Debian 12 bookworm
Sponsored Link

OpenStack Zed : Nova 設定 #22023/06/27

 
OpenStack Compute Service(Nova)をインストールします。
当例では以下のような環境に Nova API サービスをインストールします。
        eth0|10.0.0.30 
+-----------+-----------+
|   [ dlp.srv.world ]   |
|     (Control Node)    |
|                       |
|  MariaDB    RabbitMQ  |
|  Memcached  Nginx     |
|  Keystone   httpd     |
|  Glance     Nova API  |
+-----------------------+

[1] Nova をインストールします。インストール中の問には全て [No] で OK です。
root@dlp ~(keystone)#
apt -y install nova-api nova-conductor nova-scheduler nova-novncproxy placement-api python3-novaclient
[2] Nova の基本設定です。
root@dlp ~(keystone)#
mv /etc/nova/nova.conf /etc/nova/nova.conf.org

root@dlp ~(keystone)#
vi /etc/nova/nova.conf
# 新規作成
[DEFAULT]
osapi_compute_listen = 127.0.0.1
osapi_compute_listen_port = 8774
metadata_listen = 127.0.0.1
metadata_listen_port = 8775
state_path = /var/lib/nova
enabled_apis = osapi_compute,metadata
log_dir = /var/log/nova
# RabbitMQ サーバー接続情報
transport_url = rabbit://openstack:password@dlp.srv.world

[api]
auth_strategy = keystone

[vnc]
enabled = True
novncproxy_host = 127.0.0.1
novncproxy_port = 6080
novncproxy_base_url = https://dlp.srv.world:6080/vnc_auto.html

# Glance サーバー接続情報
[glance]
api_servers = https://dlp.srv.world:9292

[oslo_concurrency]
lock_path = $state_path/tmp

# MariaDB サーバー接続情報
[api_database]
connection = mysql+pymysql://nova:password@dlp.srv.world/nova_api

[database]
connection = mysql+pymysql://nova:password@dlp.srv.world/nova

# Keystone サーバー接続情報
[keystone_authtoken]
www_authenticate_uri = https://dlp.srv.world:5000
auth_url = https://dlp.srv.world:5000
memcached_servers = dlp.srv.world:11211
auth_type = password
project_domain_name = default
user_domain_name = default
project_name = service
username = nova
password = servicepassword
# Apache2 Keystone で自己署名の証明書を使用の場合は [true]
insecure = false

[placement]
auth_url = https://dlp.srv.world:5000
os_region_name = RegionOne
auth_type = password
project_domain_name = default
user_domain_name = default
project_name = service
username = placement
password = servicepassword
# Apache2 Keystone で自己署名の証明書を使用の場合は [true]
insecure = false

[wsgi]
api_paste_config = /etc/nova/api-paste.ini

[oslo_policy]
enforce_new_defaults = true

root@dlp ~(keystone)#
chmod 640 /etc/nova/nova.conf

root@dlp ~(keystone)#
chgrp nova /etc/nova/nova.conf
root@dlp ~(keystone)#
vi /etc/default/nova-consoleproxy
# 6行目 : 変更

NOVA_CONSOLE_PROXY_TYPE=
novnc
root@dlp ~(keystone)#
mv /etc/placement/placement.conf /etc/placement/placement.conf.org

root@dlp ~(keystone)#
vi /etc/placement/placement.conf
# 新規作成
[DEFAULT]
debug = false

[api]
auth_strategy = keystone

[keystone_authtoken]
www_authenticate_uri = https://dlp.srv.world:5000
auth_url = https://dlp.srv.world:5000
memcached_servers = dlp.srv.world:11211
auth_type = password
project_domain_name = default
user_domain_name = default
project_name = service
username = placement
password = servicepassword
# Apache2 Keystone で自己署名の証明書を使用の場合は [true]
insecure = false

[placement_database]
connection = mysql+pymysql://placement:password@dlp.srv.world/placement

root@dlp ~(keystone)#
vi /etc/apache2/sites-available/placement-api.conf
# 新規作成

Listen 127.0.0.1:8778

<VirtualHost *:8778>
    WSGIScriptAlias / /usr/bin/placement-api
    WSGIDaemonProcess placement-api processes=5 threads=1 user=placement group=placement display-name=%{GROUP}
    WSGIProcessGroup placement-api
    WSGIApplicationGroup %{GLOBAL}
    WSGIPassAuthorization On
    LimitRequestBody 114688

