diff --git a/source/openstack_block_storage.rst b/source/openstack_block_storage.rst index 756f0e96..296b6550 100644 --- a/source/openstack_block_storage.rst +++ b/source/openstack_block_storage.rst @@ -1,17 +1,12 @@ -<<<<<<< HEAD -Block Storage -############################################################ -======= .. _openstack_block_storage: ->>>>>>> staging Block Storage ######################## -The OpenStack Block Storage service (cinder) adds persistent storage to +The OpenStack* Block Storage service (cinder) adds persistent storage to a virtual machine. Block Storage provides an infrastructure for managing volumes, and interacts with OpenStack Compute to provide volumes for -instances. The service also enables management of volume snapshots, and +instances. The service also enables management of volume snapshots and volume types. Install and configure controller node @@ -22,28 +17,14 @@ Storage service, code-named cinder, on the controller node. This service requires at least one additional storage node that provides volumes to instances. -<<<<<<< HEAD -**Create a database:** - -#. Use the database access client to connect to the database server as - the root user:: -======= Prerequisites: -------------- Before you install and configure the Block Storage service, you ->>>>>>> staging +must create a database, service credentials, and API endpoints. #. To create the database, complete these steps: -<<<<<<< HEAD -#. Create the cinder database:: - - CREATE DATABASE cinder; - -#. Grant proper access to the cinder database. Replace ``CINDER_DBPASS`` - with a suitable password:: -======= * Use the database access client to connect to the database server as the ``root`` user:: @@ -52,7 +33,6 @@ Before you install and configure the Block Storage service, you * Create the ``cinder`` database:: CREATE DATABASE cinder; ->>>>>>> staging * Grant proper access to the ``cinder`` database:: @@ -63,121 +43,15 @@ Before you install and configure the Block Storage service, you Replace ``CINDER_DBPASS`` with a suitable password. -<<<<<<< HEAD -#. Now source the admin credentials to gain access to admin-only CLI - commands:: -======= * Exit the database access client. #. Source the ``admin`` credentials to gain access to admin-only CLI commands:: ->>>>>>> staging $ source admin-openrc.sh #. To create the service credentials, complete these steps: -<<<<<<< HEAD - * Create a cinder user:: - - $ openstack user create --password-prompt cinder - User Password: - Repeat User Password: - +----------+----------------------------------+ - | Field | Value | - +----------+----------------------------------+ - | email | None | - | enabled | True | - | id | 881ab2de4f7941e79504a759a83308be | - | name | cinder | - | username | cinder | - +----------+----------------------------------+ - - * Add the admin role to the cinder user:: - - $ openstack role add --project service --user cinder admin - +-------+----------------------------------+ - | Field | Value | - +-------+----------------------------------+ - | id | cd2cb9a39e874ea69e5d4b896eb16128 | - | name | admin | - +-------+----------------------------------+ - - * Now create the cinder service entities:: - - $ openstack service create --name cinder \ - --description "OpenStack Block Storage" volume - | Field | Value | - +-------------+----------------------------------+ - | description | OpenStack Block Storage | - | enabled | True | - | id | 1e494c3e22a24baaafcaf777d4d467eb | - | name | cinder | - | type | volume | - +-------------+----------------------------------+ - $ openstack service create --name cinderv2 - --description "OpenStack Block Storage" volumev2 - +-------------+----------------------------------+ - | Field | Value | - +-------------+----------------------------------+ - | description | OpenStack Block Storage | - | enabled | True | - | id | 16e038e449c94b40868277f1d801edb5 | - | name | cinderv2 | - | type | volumev2 | - +-------------+----------------------------------+ - -**Create service endpoints:** - -The last prerequisite is to create the Block Storage service API endpoints:: - - $ openstack endpoint create \ - --publicurl http://controller:8776/v2/%\(tenant_id\)s \ - --internalurl http://controller:8776/v2/%\(tenant_id\)s \ - --adminurl http://controller:8776/v2/%\(tenant_id\)s \ - --region RegionOne \ - volume - +--------------+-----------------------------------------+ - |Field | Value + - |--------------+-----------------------------------------+ - | adminurl | http://controller:8776/v2/%(tenant_id)s | - | id | d1b7291a2d794e26963b322c7f2a55a4 | - | internalurl | http://controller:8776/v2/%(tenant_id)s | - | publicurl | http://controller:8776/v2/%(tenant_id)s | - | region | RegionOne | - | service_id | 1e494c3e22a24baaafcaf777d4d467eb | - | service_name | cinder | - | service_type | volume | - +--------------+-----------------------------------------+ - $ openstack endpoint create \ - --publicurl http://controller:8776/v2/%\(tenant_id\)s \ - --internalurl http://controller:8776/v2/%\(tenant_id\)s \ - --adminurl http://controller:8776/v2/%\(tenant_id\)s \ - --region RegionOne \ - volumev2 - +--------------+-----------------------------------------+ - | Field | Value | - +--------------+-----------------------------------------+ - | adminurl | http://controller:8776/v2/%(tenant_id)s | - | id | 097b4a6fc8ba44b4b10d4822d2d9e076 | - | internalurl | http://controller:8776/v2/%(tenant_id)s | - | publicurl | http://controller:8776/v2/%(tenant_id)s | - | region | RegionOne | - | service_id | 16e038e449c94b40868277f1d801edb5 | - | service_name | cinderv2 | - | service_type | volumev2 | - +--------------+-----------------------------------------+ - -Installing and configuring Block Storage controller components -~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - -Once your prerequisites are finished, you can install and configure -Block Storage controller components: - -#. Install OpenStack Block Storage Controller bundle:: - - # clr_bundle_add openstack-block-storage-controller -======= * Create a ``cinder`` user:: $ openstack user create --domain default --password-prompt cinder @@ -222,9 +96,9 @@ Block Storage controller components: | type | volumev2 | +-------------+----------------------------------+ - .. note:: + .. note:: - The Block Storage services requires two service entities. + The Block Storage services requires two service entities. #. Create the Block Storage service API endpoints:: @@ -335,28 +209,17 @@ Install and configure components #. Install OpenStack Block Storage Controller bundle:: # swupd bundle-add openstack-block-storage-controller - # swupd verify --fix ->>>>>>> staging #. Custom configurations will be located at ``/etc/cinder``. * Create ``/etc/cinder`` directory:: -<<<<<<< HEAD - - mkdir /etc/cinder -======= - mkdir /etc/cinder ->>>>>>> staging + # mkdir /etc/cinder * Create empty cinder configuration file in ``/etc/cinder/cinder.conf``:: -<<<<<<< HEAD - touch /etc/cinder/cinder.conf -======= - touch /etc/cinder/cinder.conf ->>>>>>> staging + # touch /etc/cinder/cinder.conf #. Edit the ``/etc/cinder/cinder.conf`` file and complete the following actions: @@ -364,19 +227,11 @@ Install and configure components * In the ``[database]`` section, configure database access. Replace ``CINDER_DBPASS`` with the password you chose for the database:: -<<<<<<< HEAD - - [database] - ... - connection=mysql://cinder:CINDER_DBPASS@controller/cinder - -======= [database] ... connection=mysql://cinder:CINDER_DBPASS@controller/cinder ->>>>>>> staging * In the ``[DEFAULT]`` and ``[oslo_messaging_rabbit]`` section, configure RabbitMQ message queue access. Replace ``RABBIT_PASS`` with the password you chose for the account in @@ -386,12 +241,6 @@ Install and configure components ... rpc_backend = rabbit -<<<<<<< HEAD - * In the ``[DEFAULT]`` and ``[keystone_authtoken]`` sections, - configure Identity service access. Replace ``CINDER_PASS`` with the - password you chose for the cinder user in the Identity - service:: -======= [oslo_messaging_rabbit] ... rabbit_host = controller @@ -401,26 +250,11 @@ Install and configure components * In the ``[DEFAULT]`` and ``[keystone_authtoken]`` sections, configure Identity service access. Replace ``CINDER_PASS`` with the password you chose for the ``cinder`` user in the Identity service.:: ->>>>>>> staging [DEFAULT] ... auth_strategy = keystone -<<<<<<< HEAD - * In the ``[DEFAULT]`` section, configure the ``my_ip`` option to - use the management interface IP address of the controller node:: - - [DEFAULT] ... my_ip = 10.0.0.11 - -#. Let ``systemd`` set the correct permissions for files in ``/etc/cinder``:: - - # systemctl restart update-triggers.target - -#. Populate the Block Storage database:: - - # su -s /bin/sh -c "cinder-manage db sync" cinder -======= [keystone_authtoken] ... auth_uri = http://controller:5000 @@ -448,19 +282,14 @@ Configure Compute to use Block Storage * Edit the ``/etc/nova/nova.conf`` file and add the following to it:: ->>>>>>> staging [cinder] os_region_name = RegionOne -<<<<<<< HEAD -To finalize installation, enable and start the Block Storage services:: -======= Finalize installation --------------------- #. Restart the Compute API service:: ->>>>>>> staging # systemctl restart uwsgi@nova-api.service @@ -473,9 +302,6 @@ Finalize installation Install and configure a storage node ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -<<<<<<< HEAD -Install the packages:: -======= This section describes how to install and configure storage nodes for the Block Storage service. For simplicity, this configuration references one storage node with an empty local block storage device. @@ -486,41 +312,29 @@ The service provisions logical volumes on this device using the LVM driver and provides them to instances via iSCSI transport. You can follow these instructions with minor modifications to horizontally scale your environment with additional storage nodes. ->>>>>>> staging Prerequisites ------------- -#. Install the openstack block storage bundle:: +#. Install the Openstack Block Storage bundle:: # swupd bundle-add openstack-block-storage - # swupd verify --fix #. Create the LVM physical volume: ``/dev/sdb1`` If your system uses a different device name, adjust these steps accordingly:: -<<<<<<< HEAD -======= # pvcreate /dev/sdb1 Physical volume "/dev/sdb1" successfully created ->>>>>>> staging #. Create the LVM volume group ``cinder-volumes``:: -<<<<<<< HEAD -#. Create the LVM volume group ``cinder-volumes``:: - - # vgcreate cinder-volumes /dev/sdb1 - Volume group "cinder-volumes" successfully created -======= # vgcreate cinder-volumes /dev/sdb1 Volume group "cinder-volumes" successfully created ->>>>>>> staging The Block Storage service creates logical volumes in this volume group. - Only instances can access Block Storage volumes. However, the +#. Only instances can access Block Storage volumes. However, the underlying operating system manages the devices associated with the volumes. By default, the LVM volume scanning tool scans the ``/dev`` directory for block storage devices that contain volumes. If projects @@ -528,20 +342,15 @@ Prerequisites attempts to cache them which can cause a variety of problems with both the underlying operating system and project volumes. You must reconfigure LVM to scan only the devices that contain the - ``cinder-volume`` volume group. - -<<<<<<< HEAD -#. Edit the ``/etc/lvm/lvm.conf`` file + ``cinder-volume`` volume group. Edit the ``/etc/lvm/lvm.conf`` file and complete the following action: -======= ->>>>>>> staging * In the ``devices`` section, add a filter that accepts the ``/dev/sdb`` device and rejects all other devices:: devices { + ... filter = [ "a/sdb/", "r/.