6.5. 创建分布式 control plane
定义 OpenStackControlPlane 自定义资源(CR)以创建分布式 control plane,并在 OpenShift (RHOSO)服务中启用 Red Hat OpenStack Services。
以下流程会创建一个 control plane,该服务 pod 默认分散到所有区中。存储服务覆盖默认服务 pod 放置,以调度特定区域中的 cinderVolumes、cinderBackups、glanceAPI 和 manilaShares 服务 pod。在添加所需的所有自定义前,您可以使用 control plane 对问题进行故障排除并测试环境。您可以在部署的环境中添加服务自定义。有关如何在部署后自定义 control plane 的更多信息,请参阅自定义 Red Hat OpenStack Services on OpenShift 部署指南。
-
以下服务示例将默认 RHOSO MetalLB
IPAddressPool范围内的 IP 地址用于loadBalancerIPs字段。使用您在为 BGP 的 RHOSO 网络 VIP 准备 RHOCP 时创建的 IP 地址,更新loadBalancerIPs字段。 -
您可以使用
topologyRef字段将每个服务的 pod 放置到特定区中。如果没有指定,pod 会在区间自动均匀分布。
先决条件
-
您已为环境中的特定区创建了
TopologyCR。如需更多信息,请参阅 为特定区创建TopologyCR。 -
您已创建了
TopologyCR,将 pod 分散到所有区中。如需更多信息,请参阅创建将 pod 分散到所有区的TopologyCR。
流程
在工作站上创建一个名为
distributed_control_plane.yaml的文件,以定义OpenStackControlPlaneCR:apiVersion: core.openstack.org/v1beta1 kind: OpenStackControlPlane metadata: name: distributed-control-plane namespace: openstack指定在创建时的服务 pod 会在分布式区环境中的区间分布:
apiVersion: core.openstack.org/v1beta1 kind: OpenStackControlPlane metadata: name: distributed-control-plane namespace: openstack spec: topologyRef: name: spread-pods指定您在为 OpenShift 服务提供安全访问 Red Hat OpenStack Services 时创建的
SecretCR:spec: ... secret: osp-secret指定您为 Red Hat OpenShift Container Platform (RHOCP)集群存储后端创建的
storageClass:spec: ... storageClass: <RHOCP_storage_class>-
将
<RHOCP_storage_class> 替换为您为 RHOCP 集群存储后端创建的存储类。有关存储类的详情,请参考 创建存储类。
-
将
如果使用 Red Hat Ceph Storage,请定义需要访问 Red Hat Ceph Storage secret 的区和服务:
extraMounts: - extraVol: - extraVolType: Ceph mounts: - mountPath: /etc/ceph name: ceph-az1 readOnly: true propagation: - az1 volumes: - name: ceph-az1 projected: sources: - secret: name: ceph-conf-files-az1 - extraVolType: Ceph mounts: - mountPath: /etc/ceph name: ceph-az2 readOnly: true propagation: - az2 volumes: - name: ceph-az2 projected: sources: - secret: name: ceph-conf-files-az2 - extraVolType: Ceph mounts: - mountPath: /etc/ceph name: ceph-az3 readOnly: true propagation: - az3 volumes: - name: ceph-az3 projected: sources: - secret: name: ceph-conf-files-az3配置块存储服务(cinder)。
如果您在 Red Hat Ceph Storage 中使用块存储服务,请添加以下配置:在本例中,您可以使用 Red Hat Ceph Storage 在三个 AZ 中配置
cinderVolumes:cinder: template: customServiceConfig: | [DEFAULT] storage_availability_zone = az1,az2,az3 databaseInstance: openstack secret: osp-secret cinderAPI: replicas: 3 override: service: internal: metadata: annotations: metallb.universe.tf/address-pool: internalapi metallb.universe.tf/allow-shared-ip: internalapi metallb.universe.tf/loadBalancerIPs: 172.17.0.80 spec: type: LoadBalancer cinderScheduler: replicas: 1 cinderVolumes: az1: customServiceConfig: | [DEFAULT] enabled_backends = ceph glance_api_servers = https://glance-az1-internal.openstack.svc:9292 [ceph] volume_backend_name = ceph volume_driver = cinder.volume.drivers.rbd.RBDDriver rbd_ceph_conf = /etc/ceph/az1.conf rbd_user = openstack rbd_pool = volumes rbd_flatten_volume_from_snapshot = False rbd_secret_uuid = 7fd06e2a-a3e4-49fa-980c-1ed0865d2886 rbd_cluster_name = az1 backend_availability_zone = az1 topologyRef: name: zone1-node-affinity networkAttachments: - storage