ovn:/var/lib/kolla/config_files/src:ro - /etc/pki/tls/private/ovn_dbs.key:/var/lib/kolla/config_files/src-tls/etc/pki/tls/private/ovn_dbs.key:ro - /etc/pki/tls/certs/ovn_dbs.crt:/var/lib/kolla/config_files/src-tls/etc/pki/tls/certs/ovn_dbs.crt:ro step_1: memcached: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-memcached:17.1 net: host privileged: false restart: always start_order: 0 volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/memcached.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/memcached:/var/lib/kolla/config_files/src:rw,z - /var/log/containers/memcached:/var/log/memcached:rw - /etc/pki/tls/certs/memcached.crt:/var/lib/kolla/config_files/src-tls/etc/pki/tls/certs/memcached.crt:ro - /etc/pki/tls/private/memcached.key:/var/lib/kolla/config_files/src-tls/etc/pki/tls/private/memcached.key:ro mysql_bootstrap: command: - bash - -ec - 'if [ -e /var/lib/mysql/mysql ]; then exit 0; fi echo -e "\n[mysqld]\nwsrep_provider=none" >> /etc/my.cnf export DB_ROOT_PASSWORD=$(hiera ''mysql::server::root_password'') kolla_set_configs sudo -u mysql -E kolla_extend_start timeout ${DB_MAX_TIMEOUT} /bin/bash -c ''while pgrep -af /usr/bin/mysqld_safe | grep -q -v grep; do sleep 1; done'' mysqld_safe --skip-networking --wsrep-on=OFF & timeout ${DB_MAX_TIMEOUT} /bin/bash -c ''until mysqladmin -uroot -p"$(hiera ''mysql::server::root_password'')" ping 2>/dev/null; do sleep 1; done'' mysql -uroot -p"$(hiera ''mysql::server::root_password'')" -e "CREATE USER ''clustercheck''@''localhost'' IDENTIFIED BY ''$(hiera mysql_clustercheck_password)'';" mysql -uroot -p"$(hiera ''mysql::server::root_password'')" -e "GRANT PROCESS ON *.* TO ''clustercheck''@''localhost'' WITH GRANT OPTION;" mysql -uroot -p"$(hiera ''mysql::server::root_password'')" -e "DELETE FROM mysql.user WHERE user = ''root'' AND host NOT IN (''%'',''localhost'');" timeout ${DB_MAX_TIMEOUT} mysqladmin -uroot -p"$(hiera ''mysql::server::root_password'')" shutdown' detach: false environment: DB_MARIABACKUP_PASSWORD: ZI2pDjceHGSDEXz32HE7X4JaS DB_MARIABACKUP_USER: mariabackup DB_MAX_TIMEOUT: 60 KOLLA_BOOTSTRAP: true KOLLA_CONFIG_STRATEGY: COPY_ALWAYS image: registry.redhat.io/rhosp-rhel9/openstack-mariadb:17.1 net: host start_order: 1 user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/mysql.json:/var/lib/kolla/config_files/config.json:rw,z - /var/lib/config-data/puppet-generated/mysql:/var/lib/kolla/config_files/src:ro,z - /var/lib/mysql:/var/lib/mysql:rw,z - /etc/pki/tls/certs/mysql.crt:/var/lib/kolla/config_files/src-tls/etc/pki/tls/certs/mysql.crt:ro - /etc/pki/tls/private/mysql.key:/var/lib/kolla/config_files/src-tls/etc/pki/tls/private/mysql.key:ro mysql_data_ownership: command: - chown - -R - 'mysql:' - /var/lib/mysql detach: false image: registry.redhat.io/rhosp-rhel9/openstack-mariadb:17.1 net: host start_order: 0 user: root volumes: - /var/lib/mysql:/var/lib/mysql:z rabbitmq_bootstrap: command: - bash - -ec - 'kolla_set_configs if [[ -e "/var/lib/rabbitmq/.erlang.cookie" ]]; then rm -f /var/lib/rabbitmq/.erlang.cookie; fi hiera ''rabbitmq::erlang_cookie'' > /var/lib/rabbitmq/.erlang.cookie chown rabbitmq:rabbitmq /var/lib/rabbitmq/.erlang.cookie chmod 400 /var/lib/rabbitmq/.erlang.cookie' environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS TRIPLEO_DEPLOY_IDENTIFIER: '1781077158' image: registry.redhat.io/rhosp-rhel9/openstack-rabbitmq:17.1 net: host privileged: false start_order: 0 user: root volumes: - /var/lib/kolla/config_files/rabbitmq.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/rabbitmq:/var/lib/kolla/config_files/src:ro - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /var/lib/rabbitmq:/var/lib/rabbitmq:z - /etc/puppet:/etc/puppet:ro,z redis_tls_proxy: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS image: registry.redhat.io/rhosp-rhel9/openstack-redis:17.1 net: host restart: always start_order: 0 user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/redis_tls_proxy.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/redis:/var/lib/kolla/config_files/src:ro - /etc/pki/tls/certs/redis.crt:/var/lib/kolla/config_files/src-tls/etc/pki/tls/certs/redis.crt:ro - /etc/pki/tls/private/redis.key:/var/lib/kolla/config_files/src-tls/etc/pki/tls/private/redis.key:ro - /var/lib/container-config-scripts/wait-port-and-run.sh:/wait-port-and-run.sh:ro step_2: aodh_init_log: command: - /bin/bash - -c - chown -R aodh:aodh /var/log/aodh image: registry.redhat.io/rhosp-rhel9/openstack-aodh-api:17.1 net: none user: root volumes: - /var/log/containers/aodh:/var/log/aodh:z - /var/log/containers/httpd/aodh-api:/var/log/httpd:z cinder_api_init_logs: command: - /bin/bash - -c - chown -R cinder:cinder /var/log/cinder image: registry.redhat.io/rhosp-rhel9/openstack-cinder-api:17.1 net: none privileged: false user: root volumes: - /var/log/containers/cinder:/var/log/cinder:z - /var/log/containers/httpd/cinder-api:/var/log/httpd:z cinder_scheduler_init_logs: command: - /bin/bash - -c - chown -R cinder:cinder /var/log/cinder image: registry.redhat.io/rhosp-rhel9/openstack-cinder-scheduler:17.1 net: none privileged: false user: root volumes: - /var/log/containers/cinder:/var/log/cinder:z clustercheck: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-mariadb:17.1 net: host restart: always start_order: 1 volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/clustercheck.json:/var/lib/kolla/config_files/config.json - /var/lib/config-data/puppet-generated/clustercheck:/var/lib/kolla/config_files/src:ro - /var/lib/mysql:/var/lib/mysql create_dnsmasq_wrapper: command: - /container_puppet_apply.sh - '4' - file - include ::tripleo::profile::base::neutron::dhcp_agent_wrappers detach: false image: registry.redhat.io/rhosp-rhel9/openstack-neutron-dhcp-agent:17.1 net: host pid: host start_order: 1 user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /var/lib/container-config-scripts/container_puppet_apply.sh:/container_puppet_apply.sh:ro - /etc/puppet:/tmp/puppet-etc:ro - /usr/share/openstack-puppet/modules:/usr/share/openstack-puppet/modules:ro - /run/openvswitch:/run/openvswitch:shared,z - /var/lib/neutron:/var/lib/neutron:shared,z create_haproxy_wrapper: command: - /container_puppet_apply.sh - '4' - file - include ::tripleo::profile::base::neutron::ovn_metadata_agent_wrappers detach: false image: registry.redhat.io/rhosp-rhel9/openstack-neutron-metadata-agent-ovn:17.1 net: host pid: host start_order: 1 user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /var/lib/container-config-scripts/container_puppet_apply.sh:/container_puppet_apply.sh:ro - /etc/puppet:/tmp/puppet-etc:ro - /usr/share/openstack-puppet/modules:/usr/share/openstack-puppet/modules:ro - /run/openvswitch:/run/openvswitch:shared,z - /var/lib/neutron:/var/lib/neutron:shared,z create_virtlogd_wrapper: cgroupns: host command: - /container_puppet_apply.sh - '4' - file - include ::tripleo::profile::base::nova::virtlogd_wrapper detach: false environment: TRIPLEO_DEPLOY_IDENTIFIER: '1781077158' image: registry.redhat.io/rhosp-rhel9/openstack-nova-libvirt:17.1 net: host pid: host start_order: 1 user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /var/lib/container-config-scripts/container_puppet_apply.sh:/container_puppet_apply.sh:ro - /etc/puppet:/tmp/puppet-etc:ro - /usr/share/openstack-puppet/modules:/usr/share/openstack-puppet/modules:ro - /var/lib/container-config-scripts:/var/lib/container-config-scripts:shared,z glance_init_logs: command: - /bin/bash - -c - chown -R glance:glance /var/log/glance image: registry.redhat.io/rhosp-rhel9/openstack-glance-api:17.1 net: none privileged: false user: root volumes: - /var/log/containers/glance:/var/log/glance:z - /var/log/containers/httpd/glance:/var/log/httpd:z gnocchi_init_lib: command: - /bin/bash - -c - chown -R gnocchi:gnocchi /var/lib/gnocchi image: registry.redhat.io/rhosp-rhel9/openstack-gnocchi-api:17.1 net: none user: root volumes: - /var/lib/gnocchi:/var/lib/gnocchi:shared,z gnocchi_init_log: command: - /bin/bash - -c - chown -R gnocchi:gnocchi /var/log/gnocchi image: registry.redhat.io/rhosp-rhel9/openstack-gnocchi-api:17.1 net: none user: root volumes: - /var/log/containers/gnocchi:/var/log/gnocchi:z - /var/log/containers/httpd/gnocchi-api:/var/log/httpd:z heat_init_log: command: - /bin/bash - -c - chown -R heat:heat /var/log/heat image: registry.redhat.io/rhosp-rhel9/openstack-heat-engine:17.1 net: none user: root volumes: - /var/log/containers/heat:/var/log/heat:z horizon_fix_perms: command: - /bin/bash - -c - touch /var/log/horizon/horizon.log ; chown -R apache:apache /var/log/horizon && chmod -R a+rx /etc/openstack-dashboard image: registry.redhat.io/rhosp-rhel9/openstack-horizon:17.1 net: none user: root volumes: - /var/log/containers/horizon:/var/log/horizon:z - /var/log/containers/httpd/horizon:/var/log/httpd:z - /var/lib/config-data/puppet-generated/horizon/etc/openstack-dashboard:/etc/openstack-dashboard keystone_init_log: command: - /bin/bash - -c - chown -R keystone:keystone /var/log/keystone image: registry.redhat.io/rhosp-rhel9/openstack-keystone:17.1 net: none start_order: 1 user: root volumes: - /var/log/containers/keystone:/var/log/keystone:z - /var/log/containers/httpd/keystone:/var/log/httpd:z manila_init_logs: command: - /bin/bash - -c - chown -R manila:manila /var/log/manila image: registry.redhat.io/rhosp-rhel9/openstack-manila-api:17.1 net: none user: root volumes: - /var/log/containers/manila:/var/log/manila:z - /var/log/containers/httpd/manila-api:/var/log/httpd:z mysql_wait_bundle: command: - /container_puppet_apply.sh - '2' - file,file_line,concat,augeas,galera_ready,mysql_database,mysql_grant,mysql_user - include tripleo::profile::pacemaker::database::mysql_bundle detach: false environment: TRIPLEO_DEPLOY_IDENTIFIER: '1781077158' image: registry.redhat.io/rhosp-rhel9/openstack-mariadb:17.1 ipc: host net: host start_order: 0 user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /var/lib/container-config-scripts/container_puppet_apply.sh:/container_puppet_apply.sh:ro - /etc/puppet:/tmp/puppet-etc:ro - /usr/share/openstack-puppet/modules:/usr/share/openstack-puppet/modules:ro - /var/lib/mysql:/var/lib/mysql:rw,z - /var/lib/config-data/puppet-generated/mysql/root:/root:rw neutron_init_logs: command: - /bin/bash - -c - chown -R neutron:neutron /var/log/neutron image: registry.redhat.io/rhosp-rhel9/openstack-neutron-server:17.1 net: none privileged: false user: root volumes: - /var/log/containers/neutron:/var/log/neutron:z - /var/log/containers/httpd/neutron-api:/var/log/httpd:z nova_api_init_logs: command: - /bin/bash - -c - chown -R nova:nova /var/log/nova environment: TRIPLEO_DEPLOY_IDENTIFIER: '1781077158' image: registry.redhat.io/rhosp-rhel9/openstack-nova-api:17.1 net: none privileged: false user: root volumes: - /var/log/containers/nova:/var/log/nova:z - /var/log/containers/httpd/nova-api:/var/log/httpd:z nova_compute_init_log: command: - /bin/bash - -c - chown -R nova:nova /var/log/nova environment: TRIPLEO_DEPLOY_IDENTIFIER: '1781077158' image: registry.redhat.io/rhosp-rhel9/openstack-nova-compute:17.1 net: none privileged: false user: root volumes: - /var/log/containers/nova:/var/log/nova:z nova_conductor_init_log: command: - /bin/bash - -c - chown -R nova:nova /var/log/nova environment: TRIPLEO_DEPLOY_IDENTIFIER: '1781077158' image: registry.redhat.io/rhosp-rhel9/openstack-nova-conductor:17.1 net: none privileged: false user: root volumes: - /var/log/containers/nova:/var/log/nova:z nova_metadata_init_logs: command: - /bin/bash - -c - chown -R nova:nova /var/log/nova image: registry.redhat.io/rhosp-rhel9/openstack-nova-api:17.1 net: none privileged: false user: root volumes: - /var/log/containers/nova:/var/log/nova:z - /var/log/containers/httpd/nova-metadata:/var/log/httpd:z nova_virtqemud_init_logs: command: - /bin/bash - -c - chown -R tss:tss /var/log/swtpm environment: TRIPLEO_DEPLOY_IDENTIFIER: '1781077158' image: registry.redhat.io/rhosp-rhel9/openstack-nova-libvirt:17.1 net: none privileged: true security_opt: - label=level:s0 - label=type:spc_t - label=filetype:container_file_t user: root volumes: - /var/log/containers/libvirt/swtpm:/var/log/swtpm:shared,z octavia_api_init_dirs: command: - /bin/bash - -c - mkdir -p /etc/octavia/conf.d/octavia-api; chown -R octavia:octavia /etc/octavia/conf.d/octavia-api; chown -R octavia:octavia /var/log/octavia image: registry.redhat.io/rhosp-rhel9/openstack-octavia-api:17.1 net: none start_order: 0 user: root volumes: - /var/lib/config-data/puppet-generated/octavia/etc/octavia:/etc/octavia - /var/log/containers/octavia:/var/log/octavia:z - /var/log/containers/httpd/octavia-api:/var/log/httpd:z octavia_health_manager_init_dirs: command: - /bin/bash - -c - mkdir -p /etc/octavia/conf.d/octavia-health-manager; chown -R octavia:octavia /etc/octavia/conf.d/octavia-health-manager image: registry.redhat.io/rhosp-rhel9/openstack-octavia-health-manager:17.1 net: none start_order: 0 user: root volumes: - /var/lib/config-data/puppet-generated/octavia/etc/octavia:/etc/octavia:z octavia_housekeeping_init_dirs: command: - /bin/bash - -c - mkdir -p /etc/octavia/conf.d/octavia-housekeeping; chown -R octavia:octavia /etc/octavia/conf.d/octavia-housekeeping image: registry.redhat.io/rhosp-rhel9/openstack-octavia-housekeeping:17.1 net: none start_order: 0 user: root volumes: - /var/lib/config-data/puppet-generated/octavia/etc/octavia:/etc/octavia:z octavia_worker_init_dirs: command: - /bin/bash - -c - mkdir -p /etc/octavia/conf.d/octavia-worker; chown -R octavia:octavia /etc/octavia/conf.d/octavia-worker image: registry.redhat.io/rhosp-rhel9/openstack-octavia-worker:17.1 net: none start_order: 0 user: root volumes: - /var/lib/config-data/puppet-generated/octavia/etc/octavia:/etc/octavia:z placement_init_log: command: - /bin/bash - -c - chown -R placement:placement /var/log/placement image: registry.redhat.io/rhosp-rhel9/openstack-placement-api:17.1 net: none start_order: 1 user: root volumes: - /var/log/containers/placement:/var/log/placement:z - /var/log/containers/httpd/placement:/var/log/httpd:z rabbitmq_wait_bundle: command: - /container_puppet_apply.sh - '2' - file,file_line,concat,augeas,rabbitmq_policy,rabbitmq_user,rabbitmq_ready - include tripleo::profile::pacemaker::rabbitmq_bundle - '' detach: false environment: KOLLA_BOOTSTRAP: true KOLLA_CONFIG_STRATEGY: COPY_ALWAYS TRIPLEO_DEPLOY_IDENTIFIER: '1781077158' image: registry.redhat.io/rhosp-rhel9/openstack-rabbitmq:17.1 ipc: host net: host start_order: 0 user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /var/lib/container-config-scripts/container_puppet_apply.sh:/container_puppet_apply.sh:ro - /etc/puppet:/tmp/puppet-etc:ro - /usr/share/openstack-puppet/modules:/usr/share/openstack-puppet/modules:ro - /bin/true:/bin/epmd step_3: aodh_db_sync: cap_add: - AUDIT_WRITE detach: false environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS TRIPLEO_DEPLOY_IDENTIFIER: '1781077158' image: registry.redhat.io/rhosp-rhel9/openstack-aodh-api:17.1 net: host privileged: false user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/aodh_api_db_sync.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/aodh:/var/lib/kolla/config_files/src:ro - /var/log/containers/aodh:/var/log/aodh - /var/log/containers/httpd/aodh-api:/var/log/httpd - /etc/pki/tls/certs/httpd:/etc/pki/tls/certs/httpd:ro - /etc/pki/tls/private/httpd:/etc/pki/tls/private/httpd:ro ceilometer_init_log: command: - /bin/bash - -c - chown -R ceilometer:ceilometer /var/log/ceilometer image: registry.redhat.io/rhosp-rhel9/openstack-ceilometer-notification:17.1 net: none start_order: 0 user: root volumes: - /var/log/containers/ceilometer:/var/log/ceilometer:z cinder_api_db_sync: cap_add: - AUDIT_WRITE detach: false environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS TRIPLEO_DEPLOY_IDENTIFIER: '1781077158' image: registry.redhat.io/rhosp-rhel9/openstack-cinder-api:17.1 net: host privileged: false user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/cinder_api_db_sync.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/cinder:/var/lib/kolla/config_files/src:ro - /var/log/containers/cinder:/var/log/cinder:z - /etc/pki/tls/certs/httpd:/etc/pki/tls/certs/httpd:ro - /etc/pki/tls/private/httpd:/etc/pki/tls/private/httpd:ro cinder_backup_init_logs: command: - /bin/bash - -c - chown -R cinder:cinder /var/log/cinder image: registry.redhat.io/rhosp-rhel9/openstack-cinder-backup:17.1 net: none privileged: false start_order: 0 user: root volumes: - /var/log/containers/cinder:/var/log/cinder:z cinder_volume_init_logs: command: - /bin/bash - -c - chown -R cinder:cinder /var/log/cinder image: registry.redhat.io/rhosp-rhel9/openstack-cinder-volume:17.1 net: none privileged: false start_order: 0 user: root volumes: - /var/log/containers/cinder:/var/log/cinder glance_api_db_sync: cap_add: - AUDIT_WRITE command: /usr/bin/bootstrap_host_exec glance_api su glance -s /bin/bash -c '/usr/local/bin/kolla_start' detach: false environment: KOLLA_BOOTSTRAP: true KOLLA_CONFIG_STRATEGY: COPY_ALWAYS TRIPLEO_DEPLOY_IDENTIFIER: '1781077158' image: registry.redhat.io/rhosp-rhel9/openstack-glance-api:17.1 net: host privileged: false user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/glance:/var/log/glance:z - /var/log/containers/httpd/glance:/var/log/httpd:z - /var/lib/kolla/config_files/glance_api.json:/var/lib/kolla/config_files/config.json - /var/lib/config-data/puppet-generated/glance_api:/var/lib/kolla/config_files/src:ro - /var/lib/tripleo-config/ceph:/var/lib/kolla/config_files/src-ceph:z - /var/lib/config-data/puppet-generated/iscsid/etc/iscsi:/var/lib/kolla/config_files/src-iscsid:ro - /var/lib/glance:/var/lib/glance:shared heat_engine_db_sync: cap_add: - AUDIT_WRITE detach: false environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS TRIPLEO_DEPLOY_IDENTIFIER: '1781077158' image: registry.redhat.io/rhosp-rhel9/openstack-heat-engine:17.1 net: host privileged: false user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/heat:/var/log/heat:z - /var/lib/kolla/config_files/heat_engine_db_sync.