*/"] - } Install and configure components -------------------------------- @@ -558,11 +367,6 @@ Install and configure components connection = mysql://cinder:CINDER_DBPASS@controller/cinder * In the ``[DEFAULT]`` and ``[oslo_messaging_rabbit]`` sections, -<<<<<<< HEAD - configure *RabbitMQ* message queue access. Replace ``RABBIT_PASS`` - with the password you chose for the openstack account in - *RabbitMQ*:: -======= configure ``RabbitMQ`` message queue access. Replace ``RABBIT_PASS`` with the password you chose for the openstack account in ``RabbitMQ``:: @@ -570,7 +374,6 @@ Install and configure components [DEFAULT] ... rpc_backend = rabbit ->>>>>>> staging [oslo_messaging_rabbit] ... @@ -581,13 +384,10 @@ Install and configure components * In the ``[DEFAULT]`` and ``[keystone_authtoken]`` sections, configure Identity service access. Replace ``CINDER_PASS`` with the password you chose for the cinder user in the Identity service:: -<<<<<<< HEAD -======= [DEFAULT] ... auth_strategy = keystone ->>>>>>> staging [keystone_authtoken] ... @@ -601,12 +401,6 @@ Install and configure components password = CINDER_PASS * In the ``[DEFAULT]`` section, configure the ``my_ip`` option. -<<<<<<< HEAD - Replace *MANAGEMENT_INTERFACE_IP_ADDRESS* with the IP address - of the management network interface on your storage node, - typically 10.0.0.41 for the first node in the example - architecture:: -======= Replace ``MANAGEMENT_INTERFACE_IP_ADDRESS`` with the IP address of the management network interface on your storage node, typically 10.0.0.41 for the first node in the example @@ -615,17 +409,11 @@ Install and configure components [DEFAULT] ... my_ip = MANAGEMENT_INTERFACE_IP_ADDRESS ->>>>>>> staging * In the ``[lvm]`` section, configure the LVM back end with the LVM driver, ``cinder-volumes`` volume group, iSCSI protocol, and appropriate iSCSI service:: -<<<<<<< HEAD - * In the ``[lvm]`` section, configure the LVM back end with the LVM - driver, ``cinder-volumes`` volume group, iSCSI protocol, and - appropriate iSCSI service:: -======= [lvm] ... volume_driver = cinder.volume.drivers.lvm.LVMVolumeDriver @@ -634,22 +422,11 @@ Install and configure components iscsi_helper = tgtadm * In the ``[DEFAULT]`` section, enable the LVM back end:: ->>>>>>> staging [DEFAULT] ... enabled_backends = lvm -<<<<<<< HEAD - * In the ``[DEFAULT]`` section, enable the LVM back end:: - - [DEFAULT] - ... - enabled_backends = lvm - - * In the ``[DEFAULT]`` section, configure the location of the Image - service:: -======= * In the ``[DEFAULT]`` section, configure the location of the Image service:: @@ -657,24 +434,13 @@ Install and configure components ... glance_host = controller -#. Let systemd set the correct permissions for files in ``/etc/cinder``:: +#. Ensure files have proper ownership by running the following command:: # systemctl restart update-triggers.target ->>>>>>> staging Finalize installation --------------------- -<<<<<<< HEAD -#. Let systemd set the correct permissions for files in ``/etc/cinder``:: - - # systemctl restart update-triggers.target - -Finalizing installation -~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - -Restart the Block Storage volume service including its dependencies:: -======= #. Start the Block Storage volume service including its dependencies and configure them to start when the system boots:: @@ -686,7 +452,6 @@ Configuring a compute node to use Block Storage #. Perform the following steps to enable a compute node to work with block storage:: ->>>>>>> staging # systemctl enable iscsid # systemctl start iscsi-gen-initiatorname iscsid @@ -695,15 +460,10 @@ Verify operation ~~~~~~~~~~~~~~~~ Verify operation of the Block Storage service. -<<<<<<< HEAD -Perform the following steps to enable a compute node to work with block -storage:: -======= #. Source the ``admin`` credentials to gain access to admin-only CLI commands:: $ source admin-openrc.sh ->>>>>>> staging #. List service components to verify successful launch of each process:: diff --git a/source/openstack_compute.rst b/source/openstack_compute.rst index 8f8e5d68..18414c39 100644 --- a/source/openstack_compute.rst +++ b/source/openstack_compute.rst @@ -142,7 +142,6 @@ To install and configure the Compute controller components: #. Install OpenStack Compute Controller bundle:: # swupd bundle-add openstack-compute-controller - # swupd verify --fix #. Custom configurations will be located at ``/etc/nova``. @@ -525,4 +524,4 @@ Verify operation of the Compute service. | 38047887-61a7-41ea-9b49-27987d5e8bb9 | cirros | ACTIVE | | +--------------------------------------+--------+--------+--------+ -Next topic: :ref:`openstack_block_storage`. \ No newline at end of file +Next topic: :ref:`openstack_block_storage`. diff --git a/source/openstack_dashboard.rst b/source/openstack_dashboard.rst index f84989b2..a77d3c28 100644 --- a/source/openstack_dashboard.rst +++ b/source/openstack_dashboard.rst @@ -1,27 +1,14 @@ -<<<<<<< HEAD -Dashboard -############################################################ - -The OpenStack Dashboard, also known as Horizon, is a web-based interface -for cloud administrators to manage various OpenStack resources and -services. This dashboard enables interaction with the OpenStack Compute -cloud controller via OpenStack APIs. - -Installation and configuration ------------------------------- -======= .. _openstack_dashboard: Dashboard #################### -The OpenStack Dashboard, also known as Horizon, is a web-based interface +The OpenStack* Dashboard, also known as Horizon, is a web-based interface for cloud administrators and users to manage various OpenStack resources and services. The Dashboard enables web-based interactions with the OpenStack Compute cloud controller through the OpenStack APIs. ->>>>>>> staging Installation and configuration ------------------------------ @@ -36,16 +23,7 @@ To get started with OpenStack Dashboard services: #. Install the OpenStack Dashboard bundle:: -<<<<<<< HEAD - # clr_bundle_add openstack-dashboard - -#. Enable and start the memcached service and the httpd server:: - - # systemctl enable httpd memcached - # systemctl restart httpd memcached -======= # swupd bundle-add openstack-dashboard - # swupd verify --fix #. Enable and start the dashboard socket and the Nginx server:: @@ -53,4 +31,3 @@ To get started with OpenStack Dashboard services: # systemctl restart nginx uwsgi@horizon.socket Next topic: :ref:`openstack_networking`. ->>>>>>> staging diff --git a/source/openstack_identity.rst b/source/openstack_identity.rst index 7ef71f0e..934d7999 100644 --- a/source/openstack_identity.rst +++ b/source/openstack_identity.rst @@ -61,7 +61,6 @@ Install and configure components #. Run the following command to install the packages.:: # swupd bundle-add openstack-identity - # swupd verify --fix #. Custom configurations will be located at ``/etc/keystone/``. @@ -150,7 +149,6 @@ environment variables to reduce command length. #. Install the OpenStack Python clients bundle:: # swupd bundle-add openstack-python-clients - # swupd verify --fix Create the service entity and API endpoints @@ -415,4 +413,4 @@ services. | user_id | 7004dfa0dda84d63aef81cf7f100af01 | +------------+----------------------------------+ -Next topic: :ref:`openstack_identity-openrc`. \ No newline at end of file +Next topic: :ref:`openstack_identity-openrc`. diff --git a/source/openstack_image.rst b/source/openstack_image.rst index d31d7f1f..32b7b391 100644 --- a/source/openstack_image.rst +++ b/source/openstack_image.rst @@ -135,7 +135,6 @@ Install and configure components #. Install OpenStack Image bundle.:: # swupd bundle-add openstack-image - # swupd verify --fix #. Configurations will be located at ``/etc/glance``. @@ -275,4 +274,4 @@ Linux image that helps you test your OpenStack deployment. | 38047887-61a7-41ea-9b49-27987d5e8bb9 | cirros | +--------------------------------------+--------+ -Next topic: :ref:`openstack_compute`. \ No newline at end of file +Next topic: :ref:`openstack_compute`. diff --git a/source/openstack_installing_bundles.rst b/source/openstack_installing_bundles.rst index b19a1296..04237729 100644 --- a/source/openstack_installing_bundles.rst +++ b/source/openstack_installing_bundles.rst @@ -21,6 +21,5 @@ To install, continue with the following topics: * `OpenStack Networking `_ * `OpenStack Orchestration `_ * `OpenStack Telemetry `_ -* `OpenStack Object Storage `_ -Next topic: :ref:`openstack_supporting-database`. \ No newline at end of file +Next topic: :ref:`openstack_supporting-database`. diff --git a/source/openstack_networking.rst b/source/openstack_networking.rst index 673001fa..4d302cea 100644 --- a/source/openstack_networking.rst +++ b/source/openstack_networking.rst @@ -9,7 +9,7 @@ implemented to accommodate different networking equipment and software, providing flexibility to OpenStack architecture and deployment. Installing and configuring the controller node -------------------------------------------------- +---------------------------------------------- Prerequisites ~~~~~~~~~~~~~ @@ -25,256 +25,443 @@ database, service credentials, and an API endpoint. $ mysql -u root -p * Create the ``neutron`` database:: - + CREATE DATABASE neutron; * Grant proper access to the ``neutron`` database. Replace - *``NEUTRON_DBPASS``* with a suitable password:: + *'NEUTRON_DBPASS'* with a suitable password:: GRANT ALL PRIVILEGES ON neutron.