OpenStack部署(queens版)

运行环境 | centos 7.0 | OpenStack queens | VMware Workstation 15 Pro

主机名 备注 操作系统
controller 控制节点 CentOs7
compute 计算节点 CentOs7
cinder 块存储节点 CentOs7

环境准备

关闭虚拟机防火墙及selinux (controller|compute|cinder 节点配置)

1
2
3
4
5
6
systemctl disable firewalld.service
systemctl stop firewalld.service

vi /etc/sysconfig/selinux
SELINUX=disable
setenforce 0

修改主机名

1
hostnamectl set-hostname <主机名>

修改所有主机hosts文件

1
2
3
4
vi /etc/hosts
192.168.-.- controller
192.168.-.- compute
192.168.-.- cinder

配置阿里云yum源

备份默认yum源

1
mv /etc/yum.repos.d/CentOS-Base.repo /etc/yum.repos.d/CentOS-Base.repo.backup

下载yum源

1
wget -O /etc/yum.repos.d/CentOS-Base.repo http://mirrors.aliyun.com/repo/Centos-7.repo

网络时间协议

1
2
3
4
5
6
7
8
9
10
11
yum install chrony
编辑 `/etc/chrony.conf` 文件,按照你环境的要求,修改或者删除:

server controller iburst
allow 172.16.10.0/24

在所有其他节点执行相同命令
systemctl enable chronyd.service
systemctl start chronyd.service

chronyc sources

安装OpenStack包

1
2
3
4
5
6
7
8
#启用OpenStack仓库的包:
yum install centos-release-openstack-queens -y
#在主机上升级包:
yum upgrade -y
#安装 OpenStack 客户端:
yum install python-openstackclient -y
#RHEL 和 CentOS 默认启用了 SELinux . 安装 openstack-selinux 软件包以便自动管理 OpenStack 服务的安全策略:
yum install openstack-selinux -y

大多数 OpenStack 服务使用 SQL 数据库来存储信息 (controller 节点配置)

1
yum install mariadb mariadb-server python2-PyMySQL -y
1
2
3
4
5
6
7
8
9
10
11
12
13
14
vi /etc/my.cnf.d/mariadb-server.cnf

[mysqld]
datadir=/var/lib/mysql
socket=/var/lib/mysql/mysql.sock
log-error=/var/log/mariadb/mariadb.log
pid-file=/var/run/mariadb/mariadb.pid
#修改为控制节点IP,使其他节点可以通过管理网络访问数据库
bind-address = 控制节点IP
default-storage-engine = innodb
innodb_file_per_table = on
max_connections = 4096
collation-server = utf8_general_ci
character-set-server = utf8
1
2
3
4
5
6
启动数据库服务,并将其配置为开机自启:
systemctl enable mariadb.service
systemctl start mariadb.service

#对数据库进行安全加固
mysql_secure_installation

安装配置Messaging server-RabbitMQ (controller 节点配置)

1
2
3
4
5
6
7
yum install rabbitmq-server -y

#开启服务并设置为开机自启
systemctl enable rabbitmq-server.service
systemctl start rabbitmq-server.service

netstat -ntap | grep 5672

部署memcached服务 (controller 节点配置)

1
2
3
4
5
6
7
8
9
10
yum install memcached python-memcached -y

#修改配置文件
vi /etc/sysconfig/memcached

PORT="11211"
USER="memcached"
MAXCONN="1024"
CACHESIZE="64"
OPTIONS="-l 192.168.-.-,::1"
1
2
3
#开启服务并设置为开机自启
systemctl enable memcached.service
systemctl start memcached.service

部署etcd服务 (controller 节点配置)

  • etcd是一个分布式,一致的键值存储,用于共享配置和服务发现,特点是,安全,具有可选客户端证书身份验证的自动TLS;快速,基准测试10,000次/秒;可靠,使用Raft正确分发。
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
#安装软件
yum install etcd -y