replicas: 1 az2: customServiceConfig: | [DEFAULT] enabled_backends = ceph glance_api_servers = https://glance-az2-internal.openstack.svc:9292 [ceph] volume_backend_name = ceph volume_driver = cinder.volume.drivers.rbd.RBDDriver rbd_ceph_conf = /etc/ceph/az2.conf rbd_user = openstack rbd_pool = volumes rbd_flatten_volume_from_snapshot = False rbd_secret_uuid = d4596afb-43f2-4e5d-a204-bc38a3485dc3 rbd_cluster_name = az2 backend_availability_zone = az2 topologyRef: name: zone2-node-affinity networkAttachments: - storage replicas: 1 az3: customServiceConfig: | [DEFAULT] enabled_backends = ceph glance_api_servers = https://glance-az3-internal.openstack.svc:9292 [ceph] volume_backend_name = ceph volume_driver = cinder.volume.drivers.rbd.RBDDriver rbd_ceph_conf = /etc/ceph/az3.conf rbd_user = openstack rbd_pool = volumes rbd_flatten_volume_from_snapshot = False rbd_secret_uuid = 1c348616-c493-4369-91f2-a55e4f404fbe rbd_cluster_name = az3 backend_availability_zone = az3 topologyRef: name: zone3-node-affinity networkAttachments: - storage replicas: 1 ...如果您将块存储服务与第三方存储搭配使用,请添加以下配置:在本例中,您可以使用 NetApp 在三个 AZ 中配置
cinderVolumes:cinder: apiOverride: route: haproxy.router.openshift.io/timeout: 60s template: customServiceConfig: | [DEFAULT] storage_availability_zone = az1 cinderAPI: override: service: internal: metadata: annotations: metallb.universe.tf/address-pool: internalapi metallb.universe.tf/allow-shared-ip: internalapi metallb.universe.tf/loadBalancerIPs: 172.17.0.80 spec: type: LoadBalancer replicas: 3 cinderScheduler: replicas: 1 cinderVolumes: ontap-iscsi-az1: customServiceConfig: | [DEFAULT] glance_api_servers = https://glance-az1-internal.openstack.svc:9292 [ontap-az1] backend_availability_zone = az1 volume_backend_name=ontap-az1 volume_driver=cinder.volume.drivers.netapp.common.NetAppDriver netapp_server_hostname=10.0.0.5 netapp_server_port=80 netapp_storage_protocol=iscsi netapp_storage_family=ontap_cluster consistencygroup_support=True customServiceConfigSecrets: - cinder-volume-secrets-az1 topologyRef: name: azone-node-affinity ontap-iscsi-az2: customServiceConfig: | [DEFAULT] glance_api_servers = https://glance-az2-internal.openstack.svc:9292 [ontap-az2] backend_availability_zone = az2 volume_backend_name=ontap-az2 volume_driver=cinder.volume.drivers.netapp.common.NetAppDriver netapp_server_hostname=10.0.0.6 netapp_server_port=80 netapp_storage_protocol=iscsi netapp_storage_family=ontap_cluster consistencygroup_support=True customServiceConfigSecrets: - cinder-volume-secrets-az2 topologyRef: name: bzone-node-affinity ontap-iscsi-az3: customServiceConfig: | [DEFAULT] glance_api_servers = https://glance-az3-internal.openstack.svc:9292 [ontap-az3] backend_availability_zone = az3 volume_backend_name=ontap-az3 volume_driver=cinder.volume.drivers.netapp.common.NetAppDriver netapp_server_hostname=10.0.0.7 netapp_server_port=80 netapp_storage_protocol=iscsi netapp_storage_family=ontap_cluster consistencygroup_support=True customServiceConfigSecrets: - cinder-volume-secrets-az3 topologyRef: name: czone-node-affinity databaseInstance: openstack preserveJobs: false secret: osp-secret ...