* TO 'neutron'@'localhost' \ - IDENTIFIED BY 'NEUTRON_DBPASS'; + IDENTIFIED BY 'NEUTRON_DBPASS'; GRANT ALL PRIVILEGES ON neutron.* TO 'neutron'@'%' \ - IDENTIFIED BY 'NEUTRON_DBPASS'; + IDENTIFIED BY 'NEUTRON_DBPASS'; * Exit the database access client. -#. Source the ``admin`` credentials to gain access to admin-only CLI - commands:: +#. Source the ``admin`` credentials to gain access to admin-only CLI commands:: - $ source admin-openrc.sh + $ source admin-openrc.sh #. To create the service credentials, complete these steps: * Create the ``neutron`` user:: - - $ openstack user create --password-prompt neutron - User Password: - Repeat User Password: - +----------+----------------------------------+ - | Field | Value | - +----------+----------------------------------+ - | email | None | - | enabled | True | - | id | ab67f043d9304017aaa73d692eeb4945 | - | name | neutron | - | username | neutron | - +----------+----------------------------------+ + + $ openstack user create --domain default --password-prompt neutron + User Password: + Repeat User Password: + +-----------+----------------------------------+ + | Field | Value | + +-----------+----------------------------------+ + | domain_id | default | + | enabled | True | + | id | e51ef98012974e5287d857bc709f89d0 | + | name | neutron | + +-----------+----------------------------------+ * Add the ``admin`` role to the ``neutron`` user:: - - +-------+----------------------------------+ - | Field | Value | - +-------+----------------------------------+ - | id | cd2cb9a39e874ea69e5d4b896eb16128 | - | name | admin | - +-------+----------------------------------+ + + $ openstack role add --project service --user neutron admin + + Note: This command provides no output. * Create the ``neutron`` service entity:: - - $ openstack service create --name neutron \ - --description "OpenStack Networking" network - +-------------+----------------------------------+ - | Field | Value | - +-------------+----------------------------------+ - | description | OpenStack Networking | - | enabled | True | - | id | f71529314dab4a4d8eca427e701d209e | - | name | neutron | - | type | network | - +-------------+----------------------------------+ - -#. Create the Networking service API endpoint:: - - --publicurl http://controller:9696 \ - --adminurl http://controller:9696 \ - --internalurl http://controller:9696 \ - --region RegionOne \ - network - +--------------+----------------------------------+ - | Field | Value | - +--------------+----------------------------------+ - | adminurl | http://controller:9696 | - | id | 04a7d3c1de784099aaba83a8a74100b3 | - | internalurl | http://controller:9696 | - | publicurl | http://controller:9696 | - | region | RegionOne | - | service_id | f71529314dab4a4d8eca427e701d209e | - | service_name | neutron | - | service_type | network | - +--------------+----------------------------------+ + + $ openstack service create --name neutron \ + --description "OpenStack Networking" network + +-------------+----------------------------------+ + | Field | Value | + +-------------+----------------------------------+ + | description | OpenStack Networking | + | enabled | True | + | id | a56bcd5695b943afba528192acceff01 | + | name | neutron | + | type | network | + +-------------+----------------------------------+ + +#. Create the Networking service API endpoints: + + * :: + + $ openstack endpoint create --region RegionOne \ + network public http://controller:9696 + +--------------+----------------------------------+ + | Field | Value | + +--------------+----------------------------------+ + | enabled | True | + | id | 61a8b881c8654026be84c12b943e4ee3 | + | interface | public | + | region | RegionOne | + | region_id | RegionOne | + | service_id | a56bcd5695b943afba528192acceff01 | + | service_name | neutron | + | service_type | network | + | url | http://controller:9696 | + +--------------+----------------------------------+ + + * :: + + $ openstack endpoint create --region RegionOne \ + network internal http://controller:9696 + +--------------+----------------------------------+ + | Field | Value | + +--------------+----------------------------------+ + | enabled | True | + | id | 83bf338752984e1cb5305b9a6a4b4e67 | + | interface | internal | + | region | RegionOne | + | region_id | RegionOne | + | service_id | a56bcd5695b943afba528192acceff01 | + | service_name | neutron | + | service_type | network | + | url | http://controller:9696 | + +--------------+----------------------------------+ + + * :: + + $ openstack endpoint create --region RegionOne \ + network admin http://controller:9696 + +--------------+----------------------------------+ + | Field | Value | + +--------------+----------------------------------+ + | enabled | True | + | id | 19cfff5a2e9a43298182f8785ea90414 | + | interface | admin | + | region | RegionOne | + | region_id | RegionOne | + | service_id | a56bcd5695b943afba528192acceff01 | + | service_name | neutron | + | service_type | network | + | url | http://controller:9696 | + +--------------+----------------------------------+ Installing the Networking components -~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Complete the following step to install the Networking components: -- Install OpenStack networking bundle:: - - # clr_bundle_add openstack-network +#. Install OpenStack networking bundle:: + + # swupd bundle-add openstack-network Configuring the Networking server component -~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Complete the following steps to configure the Networking server component: -The Networking server component configuration includes the database, -authentication mechanism, message queue, topology change notifications, -and plug-in. +#. Custom configurations will be located at ``/etc/neutron/``. -Edit the ``/etc/neutron/neutron.conf `` file: + * Create the ``/etc/neutron`` directory:: -#. Custom configurations will be located at ``/etc/neutron``. + # mkdir /etc/neutron - * Create /etc/neutron directory:: - - $ mkdir /etc/neutron + * Create empty neutron configuration file ``/etc/neutron/neutron.conf``:: - * Create empty neutron configuration - file:: + # touch /etc/neutron/neutron.conf - $ touch /etc/neutron/neutron.conf +#. Edit the ``/etc/neutron/neutron.conf`` file: -#. In the ``[database]`` section, configure database access. Replace - *NEUTRON_DBPASS* with the password you chose for the database:: + * In the ``[database]`` section, configure database access. Replace + *NEUTRON_DBPASS* with the password you chose for the database.:: - [database] - ... - connection = mysql://neutron:NEUTRON_DBPASS@controller/neutron + [database] + ... + connection = mysql://neutron:NEUTRON_DBPASS@controller/neutron -#. In the ``[DEFAULT]`` and ``[oslo_messaging_rabbit]`` sections, - configure RabbitMQ message queue access. Replace *``RABBIT_PASS``* - with the password you chose for the ``openstack`` account in - RabbitMQ:: + * In the ``[DEFAULT]`` section, enable the Modular Layer 2 (ML2) plug-in, + router service, and overlapping IP addresses:: - [DEFAULT] - ... - rpc_backend = rabbit - [oslo_messaging_rabbit] - ... - rabbit_host = controller - rabbit_userid = openstack - rabbit_password = RABBIT_PASS - -#. In the ``[DEFAULT]`` and ``[keystone_authtoken]`` sections, configure - Identity service access. Replace *``NEUTRON_PASS``* with the password - you chose for the ``neutron`` user in the Identity service:: + [DEFAULT] + ... + core_plugin = ml2 + service_plugins = router + allow_overlapping_ips = True - [DEFAULT] - ... - auth_strategy = keystone - [keystone_authtoken] - ... - auth_uri = http://controller:5000 - auth_url = http://controller:35357 - auth_plugin = password - project_domain_id = default - user_domain_id = default - project_name = service - username = neutron - password = NEUTRON_PASS - -#. In the ``[DEFAULT]`` section, enable the Modular Layer 2 (ML2) - plug-in, router service, and overlapping IP addresses:: + * In the ``[DEFAULT]`` and ``[oslo_messaging_rabbit]`` sections, configure + RabbitMQ message queue access. Replace *RABBIT_PASS* with the password you + chose for the ``openstack`` account in RabbitMQ:: - [DEFAULT] - ... - core_plugin = ml2 - service_plugins = router - allow_overlapping_ips = True + [DEFAULT] + ... + rpc_backend = rabbit -#. In the ``[DEFAULT]`` and ``[nova]`` sections, configure Networking to - notify Compute of network topology changes. Replace ``NOVA_PASS`` - with the password you chose for the ``nova`` user in the Identity - service:: + [oslo_messaging_rabbit] + ... + rabbit_host = controller + rabbit_userid = openstack + rabbit_password = RABBIT_PASS - [DEFAULT] - ... - notify_nova_on_port_status_changes = True - notify_nova_on_port_data_changes = True - nova_url = http://controller:8774/v2 - [nova] - ... - auth_url = http://controller:35357 - auth_plugin = password - project_domain_id = default - user_domain_id = default - region_name = RegionOne - project_name = service - username = nova - password = NOVA_PASS + * In the ``[DEFAULT]`` and ``[keystone_authtoken]`` sections, configure + Identity service access. Replace *NEUTRON_PASS* with the password you + chose for the ``neutron`` user in the Identity service:: + + [DEFAULT] + ... + auth_strategy = keystone + + [keystone_authtoken] + ... + auth_uri = http://controller:5000 + auth_url = http://controller:35357 + auth_plugin = password + project_domain_id = default + user_domain_id = default + project_name = service + username = neutron + password = NEUTRON_PASS + + * In the ``[DEFAULT]`` and ``[nova]`` sections, configure Networking to + notify Compute of network topology changes. Replace *NOVA_PASS* with the + password you chose for the ``nova`` user in the Identity service:: + + [DEFAULT] + ... + notify_nova_on_port_status_changes = True + notify_nova_on_port_data_changes = True + nova_url = http://controller:8774/v2 + + [nova] + ... + auth_url = http://controller:35357 + auth_plugin = password + project_domain_id = default + user_domain_id = default + region_name = RegionOne + project_name = service + username = nova + password = NOVA_PASS Configuring the Modular Layer 2 (ML2) plug-in ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -The ML2 plug-in uses the Open vSwitch (OVS) mechanism (agent) to build -the virtual networking framework for instances. However, the controller -node does not need the OVS components because it does not handle -instance network traffic. +The ML2 plug-in uses the Linux bridge mechanism to build layer-2 (bridging and +switching) virtual networking infrastructure for instances. -#. Custom configuration for ML2 plug-in will be stored in ``/etc/neutron/plugins/ml2``:: - - mkdir -p /etc/neutron/plugins/ml2 - touch /etc/neutron.plugins/ml2/ml2_conf.ini +#. Custom configuration will be located at ``/etc/neutron/plugins/ml2``. -#. Edit the ``/etc/neutron/plugins/ml2/ml2_conf.ini`` file as follows: + * Create the ``/etc/neutron/plugins/ml2`` directory:: - * In the ``[ml2]`` section, enable the flat, VLAN, generic routing - encapsulation (GRE), and virtual extensible LAN (VXLAN) network - type drivers, GRE tenant networks, and the OVS mechanism driver:: + # mkdir -p /etc/neutron/plugins/ml2 - [ml2] - ... - type_drivers = flat,vlan,gre,vxlan - tenant_network_types = gre - mechanism_drivers = openvswitch + * Create empty ML2 configuration file + ``/etc/neutron/plugins/ml2/ml2_conf.ini``:: - * In the ``[ml2_type_gre]`` section, configure the tunnel identifier - (id) range:: - - [ml2_type_gre] - ... - tunnel_id_ranges = 1:1000 + # touch /etc/neutron/plugins/ml2/ml2_conf.ini - * In the ``[securitygroup]`` section, enable security groups, enable - ipset, and configure the OVS iptables firewall driver:: +#. Edit the ``/etc/neutron/plugins/ml2/ml2_conf.ini`` file and complete the + following actions: + + * In the ``[ml2]`` section, enable flat, VLAN and VXLAN networks:: + + [ml2] + ... + type_drivers = flat,vlan,vxlan + + * In the ``[ml2]`` section, enable VXLAN project (private) networks:: + + [ml2] + ... + tenant_network_types = vxlan + + * In the ``[ml2]`` section, enable the Linux bridge and layer-2 population + mechanisms:: + + [ml2] + ... + mechanism_drivers = linuxbridge,l2population + + * In the ``[ml2]`` section, enable the port security extension driver:: + + [ml2] + ... + extension_drivers = port_security + + * In the ``[ml2_type_flat]`` section, configure the public flat provider + network:: + + [ml2_type_flat] + ... + flat_networks = public + + * In the [ml2_type_vxlan] section, configure the VXLAN network identifier + range for private networks:: + + [ml2_type_vxlan] + ... + vni_ranges = 1:1000 + + * In the [securitygroup] section, enable ipset to increase efficiency of + security group rules:: + + [securitygroup] + ... + enable_ipset = True + +Configure the Linux bridge agent +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + +The Linux bridge agent builds layer-2 (bridging and switching) virtual +networking infrastructure for instances including VXLAN tunnels for private +networks and handles security groups. + +#. Custom configuration for Linux bridge agent will be stored in + ``/etc/neutron/plugins/ml2/linuxbridge_agent.ini``:: + + # touch /etc/neutron/plugins/ml2/linuxbridge_agent.ini + +#. Edit the ``/etc/neutron/plugins/ml2/linuxbridge_agent.ini`` file and + complete the following actions: + + * In the ``[linux_bridge]`` section, map the public virtual network to the + public physical network interface. Replace *PUBLIC_INTERFACE_NAME* with + the name of the underlying physical public network interface:: + + [linux_bridge] + physical_interface_mappings = public:PUBLIC_INTERFACE_NAME + + * In the ``[vxlan]`` section, enable VXLAN overlay networks, configure the + IP address of the physical network interface that handles overlay networks, + and enable layer-2 population. Replace *OVERLAY_INTERFACE_IP_ADDRESS* + with the IP address of the underlying physical network interface that + handles overlay networks:: + + [vxlan] + enable_vxlan = True + local_ip = OVERLAY_INTERFACE_IP_ADDRESS + l2_population = True + + * In the ``[agent]`` section, enable ARP spoofing protection:: + + [agent] + ... + prevent_arp_spoofing = True + + * In the ``[securitygroup]`` section, enable security groups and configure + the Linux bridge iptables firewall driver:: + + [securitygroup] + ... + enable_security_group = True + firewall_driver = neutron.agent.linux.iptables_firewall.IptablesFirewallDriver + + +Configure the layer-3 agent +~~~~~~~~~~~~~~~~~~~~~~~~~~~ + +The Layer-3 (L3) agent provides routing and NAT services for virtual networks. + +#. Custom configuration for the Layer-3 agent will be stored in + ``/etc/neutron/l3_agent.ini``:: + + # touch /etc/neutron/l3_agent.ini + +#. Edit the ``/etc/neutron/l3_agent.ini`` file and complete the following + actions: + + * In the ``[DEFAULT]`` section, configure the Linux bridge interface driver + and external network bridge:: + + [DEFAULT] + ... + interface_driver = neutron.agent.linux.interface.BridgeInterfaceDriver + external_network_bridge = + + Note: The ``external_network_bridge`` option intentionally lacks a value to + enable multiple external networks on a single agent. + +Configure the DHCP agent +~~~~~~~~~~~~~~~~~~~~~~~~ + +The DHCP agent provides DHCP services for virtual networks. + +#. Custom configuration for Linux bridge agent will be stored in + ``/etc/neutron/dhcp_agent.ini``:: + + # touch /etc/neutron/dhcp_agent.ini + +#. Edit the /etc/neutron/dhcp_agent.ini file and complete the following actions: + + * In the ``[DEFAULT]`` section, configure the Linux bridge interface driver, + Dnsmasq DHCP driver, and enable isolated metadata so instances on public + networks can access metadata over the network:: + + [DEFAULT] + ... + interface_driver = neutron.agent.linux.interface.BridgeInterfaceDriver + dhcp_driver = neutron.agent.linux.dhcp.Dnsmasq + enable_isolated_metadata = True + +Configure the metadata agent +~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + +The metadata agent provides configuration information such as credentials to +instances. + +#. Custom configuration for the metadata agent will be stored in + ``/etc/neutron/metadata_agent.ini``:: + + # touch /etc/neutron/metadata_agent.ini + +#. Edit the ``/etc/neutron/metadata_agent.ini`` file and complete the + following actions: + + * In the ``[DEFAULT]`` section, configure access parameters. Replace + *NEUTRON_PASS* with the password you chose for the ``neutron`` user + in the Identity service:: + + [DEFAULT] + ... + auth_uri = http://controller:5000 + auth_url = http://controller:35357 + auth_region = RegionOne + auth_plugin = password + project_domain_id = default + user_domain_id = default + project_name = service + username = neutron + password = NEUTRON_PASS + + * In the ``[DEFAULT]`` section, configure the metadata host:: + + [DEFAULT] + ... + nova_metadata_ip = controller + + * In the ``[DEFAULT]`` section, configure the metadata proxy shared secret + Replace *METADATA_SECRET* with a suitable secret for the metadata proxy:: + + [DEFAULT] + ... + metadata_proxy_shared_secret = METADATA_SECRET - [securitygroup] - ... - enable_security_group = True - enable_ipset = True - firewall_driver = neutron.agent.linux.iptables_firewall.OVSHybridIptablesFirewallDriver Configuring Compute to use Networking ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -By default, distribution packages configure Compute to use legacy -networking. You must reconfigure Compute to manage networks through -Networking. +#. Edit the ``/etc/nova/nova.conf`` file on the controller node as follows: -#. Edit the ``/etc/nova/nova.conf`` file on the controller node as - follows: + * In the ``[neutron]`` section, configure access parameters, enable the + metadata proxy, and configure the secret. - * In the ``[DEFAULT]`` section, configure the APIs and drivers:: - - [DEFAULT] - ... - network_api_class = nova.network.neutronv2.api.API - security_group_api = neutron - linuxnet_interface_driver = nova.network.linux_net.LinuxOVSInterfaceDriver - firewall_driver = nova.virt.firewall.NoopFirewallDriver + Replace *NEUTRON_PASS* with the password you chose for the ``neutron`` + user in the Identity service. - * In the ``[neutron]`` section, configure access - parameters. Replace *NEUTRON_PASS* with the password you - chose for the ``neutron`` user in the Identity service:: + Replace *METADATA_SECRET* with the secret you chose for the metadata + proxy:: - [neutron] - ... - url = http://controller:9696 - auth_strategy = keystone - admin_auth_url = http://controller:35357/v2.0 - admin_tenant_name = service - admin_username = neutron - admin_password = NEUTRON_PASS + [neutron] + ... + url = http://controller:9696 + auth_url = http://controller:35357 + auth_plugin = password + project_domain_id = default + user_domain_id = default + region_name = RegionOne + project_name = service + username = neutron + password = NEUTRON_PASS + + service_metadata_proxy = True + metadata_proxy_shared_secret = METADATA_SECRET Finalizing installation ~~~~~~~~~~~~~~~~~~~~~~~~ @@ -286,24 +473,200 @@ Finalizing installation # ln -s /etc/neutron/plugins/ml2/ml2_conf.ini /etc/neutron/plugin.ini -#. Populate the database:: - - # su -s /bin/sh -c "neutron-db-manage --config-file /etc/neutron/neutron.conf \ - --config-file /etc/neutron/plugins/ml2/ml2_conf.ini upgrade head" neutron - -#. Let ``systemd`` set the correct permissions for files in ``/etc/neutron``:: +#. Ensure files have proper ownership by running the following command:: # systemctl restart update-triggers.target +#. Populate the database:: + + # su -s /bin/sh -c "neutron-db-manage --config-file /etc/neutron/neutron.conf \ + --config-file /etc/neutron/plugins/ml2/ml2_conf.ini upgrade head" neutron + #. Restart the Compute services:: - - # systemctl restart nova-api.service nova-scheduler.service \ - nova-conductor.service + + # systemctl restart uwsgi@nova-api.service nova-scheduler.service nova-conductor.service #. Start the Networking service and configure it to start when the system boots:: - # systemctl enable neutron-server.service - # systemctl start neutron-server.service + # systemctl enable neutron-server.service \ + neutron-linuxbridge-agent.service \ + neutron-dhcp-agent.service \ + neutron-metadata-agent.service \ + neutron-l3-agent.service + # systemctl start neutron-server.service \ + neutron-linuxbridge-agent.service \ + neutron-dhcp-agent.service \ + neutron-metadata-agent.service \ + neutron-l3-agent.service -Next topic: :ref:`openstack_orchestration`. \ No newline at end of file +Install