CentOS Stream 8
Sponsored Link

OpenStack Victoria : Create LoadBalancer Image
2021/03/26
 
Install and Configure OpenStack Load Balancing as a Service (Octavia).
This example is based on the environment like follows.
------------+---------------------------+---------------------------+------------
            |                           |                           |
        eth0|10.0.0.30              eth0|10.0.0.50              eth0|10.0.0.51
+-----------+-----------+   +-----------+-----------+   +-----------+-----------+
|    [ Control Node ]   |   |    [ Network Node ]   |   |    [ Compute Node ]   |
|                       |   |                       |   |                       |
|  MariaDB    RabbitMQ  |   |      Open vSwitch     |   |        Libvirt        |
|  Memcached  httpd     |   |     Neutron Server    |   |     Nova Compute      |
|  Keystone   Glance    |   |       OVN-Northd      |   |      Open vSwitch     |
|  Nova API             |   |     Cinder Volume     |   |   OVN Metadata Agent  |
|  Cinder API           |   |      iSCSI Target     |   |     OVN-Controller    |
|                       |   |    Octavia Services   |   |                       |
+-----------------------+   +-----------------------+   +-----------------------+

[1] Create a LoadBalancer Image and add it to Glance.
It's OK to work on any node. (example below is on Control Node)
# install from Victoria, EPEL, PowerTools

[root@dlp ~(keystone)]#
dnf --enablerepo=centos-openstack-victoria,powertools,epel -y install openstack-octavia-diskimage-create debootstrap python3-octaviaclient
# create an instance image

[root@dlp ~(keystone)]#
octavia-diskimage-create.sh
# add to Glance

[root@dlp ~(keystone)]#
openstack image create "Amphora" --tag "Amphora" --file amphora-x64-haproxy.qcow2 --disk-format qcow2 --container-format bare --private --project service
# add [flavor] for Amphora instance

[root@dlp ~(keystone)]#
openstack flavor create --id 100 --vcpus 1 --ram 1024 --disk 5 m1.octavia --private --project service
# add a security group for Amphora instance

[root@dlp ~(keystone)]#
openstack security group create lb-mgmt-sec-group --project service
# allow required ports for security group

[root@dlp ~(keystone)]#
openstack security group rule create --protocol icmp --ingress lb-mgmt-sec-group

[root@dlp ~(keystone)]#
openstack security group rule create --protocol tcp --dst-port 22:22 lb-mgmt-sec-group

[root@dlp ~(keystone)]#
openstack security group rule create --protocol tcp --dst-port 80:80 lb-mgmt-sec-group

[root@dlp ~(keystone)]#
openstack security group rule create --protocol tcp --dst-port 443:443 lb-mgmt-sec-group

[root@dlp ~(keystone)]#
openstack security group rule create --protocol tcp --dst-port 9443:9443 lb-mgmt-sec-group

[2] Configure Octavia service to set instance ID or security group ID.
[root@network ~]#
openstack image list

+--------------------------------------+-----------------+--------+
| ID                                   | Name            | Status |
+--------------------------------------+-----------------+--------+
| cb84e7e3-144d-45c0-b9cc-8f6feceddfb9 | Amphora         | active |
| 4d7293af-be5b-471b-9507-2a32f1955b11 | CentOS-Stream-8 | active |
+--------------------------------------+-----------------+--------+

[root@network ~]#
openstack flavor list --all

+-----+------------+------+------+-----------+-------+-----------+
| ID  | Name       |  RAM | Disk | Ephemeral | VCPUs | Is Public |
+-----+------------+------+------+-----------+-------+-----------+
| 0   | m1.small   | 2048 |   10 |         0 |     1 | True      |
| 100 | m1.octavia | 1024 |    5 |         0 |     1 | False     |
+-----+------------+------+------+-----------+-------+-----------+

[root@network ~]#
openstack network list

+--------------------------------------+---------+--------------------------------------+
| ID                                   | Name    | Subnets                              |
+--------------------------------------+---------+--------------------------------------+
| 9f53c3b1-ec6b-499d-854a-588d3b0b96d6 | private | 94afb0cc-1d58-4615-8fef-8852271bfc16 |
| ea9725cf-a8bc-4eb5-a374-7d7d0e11453c | public  | 63c29d7b-e870-477d-819b-e5dfe41af1d0 |
+--------------------------------------+---------+--------------------------------------+

[root@network ~]#
openstack security group list

+--------------------------------------+-------------------+------------------------+----------------------------------+------+
| ID                                   | Name              | Description            | Project                          | Tags |
+--------------------------------------+-------------------+------------------------+----------------------------------+------+
| 44e8d726-301b-4805-a473-501be9383b21 | default           | Default security group | b9bf51c6436a4c5aa7a2df05688afb49 | []   |
| 85a866df-9932-4576-96fc-3657eef2183e | lb-mgmt-sec-group | lb-mgmt-sec-group      | affa3a6446154e37adfd233c437bacc1 | []   |
| df46c2cb-fb6c-4579-9a78-e274c755b307 | secgroup01        | secgroup01             | f1f04d774d2141fb9acabd28d0e00c33 | []   |
+--------------------------------------+-------------------+------------------------+----------------------------------+------+

[root@network ~]#
vi /etc/octavia/octavia.conf
# add into [controller_worker] section

[controller_worker]
client_ca = /etc/octavia/certs/client_ca.cert.pem
amp_image_tag = Amphora
# specify [flavor] ID for Amphora instance
amp_flavor_id = 100
# specify security group ID Amphora instance
amp_secgroup_list = 85a866df-9932-4576-96fc-3657eef2183e
# specify network ID to boot Amphora instance (example below specifies public network [public])
amp_boot_network_list = ea9725cf-a8bc-4eb5-a374-7d7d0e11453c
network_driver = allowed_address_pairs_driver
compute_driver = compute_nova_driver
amphora_driver = amphora_haproxy_rest_driver 

[root@network ~]#
systemctl restart octavia-api \
octavia-health-manager \
octavia-housekeeping \
octavia-worker

Matched Content