Line data Source code
1 : #![recursion_limit = "300"]
2 :
3 : //! Main entry point for the Page Server executable.
4 :
5 : use std::env;
6 : use std::env::{var, VarError};
7 : use std::io::Read;
8 : use std::str::FromStr;
9 : use std::sync::Arc;
10 : use std::time::Duration;
11 :
12 : use anyhow::{anyhow, Context};
13 : use camino::Utf8Path;
14 : use clap::{Arg, ArgAction, Command};
15 :
16 : use metrics::launch_timestamp::{set_launch_timestamp_metric, LaunchTimestamp};
17 : use pageserver::config::PageserverIdentity;
18 : use pageserver::controller_upcall_client::ControllerUpcallClient;
19 : use pageserver::disk_usage_eviction_task::{self, launch_disk_usage_global_eviction_task};
20 : use pageserver::metrics::{STARTUP_DURATION, STARTUP_IS_LOADING};
21 : use pageserver::task_mgr::{COMPUTE_REQUEST_RUNTIME, WALRECEIVER_RUNTIME};
22 : use pageserver::tenant::{secondary, TenantSharedResources};
23 : use pageserver::{CancellableTask, ConsumptionMetricsTasks, HttpEndpointListener};
24 : use remote_storage::GenericRemoteStorage;
25 : use tokio::signal::unix::SignalKind;
26 : use tokio::time::Instant;
27 : use tokio_util::sync::CancellationToken;
28 : use tracing::*;
29 :
30 : use metrics::set_build_info_metric;
31 : use pageserver::{
32 : config::PageServerConf,
33 : deletion_queue::DeletionQueue,
34 : http, page_cache, page_service, task_mgr,
35 : task_mgr::{BACKGROUND_RUNTIME, MGMT_REQUEST_RUNTIME},
36 : tenant::mgr,
37 : virtual_file,
38 : };
39 : use postgres_backend::AuthType;
40 : use utils::crashsafe::syncfs;
41 : use utils::failpoint_support;
42 : use utils::logging::TracingErrorLayerEnablement;
43 : use utils::{
44 : auth::{JwtAuth, SwappableJwtAuth},
45 : logging, project_build_tag, project_git_version,
46 : sentry_init::init_sentry,
47 : tcp_listener,
48 : };
49 :
50 : project_git_version!(GIT_VERSION);
51 : project_build_tag!(BUILD_TAG);
52 :
53 : #[global_allocator]
54 : static GLOBAL: tikv_jemallocator::Jemalloc = tikv_jemallocator::Jemalloc;
55 :
56 : const PID_FILE_NAME: &str = "pageserver.pid";
57 :
58 : const FEATURES: &[&str] = &[
59 : #[cfg(feature = "testing")]
60 : "testing",
61 : ];
62 :
63 2 : fn version() -> String {
64 2 : format!(
65 2 : "{GIT_VERSION} failpoints: {}, features: {:?}",
66 2 : fail::has_failpoints(),
67 2 : FEATURES,
68 2 : )
69 2 : }
70 :
71 0 : fn main() -> anyhow::Result<()> {
72 0 : let launch_ts = Box::leak(Box::new(LaunchTimestamp::generate()));
73 0 :
74 0 : let arg_matches = cli().get_matches();
75 0 :
76 0 : if arg_matches.get_flag("enabled-features") {
77 0 : println!("{{\"features\": {FEATURES:?} }}");
78 0 : return Ok(());
79 0 : }
80 0 :
81 0 : let workdir = arg_matches
82 0 : .get_one::<String>("workdir")
83 0 : .map(Utf8Path::new)
84 0 : .unwrap_or_else(|| Utf8Path::new(".neon"));
85 0 : let workdir = workdir
86 0 : .canonicalize_utf8()
87 0 : .with_context(|| format!("Error opening workdir '{workdir}'"))?;
88 :
89 0 : let cfg_file_path = workdir.join("pageserver.toml");
90 0 : let identity_file_path = workdir.join("identity.toml");
91 0 :
92 0 : // Set CWD to workdir for non-daemon modes
93 0 : env::set_current_dir(&workdir)
94 0 : .with_context(|| format!("Failed to set application's current dir to '{workdir}'"))?;
95 :
96 0 : let conf = initialize_config(&identity_file_path, &cfg_file_path, &workdir)?;
97 :
98 : // Initialize logging.