and configure compute node +---------------------------------- + +Install the components +~~~~~~~~~~~~~~~~~~~~~~ + +* Install OpenStack networking bundle:: + + # swupd bundle-add openstack-network + +Configure the common component +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + +#. Edit the ``/etc/neutron/neutron.conf`` file and complete the following + actions: + + * In the ``[DEFAULT]`` and ``[oslo_messaging_rabbit]`` sections, configure + RabbitMQ message queue access. Replace *RABBIT_PASS* with the password you + chose for the openstack account in RabbitMQ.:: + + [DEFAULT] + ... + rpc_backend = rabbit + + [oslo_messaging_rabbit] + ... + rabbit_host = controller + rabbit_userid = openstack + rabbit_password = RABBIT_PASS + + * In the ``[DEFAULT]`` and ``[keystone_authtoken]`` sections, configure + Identity service access. Replace *NEUTRON_PASS* with the password you chose + for the ``neutron`` user in the Identity service:: + + [DEFAULT] + ... + auth_strategy = keystone + + [keystone_authtoken] + ... + auth_uri = http://controller:5000 + auth_url = http://controller:35357 + auth_plugin = password + project_domain_id = default + user_domain_id = default + project_name = service + username = neutron + password = NEUTRON_PASS + +Configure the Linux bridge agent +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + +#. Edit the ``/etc/neutron/plugins/ml2/linuxbridge_agent.ini`` file and complete + the following actions: + + * In the ``[linux_bridge]`` section, map the public virtual network to the + public physical network interface:: + + [linux_bridge] + physical_interface_mappings = public:PUBLIC_INTERFACE_NAME + + * In the ``[vxlan]`` section, enable VXLAN overlay networks, configure the + IP address of the physical network interface that handles overlay + networks, and enable layer-2 population:: + + [vxlan] + enable_vxlan = True + local_ip = OVERLAY_INTERFACE_IP_ADDRESS + l2_population = True + + * In the ``[agent]`` section, enable ARP spoofing protection:: + + [agent] + ... + prevent_arp_spoofing = True + + * In the ``[securitygroup]`` section, enable security groups and configure + the Linux bridge iptables firewall driver:: + + [securitygroup] + ... + enable_security_group = True + firewall_driver = neutron.agent.linux.iptables_firewall.IptablesFirewallDriver + +Configure Compute to use Networking +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + +#. Edit the ``/etc/nova/nova.conf`` file and complete the following actions: + + * In the ``[neutron]`` section, configure access parameters. Replace + *NEUTRON_PASS* with the password you chose for the ``neutron`` user in + the Identity service.:: + + [neutron] + ... + url = http://controller:9696 + auth_url = http://controller:35357 + auth_plugin = password + project_domain_id = default + user_domain_id = default + region_name = RegionOne + project_name = service + username = neutron + password = NEUTRON_PASS + +Finalize installation +~~~~~~~~~~~~~~~~~~~~~ + +#. Restart the Compute service:: + + # systemctl restart nova-compute.service + +#. Restart the Linux bridge agent:: + + # systemctl enable neutron-linuxbridge-agent.service + # systemctl restart neutron-linuxbridge-agent.service + +Verify Operation +---------------- + +#. Source the ``admin`` credentials to gain access to admin-only CLI commands:: + + $ source admin-openrc.sh + +#. List loaded extensions to verify successful launch of the neutron-server + process:: + + $ neutron ext-list + +-----------------------+-----------------------------------------------+ + | alias | name | + +-----------------------+-----------------------------------------------+ + | dns-integration | DNS Integration | + | address-scope | Address scope | + | ext-gw-mode | Neutron L3 Configurable external gateway mode | + | binding | Port Binding | + | agent | agent | + | subnet_allocation | Subnet Allocation | + | l3_agent_scheduler | L3 Agent Scheduler | + | external-net | Neutron external network | + | flavors | Neutron Service Flavors | + | net-mtu | Network MTU | + | quotas | Quota management support | + | l3-ha | HA Router extension | + | provider | Provider Network | + | multi-provider | Multi Provider Network | + | extraroute | Neutron Extra Route | + | router | Neutron L3 Router | + | extra_dhcp_opt | Neutron Extra DHCP opts | + | security-group | security-group | + | dhcp_agent_scheduler | DHCP Agent Scheduler | + | rbac-policies | RBAC Policies | + | port-security | Port Security | + | allowed-address-pairs | Allowed Address Pairs | + | dvr | Distributed Virtual Router | + +-----------------------+-----------------------------------------------+ + +#. List agents to verify successful launch of the neutron agents:: + + $ neutron agent-list + +--------------------------------------+--------------------+------------+-------+----------------+---------------------------+ + | id | agent_type | host | alive | admin_state_up | binary | + +--------------------------------------+--------------------+------------+-------+----------------+---------------------------+ + | 08905043-5010-4b87-bba5-aedb1956e27a | Linux bridge agent | compute1 | :-) | True | neutron-linuxbridge-agent | + | 27eee952-a748-467b-bf71-941e89846a92 | Linux bridge agent | controller | :-) | True | neutron-linuxbridge-agent | + | 830344ff-dc36-4956-84f4-067af667a0dc | L3 agent | controller | :-) | True | neutron-l3-agent | + | dd3644c9-1a3a-435a-9282-eb306b4b0391 | DHCP agent | controller | :-) | True | neutron-dhcp-agent | + | f49a4b81-afd6-4b3d-b923-66c8f0517099 | Metadata agent | controller | :-) | True | neutron-metadata-agent | + +--------------------------------------+--------------------+------------+-------+----------------+---------------------------+ + +Next topic: :ref:`openstack_orchestration`. diff --git a/source/openstack_orchestration.rst b/source/openstack_orchestration.rst index b3af8090..b047c2b0 100644 --- a/source/openstack_orchestration.rst +++ b/source/openstack_orchestration.rst @@ -3,196 +3,273 @@ Orchestration ############################################################ -The Orchestration module provides template-based OpenStack* API calls -on a cloud application. It integrates core components of OpenStack into -a one-file template system that allows you to create most OpenStack -resource types, including: instances, floating IPs, volumes, security -groups, and users. The module also provides advanced functionality: -instance high availability, instance auto-scaling, and nested stacks, -all of which allow OpenStack core projects to accommodate a larger user -base.   +The OpenStack* Orchestration service provides a template-based orchestration for +describing a cloud application by running OpenStack API calls to generate +running cloud applications. The software integrates other core components of +OpenStack into a one-file template system. -The service enables deployers to integrate with the Orchestration module -directly, or through custom plugins. +The templates allow you to create most OpenStack resource types, such as +instances, floating IPs, volumes, security groups and users. It also provides +advanced functionality, such as instance high availability, instance +auto-scaling, and nested stacks. This enables OpenStack core projects to +receive a larger user base. Installing and configuring controller node ------------------------------------------------ +------------------------------------------ This section describes how to install and configure the Orchestration -module, codenamed heat, on the controller node. +service, codenamed heat, on the controller node. Configuring prerequisites -~~~~~~~~~~~~~~~~~~~~~~~~~~ +~~~~~~~~~~~~~~~~~~~~~~~~~ Before you install and configure Orchestration, you must create a database, service credentials, and API endpoints. #. To create the database, complete these steps: - * Use the database access client to connect to the database server - as the ``root`` user:: + * Use the database access client to connect to the database server as + the ``root`` user:: - $ mysql -u root -p + $ mysql -u root -p * Create the ``heat`` database:: - - CREATE DATABASE heat; - * Grant proper access to the ``heat`` database. - Replace *HEAT_DBPASS*  with a suitable password:: + CREATE DATABASE heat; + + * Grant proper access to the ``heat`` database. Replace *HEAT_DBPASS*   + with a suitable password:: + + GRANT ALL PRIVILEGES ON heat.* TO 'heat'@'localhost' \ + IDENTIFIED BY 'HEAT_DBPASS'; + GRANT ALL PRIVILEGES ON heat.* TO 'heat'@'%' \ + IDENTIFIED BY 'HEAT_DBPASS'; - GRANT ALL PRIVILEGES ON heat.* TO 'heat'@'localhost' \ - IDENTIFIED BY 'HEAT_DBPASS'; - GRANT ALL PRIVILEGES ON heat.* TO 'heat'@'%' \ - IDENTIFIED BY 'HEAT_DBPASS'; - * Exit the database access client. #. Source the ``admin`` credentials to gain access to admin-only CLI commands:: - $ source admin-openrc.sh + $ source admin-openrc.sh #. To create the service credentials, complete these steps: * Create the ``heat`` user:: - - $ openstack user create --password-prompt heat - User Password: - Repeat User Password: - +----------+----------------------------------+ - | Field | Value | - +----------+----------------------------------+ - | email | None | - | enabled | True | - | id | 7fd67878dcd04d0393469ef825a7e005 | - | name | heat | - | username | heat | - +----------+----------------------------------+ - + + $ openstack user create --domain default --password-prompt heat + User Password: + Repeat User Password: + +-----------+----------------------------------+ + | Field | Value | + +-----------+----------------------------------+ + | domain_id | default | + | enabled | True | + | id | ca2e175b851943349be29a328cc5e360 | + | name | heat | + +-----------+----------------------------------+ + * Add the ``admin`` role to the ``heat`` user:: - - $ openstack role add --project service --user heat admin - +-------+----------------------------------+ - | Field | Value | - +-------+----------------------------------+ - | id | cd2cb9a39e874ea69e5d4b896eb16128 | - | name | admin | - +-------+----------------------------------+ - * Create the ``heat_stack_owner`` role:: - - $ openstack role create heat_stack_owner - +-------+----------------------------------+ - | Field | Value | - +-------+----------------------------------+ - | id | c0a1cbee7261446abc873392f616de87 | - | name | heat_stack_owner | - +-------+----------------------------------+ - - * Add the ``heat_stack_owner`` role