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/heat:/var/lib/kolla/config_files/src:ro horizon: environment: ENABLE_DESIGNATE: 'yes' ENABLE_HEAT: 'yes' ENABLE_IRONIC: 'yes' ENABLE_MANILA: 'yes' ENABLE_OCTAVIA: 'yes' KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-horizon:17.1 net: host privileged: false restart: always volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/horizon.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/horizon:/var/lib/kolla/config_files/src:ro - /var/log/containers/horizon:/var/log/horizon:z - /var/log/containers/httpd/horizon:/var/log/httpd:z - /var/tmp/horizon:/var/tmp:z - /var/www:/var/www:ro - /etc/pki/tls/certs/httpd:/etc/pki/tls/certs/httpd:ro - /etc/pki/tls/private/httpd:/etc/pki/tls/private/httpd:ro iscsid: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-iscsid:17.1 net: host privileged: true restart: always start_order: 2 volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/iscsid.json:/var/lib/kolla/config_files/config.json:ro - /dev:/dev - /run:/run - /sys:/sys - /lib/modules:/lib/modules:ro - /var/lib/config-data/puppet-generated/iscsid/etc/iscsi:/var/lib/kolla/config_files/src-iscsid:ro - /etc/target:/etc/target:z - /var/lib/iscsi:/var/lib/iscsi:z keystone: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-keystone:17.1 net: host privileged: false restart: always start_order: 2 volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/keystone:/var/log/keystone:z - /var/log/containers/httpd/keystone:/var/log/httpd:z - /etc/openldap:/etc/openldap:ro - /var/lib/kolla/config_files/keystone.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/keystone:/var/lib/kolla/config_files/src:ro - /etc/pki/tls/certs/httpd:/etc/pki/tls/certs/httpd:ro - /etc/pki/tls/private/httpd:/etc/pki/tls/private/httpd:ro keystone_bootstrap: action: exec command: - keystone - /usr/bin/bootstrap_host_exec - keystone - keystone-manage - bootstrap environment: KOLLA_BOOTSTRAP: true OS_BOOTSTRAP_ADMIN_URL: https://overcloud.ctlplane.ooo.test:35357 OS_BOOTSTRAP_INTERNAL_URL: https://overcloud.internalapi.ooo.test:5000 OS_BOOTSTRAP_PASSWORD: SwgFbrMt8B1Saf9uGUAecG5I5 OS_BOOTSTRAP_PROJECT_NAME: admin OS_BOOTSTRAP_PUBLIC_URL: https://standalone.ooo.test:13000 OS_BOOTSTRAP_REGION_ID: regionOne OS_BOOTSTRAP_ROLE_NAME: admin OS_BOOTSTRAP_SERVICE_NAME: keystone OS_BOOTSTRAP_USERNAME: admin start_order: 3 user: root keystone_cron: command: - /bin/bash - -c - /usr/local/bin/kolla_set_configs && /usr/sbin/crond -n environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /usr/share/openstack-tripleo-common/healthcheck/cron keystone image: registry.redhat.io/rhosp-rhel9/openstack-keystone:17.1 net: host privileged: false restart: always start_order: 4 user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/keystone:/var/log/keystone:z - /var/log/containers/httpd/keystone:/var/log/httpd:z - /var/lib/kolla/config_files/keystone_cron.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/keystone:/var/lib/kolla/config_files/src:ro keystone_db_sync: command: - /usr/bin/bootstrap_host_exec - keystone - /usr/local/bin/kolla_start detach: false environment: KOLLA_BOOTSTRAP: true KOLLA_CONFIG_STRATEGY: COPY_ALWAYS TRIPLEO_DEPLOY_IDENTIFIER: '1781077158' image: registry.redhat.io/rhosp-rhel9/openstack-keystone:17.1 net: host privileged: false user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/keystone:/var/log/keystone:z - /var/log/containers/httpd/keystone:/var/log/httpd:z - /etc/openldap:/etc/openldap:ro - /var/lib/kolla/config_files/keystone.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/keystone:/var/lib/kolla/config_files/src:ro - /etc/pki/tls/certs/httpd:/etc/pki/tls/certs/httpd:ro - /etc/pki/tls/private/httpd:/etc/pki/tls/private/httpd:ro manila_api_db_sync: cap_add: - AUDIT_WRITE detach: false environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS image: registry.redhat.io/rhosp-rhel9/openstack-manila-api:17.1 net: host user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/manila_api_db_sync.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/manila:/var/lib/kolla/config_files/src:ro - /var/log/containers/manila:/var/log/manila:z manila_share_init_logs: command: - /bin/bash - -c - chown -R manila:manila /var/log/manila image: registry.redhat.io/rhosp-rhel9/openstack-manila-share:17.1 net: none privileged: false start_order: 0 user: root volumes: - /var/log/containers/manila:/var/log/manila:z neutron_db_sync: cap_add: - AUDIT_WRITE detach: false environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS TRIPLEO_DEPLOY_IDENTIFIER: '1781077158' image: registry.redhat.io/rhosp-rhel9/openstack-neutron-server:17.1 net: host privileged: false user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/neutron:/var/log/neutron:z - /var/log/containers/httpd/neutron-api:/var/log/httpd:z - /var/lib/kolla/config_files/neutron_api_db_sync.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/neutron:/var/lib/kolla/config_files/src:ro nova_api_db_sync: cap_add: - AUDIT_WRITE detach: false environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS TRIPLEO_DEPLOY_IDENTIFIER: '1781077158' image: registry.redhat.io/rhosp-rhel9/openstack-nova-api:17.1 net: host start_order: 0 user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/nova:/var/log/nova:z - /var/log/containers/httpd/nova-api:/var/log/httpd:z - /var/lib/kolla/config_files/nova_api_db_sync.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/nova:/var/lib/kolla/config_files/src:ro nova_api_ensure_default_cells: detach: false environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS __OS_DEBUG: 'true' image: registry.redhat.io/rhosp-rhel9/openstack-nova-api:17.1 net: host privileged: false start_order: 1 user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/nova:/var/log/nova:z - /var/log/containers/httpd/nova-api:/var/log/httpd:z - /var/lib/kolla/config_files/nova_api_ensure_default_cells.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/nova:/var/lib/kolla/config_files/src:ro - /var/lib/container-config-scripts:/container-config-scripts:z nova_db_sync: cap_add: - AUDIT_WRITE detach: false environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS TRIPLEO_DEPLOY_IDENTIFIER: '1781077158' image: registry.redhat.io/rhosp-rhel9/openstack-nova-conductor:17.1 net: host start_order: 3 user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/nova:/var/log/nova - /var/lib/kolla/config_files/nova_conductor_db_sync.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/nova:/var/lib/kolla/config_files/src:ro nova_statedir_owner: command: /container-config-scripts/pyshim.sh /container-config-scripts/nova_statedir_ownership.py detach: false environment: NOVA_STATEDIR_OWNERSHIP_SKIP: triliovault-mounts TRIPLEO_DEPLOY_IDENTIFIER: '1781077158' __OS_DEBUG: 'true' image: registry.redhat.io/rhosp-rhel9/openstack-nova-compute:17.1 net: none privileged: false security_opt: - label=disable user: root volumes: - /var/lib/nova:/var/lib/nova:shared - /var/lib/_nova_secontext:/var/lib/_nova_secontext:shared,z - /var/lib/container-config-scripts:/container-config-scripts:z nova_virtlogd_wrapper: cgroupns: host environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS image: registry.redhat.io/rhosp-rhel9/openstack-nova-libvirt:17.1 net: host pid: host privileged: true restart: always security_opt: - label=level:s0 - label=type:spc_t - label=filetype:container_file_t start_order: 0 ulimit: - nofile=131072 - nproc=126960 volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/libvirt:/var/log/libvirt:shared,z - /lib/modules:/lib/modules:ro - /dev:/dev - /run:/run - /sys/fs/cgroup:/sys/fs/cgroup - /sys/fs/selinux:/sys/fs/selinux - /etc/selinux/config:/etc/selinux/config:ro - /etc/libvirt:/etc/libvirt:shared - /etc/ssh/ssh_known_hosts:/etc/ssh/ssh_known_hosts:ro - /run/libvirt:/run/libvirt:shared,z - /var/lib/nova:/var/lib/nova:shared - /var/lib/libvirt:/var/lib/libvirt:shared - /var/cache/libvirt:/var/cache/libvirt:shared - /var/lib/vhost_sockets:/var/lib/vhost_sockets - /var/lib/config-data/puppet-generated/nova_libvirt:/var/lib/kolla/config_files/src:ro - /var/lib/tripleo-config/ceph:/var/lib/kolla/config_files/src-ceph:z - /etc/pki/CA/cacert.pem:/etc/pki/CA/cacert.pem:ro - /etc/pki/libvirt:/etc/pki/libvirt:ro - /etc/pki/qemu:/etc/pki/qemu:ro - /var/lib/kolla/config_files/nova_virtlogd.