99 : //
100 : // It must be initialized before the custom panic hook is installed below.
101 : //
102 : // Regarding tracing_error enablement: at this time, we only use the
103 : // tracing_error crate to debug_assert that log spans contain tenant and timeline ids.
104 : // See `debug_assert_current_span_has_tenant_and_timeline_id` in the timeline module
105 0 : let tracing_error_layer_enablement = if cfg!(debug_assertions) {
106 0 : TracingErrorLayerEnablement::EnableWithRustLogFilter
107 : } else {
108 0 : TracingErrorLayerEnablement::Disabled
109 : };
110 0 : logging::init(
111 0 : conf.log_format,
112 0 : tracing_error_layer_enablement,
113 0 : logging::Output::Stdout,
114 0 : )?;
115 :
116 : // mind the order required here: 1. logging, 2. panic_hook, 3. sentry.
117 : // disarming this hook on pageserver, because we never tear down tracing.
118 0 : logging::replace_panic_hook_with_tracing_panic_hook().forget();
119 0 :
120 0 : // initialize sentry if SENTRY_DSN is provided
121 0 : let _sentry_guard = init_sentry(
122 0 : Some(GIT_VERSION.into()),
123 0 : &[("node_id", &conf.id.to_string())],
124 0 : );
125 0 :
126 0 : // after setting up logging, log the effective IO engine choice and read path implementations
127 0 : info!(?conf.virtual_file_io_engine, "starting with virtual_file IO engine");
128 0 : info!(?conf.virtual_file_io_mode, "starting with virtual_file IO mode");
129 :
130 : // The tenants directory contains all the pageserver local disk state.
131 : // Create if not exists and make sure all the contents are durable before proceeding.
132 : // Ensuring durability eliminates a whole bug class where we come up after an unclean shutdown.
133 : // After unclea shutdown, we don't know if all the filesystem content we can read via syscalls is actually durable or not.
134 : // Examples for that: OOM kill, systemd killing us during shutdown, self abort due to unrecoverable IO error.
135 0 : let tenants_path = conf.tenants_path();
136 0 : {
137 0 : let open = || {
138 0 : nix::dir::Dir::open(
139 0 : tenants_path.as_std_path(),
140 0 : nix::fcntl::OFlag::O_DIRECTORY | nix::fcntl::OFlag::O_RDONLY,
141 0 : nix::sys::stat::Mode::empty(),
142 0 : )
143 0 : };
144 0 : let dirfd = match open() {
145 0 : Ok(dirfd) => dirfd,
146 0 : Err(e) => match e {
147 : nix::errno::Errno::ENOENT => {
148 0 : utils::crashsafe::create_dir_all(&tenants_path).with_context(|| {
149 0 : format!("Failed to create tenants root dir at '{tenants_path}'")
150 0 : })?;
151 0 : open().context("open tenants dir after creating it")?
152 : }
153 0 : e => anyhow::bail!(e),
154 : },
155 : };
156 :
157 0 : if conf.no_sync {
158 0 : info!("Skipping syncfs on startup");
159 : } else {
160 0 : let started = Instant::now();
161 0 : syncfs(dirfd)?;
162 0 : let elapsed = started.elapsed();
163 0 : info!(
164 0 : elapsed_ms = elapsed.as_millis(),
165 0 : "made tenant directory contents durable"
166 : );
167 : }
168 : }
169 :
170 : // Initialize up failpoints support
171 0 : let scenario = failpoint_support::init();
172 0 :
173 0 : // Basic initialization of things that don't change after startup
174 0 : virtual_file::init(
175 0 : conf.max_file_descriptors,
176 0 : conf.virtual_file_io_engine,
177 0 : conf.virtual_file_io_mode,
178 0 : );
179 0 : page_cache::init(conf.page_cache_size);
180 0 :
181 0 : start_pageserver(launch_ts, conf).context("Failed to start pageserver")?;
182 :
183 0 : scenario.teardown();
184 0 : Ok(())
185 0 : }
186 :
187 0 : fn initialize_config(
188 0 : identity_file_path: &Utf8Path,
189 0 : cfg_file_path: &Utf8Path,
190 0 : workdir: &Utf8Path,
191 0 : ) -> anyhow::Result<&'static PageServerConf> {
192 : // The deployment orchestrator writes out an indentity file containing the node id
193 : // for all pageservers. This file is the source of truth for the node id. In order
194 : // to allow for rolling back pageserver releases, the node id is also included in
195 : // the pageserver config that the deployment orchestrator writes to disk for the pageserver.
