CentOS7 minimal openstack pike 环境搭建教程

注:controller节点是 192.168.0.201compute节点是 192.168.0.202

0. 关防火墙(所有节点)

0. 固定ip(所有节点)

1. 配置hostshostname(controllercompute节点)

  1. vi /etc/hostname(controller 节点)
controller
  1. vi /etc/hostname(compute 节点)
compute
  1. vi /etc/hostscontrollercompute节点)
192.168.0.201 controller
192.168.0.202 compute

2. 配置 NTP(controllercompute节点)

  • controller节点配置
  1. 下载:yum install chrony
  2. 配置:vi /etc/chrony.conf
allow 192.168.0.0/24
server ntp1.aliyun.com iburst
  1. 启动
    systemctl enable chronyd.service
    systemctl start chronyd.service
  2. 验证
    chronyc sources
    image.png
  • compute节点配置
  1. 下载:yum install chrony
  2. 配置:vi /etc/chrony.conf(删除所有内容)
server controller iburst

  1. 启动
    systemctl enable chronyd.service
    systemctl start chronyd.service
  2. 验证
    chronyc sources
    image.png

3. 换阿里源(所有节点)注:本操作跳过

  1. 备份
    mv /etc/yum.repos.d/CentOS-Base.repo /etc/yum.repos.d/CentOS-Base.repo_bak
  2. 获取阿里源文件
    wget -O /etc/yum.repos.d/CentOS-Base.repo http://mirrors.aliyun.com/repo/Centos-7.repo
  3. 更新cache
    yum makecache
  4. 更新
    yum -y update

4. 安装 openstack 包(所有节点)

注:如果无法 yum 没有找到包,那么可以换源


  1. 下载 pike
    yum install centos-release-openstack-pike
  2. 下载 queens
    yum install centos-release-openstack-queens
  3. 更新
    yum upgrade
  4. 下载 openstackclient
    yum install python-openstackclient
  5. 下载 selinux
    yum install openstack-selinux

4. 安装 sql (仅controller节点)

  1. 下载mariadb
    yum install mariadb mariadb-server python2-PyMySQL
  2. 创建 openstack.cnf
    vi /etc/my.cnf.d/openstack.cnf
[mysqld]
bind-address = 192.168.0.201
default-storage-engine = innodb
innodb_file_per_table
max_connections = 4096
collation-server = utf8_general_ci
character-set-server = utf8
  1. 启动
    systemctl enable mariadb.service
    systemctl start mariadb.service
  2. 修改密码
    登录:mysql -u root mysql
    修改密码:UPDATE user SET PASSWORD=PASSWORD('123456') where USER='root';
    立即刷新:FLUSH PRIVILEGES;
    退出:quit

5. 安装rabbitmq(仅controller节点)

  1. 下载
    yum install rabbitmq-server
  2. 启动

systemctl enable rabbitmq-server.service
systemctl start rabbitmq-server.service

  1. 添加 openstack 用户
    rabbitmqctl add_user openstack 123456
  2. 添加权限
    rabbitmqctl set_permissions openstack ".*" ".*" ".*"

5. 安装memcached(仅controller节点)

  1. 下载
    yum install memcached python-memcached
  2. 配置
    vi /etc/sysconfig/memcached
OPTIONS="-l 127.0.0.1,::1,controller"
  1. 启动
    systemctl enable memcached.service
    systemctl start memcached.service

6. 安装Etcd(仅controller节点) 这是一个分布式的可靠键值存储,用于分布式密钥锁定、存储配置、跟踪服务的实时状态和其他场景

  1. 下载

yum install etcd

  1. 配置
    vi /etc/etcd/etcd.conf
#[Member]
ETCD_DATA_DIR="/var/lib/etcd/default.etcd"
ETCD_LISTEN_PEER_URLS="http://192.168.0.201:2380"
ETCD_LISTEN_CLIENT_URLS="http://192.168.0.201:2379"
ETCD_NAME="controller"
#[Clustering]
ETCD_INITIAL_ADVERTISE_PEER_URLS="http://192.168.0.201:2380"
ETCD_ADVERTISE_CLIENT_URLS="http://192.168.0.201:2379"
ETCD_INITIAL_CLUSTER="controller=http://192.168.0.201:2380"
ETCD_INITIAL_CLUSTER_TOKEN="etcd-cluster-01"
ETCD_INITIAL_CLUSTER_STATE="new"
  1. 启动
    systemctl enable etcd
    systemctl start etcd