#修改配置文件
vi /etc/etcd/etcd.conf

ETCD_INITIAL_CLUSTER
ETCD_INITIAL_ADVERTISE_PEER_URLS
ETCD_ADVERTISE_CLIENT_URLS
ETCD_LISTEN_CLIENT_URLS
#[Member]
ETCD_DATA_DIR="/var/lib/etcd/default.etcd"
ETCD_LISTEN_PEER_URLS="http://控制节点IP:2380"
ETCD_LISTEN_CLIENT_URLS="http://控制节点IP:2379"
ETCD_NAME="controller"
#[Clustering]
ETCD_INITIAL_ADVERTISE_PEER_URLS="http://控制节点IP:2380"
ETCD_ADVERTISE_CLIENT_URLS="http://控制节点IP:2379"
ETCD_INITIAL_CLUSTER="controller=http://控制节点IP:2380"
ETCD_INITIAL_CLUSTER_TOKEN="etcd-cluster-01"
ETCD_INITIAL_CLUSTER_STATE="new"


#开启服务并设置为开机自启
systemctl enable etcd.service
systemctl start etcd.service

部署keystone认证服务 (controller 节点配置)

  • OpenStack:term:Identity service为认证管理,授权管理和服务目录服务管理提供单点整合。其它OpenStack服务将身份认证服务当做通用统一API来使用。此外,提供用户信息但是不在OpenStack项目中的服务(如LDAP服务)可被整合进先前存在的基础设施中。
    为了从identity服务中获益,其他的OpenStack服务需要与它合作。当某个OpenStack服务收到来自用户的请求时,该服务询问Identity服务,验证该用户是否有权限进行此次请求
    身份服务包含这些组件:
  • 服务器
    一个中心化的服务器使用RESTful 接口来提供认证和授权服务。
  • 驱动
    驱动或服务后端被整合进集中式服务器中。它们被用来访问OpenStack外部仓库的身份信息, 并且它们可能已经存在于OpenStack被部署在的基础设施(例如,SQL数据库或LDAP服务器)中。
  • 模块
    中间件模块运行于使用身份认证服务的OpenStack组件的地址空间中。这些模块拦截服务请求,取出用户凭据,并将它们送入中央是服务器寻求授权。中间件模块和OpenStack组件间的整合使用Python Web服务器网关接口。
    当安装OpenStack身份服务,用户必须将之注册到其OpenStack安装环境的每个服务。身份服务才可以追踪那些OpenStack服务已经安装,以及在网络中定位它们。

在你配置 OpenStack 身份认证服务前,你必须创建一个数据库和管理员令牌。

1
2
3
4
5
6
7
8
mysql -uroot -p****
CREATE DATABASE keystone;
#授权本地登陆
GRANT ALL PRIVILEGES ON keystone.* TO 'keystone'@'localhost' IDENTIFIED BY '*****';
#授权远程登陆
GRANT ALL PRIVILEGES ON keystone.* TO 'keystone'@'%' IDENTIFIED BY '******';
#授权任意地址登陆
FLUSH PRIVILEGES;

安装软件包

1
2
3
4
5
6
7
8
yum install openstack-keystone httpd mod_wsgi -y

vi /etc/keystone/keystone.conf

[database]
connection = mysql+pymysql://keystone:password@controller/keystone
[token]
provider = fernet

同步数据库

1
su -s /bin/sh -c "keystone-manage db_sync" keystone

初始化数据库

1
2
3
4
5
6
7
8
keystone-manage fernet_setup --keystone-user keystone --keystone-group keystone
keystone-manage credential_setup --keystone-user keystone --keystone-group keystone

keystone-manage bootstrap --bootstrap-password password \
--bootstrap-admin-url http://controller:35357/v3/ \
--bootstrap-internal-url http://controller:5000/v3/ \
--bootstrap-public-url http://controller:5000/v3/ \
--bootstrap-region-id RegionOne

