CentOS Stream 9
Sponsored Link

OpenStack Dalmatian : Create LoadBalancer Image2024/10/16

 

Install and Configure OpenStack Load Balancing as a Service (Octavia).

This example is based on the environment like follows.

------------+--------------------------+--------------------------+------------
            |                          |                          |
        eth0|10.0.0.30             eth0|10.0.0.50             eth0|10.0.0.51
+-----------+-----------+  +-----------+-----------+  +-----------+-----------+
|   [ dlp.srv.world ]   |  | [ network.srv.world ] |  |  [ node01.srv.world ] |
|     (Control Node)    |  |     (Network Node)    |  |     (Compute Node)    |
|                       |  |                       |  |                       |
|  MariaDB    RabbitMQ  |  |      Open vSwitch     |  |        Libvirt        |
|  Memcached  Nginx     |  |     Neutron Server    |  |      Nova Compute     |
|  Keystone   httpd     |  |      OVN-Northd       |  |      Open vSwitch     |
|  Glance     Nova API  |  |  Nginx  iSCSI Target  |  |   OVN Metadata Agent  |
|  Cinder API           |  |     Cinder Volume     |  |     OVN-Controller    |
|                       |  |    Octavia Services   |  |                       |
+-----------------------+  +-----------------------+  +-----------------------+

[1] Create a LoadBalancer Image and add it to Glance.
It's OK to work on any node. (example below is on Control Node)
# install from Dalmatian, EPEL, CRB

[root@dlp ~(keystone)]#
dnf --enablerepo=centos-openstack-dalmatian,epel,crb -y install openstack-octavia-diskimage-create debootstrap python3-octaviaclient
# create an instance image

[root@dlp ~(keystone)]#
octavia-diskimage-create.sh -i centos-minimal
# add to Glance

[root@dlp ~(keystone)]#
openstack image create "Amphora" --tag "Amphora" --file amphora-x64-haproxy.qcow2 --disk-format qcow2 --container-format bare --private --project service
# add [flavor] for Amphora instance

[root@dlp ~(keystone)]#
openstack flavor create --id 100 --vcpus 2 --ram 4096 --disk 5 m1.octavia --private --project service
# add a security group for Amphora instance

[root@dlp ~(keystone)]#
openstack security group create lb-mgmt-sec-group --project service
# allow required ports for security group

[root@dlp ~(keystone)]#
openstack security group rule create --protocol icmp --ingress lb-mgmt-sec-group

[root@dlp ~(keystone)]#
openstack security group rule create --protocol tcp --dst-port 22:22 lb-mgmt-sec-group

[root@dlp ~(keystone)]#
openstack security group rule create --protocol tcp --dst-port 80:80 lb-mgmt-sec-group

[root@dlp ~(keystone)]#
openstack security group rule create --protocol tcp --dst-port 443:443 lb-mgmt-sec-group

[root@dlp ~(keystone)]#
openstack security group rule create --protocol tcp --dst-port 9443:9443 lb-mgmt-sec-group

[2] Configure Octavia service to set instance ID or security group ID.
[root@network ~]#
openstack image list

+--------------------------------------+----------------+--------+
| ID                                   | Name           | Status |
+--------------------------------------+----------------+--------+
| 3b80b302-dbd7-4c13-aa72-87bdf81fb686 | Amphora        | active |
| 75e0d976-4075-4488-8f26-87d4a50aebe9 | CentOS-Stream9 | active |
+--------------------------------------+----------------+--------+

[root@network ~]#
openstack flavor list --all

+-----+------------+-------+------+-----------+-------+-----------+
| ID  | Name       |   RAM | Disk | Ephemeral | VCPUs | Is Public |
+-----+------------+-------+------+-----------+-------+-----------+
| 1   | m1.tiny    |  2048 |   10 |         0 |     1 | True      |
| 100 | m1.octavia |  4096 |    5 |         0 |     2 | False     |
| 2   | m1.small   |  4096 |   10 |         0 |     2 | True      |
| 3   | m1.medium  |  8192 |   10 |         0 |     4 | True      |
| 4   | m1.large   | 16384 |   10 |         0 |     8 | True      |
| 5   | m2.large   | 16384 |   10 |        10 |     8 | True      |
+-----+------------+-------+------+-----------+-------+-----------+

[root@network ~]#
openstack network list

+--------------------------------------+---------+--------------------------------------+
| ID                                   | Name    | Subnets                              |
+--------------------------------------+---------+--------------------------------------+
| 7302c07e-c543-4a85-a955-d6cc8a4e4011 | public  | 8fbc394a-e821-47d8-8efc-d5f7c7db0ff8 |
| aa200aa9-ddb2-4d89-aa37-ce3e3a939421 | private | dfb0949d-d775-4c17-9b07-b01ac7d71aac |
+--------------------------------------+---------+--------------------------------------+

[root@network ~]#
openstack security group list

+--------------------------------------+-------------------+------------------------+----------------------------------+------+
| ID                                   | Name              | Description            | Project                          | Tags |
+--------------------------------------+-------------------+------------------------+----------------------------------+------+
| 12477060-9c16-456d-9ad8-5081c5e2e152 | default           | Default security group | b19d04cd37254937a4eaebcd0f0f0a43 | []   |
| 4d0d0507-13c3-4cde-9717-365298005790 | lb-mgmt-sec-group | lb-mgmt-sec-group      | aff8e7e402dc4d9e849bbe0e34fa4538 | []   |
| 84b37bf4-30cc-4fd6-99fc-ffafe4aed86c | secgroup01        | secgroup01             | 756e2b4937c44d3991028e294f92d89a | []   |
+--------------------------------------+-------------------+------------------------+----------------------------------+------+

[root@network ~]#
vi /etc/octavia/octavia.conf
# add into [controller_worker] section

[controller_worker]
client_ca = /etc/octavia/certs/client_ca.cert.pem
amp_image_tag = Amphora
# specify [flavor] ID for Amphora instance
amp_flavor_id = 100
# specify security group ID for Amphora instance
amp_secgroup_list = 4d0d0507-13c3-4cde-9717-365298005790
# specify network ID to boot Amphora instance (example below specifies public network [public])
amp_boot_network_list = 7302c07e-c543-4a85-a955-d6cc8a4e4011
network_driver = allowed_address_pairs_driver
compute_driver = compute_nova_driver
amphora_driver = amphora_haproxy_rest_driver 

[root@network ~]#
systemctl restart octavia-api \
octavia-health-manager \
octavia-housekeeping \
octavia-worker

Matched Content