7. 身份服务(仅controller节点)

  • 数据库
  1. 登录 mysql -uroot -p123456

注:如果显示 1045报错,那么执行以下操作
停服务:systemctl stop mariadb.service
启动服务:mysqld_safe --user=mysql --skip-grant-tables --skip-networking &
登录:mysql -u root mysql
改密码:UPDATE user SET PASSWORD=PASSWORD('123456') where USER='root';
FLUSH PRIVILEGES;
退出:quit

  1. 创建数据库 keystone
    CREATE DATABASE keystone;
    GRANT ALL PRIVILEGES ON keystone.* TO 'keystone'@'localhost' IDENTIFIED BY '123456';
    GRANT ALL PRIVILEGES ON keystone.* TO 'keystone'@'controller' IDENTIFIED BY '123456';
    GRANT ALL PRIVILEGES ON keystone.* TO 'keystone'@'%' IDENTIFIED BY '123456';
  • 下载和配置
  1. 下载
    yum install openstack-keystone httpd mod_wsgi
  2. 配置
    vi /etc/keystone/keystone.conf
[database]
...
connection = mysql+pymysql://keystone:123456@controller/keystone

[token]
...
provider = fernet
  1. 创建数据库
    su -s /bin/sh -c "keystone-manage db_sync" keystone
  2. 初始化Fernet密钥存储库:
    keystone-manage fernet_setup --keystone-user keystone --keystone-group keystone
    keystone-manage credential_setup --keystone-user keystone --keystone-group keystone
  3. 初始化身份服务
    keystone-manage bootstrap --bootstrap-password 123456 --bootstrap-admin-url http://controller:35357/v3/ --bootstrap-internal-url http://controller:5000/v3/ --bootstrap-public-url http://controller:5000/v3/ --bootstrap-region-id RegionOne
  4. 配置 httpd
    配置:vi /etc/httpd/conf/httpd.conf
ServerName controller

创建linkln -s /usr/share/keystone/wsgi-keystone.conf /etc/httpd/conf.d/

  1. 启动服务
    systemctl enable httpd.service
    systemctl start httpd.service
  2. 登录
    export OS_USERNAME=admin
    export OS_PASSWORD=123456
    export OS_PROJECT_NAME=admin
    export OS_USER_DOMAIN_NAME=Default
    export OS_PROJECT_DOMAIN_NAME=Default
    export OS_AUTH_URL=http://controller:35357/v3
    export OS_IDENTITY_API_VERSION=3
  • 创建 domain, projects, users, and roles
  1. 创建 service project
    openstack project create --domain default --description "Service Project" service
    image.png
  2. 创建 demo project
    openstack project create --domain default --description "Demo Project" demo
    image.png
  3. 创建 demo user:
    openstack user create --domain default --password-prompt demo
    image.png
  4. 创建 user role:
    openstack role create user
    image.png
  5. 关联
    openstack role add --project demo --user demo user
  • 验证
  1. 登出
    unset OS_AUTH_URL OS_PASSWORD
  2. 验证admin
    openstack --os-auth-url http://controller:35357/v3 --os-project-domain-name Default --os-user-domain-name Default --os-project-name admin --os-username admin token issue
    image.png
  3. 验证demo
    openstack --os-auth-url http://controller:5000/v3 --os-project-domain-name Default --os-user-domain-name Default --os-project-name demo --os-username demo token issue
    image.png
  • 创建登录脚本(在root~ 目录下)
    注: 通过 readlink -f ./ 获取当前目录的绝对路径
  1. 创建 admin-openrc
    vi admin-openrc
export OS_PROJECT_DOMAIN_NAME=Default 
export OS_USER_DOMAIN_NAME=Default 
export OS_PROJECT_NAME=admin 
export OS_USERNAME=admin 
export OS_PASSWORD=123456 
export OS_AUTH_URL=http://controller:35357/v3 
export OS_IDENTITY_API_VERSION=3 
export OS_IMAGE_API_VERSION=2 
  1. 创建 demo-openrc
    vi demo-openrc
export OS_PROJECT_DOMAIN_NAME=Default 
export OS_USER_DOMAIN_NAME=Default 
export OS_PROJECT_NAME=demo 
export OS_USERNAME=demo 
export OS_PASSWORD=123456 
export OS_AUTH_URL=http://controller:5000/v3 
export OS_IDENTITY_API_VERSION=3 
export OS_IMAGE_API_VERSION=2 
  1. 验证 admin
    登录:. admin-openrc
    注:登录也可以用source admin-openrc,注意上面是. admin-openrc,不是./admin-openrc
    验证:openstack token issue
    image.png
  2. 查看环境变量
    echo $OS_PROJECT_DOMAIN_NAME $OS_USER_DOMAIN_NAME $OS_PROJECT_NAME $OS_USERNAME $OS_PASSWORD $OS_AUTH_URL $OS_IDENTITY_API_VERSION $OS_IMAGE_API_VERSION
  3. 登出
    unset OS_PROJECT_DOMAIN_NAME OS_USER_DOMAIN_NAME OS_PROJECT_NAME OS_USERNAME OS_PASSWORD OS_AUTH_URL OS_IDENTITY_API_VERSION OS_IMAGE_API_VERSION