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/container-config-scripts/virtlogd_wrapper:/usr/local/bin/virtlogd_wrapper:ro nova_virtnodedevd: cgroupns: host depends_on: - tripleo_nova_virtlogd_wrapper.service environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS image: registry.redhat.io/rhosp-rhel9/openstack-nova-libvirt:17.1 net: host pid: host pids_limit: 65536 privileged: true restart: always security_opt: - label=level:s0 - label=type:spc_t - label=filetype:container_file_t start_order: 2 ulimit: - nofile=131072 - nproc=126960 volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/libvirt:/var/log/libvirt:shared,z - /lib/modules:/lib/modules:ro - /dev:/dev - /run:/run - /sys/fs/cgroup:/sys/fs/cgroup - /sys/fs/selinux:/sys/fs/selinux - /etc/selinux/config:/etc/selinux/config:ro - /etc/libvirt:/etc/libvirt:shared - /etc/ssh/ssh_known_hosts:/etc/ssh/ssh_known_hosts:ro - /run/libvirt:/run/libvirt:shared,z - /var/lib/nova:/var/lib/nova:shared - /var/lib/libvirt:/var/lib/libvirt:shared - /var/cache/libvirt:/var/cache/libvirt:shared - /var/lib/vhost_sockets:/var/lib/vhost_sockets - /var/lib/config-data/puppet-generated/nova_libvirt:/var/lib/kolla/config_files/src:ro - /var/lib/tripleo-config/ceph:/var/lib/kolla/config_files/src-ceph:z - /etc/pki/CA/cacert.pem:/etc/pki/CA/cacert.pem:ro - /etc/pki/libvirt:/etc/pki/libvirt:ro - /etc/pki/qemu:/etc/pki/qemu:ro - /var/lib/kolla/config_files/nova_virtnodedevd.json:/var/lib/kolla/config_files/config.json:ro nova_virtproxyd: cgroupns: host depends_on: - tripleo_nova_virtlogd_wrapper.service environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS image: registry.redhat.io/rhosp-rhel9/openstack-nova-libvirt:17.1 net: host pid: host pids_limit: 65536 privileged: true restart: always security_opt: - label=level:s0 - label=type:spc_t - label=filetype:container_file_t start_order: 5 ulimit: - nofile=131072 - nproc=126960 volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/libvirt:/var/log/libvirt:shared,z - /lib/modules:/lib/modules:ro - /dev:/dev - /run:/run - /sys/fs/cgroup:/sys/fs/cgroup - /sys/fs/selinux:/sys/fs/selinux - /etc/selinux/config:/etc/selinux/config:ro - /etc/libvirt:/etc/libvirt:shared - /etc/ssh/ssh_known_hosts:/etc/ssh/ssh_known_hosts:ro - /run/libvirt:/run/libvirt:shared,z - /var/lib/nova:/var/lib/nova:shared - /var/lib/libvirt:/var/lib/libvirt:shared - /var/cache/libvirt:/var/cache/libvirt:shared - /var/lib/vhost_sockets:/var/lib/vhost_sockets - /var/lib/config-data/puppet-generated/nova_libvirt:/var/lib/kolla/config_files/src:ro - /var/lib/tripleo-config/ceph:/var/lib/kolla/config_files/src-ceph:z - /etc/pki/CA/cacert.pem:/etc/pki/CA/cacert.pem:ro - /etc/pki/libvirt:/etc/pki/libvirt:ro - /etc/pki/qemu:/etc/pki/qemu:ro - /var/lib/kolla/config_files/nova_virtproxyd.json:/var/lib/kolla/config_files/config.json:ro nova_virtqemud: cgroupns: host depends_on: - tripleo_nova_virtlogd_wrapper.service environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS image: registry.redhat.io/rhosp-rhel9/openstack-nova-libvirt:17.1 net: host pid: host pids_limit: 65536 privileged: true restart: always security_opt: - label=level:s0 - label=type:spc_t - label=filetype:container_file_t start_order: 4 ulimit: - nofile=131072 - nproc=126960 volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/libvirt:/var/log/libvirt:shared,z - /lib/modules:/lib/modules:ro - /dev:/dev - /run:/run - /sys/fs/cgroup:/sys/fs/cgroup - /sys/fs/selinux:/sys/fs/selinux - /etc/selinux/config:/etc/selinux/config:ro - /etc/libvirt:/etc/libvirt:shared - /etc/ssh/ssh_known_hosts:/etc/ssh/ssh_known_hosts:ro - /run/libvirt:/run/libvirt:shared,z - /var/lib/nova:/var/lib/nova:shared - /var/lib/libvirt:/var/lib/libvirt:shared - /var/cache/libvirt:/var/cache/libvirt:shared - /var/lib/vhost_sockets:/var/lib/vhost_sockets - /var/lib/config-data/puppet-generated/nova_libvirt:/var/lib/kolla/config_files/src:ro - /var/lib/tripleo-config/ceph:/var/lib/kolla/config_files/src-ceph:z - /etc/pki/CA/cacert.pem:/etc/pki/CA/cacert.pem:ro - /etc/pki/libvirt:/etc/pki/libvirt:ro - /etc/pki/qemu:/etc/pki/qemu:ro - /var/lib/kolla/config_files/nova_virtqemud.json:/var/lib/kolla/config_files/config.json:ro - /var/log/containers/libvirt/swtpm:/var/log/swtpm:z nova_virtsecretd: cgroupns: host depends_on: - tripleo_nova_virtlogd_wrapper.service environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS image: registry.redhat.io/rhosp-rhel9/openstack-nova-libvirt:17.1 net: host pid: host pids_limit: 65536 privileged: true restart: always security_opt: - label=level:s0 - label=type:spc_t - label=filetype:container_file_t start_order: 1 ulimit: - nofile=131072 - nproc=126960 volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/libvirt:/var/log/libvirt:shared,z - /lib/modules:/lib/modules:ro - /dev:/dev - /run:/run - /sys/fs/cgroup:/sys/fs/cgroup - /sys/fs/selinux:/sys/fs/selinux - /etc/selinux/config:/etc/selinux/config:ro - /etc/libvirt:/etc/libvirt:shared - /etc/ssh/ssh_known_hosts:/etc/ssh/ssh_known_hosts:ro - /run/libvirt:/run/libvirt:shared,z - /var/lib/nova:/var/lib/nova:shared - /var/lib/libvirt:/var/lib/libvirt:shared - /var/cache/libvirt:/var/cache/libvirt:shared - /var/lib/vhost_sockets:/var/lib/vhost_sockets - /var/lib/config-data/puppet-generated/nova_libvirt:/var/lib/kolla/config_files/src:ro - /var/lib/tripleo-config/ceph:/var/lib/kolla/config_files/src-ceph:z - /etc/pki/CA/cacert.pem:/etc/pki/CA/cacert.pem:ro - /etc/pki/libvirt:/etc/pki/libvirt:ro - /etc/pki/qemu:/etc/pki/qemu:ro - /var/lib/kolla/config_files/nova_virtsecretd.json:/var/lib/kolla/config_files/config.json:ro nova_virtstoraged: cgroupns: host depends_on: - tripleo_nova_virtlogd_wrapper.service environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS image: registry.redhat.io/rhosp-rhel9/openstack-nova-libvirt:17.1 net: host pid: host pids_limit: 65536 privileged: true restart: always security_opt: - label=level:s0 - label=type:spc_t - label=filetype:container_file_t start_order: 3 ulimit: - nofile=131072 - nproc=126960 volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/libvirt:/var/log/libvirt:shared,z - /lib/modules:/lib/modules:ro - /dev:/dev - /run:/run - /sys/fs/cgroup:/sys/fs/cgroup - /sys/fs/selinux:/sys/fs/selinux - /etc/selinux/config:/etc/selinux/config:ro - /etc/libvirt:/etc/libvirt:shared - /etc/ssh/ssh_known_hosts:/etc/ssh/ssh_known_hosts:ro - /run/libvirt:/run/libvirt:shared,z - /var/lib/nova:/var/lib/nova:shared - /var/lib/libvirt:/var/lib/libvirt:shared - /var/cache/libvirt:/var/cache/libvirt:shared - /var/lib/vhost_sockets:/var/lib/vhost_sockets - /var/lib/config-data/puppet-generated/nova_libvirt:/var/lib/kolla/config_files/src:ro - /var/lib/tripleo-config/ceph:/var/lib/kolla/config_files/src-ceph:z - /etc/pki/CA/cacert.pem:/etc/pki/CA/cacert.pem:ro - /etc/pki/libvirt:/etc/pki/libvirt:ro - /etc/pki/qemu:/etc/pki/qemu:ro - /var/lib/kolla/config_files/nova_virtstoraged.json:/var/lib/kolla/config_files/config.json:ro octavia_db_sync: cap_add: - AUDIT_WRITE detach: false environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS TRIPLEO_DEPLOY_IDENTIFIER: '1781077158' image: registry.redhat.io/rhosp-rhel9/openstack-octavia-api:17.1 net: host privileged: false start_order: 0 user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/octavia_api_db_sync.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/octavia:/var/lib/kolla/config_files/src:ro - /var/log/containers/octavia:/var/log/octavia:z - /run/octavia:/run/octavia:shared,z - /etc/pki/tls/certs/ovn_octavia.crt:/var/lib/kolla/config_files/src-tls/etc/pki/tls/certs/ovn_octavia.crt:ro - /etc/pki/tls/private/ovn_octavia.key:/var/lib/kolla/config_files/src-tls/etc/pki/tls/private/ovn_octavia.key:ro placement_api_db_sync: cap_add: - AUDIT_WRITE detach: false environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS TRIPLEO_DEPLOY_IDENTIFIER: '1781077158' image: registry.redhat.io/rhosp-rhel9/openstack-placement-api:17.1 net: host start_order: 1 user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/placement:/var/log/placement:z - /var/log/containers/httpd/placement:/var/log/httpd:z - /var/lib/kolla/config_files/placement_api_db_sync.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/placement:/var/lib/kolla/config_files/src:ro swift_copy_rings: command: - /bin/bash - -c - cp -v -dR --preserve -t /etc/swift /swift_ringbuilder/etc/swift/*.gz /swift_ringbuilder/etc/swift/*.builder /swift_ringbuilder/etc/swift/backups detach: false environment: TRIPLEO_DEPLOY_IDENTIFIER: '1781077158' image: registry.redhat.io/rhosp-rhel9/openstack-swift-proxy-server:17.1 net: none user: root volumes: - /var/lib/config-data/puppet-generated/swift/etc/swift:/etc/swift:rw,z - /var/lib/config-data/puppet-generated/swift_ringbuilder:/swift_ringbuilder:ro swift_setup_srv: command: - find - /srv/node - -maxdepth - '1' - -type - d - -exec - chown - 'swift:' - '{}' - ; environment: TRIPLEO_DEPLOY_IDENTIFIER: '1781077158' image: registry.redhat.io/rhosp-rhel9/openstack-swift-account:17.1 net: none user: root volumes: - /srv/node:/srv/node:z step_4: aodh_api: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-aodh-api:17.1 net: host privileged: false restart: always volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/aodh_api.