配置apache服务

1
2
3
4
5
6
7
8
vi /etc/httpd/conf/httpd.conf

ServerName controller

ln -s /usr/share/keystone/wsgi-keystone.conf /etc/httpd/conf.d/

systemctl enable httpd.service
systemctl start httpd.service

设置环境变量脚本

1
2
3
4
5
6
7
8
export OS_PROJECT_DOMAIN_NAME=Default
export OS_USER_DOMAIN_NAME=Default
export OS_PROJECT_NAME=admin
export OS_USERNAME=admin
export OS_PASSWORD= `***`
export OS_AUTH_URL=http://controller:5000/v3
export OS_IDENTITY_API_VERSION=3
export OS_IMAGE_API_VERSION=2

创建域、项目用户和角色

1
2
3
4
5
6
7
8
9
10
11
12
创建域
openstack domain create --description "Domain" example
创建项目
openstack project create --domain default --description "Service Project" service
创建平台demo项目
openstack project create --domain default --description "Demo Project" demo
创建demo用户
openstack user create --domain default --password-prompt demo
创建用户角色
openstack role create user
添加用户角色到demo项目和用户
openstack role add --project demo --user demo user //该步骤没有返回值

验证keystone

1
2
3
4
5
6
7
8
9
10
11
12
#取消环境变量
unset OS_AUTH_URL OS_PASSWORD

#admin用户返回的认证token
openstack --os-auth-url http://controller:35357/v3 \
--os-project-domain-name Default --os-user-domain-name Default \
--os-project-name admin --os-username admin token issue

#demo用户返回的认证token
openstack --os-auth-url http://controller:5000/v3 \
--os-project-domain-name Default --os-user-domain-name Default \
--os-project-name demo --os-username demo token issue

创建openstack客户端环境脚本

创建admin-openrc脚本

1
2
3
4
5
6
7
8
9
vi admin-openrc
export OS_PROJECT_DOMAIN_NAME=Default
export OS_USER_DOMAIN_NAME=Default
export OS_PROJECT_NAME=admin
export OS_USERNAME=admin
export OS_PASSWORD=password
export OS_AUTH_URL=http://controller:5000/v3
export OS_IDENTITY_API_VERSION=3
export OS_IMAGE_API_VERSION=2

创建demo-openrc脚本

1
2
3
4
5
6
7
8
9
vi demo-openrc
export OS_PROJECT_DOMAIN_NAME=Default
export OS_USER_DOMAIN_NAME=Default
export OS_PROJECT_NAME=demo
export OS_USERNAME=demo
export OS_PASSWORD=password
export OS_AUTH_URL=http://controller:5000/v3
export OS_IDENTITY_API_VERSION=3
export OS_IMAGE_API_VERSION=2

使用脚本验证返回值 查看admin用户的token信息

1
2
source ~/admin-openrc
openstack token issue

镜像服务——glance (controller 节点配置)

###配置MySQL数据库及授权

1
2
3
4
5
6
7
8
9
10
11
mysql -u root -p

CREATE DATABASE glance;
GRANT ALL PRIVILEGES ON glance.* TO 'glance'@'localhost' IDENTIFIED BY 'password';
GRANT ALL PRIVILEGES ON glance.* TO 'glance'@'%' IDENTIFIED BY 'password';
FLUSH PRIVILEGES;

#获取admin用户的环境变量

source admin-penrc
export | grep OS_

创建glance用户

1
openstack user create --domain default --password-prompt glance

admin用户添加到glance用户和项目中

1
openstack role add --project service --user glance admin

创建glance服务

1
openstack service create --name glance  --description "OpenStack Image" image

创建镜像服务API端点

1
2
3
4
5
#OpenStack使用三种API端点变种代表每种服务:admin、internal、public。

openstack endpoint create --region RegionOne image public http://controller:9292
openstack endpoint create --region RegionOne image internal http://controller:9292
openstack endpoint create --region RegionOne image admin http://controller:9292

安装glance包

1
yum install openstack-glance -y

创建images文件夹,并修改属性

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
mkdir /var/lib/glance/images
cd /var/lib
chown -hR glance:glance glance

#修改glance-api.conf配置文件

vi /etc/glance/glance-api.conf

[database]
connection = mysql+pymysql://glance:password@controller/glance

[keystone_authtoken]
auth_uri = http://controller:5000
auth_url = http://controller:35357
memcached_servers = controller:11211
auth_type = password
project_domain_name = default
user_domain_name = default
project_name = service
username = glance
password = password