8. 镜像服务(仅controller节点)

  • 数据库
  1. 登录
    mysql -uroot -p123456
  2. 创建数据库glance
    CREATE DATABASE glance;
  3. 登录操作权限
    GRANT ALL PRIVILEGES ON glance.* TO 'glance'@'localhost' IDENTIFIED BY '123456';
    GRANT ALL PRIVILEGES ON glance.* TO 'glance'@'controller' IDENTIFIED BY '123456';
    GRANT ALL PRIVILEGES ON glance.* TO 'glance'@'%' IDENTIFIED BY '123456';
  4. 退出 exit
  • 创建 glance
  1. 登录 . admin-openrc
  2. 创建glance user:
    openstack user create --domain default --password-prompt glance
    image.png
  3. 关联
    openstack role add --project service --user glance admin
  4. 创建glance service:
    openstack service create --name glance --description "OpenStack Image" image
    image.png
  5. 创建API
    openstack endpoint create --region RegionOne image public http://controller:9292
    image.png

    openstack endpoint create --region RegionOne image internal http://controller:9292
    image.png

    openstack endpoint create --region RegionOne image admin http://controller:9292
    image.png
  • 下载和配置
  1. 下载
    yum install openstack-glance
  2. 配置
    vi /etc/glance/glance-api.conf
[database]
...
connection = mysql+pymysql://glance:123456@controller/glance

[keystone_authtoken]
...
auth_uri = http://controller:5000
auth_url = http://controller:35357
memcached_servers = controller:11211
auth_type = password
project_domain_name = default
user_domain_name = default
project_name = service
username = glance
password = 123456

[paste_deploy]
...
flavor = keystone

[glance_store]
...
stores = file,http
default_store = file
filesystem_store_datadir = /var/lib/glance/images/
  1. 配置
    vi /etc/glance/glance-registry.conf
[database]
...
connection = mysql+pymysql://glance:123456@controller/glance

[keystone_authtoken]
...
auth_uri = http://controller:5000
auth_url = http://controller:35357
memcached_servers = controller:11211
auth_type = password
project_domain_name = default
user_domain_name = default
project_name = service
username = glance
password = 123456

[paste_deploy]
...
flavor = keystone
  1. 填充数据库
    su -s /bin/sh -c "glance-manage db_sync" glance
  2. 启动
    systemctl enable openstack-glance-api.service openstack-glance-registry.service
    systemctl start openstack-glance-api.service openstack-glance-registry.service
  • 验证
  1. 登录:. admin-openrc
  2. 下载:wget http://download.cirros-cloud.net/0.3.5/cirros-0.3.5-x86_64-disk.img
  3. 上传: openstack image create "cirros" --file cirros-0.3.5-x86_64-disk.img --disk-format qcow2 --container-format bare --public
    image.png
  4. 查看列表
    openstack image list
    image.png

