OpenStack Antelope : Create LoadBalancer Image2023/04/20 |
Install and Configure OpenStack Load Balancing as a Service (Octavia).
This example is based on the environment like follows.
------------+--------------------------+--------------------------+------------ | | | eth0|10.0.0.30 eth0|10.0.0.50 eth0|10.0.0.51 +-----------+-----------+ +-----------+-----------+ +-----------+-----------+ | [ dlp.srv.world ] | | [ network.srv.world ] | | [ node01.srv.world ] | | (Control Node) | | (Network Node) | | (Compute Node) | | | | | | | | MariaDB RabbitMQ | | Open vSwitch | | Libvirt | | Memcached Nginx | | Neutron Server | | Nova Compute | | Keystone httpd | | OVN-Northd | | Open vSwitch | | Glance Nova API | | Nginx iSCSI Target | | OVN Metadata Agent | | Cinder API | | Cinder Volume | | OVN-Controller | | | | Octavia Services | | | +-----------------------+ +-----------------------+ +-----------------------+ |
[1] | Create a LoadBalancer Image and add it to Glance. It's OK to work on any node. (example below is on Control Node) |
[root@dlp ~(keystone)]#
dnf --enablerepo=centos-openstack-antelope,epel,crb -y install openstack-octavia-diskimage-create debootstrap python3-octaviaclient # create an instance image [root@dlp ~(keystone)]# octavia-diskimage-create.sh -d focal
# add to Glance [root@dlp ~(keystone)]# openstack image create "Amphora" --tag "Amphora" --file amphora-x64-haproxy.qcow2 --disk-format qcow2 --container-format bare --private --project service
# add [flavor] for Amphora instance [root@dlp ~(keystone)]# openstack flavor create --id 100 --vcpus 1 --ram 2048 --disk 5 m1.octavia --private --project service
# add a security group for Amphora instance [root@dlp ~(keystone)]# openstack security group create lb-mgmt-sec-group --project service
# allow required ports for security group [root@dlp ~(keystone)]# openstack security group rule create --protocol icmp --ingress lb-mgmt-sec-group [root@dlp ~(keystone)]# openstack security group rule create --protocol tcp --dst-port 22:22 lb-mgmt-sec-group [root@dlp ~(keystone)]# openstack security group rule create --protocol tcp --dst-port 80:80 lb-mgmt-sec-group [root@dlp ~(keystone)]# openstack security group rule create --protocol tcp --dst-port 443:443 lb-mgmt-sec-group [root@dlp ~(keystone)]# openstack security group rule create --protocol tcp --dst-port 9443:9443 lb-mgmt-sec-group |
[2] | Configure Octavia service to set instance ID or security group ID. |
[root@network ~]# openstack image list +--------------------------------------+----------------+--------+ | ID | Name | Status | +--------------------------------------+----------------+--------+ | 8758e9d1-dc3c-41fb-86cb-3a17647f4347 | Amphora | active | | 17d50b54-c009-45ff-96ed-58086f79065f | CentOS-Stream9 | active | +--------------------------------------+----------------+--------+[root@network ~]# openstack flavor list --all +-----+------------+------+------+-----------+-------+-----------+ | ID | Name | RAM | Disk | Ephemeral | VCPUs | Is Public | +-----+------------+------+------+-----------+-------+-----------+ | 1 | m1.small | 2048 | 10 | 0 | 1 | True | | 100 | m1.octavia | 2048 | 5 | 0 | 1 | False | | 2 | m1.medium | 4096 | 10 | 0 | 2 | True | | 3 | m1.large | 8192 | 20 | 0 | 4 | True | +-----+------------+------+------+-----------+-------+-----------+[root@network ~]# openstack network list +--------------------------------------+---------+--------------------------------------+ | ID | Name | Subnets | +--------------------------------------+---------+--------------------------------------+ | 913ec733-5a60-4df0-b182-49a393675bca | private | bd8d7602-95e4-4540-971e-a0104dd8b658 | | c1c6a4c6-776e-4c4f-b557-b9efc4a43ee8 | public | 68cec7d2-f12f-4272-ac16-8dba6148888b | +--------------------------------------+---------+--------------------------------------+[root@network ~]# openstack security group list +--------------------------------------+-------------------+------------------------+----------------------------------+------+ | ID | Name | Description | Project | Tags | +--------------------------------------+-------------------+------------------------+----------------------------------+------+ | 8e7c62e6-a72d-409c-b84e-702d1ce2b80f | secgroup01 | secgroup01 | 40aa0807595447f0bd8d5b2dbfa1839b | [] | | d729d220-def5-4b74-8ae8-d8449c73485e | default | Default security group | 40aa0807595447f0bd8d5b2dbfa1839b | [] | | f1eec1f7-a405-4191-ab8d-ce5e1e4f7ce1 | lb-mgmt-sec-group | lb-mgmt-sec-group | 6d680c2574034967ab496a59d1319a65 | [] | +--------------------------------------+-------------------+------------------------+----------------------------------+------+
[root@network ~]#
vi /etc/octavia/octavia.conf # add into [controller_worker] section
[controller_worker]
client_ca = /etc/octavia/certs/client_ca.cert.pem
amp_image_tag = Amphora
# specify [flavor] ID for Amphora instance
amp_flavor_id = 100
# specify security group ID Amphora instance
amp_secgroup_list = f1eec1f7-a405-4191-ab8d-ce5e1e4f7ce1
# specify network ID to boot Amphora instance (example below specifies public network [public])
amp_boot_network_list = c1c6a4c6-776e-4c4f-b557-b9efc4a43ee8
network_driver = allowed_address_pairs_driver
compute_driver = compute_nova_driver
amphora_driver = amphora_haproxy_rest_driver
[root@network ~]# |
Sponsored Link |