配置块存储备份服务。
注意cinderBackup参数(单数)已弃用。使用cinderBackups(复数)在可用区间配置多个备份实例。如果需要从
cinderBackup迁移到cinderBackups,请参阅 配置持久性存储 中的 配置块存储备份服务。https://docs.redhat.com/en/documentation/red_hat_openstack_services_on_openshift/18.0/html/configuring_persistent_storage/assembly_configuring-the-block-storage-backup-service_block-storage-backup如果使用 Red Hat Ceph Storage,请添加
cinderBackups参数,为每个 AZ 配置块存储备份服务:cinder: template: ... cinderVolumes: ... cinderBackup: replicas: 0 cinderBackups: az1: customServiceConfig: | [DEFAULT] storage_availability_zone = az1 backup_driver = cinder.backup.drivers.ceph.CephBackupDriver backup_ceph_pool = backup-az1 backup_ceph_user = openstack topologyRef: name: zone1-node-affinity networkAttachments: - storage replicas: 2 az2: customServiceConfig: | [DEFAULT] storage_availability_zone = az2 backup_driver = cinder.backup.drivers.ceph.CephBackupDriver backup_ceph_pool = backup-az2 backup_ceph_user = openstack topologyRef: name: zone2-node-affinity networkAttachments: - storage replicas: 2 az3: customServiceConfig: | [DEFAULT] storage_availability_zone = az3 backup_driver = cinder.backup.drivers.ceph.CephBackupDriver backup_ceph_pool = backup-az3 backup_ceph_user = openstack topologyRef: name: zone3-node-affinity networkAttachments: - storage replicas: 2 ...如果您使用第三方存储,请添加
cinderBackups参数,为每个 AZ 配置块存储备份服务。在这个示例中,您使用 NFS 备份驱动程序:cinder: template: ... cinderVolumes: ... cinderBackup: replicas: 0 cinderBackups: az1: customServiceConfig: | [DEFAULT] backup_share = <nfs_server_ip>:<nfs_mount_path> backup_driver = cinder.backup.drivers.nfs.NFSBackupDriver backup_mount_point_base = /var/lib/cinder/backup storage_availability_zone = az1 topologyRef: name: zone1-node-affinity networkAttachments: - storage replicas: 2 az2: customServiceConfig: | [DEFAULT] backup_share = <nfs_server_ip>:<nfs_mount_path> backup_driver = cinder.backup.drivers.nfs.NFSBackupDriver backup_mount_point_base = /var/lib/cinder/backup storage_availability_zone = az2 topologyRef: name: zone2-node-affinity networkAttachments: - storage replicas: 2 az3: customServiceConfig: | [DEFAULT] backup_share = <nfs_server_ip>:<nfs_mount_path> backup_driver = cinder.backup.drivers.nfs.NFSBackupDriver backup_mount_point_base = /var/lib/cinder/backup storage_availability_zone = az3 topologyRef: name: zone3-node-affinity networkAttachments: - storage replicas: 2 ...其中:
- <nfs_server_ip>:<nfs_mount_path>
指定备份存储库的 NFS 服务器 IP 地址和挂载路径。例如:
10.0.0.2:/data/cinderbackup-az1。为每个可用区的 NFS 服务器配置替换。您可以自定义其他备份选项。如需更多信息,请参阅 配置持久性存储中的备份存储后端 。
配置 Compute 服务(nova):
nova: template: apiServiceTemplate: replicas: 3 override: service: internal: metadata: annotations: metallb.universe.tf/address-pool: internalapi metallb.universe.tf/allow-shared-ip: internalapi metallb.universe.tf/loadBalancerIPs: 172.17.0.80 spec: type: LoadBalancer metadataServiceTemplate: replicas: 3 override: service: metadata: annotations: metallb.universe.tf/address-pool: internalapi metallb.universe.tf/allow-shared-ip: internalapi metallb.universe.tf/loadBalancerIPs: 172.17.0.80 spec: type: LoadBalancer schedulerServiceTemplate: replicas: 3 cellTemplates: cell0: cellDatabaseAccount: nova-cell0 cellDatabaseInstance: openstack cellMessageBusInstance: rabbitmq hasAPIAccess: true cell1: cellDatabaseAccount: nova-cell1 cellDatabaseInstance: openstack-cell1 cellMessageBusInstance: rabbitmq-cell1 conductorServiceTemplate: replicas: 1 noVNCProxyServiceTemplate: enabled: true networkAttachments: - ctlplane hasAPIAccess: true secret: osp-secret为数据平面配置 DNS 服务:
dns: template: options: - key: server values: - <IP address for DNS server reachable from dnsmasq pod> override: service: metadata: annotations: metallb.universe.tf/address-pool: ctlplane metallb.universe.tf/allow-shared-ip: ctlplane metallb.universe.tf/loadBalancerIPs: 192.168.122.80 spec: type: LoadBalancer replicas: 2-
