Filip Pytloun | 4a72d79 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 1 | |
Aleš Komárek | 7215285 | 2017-04-11 13:48:48 +0200 | [diff] [blame] | 2 | ============ |
| 3 | Nova Formula |
| 4 | ============ |
Filip Pytloun | 4a72d79 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 5 | |
Jakub Pavlik | fcf34f8 | 2016-05-20 09:35:51 +0200 | [diff] [blame] | 6 | OpenStack Nova provides a cloud computing fabric controller, supporting a wide |
| 7 | variety of virtualization technologies, including KVM, Xen, LXC, VMware, and |
| 8 | more. In addition to its native API, it includes compatibility with the |
| 9 | commonly encountered Amazon EC2 and S3 APIs. |
Filip Pytloun | 4a72d79 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 10 | |
Aleš Komárek | 7215285 | 2017-04-11 13:48:48 +0200 | [diff] [blame] | 11 | Sample Pillars |
Filip Pytloun | 4a72d79 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 12 | ============== |
| 13 | |
| 14 | Controller nodes |
| 15 | ---------------- |
| 16 | |
| 17 | Nova services on the controller node |
| 18 | |
| 19 | .. code-block:: yaml |
| 20 | |
| 21 | nova: |
| 22 | controller: |
| 23 | version: juno |
| 24 | enabled: true |
| 25 | security_group: true |
Lachlan Evenson | b72de50 | 2016-01-20 15:34:04 -0800 | [diff] [blame] | 26 | cpu_allocation_ratio: 8.0 |
| 27 | ram_allocation_ratio: 1.0 |
Jiri Konecny | 9344a37 | 2016-03-21 19:25:48 +0100 | [diff] [blame] | 28 | disk_allocation_ratio: 1.0 |
Jiri Konecny | b5a80e4 | 2016-03-22 11:51:01 +0100 | [diff] [blame] | 29 | workers: 8 |
Jakub Pavlik | 617a896 | 2016-09-04 18:50:06 +0200 | [diff] [blame] | 30 | report_interval: 60 |
Filip Pytloun | 4a72d79 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 31 | bind: |
| 32 | public_address: 10.0.0.122 |
| 33 | public_name: openstack.domain.com |
| 34 | novncproxy_port: 6080 |
| 35 | database: |
| 36 | engine: mysql |
| 37 | host: 127.0.0.1 |
| 38 | port: 3306 |
| 39 | name: nova |
| 40 | user: nova |
| 41 | password: pwd |
| 42 | identity: |
| 43 | engine: keystone |
| 44 | host: 127.0.0.1 |
| 45 | port: 35357 |
| 46 | user: nova |
| 47 | password: pwd |
| 48 | tenant: service |
| 49 | message_queue: |
| 50 | engine: rabbitmq |
| 51 | host: 127.0.0.1 |
| 52 | port: 5672 |
| 53 | user: openstack |
| 54 | password: pwd |
| 55 | virtual_host: '/openstack' |
| 56 | network: |
| 57 | engine: neutron |
| 58 | host: 127.0.0.1 |
| 59 | port: 9696 |
Jakub Pavlik | 617a896 | 2016-09-04 18:50:06 +0200 | [diff] [blame] | 60 | extension_sync_interval: 600 |
Filip Pytloun | 4a72d79 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 61 | identity: |
| 62 | engine: keystone |
| 63 | host: 127.0.0.1 |
| 64 | port: 35357 |
| 65 | user: neutron |
| 66 | password: pwd |
| 67 | tenant: service |
| 68 | metadata: |
| 69 | password: password |
Petr Michalec | aa23dc0 | 2016-11-29 16:30:25 +0100 | [diff] [blame] | 70 | audit: |
| 71 | enabled: false |
Simon Pasquier | 8683b7a | 2017-02-03 16:00:16 +0100 | [diff] [blame] | 72 | osapi_max_limit: 500 |
Filip Pytloun | 4a72d79 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 73 | |
Jiri Konecny | e31f2c5 | 2016-04-14 17:16:02 +0200 | [diff] [blame] | 74 | |
