CentOS 7
Sponsored Link

OpenStack Newton : Nova 設定2016/10/22

 
OpenStack Compute Service(Nova)をインストールします。
[1]
こちらを参考に KVMハイパーバイザーをインストールしておきます。なお、リンク先 [2] のブリッジの設定は不要です。
[2] Keystone に Nova 用のユーザー等々を登録しておきます。
# nova ユーザー作成 (service プロジェクト所属)

[root@dlp ~(keystone)]#
openstack user create --domain default --project service --password servicepassword nova

+---------------------+----------------------------------+
| Field               | Value                            |
+---------------------+----------------------------------+
| default_project_id  | fb1ebfb4fe2a4ef3918d02932f4de062 |
| domain_id           | default                          |
| enabled             | True                             |
| id                  | ab6661701e1041b7aa106299c981876c |
| name                | nova                             |
| password_expires_at | None                             |
+---------------------+----------------------------------+

# nova ユーザーを admin ロール に加える

[root@dlp ~(keystone)]#
openstack role add --project service --user nova admin
# nova 用サービスエントリ作成

[root@dlp ~(keystone)]#
openstack service create --name nova --description "OpenStack Compute service" compute

+-------------+----------------------------------+
| Field       | Value                            |
+-------------+----------------------------------+
| description | OpenStack Compute service        |
| enabled     | True                             |
| id          | 7b25f77f64264cd9bc82d0b2871621a4 |
| name        | nova                             |
| type        | compute                          |
+-------------+----------------------------------+

# Keystone ホストを定義しておく

[root@dlp ~(keystone)]#
export controller=10.0.0.30
# nova 用エンドポイント作成 (public)

[root@dlp ~(keystone)]#
openstack endpoint create --region RegionOne compute public http://$controller:8774/v2.1/%\(tenant_id\)s

+--------------+------------------------------------------+
| Field        | Value                                    |
+--------------+------------------------------------------+
| enabled      | True                                     |
| id           | 36587839b3bd4c8ba1026396abcf62e8         |
| interface    | public                                   |
| region       | RegionOne                                |
| region_id    | RegionOne                                |
| service_id   | 7b25f77f64264cd9bc82d0b2871621a4         |
| service_name | nova                                     |
| service_type | compute                                  |
| url          | http://10.0.0.30:8774/v2.1/%(tenant_id)s |
+--------------+------------------------------------------+

# nova 用エンドポイント作成 (internal)

[root@dlp ~(keystone)]#
openstack endpoint create --region RegionOne compute internal http://$controller:8774/v2.1/%\(tenant_id\)s

+--------------+------------------------------------------+
| Field        | Value                                    |
+--------------+------------------------------------------+
| enabled      | True                                     |
| id           | 680786d48ab241e7956f64e9c43a8d8a         |
| interface    | internal                                 |
| region       | RegionOne                                |
| region_id    | RegionOne                                |
| service_id   | 7b25f77f64264cd9bc82d0b2871621a4         |
| service_name | nova                                     |
| service_type | compute                                  |
| url          | http://10.0.0.30:8774/v2.1/%(tenant_id)s |
+--------------+------------------------------------------+

# nova 用エンドポイント作成 (admin)

[root@dlp ~(keystone)]#
openstack endpoint create --region RegionOne compute admin http://$controller:8774/v2.1/%\(tenant_id\)s

+--------------+------------------------------------------+
| Field        | Value                                    |
+--------------+------------------------------------------+
| enabled      | True                                     |
| id           | 6d112645fff146bcb18a2ab07178e670         |
| interface    | admin                                    |
| region       | RegionOne                                |
| region_id    | RegionOne                                |
| service_id   | 7b25f77f64264cd9bc82d0b2871621a4         |
| service_name | nova                                     |
| service_type | compute                                  |
| url          | http://10.0.0.30:8774/v2.1/%(tenant_id)s |
+--------------+------------------------------------------+
[3] Nova をインストールします。
# Newton, EPEL からインストール

[root@dlp ~(keystone)]#
yum --enablerepo=centos-openstack-newton,epel -y install openstack-nova
[4] Nova 用のユーザーとデータベースを MariaDB に登録しておきます。
[root@dlp ~(keystone)]#
mysql -u root -p

Enter password:
Welcome to the MariaDB monitor.  Commands end with ; or \g.
Your MariaDB connection id is 11
Server version: 10.1.17-MariaDB MariaDB Server

Copyright (c) 2000, 2016, Oracle, MariaDB Corporation Ab and others.

Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.

MariaDB [(none)]>
create database nova;

Query OK, 1 row affected (0.00 sec)
MariaDB [(none)]>
create database nova_api;

Query OK, 1 row affected (0.00 sec)
MariaDB [(none)]>
grant all privileges on nova.* to nova@'localhost' identified by 'password';

Query OK, 0 rows affected (0.00 sec)
MariaDB [(none)]>
grant all privileges on nova.* to nova@'%' identified by 'password';

Query OK, 0 rows affected (0.00 sec)
MariaDB [(none)]>
grant all privileges on nova_api.* to nova@'localhost' identified by 'password';

Query OK, 0 rows affected (0.00 sec)
MariaDB [(none)]>
grant all privileges on nova_api.* to nova@'%' identified by 'password';

Query OK, 0 rows affected (0.00 sec)
MariaDB [(none)]>
flush privileges;

Query OK, 0 rows affected (0.00 sec)
MariaDB [(none)]>
exit

Bye
[5] Nova の基本設定です。
[root@dlp ~(keystone)]#
mv /etc/nova/nova.conf /etc/nova/nova.conf.org

[root@dlp ~(keystone)]#
vi /etc/nova/nova.conf
# 新規作成

[DEFAULT]
# 自ホストのIP

my_ip = 10.0.0.30
state_path = /var/lib/nova
enabled_apis = osapi_compute,metadata
osapi_compute_listen = 0.0.0.0
osapi_compute_listen_port = 8774
rootwrap_config = /etc/nova/rootwrap.conf
api_paste_config = /etc/nova/api-paste.ini
auth_strategy = keystone
log_dir = /var/log/nova
rpc_backend = rabbit
# VNC を有効にする

[vnc]
enabled = True
vncserver_listen = 0.0.0.0
vncserver_proxyclient_address = $my_ip
novncproxy_base_url = http://10.0.0.30:6080/vnc_auto.html
# Glance サーバーを指定

[glance]
api_servers = http://10.0.0.30:9292
[oslo_concurrency]
lock_path = /var/lib/nova/tmp
# RabbitMQ サーバー接続情報

[oslo_messaging_rabbit]
rabbit_host = 10.0.0.30
rabbit_port = 5672
rabbit_userid = openstack
rabbit_password = password
# MariaDB サーバー接続情報

[api_database]
connection = mysql+pymysql://nova:password@10.0.0.30/nova_api
[database]
connection = mysql+pymysql://nova:password@10.0.0.30/nova
# Keystone サーバー接続情報

[keystone_authtoken]
auth_uri = http://10.0.0.30:5000
auth_url = http://10.0.0.30:35357
memcached_servers = 10.0.0.30:11211
auth_type = password
project_domain_name = default
user_domain_name = default
project_name = service
username = nova
password = servicepassword
[root@dlp ~(keystone)]#
chmod 640 /etc/nova/nova.conf

[root@dlp ~(keystone)]#
chgrp nova /etc/nova/nova.conf

[6] Nova ネットワーク ( nova-network ) を利用する場合のネットワーク設定です。
Neutron Service を利用する場合は、こちらを参照して設定してください
なお、レガシーネットワーク ( nova-network ) は非推奨となっています。
[root@dlp ~(keystone)]#
vi /etc/nova/nova.conf
# [DEFAULT] セクション内の適当な場所へ追記

use_neutron = False
libvirt_vif_driver = nova.virt.libvirt.vif.LibvirtGenericVIFDriver
linuxnet_interface_driver = nova.network.linux_net.LinuxBridgeInterfaceDriver
firewall_driver = nova.virt.libvirt.firewall.IptablesFirewallDriver
network_manager = nova.network.manager.FlatDHCPManager
network_size = 254
allow_same_net_traffic = False
multi_host = True
send_arp_for_ha = True
share_dhcp_address = True
force_dhcp_release = True
# パブリック用のインターフェース名

public_interface = eth0
# 適当なブリッジインターフェイス名

flat_network_bridge = br100
# フラットDHCPブリッジに使用するインターフェース名

flat_interface = dummy0
# フラットDHCPブリッジに指定したダミーインターフェースを追加して起動

[root@dlp ~(keystone)]#
cat > /etc/sysconfig/network-scripts/ifcfg-dummy0 <<EOF
DEVICE=dummy0
BOOTPROTO=none
ONBOOT=yes
TYPE=Ethernet
NM_CONTROLLED=no
EOF
[root@dlp ~(keystone)]#
echo "alias dummy0 dummy" > /etc/modprobe.d/dummy.conf