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/aodh:/var/lib/kolla/config_files/src:ro - /var/log/containers/aodh:/var/log/aodh - /var/log/containers/httpd/aodh-api:/var/log/httpd - /etc/pki/tls/certs/httpd:/etc/pki/tls/certs/httpd:ro - /etc/pki/tls/private/httpd:/etc/pki/tls/private/httpd:ro aodh_api_cron: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /usr/share/openstack-tripleo-common/healthcheck/cron aodh image: registry.redhat.io/rhosp-rhel9/openstack-aodh-api:17.1 net: host privileged: false restart: always user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/aodh_api_cron.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/aodh:/var/lib/kolla/config_files/src:ro - /var/log/containers/aodh:/var/log/aodh - /var/log/containers/httpd/aodh-api:/var/log/httpd aodh_evaluator: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-aodh-evaluator:17.1 net: host privileged: false restart: always volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/aodh_evaluator.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/aodh:/var/lib/kolla/config_files/src:ro - /var/log/containers/aodh:/var/log/aodh:z aodh_listener: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck 5672 image: registry.redhat.io/rhosp-rhel9/openstack-aodh-listener:17.1 net: host privileged: false restart: always volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/aodh_listener.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/aodh:/var/lib/kolla/config_files/src:ro - /var/log/containers/aodh:/var/log/aodh:z aodh_notifier: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck 5672 image: registry.redhat.io/rhosp-rhel9/openstack-aodh-notifier:17.1 net: host privileged: false restart: always volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/aodh_notifier.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/aodh:/var/lib/kolla/config_files/src:ro - /var/log/containers/aodh:/var/log/aodh:z ceilometer_agent_central: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-ceilometer-central:17.1 net: host privileged: false restart: always volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/ceilometer_agent_central.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/ceilometer:/var/lib/kolla/config_files/src:ro - /var/log/containers/ceilometer:/var/log/ceilometer:z ceilometer_agent_compute: depends_on: - tripleo_nova_libvirt.target environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-ceilometer-compute:17.1 net: host privileged: false restart: always volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/ceilometer_agent_compute.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/ceilometer:/var/lib/kolla/config_files/src:ro - /run/libvirt:/run/libvirt:shared,z - /var/log/containers/ceilometer:/var/log/ceilometer:z ceilometer_agent_notification: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck 5672 image: registry.redhat.io/rhosp-rhel9/openstack-ceilometer-notification:17.1 net: host privileged: false restart: always volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/ceilometer_agent_notification.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/ceilometer:/var/lib/kolla/config_files/src:ro - /var/log/containers/ceilometer:/var/log/ceilometer:z cinder_api: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-cinder-api:17.1 net: host privileged: false restart: always user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/cinder_api.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/cinder:/var/lib/kolla/config_files/src:ro - /var/log/containers/cinder:/var/log/cinder:z - /var/log/containers/httpd/cinder-api:/var/log/httpd:z - /etc/pki/tls/certs/httpd:/etc/pki/tls/certs/httpd:ro - /etc/pki/tls/private/httpd:/etc/pki/tls/private/httpd:ro cinder_api_cron: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /usr/share/openstack-tripleo-common/healthcheck/cron cinder image: registry.redhat.io/rhosp-rhel9/openstack-cinder-api:17.1 net: host privileged: false restart: always user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/cinder_api_cron.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/cinder:/var/lib/kolla/config_files/src:ro - /var/log/containers/cinder:/var/log/cinder:z - /var/log/containers/httpd/cinder-api:/var/log/httpd:z cinder_scheduler: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck 5672 image: registry.redhat.io/rhosp-rhel9/openstack-cinder-scheduler:17.1 net: host privileged: false restart: always volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/config-data/puppet-generated/cinder:/var/lib/kolla/config_files/src:ro - /var/log/containers/cinder:/var/log/cinder:z - /var/lib/kolla/config_files/cinder_scheduler.json:/var/lib/kolla/config_files/config.json:ro configure_cms_options: command: - /bin/bash - -c - CMS_OPTS=$(hiera ovn::controller::ovn_cms_options -c /etc/puppet/hiera.yaml); if [ X"$CMS_OPTS" != X ]; then ovs-vsctl set open . external_ids:ovn-cms-options=$CMS_OPTS;else ovs-vsctl remove open . external_ids ovn-cms-options; fi detach: false environment: TRIPLEO_DEPLOY_IDENTIFIER: '1781077158' image: registry.redhat.io/rhosp-rhel9/openstack-ovn-controller:17.1 net: host privileged: true start_order: 0 user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /lib/modules:/lib/modules:ro - /run/openvswitch:/run/openvswitch:shared,z glance_api: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-glance-api:17.1 net: host privileged: false restart: always start_order: 2 volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/glance:/var/log/glance:z - /var/log/containers/httpd/glance:/var/log/httpd:z - /var/lib/kolla/config_files/glance_api.json:/var/lib/kolla/config_files/config.json - /var/lib/config-data/puppet-generated/glance_api:/var/lib/kolla/config_files/src:ro - /var/lib/tripleo-config/ceph:/var/lib/kolla/config_files/src-ceph:z - /var/lib/config-data/puppet-generated/iscsid/etc/iscsi:/var/lib/kolla/config_files/src-iscsid:ro - /var/lib/glance:/var/lib/glance:shared glance_api_cron: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /usr/share/openstack-tripleo-common/healthcheck/cron glance image: registry.redhat.io/rhosp-rhel9/openstack-glance-api:17.1 net: host privileged: false restart: always start_order: 2 user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/glance:/var/log/glance:z - /var/log/containers/httpd/glance:/var/log/httpd:z - /var/lib/kolla/config_files/glance_api_cron.json:/var/lib/kolla/config_files/config.json - /var/lib/config-data/puppet-generated/glance_api:/var/lib/kolla/config_files/src:ro - /var/lib/glance:/var/lib/glance:shared glance_api_internal: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-glance-api:17.1 net: host privileged: false restart: always start_order: 2 volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/glance:/var/log/glance:z - /var/log/containers/httpd/glance:/var/log/httpd:z - /var/lib/kolla/config_files/glance_api.json:/var/lib/kolla/config_files/config.json - /var/lib/config-data/puppet-generated/glance_api_internal:/var/lib/kolla/config_files/src:ro - /var/lib/tripleo-config/ceph:/var/lib/kolla/config_files/src-ceph:z - /var/lib/config-data/puppet-generated/iscsid/etc/iscsi:/var/lib/kolla/config_files/src-iscsid:ro - /var/lib/glance:/var/lib/glance:shared glance_api_internal_tls_proxy: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS image: registry.redhat.io/rhosp-rhel9/openstack-glance-api:17.1 net: host restart: always start_order: 3 user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/glance:/var/log/glance:z - /var/log/containers/httpd/glance:/var/log/httpd:z - /var/lib/kolla/config_files/glance_api_tls_proxy.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/glance_api_internal:/var/lib/kolla/config_files/src:ro - /etc/pki/tls/certs/httpd:/etc/pki/tls/certs/httpd:ro - /etc/pki/tls/private/httpd:/etc/pki/tls/private/httpd:ro glance_api_tls_proxy: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS image: registry.redhat.io/rhosp-rhel9/openstack-glance-api:17.1 net: host restart: always start_order: 3 user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/glance:/var/log/glance:z - /var/log/containers/httpd/glance:/var/log/httpd:z - /var/lib/kolla/config_files/glance_api_tls_proxy.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/glance_api:/var/lib/kolla/config_files/src:ro - /etc/pki/tls/certs/httpd:/etc/pki/tls/certs/httpd:ro - /etc/pki/tls/private/httpd:/etc/pki/tls/private/httpd:ro heat_api: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-heat-api:17.1 net: host privileged: false restart: always user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/heat:/var/log/heat:z - /var/log/containers/httpd/heat-api:/var/log/httpd:z - /var/lib/kolla/config_files/heat_api.