选项:利用键值对定义每个 DNS 服务器所需的dnsmasq实例。在本例中,定义了一个键值对,因为只有一个 DNS 服务器配置为将请求转发到。 Key: 指定为部署的dnsmasq实例自定义dnsmasq参数。设置为以下有效值之一:-
server -
rev-server -
srv-host -
txt-record -
ptr-record -
rebind-domain-ok -
naptr-record -
CNAME -
host-record -
caa-record -
dns-rr -
auth-zone -
synth-domain -
no-negcache -
local
-
值:指定 DNS 服务器的值,可从 RHOCP 集群网络上的dnsmasq容器集访问。您可以将通用 DNS 服务器指定为值,如1.1.1.1或特定域的 DNS 服务器,例如/google.com/8.8.8.8。注意此 DNS 服务
dnsmasq为 RHOSO 数据平面上的节点提供 DNS 服务。dnsmasq与 RHOSO DNS 服务(指定)不同,它为云租户提供 DNS 服务。
-
配置 Identity 服务(keystone):
keystone: template: override: service: internal: metadata: annotations: metallb.universe.tf/address-pool: internalapi metallb.universe.tf/allow-shared-ip: internalapi metallb.universe.tf/loadBalancerIPs: 172.17.0.80 spec: type: LoadBalancer databaseInstance: openstack secret: osp-secret replicas: 3配置镜像服务(glance)。
如果您将镜像服务与 Red Hat Ceph Storage 搭配使用,请配置以下内容:
glance: template: databaseInstance: openstack glanceAPIs: az1: customServiceConfig: | [DEFAULT] enabled_import_methods = [web-download,copy-image,glance-direct] enabled_backends = az1:rbd [glance_store] default_backend = az1 [az1] rbd_store_ceph_conf = /etc/ceph/az1.conf store_description = "az1 RBD backend" rbd_store_pool = images rbd_store_user = openstack rbd_thin_provisioning = True networkAttachments: - storage override: service: internal: metadata: annotations: metallb.universe.tf/address-pool: internalapi metallb.universe.tf/allow-shared-ip: internalapi metallb.universe.tf/loadBalancerIPs: 172.17.0.81 spec: type: LoadBalancer replicas: 2 topologyRef: name: zone1-node-affinity type: edge az2: customServiceConfig: | [DEFAULT] enabled_import_methods = [web-download,copy-image,glance-direct] enabled_backends = az1:rbd,az2:rbd [glance_store] default_backend = az2 [az2] rbd_store_ceph_conf = /etc/ceph/az2.conf store_description = "az2 RBD backend" rbd_store_pool = images rbd_store_user = openstack rbd_thin_provisioning = True [az1] rbd_store_ceph_conf = /etc/ceph/az1.conf store_description = "az1 RBD backend" rbd_store_pool = images rbd_store_user = openstack rbd_thin_provisioning = True networkAttachments: - storage override: service: internal: metadata: annotations: metallb.universe.tf/address-pool: internalapi metallb.universe.tf/allow-shared-ip: internalapi metallb.universe.tf/loadBalancerIPs: 172.17.0.82 spec: type: LoadBalancer replicas: 2 topologyRef: name: zone2-node-affinity type: edge az3: customServiceConfig: | [DEFAULT] enabled_import_methods = [web-download,copy-image,glance-direct] enabled_backends = az1:rbd,az3:rbd [glance_store] default_backend = az3 [az3] rbd_store_ceph_conf = /etc/ceph/az3.conf store_description = "az3 RBD backend" rbd_store_pool = images rbd_store_user = openstack rbd_thin_provisioning = True [az1] rbd_store_ceph_conf = /etc/ceph/az1.conf store_description = "az1 RBD backend" rbd_store_pool = images rbd_store_user = openstack rbd_thin_provisioning = True networkAttachments: - storage override: service: internal: metadata: annotations: metallb.universe.tf/address-pool: internalapi metallb.universe.tf/allow-shared-ip: internalapi metallb.universe.tf/loadBalancerIPs: 172.17.0.83 spec: type: LoadBalancer replicas: 2 topologyRef: name: zone3-node-affinity type: edge default: customServiceConfig: | [DEFAULT] enabled_import_methods = [web-download,copy-image,glance-direct] enabled_backends = az1:rbd,az2:rbd,az3:rbd [glance_store] default_backend = az1 [az1] rbd_store_ceph_conf = /etc/ceph/az1.conf store_description = "az1 RBD backend" rbd_store_pool = images rbd_store_user = openstack rbd_thin_provisioning = True [az2] rbd_store_ceph_conf = /etc/ceph/az2.conf store_description = "az2 RBD backend" rbd_store_pool = images rbd_store_user = openstack rbd_thin_provisioning = True [az3] rbd_store_ceph_conf = /etc/ceph/az3.conf store_description = "az3 RBD backend" rbd_store_pool = images rbd_store_user = openstack rbd_thin_provisioning = True networkAttachments: - storage override: service: internal: metadata: annotations: metallb.universe.tf/address-pool: internalapi metallb.universe.tf/allow-shared-ip: internalapi metallb.universe.tf/loadBalancerIPs: 172.17.0.80 spec: type: LoadBalancer replicas: 3 type: split keystoneEndpoint: default storage: storageClass: local-storage storageRequest: 10G uniquePodNames: true如果您将镜像服务与第三方存储搭配使用,请配置以下内容:在本例中,您有三个 AZ,您使用块存储服务作为镜像服务的后端。您可以为每个 AZ 创建单独的