[paste_deploy]
flavor = keystone

[glance_store]
stores = file,http
default_store = file
filesystem_store_datadir = /var/lib/glance/images

#修改glance-registry.conf配置文件

vi /etc/glance/glance-registry.conf

[database]
connection = mysql+pymysql://glance:password@controller/glance

[keystone_authtoken]
auth_uri = http://controller:5000
auth_url = http://controller:35357
memcached_servers = controller:11211
auth_type = password
project_domain_name = default
user_domain_name = default
project_name = service
username = glance
password = password

[paste_deploy]
flavor = keystone

同步镜像数据库

1
su -s /bin/sh -c "glance-manage db_sync" glance

启动服务

1
2
3
4
systemctl enable openstack-glance-api.service
systemctl start openstack-glance-api.service
systemctl enable openstack-glance-registry.service
systemctl start openstack-glance-registry.service

上传镜像

~/admin-openrc```
1
2
3
4
5
6
7
8
9

下载一个小型linux镜像进行测试
`wget http://download.cirros-cloud.net/0.3.5/cirros-0.3.5-x86_64-disk.img`

上传镜像,使用QCOW2磁盘格式,裸容器格式和公开可见性将图像上传到Image服务,以便所有项目都可以访问它
`openstack image create "cirros" --file cirros-0.3.5-x86_64-disk.img --disk-format qcow2 --container-format bare --public`

### 查看上传的镜像
```openstack image list

部署compute服务 (controller 节点配置)

安装与配置 配置MySQL数据库及授权

1
2
3
4
5
6
7
8
9
10
mysql -u root -p
CREATE DATABASE nova_api;
CREATE DATABASE nova;
CREATE DATABASE nova_cell0;
GRANT ALL PRIVILEGES ON nova_api.* TO 'nova'@'localhost' IDENTIFIED BY 'password';
GRANT ALL PRIVILEGES ON nova_api.* TO 'nova'@'%' IDENTIFIED BY 'password';
GRANT ALL PRIVILEGES ON nova.* TO 'nova'@'localhost' IDENTIFIED BY 'password';
GRANT ALL PRIVILEGES ON nova.* TO 'nova'@'%' IDENTIFIED BY 'password';
GRANT ALL PRIVILEGES ON nova_cell0.* TO 'nova'@'localhost' IDENTIFIED BY 'password';
GRANT ALL PRIVILEGES ON nova_cell0.* TO 'nova'@'%' IDENTIFIED BY 'password';

创建nova用户

1
2
source ~/admin-openrc
openstack user create --domain default --password-prompt nova

添加admin用户为nova用户

1
openstack role add --project service --user nova admin

创建nova服务端点

service create --name nova --description "OpenStack Compute" compute```
1
2
3
4
5
6

### 创建compute API 服务端点
```shell
openstack endpoint create --region RegionOne compute public http://controller:8774/v2.1
openstack endpoint create --region RegionOne compute internal http://controller:8774/v2.1
openstack endpoint create --region RegionOne compute admin http://controller:8774/v2.1

创建一个placement服务用户

1
openstack user create --domain default --password-prompt placement

添加placement用户为项目服务admin角色

1
openstack role add --project service --user placement admin

在服务目录创建Placement API服务

1
openstack service create --name placement --description "Placement API" placement

创建Placement API服务端点

1
2
3
openstack endpoint create --region RegionOne placement public http://controller:8778
openstack endpoint create --region RegionOne placement internal http://controller:8778
openstack endpoint create --region RegionOne placement admin http://controller:8778

安装软件包

1
yum install openstack-nova-api openstack-nova-conductor  openstack-nova-console openstack-nova-novncproxy  openstack-nova-scheduler openstack-nova-placement-api -y

修改nova.conf配置文件

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
vi /etc/nova/nova.conf

[DEFAULT]
enabled_apis=osapi_compute,metadata
transport_url=rabbit://openstack:password@controller
my_ip=控制节点IP
use_neutron=true
firewall_driver=nova.virt.firewall.NoopFirewallDriver

