首页 文章 精选 留言 我的

精选列表

搜索[rpm包],共10021篇文章
优秀的个人博客,低调大师

openstack 管理三十 - rpm 方式部署 openstack [cinder]

作用 1 cinder 需要连接 ceph 进行云硬盘存储 2 cinder 需要连接 keystone 进行用户验证 3 cinder 需要连接 rabbitmq 处理消息队列 默认下 openstack 提供卷驱动, 支持下面的块存储类型 LVM/iSCSI ThinLVM NFS NetAPP NFS Red Hat Storage (Gluster) Dell EqualLogic CEPH 配置 配置 keystone 验证 # openstack-config --set /etc/cinder/cinder.conf DEFAULT auth_strategy keystone # openstack-config --set /etc/cinder/cinder.conf keystone_authtoken auth_host 240.10.130.25 # openstack-config --set /etc/cinder/cinder.conf keystone_authtoken admin_tenant_name service # openstack-config --set /etc/cinder/cinder.conf keystone_authtoken admin_user cinder # openstack-config --set /etc/cinder/cinder.conf keystone_authtoken admin_password cinder # openstack-config --set /etc/cinder/cinder.conf keystone_authtoken identity_uri http://240.10.130.25:35357 数据库配置 # openstack-config --set /etc/cinder/cinder.conf DEFAULT sql_connection mysql://cinder:cinder@240.10.130.25/cinder # cinder-manage db sync 执行 db sync 之后, 正常会在数据库中看到下面一堆表 mysql> use cinder; Database changed mysql> show tables; +--------------------------+ | Tables_in_cinder | +--------------------------+ | backups | | encryption | | iscsi_targets | | migrate_version | | quality_of_service_specs | | quota_classes | | quota_usages | | quotas | | reservations | | services | | snapshot_metadata | | snapshots | | transfers | | volume_admin_metadata | | volume_glance_metadata | | volume_metadata | | volume_type_extra_specs | | volume_types | | volumes | +--------------------------+ 19 rows in set (0.00 sec) 配置 cinder 服务配置 cpu 配置 设定 cinder 的进程数量 cores = cpu 个数 # CORES=16 # openstack-config --set /etc/cinder/cinder.conf DEFAULT osapi_volume_workers $CORES cinder 连接 rabbitmq 设定 rabbitmq 作为 rpc 后台 # openstack-config --set /etc/cinder/cinder.conf DEFAULT rpc_backend cinder.openstack.common.rpc.impl_kombu cinder 连接 rabbitmq 方法 # openstack-config --set /etc/cinder/cinder.conf DEFAULT rabbit_host 240.10.130.25 # openstack-config --set /etc/cinder/cinder.conf DEFAULT rabbit_virtual_host / # openstack-config --set /etc/cinder/cinder.conf DEFAULT rabbit_port 5672 # openstack-config --set /etc/cinder/cinder.conf DEFAULT rabbit_userid guest # openstack-config --set /etc/cinder/cinder.conf DEFAULT rabbit_password openstack cinder 与 ceph 连接 参考 openstack 管理二十二 - cinder 连接多个存储 backend 注: 默认情况下, 当 cinder 成功使用, 并在创建云硬盘时候, 会自动地连接 ceph, 不需要人为手动挂载 配置 token 验证 (可选, 不影响 cinder create 1) # openstack-config --set /etc/cinder/api-paste.ini filter:authtoken paste.filter_factory keystoneclient.middleware.auth_token:filter_factory 注: 假如上述 token 不配置, 则在 /var/log/cinder/api.log 中会经常看见下面警告 2014-10-04 15:40:35.830 63155 WARNING keystoneclient.middleware.auth_token [-] Configuring auth_uri to point to the public identity endpoint is required; clients may not be able to authenticate against an admin endpoint 2014-10-04 15:40:35.873 63155 WARNING keystoneclient.middleware.auth_token [-] Configuring auth_uri to point to the public identity endpoint is required; clients may not be able to authenticate against an admin endpoint 而下面警告可忽略, 官方提出这个可能是一个 bug, 并在下一个版本会修复 2014-10-04 15:41:05.370 63170 WARNING cinder.context [-] Arguments dropped when creating context: {'user': None, 'tenant': None, 'user_identity': u'- - - - -'} 2014-10-04 15:42:05.372 63170 WARNING cinder.context [-] Arguments dropped when creating context: {'user': None, 'tenant': None, 'user_identity': u'- - - - -'}

优秀的个人博客,低调大师

openstack 管理三十三 - rpm 方式部署 openstack [compute]