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/heat_api:/var/lib/kolla/config_files/src:ro - /etc/pki/tls/certs/httpd:/etc/pki/tls/certs/httpd:ro - /etc/pki/tls/private/httpd:/etc/pki/tls/private/httpd:ro heat_api_cfn: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-heat-api-cfn:17.1 net: host privileged: false restart: always user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/heat:/var/log/heat:z - /var/log/containers/httpd/heat-api-cfn:/var/log/httpd:z - /var/lib/kolla/config_files/heat_api_cfn.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/heat_api_cfn:/var/lib/kolla/config_files/src:ro - /etc/pki/tls/certs/httpd:/etc/pki/tls/certs/httpd:ro - /etc/pki/tls/private/httpd:/etc/pki/tls/private/httpd:ro heat_api_cron: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /usr/share/openstack-tripleo-common/healthcheck/cron heat image: registry.redhat.io/rhosp-rhel9/openstack-heat-api:17.1 net: host privileged: false restart: always user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/heat:/var/log/heat:z - /var/log/containers/httpd/heat-api:/var/log/httpd:z - /var/lib/kolla/config_files/heat_api_cron.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/heat_api:/var/lib/kolla/config_files/src:ro heat_engine: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck 5672 image: registry.redhat.io/rhosp-rhel9/openstack-heat-engine:17.1 net: host privileged: false restart: always stop_grace_period: 60 volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/heat:/var/log/heat:z - /var/lib/kolla/config_files/heat_engine.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/heat:/var/lib/kolla/config_files/src:ro keystone_refresh: action: exec command: - keystone - pkill - --signal - USR1 - httpd start_order: 1 user: root logrotate_crond: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /usr/share/openstack-tripleo-common/healthcheck/cron image: registry.redhat.io/rhosp-rhel9/openstack-cron:17.1 net: none pid: host privileged: true restart: always user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/logrotate-crond.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/crond:/var/lib/kolla/config_files/src:ro - /var/log/containers:/var/log/containers:z manila_api: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS image: registry.redhat.io/rhosp-rhel9/openstack-manila-api:17.1 net: host restart: always user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/manila_api.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/manila:/var/lib/kolla/config_files/src:ro - /var/log/containers/manila:/var/log/manila:z - /var/log/containers/httpd/manila-api:/var/log/httpd:z - /etc/pki/tls/certs/httpd:/etc/pki/tls/certs/httpd:ro - /etc/pki/tls/private/httpd:/etc/pki/tls/private/httpd:ro manila_api_cron: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /usr/share/openstack-tripleo-common/healthcheck/cron manila image: registry.redhat.io/rhosp-rhel9/openstack-manila-api:17.1 net: host privileged: false restart: always user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/manila_api_cron.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/manila:/var/lib/kolla/config_files/src:ro - /var/log/containers/manila:/var/log/manila:z - /var/log/containers/httpd/manila-api:/var/log/httpd:z manila_scheduler: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck 5672 image: registry.redhat.io/rhosp-rhel9/openstack-manila-scheduler:17.1 net: host restart: always volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/manila_scheduler.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/manila:/var/lib/kolla/config_files/src:ro - /var/log/containers/manila:/var/log/manila:z neutron_api: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-neutron-server:17.1 net: host privileged: false restart: always start_order: 0 volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/neutron:/var/log/neutron:z - /var/log/containers/httpd/neutron-api:/var/log/httpd:z - /var/lib/kolla/config_files/neutron_api.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/neutron:/var/lib/kolla/config_files/src:ro - /etc/pki/tls/certs/neutron_ovn.crt:/var/lib/kolla/config_files/src-tls/etc/pki/tls/certs/neutron_ovn.crt:ro - /etc/pki/tls/private/neutron_ovn.key:/var/lib/kolla/config_files/src-tls/etc/pki/tls/private/neutron_ovn.key:ro neutron_dhcp: cgroupns: host depends_on: - openvswitch.service environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck 5672 image: registry.redhat.io/rhosp-rhel9/openstack-neutron-dhcp-agent:17.1 net: host pid: host privileged: true restart: always security_opt: - label=disable start_order: 10 ulimit: - nofile=16384 volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/neutron:/var/log/neutron:z - /var/lib/kolla/config_files/neutron_dhcp.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/neutron:/var/lib/kolla/config_files/src:ro - /lib/modules:/lib/modules:ro - /run/openvswitch:/run/openvswitch:shared,z - /var/lib/neutron:/var/lib/neutron:shared,z - /run/netns:/run/netns:shared - /var/lib/neutron/kill_scripts:/etc/neutron/kill_scripts:shared,z - /var/lib/neutron/dnsmasq_wrapper:/usr/local/bin/dnsmasq:ro - /var/lib/neutron/dhcp_haproxy_wrapper:/usr/local/bin/haproxy:ro - /etc/pki/tls/certs/neutron.crt:/var/lib/kolla/config_files/src-tls/etc/pki/tls/certs/neutron.crt:ro - /etc/pki/tls/private/neutron.key:/var/lib/kolla/config_files/src-tls/etc/pki/tls/private/neutron.key:ro neutron_server_tls_proxy: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS image: registry.redhat.io/rhosp-rhel9/openstack-neutron-server:17.1 net: host restart: always user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/neutron:/var/log/neutron:z - /var/log/containers/httpd/neutron-api:/var/log/httpd:z - /var/lib/kolla/config_files/neutron_server_tls_proxy.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/neutron:/var/lib/kolla/config_files/src:ro - /etc/pki/tls/certs/httpd:/etc/pki/tls/certs/httpd:ro - /etc/pki/tls/private/httpd:/etc/pki/tls/private/httpd:ro neutron_sriov_agent: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck 5672 image: registry.redhat.io/rhosp-rhel9/openstack-neutron-sriov-agent:17.1 net: host pid: host privileged: true restart: always start_order: 10 ulimit: - nofile=16384 volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/neutron:/var/log/neutron:z - /var/lib/kolla/config_files/neutron_sriov_agent.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/neutron:/var/lib/kolla/config_files/src:ro - /lib/modules:/lib/modules:ro - /run:/run - /sys/class/net:/sys/class/net:rw nova_api: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-nova-api:17.1 net: host privileged: false restart: always start_order: 2 user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/nova:/var/log/nova:z - /var/log/containers/httpd/nova-api:/var/log/httpd:z - /var/lib/kolla/config_files/nova_api.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/nova:/var/lib/kolla/config_files/src:ro - /etc/pki/tls/certs/httpd:/etc/pki/tls/certs/httpd:ro - /etc/pki/tls/private/httpd:/etc/pki/tls/private/httpd:ro nova_api_cron: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /usr/share/openstack-tripleo-common/healthcheck/cron nova image: registry.redhat.io/rhosp-rhel9/openstack-nova-api:17.1 net: host privileged: false restart: always start_order: 4 user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/nova:/var/log/nova:z - /var/log/containers/httpd/nova-api:/var/log/httpd:z - /var/lib/kolla/config_files/nova_api_cron.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/nova:/var/lib/kolla/config_files/src:ro nova_conductor: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck 5672 image: registry.redhat.io/rhosp-rhel9/openstack-nova-conductor:17.1 net: host privileged: false restart: always volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/nova:/var/log/nova - /var/lib/kolla/config_files/nova_conductor.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/nova:/var/lib/kolla/config_files/src:ro nova_metadata: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-nova-api:17.1 net: host restart: always start_order: 2 user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/nova:/var/log/nova:z - /var/log/containers/httpd/nova-metadata:/var/log/httpd:z - /var/lib/kolla/config_files/nova_metadata.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/nova_metadata:/var/lib/kolla/config_files/src:ro - /etc/pki/tls/certs/httpd:/etc/pki/tls/certs/httpd:ro - /etc/pki/tls/private/httpd:/etc/pki/tls/private/httpd:ro nova_migration_target: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-nova-compute:17.1 net: host privileged: true restart: always user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/nova-migration-target.