[api_database]
connection=mysql+pymysql://nova:password@controller/nova_api

[database]
connection=mysql+pymysql://nova:password@controller/nova

[api]
auth_strategy=keystone

[keystone_authtoken]
auth_uri=http://controller:5000
auth_url=http://controller:35357
memcached_servers=controller:11211
auth_type=password
project_domain_name = default
user_domain_name = default
project_name = service
username = nova
password = password

[vnc]
enabled=true
server_listen=$my_ip
server_proxyclient_address=$my_ip

[glance]
api_servers=http://controller:9292

[oslo_concurrency]
lock_path=/var/lib/nova/tmp

[placement]
os_region_name=RegionOne
auth_type=password
auth_url=http://controller:35357/v3
project_name=service
project_domain_name=Default
username=placement
user_domain_name=Default
password=password

启用placement API访问

vi /etc/httpd/conf.d/00-nova-placement-api.conf

1
2
3
4
5
6
7
8
9
<Directory /usr/bin>
<IfVersion >= 2.4>
Require all granted
</IfVersion>
<IfVersion < 2.4>
Order allow,deny
Allow from all
</IfVersion>
</Directory>

重启httpd服务

1
systemctl restart httpd.service

同步nova-api数据库

1
su -s /bin/sh -c "nova-manage api_db sync" nova

注册cell0数据库

1
su -s /bin/sh -c "nova-manage cell_v2 map_cell0" nova

创建cell1 cell

1
su -s /bin/sh -c "nova-manage cell_v2 create_cell --name=cell1 --verbose" nova

同步nova数据库

1
su -s /bin/sh -c "nova-manage db sync" nova

验证数据库是否注册正确

1
nova-manage cell_v2 list_cells

启动并将服务添加为开机自启

1
2
3
4
5
6
7
8
9
10
systemctl enable openstack-nova-api.service
systemctl enable openstack-nova-consoleauth.service
systemctl enable openstack-nova-scheduler.service
systemctl enable openstack-nova-conductor.service
systemctl enable openstack-nova-novncproxy.service
systemctl start openstack-nova-api.service
systemctl start openstack-nova-consoleauth.service
systemctl start openstack-nova-scheduler.service
systemctl start openstack-nova-conductor.service
systemctl start openstack-nova-novncproxy.service

compute节点安装compute (compute 节点配置)

安装软件包

1
yum install openstack-nova-compute -y

修改nova.conf配置文件

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
vi /etc/nova/nova.conf

[DEFAULT]
my_ip = `compute节点IP`
use_neutron=true
firewall_driver=nova.virt.firewall.NoopFirewallDriver
enabled_apis = osapi_compute,metadata
transport_url = rabbit://openstack:password@controller

[api]
auth_strategy=keystone

[keystone_authtoken]
auth_uri = http://`controller节点IP`:5000
auth_url = http://controller:35357
memcached_servers=controller:11211
auth_type=password
project_domain_name=default
user_domain_name=default
project_name=service
username=nova
password=password

[vnc]
enabled=true
server_listen=0.0.0.0
server_proxyclient_address=$my_ip
novncproxy_base_url=http://controller:6080/vnc_auto.html

[glance]
api_servers=http://controller:9292

[oslo_concurrency]
lock_path=/var/lib/nova/tmp

[placement]
os_region_name=RegionOne
auth_type = password
auth_url=http://controller:35357/v3
project_name = service
project_domain_name = Default
user_domain_name = Default
username = placement
password = password

启动服务同时添加为开机自启

1
2
3
4
systemctl enable libvirtd.service
systemctl restart libvirtd
systemctl enable openstack-nova-compute.service
systemctl start openstack-nova-compute.service

添加compute节点到cell数据库,在controller节点上进行操作,验证在数据库中的计算节点

1
2
source ~/admin-openrc
openstack compute service list --service nova-compute

发现计算节点

1
su -s /bin/sh -c "nova-manage cell_v2 discover_hosts --verbose" nova

在controller节点验证计算服务操作

1
openstack compute service list

列出身份服务中的API端点以验证与身份服务的连接

1
openstack catalog list

检查cells和placement API是否正常

1
nova-status upgrade check

安装Networking服务 (controller 节点)