196 : // A rolled back version of the pageserver will get the node id from the pageserver.toml
197 : // config file.
198 0 : let identity = match std::fs::File::open(identity_file_path) {
199 0 : Ok(mut f) => {
200 0 : let md = f.metadata().context("stat config file")?;
201 0 : if !md.is_file() {
202 0 : anyhow::bail!("Pageserver found identity file but it is a dir entry: {identity_file_path}. Aborting start up ...");
203 0 : }
204 0 :
205 0 : let mut s = String::new();
206 0 : f.read_to_string(&mut s).context("read identity file")?;
207 0 : toml_edit::de::from_str::<PageserverIdentity>(&s)?
208 : }
209 0 : Err(e) => {
210 0 : anyhow::bail!("Pageserver could not read identity file: {identity_file_path}: {e}. Aborting start up ...");
211 : }
212 : };
213 :
214 0 : let config_file_contents =
215 0 : std::fs::read_to_string(cfg_file_path).context("read config file from filesystem")?;
216 0 : let config_toml = serde_path_to_error::deserialize(
217 0 : toml_edit::de::Deserializer::from_str(&config_file_contents)
218 0 : .context("build toml deserializer")?,
219 : )
220 0 : .context("deserialize config toml")?;
221 0 : let conf = PageServerConf::parse_and_validate(identity.id, config_toml, workdir)
222 0 : .context("runtime-validation of config toml")?;
223 :
224 0 : Ok(Box::leak(Box::new(conf)))
225 0 : }
226 :
227 : struct WaitForPhaseResult<F: std::future::Future + Unpin> {
228 : timeout_remaining: Duration,
229 : skipped: Option<F>,
230 : }
231 :
232 : /// During startup, we apply a timeout to our waits for readiness, to avoid
233 : /// stalling the whole service if one Tenant experiences some problem. Each
234 : /// phase may consume some of the timeout: this function returns the updated
235 : /// timeout for use in the next call.
236 0 : async fn wait_for_phase<F>(phase: &str, mut fut: F, timeout: Duration) -> WaitForPhaseResult<F>
237 0 : where
238 0 : F: std::future::Future + Unpin,
239 0 : {
240 0 : let initial_t = Instant::now();
241 0 : let skipped = match tokio::time::timeout(timeout, &mut fut).await {
242 0 : Ok(_) => None,
243 : Err(_) => {
244 0 : tracing::info!(
245 0 : timeout_millis = timeout.as_millis(),
246 0 : %phase,
247 0 : "Startup phase timed out, proceeding anyway"
248 : );
249 0 : Some(fut)
250 : }
251 : };
252 :
253 0 : WaitForPhaseResult {
254 0 : timeout_remaining: timeout
255 0 : .checked_sub(Instant::now().duration_since(initial_t))
256 0 : .unwrap_or(Duration::ZERO),
257 0 : skipped,
258 0 : }
259 0 : }
260 :
261 0 : fn startup_checkpoint(started_at: Instant, phase: &str, human_phase: &str) {
262 0 : let elapsed = started_at.elapsed();
263 0 : let secs = elapsed.as_secs_f64();
264 0 : STARTUP_DURATION.with_label_values(&[phase]).set(secs);
265 0 :
266 0 : info!(
267 0 : elapsed_ms = elapsed.as_millis(),
268 0 : "{human_phase} ({secs:.3}s since start)"
269 : )
270 0 : }
271 :
272 0 : fn start_pageserver(
273 0 : launch_ts: &'static LaunchTimestamp,
274 0 : conf: &'static PageServerConf,
275 0 : ) -> anyhow::Result<()> {
276 0 : // Monotonic time for later calculating startup duration
277 0 : let started_startup_at = Instant::now();
278 0 :
279 0 : // Print version and launch timestamp to the log,
280 0 : // and expose them as prometheus metrics.
