OpenStack Victoria : Create LoadBalancer Image2020/11/26 |
Install and Configure OpenStack Load Balancing as a Service (Octavia).
This example is based on the environment like follows.
Configured Networking is Geneve like here on this environment. ------------+---------------------------+---------------------------+------------ | | | eth0|10.0.0.30 eth0|10.0.0.50 eth0|10.0.0.51 +-----------+-----------+ +-----------+-----------+ +-----------+-----------+ | [ Control Node ] | | [ Network Node ] | | [ Compute Node ] | | | | | | | | MariaDB RabbitMQ | | Open vSwitch | | Libvirt | | Memcached httpd | | Neutron Server | | Nova Compute | | Keystone Glance | | OVN-Northd | | Open vSwitch | | Nova API | | Octavia Services | | OVN Metadata Agent | | | | | | OVN-Controller | +-----------------------+ +-----------------------+ +-----------------------+ |
[1] | Create a LoadBalancer Image and add it to Glance. It's OK to work on any node. (example below is on Control Node) |
[root@dlp ~(keystone)]#
dnf --enablerepo=centos-openstack-victoria,powertools,epel -y install openstack-octavia-diskimage-create debootstrap python3-octaviaclient # create an instance image [root@dlp ~(keystone)]# octavia-diskimage-create.sh
# add to Glance [root@dlp ~(keystone)]# openstack image create "Amphora" --tag "Amphora" --file amphora-x64-haproxy.qcow2 --disk-format qcow2 --container-format bare --private --project service
# add [flavor] for Amphora instance [root@dlp ~(keystone)]# openstack flavor create --id 100 --vcpus 1 --ram 1024 --disk 5 m1.octavia --private --project service
# add a security group for Amphora instance [root@dlp ~(keystone)]# openstack security group create lb-mgmt-sec-group --project service
# allow required ports for security group [root@dlp ~(keystone)]# openstack security group rule create --protocol icmp --ingress lb-mgmt-sec-group [root@dlp ~(keystone)]# openstack security group rule create --protocol tcp --dst-port 22:22 lb-mgmt-sec-group [root@dlp ~(keystone)]# openstack security group rule create --protocol tcp --dst-port 80:80 lb-mgmt-sec-group [root@dlp ~(keystone)]# openstack security group rule create --protocol tcp --dst-port 443:443 lb-mgmt-sec-group [root@dlp ~(keystone)]# openstack security group rule create --protocol tcp --dst-port 9443:9443 lb-mgmt-sec-group |
[2] | Configure Octavia service to set instance ID or security group ID. |
[root@network ~]# openstack image list +--------------------------------------+---------+--------+ | ID | Name | Status | +--------------------------------------+---------+--------+ | dd333ba2-caf5-46c1-9e47-c913eb08b406 | Amphora | active | | 214323d8-21a4-46e7-8c85-1f119fc6cf60 | CentOS8 | active | +--------------------------------------+---------+--------+[root@network ~]# openstack flavor list --all +-----+------------+------+------+-----------+-------+-----------+ | ID | Name | RAM | Disk | Ephemeral | VCPUs | Is Public | +-----+------------+------+------+-----------+-------+-----------+ | 0 | m1.small | 2048 | 10 | 0 | 1 | True | | 100 | m1.octavia | 1024 | 5 | 0 | 1 | False | +-----+------------+------+------+-----------+-------+-----------+[root@network ~]# openstack network list +--------------------------------------+---------+--------------------------------------+ | ID | Name | Subnets | +--------------------------------------+---------+--------------------------------------+ | 431d7888-dcde-40dc-9727-ecfa65a25366 | private | db0a36a6-5be6-4609-951e-27b4d3f9f5b9 | | dae78c9d-c885-4949-a05d-8e456f9ba1b9 | public | e09e5481-afaf-484e-9c7a-b24a3545d092 | +--------------------------------------+---------+--------------------------------------+[root@network ~]# openstack security group list +--------------------------------------+-------------------+------------------------+----------------------------------+------+ | ID | Name | Description | Project | Tags | +--------------------------------------+-------------------+------------------------+----------------------------------+------+ | 35c642b6-14e9-470e-90c5-63061265b636 | lb-mgmt-sec-group | lb-mgmt-sec-group | 78a30ddac623441396857b102e8b6a13 | [] | | 58f7b204-841e-4c8e-88dd-e88710bdfb8d | secgroup01 | secgroup01 | 36a0b2c4640c4d1e98c9e758c61e1bf8 | [] | | 635110a1-e0ab-4f98-9fb4-83fa7340e8a3 | default | Default security group | f631c12338934447bb3172f3378d2b9a | [] | +--------------------------------------+-------------------+------------------------+----------------------------------+------+
[root@network ~]#
vi /etc/octavia/octavia.conf # add into [controller_worker] section
[controller_worker]
client_ca = /etc/octavia/certs/client_ca.cert.pem
amp_image_tag = Amphora
# specify [flavor] ID for Amphora instance
amp_flavor_id = 100
# specify security group ID Amphora instance
amp_secgroup_list = 35c642b6-14e9-470e-90c5-63061265b636
# specify network ID to boot Amphora instance (example below specifies public network [public])
amp_boot_network_list = dae78c9d-c885-4949-a05d-8e456f9ba1b9
network_driver = allowed_address_pairs_driver
compute_driver = compute_nova_driver
amphora_driver = amphora_haproxy_rest_driver
[root@network ~]# |
Sponsored Link |
|