CentOS Stream 9
Sponsored Link

OpenStack Yoga : Create LoadBalancer Image2022/06/10

 
Install and Configure OpenStack Load Balancing as a Service (Octavia).
This example is based on the environment like follows.
------------+-----------------------------+-----------------------------+------------
            |                             |                             |
        eth0|10.0.0.30                eth0|10.0.0.50                eth0|10.0.0.51
+-----------+-----------+     +-----------+-----------+     +-----------+-----------+
|   [ dlp.srv.world ]   |     | [ network.srv.world ] |     |  [ node01.srv.world ] |
|     (Control Node)    |     |     (Network Node)    |     |     (Compute Node)    |
|                       |     |                       |     |                       |
|  MariaDB    RabbitMQ  |     |      Open vSwitch     |     |        Libvirt        |
|  Memcached  httpd     |     |     Neutron Server    |     |      Nova Compute     |
|  Keystone   Glance    |     |      OVN-Northd       |     |      Open vSwitch     |
|  Nova API  Cinder API |     |     Cinder Volume     |     |   OVN Metadata Agent  |
|                       |     |    Octavia Services   |     |     OVN-Controller    |
+-----------------------+     +-----------------------+     +-----------------------+

[1] Create a LoadBalancer Image and add it to Glance.
It's OK to work on any node. (example below is on Control Node)
# install from Yoga, EPEL, CRB

[root@dlp ~(keystone)]#
dnf --enablerepo=centos-openstack-yoga,epel,crb -y install openstack-octavia-diskimage-create debootstrap python3-octaviaclient
# create an instance image

[root@dlp ~(keystone)]#
octavia-diskimage-create.sh -d focal
# add to Glance

[root@dlp ~(keystone)]#
openstack image create "Amphora" --tag "Amphora" --file amphora-x64-haproxy.qcow2 --disk-format qcow2 --container-format bare --private --project service
# add [flavor] for Amphora instance

[root@dlp ~(keystone)]#
openstack flavor create --id 100 --vcpus 1 --ram 1024 --disk 5 m1.octavia --private --project service
# add a security group for Amphora instance

[root@dlp ~(keystone)]#
openstack security group create lb-mgmt-sec-group --project service
# allow required ports for security group

[root@dlp ~(keystone)]#
openstack security group rule create --protocol icmp --ingress lb-mgmt-sec-group

[root@dlp ~(keystone)]#
openstack security group rule create --protocol tcp --dst-port 22:22 lb-mgmt-sec-group

[root@dlp ~(keystone)]#
openstack security group rule create --protocol tcp --dst-port 80:80 lb-mgmt-sec-group

[root@dlp ~(keystone)]#
openstack security group rule create --protocol tcp --dst-port 443:443 lb-mgmt-sec-group

[root@dlp ~(keystone)]#
openstack security group rule create --protocol tcp --dst-port 9443:9443 lb-mgmt-sec-group

[2] Configure Octavia service to set instance ID or security group ID.
[root@network ~]#
openstack image list

+--------------------------------------+----------------+--------+
| ID                                   | Name           | Status |
+--------------------------------------+----------------+--------+
| 64191618-854a-4efd-ad85-c0be43816757 | Amphora        | active |
| 1044ab46-c42b-4cf6-ab1f-aaeb011fb3b9 | CentOS-Stream9 | active |
+--------------------------------------+----------------+--------+

[root@network ~]#
openstack flavor list --all

+-----+------------+------+------+-----------+-------+-----------+
| ID  | Name       |  RAM | Disk | Ephemeral | VCPUs | Is Public |
+-----+------------+------+------+-----------+-------+-----------+
| 0   | m1.small   | 2048 |   10 |         0 |     1 | True      |
| 100 | m1.octavia | 1024 |    5 |         0 |     1 | False     |
+-----+------------+------+------+-----------+-------+-----------+

[root@network ~]#
openstack network list

+--------------------------------------+---------+--------------------------------------+
| ID                                   | Name    | Subnets                              |
+--------------------------------------+---------+--------------------------------------+
| 9669b364-5e91-4858-bff1-437a23be347b | public  | 50ab40e2-c1ff-4371-a829-bbc228ddd16f |
| c4ede804-96e1-4b1b-bf1b-341f752065c0 | private | 80a576b7-55e6-4d3b-86d9-26bb0c4e7d57 |
+--------------------------------------+---------+--------------------------------------+

[root@network ~]#
openstack security group list

+--------------------------------------+-------------------+------------------------+----------------------------------+------+
| ID                                   | Name              | Description            | Project                          | Tags |
+--------------------------------------+-------------------+------------------------+----------------------------------+------+
| 1998cf27-0634-4727-8eef-ca0a659d6b45 | lb-mgmt-sec-group | lb-mgmt-sec-group      | 0f2625947bf0433a9519ba8a29434bdf | []   |
| 29bc3919-b600-4a86-b085-7918a60272d3 | secgroup01        | secgroup01             | 911e5ff7686741c782d6acc6d7155db1 | []   |
| 815d1c24-baac-4530-9966-8fdcfacbc4d4 | default           | Default security group | 911e5ff7686741c782d6acc6d7155db1 | []   |
+--------------------------------------+-------------------+------------------------+----------------------------------+------+

[root@network ~]#
vi /etc/octavia/octavia.conf
# add into [controller_worker] section

[controller_worker]
client_ca = /etc/octavia/certs/client_ca.cert.pem
amp_image_tag = Amphora
# specify [flavor] ID for Amphora instance
amp_flavor_id = 100
# specify security group ID Amphora instance
amp_secgroup_list = 1998cf27-0634-4727-8eef-ca0a659d6b45
# specify network ID to boot Amphora instance (example below specifies public network [public])
amp_boot_network_list = 9669b364-5e91-4858-bff1-437a23be347b
network_driver = allowed_address_pairs_driver
compute_driver = compute_nova_driver
amphora_driver = amphora_haproxy_rest_driver 

[root@network ~]#
systemctl restart octavia-api \
octavia-health-manager \
octavia-housekeeping \
octavia-worker

Matched Content