9. 计算服务(controller节点)

  • 数据库
  1. 登录:mysql -uroot -p123456
  2. 创建数据库:
    CREATE DATABASE nova_api;
    CREATE DATABASE nova;
    CREATE DATABASE nova_cell0;
  3. 权限
    GRANT ALL PRIVILEGES ON nova_api.* TO 'nova'@'localhost' IDENTIFIED BY '123456';
    GRANT ALL PRIVILEGES ON nova_api.* TO 'nova'@'controller' IDENTIFIED BY '123456';
    GRANT ALL PRIVILEGES ON nova_api.* TO 'nova'@'%' IDENTIFIED BY '123456';
    GRANT ALL PRIVILEGES ON nova.* TO 'nova'@'localhost' IDENTIFIED BY '123456';
    GRANT ALL PRIVILEGES ON nova.* TO 'nova'@'controller' IDENTIFIED BY '123456';
    GRANT ALL PRIVILEGES ON nova.* TO 'nova'@'%' IDENTIFIED BY '123456';
    GRANT ALL PRIVILEGES ON nova_cell0.* TO 'nova'@'localhost' IDENTIFIED BY '123456';
    GRANT ALL PRIVILEGES ON nova_cell0.* TO 'nova'@'controller' IDENTIFIED BY '123456';
    GRANT ALL PRIVILEGES ON nova_cell0.* TO 'nova'@'%' IDENTIFIED BY '123456';
  4. 退出exit
  • 创建 nova
  1. 登录. admin-openrc
  2. 创建nova user:
    openstack user create --domain default --password-prompt nova
    image.png
  3. 关联
    openstack role add --project service --user nova admin
  4. 创建 nova service
    openstack service create --name nova --description "OpenStack Compute" compute
    image.png
  5. 创建 API
    openstack endpoint create --region RegionOne compute public http://controller:8774/v2.1
    image.png

    openstack endpoint create --region RegionOne compute internal http://controller:8774/v2.1
    image.png

    openstack endpoint create --region RegionOne compute admin http://controller:8774/v2.1
    image.png
  • 创建 placement
  1. 登录. admin-openrc
  2. 创建 placement user
    openstack user create --domain default --password-prompt placement
    image.png
  3. 关联
    openstack role add --project service --user placement admin
  4. 创建API
    openstack service create --name placement --description "Placement API" placement
    image.png

    openstack endpoint create --region RegionOne placement public http://controller:8778
    image.png

    openstack endpoint create --region RegionOne placement internal http://controller:8778
    image.png

    openstack endpoint create --region RegionOne placement admin http://controller:8778
    image.png
  • 下载和配置
  1. 下载:
    yum install openstack-nova-api openstack-nova-conductor openstack-nova-console openstack-nova-novncproxy openstack-nova-scheduler openstack-nova-placement-api
  2. 配置
    vi /etc/nova/nova.conf
[DEFAULT]
...
enabled_apis = osapi_compute,metadata
transport_url = rabbit://openstack:123456@controller
my_ip = 192.168.0.201
use_neutron = True
firewall_driver = nova.virt.firewall.NoopFirewallDriver

[api_database]
...
connection = mysql+pymysql://nova:123456@controller/nova_api

[database]
...
connection = mysql+pymysql://nova:123456@controller/nova

[api]
...
auth_strategy = keystone

[keystone_authtoken]
...
auth_uri = http://controller:5000
auth_url = http://controller:35357
memcached_servers = controller:11211
auth_type = password
project_domain_name = default
user_domain_name = default
project_name = service
username = nova
password = 123456

[vnc]
enabled = true
...
vncserver_listen = $my_ip
vncserver_proxyclient_address = $my_ip

[glance]
...
api_servers = http://controller:9292

[oslo_concurrency]
...
lock_path = /var/lib/nova/tmp

[placement]
...
os_region_name = RegionOne
project_domain_name = Default
project_name = service
auth_type = password
user_domain_name = Default
auth_url = http://controller:35357/v3
username = placement
password = 123456