281 0 : // A changed version string indicates changed software.
282 0 : // A changed launch timestamp indicates a pageserver restart.
283 0 : info!(
284 0 : "version: {} launch_timestamp: {} build_tag: {}",
285 0 : version(),
286 0 : launch_ts.to_string(),
287 : BUILD_TAG,
288 : );
289 0 : set_build_info_metric(GIT_VERSION, BUILD_TAG);
290 0 : set_launch_timestamp_metric(launch_ts);
291 0 : #[cfg(target_os = "linux")]
292 0 : metrics::register_internal(Box::new(metrics::more_process_metrics::Collector::new())).unwrap();
293 0 : metrics::register_internal(Box::new(
294 0 : pageserver::metrics::tokio_epoll_uring::Collector::new(),
295 0 : ))
296 0 : .unwrap();
297 0 : pageserver::preinitialize_metrics();
298 0 :
299 0 : // If any failpoints were set from FAILPOINTS environment variable,
300 0 : // print them to the log for debugging purposes
301 0 : let failpoints = fail::list();
302 0 : if !failpoints.is_empty() {
303 0 : info!(
304 0 : "started with failpoints: {}",
305 0 : failpoints
306 0 : .iter()
307 0 : .map(|(name, actions)| format!("{name}={actions}"))
308 0 : .collect::<Vec<String>>()
309 0 : .join(";")
310 : )
311 0 : }
312 :
313 : // Create and lock PID file. This ensures that there cannot be more than one
314 : // pageserver process running at the same time.
315 0 : let lock_file_path = conf.workdir.join(PID_FILE_NAME);
316 0 : info!("Claiming pid file at {lock_file_path:?}...");
317 0 : let lock_file =
318 0 : utils::pid_file::claim_for_current_process(&lock_file_path).context("claim pid file")?;
319 0 : info!("Claimed pid file at {lock_file_path:?}");
320 :
321 : // Ensure that the lock file is held even if the main thread of the process panics.
322 : // We need to release the lock file only when the process exits.
323 0 : std::mem::forget(lock_file);
324 0 :
325 0 : // Bind the HTTP and libpq ports early, so that if they are in use by some other
326 0 : // process, we error out early.
327 0 : let http_addr = &conf.listen_http_addr;
328 0 : info!("Starting pageserver http handler on {http_addr}");
329 0 : let http_listener = tcp_listener::bind(http_addr)?;
330 :
331 0 : let pg_addr = &conf.listen_pg_addr;
332 0 :
333 0 : info!("Starting pageserver pg protocol handler on {pg_addr}");
334 0 : let pageserver_listener = tcp_listener::bind(pg_addr)?;
335 :
336 : // Launch broker client
337 : // The storage_broker::connect call needs to happen inside a tokio runtime thread.
338 0 : let broker_client = WALRECEIVER_RUNTIME
339 0 : .block_on(async {
340 0 : // Note: we do not attempt connecting here (but validate endpoints sanity).