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/nova_libvirt:/var/lib/kolla/config_files/src:ro - /etc/ssh:/host-ssh:ro - /run/libvirt:/run/libvirt:shared,z - /var/lib/nova:/var/lib/nova:shared nova_scheduler: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck 5672 image: registry.redhat.io/rhosp-rhel9/openstack-nova-scheduler:17.1 net: host privileged: false restart: always volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/nova:/var/log/nova - /var/lib/kolla/config_files/nova_scheduler.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/nova:/var/lib/kolla/config_files/src:ro nova_vnc_proxy: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-nova-novncproxy:17.1 net: host privileged: false restart: always volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/nova:/var/log/nova - /var/lib/kolla/config_files/nova_vnc_proxy.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/nova:/var/lib/kolla/config_files/src:ro - /etc/ipa/ca.crt:/etc/pki/CA/certs/vnc.crt:ro - /etc/pki/tls/certs/libvirt-vnc-client-cert.crt:/var/lib/kolla/config_files/src-tls/etc/pki/tls/certs/libvirt-vnc-client-cert.crt:ro - /etc/pki/tls/private/libvirt-vnc-client-cert.key:/var/lib/kolla/config_files/src-tls/etc/pki/tls/private/libvirt-vnc-client-cert.key:ro - /etc/pki/tls/certs/novnc-proxy.crt:/var/lib/kolla/config_files/src-tls/etc/pki/tls/certs/novnc-proxy.crt:ro - /etc/pki/tls/private/novnc-proxy.key:/var/lib/kolla/config_files/src-tls/etc/pki/tls/private/novnc-proxy.key:ro nova_wait_for_api_service: detach: false environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS __OS_DEBUG: 'true' image: registry.redhat.io/rhosp-rhel9/openstack-nova-api:17.1 net: host privileged: false start_order: 3 user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/nova:/var/log/nova:z - /var/log/containers/httpd/nova-api:/var/log/httpd:z - /var/lib/kolla/config_files/nova_wait_for_api_service.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/nova:/var/lib/kolla/config_files/src:ro - /var/lib/container-config-scripts:/container-config-scripts:z octavia_api: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-octavia-api:17.1 net: host privileged: false restart: always start_order: 2 user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/octavia_api.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/octavia:/var/lib/kolla/config_files/src:ro - /var/log/containers/octavia:/var/log/octavia:z - /run/octavia:/run/octavia:shared,z - /var/log/containers/httpd/octavia-api:/var/log/httpd:z - /etc/pki/tls/certs/httpd:/etc/pki/tls/certs/httpd:ro - /etc/pki/tls/private/httpd:/etc/pki/tls/private/httpd:ro - /etc/pki/tls/certs/ovn_octavia.crt:/var/lib/kolla/config_files/src-tls/etc/pki/tls/certs/ovn_octavia.crt:ro - /etc/pki/tls/private/ovn_octavia.key:/var/lib/kolla/config_files/src-tls/etc/pki/tls/private/ovn_octavia.key:ro octavia_driver_agent: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS image: registry.redhat.io/rhosp-rhel9/openstack-octavia-api:17.1 net: host privileged: true restart: always start_order: 2 volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/octavia_driver_agent.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/octavia:/var/lib/kolla/config_files/src:ro - /var/log/containers/octavia:/var/log/octavia:z - /run/octavia:/run/octavia:shared,z - /etc/pki/tls/certs/ovn_octavia.crt:/var/lib/kolla/config_files/src-tls/etc/pki/tls/certs/ovn_octavia.crt:ro - /etc/pki/tls/private/ovn_octavia.key:/var/lib/kolla/config_files/src-tls/etc/pki/tls/private/ovn_octavia.key:ro ovn_controller: depends_on: - openvswitch.service environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck 6642 image: registry.redhat.io/rhosp-rhel9/openstack-ovn-controller:17.1 net: host privileged: true restart: always start_order: 1 user: root volumes: - /var/lib/kolla/config_files/ovn_controller.json:/var/lib/kolla/config_files/config.json:ro - /lib/modules:/lib/modules:ro - /run:/run - /var/lib/openvswitch/ovn:/run/ovn:shared,z - /var/log/containers/openvswitch:/var/log/openvswitch:z - /var/log/containers/openvswitch:/var/log/ovn:z - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/pki/tls/certs/ovn_controller.crt:/etc/pki/tls/certs/ovn_controller.crt - /etc/pki/tls/private/ovn_controller.key:/etc/pki/tls/private/ovn_controller.key ovn_metadata_agent: cgroupns: host environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-neutron-metadata-agent-ovn:17.1 net: host pid: host privileged: true restart: always start_order: 1 volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/neutron:/var/log/neutron:z - /var/lib/kolla/config_files/ovn_metadata_agent.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/neutron:/var/lib/kolla/config_files/src:ro - /lib/modules:/lib/modules:ro - /run/openvswitch:/run/openvswitch:shared,z - /var/lib/neutron:/var/lib/neutron:shared,z - /run/netns:/run/netns:shared - /var/lib/neutron/kill_scripts:/etc/neutron/kill_scripts:shared,z - /var/lib/neutron/ovn_metadata_haproxy_wrapper:/usr/local/bin/haproxy:ro - /etc/pki/tls/certs/ovn_metadata.crt:/etc/pki/tls/certs/ovn_metadata.crt - /etc/pki/tls/private/ovn_metadata.key:/etc/pki/tls/private/ovn_metadata.key placement_api: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-placement-api:17.1 net: host restart: always start_order: 1 user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/placement:/var/log/placement:z - /var/log/containers/httpd/placement:/var/log/httpd:z - /var/lib/kolla/config_files/placement_api.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/placement:/var/lib/kolla/config_files/src:ro - /etc/pki/tls/certs/httpd:/etc/pki/tls/certs/httpd:ro - /etc/pki/tls/private/httpd:/etc/pki/tls/private/httpd:ro placement_wait_for_service: detach: false environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS __OS_DEBUG: 'true' image: registry.redhat.io/rhosp-rhel9/openstack-placement-api:17.1 net: host privileged: false start_order: 2 user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/placement:/var/log/placement:z - /var/log/containers/httpd/placement:/var/log/httpd:z - /var/lib/kolla/config_files/placement_api_wait_for_service.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/placement:/var/lib/kolla/config_files/src:ro - /var/lib/container-config-scripts:/container-config-scripts:z setup_ovs_manager: command: - /container_puppet_apply.sh - '4' - exec - include tripleo::profile::base::neutron::ovn_metadata detach: false environment: TRIPLEO_DEPLOY_IDENTIFIER: '1781077158' image: registry.redhat.io/rhosp-rhel9/openstack-neutron-metadata-agent-ovn:17.1 net: host privileged: true start_order: 0 user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /var/lib/container-config-scripts/container_puppet_apply.sh:/container_puppet_apply.sh:ro - /etc/puppet:/tmp/puppet-etc:ro - /usr/share/openstack-puppet/modules:/usr/share/openstack-puppet/modules:ro - /lib/modules:/lib/modules:ro - /run/openvswitch:/run/openvswitch:shared,z swift_account_reaper: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS image: registry.redhat.io/rhosp-rhel9/openstack-swift-account:17.1 net: host restart: always user: swift volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/swift_account_reaper.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/swift:/var/lib/kolla/config_files/src:ro - /srv/node:/srv/node - /dev:/dev - /var/cache/swift:/var/cache/swift:z - /var/log/containers/swift:/var/log/swift:z swift_account_server: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-swift-account:17.1 net: host restart: always user: swift volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/swift_account_server.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/swift:/var/lib/kolla/config_files/src:ro - /srv/node:/srv/node - /dev:/dev - /var/cache/swift:/var/cache/swift - /var/log/containers/swift:/var/log/swift:z swift_container_server: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-swift-container:17.1 net: host restart: always user: swift volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/swift_container_server.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/swift:/var/lib/kolla/config_files/src:ro - /srv/node:/srv/node - /dev:/dev - /var/cache/swift:/var/cache/swift - /var/log/containers/swift:/var/log/swift:z swift_container_updater: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS image: registry.redhat.io/rhosp-rhel9/openstack-swift-container:17.1 net: host restart: always user: swift volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/swift_container_updater.