作用 compute 用户启动 instance compute 可以连接 ceph 作为 instance 外部存储 软件安装 # yum install -y openstack-neutron.noarch openstack-neutron-ml2.noarch openstack-neutron-openvswitch.noarch openstack-nova-api openstack-nova-compute openstack-nova-conductor openstack-nova-scheduler python-cinderclient openstack-utils openstack-nova-novncproxy 配置 neutron-metadata-agent, neutron-openvswitch-agent 定义 neutron 连接 keystone 认证 # openstack-config --set /etc/neutron/neutron.conf DEFAULT auth_strategy keystone # openstack-config --set /etc/neutron/neutron.conf keystone_authtoken auth_host 240.10.130.25 # openstack-config --set /etc/neutron/neutron.conf keystone_authtoken admin_tenant_name service # openstack-config --set /etc/neutron/neutron.conf keystone_authtoken admin_user neutron # openstack-config --set /etc/neutron/neutron.conf keystone_authtoken admin_password neutron 定义 neutron 连接 rabbitmq # openstack-config --set /etc/neutron/neutron.conf DEFAULT rpc_backend neutron.openstack.common.rpc.impl_kombu # openstack-config --set /etc/neutron/neutron.conf DEFAULT rabbit_host 240.10.130.25 # openstack-config --set /etc/neutron/neutron.conf DEFAULT rabbit_port 5672 # openstack-config --set /etc/neutron/neutron.conf DEFAULT rabbit_userid neutron # openstack-config --set /etc/neutron/neutron.conf DEFAULT rabbit_password openstack 定义 neutron 使用 ml2 的网络 plugin # ln -s /etc/neutron/plugins/ml2/ml2_conf.ini /etc/neutron/plugin.ini # openstack-config --set /etc/neutron/neutron.conf DEFAULT core_plugin neutron.plugins.ml2.plugin.Ml2Plugin # openstack-config --set /etc/neutron/neutron.conf DEFAULT service_plugins neutron.services.l3_router.l3_router_plugin.L3RouterPlugin # openstack-config --set /etc/neutron/plugin.ini ml2 type_drivers vxlan,flat # openstack-config --set /etc/neutron/plugin.ini ml2 tenant_network_types vxlan,flat # openstack-config --set /etc/neutron/plugin.ini ml2 mechanism_drivers openvswitch # openstack-config --set /etc/neutron/plugin.ini agent l2_population True 配置 ovs plugin # openstack-config --set /etc/neutron/plugins/openvswitch/ovs_neutron_plugin.ini ovs bridge_mappings physnet1:br-ex # openstack-config --set /etc/neutron/plugins/openvswitch/ovs_neutron_plugin.ini ovs network_vlan_ranges physnet1 # openstack-config --set /etc/neutron/plugins/openvswitch/ovs_neutron_plugin.ini ovs tunnel_type vxlan # openstack-config --set /etc/neutron/plugins/openvswitch/ovs_neutron_plugin.ini ovs local_ip 10.199.130.31 # openstack-config --set /etc/neutron/plugins/openvswitch/ovs_neutron_plugin.ini ovs enable_tunneling True # openstack-config --set /etc/neutron/plugins/openvswitch/ovs_neutron_plugin.ini ovs integration_bridge br-int # openstack-config --set /etc/neutron/plugins/openvswitch/ovs_neutron_plugin.ini ovs tunnel_bridge br-tun # openstack-config --set /etc/neutron/plugins/openvswitch/ovs_neutron_plugin.ini agent tunnel_types vxlan # openstack-config --set /etc/neutron/plugins/openvswitch/ovs_neutron_plugin.ini securitygroup firewall_driver neutron.agent.linux.iptables_firewall.OVSHybridIptablesFirewallDriver 桥接网络配置 /etc/sysconfig/network-scripts/ifcfg-eth0 DEVICE=eth0 ONBOOT=yes HWADDR=48:46:FB:04:97:5C TYPE=OVSPort DEVICETYPE=ovs OVS_BRIDGE=br-ex /etc/sysconfig/network-scripts/ifcfg-br-ex DEVICE=br-ex DEVICETYPE=ovs TYPE=OVSBridge BOOTPROTO=static IPADDR=10.199.130.31 NETMASK=255.255.252.0 GATEWAY=10.199.128.1 ONBOOT=yes 重启网络生效 service network restart 配置 compute 配置 keystone 验证 # openstack-config --set /etc/nova/nova.conf DEFAULT auth_strategy keystone # openstack-config --set /etc/nova/api-paste.ini filter:authtoken auth_host 240.10.130.25 # openstack-config --set /etc/nova/api-paste.ini filter:authtoken admin_tenant_name service # openstack-config --set /etc/nova/api-paste.ini filter:authtoken admin_user nova # openstack-config --set /etc/nova/api-paste.ini filter:authtoken admin_password nova 连接 rabbitmq, 用于处理消息队列 # openstack-config --set /etc/nova/nova.conf DEFAULT rpc_backend rabbit # openstack-config --set /etc/nova/nova.conf DEFAULT rabbit_host 240.10.130.25 # openstack-config --set /etc/nova/nova.conf DEFAULT rabbit_port 5672 # openstack-config --set /etc/nova/nova.conf DEFAULT rabbit_userid nova # openstack-config --set /etc/nova/nova.conf DEFAULT rabbit_password openstack 连接 glance, 用于获取镜像信息 # openstack-config --set /etc/nova/nova.conf DEFAULT glance_host 10.199.130.25 # openstack-config --set /etc/nova/nova.conf DEFAULT glance_port 9292 # openstack-config --set /etc/nova/nova.conf DEFAULT glance_protocol http # openstack-config --set /etc/nova/nova.conf DEFAULT glance_api_servers 10.199.130.25:9292 # openstack-config --set /etc/nova/nova.conf DEFAULT image_service nova.image.glance.GlanceImageService 连接 neutron 获得网络信息 # openstack-config --set /etc/nova/nova.conf DEFAULT network_api_class nova.network.neutronv2.api.API # openstack-config --set /etc/nova/nova.conf DEFAULT neutron_url http://240.10.130.29:9696/ # openstack-config --set /etc/nova/nova.conf DEFAULT neutron_admin_tenant_name service # openstack-config --set /etc/nova/nova.conf DEFAULT neutron_admin_username neutron # openstack-config --set /etc/nova/nova.conf DEFAULT neutron_admin_password neutron # openstack-config --set /etc/nova/nova.conf DEFAULT neutron_admin_auth_url http://240.10.130.25:35357/v2.0 # openstack-config --set /etc/nova/nova.conf DEFAULT security_group_api neutron # openstack-config --set /etc/nova/nova.conf DEFAULT firewall_drivernova.virt.firewall.NoopFirewallDriver 获得 libvirt 虚拟化支持 # openstack-config --set /etc/nova/nova.conf DEFAULT compute_driver nova.virt.libvirt.LibvirtDriver # openstack-config --set /etc/nova/nova.conf DEFAULT libvirt_inject_partition \-1 # openstack-config --set /etc/nova/nova.conf libvirt virt_type kvm # openstack-config --set /etc/nova/nova.conf libvirt inject_password True # openstack-config --set /etc/nova/nova.conf libvirt live_migration_uri qemu+ssh://nova@%s/system?keyfile=/etc/nova/ssh/nova_migration_key # openstack-config --set /etc/nova/nova.conf libvirt vif_driver nova.virt.libvirt.vif.LibvirtGenericVIFDriver # openstack-config --set /etc/nova/nova.conf libvirt cpu_mode host-model 设定云主机超配信息 openstack-config --set /etc/nova/nova.conf DEFAULT cpu_allocation_ratio=16.0 openstack-config --set /etc/nova/nova.conf DEFAULT ram_allocation_ratio=1.5 openstack-config --set /etc/nova/nova.conf DEFAULT reserved_host_memory_mb=8096 openstack-config --set /etc/nova/nova.conf DEFAULT reserved_host_disk_mb=80 配置连接 nova 的数据库 openstack-config --set /etc/nova/nova.conf DEFAULT sql_connection mysql://nova:openstack@240.10.130.25/nova 配置 vnc 连接 # openstack-config --set /etc/nova/nova.conf DEFAULT novncproxy_base_url http://10.199.130.30:6080/vnc_auto.html # openstack-config --set /etc/nova/nova.conf DEFAULT vncserver_listen 0.0.0.0 # openstack-config --set /etc/nova/nova.conf DEFAULT vncserver_proxyclient_address 240.10.130.30 # openstack-config --set /etc/nova/nova.conf DEFAULT vnc_enabled True compute 节点服务启动 service messagebus restart service libvirtd restart service openstack-nova-compute restart service neutron-openvswitch-agent restart 验证 检测服务 [root@hh-yun-compute-130025 ~]# source /root/keystonerc_admin [root@hh-yun-compute-130025 ~(keystone_admin)]# nova service-list +------------------+-----------------------------------+----------+---------+-------+----------------------------+-----------------+ | Binary | Host | Zone | Status | State | Updated_at | Disabled Reason | +------------------+-----------------------------------+----------+---------+-------+----------------------------+-----------------+ | nova-consoleauth | hh-yun-compute-130030.vclound.com | internal | enabled | up | 2014-10-14T09:48:59.000000 | - | | nova-scheduler | hh-yun-compute-130030.vclound.com | internal | enabled | up | 2014-10-14T09:49:02.000000 | - | | nova-conductor | hh-yun-compute-130030.vclound.com | internal | enabled | up | 2014-10-14T09:48:55.000000 | - | | nova-compute | hh-yun-compute-130030.vclound.com | nova | enabled | down | 2014-10-11T08:31:52.000000 | - | | nova-compute | hh-yun-compute-130031.vclound.com | nova | enabled | up | 2014-10-14T09:48:55.000000 | - | | nova-compute | hh-yun-compute-130032.vclound.com | nova | enabled | up | 2014-10-14T09:48:54.000000 | - | +------------------+-----------------------------------+----------+---------+-------+----------------------------+-----------------+ [root@hh-yun-compute-130025 ~(keystone_admin)]# neutron agent-list +--------------------------------------+--------------------+-----------------------------------+-------+----------------+ | id | agent_type | host | alive | admin_state_up | +--------------------------------------+--------------------+-----------------------------------+-------+----------------+ | 21fa636f-141f-4d59-8be4-9d85d71498e8 | Open vSwitch agent | hh-yun-compute-130032.vclound.com | :-) | True | | 2ec500b0-84f7-4f4d-8565-8ba0abdb3c50 | Open vSwitch agent | hh-yun-compute-130031.vclound.com | :-) | True | | 6f24029b-e24e-424f-a0c3-bfb507eae6da | L3 agent | hh-yun-compute-130029.vclound.com | :-) | True | | 730a9541-ae3d-4448-8798-b825f80514a2 | Metadata agent | hh-yun-compute-130029.vclound.com | :-) | True | | 98ef41f5-46c7-48b3-a8a0-5f638a15c881 | Metadata agent | hh-yun-compute-130031.vclound.com | :-) | True | | a03f5dd1-cc2f-4b5e-ad58-1b0186638bc9 | DHCP agent | hh-yun-compute-130029.vclound.com | :-) | True | | dbc049c1-7101-4470-bc45-9b21c76265ec | Metadata agent | hh-yun-compute-130032.vclound.com | :-) | True | | ec475da6-9a76-498b-a3e7-c711be90673c | Open vSwitch agent | hh-yun-compute-130029.vclound.com | :-) | True | +--------------------------------------+--------------------+-----------------------------------+-------+----------------+ 创建云主机 nova boot --flavor m1.small --image centos5.8 --security_group terry_test_rule --nic net-id=b26b81fc-bda9-4882-950c-614e9546bcd1 terry_test +--------------------------------------+--------------------------------------------------+ | Property | Value | +--------------------------------------+--------------------------------------------------+ | OS-DCF:diskConfig | MANUAL | | OS-EXT-AZ:availability_zone | nova | | OS-EXT-SRV-ATTR:host | - | | OS-EXT-SRV-ATTR:hypervisor_hostname | - | | OS-EXT-SRV-ATTR:instance_name | instance-00000008 | | OS-EXT-STS:power_state | 0 | | OS-EXT-STS:task_state | scheduling | | OS-EXT-STS:vm_state | building | | OS-SRV-USG:launched_at | - | | OS-SRV-USG:terminated_at | - | | accessIPv4 | | | accessIPv6 | | | adminPass | u7CNVSq5ceyv | | config_drive | | | created | 2014-10-13T08:00:48Z | | flavor | m1.small (2) | | hostId | | | id | 1281d02c-a79e-4241-a596-3c1a10b3e7e9 | | image | centos5.8 (438d5c5a-f595-45e5-8236-801b9da8f9ab) | | key_name | - | | metadata | {} | | name | terry_test | | os-extended-volumes:volumes_attached | [] | | progress | 0 | | security_groups | terry_test_rule | | status | BUILD | | tenant_id | 59728cade8b14853a8d3cee8c2567881 | | updated | 2014-10-13T08:00:48Z | | user_id | 43f38bc5c1314670b0cf1d925736ff3a | +--------------------------------------+--------------------------------------------------+ 检验 [root@hh-yun-compute-130025 ~(keystone_admin)]# nova list +--------------------------------------+------------+--------+------------+-------------+------------------------+ | ID | Name | Status | Task State | Power State | Networks | +--------------------------------------+------------+--------+------------+-------------+------------------------+ | 1281d02c-a79e-4241-a596-3c1a10b3e7e9 | terry_test | BUILD | spawning | NOSTATE | ext_net=10.199.131.209 | +--------------------------------------+------------+--------+------------+-------------+------------------------+ [root@hh-yun-compute-130025 ~(keystone_admin)]# nova list +--------------------------------------+------------+--------+------------+-------------+------------------------+ | ID | Name | Status | Task State | Power State | Networks | +--------------------------------------+------------+--------+------------+-------------+------------------------+ | 1281d02c-a79e-4241-a596-3c1a10b3e7e9 | terry_test | ACTIVE | - | Running | ext_net=10.199.131.209 | +--------------------------------------+------------+--------+------------+-------------+------------------------+ 日志验证 [root@hh-yun-compute-130025 ~(keystone_admin)]# nova console-log terry_test Starting cloud-init-local: Starting cloud-init: Cloud-init v. 0.7.4 running 'init-local' at Mon, 13 Oct 2014 08:01:44 +0000. Up 31.90 seconds. [ OK ] Starting cloud-init: Starting cloud-init: Cloud-init v. 0.7.4 running 'init' at Mon, 13 Oct 2014 08:01:44 +0000. Up 32.23 seconds. ci-info: ++++++++++++++++++++++++++++Net device info++++++++++++++++++++++++++++ ci-info: +--------+-------+----------------+---------------+-------------------+ ci-info: | Device | Up | Address | Mask | Hw-Address | ci-info: +--------+-------+----------------+---------------+-------------------+ ci-info: | sit0 | False | . | . | . | ci-info: | lo | True | 127.0.0.1 | 255.0.0.0 | . | ci-info: | eth0 | True | 10.199.131.209 | 255.255.252.0 | fa:16:3e:b6:10:59 | ci-info: +--------+-------+----------------+---------------+-------------------+ ci-info: ++++++++++++++++++++++++++++++++Route info+++++++++++++++++++++++++++++++++ ci-info: +-------+--------------+--------------+---------------+-----------+-------+ ci-info: | Route | Destination | Gateway | Genmask | Interface | Flags | ci-info: +-------+--------------+--------------+---------------+-----------+-------+ ci-info: | 0 | 10.199.128.0 | 0.0.0.0 | 255.255.252.0 | eth0 | U | ci-info: | 1 | 169.254.0.0 | 0.0.0.0 | 255.255.0.0 | eth0 | U | ci-info: | 2 | 0.0.0.0 | 10.199.128.1 | 0.0.0.0 | eth0 | UG | ci-info: +-------+--------------+--------------+---------------+-----------+-------+ Successfully create eth0 nic configuration file # Virtio Network Device DEVICE=eth0 BOOTPROTO=none ONBOOT=yes NETMASK=255.255.252.0 IPADDR=10.199.131.209 HWADDR=fa:16:3e:b6:10:59 BROADCAST=10.199.131.255 TYPE=Ethernet MTU=1450 ***************** Shutting down interface eth0: [ OK ] Shutting down loopback interface: [ OK ] Bringing up loopback interface: [ OK ] Bringing up interface eth0: [ OK ] ***************** DNS resolv.conf: ; generated by /usr/sbin/change_dhcp2fixedip.sh nameserver 10.199.129.21 ***************** Network configuration file is done. [ OK ] Starting cloud-config: Starting cloud-init: Cloud-init v. 0.7.4 running 'modules:config' at Mon, 13 Oct 2014 08:01:59 +0000. Up 46.85 seconds. [ OK ] Starting cloud-final: Starting cloud-init: Cloud-init v. 0.7.4 running 'modules:final' at Mon, 13 Oct 2014 08:02:00 +0000. Up 47.60 seconds. ci-info: no authorized ssh keys fingerprints found for user apps. ci-info: no authorized ssh keys fingerprints found for user apps. ec2: ec2: ############################################################# ec2: -----BEGIN SSH HOST KEY FINGERPRINTS----- ec2: 1024 fe:e8:c5:5c:73:77:15:24:1f:12:ec:14:47:e2:6b:96 /etc/ssh/ssh_host_dsa_key.pub ec2: 2048 41:70:b7:40:86:79:69:ed:82:6e:08:9e:26:32:25:65 /etc/ssh/ssh_host_key.pub ec2: 2048 94:05:cb:3e:d1:a6:4b:5c:92:2c:4a:c5:33:e3:2b:c5 /etc/ssh/ssh_host_rsa_key.pub ec2: -----END SSH HOST KEY FINGERPRINTS----- ec2: ############################################################# -----BEGIN SSH HOST KEY KEYS----- 2048 35 24719050152202493952997764556808574180021483630571545678073814674834202864549990758294160432886566801351575961690720917902026807869558309589491740363104364672910884140833931316256583453042582305449902291903306361761690698760484435248642299693277384199758799190120646312710570653607607334393232605584218823199035894711152805635283940392739554801142234598490992296063909154465800405846799268020700973109825520692081165606126385351983258006278326660672731432219855911319945415678243385593968583270276881889985961899591589675998971591411582249557089252116513013337851462069105055419123305526546752802961464039386703608659 ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEAwhlU3hJmVhTK9etyhVCmy/BeoqL8BIh3vPsXNLVQ8s/iw1hrJSFQE7C6GUECveIkZQv+DsbqNmmiSrpAmJnyMrc0+iNXt9kqaRUniiySXu7mE7fEajFTH1TTVEKy1733KSg4VXpWFgkqkyMjopJqR9i9A+n8RpW96mYodEeVsG991BQo0p9+cccKNObUbUllnl9EPWKUkaGqu5WvvmuGjOZEQrwnn4l7RXumkUQ5dtb7vqgIpZtlY30tz3JNHjjoF3BpqpcWX24+vJpji4lQ1Dgx6WNXseR5/gv6lICr8LoYJFSiBGZJACp60P2YLFiUe//Ln39Tvr+VA9GAhTDk9Q== -----END SSH HOST KEY KEYS----- Cloud-init v. 0.7.4 finished at Mon, 13 Oct 2014 08:02:00 +0000. Datasource DataSourceEc2. Up 47.75 seconds [ OK ] CentOS release 5.8 (Final) Kernel 2.6.18-308.el5 on an x86_64 terry-test login: 网络连接测试 [root@hh-yun-compute-130025 ~(keystone_admin)]# ping -c 1 10.199.131.209 PING 10.199.131.209 (10.199.131.209) 56(84) bytes of data. 64 bytes from 10.199.131.209: icmp_seq=1 ttl=64 time=0.232 ms --- 10.199.131.209 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.232/0.232/0.232/0.000 ms [root@hh-yun-compute-130025 ~(keystone_admin)]# ssh 10.199.131.209 The authenticity of host '10.199.131.209 (10.199.131.209)' can't be established. RSA key fingerprint is 94:05:cb:3e:d1:a6:4b:5c:92:2c:4a:c5:33:e3:2b:c5. Are you sure you want to continue connecting (yes/no)? nova compute 连接 ceph 方法 参考 openstack 管理二十三 - nova compute 连接 ceph 集群