注:删掉 [placement] [keystone_authtoken]的其他项

  1. 配置
    vi /etc/httpd/conf.d/00-nova-placement-api.conf
...
<Directory /usr/bin>
  <IfVersion >= 2.4>
     Require all granted
  </IfVersion>
  <IfVersion < 2.4>
     Order allow,deny
     Allow from all
  </IfVersion>
</Directory>
  1. 重启 httpd
    systemctl restart httpd
  2. 填充数据库
    su -s /bin/sh -c "nova-manage api_db sync" nova
    su -s /bin/sh -c "nova-manage cell_v2 map_cell0" nova
    su -s /bin/sh -c "nova-manage cell_v2 create_cell --name=cell1 --verbose" nova
    image.png

    su -s /bin/sh -c "nova-manage db sync" nova
  3. 验证 cell0 cell1
    nova-manage cell_v2 list_cells
    image.png
  4. 启动
    systemctl enable openstack-nova-api.service openstack-nova-consoleauth.service openstack-nova-scheduler.service openstack-nova-conductor.service openstack-nova-novncproxy.service

systemctl start openstack-nova-api.service openstack-nova-consoleauth.service openstack-nova-scheduler.service openstack-nova-conductor.service openstack-nova-novncproxy.service

10. 计算服务(compute节点)

  • 下载和配置
  1. 下载
    yum install openstack-nova-compute
  2. 配置
    vi /etc/nova/nova.conf
[DEFAULT]
...
enabled_apis = osapi_compute,metadata
transport_url = rabbit://openstack:123456@controller
my_ip = 192.168.0.202
use_neutron = True
firewall_driver = nova.virt.firewall.NoopFirewallDriver

[api]
...
auth_strategy = keystone

[keystone_authtoken]
...
auth_uri = http://controller:5000
auth_url = http://controller:35357
memcached_servers = controller:11211
auth_type = password
project_domain_name = default
user_domain_name = default
project_name = service
username = nova
password = 123456

[vnc]
...
enabled = True
vncserver_listen = 0.0.0.0
vncserver_proxyclient_address = $my_ip
novncproxy_base_url = http://controller:6080/vnc_auto.html

[glance]
...
api_servers = http://controller:9292

[oslo_concurrency]
...
lock_path = /var/lib/nova/tmp

[placement]
...
os_region_name = RegionOne
project_domain_name = Default
project_name = service
auth_type = password
user_domain_name = Default
auth_url = http://controller:35357/v3
username = placement
password = 123456
  1. 启动
    systemctl enable libvirtd.service openstack-nova-compute.service
    systemctl start libvirtd.service openstack-nova-compute.service

11. 计算服务(controller节点)

  • 添加compute节点到 cell数据库
  1. 登陆:. admin-openrc
  2. 查看:openstack compute service list --service nova-compute
    image.png
  3. 手动注册 compute 节点到 cell数据库 (每次添加新compute节点都需要这个操作)
    su -s /bin/sh -c "nova-manage cell_v2 discover_hosts --verbose" nova
    image.png
  4. 自动注册 compute 节点到 cell数据库(只需要操作一次)
    vi /etc/nova/nova.conf
[scheduler]
discover_hosts_in_cells_interval = 300

注:3 4 操作任选其一

  • 验证
  1. 登陆:. admin-openrc
  2. 查看计算服务列表:openstack compute service list
    image.png
  3. 查看 apiopenstack catalog list
    image.png
  4. 查看镜像列表:openstack image list
    image.png
  5. 检查 cellsplacement API 是否正常工作
    nova-status upgrade check
    image.png

12. 网络服务(controller节点)