[root@dlp ~(keystone)]#
ifup dummy0

[7] SELinux を有効にしている場合は、ポリシーの変更が必要です。
[root@dlp ~(keystone)]#
semanage port -a -t http_port_t -p tcp 8778

[root@dlp ~(keystone)]#
vi nova_pol.te
# 以下の内容で新規作成

module nova_pol 1.0;

require {
        type nova_t;
        type httpd_config_t;
        type httpd_t;
        type nova_log_t;
        type sysctl_net_t;
        type netutils_exec_t;
        class file { read getattr create open execute };
        class dir { write search add_name };
        class capability { kill sys_ptrace };
        class capability2 block_suspend;
}

#============= httpd_t ==============
allow httpd_t nova_log_t:dir { write add_name };
allow httpd_t nova_log_t:file { create open };

#============= nova_t ==============
allow nova_t httpd_config_t:dir search;
allow nova_t netutils_exec_t:file execute;
allow nova_t self:capability kill;
allow nova_t sysctl_net_t:dir search;
allow nova_t sysctl_net_t:file { read getattr open };
allow nova_t self:capability sys_ptrace;
allow nova_t self:capability2 block_suspend;

[root@dlp ~(keystone)]#
checkmodule -m -M -o nova_pol.mod nova_pol.te

checkmodule: loading policy configuration from nova_pol.te
checkmodule: policy configuration loaded
checkmodule: writing binary representation (version 17) to nova_pol.mod
# 中間ファイルからモジュール生成

[root@dlp ~(keystone)]#
semodule_package --outfile nova_pol.pp --module nova_pol.mod

# モジュールインストール

[root@dlp ~(keystone)]#
semodule -i nova_pol.pp

[8] Firewalld を有効にしている場合は、サービスポートの許可が必要です。
[root@dlp ~(keystone)]#
firewall-cmd --add-port={6080/tcp,8774/tcp,8775/tcp} --permanent

success
[root@dlp ~(keystone)]#
firewall-cmd --reload

success
[9] Nova をサービス起動します。
レガシーネットワーク ( nova-network ) を利用しない場合は「network」を除外してください。
[root@dlp ~(keystone)]#
su -s /bin/bash nova -c "nova-manage api_db sync"

[root@dlp ~(keystone)]#
su -s /bin/bash nova -c "nova-manage db sync"

[root@dlp ~(keystone)]#
for service in api cert consoleauth conductor scheduler compute novncproxy network; do
systemctl start openstack-nova-$service
systemctl enable openstack-nova-$service
done
# 動作確認

[root@dlp ~(keystone)]#
nova service-list

+----+------------------+---------------+----------+---------+-------+----------------------------+-----------------+
| Id | Binary           | Host          | Zone     | Status  | State | Updated_at                 | Disabled Reason |
+----+------------------+---------------+----------+---------+-------+----------------------------+-----------------+
| 10 | nova-cert        | dlp.srv.world | internal | enabled | up    | 2016-10-21T16:24:38.000000 | -               |
| 11 | nova-consoleauth | dlp.srv.world | internal | enabled | up    | 2016-10-21T16:24:37.000000 | -               |
| 12 | nova-conductor   | dlp.srv.world | internal | enabled | up    | 2016-10-21T16:24:37.000000 | -               |
| 14 | nova-scheduler   | dlp.srv.world | internal | enabled | up    | 2016-10-21T16:24:38.000000 | -               |
| 15 | nova-compute     | dlp.srv.world | nova     | enabled | up    | 2016-10-21T16:24:38.000000 | -               |
| 16 | nova-network     | dlp.srv.world | internal | enabled | up    | 2016-10-21T16:24:38.000000 | -               |
+----+------------------+---------------+----------+---------+-------+----------------------------+-----------------+
関連コンテンツ