OpenStack Epoxy : Create LoadBalancer Image2025/04/24 |
Install and Configure OpenStack Load Balancing as a Service (Octavia). This example is based on the environment like follows. ------------+--------------------------+--------------------------+------------ | | | eth0|10.0.0.30 eth0|10.0.0.50 eth0|10.0.0.51 +-----------+-----------+ +-----------+-----------+ +-----------+-----------+ | [ dlp.srv.world ] | | [ network.srv.world ] | | [ node01.srv.world ] | | (Control Node) | | (Network Node) | | (Compute Node) | | | | | | | | MariaDB RabbitMQ | | Open vSwitch | | Libvirt | | Memcached Nginx | | Neutron Server | | Nova Compute | | Keystone httpd | | OVN-Northd | | Open vSwitch | | Glance Nova API | | Nginx iSCSI Target | | OVN Metadata Agent | | Cinder API | | Cinder Volume | | OVN-Controller | | | | Octavia Services | | | +-----------------------+ +-----------------------+ +-----------------------+ |
[1] | Create a LoadBalancer Image and add it to Glance. It's OK to work on any node. (example below is on Control Node) |
# create an instance image root@dlp ~(keystone)# apt -y install podman root@dlp ~(keystone)# mkdir /var/lib/containers/tmpdisk root@dlp ~(keystone)# podman run --privileged -it -v /var/lib/containers/tmpdisk:/mnt centos:stream9 /bin/bash bash-5.1# cd /mnt bash-5.1# dnf -y install centos-release-openstack-dalmatian epel-release sudo bash-5.1# dnf --enablerepo=crb -y install openstack-octavia-diskimage-create debootstrap python3-octaviaclient bash-5.1# chmod 440 /etc/shadow bash-5.1# octavia-diskimage-create.sh -i centos-minimal ..... ..... uccessfully built the amphora image using amphora-agent from the master branch. Amphora image size: //amphora-x64-haproxy.qcow2 551654912bash-5.1# exit
# add to Glance root@dlp ~(keystone)# openstack image create "Amphora" --tag "Amphora" --file /var/lib/containers/tmpdisk/amphora-x64-haproxy.qcow2 --disk-format qcow2 --container-format bare --private --project service
# add [flavor] for Amphora instance root@dlp ~(keystone)# openstack flavor create --id 100 --vcpus 1 --ram 2048 --disk 10 m1.octavia --private --project service
# add a security group for Amphora instance root@dlp ~(keystone)# openstack security group create lb-mgmt-sec-group --project service
# allow required ports for security group root@dlp ~(keystone)# openstack security group rule create --protocol icmp --ingress lb-mgmt-sec-group root@dlp ~(keystone)# openstack security group rule create --protocol tcp --dst-port 22:22 lb-mgmt-sec-group root@dlp ~(keystone)# openstack security group rule create --protocol tcp --dst-port 80:80 lb-mgmt-sec-group root@dlp ~(keystone)# openstack security group rule create --protocol tcp --dst-port 443:443 lb-mgmt-sec-group root@dlp ~(keystone)# openstack security group rule create --protocol tcp --dst-port 9443:9443 lb-mgmt-sec-group |
[2] | Configure Octavia service to set instance ID or security group ID. |
root@network:~# openstack image list +--------------------------------------+------------+--------+ | ID | Name | Status | +--------------------------------------+------------+--------+ | ca826f70-b37f-43ef-acda-baf047b43991 | Amphora | active | | f1c2157b-e54b-42c2-a09d-885d21b7aa72 | Ubuntu2404 | active | +--------------------------------------+------------+--------+root@network:~# openstack flavor list --all +-----+------------+-------+------+-----------+-------+-----------+ | ID | Name | RAM | Disk | Ephemeral | VCPUs | Is Public | +-----+------------+-------+------+-----------+-------+-----------+ | 1 | m1.tiny | 2048 | 10 | 0 | 1 | True | | 100 | m1.octavia | 2048 | 10 | 0 | 1 | False | | 2 | m1.small | 4096 | 10 | 0 | 2 | True | | 3 | m1.medium | 8192 | 10 | 0 | 4 | True | | 4 | m1.large | 16384 | 10 | 0 | 8 | True | | 5 | m2.medium | 8192 | 10 | 10 | 4 | True | +-----+------------+-------+------+-----------+-------+-----------+root@network:~# openstack network list +---------------------------------+---------+----------------------------------+ | ID | Name | Subnets | +---------------------------------+---------+----------------------------------+ | cb803bda-6f08-4ae3-9018- | public | b691b066-62df-45be-a5ee- | | 1c4320ad0295 | | 911e347174ba | | fb4dc320-1981-4914-9d3f- | private | daeaa092-2e5d-44de-9de4- | | f8fd757c4562 | | 51bea52b51b4 | +---------------------------------+---------+----------------------------------+root@network:~# openstack security group list +-----------------+-----------------+-----------------+-----------------+------+ | ID | Name | Description | Project | Tags | +-----------------+-----------------+-----------------+-----------------+------+ | 1308edaf-2ae3- | secgroup01 | secgroup01 | 407400ec8d16434 | [] | | 44fc-8763- | | | e9badf4ceb9d71f | | | 29b850697257 | | | 1e | | | b80ba15a-79dc- | default | Default | 5039718bba1c4de | [] | | 435c-9f1d- | | security group | 9bb4b792bedfb35 | | | def9c599002e | | | 8d | | | eab3d0e5-c858- | lb-mgmt-sec- | lb-mgmt-sec- | e5fb0e2eb880471 | [] | | 44c3-8460- | group | group | a9101084118997e | | | db7fcf22af70 | | | 43 | | +-----------------+-----------------+-----------------+-----------------+------+
root@network:~#
vi /etc/octavia/octavia.conf # add into [controller_worker] section
[controller_worker]
client_ca = /etc/octavia/certs/client_ca.cert.pem
amp_image_tag = Amphora
# specify [flavor] ID for Amphora instance
amp_flavor_id = 100
# specify security group ID for Amphora instance
amp_secgroup_list = eab3d0e5-c858-44c3-8460-db7fcf22af70
# specify network ID to boot Amphora instance (example below specifies public network [public])
amp_boot_network_list = cb803bda-6f08-4ae3-9018-1c4320ad0295
network_driver = allowed_address_pairs_driver
compute_driver = compute_nova_driver
amphora_driver = amphora_haproxy_rest_driver
root@network:~# |
Sponsored Link |