341 0 : storage_broker::connect(conf.broker_endpoint.clone(), conf.broker_keepalive_interval)
342 0 : })
343 0 : .with_context(|| {
344 0 : format!(
345 0 : "create broker client for uri={:?} keepalive_interval={:?}",
346 0 : &conf.broker_endpoint, conf.broker_keepalive_interval,
347 0 : )
348 0 : })?;
349 :
350 : // Initialize authentication for incoming connections
351 : let http_auth;
352 : let pg_auth;
353 0 : if conf.http_auth_type == AuthType::NeonJWT || conf.pg_auth_type == AuthType::NeonJWT {
354 : // unwrap is ok because check is performed when creating config, so path is set and exists
355 0 : let key_path = conf.auth_validation_public_key_path.as_ref().unwrap();
356 0 : info!("Loading public key(s) for verifying JWT tokens from {key_path:?}");
357 :
358 0 : let jwt_auth = JwtAuth::from_key_path(key_path)?;
359 0 : let auth: Arc<SwappableJwtAuth> = Arc::new(SwappableJwtAuth::new(jwt_auth));
360 :
361 0 : http_auth = match &conf.http_auth_type {
362 0 : AuthType::Trust => None,
363 0 : AuthType::NeonJWT => Some(auth.clone()),
364 : };
365 0 : pg_auth = match &conf.pg_auth_type {
366 0 : AuthType::Trust => None,
367 0 : AuthType::NeonJWT => Some(auth),
368 : };
369 0 : } else {
370 0 : http_auth = None;
371 0 : pg_auth = None;
372 0 : }
373 0 : info!("Using auth for http API: {:#?}", conf.http_auth_type);
374 0 : info!("Using auth for pg connections: {:#?}", conf.pg_auth_type);
375 :
376 0 : match var("NEON_AUTH_TOKEN") {
377 0 : Ok(v) => {
378 0 : info!("Loaded JWT token for authentication with Safekeeper");
379 0 : pageserver::config::SAFEKEEPER_AUTH_TOKEN
380 0 : .set(Arc::new(v))
381 0 : .map_err(|_| anyhow!("Could not initialize SAFEKEEPER_AUTH_TOKEN"))?;
382 : }
383 : Err(VarError::NotPresent) => {
384 0 : info!("No JWT token for authentication with Safekeeper detected");
385 : }
386 0 : Err(e) => {
387 0 : return Err(e).with_context(|| {
388 0 : "Failed to either load to detect non-present NEON_AUTH_TOKEN environment variable"
389 0 : })
390 : }
391 : };
392 :
393 : // Top-level cancellation token for the process
394 0 : let shutdown_pageserver = tokio_util::sync::CancellationToken::new();
395 :
396 : // Set up remote storage client
397 0 : let remote_storage = BACKGROUND_RUNTIME.block_on(create_remote_storage_client(conf))?;
398 :
399 : // Set up deletion queue
400 0 : let (deletion_queue, deletion_workers) = DeletionQueue::new(
401 0 : remote_storage.clone(),
402 0 : ControllerUpcallClient::new(conf, &shutdown_pageserver),
403 0 : conf,
404 0 : );
405 0 : deletion_workers.spawn_with(BACKGROUND_RUNTIME.handle());
406 0 :
407 0 : // Up to this point no significant I/O has been done: this should have been fast. Record
408 0 : // duration prior to starting I/O intensive phase of startup.
409 0 : startup_checkpoint(started_startup_at, "initial", "Starting loading tenants");
410 0 : STARTUP_IS_LOADING.set(1);
411 0 :
412 0 : // Startup staging or optimizing:
413 0 : //
414 0 : // We want to minimize downtime for `page_service` connections, and trying not to overload
415 0 : // BACKGROUND_RUNTIME by doing initial compactions and initial logical sizes at the same time.
416 0 : //
417 0 : // init_done_rx will notify when all initial load operations have completed.
418 0 : //
419 0 : // background_jobs_can_start (same name used to hold off background jobs from starting at
420 0 : // consumer side) will be dropped once we can start the background jobs. Currently it is behind
421 0 : // completing all initial logical size calculations (init_logical_size_done_rx) and a timeout
422 0 : // (background_task_maximum_delay).