  • 数据库
  1. 登陆:mysql -uroot -p123456
  2. 创建neutron
    CREATE DATABASE neutron;
    GRANT ALL PRIVILEGES ON neutron.* TO 'neutron'@'localhost' IDENTIFIED BY '123456';
    GRANT ALL PRIVILEGES ON neutron.* TO 'neutron'@'controller' IDENTIFIED BY '123456';
    GRANT ALL PRIVILEGES ON neutron.* TO 'neutron'@'%' IDENTIFIED BY '123456';
  3. 登出:exit
  • 创建 neutron 用户
  1. 登陆:
    . admin-openrc
  2. 创建 neutron 用户:
    openstack user create --domain default --password-prompt neutron
    image.png
  3. 关联:
    openstack role add --project service --user neutron admin
  4. 创建 neutron service:
    openstack service create --name neutron --description "OpenStack Networking" network
    image.png
  5. 创建 API
    openstack endpoint create --region RegionOne network public http://controller:9696
    image.png

    openstack endpoint create --region RegionOne network internal http://controller:9696
    image.png

    openstack endpoint create --region RegionOne network admin http://controller:9696
    image.png
  • 安装和配置(基于Provider networks)
  1. 安装:
    yum install openstack-neutron openstack-neutron-ml2 openstack-neutron-linuxbridge ebtables
  2. 配置:
    vi /etc/neutron/neutron.conf
[DEFAULT]
...
core_plugin = ml2
service_plugins =
transport_url = rabbit://openstack:123456@controller
auth_strategy = keystone
notify_nova_on_port_status_changes = true
notify_nova_on_port_data_changes = true

[database]
...
connection = mysql+pymysql://neutron:123456@controller/neutron

[keystone_authtoken]
...
auth_uri = http://controller:5000
auth_url = http://controller:35357
memcached_servers = controller:11211
auth_type = password
project_domain_name = default
user_domain_name = default
project_name = service
username = neutron
password = 123456

[nova]
...
auth_url = http://controller:35357
auth_type = password
project_domain_name = default
user_domain_name = default
region_name = RegionOne
project_name = service
username = nova
password = 123456

[oslo_concurrency]
...
lock_path = /var/lib/neutron/tmp
  1. 配置
    vi /etc/neutron/plugins/ml2/ml2_conf.ini
[ml2]
...
type_drivers = flat,vlan
tenant_network_types =
mechanism_drivers = linuxbridge
extension_drivers = port_security

[ml2_type_flat]
...
flat_networks = provider

[securitygroup]
...
enable_ipset = true
  1. 配置
    vi /etc/neutron/plugins/ml2/linuxbridge_agent.ini
[linux_bridge]
physical_interface_mappings = provider:enp3s0

[vxlan]
enable_vxlan = false

[securitygroup]
...
enable_security_group = true
firewall_driver = neutron.agent.linux.iptables_firewall.IptablesFirewallDriver
  1. 配置
    vi /etc/neutron/dhcp_agent.ini
[DEFAULT]
...
interface_driver = linuxbridge
dhcp_driver = neutron.agent.linux.dhcp.Dnsmasq
enable_isolated_metadata = true
  • 配置和启动
  1. 配置
    vi /etc/neutron/metadata_agent.ini
[DEFAULT]
...
nova_metadata_host = controller
metadata_proxy_shared_secret = 123456
  1. 配置
    vi /etc/nova/nova.conf
[neutron]
...
url = http://controller:9696
auth_url = http://controller:35357
auth_type = password
project_domain_name = default
user_domain_name = default
region_name = RegionOne
project_name = service
username = neutron
password = 123456
service_metadata_proxy = true
metadata_proxy_shared_secret = 123456
  1. link
    ln -s /etc/neutron/plugins/ml2/ml2_conf.ini /etc/neutron/plugin.ini
  2. 填充数据库
    su -s /bin/sh -c "neutron-db-manage --config-file /etc/neutron/neutron.conf --config-file /etc/neutron/plugins/ml2/ml2_conf.ini upgrade head" neutron
  3. 重启 API service
    systemctl restart openstack-nova-api.service
  4. 启动

systemctl enable neutron-server.service neutron-linuxbridge-agent.service neutron-dhcp-agent.service neutron-metadata-agent.service

systemctl start neutron-server.service neutron-linuxbridge-agent.service neutron-dhcp-agent.service neutron-metadata-agent.service

13. 网络服务(compute节点)

  • 安装和配置
  1. 下载
    yum install openstack-neutron-linuxbridge ebtables ipset
  2. 配置
    vi /etc/neutron/neutron.conf
[DEFAULT]
...
transport_url = rabbit://openstack:123456@controller
auth_strategy = keystone

