Friday, December 5, 2025

OpenStack Epoxy : Create LoadBalancer Image

 

OpenStack Epoxy : Create LoadBalancer Image

 

Install and Configure OpenStack Load Balancing as a Service (Octavia).

This example is based on the environment like follows.

------------+--------------------------+--------------------------+------------
            |                          |                          |
        eth0|10.0.0.30             eth0|10.0.0.50             eth0|10.0.0.51
+-----------+-----------+  +-----------+-----------+  +-----------+-----------+
|   [ dlp.srv.world ]   |  | [ network.srv.world ] |  |  [ node01.srv.world ] |
|     (Control Node)    |  |     (Network Node)    |  |     (Compute Node)    |
|                       |  |                       |  |                       |
|  MariaDB    RabbitMQ  |  |      Open vSwitch     |  |        Libvirt        |
|  Memcached  Nginx     |  |     Neutron Server    |  |      Nova Compute     |
|  Keystone   httpd     |  |      OVN-Northd       |  |      Open vSwitch     |
|  Glance     Nova API  |  |  Nginx  iSCSI Target  |  |   OVN Metadata Agent  |
|  Cinder API           |  |     Cinder Volume     |  |     OVN-Controller    |
|                       |  |    Octavia Services   |  |                       |
+-----------------------+  +-----------------------+  +-----------------------+

[1]Create a LoadBalancer Image and add it to Glance. It's OK to work on any node. (example below is on Control Node)
# create an instance image

root@dlp ~(keystone)# 
apt -y install podman

root@dlp ~(keystone)# 
mkdir -p /var/lib/containers/tmpdisk

root@dlp ~(keystone)# 
apparmor_parser -R /etc/apparmor.d/runc

root@dlp ~(keystone)# 
apparmor_parser -R /etc/apparmor.d/crun

root@dlp ~(keystone)# 
podman run --privileged -it -v /var/lib/containers/tmpdisk:/mnt centos:stream9 /bin/bash

bash-5.1# 
cd /mnt

bash-5.1# 
dnf -y install centos-release-openstack-epoxy epel-release sudo

bash-5.1# 
dnf --enablerepo=crb -y install openstack-octavia-diskimage-create debootstrap python3-octaviaclient

bash-5.1# 
chmod 440 /etc/shadow

bash-5.1# 
octavia-diskimage-create.sh -i centos-minimal

.....
.....
Successfully built the amphora image using amphora-agent from the master branch.
Amphora image size: /mnt/amphora-x64-haproxy.qcow2 561040384
bash-5.1# 
# add to Glance

root@dlp ~(keystone)# 
openstack image create "Amphora" --tag "Amphora" --file /var/lib/containers/tmpdisk/amphora-x64-haproxy.qcow2 --disk-format qcow2 --container-format bare --private --project service
# add [flavor] for Amphora instance

root@dlp ~(keystone)# 
openstack flavor create --id 100 --vcpus 1 --ram 2048 --disk 10 m1.octavia --private --project service
# add a security group for Amphora instance

root@dlp ~(keystone)# 
openstack security group create lb-mgmt-sec-group --project service
# allow required ports for security group

root@dlp ~(keystone)# 
openstack security group rule create --protocol icmp --ingress lb-mgmt-sec-group

root@dlp ~(keystone)# 
openstack security group rule create --protocol tcp --dst-port 22:22 lb-mgmt-sec-group

root@dlp ~(keystone)# 
openstack security group rule create --protocol tcp --dst-port 80:80 lb-mgmt-sec-group

root@dlp ~(keystone)# 
openstack security group rule create --protocol tcp --dst-port 443:443 lb-mgmt-sec-group

root@dlp ~(keystone)# 
openstack security group rule create --protocol tcp --dst-port 9443:9443 lb-mgmt-sec-group

[2]Configure Octavia service to set instance ID or security group ID.
root@network:~# 
openstack image list

+--------------------------------------+----------+--------+
| ID                                   | Name     | Status |
+--------------------------------------+----------+--------+
| ba130f12-d980-4b24-b10c-8bff2fc1d0e1 | Amphora  | active |
| 33def798-3361-483b-9de1-8c2c6e1c840c | Debian13 | active |
+--------------------------------------+----------+--------+

root@network:~# 
openstack flavor list --all

+-----+------------+-------+------+-----------+-------+-----------+
| ID  | Name       |   RAM | Disk | Ephemeral | VCPUs | Is Public |
+-----+------------+-------+------+-----------+-------+-----------+
| 1   | m1.tiny    |  2048 |   10 |         0 |     1 | True      |
| 100 | m1.octavia |  2048 |   10 |         0 |     1 | False     |
| 2   | m1.small   |  4096 |   10 |         0 |     2 | True      |
| 3   | m1.medium  |  8192 |   10 |         0 |     4 | True      |
| 4   | m1.large   | 16384 |   10 |         0 |     8 | True      |
| 5   | m2.medium  |  8192 |   10 |        10 |     4 | True      |
+-----+------------+-------+------+-----------+-------+-----------+

root@network:~# 
openstack network list

+---------------------------------+---------+----------------------------------+
| ID                              | Name    | Subnets                          |
+---------------------------------+---------+----------------------------------+
| 7de3878f-814f-4909-b4e6-        | public  | 319013fd-5412-4cce-              |
| d4dc1c740577                    |         | bb87-49f5a0c91b0e                |
| d442015a-b6f6-4349-890b-        | private | bb5efd0a-ea4d-42ee-99ca-         |
| c08eb5366a4d                    |         | 97cee2f56ca2                     |
+---------------------------------+---------+----------------------------------+

root@network:~# 
openstack security group list

+-----------------+-----------------+-----------------+-----------------+------+
| ID              | Name            | Description     | Project         | Tags |
+-----------------+-----------------+-----------------+-----------------+------+
| 8af05d75-dc3a-  | secgroup01      | secgroup01      | ecfa98ba82de421 | []   |
| 4e53-a3ab-      |                 |                 | e8f16c3d862b5ab |      |
| dd5dfeb3981b    |                 |                 | 04              |      |
| 9dd6c8b5-4dd1-  | default         | Default         | ecfa98ba82de421 | []   |
| 4bf4-bdb0-      |                 | security group  | e8f16c3d862b5ab |      |
| 455c1888f290    |                 |                 | 04              |      |
| dc3dba55-4c3c-  | lb-mgmt-sec-    | lb-mgmt-sec-    | a60814a6c56241e | []   |
| 41ad-80c2-      | group           | group           | dbbdfae6c290f8a |      |
| 34abe2ca7266    |                 |                 | bc              |      |
+-----------------+-----------------+-----------------+-----------------+------+

root@network:~# 
vi /etc/octavia/octavia.conf
# add into [controller_worker] section

[controller_worker]
client_ca = /etc/octavia/certs/client_ca.cert.pem
amp_image_tag = Amphora
# specify [flavor] ID for Amphora instance
amp_flavor_id = 100
# specify security group ID for Amphora instance
amp_secgroup_list = dc3dba55-4c3c-41ad-80c2-34abe2ca7266
# specify network ID to boot Amphora instance (example below specifies public network [public])
amp_boot_network_list = 7de3878f-814f-4909-b4e6-d4dc1c740577
network_driver = allowed_address_pairs_driver
compute_driver = compute_nova_driver
amphora_driver = amphora_haproxy_rest_driver 

root@network:~# 
systemctl restart octavia-api \
octavia-health-manager \
octavia-housekeeping \
octavia-worker

[3]On all Compute Node, Install required packages.
root@node01:~# 
apt -y install genisoimage
Matched Content

No comments:

Post a Comment