安装和配置controller节点neutron网络配置,创建nuetron数据库并授权

1
2
3
4
mysql -u root -p
CREATE DATABASE neutron;
GRANT ALL PRIVILEGES ON neutron.* TO 'neutron'@'localhost' IDENTIFIED BY 'password';
GRANT ALL PRIVILEGES ON neutron.* TO 'neutron'@'%' IDENTIFIED BY 'password';

创建用户

1
2
source ~/admin-openrc
openstack user create --domain default --password-prompt neutron

创建neutron服务

1
openstack service create --name neutron   --description "OpenStack Networking" network

创建网络服务端点

1
2
3
openstack endpoint create --region RegionOne  network public http://controller:9696
openstack endpoint create --region RegionOne network internal http://controller:9696
openstack endpoint create --region RegionOne network admin http://controller:9696

安装软件包

1
yum install -y openstack-neutron openstack-neutron-ml2  openstack-neutron-linuxbridge ebtables

修改配置文件

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
vi  /etc/neutron/neutron.conf

[database]
connection = mysql+pymysql://neutron:password@controller/neutron

[DEFAULT]
auth_strategy = keystone
core_plugin = ml2
#为空代表禁用其他插件
service_plugins =
transport_url = rabbit://openstack:password@controller
notify_nova_on_port_status_changes = true
notify_nova_on_port_data_changes = true

[keystone_authtoken]
auth_uri = http://controller:5000
auth_url = http://controller:35357
memcached_servers = controller:11211
auth_type = password
project_domain_name = default
user_domain_name = default
project_name = service
username = neutron
password = password

[nova]
auth_url = http://controller:35357
auth_type = password
project_domain_name = default
user_domain_name = default
region_name = RegionOne
project_name = service
username = nova
password = password

[oslo_concurrency]
lock_path = /var/lib/neutron/tmp

配置网络二层插件

1
2
3
4
5
6
7
8
9
10
11
12
13
14
vi /etc/neutron/plugins/ml2/ml2_conf.ini

[ml2]
type_drivers = flat,vlan
#设置空是禁用本地网络
tenant_network_types =
mechanism_drivers = linuxbridge
extension_drivers = port_security

[ml2_type_flat]
flat_networks = provider

[securitygroup]
enable_ipset = true

配置Linux网桥

1
2
3
4
5
6
7
8
9
10
11
vi  /etc/neutron/plugins/ml2/linuxbridge_agent.ini

[linux_bridge]
physical_interface_mappings = provider:ens33

[vxlan]
enable_vxlan = false

[securitygroup]
enable_security_group = true
firewall_driver = neutron.agent.linux.iptables_firewall.IptablesFirewallDriver

配置DHCP

1
2
3
4
5
vi /etc/neutron/dhcp_agent.ini

interface_driver = linuxbridge
dhcp_driver = neutron.agent.linux.dhcp.Dnsmasq
enable_isolated_metadata = true

配置metadata

1
2
3
4
5
vi  /etc/neutron/metadata_agent.ini

[DEFAULT]
nova_metadata_host = controller
metadata_proxy_shared_secret = password

配置计算服务使用网络服务

1
2
3
4
5
6
7
8
9
10
11
12
13
14
vi /etc/nova/nova.conf

[neutron]
url = http://controller:9696
auth_url = http://controller:35357
auth_type = password
project_domain_name = default
user_domain_name = default
region_name = RegionOne
project_name = service
username = neutron
password = password
service_metadata_proxy = true
metadata_proxy_shared_secret = password

建立服务软连接

1
ln -s /etc/neutron/plugins/ml2/ml2_conf.ini /etc/neutron/plugin.ini

同步数据库

1
su -s /bin/sh -c "neutron-db-manage --config-file /etc/neutron/neutron.conf   --config-file /etc/neutron/plugins/ml2/ml2_conf.ini upgrade head" neutron