[keystone_authtoken]
...
auth_uri = http://controller:5000
auth_url = http://controller:35357
memcached_servers = controller:11211
auth_type = password
project_domain_name = default
user_domain_name = default
project_name = service
username = neutron
password = 123456

[oslo_concurrency]
...
lock_path = /var/lib/neutron/tmp
  • 配置(基于 Provider networks)
  1. 配置
    vi /etc/neutron/plugins/ml2/linuxbridge_agent.ini
[linux_bridge]
physical_interface_mappings = provider:enp3s0

[vxlan]
enable_vxlan = false

[securitygroup]
...
enable_security_group = true
firewall_driver = neutron.agent.linux.iptables_firewall.IptablesFirewallDriver
  • 配置和启动
  1. 配置
    vi /etc/nova/nova.conf
[neutron]
...
url = http://controller:9696
auth_url = http://controller:35357
auth_type = password
project_domain_name = default
user_domain_name = default
region_name = RegionOne
project_name = service
username = neutron
password = 123456
  1. 启动
    systemctl restart openstack-nova-compute.service
    systemctl enable neutron-linuxbridge-agent.service
    systemctl start neutron-linuxbridge-agent.service
  • 验证(Controller 节点)
  1. 登录:. admin-openrc
  2. 查看列表:openstack network agent list
    image.png

14. 仪表盘dashboard(controller节点)

  1. 下载
    yum install openstack-dashboard
  2. 配置
    vi /etc/openstack-dashboard/local_settings
OPENSTACK_HOST = "controller"
OPENSTACK_KEYSTONE_URL = "http://%s:5000/v3" % OPENSTACK_HOST
OPENSTACK_KEYSTONE_DEFAULT_ROLE = "user"

OPENSTACK_KEYSTONE_MULTIDOMAIN_SUPPORT = True

SESSION_ENGINE = 'django.contrib.sessions.backends.cache'
CACHES = {
   'default': {
        'BACKEND': 'django.core.cache.backends.memcached.MemcachedCache',
        'LOCATION': 'controller:11211',
   }
}

OPENSTACK_API_VERSIONS = {
   "identity": 3,
   "image": 2,
   "volume": 2,
}

OPENSTACK_KEYSTONE_DEFAULT_DOMAIN = "Default"

ALLOWED_HOSTS = ['*']

OPENSTACK_NEUTRON_NETWORK = {
   ...
   'enable_router': False,
   'enable_quotas': False,
   'enable_distributed_router': False,
   'enable_ha_router': False,
   'enable_lb': False,
   'enable_firewall': False,
   'enable_vpn': False,
   'enable_fip_topology_check': False,
}

TIME_ZONE = "UTC"
  1. 配置
    vi /etc/httpd/conf.d/openstack-dashboard.conf
...
WSGIApplicationGroup %{GLOBAL}
image.png
  1. 重启
    systemctl restart httpd.service memcached.service
  2. 测试
    http://192.168.0.201/dashboard

15.启动一个实例

  • 创建虚拟网络(基于 provider networks)
  1. 登录. admin-openrc
  2. 创建 network
    openstack network create --share --external --provider-physical-network provider --provider-network-type flat provider
    image.png
  3. 创建子网

openstack subnet create --network provider --allocation-pool start=192.168.0.220,end=192.168.0.229 --dns-nameserver 192.168.0.1 --gateway 192.168.0.1 --subnet-range 192.168.0.0/24 provider