glanceAPI服务器集,它使用多存储写入多个块存储服务后端。如果将 multistore 配置为使用块存储服务作为其后端,则必须在创建分布式 control plane 时为
cinder-volume服务创建卷类型。请参阅第 25 步以完成此配置。本例使用块存储服务 iSCSI 来存储镜像服务镜像,它可以支持多路径,以及
cinder_use_multipath和cinder_do_extend_attached等多路径选项。如果您正在使用的存储协议或者您的环境不支持多路径,请不要使用这些选项。glanceAPIs: az1: customServiceConfig: | [DEFAULT] enabled_backends = az1:cinder enabled_import_methods = [web-download,copy-image,glance-direct] [glance_store] default_backend = az1 [az1] store_description = AZ1 NetApp iscsi cinder backend cinder_store_auth_address = {{ .KeystoneInternalURL }} cinder_store_user_name = {{ .ServiceUser }} cinder_store_password = {{ .ServicePassword }} cinder_store_project_name = service cinder_catalog_info = volumev3::internalURL cinder_use_multipath = true cinder_do_extend_attached = true cinder_volume_type = glance-ontap-az1 networkAttachments: - storage override: service: internal: metadata: annotations: metallb.universe.tf/address-pool: internalapi metallb.universe.tf/allow-shared-ip: internalapi metallb.universe.tf/loadBalancerIPs: 172.17.0.81 spec: type: LoadBalancer replicas: 2 topologyRef: name: azone-node-affinity type: edge az2: customServiceConfig: | [DEFAULT] enabled_backends = az1:cinder,az2:cinder [glance_store] default_backend = az2 [az2] store_description = AZ2 NetApp iscsi cinder backend cinder_store_auth_address = {{ .KeystoneInternalURL }} cinder_store_user_name = {{ .ServiceUser }} cinder_store_password = {{ .ServicePassword }} cinder_store_project_name = service cinder_catalog_info = volumev3::internalURL cinder_use_multipath = true cinder_do_extend_attached = true cinder_volume_type = glance-ontap-az2 [az1] store_description = AZ1 NetApp iscsi cinder backend cinder_store_auth_address = {{ .KeystoneInternalURL }} cinder_store_user_name = {{ .ServiceUser }} cinder_store_password = {{ .ServicePassword }} cinder_store_project_name = service cinder_catalog_info = volumev3::internalURL cinder_use_multipath = true cinder_do_extend_attached = true cinder_volume_type = glance-ontap-az1 networkAttachments: - storage override: service: internal: metadata: annotations: metallb.universe.tf/address-pool: internalapi metallb.universe.tf/allow-shared-ip: internalapi metallb.universe.tf/loadBalancerIPs: 172.17.0.82 spec: type: LoadBalancer replicas: 2 topologyRef: name: bzone-node-affinity type: edge az3: customServiceConfig: | [DEFAULT] enabled_backends = az1:cinder,az3:cinder [glance_store] default_backend = az3 [az3] store_description = AZ3 NetApp iscsi cinder backend cinder_store_auth_address = {{ .KeystoneInternalURL }} cinder_store_user_name = {{ .ServiceUser }} cinder_store_password = {{ .ServicePassword }} cinder_store_project_name = service cinder_catalog_info = volumev3::internalURL cinder_use_multipath = true cinder_do_extend_attached = true cinder_volume_type = glance-ontap-az3 [az1] store_description = AZ1 NetApp iscsi cinder backend cinder_store_auth_address = {{ .KeystoneInternalURL }} cinder_store_user_name = {{ .ServiceUser }} cinder_store_password = {{ .ServicePassword }} cinder_store_project_name = service cinder_catalog_info = volumev3::internalURL cinder_use_multipath = true cinder_do_extend_attached = true cinder_volume_type = glance-ontap-az1 networkAttachments: - storage override: service: internal: metadata: annotations: metallb.universe.tf/address-pool: internalapi metallb.universe.tf/allow-shared-ip: internalapi metallb.universe.tf/loadBalancerIPs: 172.17.0.83 