优秀的个人博客,低调大师

openstack 管理三十二 - rpm 方式部署 openstack [neutron]

作用 1 neutron 实现了 openstack 下的虚拟网络功能 2 能够实现路由与交换功能 3 能够具有 dhcp 分配 ip 至云主机 neutron 定义了整个 openstack 的网络模型, 当前测试使用了 flat (平面网络) 生产使用了 vlan flat gre local vlan vxlan neutron 在网络类型中支持下面的组件, 当前使用了 ovs 作为虚拟交换机 arista cisco nexus hyper-V agent L2 population linux bridge agent open vswitch agent tail-f NCS 软件安装 # yum install -y openstack-neutron.noarch openstack-neutron-ml2.noarch openstack-neutron-openvswitch.noarch 必须升级 iproute, 升级后, ip 命令能够具有 netns 参数, 否则在创建云主机时, 无法分配 ip (rhel7不需要) # yum update iproute neutron 连接 keystone # openstack-config --set /etc/neutron/neutron.conf DEFAULT auth_strategy keystone # openstack-config --set /etc/neutron/neutron.conf keystone_authtoken auth_host 240.10.130.25 # openstack-config --set /etc/neutron/neutron.conf keystone_authtoken admin_tenant_name service # openstack-config --set /etc/neutron/neutron.conf keystone_authtoken admin_user neutron # openstack-config --set /etc/neutron/neutron.conf keystone_authtoken admin_password neutron # openstack-config --set /etc/neutron/neutron.conf keystone_authtoken auth_port 35357 # openstack-config --set /etc/neutron/neutron.conf keystone_authtoken auth_protocal http # openstack-config --set /etc/neutron/neutron.conf keystone_authtoken auth_uri http://240.10.130.25:5000/ # openstack-config --set /etc/neutron/neutron.conf agent root_helper sudo\ neutron-rootwrap\ /etc/neutron/rootwrap.conf # openstack-config --set /etc/neutron/neutron.conf agent report_interval 30 neutron 连接 rabbitmq # openstack-config --set /etc/neutron/neutron.conf DEFAULT rpc_backend neutron.openstack.common.rpc.impl_kombu # openstack-config --set /etc/neutron/neutron.conf DEFAULT rabbit_host 240.10.130.25 # openstack-config --set /etc/neutron/neutron.conf DEFAULT rabbit_port 5672 # openstack-config --set /etc/neutron/neutron.conf DEFAULT rabbit_userid neutron # openstack-config --set /etc/neutron/neutron.conf DEFAULT rabbit_password openstack 定义网络 plugin 选择 ml2 作为当前网络 plugin 核心, ovs 将会在以后弃用 # ln -s /etc/neutron/plugins/ml2/ml2_conf.ini /etc/neutron/plugin.ini # openstack-config --set /etc/neutron/neutron.conf DEFAULT core_plugin neutron.plugins.ml2.plugin.Ml2Plugin # openstack-config --set /etc/neutron/neutron.conf DEFAULT service_plugins neutron.services.l3_router.l3_router_plugin.L3RouterPlugin # openstack-config --set /etc/neutron/plugin.ini ml2 type_drivers vxlan,flat # openstack-config --set /etc/neutron/plugin.ini ml2 tenant_network_types vxlan,flat # openstack-config --set /etc/neutron/plugin.ini ml2 mechanism_drivers openvswitch # openstack-config --set /etc/neutron/plugin.ini agent l2_population True 配置 ml2 plugin # openstack-config --set /etc/neutron/plugins/ml2/ml2_conf.ini ml2 type_drivers flat,vxlan # openstack-config --set /etc/neutron/plugins/ml2/ml2_conf.ini ml2 tenant_network_types vxlan,flat # openstack-config --set /etc/neutron/plugins/ml2/ml2_conf.ini ml2 mechanism_drivers openvswitch # openstack-config --set /etc/neutron/plugins/ml2/ml2_conf.ini ml2_type_vxlan vxlan_group 239.1.1.1 neutron 连接 nova 定义连接 nova 方法, 不定义无法正常创建云主机 # openstack-config --set /etc/neutron/neutron.conf DEFAULT notify_nova_on_port_data_changes True # openstack-config --set /etc/neutron/neutron.conf DEFAULT notify_nova_on_port_status_changes True # openstack-config --set /etc/neutron/neutron.conf DEFAULT nova_url http://240.10.130.30:8774/v2 # openstack-config --set /etc/neutron/neutron.conf DEFAULT nova_region_name RegionOne # openstack-config --set /etc/neutron/neutron.conf DEFAULT nova_admin_username nova # openstack-config --set /etc/neutron/neutron.conf DEFAULT nova_admin_tenant_id 5abe0972887645698adbdb94167f9be9 # openstack-config --set /etc/neutron/neutron.conf DEFAULT nova_admin_password nova # openstack-config --set /etc/neutron/neutron.conf DEFAULT nova_admin_auth_url http://240.10.130.25:35357/v2.0 # openstack-config --set /etc/neutron/neutron.conf DEFAULT send_events_interval 2 neutron 连接数据库 # openstack-config --set /etc/neutron/neutron.conf database connection mysql://neutron:openstack@240.10.130.25:3306/neutron_ml2 初始化 neutron 数据库 # neutron-db-manage --config-file /usr/share/neutron/neutron-dist.conf --config-file /etc/neutron/neutron.conf --config-file /etc/neutron/plugin.ini upgrade head 上述命令假如成功, 会出现类似下面的信息 INFO [alembic.migration] Running upgrade 538732fa21e1 -> 5ac1c354a051 INFO [alembic.migration] Running upgrade 5ac1c354a051 -> icehouse 启动 neutron # service neutron-server restart L3 agent 配置 # openstack-config --set /etc/neutron/l3_agent.ini DEFAULT gateway_external_network_id # openstack-config --set /etc/neutron/l3_agent.ini DEFAULT external_network_bridge # openstack-config --set /etc/neutron/l3_agent.ini DEFAULT interface_driver neutron.agent.linux.interface.OVSInterfaceDriver 桥接网络配置 /etc/sysconfig/network-scripts/ifcfg-eth0 DEVICE=eth0 ONBOOT=yes HWADDR=48:46:FB:04:97:EC TYPE=OVSPort DEVICETYPE=ovs OVS_BRIDGE=br-ex /etc/sysconfig/network-scripts/ifcfg-eth0 DEVICE=br-ex DEVICETYPE=ovs TYPE=OVSBridge BOOTPROTO=static IPADDR=10.199.130.29 NETMASK=255.255.252.0 GATEWAY=10.199.128.1 ONBOOT=yes 重启网络可实现桥接网络 # service network restart 创建 OVS 桥接网络 # openstack-config --set /etc/neutron/plugins/openvswitch/ovs_neutron_plugin.ini ovs network_vlan_ranges physnet1 # openstack-config --set /etc/neutron/plugins/openvswitch/ovs_neutron_plugin.ini ovs tunnel_type vxlan # openstack-config --set /etc/neutron/plugins/openvswitch/ovs_neutron_plugin.ini ovs bridge_mappings physnet1:br-ex # openstack-config --set /etc/neutron/plugins/openvswitch/ovs_neutron_plugin.ini ovs local_ip 10.199.130.29 # openstack-config --set /etc/neutron/plugins/openvswitch/ovs_neutron_plugin.ini ovs enable_tunneling True # openstack-config --set /etc/neutron/plugins/openvswitch/ovs_neutron_plugin.ini ovs integration_bridge br-int # openstack-config --set /etc/neutron/plugins/openvswitch/ovs_neutron_plugin.ini ovs tunnel_bridge br-tun # openstack-config --set /etc/neutron/plugins/openvswitch/ovs_neutron_plugin.ini agent tunnel_types vxlan # openstack-config --set /etc/neutron/plugins/openvswitch/ovs_neutron_plugin.ini securitygroup firewall_driver \ # neutron.agent.linux.iptables_firewall.OVSHybridIptablesFirewallDriver 服务启动 service neutron-l3-agent restart service neutron-openvswitch-agent restart 在 openstack 环境下创建网络 网络管理 创建 ext_net 网络, 指定使用平面网络类型 # source /root/keystonerc_admin # neutron net-create ext_net --provider:network_type flat --provider:physical_network physnet1 --router:external=True 创建子网 public_net, 指定网络, dhcp 分配池, dns 信息 # neutron subnet-create ext_net --name public_net --gateway 10.199.128.1 10.199.128.0/22 --allocation-pool start=10.199.131.200,end=10.199.131.220 --enable_dhcp=true --dns-nameserver 10.199.129.21 配置 dhcp agent 功能 # openstack-config --set /etc/neutron/dhcp_agent.ini DEFAULT auth_strategy keystone # openstack-config --set /etc/neutron/dhcp_agent.ini DEFAULT resync_interval 30 # openstack-config --set /etc/neutron/dhcp_agent.ini DEFAULT interface_driver neutron.agent.linux.interface.OVSInterfaceDriver # openstack-config --set /etc/neutron/dhcp_agent.ini DEFAULT dhcp_driver neutron.agent.linux.dhcp.Dnsmasq # openstack-config --set /etc/neutron/dhcp_agent.ini DEFAULT use_namespaces True # openstack-config --set /etc/neutron/dhcp_agent.ini DEFAULT enable_isolated_metadata True # openstack-config --set /etc/neutron/dhcp_agent.ini DEFAULT enable_metadata_network False # openstack-config --set /etc/neutron/dhcp_agent.ini DEFAULT dhcp_delete_namespaces False # openstack-config --set /etc/neutron/dhcp_agent.ini DEFAULT root_helper sudo\ neutron-rootwrap\ /etc/neutron/rootwrap.conf # openstack-config --set /etc/neutron/dhcp_agent.ini DEFAULT state_path /var/lib/neutron # openstack-config --set /etc/neutron/dhcp_agent.ini keystone_authtoken auth_host 10.199.130.25 # openstack-config --set /etc/neutron/dhcp_agent.ini keystone_authtoken admin_tenant_name service # openstack-config --set /etc/neutron/dhcp_agent.ini keystone_authtoken admin_user neutron # openstack-config --set /etc/neutron/dhcp_agent.ini keystone_authtoken admin_password openstack 配置 metadata agent 验证信息 # openstack-config --set /etc/neutron/metadata_agent.ini DEFAULT auth_url http://240.10.130.25:35357/v2.0 # openstack-config --set /etc/neutron/metadata_agent.ini DEFAULT auth_region RegionOne # openstack-config --set /etc/neutron/metadata_agent.ini DEFAULT admin_tenant_name service # openstack-config --set /etc/neutron/metadata_agent.ini DEFAULT admin_user neutron # openstack-config --set /etc/neutron/metadata_agent.ini DEFAULT admin_password neutron # openstack-config --set /etc/neutron/metadata_agent.ini DEFAULT debug False # openstack-config --set /etc/neutron/metadata_agent.ini DEFAULT auth_insecure False # openstack-config --set /etc/neutron/metadata_agent.ini DEFAULT nova_metadata_ip 240.10.130.30 # openstack-config --set /etc/neutron/metadata_agent.ini DEFAULT nova_metadata_port 8775 # openstack-config --set /etc/neutron/metadata_agent.ini DEFAULT metadata_proxy_shared_secret 744ee65672684281 # openstack-config --set /etc/neutron/metadata_agent.ini DEFAULT metadata_workers 0 假如 metadata 没有配置, 创建虚拟机期间将会遇见下面错误 ci-info: ++++++++++++++++++++++++++++Net device info++++++++++++++++++++++++++++ ci-info: +--------+-------+----------------+---------------+-------------------+ ci-info: | Device | Up | Address | Mask | Hw-Address | ci-info: +--------+-------+----------------+---------------+-------------------+ ci-info: | sit0 | False | . | . | . | ci-info: | lo | True | 127.0.0.1 | 255.0.0.0 | . | ci-info: | eth0 | True | 10.199.131.208 | 255.255.252.0 | fa:16:3e:0e:61:31 | ci-info: +--------+-------+----------------+---------------+-------------------+ ci-info: ++++++++++++++++++++++++++++++++Route info+++++++++++++++++++++++++++++++++ ci-info: +-------+--------------+--------------+---------------+-----------+-------+ ci-info: | Route | Destination | Gateway | Genmask | Interface | Flags | ci-info: +-------+--------------+--------------+---------------+-----------+-------+ ci-info: | 0 | 10.199.128.0 | 0.0.0.0 | 255.255.252.0 | eth0 | U | ci-info: | 1 | 169.254.0.0 | 0.0.0.0 | 255.255.0.0 | eth0 | U | ci-info: | 2 | 0.0.0.0 | 10.199.128.1 | 0.0.0.0 | eth0 | UG | ci-info: +-------+--------------+--------------+---------------+-----------+-------+ 2014-10-13 15:35:21,836 - url_helper.py[WARNING]: Calling 'http://169.254.169.254/2009-04-04/meta-data/instance-id' failed [0/120s]: bad status code [500] 2014-10-13 15:35:22,846 - url_helper.py[WARNING]: Calling 'http://169.254.169.254/2009-04-04/meta-data/instance-id' failed [1/120s]: bad status code [500] neutron 服务启动 # service messagebus restart # service neutron-server restart # service neutron-dhcp-agent restart # service neutron-l3-agent restart # service neutron-metadata-agent restart # service neutron-openvswitch-agent restart