重启compute API服务

1
systemctl restart openstack-nova-api.service

启动neutron服务并添加为开机自启

1
2
3
4
5
6
7
8
systemctl enable neutron-server.service   
systemctl enable neutron-linuxbridge-agent.service
systemctl enable neutron-dhcp-agent.service
systemctl enable neutron-metadata-agent.service
systemctl start neutron-server.service
systemctl start neutron-linuxbridge-agent.service
systemctl start neutron-dhcp-agent.service
systemctl start neutron-metadata-agent.service

配置compute节点网络服务 (compute 节点)

安装软件包

1
yum install -y openstack-neutron-linuxbridge ebtables ipset

配置公共组件

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
vi /etc/neutron/neutron.conf

[DEFAULT]
auth_strategy = keystone
transport_url = rabbit://openstack:password@controller

[keystone_authtoken]
auth_uri = http://controller:5000
auth_url = http://controller:35357
memcached_servers = controller:11211
auth_type = password
project_domain_name = default
user_domain_name = default
project_name = service
username = neutron
password = password

[oslo_concurrency]
lock_path = /var/lib/neutron/tmp

配置Linux网桥

1
2
3
4
5
6
7
8
9
10
11
vi /etc/neutron/plugins/ml2/linuxbridge_agent.ini

[linux_bridge]
physical_interface_mappings = provider:ens33

[vxlan]
enable_vxlan = false

[securitygroup]
enable_security_group = true
firewall_driver = neutron.agent.linux.iptables_firewall.IptablesFirewallDriver

配置计算节点网络服务

1
2
3
4
5
6
7
8
9
10
11
12
vi /etc/nova/nova.conf

[neutron]
url = http://controller:9696
auth_url = http://controller:35357
auth_type = password
project_domain_name = default
user_domain_name = default
region_name = RegionOne
project_name = service
username = neutron
password = password

启动服务

1
2
3
systemctl restart openstack-nova-compute.service
systemctl enable neutron-linuxbridge-agent.service
systemctl start neutron-linuxbridge-agent.service

部署Horizon服务 (controller 节点)

在controller节点安装Horizon服务,安装软件包

1
yum install openstack-dashboard -y

修改配置文件

1
2
3
4
5
6
vi /etc/openstack-dashboard/local_settings

OPENSTACK_HOST = "controller"
OPENSTACK_KEYSTONE_DEFAULT_ROLE = "admin"
ALLOWED_HOSTS = ['*']
SESSION_ENGINE = 'django.contrib.sessions.backends.file'

配置memcache会话存储

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
#添加
SESSION_ENGINE = 'django.contrib.sessions.backends.cache'
#注释166-170 行去掉 注释159-164行
CACHES = {
'default': {
'BACKEND': 'django.core.cache.backends.memcached.MemcachedCache',
'LOCATION': 'controller:11211',
}
}
#开启身份认证API版本v3
OPENSTACK_KEYSTONE_URL = "http://%s:5000/v3" % OPENSTACK_HOST
#开启domains版本支持 76行
OPENSTACK_KEYSTONE_MULTIDOMAIN_SUPPORT = True

#配置API版本 65行
OPENSTACK_API_VERSIONS = {
"identity": 3,
"image": 2,
"volume": 2,
}
OPENSTACK_KEYSTONE_DEFAULT_DOMAIN = "Default"

OPENSTACK_NEUTRON_NETWORK = {

'enable_router': False,
'enable_quotas': False,
'enable_distributed_router': False,
'enable_ha_router': False,
'enable_lb': False,
'enable_firewall': False,
'enable_***': False,
'enable_fip_topology_check': False,
}

解决网页无法打开检查

1
2
3
4
vi /etc/httpd/conf.d/openstack-dashboard.conf

WSGISocketPrefix run/wsgi
WSGIApplicationGroup %{GLOBAL} //添加

重启web服务和会话存储

1
2
systemctl restart httpd.service 
systemctl restart memcached.service

登陆测试

1
2
3
4
5
http://控制节点IP/dashboard

domain: default
用户名:admin
密码: password //自己设置的密码
本文结束感谢您的阅读,本文原创–支持原创
有问题请联系我--strivedeer@163.com