to the ``demo`` tenant and - user. - - Note: You must add the ``heat_stack_owner`` role to users that - manage stacks:: - - $ openstack role add --project demo --user demo heat_stack_owner - +-------+----------------------------------+ - | Field | Value | - +-------+----------------------------------+ - | id | c0a1cbee7261446abc873392f616de87 | - | name | heat_stack_owner | - +-------+----------------------------------+ - - * Create the ``heat_stack_user`` role. - - Note: The Orchestration service automatically assigns the ``heat_stack_user`` role - to users that it creates during stack deployment. By default, this role restricts  - API operations. To avoid conflicts, do not add this role to users with the  - heat_stack_owner role:: - - $ openstack role create heat_stack_user - +-------+----------------------------------+ - | Field | Value | - +-------+----------------------------------+ - | id | e01546b1a81c4e32a6d14a9259e60154 | - | name | heat_stack_user | - +-------+----------------------------------+ + $ openstack role add --project service --user heat admin * Create the ``heat`` and ``heat-cfn`` service entities:: - - +-------------+----------------------------------+ - | Field | Value | - +-------------+----------------------------------+ - | description | Orchestration | - | enabled | True | - | id | 031112165cad4c2bb23e84603957de29 | - | name | heat | - | type | orchestration | - +-------------+----------------------------------+ - $ openstack service create --name heat-cfn \ - --description "Orchestration" cloudformation - +-------------+----------------------------------+ - | Field | Value | - +-------------+----------------------------------+ - | description | Orchestration | - | enabled | True | - | id | 297740d74c0a446bbff867acdccb33fa | - | name | heat-cfn | - | type | cloudformation | - +-------------+----------------------------------+ + + $ openstack service create --name heat \ + --description "Orchestration" orchestration + +-------------+----------------------------------+ + | Field | Value | + +-------------+----------------------------------+ + | description | Orchestration | + | enabled | True | + | id | 727841c6f5df4773baa4e8a5ae7d72eb | + | name | heat | + | type | orchestration | + +-------------+----------------------------------+ + + $ openstack service create --name heat-cfn \ + --description "Orchestration" cloudformation + +-------------+----------------------------------+ + | Field | Value | + +-------------+----------------------------------+ + | description | Orchestration | + | enabled | True | + | id | c42cede91a4e47c3b10c8aedc8d890c6 | + | name | heat-cfn | + | type | cloudformation | + +-------------+----------------------------------+ #. Create the Orchestration service API endpoints:: - - $ openstack endpoint create \ - --publicurl http://controller:8004/v1/%\(tenant_id\)s \ - --internalurl http://controller:8004/v1/%\(tenant_id\)s \ - --adminurl http://controller:8004/v1/%\(tenant_id\)s \ - --region RegionOne \ - orchestration - +--------------+-----------------------------------------+ - | Field | Value | - +--------------+-----------------------------------------+ - | adminurl | http://controller:8004/v1/%(tenant_id)s | - | id | f41225f665694b95a46448e8676b0dc2 | - | internalurl | http://controller:8004/v1/%(tenant_id)s | - | publicurl | http://controller:8004/v1/%(tenant_id)s | - | region | RegionOne | - | service_id | 031112165cad4c2bb23e84603957de29 | - | service_name | heat | - | service_type | orchestration | - +--------------+-----------------------------------------+ - $ openstack endpoint create \ - --publicurl http://controller:8000/v1 \ - --internalurl http://controller:8000/v1 \ - --adminurl http://controller:8000/v1 \ - --region RegionOne \ - cloudformation - +--------------+----------------------------------+ - | Field | Value | - +--------------+----------------------------------+ - | adminurl | http://controller:8000/v1 | - | id | f41225f665694b95a46448e8676b0dc2 | - | internalurl | http://controller:8000/v1 | - | publicurl | http://controller:8000/v1 | - | region | RegionOne | - | service_id | 297740d74c0a446bbff867acdccb33fa | - | service_name | heat-cfn | - | service_type | cloudformation | - +--------------+----------------------------------+ -Installing and configuring the Orchestration components ----------------------------------------------------------- + $ openstack endpoint create --region RegionOne \ + orchestration public http://controller:8004/v1/%\(tenant_id\)s + +--------------+-----------------------------------------+ + | Field | Value | + +--------------+-----------------------------------------+ + | enabled | True | + | id | 3f4dab34624e4be7b000265f25049609 | + | interface | public | + | region | RegionOne | + | region_id | RegionOne | + | service_id | 727841c6f5df4773baa4e8a5ae7d72eb | + | service_name | heat | + | service_type | orchestration | + | url | http://controller:8004/v1/%(tenant_id)s | + +--------------+-----------------------------------------+ + + $ openstack endpoint create --region RegionOne \ + orchestration internal http://controller:8004/v1/%\(tenant_id\)s + +--------------+-----------------------------------------+ + | Field | Value | + +--------------+-----------------------------------------+ + | enabled | True | + | id | 9489f78e958e45cc85570fec7e836d98 | + | interface | internal | + | region | RegionOne | + | region_id | RegionOne | + | service_id | 727841c6f5df4773baa4e8a5ae7d72eb | + | service_name | heat | + | service_type | orchestration | + | url | http://controller:8004/v1/%(tenant_id)s | + +--------------+-----------------------------------------+ + + $ openstack endpoint create --region RegionOne \ + orchestration admin http://controller:8004/v1/%\(tenant_id\)s + +--------------+-----------------------------------------+ + | Field | Value | + +--------------+-----------------------------------------+ + | enabled | True | + | id | 76091559514b40c6b7b38dde790efe99 | + | interface | admin | + | region | RegionOne | + | region_id | RegionOne | + | service_id | 727841c6f5df4773baa4e8a5ae7d72eb | + | service_name | heat | + | service_type | orchestration | + | url | http://controller:8004/v1/%(tenant_id)s | + +--------------+-----------------------------------------+ + + $ openstack endpoint create --region RegionOne \ + cloudformation public http://controller:8000/v1 + +--------------+----------------------------------+ + | Field | Value | + +--------------+----------------------------------+ + | enabled | True | + | id | b3ea082e019c4024842bf0a80555052c | + | interface | public | + | region | RegionOne | + | region_id | RegionOne | + | service_id | c42cede91a4e47c3b10c8aedc8d890c6 | + | service_name | heat-cfn | + | service_type | cloudformation | + | url | http://controller:8000/v1 | + +--------------+----------------------------------+ + + $ openstack endpoint create --region RegionOne \ + cloudformation internal http://controller:8000/v1 + +--------------+----------------------------------+ + | Field | Value | + +--------------+----------------------------------+ + | enabled | True | + | id | 169df4368cdc435b8b115a9cb084044e | + | interface | internal | + | region | RegionOne | + | region_id | RegionOne | + | service_id | c42cede91a4e47c3b10c8aedc8d890c6 | + | service_name | heat-cfn | + | service_type | cloudformation | + | url | http://controller:8000/v1 | + +--------------+----------------------------------+ + + $ openstack endpoint create --region RegionOne \ + cloudformation admin http://controller:8000/v1 + +--------------+----------------------------------+ + | Field | Value | + +--------------+----------------------------------+ + | enabled | True | + | id | 3d3edcd61eb343c1bbd629aa041ff88b | + | interface | internal | + | region | RegionOne | + | region_id | RegionOne | + | service_id | c42cede91a4e47c3b10c8aedc8d890c6 | + | service_name | heat-cfn | + | service_type | cloudformation | + | url | http://controller:8000/v1 | + +--------------+----------------------------------+ + +#. Orchestration requires additional information in the Identity service to + manage stacks. To add this information, complete these steps: + + * Create the ``heat`` domain that contains projects and users for stacks:: + + $ openstack domain create --description "Stack projects and users" heat + +-------------+----------------------------------+ + | Field | Value | + +-------------+----------------------------------+ + | description | Stack projects and users | + | enabled | True | + | id | 0f4d1bd326f2454dacc72157ba328a47 | + | name | heat | + +-------------+----------------------------------+ + + * Create the ``heat_domain_admin`` user to manage projects and users in the + ``heat`` domain:: + + $ openstack user create --domain heat --password-prompt heat_domain_admin + User Password: + Repeat User Password: + +-----------+----------------------------------+ + | Field | Value | + +-----------+----------------------------------+ + | domain_id | 0f4d1bd326f2454dacc72157ba328a47 | + | enabled | True | + | id | b7bd1abfbcf64478b47a0f13cd4d970a | + | name | heat_domain_admin | + +-----------+----------------------------------+ + + * Add the ``admin`` role to the ``heat_domain_admin`` in the ``heat`` domain + to enable administrative stack management privileges by the + ``heat_domain_admin`` user:: + + $ openstack role add --domain heat --user heat_domain_admin admin + + * Create the ``heat_stack_owner`` role:: + + $ openstack role create heat_stack_owner + +-------+----------------------------------+ + | Field | Value | + +-------+----------------------------------+ + | id | 15e34f0c4fed4e68b3246275883c8630 | + | name | heat_stack_owner | + +-------+----------------------------------+ + + * Create the ``heat_stack_user`` role:: + + $ openstack role create heat_stack_user + +-------+----------------------------------+ + | Field | Value | + +-------+----------------------------------+ + | id | 88849d41a55d4d1d91e4f11bffd8fc5c | + | name | heat_stack_user | + +-------+----------------------------------+ + +Installing and configuring components +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ To install and configure the Orchestration components: #. Install OpenStack Orchestration bundle:: - - # clr_bundle_add openstack-orchestration -#. Create the ``/etc/heat/heat.conf file``:: - - # mkdir /etc/heat # touch /etc/heat/heat.conf + # swupd bundle-add