优秀的个人博客,低调大师

openstack 管理三十一 - rpm 方式部署 openstack [nova]

作用 1 响应云主机请求, 并把连接调度至对应的 compute 节点 2 提供 console 认证服务 3 提供 vnc 访问云主机功能 软件安装 # yum install -y openstack-nova-api openstack-nova-compute openstack-nova-conductor openstack-nova-scheduler python-cinderclient openstack-utils openstack-nova-novncproxy openstack-nova-console 配置 vnc 服务 # openstack-config --set /etc/nova/nova.conf DEFAULT openstack-config --set /etc/nova/nova.conf DEFAULT xvpvncproxy_base_url http://0.0.0.0:6081/console # openstack-config --set /etc/nova/nova.conf DEFAULT vncserver_listen 0.0.0.0 # openstack-config --set /etc/nova/nova.conf DEFAULT vncserver_proxyclient_address 0.0.0.0 # openstack-config --set /etc/nova/nova.conf DEFAULT vnc_enabled true # openstack-config --set /etc/nova/nova.conf DEFAULT vpvncproxy_port 6081 # openstack-config --set /etc/nova/nova.conf DEFAULT xvpvncproxy_host 0.0.0.0 # openstack-config --set /etc/nova/nova.conf DEFAULT novncproxy_host=0.0.0.0 # openstack-config --set /etc/nova/nova.conf DEFAULT novncproxy_port=6080 配置 keystone 验证 # openstack-config --set /etc/nova/nova.conf DEFAULT auth_strategy keystone # openstack-config --set /etc/nova/nova.conf keystone_authtoken auth_host 240.10.130.25 # openstack-config --set /etc/nova/nova.conf keystone_authtoken auth_port 35357 # openstack-config --set /etc/nova/nova.conf keystone_authtoken auth_protocol http # openstack-config --set /etc/nova/nova.conf keystone_authtoken auth_uri http://240.10.130.25:5000/ # openstack-config --set /etc/nova/nova.conf keystone_authtoken admin_user nova # openstack-config --set /etc/nova/nova.conf keystone_authtoken admin_password nova # openstack-config --set /etc/nova/nova.conf keystone_authtoken admin_tenant_name service # openstack-config --set /etc/nova/api-paste.ini filter:authtoken auth_host 240.10.130.25 # openstack-config --set /etc/nova/api-paste.ini filter:authtoken admin_tenant_name service # openstack-config --set /etc/nova/api-paste.ini filter:authtoken admin_user nova # openstack-config --set /etc/nova/api-paste.ini filter:authtoken admin_password nova # openstack-config --set /etc/nova/api-paste.ini filter:authtoken paste.filter_factory keystoneclient.middleware.auth_token:filter_factory nova 连接 glance # openstack-config --set /etc/nova/nova.conf DEFAULT glance_host 10.199.130.25 # openstack-config --set /etc/nova/nova.conf DEFAULT glance_port 9292 # openstack-config --set /etc/nova/nova.conf DEFAULT glance_protocol http # openstack-config --set /etc/nova/nova.conf DEFAULT glance_api_servers 10.199.130.25:9292 # openstack-config --set /etc/nova/nova.conf DEFAULT image_service nova.image.glance.GlanceImageService nova 连接 rabbitmq # openstack-config --set /etc/nova/nova.conf DEFAULT rpc_backend rabbit # openstack-config --set /etc/nova/nova.conf DEFAULT rabbit_host 240.10.130.25 # openstack-config --set /etc/nova/nova.conf DEFAULT rabbit_port 5672 # openstack-config --set /etc/nova/nova.conf DEFAULT rabbit_userid nova # openstack-config --set /etc/nova/nova.conf DEFAULT rabbit_password openstack 设定虚拟云主机超配 # openstack-config --set /etc/nova/nova.conf DEFAULT cpu_allocation_ratio=16.0 # openstack-config --set /etc/nova/nova.conf DEFAULT ram_allocation_ratio=1.5 # openstack-config --set /etc/nova/nova.conf DEFAULT reserved_host_memory_mb=1024 # openstack-config --set /etc/nova/nova.conf DEFAULT reserved_host_disk_mb=0 nova 节点启用 metadata-proxy 连接 metadata # openstack-config --set /etc/nova/nova.conf DEFAULT enabled_apis ec2,osapi_compute,metadata # openstack-config --set /etc/nova/nova.conf DEFAULT metadata_listen 0.0.0.0 # openstack-config --set /etc/nova/nova.conf DEFAULT metadata_workers 24 # openstack-config --set /etc/nova/nova.conf DEFAULT rootwrap_config /etc/nova/rootwrap.conf # openstack-config --set /etc/nova/nova.conf DEFAULT use_forwarded_for False # openstack-config --set /etc/nova/nova.conf DEFAULT service_neutron_metadata_proxy True # openstack-config --set /etc/nova/nova.conf DEFAULT neutron_metadata_proxy_shared_secret 744ee65672684281 # openstack-config --set /etc/nova/nova.conf DEFAULT neutron_default_tenant_id default # openstack-config --set /etc/nova/nova.conf DEFAULT metadata_host 240.10.130.30 nova 连接 neutron # openstack-config --set /etc/nova/nova.conf DEFAULT network_api_class nova.network.neutronv2.api.API # openstack-config --set /etc/nova/nova.conf DEFAULT neutron_url http://240.10.130.29:9696/ # openstack-config --set /etc/nova/nova.conf DEFAULT neutron_admin_tenant_name service # openstack-config --set /etc/nova/nova.conf DEFAULT neutron_admin_username neutron # openstack-config --set /etc/nova/nova.conf DEFAULT neutron_admin_password neutron # openstack-config --set /etc/nova/nova.conf DEFAULT neutron_admin_auth_url http://240.10.130.25:35357/v2.0 # openstack-config --set /etc/nova/nova.conf DEFAULT security_group_api neutron # openstack-config --set /etc/nova/nova.conf DEFAULT firewall_drivernova.virt.firewall.NoopFirewallDriver 指定 libvirt 连接驱动 openstack-config --set /etc/nova/nova.conf libvirt vif_driver nova.virt.libvirt.vif.LibvirtGenericVIFDriver 支持 ovs 网络 plugin openstack-config --set /etc/nova/nova.conf libvirt vif_driver nova.virt.libvirt.vif.LibvirtGenericVIFDriver nova 连接 db openstack-config --set /etc/nova/nova.conf DEFAULT sql_connection mysql://nova:openstack@240.10.130.25/nova 初始化数据 当数据库配置成功, 则下面命令能够在数据库上产生 108 个表 sudo -u nova nova-manage db sync 服务启动 # service openstack-nova-consoleauth restart # service openstack-nova-novncproxy restart # service messagebus restart # service libvirtd restart # service openstack-nova-api restart # service openstack-nova-scheduler restart # service openstack-nova-conductor restart 创建防火墙 [root@hh-yun-compute-130025 ~(keystone_admin)]# nova agent-list +----------+------------+----+--------------+---------+---------+-----+ | Agent_id | Hypervisor | OS | Architecture | Version | Md5hash | Url | +----------+------------+----+--------------+---------+---------+-----+ +----------+------------+----+--------------+---------+---------+-----+ 检测服务状态 [root@hh-yun-compute-130025 ~(keystone_admin)]# nova service-list +------------------+-----------------------------------+----------+---------+-------+----------------------------+-----------------+ | Binary | Host | Zone | Status | State | Updated_at | Disabled Reason | +------------------+-----------------------------------+----------+---------+-------+----------------------------+-----------------+ | nova-consoleauth | hh-yun-compute-130030.vclound.com | internal | enabled | up | 2014-10-11T02:36:15.000000 | - | | nova-scheduler | hh-yun-compute-130030.vclound.com | internal | enabled | up | 2014-10-11T02:36:16.000000 | - | | nova-conductor | hh-yun-compute-130030.vclound.com | internal | enabled | up | 2014-10-11T02:36:16.000000 | - | | nova-compute | hh-yun-compute-130030.vclound.com | nova | disabled| down | 2014-10-11T02:36:16.000000 | - | +------------------+-----------------------------------+----------+---------+-------+----------------------------+-----------------+ 检测网络 [root@hh-yun-compute-130025 ~(keystone_admin)]# nova network-list +--------------------------------------+---------+------+ | ID | Label | Cidr | +--------------------------------------+---------+------+ | b26b81fc-bda9-4882-950c-614e9546bcd1 | ext_net | - | +--------------------------------------+---------+------+ 检测安全组 [root@hh-yun-compute-130025 ~(keystone_admin)]# nova secgroup-list +--------------------------------------+---------+-------------+ | Id | Name | Description | +--------------------------------------+---------+-------------+ | 9caa0d6f-c063-46f9-ab3b-845962ac836b | default | default | +--------------------------------------+---------+-------------+ 检测规则 [root@hh-yun-compute-130025 ~(keystone_admin)]# nova secgroup-list-rules default +-------------+-----------+---------+-----------+--------------+ | IP Protocol | From Port | To Port | IP Range | Source Group | +-------------+-----------+---------+-----------+--------------+ | | | | | default | | | | | | default | +-------------+-----------+---------+-----------+--------------+ 为 default 安全组加添规则 # nova secgroup-add-rule default icmp -1 -1 0.0.0.0/0 > /dev/null # nova secgroup-add-rule default tcp 22 22 0.0.0.0/0 > /dev/null # nova secgroup-add-rule default udp 53 53 0.0.0.0/0 > /dev/null 验证 [root@hh-yun-compute-130025 ~(keystone_admin)]# nova secgroup-list-rules default +-------------+-----------+---------+-----------+--------------+ | IP Protocol | From Port | To Port | IP Range | Source Group | +-------------+-----------+---------+-----------+--------------+ | icmp | -1 | -1 | 0.0.0.0/0 | | | | | | | default | | tcp | 22 | 22 | 0.0.0.0/0 | | | udp | 53 | 53 | 0.0.0.0/0 | | | | | | | default | +-------------+-----------+---------+-----------+--------------+ 创建新的安全组 # nova secgroup-create terry_test_rule "allow ping and ssh" > /dev/null # nova secgroup-add-rule terry_test_rule icmp -1 -1 0.0.0.0/0 > /dev/null # nova secgroup-add-rule terry_test_rule tcp 22 22 0.0.0.0/0 > /dev/null # nova secgroup-add-rule terry_test_rule udp 53 53 0.0.0.0/0 > /dev/null 验证 [root@hh-yun-compute-130025 ~(keystone_admin)]# nova secgroup-list-rules terry_test_rule +-------------+-----------+---------+-----------+--------------+ | IP Protocol | From Port | To Port | IP Range | Source Group | +-------------+-----------+---------+-----------+--------------+ | icmp | -1 | -1 | 0.0.0.0/0 | | | udp | 53 | 53 | 0.0.0.0/0 | | | tcp | 22 | 22 | 0.0.0.0/0 | | +-------------+-----------+---------+-----------+--------------+

