OpenStack擴展自定義功能介紹
得益于OpenStack的良好架構(gòu),對OpenStack進行擴展非常方便,每個模塊都留出了各種接口和擴展點,能夠讓用戶擴展自定義功能。下面以操作記錄為例子,介紹一下如何擴展nova-api組件。
需求:
用戶的一些重要操作必須記錄下來,方便進行事后查詢,比如instance的創(chuàng)建、銷毀,比如公網(wǎng)IP的申請、分配等等。
實現(xiàn): 
因為所有的這些操作都是通過調(diào)用nova-api進行,我們要對nova-api進行擴展,記錄相關(guān)的請求。nova-api是基于Python Paste來構(gòu)建的,只需要在配置文件里面進行修改(nova-api-paste.ini),在pipeline上添加一個名為audit的filter:
Text代碼
- [pipeline:openstackapi11]
 - pipeline = faultwrap authtoken keystonecontext ratelimit audit extensions osapiapp11
 - [filter:audit]
 - paste.filter_factory = nova.api.openstack.audit:AuditMiddleware.factory
 
然后我們寫一個Middleware:
Python代碼
- import time
 - from nova import log as logging
 - from nova import wsgi as base_wsgi
 - from nova.api.openstack import wsgi
 - LOG = logging.getLogger('nova.api.audit')
 - class AuditMiddleware(base_wsgi.Middleware):
 - """store POST/PUT/DELETE api request for audit."""
 - def __init__(self, application, audit_methods='POST,PUT,DELETE'):
 - base_wsgi.Middleware.__init__(self, application)
 - self._audit_methods = audit_methods.split(",")
 - def process_request(self, req):
 - self._need_audit = req.method in self._audit_methods
 - if self._need_audit:
 - self._request = req
 - self._requested_at = time.time()
 - def process_response(self, response):
 - if self._need_audit and response.status_int >= 200 and response.status_int < 300:
 - self._store_log(response)
 - return response
 - def _store_log(self, response):
 - req = self._request
 - LOG.info("tenant: %s, user: %s, %s: %s, at: %s",
 - req.headers.get('X-Tenant', 'admin'),
 - req.headers.get('X-User', 'admin'),
 - req.method,
 - req.path_info,
 - self._requested_at)
 
重啟一下nova-api進程,然后在dashboard上做一些操作,我們就能在日志文件里面看到如下的信息:
Text代碼
- tenant: 1, user: admin, POST: /1/os-security-group-rules, at: 1326352441.16
 - tenant: 1, user: admin, DELETE: /1/servers/32, at: 1326353021.58
 
這里默認記錄所有的非GET請求,如果不想將PUT請求記錄(PUT對應(yīng)更新),在配置文件里面更改一下:
Text代碼
- [filter:audit]
 - audit_methods=POST,DELETE
 
更進一步,可以將_store_log改造一下,將數(shù)據(jù)保存到數(shù)據(jù)庫,我們可以在配置文件里面添加數(shù)據(jù)庫的連接信息等,然后利用API Extension來寫一個擴展API,提供查詢租戶audit log的api功能。















 
 
 




 
 
 
 