spec: type: LoadBalancer replicas: 2 topologyRef: name: czone-node-affinity type: edge default: customServiceConfig: | [DEFAULT] enabled_backends = az1:cinder,az2:cinder,az3:cinder [glance_store] default_backend = az1 [az1] store_description = AZ1 NetApp iscsi cinder backend cinder_store_auth_address = {{ .KeystoneInternalURL }} cinder_store_user_name = {{ .ServiceUser }} cinder_store_password = {{ .ServicePassword }} cinder_store_project_name = service cinder_catalog_info = volumev3::internalURL cinder_use_multipath = true cinder_do_extend_attached = true cinder_volume_type = glance-ontap-az1 [az2] store_description = AZ2 NetApp iscsi cinder backend cinder_store_auth_address = {{ .KeystoneInternalURL }} cinder_store_user_name = {{ .ServiceUser }} cinder_store_password = {{ .ServicePassword }} cinder_store_project_name = service cinder_catalog_info = volumev3::internalURL cinder_use_multipath = true cinder_do_extend_attached = true cinder_volume_type = glance-ontap-az2 [az3] store_description = AZ3 NetApp iscsi cinder backend cinder_store_auth_address = {{ .KeystoneInternalURL }} cinder_store_user_name = {{ .ServiceUser }} cinder_store_password = {{ .ServicePassword }} cinder_store_project_name = service cinder_catalog_info = volumev3::internalURL cinder_use_multipath = true cinder_do_extend_attached = true cinder_volume_type = glance-ontap-az3
配置密钥管理服务(barbican):
barbican: template: databaseInstance: openstack secret: osp-secret barbicanAPI: replicas: 3 override: service: internal: metadata: annotations: metallb.universe.tf/address-pool: internalapi metallb.universe.tf/allow-shared-ip: internalapi metallb.universe.tf/loadBalancerIPs: 172.17.0.80 spec: type: LoadBalancer barbicanWorker: replicas: 3 barbicanKeystoneListener: replicas: 1配置网络服务(neutron):
neutron: template: customServiceConfig: | [DEFAULT] vlan_transparent = true debug = true [ovs] igmp_snooping_enable = true databaseInstance: openstack networkAttachments: - internalapi override: service: internal: metadata: annotations: metallb.universe.tf/address-pool: internalapi metallb.universe.tf/allow-shared-ip: internalapi metallb.universe.tf/loadBalancerIPs: 172.17.0.80 spec: type: LoadBalancer replicas: 3 secret: osp-secret确保 Object Storage 服务(swift)已禁用:
swift: enabled: false配置 OVN:
ovn: template: ovnDBCluster: ovndbcluster-nb: dbType: NB networkAttachment: internalapi replicas: 3 storageRequest: 10G ovndbcluster-sb: dbType: SB networkAttachment: internalapi replicas: 3 storageRequest: 10G ovnNorthd: networkAttachment: internalapi配置放置服务(placement):
placement: template: override: service: internal: metadata: annotations: metallb.universe.tf/address-pool: internalapi metallb.universe.tf/allow-shared-ip: internalapi metallb.universe.tf/loadBalancerIPs: 172.17.0.80 spec: type: LoadBalancer databaseInstance: openstack replicas: 3 secret: osp-secret配置 Telemetry 服务(ceilometer、prometheus):
telemetry: enabled: true template: metricStorage: enabled: true dashboardsEnabled: true dataplaneNetwork: ctlplane networkAttachments: - ctlplane monitoringStack: alertingEnabled: true scrapeInterval: 30s storage: strategy: persistent retention: 24h persistent: pvcStorageRequest: 20G autoscaling: enabled: false aodh: databaseAccount: aodh databaseInstance: openstack passwordSelector: aodhService: AodhPassword rabbitMqClusterName: rabbitmq serviceUser: aodh secret: osp-secret heatInstance: heat ceilometer: template: passwordSelector: service: CeilometerPassword secret: osp-secret serviceUser: ceilometer logging: enabled: false-
metricStorage.dataplaneNetwork:定义用于提取 dataplanenode_exporter端点的网络。 -
metricStorage.networkAttachments:列出每个服务 pod 附加到的网络。使用NetworkAttachmentDefinition资源名称来指定。您可以为您指定的每个网络附加配置服务的 NIC。如果您没有配置每个服务 pod 附加到的隔离网络,则使用默认 pod 网络。您必须创建一个与指定为dataplaneNetwork的网络匹配的networkAttachment,以便 Prometheus 可以从 dataplane 节点中提取数据。 -
自动缩放:您必须存在autoscaling字段,即使禁用了自动扩展。有关自动扩展的更多信息,请参阅实例自动扩展。