423 0 : let (init_remote_done_tx, init_remote_done_rx) = utils::completion::channel();
424 0 : let (init_done_tx, init_done_rx) = utils::completion::channel();
425 0 :
426 0 : let (background_jobs_can_start, background_jobs_barrier) = utils::completion::channel();
427 0 :
428 0 : let order = pageserver::InitializationOrder {
429 0 : initial_tenant_load_remote: Some(init_done_tx),
430 0 : initial_tenant_load: Some(init_remote_done_tx),
431 0 : background_jobs_can_start: background_jobs_barrier.clone(),
432 0 : };
433 0 :
434 0 : info!(config=?conf.l0_flush, "using l0_flush config");
435 0 : let l0_flush_global_state =
436 0 : pageserver::l0_flush::L0FlushGlobalState::new(conf.l0_flush.clone());
437 0 :
438 0 : // Scan the local 'tenants/' directory and start loading the tenants
439 0 : let deletion_queue_client = deletion_queue.new_client();
440 0 : let background_purges = mgr::BackgroundPurges::default();
441 0 : let tenant_manager = BACKGROUND_RUNTIME.block_on(mgr::init_tenant_mgr(
442 0 : conf,
443 0 : background_purges.clone(),
444 0 : TenantSharedResources {
445 0 : broker_client: broker_client.clone(),
446 0 : remote_storage: remote_storage.clone(),
447 0 : deletion_queue_client,
448 0 : l0_flush_global_state,
449 0 : },
450 0 : order,
451 0 : shutdown_pageserver.clone(),
452 0 : ))?;
453 0 : let tenant_manager = Arc::new(tenant_manager);
454 0 :
455 0 : BACKGROUND_RUNTIME.spawn({
456 0 : let shutdown_pageserver = shutdown_pageserver.clone();
457 0 : let drive_init = async move {
458 0 : // NOTE: unlike many futures in pageserver, this one is cancellation-safe
459 0 : let guard = scopeguard::guard_on_success((), |_| {
460 0 : tracing::info!("Cancelled before initial load completed")
461 0 : });
462 0 :
463 0 : let timeout = conf.background_task_maximum_delay;
464 0 :
465 0 : let init_remote_done = std::pin::pin!(async {
466 0 : init_remote_done_rx.wait().await;
467 0 : startup_checkpoint(
468 0 : started_startup_at,
469 0 : "initial_tenant_load_remote",
470 0 : "Remote part of initial load completed",
471 0 : );
472 0 : });
473 :
474 : let WaitForPhaseResult {
475 0 : timeout_remaining: timeout,
476 0 : skipped: init_remote_skipped,
477 0 : } = wait_for_phase("initial_tenant_load_remote", init_remote_done, timeout).await;
478 :
479 0 : let init_load_done = std::pin::pin!(async {
480 0 : init_done_rx.wait().await;
481 0 : startup_checkpoint(
482 0 : started_startup_at,
483 0 : "initial_tenant_load",
484 0 : "Initial load completed",
485 0 : );
486 0 : STARTUP_IS_LOADING.set(0);
487 0 : });
488 :
489 : let WaitForPhaseResult {
490 0 : timeout_remaining: _timeout,
491 0 : skipped: init_load_skipped,
492 0 : } = wait_for_phase("initial_tenant_load", init_load_done, timeout).await;
493 :
494 : // initial logical sizes can now start, as they were waiting on init_done_rx.
495 :
496 0 : scopeguard::ScopeGuard::into_inner(guard);
497 0 :
498 0 : // allow background jobs to start: we either completed prior stages, or they reached timeout
499 0 : // and were skipped. It is important that we do not let them block background jobs indefinitely,
500 0 : // because things like consumption metrics for billing are blocked by this barrier.
501 0 : drop(background_jobs_can_start);
502 0 : startup_checkpoint(
503 0 : started_startup_at,
504 0 : "background_jobs_can_start",
505 0 : "Starting background jobs",
506 0 : );
507 0 :
508 0 : // We are done. If we skipped any phases due to timeout, run them to completion here so that
509 0 : // they will eventually update their startup_checkpoint, and so that we do not declare the
510 0 : // 'complete' stage until all the other stages are really done.