openstack-orchestration + +#. Custom configuration will be located at ``/etc/heat/heat.conf file``. + + * Create the ``/etc/heat`` directory:: + + # mkdir /etc/heat + + * Create empty heat configuration file ``/etc/heat/heat.conf``:: + + # touch /etc/heat/heat.conf #. Edit the ``/etc/heat/heat.conf`` file and complete the following actions: @@ -201,82 +278,88 @@ To install and configure the Orchestration components: Replace *HEAT_DBPASS*  with the password you chose for the Orchestration database:: - [database] - ... - connection = mysql://heat:HEAT_DBPASS@controller/heat + [database] + ... + connection = mysql://heat:HEAT_DBPASS@controller/heat - * In the ``[DEFAULT]`` and ``[oslo_messaging_rabbit]`` sections, - configure RabbitMQ message queue access. - Replace *``RABBIT_PASS``*  with the password you chose for - the ``openstack`` account in RabbitMQ:: + * In the ``[DEFAULT]`` and ``[oslo_messaging_rabbit]`` sections, configure + RabbitMQ message queue access. Replace ``RABBIT_PASS``  with the password + you chose for the ``openstack`` account in RabbitMQ:: - [DEFAULT] - ... - rpc_backend = rabbit - [oslo_messaging_rabbit] - ... - rabbit_host = controller - rabbit_userid = openstack - rabbit_password = RABBIT_PASS + [DEFAULT] + ... + rpc_backend = rabbit - * In the ``[keystone_authtoken]`` and ``[ec2authtoken]`` sections, - configure Identity service access. Replace *HEAT_PASS*  with - the password you chose for the ``heat`` user in the Identity - service:: + [oslo_messaging_rabbit] + ... + rabbit_host = controller + rabbit_userid = openstack + rabbit_password = RABBIT_PASS + + * In the ``[keystone_authtoken]``, ``[trustee]``, ``[clients_keystone]``, + and ``[ec2authtoken]`` sections, configure Identity service access. Replace + ``HEAT_PASS`` with the password you chose for the heat user in the Identity + service.:: + + [keystone_authtoken] + ... + auth_uri = http://controller:5000 + auth_url = http://controller:35357 + auth_plugin = password + project_domain_id = default + user_domain_id = default + project_name = service + username = heat + password = HEAT_PASS + + [trustee] + ... + auth_uri = http://controller:5000 + auth_url = http://controller:35357 + auth_plugin = password + project_domain_id = default + user_domain_id = default + project_name = service + username = heat + password = HEAT_PASS + + [clients_keystone] + ... + auth_uri = http://controller:5000 + + [ec2authtoken] + ... + auth_uri = http://controller:5000 - [keystone_authtoken] - ... - auth_uri = http://controller:5000/v2.0 - identity_uri = http://controller:35357 - admin_tenant_name = service - admin_user = heat - admin_password = HEAT_PASS - [ec2authtoken] - ... - auth_uri = http://controller:5000/v2.0 * In the ``[DEFAULT]`` section, configure the metadata and wait condition URLs:: - [DEFAULT] - ... - heat_metadata_server_url = http://controller:8000 - heat_waitcondition_server_url = http://controller:8000/v1/waitcondition + [DEFAULT] + ... + heat_metadata_server_url = http://controller:8000 + heat_waitcondition_server_url = http://controller:8000/v1/waitcondition - * In the ``[DEFAULT]`` section, configure information about the - heat Identity service domain. Replace  *``HEAT_DOMAIN_PASS``* -  with the password you chose for the admin user of - the ``heat`` user domain in the Identity service:: + * In the ``[DEFAULT]`` section, configure the stack domain and administrative + credentials. Replace ``HEAT_DOMAIN_PASS`` with the password you chose for + the ``heat_domain_admin`` user in the Identity service.:: - [DEFAULT] - ... - stack_domain_admin = heat_domain_admin - stack_domain_admin_password = HEAT_DOMAIN_PASS - stack_user_domain_name = heat_user_domain + [DEFAULT] + ... + stack_domain_admin = heat_domain_admin + stack_domain_admin_password = HEAT_DOMAIN_PASS + stack_user_domain_name = heat -#. Source the ``admin`` credentials to gain access to admin-only CLI - commands:: - $ source admin-openrc.sh +#. Ensure files have proper ownership by running the following command:: -#. Create the heat domain in Identity service. - Replace *``HEAT_DOMAIN_PASS``*  with a suitable - password:: - - $ heat-keystone-setup-domain \ - --stack-user-domain-name heat_user_domain \ - --stack-domain-admin heat_domain_admin \ - --stack-domain-admin-password HEAT_DOMAIN_PASS - -#. Let systemd set the correct permissions for files in ``/etc/heat``:: - - # systemctl restart update-triggers.target + # systemctl restart update-triggers.target #. Populate the Orchestration database:: - - # su -s /bin/sh -c "heat-manage db_sync" heat`` -Finalizing installation + # su -s /bin/sh -c "heat-manage db_sync" heat + +Finalize installation ~~~~~~~~~~~~~~~~~~~~~~~~ Complete this step to finalize the installation: @@ -284,7 +367,27 @@ Complete this step to finalize the installation: * Start the Orchestration services and configure them to start when the system boots:: - # systemctl enable heat-api.service heat-api-cfn.service heat-engine.service - # systemctl start heat-api.service heat-api-cfn.service heat-engine.service`` + # systemctl enable heat-api.service heat-api-cfn.service heat-engine.service + # systemctl start heat-api.service heat-api-cfn.service heat-engine.service -Next topic: :ref:`openstack_telemetry`. \ No newline at end of file +Verify operation +---------------- + +#. Source the ``admin`` tenant credentials:: + + $ source admin-openrc.sh + +#. List service components to verify successful launch and registration of each + process:: + + $ heat service-list + +------------+-------------+--------------------------------------+------------+--------+----------------------------+--------+ + | hostname | binary | engine_id | host | topic | updated_at | status | + +------------+-------------+--------------------------------------+------------+--------+----------------------------+--------+ + | controller | heat-engine | 3e85d1ab-a543-41aa-aa97-378c381fb958 | controller | engine | 2015-10-13T14:16:06.000000 | up | + | controller | heat-engine | 45dbdcf6-5660-4d5f-973a-c4fc819da678 | controller | engine | 2015-10-13T14:16:06.000000 | up | + | controller | heat-engine | 51162b63-ecb8-4c6c-98c6-993af899c4f7 | controller | engine | 2015-10-13T14:16:06.000000 | up | + | controller | heat-engine | 8d7edc6d-77a6-460d-bd2a-984d76954646 | controller | engine | 2015-10-13T14:16:06.000000 | up | + +------------+-------------+--------------------------------------+------------+--------+----------------------------+--------+ + +Next topic: :ref:`openstack_telemetry`. diff --git a/source/openstack_supporting-database.rst b/source/openstack_supporting-database.rst index 62eac990..615e65c1 100644 --- a/source/openstack_supporting-database.rst +++ b/source/openstack_supporting-database.rst @@ -13,7 +13,6 @@ Install and configure the database server #. Install MariaDB bundle:: # swupd bundle-add database-mariadb - # swupd verify --fix #. Create the ``/etc/mariadb/`` folder and the ``/etc/mariadb/openstack.cnf`` file:: @@ -50,4 +49,4 @@ Complete the following steps to finalize database installation: # mysql_secure_installation -Next topic: :ref:`openstack_supporting-messaging`. \ No newline at end of file +Next topic: :ref:`openstack_supporting-messaging`. diff --git a/source/openstack_supporting-messaging.rst b/source/openstack_supporting-messaging.rst index be9c167d..aa0fe3f0 100644 --- a/source/openstack_supporting-messaging.rst +++ b/source/openstack_supporting-messaging.rst @@ -14,7 +14,6 @@ Install the message queue service #. Install the message queue bundle.:: # swupd bundle-add message-broker-rabbitmq - # swupd verify --fix Configuring the message broker service -------------------------------------- @@ -45,4 +44,4 @@ Complete the following steps to configure the message broker service: Setting permissions for user "openstack" in vhost "/" ... ...done. -Next topic: :ref:`openstack_identity`. \ No newline at end of file +Next topic: :ref:`openstack_identity`. diff --git a/source/openstack_telemetry.rst b/source/openstack_telemetry.rst index 51b6e257..1ddd62a1 100644 --- a/source/openstack_telemetry.rst +++ b/source/openstack_telemetry.rst @@ -6,59 +6,64 @@ Telemetry Overview --------- -The Telemetry module performs the following functions: +The OpenStack* Telemetry service performs the following functions: -- Efficiently polls metering data related to OpenStack services; +- Efficiently polls metering data related to OpenStack services - Collects event and metering data by monitoring notifications sent - from services; + from services - Publishes collected data to various targets, including data stores - and message queues; and -- Creates alarms when collected data breaks defined rules. + and message queues +- Creates alarms when collected data breaks defined rules -Installing and configuring controller node ------------------------------------------------ +Installing and configuring +--------------------------- This section describes how to install and configure the Telemetry -module, code-named ceilometer, on the controller node. The Telemetry -module uses separate agents to collect measurements from each OpenStack -service in your environment. +service, code-named ceilometer, on the controller node. The Telemetry +service collects measurements from most OpenStack services and optionally +triggers alarms. + Prerequisites ~~~~~~~~~~~~~~~ -Before installing and configuring the ``telemetry`` module, install +Before installing and configuring the ``telemetry`` service, install MongoDB* and create a MongoDB database, service credentials, and API endpoint. #. Install the MongoDB bundle:: - - # clr_bundle_add database-mongodb + + # swupd bundle-add database-mongodb #. Create the ``/etc/mongodb/`` folder and the - ``/etc/mongodb/openstack.cnf`` file. + ``/etc/mongodb/openstack.cnf`` file.:: + + # mkdir /etc/mongodb + # touch /etc/mongodb/openstack.cnf + #. Configure the ``bind_ip`` key to use the management interface IP - address of the controller node:: + address of the controller node by editing the ``/etc/mongodb/openstack.cnf`` file:: bind_ip = 10.0.0.11 #. Start the database service and configure it to start when the system boots with the following commands:: - # systemctl enable mongodb.service + # systemctl enable mongodb.service # systemctl start mongodb.service #. Create the ``ceilometer`` database. Replace *CEILOMETER_DBPASS* with a suitable password:: - # mongo --host controller --eval ' - db = db.getSiblingDB("ceilometer"); - db.createUser({user: "ceilometer", - pwd: "CEILOMETER_DBPASS", - roles: [ "readWrite", "dbAdmin" ]})' + # mongo --host controller --eval ' + db = db.getSiblingDB("ceilometer"); + db.createUser({user: "ceilometer", + pwd: "CEILOMETER_DBPASS", + roles: [ "readWrite", "dbAdmin" ]})' - MongoDB shell version: 2.6.x - connecting to: controller:27017/test - Successfully added user: { "user" : "ceilometer", "roles" : [ "readWrite", "dbAdmin" ] } + MongoDB shell version: 3.1.7 + connecting to: controller:27017/test + Successfully added user: { "user" : "ceilometer", "roles" : [ "readWrite", "dbAdmin" ] } #. Source the ``admin`` credentials to gain access to admin-only CLI commands:: @@ -68,157 +73,186 @@ endpoint. #. To create the service credentials, complete these steps: * Create the ``ceilometer`` user:: - - $ openstack user create --password-prompt ceilometer - User Password: - Repeat User Password: - +----------+----------------------------------+ - | Field | Value | - +----------+----------------------------------+ - | email | None | - | enabled | True | - | id | b7657c9ea07a4556aef5d34cf70713a3 | - | name | ceilometer | - | username | ceilometer | - +----------+----------------------------------+ + + $ openstack user create --domain default --password-prompt ceilometer + User Password: + Repeat User Password: + +-----------+----------------------------------+ + | Field | Value | + +-----------+----------------------------------+ + | domain_id | default | + | enabled | True | + | id | c859c96f57bd4989a8ea1a0b1d8ff7cd | + | name | ceilometer | + +-----------+----------------------------------+ * Add the ``admin`` role to the ``ceilometer`` user:: - - $ openstack role add --project service --user ceilometer admin - +-------+----------------------------------+ - | Field | Value | - +-------+----------------------------------+ - | id | cd2cb9a39e874ea69e5d4b896eb16128 | - | name | admin | - +-------+----------------------------------+ + + $ openstack role add --project service --user ceilometer admin * Create the ``ceilometer`` service entity:: - - $ openstack service create --name ceilometer \ - --description "Telemetry" metering - +-------------+----------------------------------+ - | Field | Value | - +-------------+----------------------------------+ - | description | Telemetry | - | enabled | True | - | id | 3405453b14da441ebb258edfeba96d83 | - | name | ceilometer | - | type | metering | - +-------------+----------------------------------+ -#. Create the Telemetry module API endpoint:: - - $ openstack endpoint create \ - --publicurl http://controller:8777 \ - --internalurl http://controller:8777 \ - --adminurl http://controller:8777 \ - --region RegionOne \ - metering - +--------------+----------------------------------+ - | Field | Value | - +--------------+----------------------------------+ - | adminurl | http://controller:8777 | - | id | d3716d85b10d4e60a67a52c6af0068cd | - | internalurl | http://controller:8777 | - | publicurl | http://controller:8777 | - | region | RegionOne | - | service_id | 3405453b14da441ebb258edfeba96d83 | - | service_name | ceilometer | - | service_type | metering | - +--------------+----------------------------------+ + $ openstack service create --name ceilometer \ + --description "Telemetry" metering + +-------------+----------------------------------+ + | Field | Value | + +-------------+----------------------------------+ + | description | Telemetry | + | enabled | True | + | id | 3405453b14da441ebb258edfeba96d83 | + | name | ceilometer | + | type | metering | + +-------------+----------------------------------+ -Installing and configuring the Telemetry module components -~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +#. Create the Telemetry service API endpoints:: + + $ openstack endpoint create --region RegionOne \ + metering public http://controller:8777 + +--------------+----------------------------------+ + | Field | Value | + +--------------+----------------------------------+ + | enabled | True | + | id | 340be3625e9b4239a6415d034e98aace | + | interface | public | + | region | RegionOne | + | region_id | RegionOne | + | service_id | 8c2c7f1b9b5049ea9e63757b5533e6d2 | + | service_name | celiometer | + | service_type | metering | + | url | http://controller:8777 | + +--------------+----------------------------------+ + + $ openstack endpoint create --region RegionOne \ + metering internal http://controller:8777 + +--------------+----------------------------------+ + | Field | Value | + +--------------+----------------------------------+ + | enabled | True | + | id | 340be3625e9b4239a6415d034e98aace | + | interface | internal | + | region | RegionOne | + | region_id | RegionOne | + | service_id | 8c2c7f1b9b5049ea9e63757b5533e6d2 | + | service_name | celiometer | + | service_type | metering | + | url | http://controller:8777 | + +--------------+----------------------------------+ + + $ openstack endpoint create --region RegionOne \ + metering admin http://controller:8777 + +--------------+----------------------------------+ + | Field | Value | + +--------------+----------------------------------+ + | enabled | True | + | id | 340be3625e9b4239a6415d034e98aace | + | interface | admin | + | region | RegionOne | + | region_id | RegionOne | + | service_id | 8c2c7f1b9b5049ea9e63757b5533e6d2 | + | service_name | celiometer | + | service_type | metering | + | url | http://controller:8777 | + +--------------+----------------------------------+ + + +Install and configure components +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ #. Install the OpenStack Telemetry Controller bundle:: - - # clr_bundle_add openstack-telemetry-controller -#. Generate a random value to use as the telemetry secret:: - - $ openssl rand -hex 10 + # swupd bundle-add openstack-telemetry-controller #. Custom configurations will be located at ``/etc/ceilometer``. * Create ``/etc/ceilometer`` directory:: - - mkdir /etc/ceilometer + + # mkdir /etc/ceilometer * Create the empty ceilometer configuration file:: - - /etc/ceilometer/ceilometer.conf - touch /etc/ceilometer/ceilometer.conf -#. Edit the following file:\ ``/etc/ceilometer/ceilometer.conf``\ Then + # touch /etc/ceilometer/ceilometer.conf + +#. Edit the ``/etc/ceilometer/ceilometer.conf`` file and complete the following actions: * In the ``[database]`` section, configure database access. Replace - *``CEILOMETER_DBPASS``* with the password you chose for the + *CEILOMETER_DBPASS* with the password you chose for the Telemetry module database. You must escape special characters such as ':', '/', '+', and '@' in the connection string in accordance with RFC2396:: - [database] - ... + [database] + ... connection = mongodb://ceilometer:CEILOMETER_DBPASS@controller:27017/ceilometer * In the ``[DEFAULT]`` and ``[oslo_messaging_rabbit]`` sections, - configure RabbitMQ message queue access. Replace *``RABBIT_PASS``* + configure RabbitMQ message queue access. Replace *RABBIT_PASS* with the password you chose for the ``openstack`` account in RabbitMQ:: - [DEFAULT] - ... - rpc_backend = rabbit - [oslo_messaging_rabbit] - rabbit_host = controller - rabbit_userid = openstack - rabbit_password = RABBIT_PASS + [DEFAULT] + ... + rpc_backend = rabbit + + [oslo_messaging_rabbit] + ... + rabbit_host = controller + rabbit_userid = openstack + rabbit_password = RABBIT_PASS * In the ``[DEFAULT]`` and ``[keystone_authtoken]`` sections, - configure Identity service access. Replace *``CEILOMETER_PASS``* + configure Identity service access. Replace *CEILOMETER_PASS* with the password you chose for the ``celiometer`` user in the Identity service:: - [DEFAULT] - ... - auth_strategy = keystone - [keystone_authtoken] - auth_uri = http://controller:5000/v2.0 - identity_uri = http://controller:35357 - admin_tenant_name = service - admin_user = ceilometer - admin_password = CEILOMETER_PASS + [DEFAULT] + ... + auth_strategy = keystone + + [keystone_authtoken] + ... + auth_uri = http://controller:5000 + auth_url = http://controller:35357 + auth_plugin = password + project_domain_id = default + user_domain_id = default + project_name = service + username = ceilometer + password = CEILOMETER_PASS * In the ``[service_credentials]`` section, configure service - credentials. Replace *``CEILOMETER_PASS``* with the password you + credentials. Replace *CEILOMETER_PASS* with the password you chose for the ``ceilometer`` user in the Identity service:: - [service_credentials] - ... - os_auth_url = http://controller:5000/v2.0 - os_username = ceilometer - os_tenant_name = service - os_password = CEILOMETER_PASS - os_endpoint_type = internalURL - os_region_name = RegionOne + [service_credentials] + ... + os_auth_url = http://controller:5000/v2.0 + os_username = ceilometer + os_tenant_name = service + os_password = CEILOMETER_PASS + os_endpoint_type = internalURL + os_region_name = RegionOne - * In the ``[publisher]`` section, configure the telemetry secret. - Replace *``TELEMETRY_SECRET``* with the telemetry secret that you - generated in a previous step:: + * Ensure files have proper ownership by running the following command:: + + # systemctl restart update-triggers.target - [publisher] - ... - telemetry_secret = TELEMETRY_SECRET Finalizing installation ~~~~~~~~~~~~~~~~~~~~~~~~ -* Start the Telemetry services and configure them to start when the system boots:: - - # systemctl enable ceilometer-api.service ceilometer-agent-notification.service ceilometer-agent-central.service ceilometer-collector.service \ - ceilometer-alarm-evaluator.service ceilometer-alarm-notifier.service - # systemctl start ceilometer-api.service ceilometer-agent-notification.service ceilometer-agent-central.service ceilometer-collector.service \ - ceilometer-alarm-evaluator.service ceilometer-alarm-notifier.service +#. Start the Telemetry services and configure them to start when the system boots:: -Next topic: :ref:`openstack_object_storage`. \ No newline at end of file + # systemctl enable ceilometer-agent-central.service \ + ceilometer-agent-notification.service \ + ceilometer-api.service \ + ceilometer-collector.service \ + ceilometer-alarm-evaluator.service \ + ceilometer-alarm-notifier.service + + # systemctl start ceilometer-agent-central.service \ + ceilometer-agent-notification.service \ + ceilometer-api.service \ + ceilometer-collector.service \ + ceilometer-alarm-evaluator.service \ + ceilometer-alarm-notifier.service