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/swift:/var/lib/kolla/config_files/src:ro - /srv/node:/srv/node - /dev:/dev - /var/cache/swift:/var/cache/swift - /var/log/containers/swift:/var/log/swift:z swift_object_expirer: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS image: registry.redhat.io/rhosp-rhel9/openstack-swift-proxy-server:17.1 net: host restart: always user: swift volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/swift_object_expirer.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/swift:/var/lib/kolla/config_files/src:ro - /srv/node:/srv/node - /dev:/dev - /var/cache/swift:/var/cache/swift - /var/log/containers/swift:/var/log/swift:z swift_object_server: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-swift-object:17.1 net: host restart: always user: swift volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/swift_object_server.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/swift:/var/lib/kolla/config_files/src:ro - /srv/node:/srv/node - /dev:/dev - /var/cache/swift:/var/cache/swift - /var/log/containers/swift:/var/log/swift:z swift_object_updater: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS image: registry.redhat.io/rhosp-rhel9/openstack-swift-object:17.1 net: host restart: always user: swift volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/swift_object_updater.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/swift:/var/lib/kolla/config_files/src:ro - /srv/node:/srv/node - /dev:/dev - /var/cache/swift:/var/cache/swift - /var/log/containers/swift:/var/log/swift:z swift_proxy: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-swift-proxy-server:17.1 net: host restart: always start_order: 2 user: swift volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/swift_proxy.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/swift:/var/lib/kolla/config_files/src:ro - /srv/node:/srv/node - /dev:/dev - /var/log/containers/swift:/var/log/swift:z swift_proxy_tls_proxy: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS image: registry.redhat.io/rhosp-rhel9/openstack-swift-proxy-server:17.1 net: host restart: always start_order: 3 user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/swift_proxy_tls_proxy.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/swift:/var/lib/kolla/config_files/src:ro - /etc/pki/tls/certs/httpd:/etc/pki/tls/certs/httpd:ro - /etc/pki/tls/private/httpd:/etc/pki/tls/private/httpd:ro step_5: ceilometer_gnocchi_upgrade: detach: false environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS image: registry.redhat.io/rhosp-rhel9/openstack-ceilometer-central:17.1 net: host privileged: false start_order: 99 user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/ceilometer_agent_gnocchi_upgrade.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/ceilometer:/var/lib/kolla/config_files/src:ro - /var/log/containers/ceilometer:/var/log/ceilometer:z gnocchi_api: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-gnocchi-api:17.1 net: host privileged: false restart: always start_order: 1 volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/gnocchi:/var/lib/gnocchi:shared,z - /var/lib/kolla/config_files/gnocchi_api.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/gnocchi:/var/lib/kolla/config_files/src:ro - /var/log/containers/gnocchi:/var/log/gnocchi:z - /var/log/containers/httpd/gnocchi-api:/var/log/httpd:z - /var/lib/tripleo-config/ceph:/var/lib/kolla/config_files/src-ceph:z - /etc/pki/tls/certs/httpd:/etc/pki/tls/certs/httpd:ro - /etc/pki/tls/private/httpd:/etc/pki/tls/private/httpd:ro gnocchi_db_sync: cap_add: - AUDIT_WRITE detach: false environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS TRIPLEO_DEPLOY_IDENTIFIER: '1781077158' image: registry.redhat.io/rhosp-rhel9/openstack-gnocchi-api:17.1 net: host privileged: false start_order: 0 user: root volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/gnocchi_db_sync.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/gnocchi:/var/lib/kolla/config_files/src:ro - /var/lib/gnocchi:/var/lib/gnocchi:shared,z - /var/log/containers/gnocchi:/var/log/gnocchi:z - /var/log/containers/httpd/gnocchi-api:/var/log/httpd:z - /var/lib/tripleo-config/ceph:/var/lib/kolla/config_files/src-ceph:z gnocchi_metricd: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-gnocchi-metricd:17.1 net: host privileged: false restart: always start_order: 1 volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/gnocchi_metricd.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/gnocchi:/var/lib/kolla/config_files/src:ro - /var/log/containers/gnocchi:/var/log/gnocchi:z - /var/lib/tripleo-config/ceph:/var/lib/kolla/config_files/src-ceph:z - /var/lib/gnocchi:/var/lib/gnocchi:shared,z gnocchi_statsd: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-gnocchi-statsd:17.1 net: host privileged: false restart: always start_order: 1 volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/gnocchi_statsd.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/gnocchi:/var/lib/kolla/config_files/src:ro - /var/log/containers/gnocchi:/var/log/gnocchi:z - /var/lib/tripleo-config/ceph:/var/lib/kolla/config_files/src-ceph:z - /var/lib/gnocchi:/var/lib/gnocchi:shared,z nova_compute: depends_on: - tripleo_nova_libvirt.target environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS LIBGUESTFS_BACKEND: direct healthcheck: test: /openstack/healthcheck 5672 image: registry.redhat.io/rhosp-rhel9/openstack-nova-compute:17.1 ipc: host net: host privileged: true restart: always start_order: 3 ulimit: - nofile=131072 - memlock=67108864 user: nova volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/log/containers/nova:/var/log/nova - /etc/ssh/ssh_known_hosts:/etc/ssh/ssh_known_hosts:ro - /var/lib/kolla/config_files/nova_compute.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/nova_libvirt:/var/lib/kolla/config_files/src:ro - /var/lib/config-data/puppet-generated/iscsid/etc/iscsi:/var/lib/kolla/config_files/src-iscsid:ro - /var/lib/tripleo-config/ceph:/var/lib/kolla/config_files/src-ceph:z - /dev:/dev - /lib/modules:/lib/modules:ro - /run:/run - /run/nova:/run/nova:z - /var/lib/iscsi:/var/lib/iscsi:z - /var/lib/libvirt:/var/lib/libvirt:shared - /sys/class/net:/sys/class/net - /sys/bus/pci:/sys/bus/pci - /boot:/boot:ro - /var/lib/nova:/var/lib/nova:shared nova_wait_for_compute_service: detach: false environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS __OS_DEBUG: 'true' image: registry.redhat.io/rhosp-rhel9/openstack-nova-compute:17.1 net: host start_order: 4 user: nova volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/nova_compute_wait_for_compute_service.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/nova_libvirt:/var/lib/kolla/config_files/src:ro - /var/log/containers/nova:/var/log/nova - /var/lib/container-config-scripts:/container-config-scripts octavia_health_manager: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-octavia-health-manager:17.1 net: host privileged: false restart: always start_order: 2 stop_grace_period: 630 volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/octavia_health_manager.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/octavia:/var/lib/kolla/config_files/src:ro - /var/log/containers/octavia:/var/log/octavia:z octavia_housekeeping: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck image: registry.redhat.io/rhosp-rhel9/openstack-octavia-housekeeping:17.1 net: host privileged: false restart: always start_order: 2 stop_grace_period: 630 volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/octavia_housekeeping.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/octavia:/var/lib/kolla/config_files/src:ro - /var/log/containers/octavia:/var/log/octavia:z octavia_rsyslog: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS image: registry.redhat.io/rhosp-rhel9/openstack-rsyslog:17.1 net: host privileged: true restart: always start_order: 2 volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/octavia_rsyslog.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/octavia:/var/lib/kolla/config_files/src:ro - /var/log/containers/octavia-amphorae:/var/log/octavia:z octavia_worker: environment: KOLLA_CONFIG_STRATEGY: COPY_ALWAYS healthcheck: test: /openstack/healthcheck 5672 image: registry.redhat.io/rhosp-rhel9/openstack-octavia-worker:17.1 net: host privileged: false restart: always start_order: 2 stop_grace_period: 630 volumes: - /etc/hosts:/etc/hosts:ro - /etc/localtime:/etc/localtime:ro - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro - /etc/pki/ca-trust/source/anchors:/etc/pki/ca-trust/source/anchors:ro - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro - /dev/log:/dev/log - /etc/ipa/ca.crt:/etc/ipa/ca.crt:ro - /etc/puppet:/etc/puppet:ro - /var/lib/kolla/config_files/octavia_worker.json:/var/lib/kolla/config_files/config.json:ro - /var/lib/config-data/puppet-generated/octavia:/var/lib/kolla/config_files/src:ro - /var/log/containers/octavia:/var/log/octavia:z