511 0 : let guard = scopeguard::guard_on_success((), |_| {
512 0 : tracing::info!("Cancelled before waiting for skipped phases done")
513 0 : });
514 0 : if let Some(f) = init_remote_skipped {
515 0 : f.await;
516 0 : }
517 0 : if let Some(f) = init_load_skipped {
518 0 : f.await;
519 0 : }
520 0 : scopeguard::ScopeGuard::into_inner(guard);
521 0 :
522 0 : startup_checkpoint(started_startup_at, "complete", "Startup complete");
523 0 : };
524 0 :
525 0 : async move {
526 0 : let mut drive_init = std::pin::pin!(drive_init);
527 0 : // just race these tasks
528 0 : tokio::select! {
529 0 : _ = shutdown_pageserver.cancelled() => {},
530 0 : _ = &mut drive_init => {},
531 : }
532 0 : }
533 0 : });
534 0 :
535 0 : let (secondary_controller, secondary_controller_tasks) = secondary::spawn_tasks(
536 0 : tenant_manager.clone(),
537 0 : remote_storage.clone(),
538 0 : background_jobs_barrier.clone(),
539 0 : shutdown_pageserver.clone(),
540 0 : );
541 0 :
542 0 : // shared state between the disk-usage backed eviction background task and the http endpoint
543 0 : // that allows triggering disk-usage based eviction manually. note that the http endpoint
544 0 : // is still accessible even if background task is not configured as long as remote storage has
545 0 : // been configured.
546 0 : let disk_usage_eviction_state: Arc<disk_usage_eviction_task::State> = Arc::default();
547 0 :
548 0 : let disk_usage_eviction_task = launch_disk_usage_global_eviction_task(
549 0 : conf,
550 0 : remote_storage.clone(),
551 0 : disk_usage_eviction_state.clone(),
552 0 : tenant_manager.clone(),
553 0 : background_jobs_barrier.clone(),
554 0 : );
555 :
556 : // Start up the service to handle HTTP mgmt API request. We created the
557 : // listener earlier already.
558 0 : let http_endpoint_listener = {
559 0 : let _rt_guard = MGMT_REQUEST_RUNTIME.enter(); // for hyper
560 0 : let cancel = CancellationToken::new();
561 :
562 0 : let router_state = Arc::new(
563 0 : http::routes::State::new(
564 0 : conf,
565 0 : tenant_manager.clone(),
566 0 : http_auth.clone(),
567 0 : remote_storage.clone(),
568 0 : broker_client.clone(),
569 0 : disk_usage_eviction_state,
570 0 : deletion_queue.new_client(),
571 0 : secondary_controller,
572 0 : )
573 0 : .context("Failed to initialize router state")?,
574 : );
575 0 : let router = http::make_router(router_state, launch_ts, http_auth.clone())?
576 0 : .build()
577 0 : .map_err(|err| anyhow!(err))?;
578 0 : let service = utils::http::RouterService::new(router).unwrap();
579 0 : let server = hyper0::Server::from_tcp(http_listener)?
580 0 : .serve(service)
581 0 : .with_graceful_shutdown({
582 0 : let cancel = cancel.clone();
583 0 : async move { cancel.clone().cancelled().await }
584 0 : });
585 0 :
586 0 : let task = MGMT_REQUEST_RUNTIME.spawn(task_mgr::exit_on_panic_or_error(
587 0 : "http endpoint listener",
588 0 : server,
589 0 : ));
590 0 : HttpEndpointListener(CancellableTask { task, cancel })
591 0 : };
592 0 :
593 0 : let consumption_metrics_tasks = {
594 0 : let cancel = shutdown_pageserver.child_token();
595 0 : let task = crate::BACKGROUND_RUNTIME.spawn({
596 0 : let tenant_manager = tenant_manager.clone();
597 0 : let cancel = cancel.clone();
598 0 : async move {
599 0 : // first wait until background jobs are cleared to launch.
600 0 : //
601 0 : // this is because we only process active tenants and timelines, and the
602 0 : // Timeline::get_current_logical_size will spawn the logical size calculation,
603 0 : // which will not be rate-limited.
604 0 : tokio::select! {
605 0 : _ = cancel.cancelled() => { return; },
606 0 : _ = background_jobs_barrier.wait() => {}
607 0 : };
608 0 :
609 0 : pageserver::consumption_metrics::run(conf, tenant_manager, cancel).await;
610 0 : }
611 0 : });
612 0 : ConsumptionMetricsTasks(CancellableTask { task, cancel })
613 : };
614 :
615 : // Spawn a task to listen for libpq connections. It will spawn further tasks
616 : // for each connection. We created the listener earlier already.