    <IfVersion >= 2.4>
      ErrorLogFormat "%{cu}t %M"
    </IfVersion>

    ErrorLog /var/log/apache2/placement_api_error.log
    CustomLog /var/log/apache2/placement_api_access.log combined

    <Directory /usr/bin>
        Require all granted
    </Directory>
</VirtualHost>

Alias /placement /usr/bin/placement-api
<Location /placement>
  SetHandler wsgi-script
  Options +ExecCGI

  WSGIProcessGroup placement-api
  WSGIApplicationGroup %{GLOBAL}
  WSGIPassAuthorization On
</Location>

root@dlp ~(keystone)#
chmod 640 /etc/placement/placement.conf

root@dlp ~(keystone)#
chgrp placement /etc/placement/placement.conf
root@dlp ~(keystone)#
vi /etc/init.d/nova-api
# 95行目 : 追記

UWSGI_BIND_IP="
127.0.0.1
"
root@dlp ~(keystone)#
vi /etc/init.d/nova-api-metadata
# 95行目 : 追記

UWSGI_BIND_IP="
127.0.0.1
"
root@dlp ~(keystone)#
a2ensite placement-api

Enabling site placement-api.
To activate the new configuration, you need to run:
  systemctl reload apache2

root@dlp ~(keystone)#
systemctl disable --now placement-api

root@dlp ~(keystone)#
systemctl reload apache2

[3] Nginx にプロキシの設定をします。
root@dlp ~(keystone)#
vi /etc/nginx/nginx.conf
# [stream] セクション内に追記

stream {
    upstream glance-api {
        server 127.0.0.1:9292;
    }
    server {
        listen 10.0.0.30:9292 ssl;
        proxy_pass glance-api;
    }
    upstream nova-api {
        server 127.0.0.1:8774;
    }
    server {
        listen 10.0.0.30:8774 ssl;
        proxy_pass nova-api;
    }
    upstream nova-metadata-api {
        server 127.0.0.1:8775;
    }
    server {
        listen 10.0.0.30:8775 ssl;
        proxy_pass nova-metadata-api;
    }
    upstream placement-api {
        server 127.0.0.1:8778;
    }
    server {
        listen 10.0.0.30:8778 ssl;
        proxy_pass placement-api;
    }
    upstream novncproxy {
        server 127.0.0.1:6080;
    }
    server {
        listen 10.0.0.30:6080 ssl;
        proxy_pass novncproxy;
    }
    ssl_certificate "/etc/letsencrypt/live/dlp.srv.world/fullchain.pem";
    ssl_certificate_key "/etc/letsencrypt/live/dlp.srv.world/privkey.pem";
}
[4] データベースにデータを追加して Nova をサービス起動します。
なお、データ投入の際に表示される deprecated ~ な Warning メッセージは気にする必要はありません。
root@dlp ~(keystone)#
su -s /bin/bash placement -c "placement-manage db sync"
root@dlp ~(keystone)#
su -s /bin/bash nova -c "nova-manage api_db sync"
root@dlp ~(keystone)#
su -s /bin/bash nova -c "nova-manage cell_v2 map_cell0"
root@dlp ~(keystone)#
su -s /bin/bash nova -c "nova-manage db sync"
root@dlp ~(keystone)#
su -s /bin/bash nova -c "nova-manage cell_v2 create_cell --name cell1"
root@dlp ~(keystone)#
systemctl stop nova-api nova-api-metadata nova-conductor nova-scheduler nova-novncproxy

root@dlp ~(keystone)#
systemctl restart nginx

root@dlp ~(keystone)#
systemctl enable --now nova-api nova-api-metadata nova-conductor nova-scheduler nova-novncproxy

# 状態確認

root@dlp ~(keystone)#
openstack compute service list

+--------------------------------------+----------------+---------------+----------+---------+-------+----------------------------+
| ID                                   | Binary         | Host          | Zone     | Status  | State | Updated At                 |
+--------------------------------------+----------------+---------------+----------+---------+-------+----------------------------+
| 763baff5-8b45-464c-a911-f2ef9d28f9c1 | nova-scheduler | dlp.srv.world | internal | enabled | up    | 2023-06-23T03:44:29.000000 |
| 025da87c-7c9d-4612-8828-1aba0438cc5f | nova-conductor | dlp.srv.world | internal | enabled | up    | 2023-06-23T03:44:29.000000 |
+--------------------------------------+----------------+---------------+----------+---------+-------+----------------------------+
関連コンテンツ