image.png

  • 创建 flavor
  1. 登录. admin-openrc
  2. 创建:
    openstack flavor create --id 0 --vcpus 1 --ram 64 --disk 1 m1.nano
  • 创建 key pair
  1. 登录:. demo-openrc
  2. 创建:
    ssh-keygen -q -N ""
    回车
    openstack keypair create --public-key ~/.ssh/id_rsa.pub mykey
  3. 查看
    openstack keypair list
  • 配置安全组
  1. 登录:. demo-openrc
  2. ICMP
    openstack security group rule create --proto icmp default
  3. SSH
    openstack security group rule create --proto tcp --dst-port 22 default
  • 创建一个 instance
image.png
最后编辑于
©著作权归作者所有,转载或内容合作请联系作者
  • 序言:七十年代末,一起剥皮案震惊了整个滨河市,随后出现的几起案子,更是在滨河造成了极大的恐慌,老刑警刘岩,带你破解...
    沈念sama阅读 193,968评论 5 459
  • 序言:滨河连续发生了三起死亡事件,死亡现场离奇诡异,居然都是意外死亡,警方通过查阅死者的电脑和手机,发现死者居然都...
    沈念sama阅读 81,682评论 2 371
  • 文/潘晓璐 我一进店门,熙熙楼的掌柜王于贵愁眉苦脸地迎上来,“玉大人,你说我怎么就摊上这事。” “怎么了?”我有些...
    开封第一讲书人阅读 141,254评论 0 319
  • 文/不坏的土叔 我叫张陵,是天一观的道长。 经常有香客问我,道长,这世上最难降的妖魔是什么? 我笑而不...
    开封第一讲书人阅读 52,074评论 1 263
  • 正文 为了忘掉前任,我火速办了婚礼,结果婚礼上,老公的妹妹穿的比我还像新娘。我一直安慰自己,他们只是感情好,可当我...
    茶点故事阅读 60,964评论 4 355
  • 文/花漫 我一把揭开白布。 她就那样静静地躺着,像睡着了一般。 火红的嫁衣衬着肌肤如雪。 梳的纹丝不乱的头发上,一...
    开封第一讲书人阅读 46,055评论 1 272
  • 那天,我揣着相机与录音,去河边找鬼。 笑死,一个胖子当着我的面吹牛,可吹牛的内容都是我干的。 我是一名探鬼主播,决...
    沈念sama阅读 36,484评论 3 381
  • 文/苍兰香墨 我猛地睁开眼,长吁一口气:“原来是场噩梦啊……” “哼!你这毒妇竟也来了?” 一声冷哼从身侧响起,我...
    开封第一讲书人阅读 35,170评论 0 253
  • 序言:老挝万荣一对情侣失踪,失踪者是张志新(化名)和其女友刘颖,没想到半个月后,有当地人在树林里发现了一具尸体,经...
    沈念sama阅读 39,433评论 1 290
  • 正文 独居荒郊野岭守林人离奇死亡,尸身上长有42处带血的脓包…… 初始之章·张勋 以下内容为张勋视角 年9月15日...
    茶点故事阅读 34,512评论 2 308
  • 正文 我和宋清朗相恋三年,在试婚纱的时候发现自己被绿了。 大学时的朋友给我发了我未婚夫和他白月光在一起吃饭的照片。...
    茶点故事阅读 36,296评论 1 325
  • 序言:一个原本活蹦乱跳的男人离奇死亡,死状恐怖,灵堂内的尸体忽然破棺而出,到底是诈尸还是另有隐情,我是刑警宁泽,带...
    沈念sama阅读 32,184评论 3 312
  • 正文 年R本政府宣布,位于F岛的核电站,受9级特大地震影响,放射性物质发生泄漏。R本人自食恶果不足惜,却给世界环境...
    茶点故事阅读 37,545评论 3 298
  • 文/蒙蒙 一、第九天 我趴在偏房一处隐蔽的房顶上张望。 院中可真热闹,春花似锦、人声如沸。这庄子的主人今日做“春日...
    开封第一讲书人阅读 28,880评论 0 17
  • 文/苍兰香墨 我抬头看了看天上的太阳。三九已至,却和暖如春,着一层夹袄步出监牢的瞬间,已是汗流浃背。 一阵脚步声响...
    开封第一讲书人阅读 30,150评论 1 250
  • 我被黑心中介骗来泰国打工, 没想到刚下飞机就差点儿被人妖公主榨干…… 1. 我叫王不留,地道东北人。 一个月前我还...
    沈念sama阅读 41,437评论 2 341
  • 正文 我出身青楼,却偏偏与公主长得像,于是被迫代替她去往敌国和亲。 传闻我的和亲对象是个残疾皇子,可洞房花烛夜当晚...
    茶点故事阅读 40,630评论 2 335

推荐阅读更多精彩内容