617 0 : let page_service = page_service::spawn(conf, tenant_manager.clone(), pg_auth, {
618 0 : let _entered = COMPUTE_REQUEST_RUNTIME.enter(); // TcpListener::from_std requires it
619 0 : pageserver_listener
620 0 : .set_nonblocking(true)
621 0 : .context("set listener to nonblocking")?;
622 0 : tokio::net::TcpListener::from_std(pageserver_listener).context("create tokio listener")?
623 : });
624 :
625 0 : let mut shutdown_pageserver = Some(shutdown_pageserver.drop_guard());
626 0 :
627 0 : // All started up! Now just sit and wait for shutdown signal.
628 0 :
629 0 : {
630 0 : BACKGROUND_RUNTIME.block_on(async move {
631 0 : let mut sigint = tokio::signal::unix::signal(SignalKind::interrupt()).unwrap();
632 0 : let mut sigterm = tokio::signal::unix::signal(SignalKind::terminate()).unwrap();
633 0 : let mut sigquit = tokio::signal::unix::signal(SignalKind::quit()).unwrap();
634 0 : let signal = tokio::select! {
635 0 : _ = sigquit.recv() => {
636 0 : info!("Got signal SIGQUIT. Terminating in immediate shutdown mode",);
637 0 : std::process::exit(111);
638 : }
639 0 : _ = sigint.recv() => { "SIGINT" },
640 0 : _ = sigterm.recv() => { "SIGTERM" },
641 : };
642 :
643 0 : info!("Got signal {signal}. Terminating gracefully in fast shutdown mode",);
644 :
645 : // This cancels the `shutdown_pageserver` cancellation tree.
646 : // Right now that tree doesn't reach very far, and `task_mgr` is used instead.
647 : // The plan is to change that over time.
648 0 : shutdown_pageserver.take();
649 0 : pageserver::shutdown_pageserver(
650 0 : http_endpoint_listener,
651 0 : page_service,
652 0 : consumption_metrics_tasks,
653 0 : disk_usage_eviction_task,
654 0 : &tenant_manager,
655 0 : background_purges,
656 0 : deletion_queue.clone(),
657 0 : secondary_controller_tasks,
658 0 : 0,
659 0 : )
660 0 : .await;
661 0 : unreachable!()
662 0 : })
663 : }
664 0 : }
665 :
666 0 : async fn create_remote_storage_client(
667 0 : conf: &'static PageServerConf,
668 0 : ) -> anyhow::Result<GenericRemoteStorage> {
669 0 : let config = if let Some(config) = &conf.remote_storage_config {
670 0 : config
671 : } else {
672 0 : anyhow::bail!("no remote storage configured, this is a deprecated configuration");
673 : };
674 :
675 : // Create the client
676 0 : let mut remote_storage = GenericRemoteStorage::from_config(config).await?;
677 :
678 : // If `test_remote_failures` is non-zero, wrap the client with a
679 : // wrapper that simulates failures.
680 0 : if conf.test_remote_failures > 0 {
681 0 : if !cfg!(feature = "testing") {
682 0 : anyhow::bail!("test_remote_failures option is not available because pageserver was compiled without the 'testing' feature");
683 0 : }
684 0 : info!(
685 0 : "Simulating remote failures for first {} attempts of each op",
686 : conf.test_remote_failures
687 : );
688 0 : remote_storage =
689 0 : GenericRemoteStorage::unreliable_wrapper(remote_storage, conf.test_remote_failures);
690 0 : }
691 :
692 0 : Ok(remote_storage)
693 0 : }
694 :
695 2 : fn cli() -> Command {
696 2 : Command::new("Neon page server")
697 2 : .about("Materializes WAL stream to pages and serves them to the postgres")
698 2 : .version(version())
699 2 : .arg(
700 2 : Arg::new("workdir")
701 2 : .short('D')
702 2 : .long("workdir")
703 2 : .help("Working directory for the pageserver"),
704 2 : )
705 2 : .arg(
706 2 : Arg::new("enabled-features")
707 2 : .long("enabled-features")
708 2 : .action(ArgAction::SetTrue)
709 2 : .help("Show enabled compile time features"),
710 2 : )
711 2 : }
712 :
713 : #[test]
714 2 : fn verify_cli() {
715 2 : cli().debug_assert();
716 2 : }
|