优秀的个人博客,低调大师

openstack 管理二十八 - rpm 方式部署 openstack [keystone]

说明 1 keystone 数据存储至 mariadb 中 2 keystone 主要为 nova, neutron, cinder 等组件提供数据认证服务, 3 keystone 自身管理 user, tenant, service, endpoint 等重要信息 安装 yum install -y openstack-keystone.noarch openstack-keystone-doc.noarch python-keystone.noarch python-keystoneclient.noarch python-keystoneclient-doc.noarch python-keyring openstack-utils 配置 直接配置 token # SERVICE_TOKEN=1wef2djdf98324jkl # openstack-config --set /etc/keysto ne/keystone.conf DEFAULT admin_token $SERVICE_TOKEN 强制更新 token 并删除旧 token # keystone-manage token_flush 直接配置 keystone 的数据库连接方法 # openstack-config --set /etc/keystone/keystone.conf database sql_connection mysql://keystone:test123@240.10.130.25/keystone keystone 服务器设定 # openstack-config --set /etc/keysto ne/keystone.conf DEFAULT public_bind_host 240.10.130.25 # openstack-config --set /etc/keysto ne/keystone.conf DEFAULT admin_bind_host 240.10.130.25 # openstack-config --set /etc/keysto ne/keystone.conf DEFAULT compute_port 8774 # openstack-config --set /etc/keysto ne/keystone.conf DEFAULT admin_port 35357 # openstack-config --set /etc/keysto ne/keystone.conf DEFAULT public_port 5000 keystone 存储格式定义 # openstack-config --set /etc/keysto ne/keystone.conf signing token_format UUID # openstack-config --set /etc/keystone/keystone.conf token provider keystone.token.providers.uuid.Provider 启动 keystone 服务 # service openstack-keystone start 创建相应数据库表 # keystone-manage db_sync 假如连接成功, 则自动创建下面表 mysql> use keystone; mysql> show tables; +-----------------------+ | Tables_in_keystone | +-----------------------+ | assignment | | credential | | domain | | endpoint | | group | | migrate_version | | policy | | project | | region | | role | | service | | token | | trust | | trust_role | | user | | user_group_membership | +-----------------------+ 16 rows in set (0.00 sec) keystone 客户端安装 要连接 keystone 需要安装 python-keystoneclient yum install -y python-keystoneclient 创建测试 tenant 与 admin tenant 参考 /etc/keystone/keystone.conf 中自定义的 token 与 admin_bind_host 参考, 对应下面 endpoint 与 token 值 # export ENDPOINT=240.10.130.25 # export SERVICE_TOKEN=1wef2djdf98324jkl # export SERVICE_ENDPOINT=http://${ENDPOINT}:35357/v2.0 创建 tenant 测试 [root@hh-yun-compute-130025 ~]# keystone tenant-create --name cookbook --description "Default Cookbook Tenant" --enabled true +-------------+----------------------------------+ | Property | Value | +-------------+----------------------------------+ | description | Default Cookbook Tenant | | enabled | True | | id | c74de0a2760343ac93f27095023be1cd | | name | cookbook | +-------------+----------------------------------+ 检测 tenant 信息 [root@hh-yun-compute-130025 ~]# keystone tenant-list +----------------------------------+----------+---------+ | id | name | enabled | +----------------------------------+----------+---------+ | c74de0a2760343ac93f27095023be1cd | cookbook | True | +----------------------------------+----------+---------+ 另外, 我们必须要创建一个 admin 的 tenant, admin 环境才能够保证用户具有完整的环境 [root@hh-yun-compute-130025 ~]# keystone tenant-create --name admin --description "Admin tenant" --enabled true +-------------+----------------------------------+ | Property | Value | +-------------+----------------------------------+ | description | Admin tenant | | enabled | True | | id | 59728cade8b14853a8d3cee8c2567881 | | name | admin | +-------------+----------------------------------+ [root@hh-yun-compute-130025 ~]# keystone tenant-list +----------------------------------+----------+---------+ | id | name | enabled | +----------------------------------+----------+---------+ | 59728cade8b14853a8d3cee8c2567881 | admin | True | | c74de0a2760343ac93f27095023be1cd | cookbook | True | +----------------------------------+----------+---------+ 配置 keystone 角色 1 role 是用户在 tenant 下的权限的体现 2 常见有 admin 与 member 两种角色 注意: /etc/keystone/policy.json 定义了管理员角色 “admin_required”: “role:admin or is_admin:1”, 从 /etc/keystone/keystone.conf 下获得 keystone 认证信息 # export ENDPOINT=240.10.130.25 # export SERVICE_TOKEN=1wef2djdf98324jkl # export SERVICE_ENDPOINT=http://${ENDPOINT}:35357/v2.0 创建 admin 角色 # keystone role-create --name admin 创建 member 角色 # keystone role-create --name Member (旧版) # keystone role-create --name _member_ ( i 版) 利用 keystone 创建用户 1. 查询 tenant [root@hh-yun-compute-130025 ~]# keystone tenant-list +----------------------------------+----------+---------+ | id | name | enabled | +----------------------------------+----------+---------+ | 59728cade8b14853a8d3cee8c2567881 | admin | True | | c74de0a2760343ac93f27095023be1cd | cookbook | True | +----------------------------------+----------+---------+ 2. 创建 admin 用户 [root@hh-yun-compute-130025 ~]# keystone user-create --name admin --tenant cookbook --pass test123 --email terry.zeng@vipshop.com --enabled true +----------+----------------------------------+ | Property | Value | +----------+----------------------------------+ | email | terry.zeng@vipshop.com | | enabled | True | | id | 43f38bc5c1314670b0cf1d925736ff3a | | name | admin | | tenantId | c74de0a2760343ac93f27095023be1cd | | username | admin | +----------+----------------------------------+ 3. 查询角色 [root@hh-yun-compute-130025 ~]# keystone role-list +----------------------------------+----------+ | id | name | +----------------------------------+----------+ | 9fe2ff9ee4384b1894a90878d3e92bab | _member_ | | 6ddaf6bbd9684a109ecf83f7939bcf94 | admin | +----------------------------------+----------+ 4. 查询用户 [root@hh-yun-compute-130025 ~]# keystone user-list +----------------------------------+-------+---------+------------------------+ | id | name | enabled | email | +----------------------------------+-------+---------+------------------------+ | 43f38bc5c1314670b0cf1d925736ff3a | admin | True | terry.zeng@vipshop.com | +----------------------------------+-------+---------+------------------------+ 5. 指定用户新的 tenant 角色 [root@hh-yun-compute-130025 ~]# keystone user-role-add --user admin --role admin --tenant admin 参考 为 cookbook tenant 授权 demo 为管理员 [root@hh-yun-compute-130025 ~]# keystone user-create --name demo --tenant cookbook --pass test123 --email demo@localhost --enabled true +----------+----------------------------------+ | Property | Value | +----------+----------------------------------+ | email | demo@localhost | | enabled | True | | id | a57b848ff4244b98be66ef8f133fc9ce | | name | demo | | tenantId | c74de0a2760343ac93f27095023be1cd | | username | demo | +----------+----------------------------------+ [root@hh-yun-compute-130025 ~]# keystone user-role-add --user demo --role admin --tenant cookbook service 定义 1 云环境中每个服务都运行在一个特定的 url 下, 成为 endpoint 地址 2 客户端连接 openstack 环境时候, 允许 openstack 身份验证服务, 这个服务将返回 用户可以访问的 endpoint url 要启用上述功能, 我们需要定义 endpoint, 1 云环境下, 我们可以定义多个区域, 不同区域可以跑在不同的数据中心中 2 在 openstack 身份认证服务下不同区域由不同的 ip 及 urls 进行指定 3 当我们只有一个独立环境时候, 我们配置为 RegionOne 下面是openstack i 版需要定义的服务 endpoint 1. 定义 nova keystone service-create --name nova --type compute --description 'OpenStack Compute Service' 2. 定义 nova_ec2 (旧版本叫 ec2) keystone service-create --name nova_ec2 --type ec2 --description 'EC2 Service' 3. 