-
配置共享文件系统服务(manila)。
如果您将共享文件系统服务与 Red Hat Ceph Storage 搭配使用,请添加以下配置:
manila: enabled: true template: manilaAPI: customServiceConfig: | [DEFAULT] enabled_share_protocols=nfs,cephfs networkAttachments: - internalapi override: service: internal: metadata: annotations: metallb.universe.tf/address-pool: internalapi metallb.universe.tf/allow-shared-ip: internalapi metallb.universe.tf/loadBalancerIPs: 172.17.0.80 spec: type: LoadBalancer replicas: 3 manilaScheduler: replicas: 3 manilaShares: az1: customServiceConfig: | [DEFAULT] enabled_share_backends = cephfs_az1 enabled_share_protocols = cephfs [cephfs_az1] driver_handles_share_servers = False share_backend_name = cephfs_az1 share_driver = manila.share.drivers.cephfs.driver.CephFSDriver cephfs_conf_path = /etc/ceph/az1.conf cephfs_cluster_name = az1 cephfs_auth_id=openstack cephfs_volume_mode = 0755 cephfs_protocol_helper_type = CEPHFS backend_availability_zone = az1 networkAttachments: - storage replicas: 1 topologyRef: name: zone1-node-affinity az2: customServiceConfig: | [DEFAULT] enabled_share_backends = cephfs_az2 enabled_share_protocols = cephfs [cephfs_az2] driver_handles_share_servers = False share_backend_name = cephfs_az2 share_driver = manila.share.drivers.cephfs.driver.CephFSDriver cephfs_conf_path = /etc/ceph/az2.conf cephfs_cluster_name = az2 cephfs_auth_id=openstack cephfs_volume_mode = 0755 cephfs_protocol_helper_type = CEPHFS backend_availability_zone = az2 networkAttachments: - storage replicas: 1 topologyRef: name: zone2-node-affinity az3: customServiceConfig: | [DEFAULT] enabled_share_backends = cephfs_az3 enabled_share_protocols = cephfs [cephfs_az3] driver_handles_share_servers = False share_backend_name = cephfs_az3 share_driver = manila.share.drivers.cephfs.driver.CephFSDriver cephfs_conf_path = /etc/ceph/az3.conf cephfs_cluster_name = az3 cephfs_auth_id=openstack cephfs_volume_mode = 0755 cephfs_protocol_helper_type = CEPHFS backend_availability_zone = az3 networkAttachments: - storage replicas: 1 topologyRef: name: zone3-node-affinity如果您将共享文件系统服务与第三方存储搭配使用,请配置以下内容:在本例中,您可以使用 NetApp 在三个 AZ 中配置共享文件系统服务。
在以下示例中,
driver_handles_share_servers设置为 True。如果您没有这个选项,则将driver_handles_share_servers字段设置为 False。如需更多信息,请参阅 配置持久性存储 中的 验证分布式 control plane 和 配置 共享文件系统服务(manila)。manila: apiOverride: route: haproxy.router.openshift.io/timeout: 60s enabled: true template: manilaAPI: customServiceConfig: | [DEFAULT] storage_availability_zone = az1,az2,az3 default_share_type = nfs-multiaz enabled_share_protocols=nfs debug = true networkAttachments: - internalapi override: service: internal: metadata: annotations: metallb.universe.tf/address-pool: internalapi metallb.universe.tf/allow-shared-ip: internalapi metallb.universe.tf/loadBalancerIPs: 172.17.0.80 spec: type: LoadBalancer replicas: 3 manilaScheduler: replicas: 3 manilaShares: az1: customServiceConfig: | [DEFAULT] enabled_share_backends = nfs_az1 enabled_share_protocols = nfs [nfs_az1] driver_handles_share_servers = True share_backend_name = nfs_az backend_availability_zone = az1 share_driver=manila.share.drivers.netapp.common.NetAppDriver netapp_storage_family=ontap_cluster netapp_transport_type=http customServiceConfigSecrets: - osp-secret-manila-az1 networkAttachments: - storage replicas: 1 topologyRef: name: azone-node-affinity az2: customServiceConfig: | [DEFAULT] enabled_share_backends = nfs_az2 enabled_share_protocols = nfs [nfs_az2] driver_handles_share_servers = True share_backend_name = nfs_az backend_availability_zone = az2 share_driver=manila.share.drivers.netapp.common.NetAppDriver netapp_storage_family=ontap_cluster netapp_transport_type=http customServiceConfigSecrets: - osp-secret-manila-az2 networkAttachments: - storage replicas: 1 topologyRef: name: bzone-node-affinity az3: customServiceConfig: | [DEFAULT] enabled_share_backends = nfs_az3 enabled_share_protocols = nfs [nfs_az3] driver_handles_share_servers = True share_backend_name = nfs_az backend_availability_zone = az3 share_driver=manila.share.drivers.netapp.common.NetAppDriver netapp_storage_family=ontap_cluster netapp_transport_type=http customServiceConfigSecrets: - osp-secret-manila-az3 networkAttachments: - storage replicas: 1 topologyRef: name: czone-node-affinity preserveJobs: false