定义 glance 服务 keystone service-create --name glance --type image --description 'OpenStack Image Service' 4. 定义 cinder 服务 keystone service-create --name cinder --type volume --description 'Cinder Service' 5. 定义 cinder_v2 keystone service-create --name cinder_v2 --type volume2 --description 'Cinder Service v2' 6. 定义 keystone keystone service-create --name keystone --type identity --description 'OpenStack Identity Service' 7. 定义 neutron keystone service-create --name neutron --type network --description 'Neutron Networking Service' 定义 endpoint Openstack 身份服务可以配置三种服务请求方法 1 public Url (针对最终用户) 2 administration Url (具有管理权限的用户, 可以与 public url 使用不同的地址) 3 internal Url (使用在一个专用网络上, 与公网隔离) 当前品云使这种方式, 同时调用 eth1 作为组件间通讯方法 当服务定义后, 我们可以为服务添加 endpoint urls, 参考命令语法 [root@hh-yun-compute-130025 ~]# keystone endpoint-create usage: keystone endpoint-create [--region <endpoint-region>] --service <service> --publicurl <public-url> [--adminurl <admin-url>] [--internalurl <internal-url>] 定义 nova endpoint # PUBLIC="http://240.10.130.30:8774/v2/\$(tenant_id)s" # keystone endpoint-create --region RegionOne --service nova --publicurl $PUBLIC --adminurl $PUBLIC --internalurl $PUBLIC +-------------+--------------------------------------------+ | Property | Value | +-------------+--------------------------------------------+ | adminurl | http://240.10.130.30:8774/v2/$(tenant_id)s | | id | fe31d81f395f46e39dd2e3ba9276c4ba | | internalurl | http://240.10.130.30:8774/v2/$(tenant_id)s | | publicurl | http://240.10.130.30:8774/v2/$(tenant_id)s | | region | RegionOne | | service_id | 38df11244f3e42698f3c123cc89e9a82 | +-------------+--------------------------------------------+ 定义 nova_ec2 endpoint # PUBLIC="http://240.10.130.30:8773/services/Cloud" # ADMIN="http://240.10.130.30:8773/services/Admin" # INTERNAL=$PUBLIC # keystone endpoint-create --region RegionOne --service_id nova_ec2 --publicurl $PUBLIC --adminurl $ADMIN --internalurl $INTERNAL +-------------+------------------------------------------+ | Property | Value | +-------------+------------------------------------------+ | adminurl | http://240.10.130.30:8773/services/Admin | | id | a835a2aeba444692b215136e641a9e5c | | internalurl | http://240.10.130.30:8773/services/Cloud | | publicurl | http://240.10.130.30:8773/services/Cloud | | region | RegionOne | | service_id | 18cbe76bbcab479595d90d7a50b7dcdf | +-------------+------------------------------------------+ 定义 glance endpoint # PUBLIC="http://240.10.130.25:9292/v1" # keystone endpoint-create --region RegionOne --service_id glance --publicurl $PUBLIC --adminurl $PUBLIC --internalurl $PUBLIC +-------------+----------------------------------+ | Property | Value | +-------------+----------------------------------+ | adminurl | http://240.10.130.25:9292/v1 | | id | b3773df6ad2643fa84c6cae71a7a71cc | | internalurl | http://240.10.130.25:9292/v1 | | publicurl | http://240.10.130.25:9292/v1 | | region | RegionOne | | service_id | d23d46ad40bd4fc89c9c88118acedf75 | +-------------+----------------------------------+ 定义 cinder endpoint # PUBLIC="http://240.10.130.25:8776/v1/%(tenant_id)s" # keystone endpoint-create --region RegionOne --service_id cinder --publicurl $PUBLIC --adminurl $PUBLIC --internalurl $PUBLIC +-------------+--------------------------------------------+ | Property | Value | +-------------+--------------------------------------------+ | adminurl | http://240.10.130.25:8776/v1/%(tenant_id)s | | id | 044bc4aeb52e4ddd9b60984b82f1a619 | | internalurl | http://240.10.130.25:8776/v1/%(tenant_id)s | | publicurl | http://240.10.130.25:8776/v1/%(tenant_id)s | | region | RegionOne | | service_id | eb92fe7081394648ae9cc25eec0713d7 | +-------------+--------------------------------------------+ 定义 cinder_v2 endpoint # PUBLIC="http://240.10.130.25:8776/v2/%(tenant_id)s" # keystone endpoint-create --region RegionOne --service_id cinder_v2 --publicurl $PUBLIC --adminurl $PUBLIC --internalurl $PUBLIC +-------------+--------------------------------------------+ | Property | Value | +-------------+--------------------------------------------+ | adminurl | http://240.10.130.25:8776/v2/%(tenant_id)s | | id | a4f434470e364ff89030d2919eb39c86 | | internalurl | http://240.10.130.25:8776/v2/%(tenant_id)s | | publicurl | http://240.10.130.25:8776/v2/%(tenant_id)s | | region | RegionOne | | service_id | 63376b37779846eba1f4a96aa142ba94 | +-------------+--------------------------------------------+ 定义keystone endpoint # PUBLIC="http://240.10.130.25:5000/v2.0" # ADMIN="http://240.10.130.25:35357/v2.0" # INTERNAL=$PUBLIC # keystone endpoint-create --region RegionOne --service_id keystone --publicurl $PUBLIC --adminurl $ADMIN --internalurl $INTERNAL +-------------+----------------------------------+ | Property | Value | +-------------+----------------------------------+ | adminurl | http://240.10.130.25:35357/v2.0 | | id | 047b73ba968d41d98ea707ca51f1db33 | | internalurl | http://240.10.130.25:5000/v2.0 | | publicurl | http://240.10.130.25:5000/v2.0 | | region | RegionOne | | service_id | 96dba0ee5a154727843cd975f4ce5e29 | +-------------+----------------------------------+ 定义 neutron endpoint # PUBLIC="http://240.10.130.29:9696/" # keystone endpoint-create --region RegionOne --service_id neutron --publicurl $PUBLIC --adminurl $PUBLIC --internalurl $PUBLIC +-------------+----------------------------------+ | Property | Value | +-------------+----------------------------------+ | adminurl | http://240.10.130.29:9696/ | | id | 52f34a0e1f0446c3b0683a330b1a1ce4 | | internalurl | http://240.10.130.29:9696/ | | publicurl | http://240.10.130.29:9696/ | | region | RegionOne | | service_id | 7123d8111fa14e06a59b757c3a78901f | +-------------+----------------------------------+ 创建 service tenant 需要创建 service tenant, 用于允许上述服务在 openstack 中运行 并创建对应服务的用户密码并对应 service tenant ### 注意, 品云使用 services 作为 tenant 区别不大 ### 用户创建方法与普通创建方法一样, 并分配至 service tenant 中 创建 service tenant # keystone tenant-create --name service --description "Service Tenant" --enabled true 创建用户 # keystone user-create --name nova --pass nova --tenant service --email nova@localhost --enabled true # keystone user-create --name glance --pass glance --tenant service --email glance@localhost --enabled true # keystone user-create --name keystone --pass keystone --tenant service --email keystone@localhost --enabled true # keystone user-create --name cinder --pass cinder --tenant service --email cinder@localhost --enabled true # keystone user-create --name neutron --pass neutron --tenant service --email neutron@localhost --enabled true 修改用户角色 # keystone user-role-add --user nova --role admin --tenant service # keystone user-role-add --user glance --role admin --tenant service # keystone user-role-add --user keystone --role admin --tenant service # keystone user-role-add --user cinder --role admin --tenant service # keystone user-role-add --user neutron --role admin --tenant service

优秀的个人博客,低调大师

openstack 管理二十九 - rpm 方式部署 openstack [glance]

作用 1 glance 主要用于管理云主机镜像 2 glance 需要进行 keystone 验证 3 在第一次云主机创建时候, 把镜像从 glance server 传输至 compute 组件中 安装 yum install -y openstack-glance.noarch openstack-glance-doc.noarch python-glance.noarch python-glanceclient.noarch python-glanceclient-doc.noarch openstack-utils glance 连接 db 数据库连接配置 # openstack-config --set /etc/glance/glance-api.conf DEFAULT sql_connection mysql://glance:glance@240.10.130.25/glance # openstack-config --set /etc/glance/glance-api.conf DEFAULT sql_idle_timeout 3600 # openstack-config --set /etc/glance/glance-registry.conf DEFAULT sql_connection mysql://glance:glance@240.10.130.25/glance # openstack-config --set /etc/glance/glance-registry.conf DEFAULT sql_idle_timeout 3600 glance 连接 keystone 配置 /etc/glance/glance-api.conf # openstack-config --set /etc/glance/glance-api.conf paste_deploy flavor keystone # openstack-config --set /etc/glance/glance-api.conf keystone_authtoken auth_host 240.10.130.25 # openstack-config --set /etc/glance/glance-api.conf keystone_authtoken auth_port 35357 # openstack-config --set /etc/glance/glance-api.conf keystone_authtoken auth_protocol http # openstack-config --set /etc/glance/glance-api.conf keystone_authtoken admin_tenant_name services # openstack-config --set /etc/glance/glance-api.conf keystone_authtoken admin_user glance # openstack-config --set /etc/glance/glance-api.conf keystone_authtoken admin_password glance 配置 /etc/glance/glance-registry.conf # openstack-config --set /etc/glance/glance-registry.conf paste_deploy flavor keystone # openstack-config --set /etc/glance/glance-registry.conf keystone_authtoken auth_host 240.10.130.25 # openstack-config --set /etc/glance/glance-registry.conf keystone_authtoken auth_port 35357 # openstack-config --set /etc/glance/glance-registry.conf keystone_authtoken auth_protocol http # openstack-config --set /etc/glance/glance-registry.conf keystone_authtoken admin_tenant_name services # openstack-config --set /etc/glance/glance-registry.conf keystone_authtoken admin_user glance # openstack-config --set /etc/glance/glance-registry.conf keystone_authtoken admin_password glance # openstack-config --set /etc/glance/glance-registry.conf paste_deploy config_file /etc/glance/glance-api-paste.ini # openstack-config --set /etc/glance/glance-registry.conf paste_deploy flavor keystone 配置 /etc/glance/glance-api-paste.ini # openstack-config --set /etc/glance/glance-api-paste.ini filter:authtoken paste.filter_factory keystoneclient.middleware.auth_token:filter_factory # openstack-config --set /etc/glance/glance-api-paste.ini filter:authtoken admin_tenant_name service # openstack-config --set /etc/glance/glance-api-paste.ini filter:authtoken admin_user glance # openstack-config --set /etc/glance/glance-api-paste.ini filter:authtoken admin_password glance 配置 /etc/glance/glance-registry-paste.ini # openstack-config --set /etc/glance/glance-registry-paste.ini filter:authtoken paste.filter_factory keystoneclient.middleware.auth_token:filter_factory # openstack-config --set /etc/glance/glance-registry-paste.ini filter:authtoken admin_tenant_name service # openstack-config --set /etc/glance/glance-registry-paste.ini filter:authtoken admin_user glance # openstack-config --set /etc/glance/glance-registry-paste.ini filter:authtoken admin_password glance 启动 glance # service openstack-glance-registry restart # service openstack-glance-api restart 初始化 glance 数据 # glance-manage version_control 0 # glance-manage db_sync 成功后, 自动在 mysql 数据库下创建 glance.* 表 mysql> use glance; Database changed mysql> show tables; +------------------+ | Tables_in_glance | +------------------+ | image_locations | | image_members | | image_properties | | image_tags | | images | | migrate_version | | task_info | | tasks | +------------------+ 8 rows in set (0.00 sec) glance 客户端安装 # yum install -y python-glanceclient.noarch python-glanceclient-doc.noarch 管理 glance [root@hh-yun-compute-130025 ~(keystone_cookbook)]# cat keystonerc_cookbook export OS_USERNAME=admin export OS_TENANT_NAME=cookbook export OS_PASSWORD=test123 export OS_NO_CACHE=1 export OS_AUTH_URL=http://240.10.130.25:35357/v2.0/ export PS1='[\u@\h \W(keystone_cookbook)]\$ ' 镜像管理 获得 centos5.8_x86_64_2.9.4.qcow2, 并上传 [root@hh-yun-compute-130025 ~(keystone_cookbook)]# glance image-list +----+------+-------------+------------------+------+--------+ | ID | Name | Disk Format | Container Format | Size | Status | +----+------+-------------+------------------+------+--------+ +----+------+-------------+------------------+------+--------+ # glance image-create --name='centos5.8' --disk-format=qcow2 --container-format=bare --is-public=True --file=./centos5.8_x86_64_2.9.4.qcow2 +------------------+--------------------------------------+ | Property | Value | +------------------+--------------------------------------+ | checksum | 1b957548077dc554915e82424d4c089a | | container_format | bare | | created_at | 2014-10-01T10:00:17 | | deleted | False | | deleted_at | None | | disk_format | qcow2 | | id | 438d5c5a-f595-45e5-8236-801b9da8f9ab | | is_public | True | | min_disk | 0 | | min_ram | 0 | | name | centos5.8 | | owner | c74de0a2760343ac93f27095023be1cd | | protected | False | | size | 460841984 | | status | active | | updated_at | 2014-10-01T10:00:19 | | virtual_size | None | +------------------+--------------------------------------+ [root@hh-yun-compute-130025 ~(keystone_cookbook)]# glance image-list +--------------------------------------+-----------+-------------+------------------+-----------+--------+ | ID | Name | Disk Format | Container Format | Size | Status | +--------------------------------------+-----------+-------------+------------------+-----------+--------+ | 438d5c5a-f595-45e5-8236-801b9da8f9ab | centos5.8 | qcow2 | bare | 460841984 | active | +--------------------------------------+-----------+-------------+------------------+-----------+--------+ 利用下面命令能够把某些不公开的镜像分享至指定的 tenant 中 # glance [--can-share] member-create image-id tenant-id

优秀的个人博客,低调大师

openstack 管理二十六 - rpm 方式部署 openstack [mariadb]

目的 1. 配置 openstack 可用的 mariadb 2. mariadb 用于存储 openstack 中的所有信息 3. 暂不以高可用为目的 安装 yum install -y mariadb* 配置 必须要设定默认字符集为 utf8, 否则无法自动创建表 注 因测试环境, 暂无对 innodb 进行优化 /etc/my.cnf [mysql] default_character_set=utf8 [mysqld] datadir=/var/lib/mysql socket=/var/lib/mysql/mysql.sock skip-name-resolve max_connections = 1000 character_set_server = utf8 user=mysql symbolic-links=0 [mysqld_safe] log-error=/var/log/mysqld.log pid-file=/var/run/mysqld/mysqld.pid 启动 service mysqld restart 验证 mysql 命令能够直接登入 mysql> 终端则可 创建用户 创建 keystone 用户 create database keystone character set utf8; GRANT ALL PRIVILEGES ON keystone.* TO 'keystone'@'%' identified by 'test123'; GRANT ALL PRIVILEGES ON keystone.* TO 'keystone'@'localhost' identified by 'test123'; flush privileges; 创建 glance 用户 create database glance character set utf8; GRANT ALL PRIVILEGES ON glance.* TO 'glance'@'%' identified by 'glance'; GRANT ALL PRIVILEGES ON glance.* TO 'glance'@'localhost' identified by 'glance'; GRANT ALL PRIVILEGES ON glance.* TO 'glance'@'127.0.0.1' identified by 'glance'; flush privileges; 创建 cinder 用户 grant all on cinder.* to 'cinder'@'localhost' identified by 'cinder'; grant all on cinder.* to 'cinder'@'240.10.130.25' identified by 'cinder'; flush privileges; create databae cinder character set utf8; 创建 neutron 用户 create database neutron_ml2 character set utf8; GRANT ALL PRIVILEGES ON neutron_ml2.* TO 'neutron'@'%' identified by 'openstack'; GRANT ALL PRIVILEGES ON neutron_ml2.* TO 'neutron'@'localhost' identified by 'openstack'; GRANT ALL PRIVILEGES ON neutron_ml2.* TO 'neutron'@'127.0.0.1' identified by 'openstack'; flush privileges; 创建 nova 用户 CREATE DATABASE nova character set utf8; GRANT ALL ON nova.* TO 'nova'@'%' IDENTIFIED BY 'openstack'; GRANT ALL ON nova.* TO 'nova'@'localhost' IDENTIFIED BY 'openstack'; FLUSH PRIVILEGES;

资源下载

更多资源
Mario

Mario

马里奥是站在游戏界顶峰的超人气多面角色。马里奥靠吃蘑菇成长,特征是大鼻子、头戴帽子、身穿背带裤,还留着胡子。与他的双胞胎兄弟路易基一起,长年担任任天堂的招牌角色。

Nacos

Nacos

Nacos /nɑ:kəʊs/ 是 Dynamic Naming and Configuration Service 的首字母简称,一个易于构建 AI Agent 应用的动态服务发现、配置管理和AI智能体管理平台。Nacos 致力于帮助您发现、配置和管理微服务及AI智能体应用。Nacos 提供了一组简单易用的特性集,帮助您快速实现动态服务发现、服务配置、服务元数据、流量管理。Nacos 帮助您更敏捷和容易地构建、交付和管理微服务平台。

Rocky Linux

Rocky Linux

Rocky Linux(中文名:洛基)是由Gregory Kurtzer于2020年12月发起的企业级Linux发行版,作为CentOS稳定版停止维护后与RHEL(Red Hat Enterprise Linux)完全兼容的开源替代方案,由社区拥有并管理,支持x86_64、aarch64等架构。其通过重新编译RHEL源代码提供长期稳定性,采用模块化包装和SELinux安全架构,默认包含GNOME桌面环境及XFS文件系统,支持十年生命周期更新。

WebStorm

WebStorm

WebStorm 是jetbrains公司旗下一款JavaScript 开发工具。目前已经被广大中国JS开发者誉为“Web前端开发神器”、“最强大的HTML5编辑器”、“最智能的JavaScript IDE”等。与IntelliJ IDEA同源,继承了IntelliJ IDEA强大的JS部分的功能。

用户登录
用户注册