禁用负载均衡服务(octavia),因为在 OVN 服务中禁用
enable-chassis-as-gateway时不支持它。如需更多信息,请参阅 OSPRH-10766。octavia: enabled: false配置编排服务(heat):
heat: cnfAPIOverride: route: {} enabled: true template: databaseInstance: openstack heatAPI: override: service: internal: metadata: annotations: metallb.universe.tf/address-pool: internalapi metallb.universe.tf/allow-shared-ip: internalapi metallb.universe.tf/loadBalancerIPs: 172.17.0.80 spec: type: LoadBalancer replicas: 3 heatEngine: override: service: internal: metadata: annotations: metallb.universe.tf/address-pool: internalapi metallb.universe.tf/allow-shared-ip: internalapi metallb.universe.tf/loadBalancerIPs: 172.17.0.80 spec: type: LoadBalancer replicas: 3 secret: osp-secret配置 Dashboard 服务(horizon):
horizon: enabled: true template: replicas: 2 secret: osp-secret添加以下服务配置来实现高可用性(HA):
用于所有 RHOSO 服务(
openstack)的 MariaDB Galera 集群,以及用于 cell1 的 Compute 服务使用的 MariaDB Galera 集群(openstack-):cell1galera: enabled: true templates: openstack: storageRequest: 5000M secret: osp-secret replicas: 3 openstack-cell1: storageRequest: 5000M secret: osp-secret replicas: 3包含三个 memcached 服务器的单个 memcached 集群:
memcached: templates: memcached: replicas: 3用于所有 RHOSO 服务的 RabbitMQ 集群(
rabbitmq)和 RabbitMQ 集群,供计算服务用于cell1(rabbitmq-cell1)使用:rabbitmq: templates: rabbitmq: replicas: 3 override: service: metadata: annotations: metallb.universe.tf/address-pool: internalapi metallb.universe.tf/loadBalancerIPs: 172.17.0.85 spec: type: LoadBalancer rabbitmq-cell1: replicas: 3 override: service: metadata: annotations: metallb.universe.tf/address-pool: internalapi metallb.universe.tf/loadBalancerIPs: 172.17.0.86 spec: type: LoadBalancer注意您不能在同一虚拟 IP (VIP)地址上配置多个 RabbitMQ 实例,因为所有 RabbitMQ 实例都使用相同的端口。如果您需要将多个 RabbitMQ 实例公开给同一网络,则必须使用不同的 IP 地址。
创建 control plane:
$ oc create -f distributed_control_plane.yaml -n openstack等待 RHOCP 创建与
OpenStackControlPlaneCR 相关的资源。运行以下命令来检查状态:$ oc get openstackcontrolplane -n openstack NAME STATUS MESSAGE distributed-control-plane Unknown Setup started当状态为 "Setup complete" 时,会创建
OpenStackControlPlane资源。提示将
-w选项附加到get命令的末尾,以跟踪部署进度。注意创建 control plane 还会创建一个
OpenStackClientpod,您可以通过远程 shell (rsh)访问以运行 OpenStack CLI 命令。$ oc rsh -n openstack openstackclient可选:通过查看
openstack命名空间中的 pod 确认部署了 control plane:$ oc get pods -n openstack当所有 pod 都已完成或运行时,会部署 control plane。
如果您将镜像服务与第三方存储搭配使用,并且将多存储配置为使用块存储服务作为其后端,则每个
glance存储都指定了唯一的cinder_volume_type。您可以使用-private 选项创建卷类型,以防止它们暴露给云用户。要允许镜像服务访问这些卷类型,您可以将每种类型的-project设置为服务项目 ID。打开与
OpenStackClientpod 的远程 shell 连接:$ oc rsh -n openstack openstackclient识别服务项目 ID:
$ sh-5.1$ openstack project list +----------------------------------+---------+ | ID | Name | +----------------------------------+---------+ | 439f0ee839144b4c8640b9153a596a30 | admin | | 7a8946c6ec7c4d0488c592f0306eaa35 | service | +----------------------------------+---------+ $ sh-5.1$将镜像服务的服务用户项目 ID 存储在 shell 变量中:
$ SERVICE_PROJECT_ID=$(openstack project show service -c id -f value)为每个 AZ 中的三个 cinder-volume 服务创建一个类型。设置其项目 ID 和 AZ。使用 spec 键
RESKEY:availability_zones将 AZ 传递给块存储服务,即使镜像服务仅在请求卷时传递类型:$ openstack volume type create --private --project "$SERVICE_PROJECT_ID" --property "RESKEY:availability_zones=az1" glance-ontap-az1 $ openstack volume type create --private --project "$SERVICE_PROJECT_ID" --property "RESKEY:availability_zones=az2" glance-ontap-az2 $ openstack volume type create --private --project "$SERVICE_PROJECT_ID" --property "RESKEY:availability_zones=az3" glance-ontap-az3退出
openstackclientpod:$ exit