Filip Pytloun | 4a72d79 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 75 | Nova services from custom package repository |
| 76 | |
| 77 | .. code-block:: yaml |
| 78 | |
| 79 | nova: |
| 80 | controller: |
| 81 | version: juno |
| 82 | source: |
| 83 | engine: pkg |
| 84 | address: http://... |
| 85 | .... |
| 86 | |
Jiri Konecny | e31f2c5 | 2016-04-14 17:16:02 +0200 | [diff] [blame] | 87 | |
| 88 | Client-side RabbitMQ HA setup |
| 89 | |
| 90 | .. code-block:: yaml |
| 91 | |
| 92 | nova: |
| 93 | controller: |
| 94 | .... |
| 95 | message_queue: |
| 96 | engine: rabbitmq |
| 97 | members: |
| 98 | - host: 10.0.16.1 |
| 99 | - host: 10.0.16.2 |
| 100 | - host: 10.0.16.3 |
| 101 | user: openstack |
| 102 | password: pwd |
| 103 | virtual_host: '/openstack' |
| 104 | .... |
| 105 | |
| 106 | |
Petr Michalec | aa23dc0 | 2016-11-29 16:30:25 +0100 | [diff] [blame] | 107 | Enable auditing filter, ie: CADF |
| 108 | |
| 109 | .. code-block:: yaml |
| 110 | |
| 111 | nova: |
| 112 | controller: |
Simon Pasquier | 6a3c8f7 | 2016-12-19 15:37:24 +0100 | [diff] [blame] | 113 | audit: |
Petr Michalec | aa23dc0 | 2016-11-29 16:30:25 +0100 | [diff] [blame] | 114 | enabled: true |
| 115 | .... |
| 116 | filter_factory: 'keystonemiddleware.audit:filter_factory' |
| 117 | map_file: '/etc/pycadf/nova_api_audit_map.conf' |
| 118 | .... |
| 119 | |
| 120 | |
Ondrej Smola | 25b53cb | 2017-04-28 10:56:19 +0200 | [diff] [blame] | 121 | Enable CORS parameters |
| 122 | |
| 123 | .. code-block:: yaml |
| 124 | |
| 125 | nova: |
| 126 | controller: |
| 127 | cors: |
| 128 | allowed_origin: https:localhost.local,http:localhost.local |
| 129 | expose_headers: X-Auth-Token,X-Openstack-Request-Id,X-Subject-Token |
| 130 | allow_methods: GET,PUT,POST,DELETE,PATCH |
| 131 | allow_headers: X-Auth-Token,X-Openstack-Request-Id,X-Subject-Token |
| 132 | allow_credentials: True |
| 133 | max_age: 86400 |
| 134 | |
Dmitry Ukov | 3562a08 | 2017-05-04 00:00:48 +0400 | [diff] [blame] | 135 | Configuration of policy.json file |
| 136 | |
| 137 | .. code-block:: yaml |
| 138 | |
| 139 | nova: |
| 140 | controller: |
| 141 | .... |
| 142 | policy: |
| 143 | context_is_admin: 'role:admin or role:administrator' |
| 144 | 'compute:create': 'rule:admin_or_owner' |
| 145 | # Add key without value to remove line from policy.json |
| 146 | 'compute:create:attach_network': |
Ondrej Smola | 25b53cb | 2017-04-28 10:56:19 +0200 | [diff] [blame] | 147 | |
Filip Pytloun | 4a72d79 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 148 | Compute nodes |
| 149 | ------------- |
| 150 | |
| 151 | Nova controller services on compute node |
| 152 | |
| 153 | .. code-block:: yaml |
| 154 | |
| 155 | nova: |
| 156 | compute: |
| 157 | version: juno |
| 158 | enabled: true |
| 159 | virtualization: kvm |
Jiri Broulik | 70d9e3f | 2017-02-15 18:37:13 +0100 | [diff] [blame] | 160 | availability_zone: availability_zone_01 |
Damian Szeluga | e192241 | 2017-04-18 16:36:46 +0200 | [diff] [blame] | 161 | aggregates: |
| 162 | - hosts_with_fc |
| 163 | - hosts_with_ssd |
Filip Pytloun | 4a72d79 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 164 | security_group: true |
Petr Michalec | f03e488 | 2017-04-10 10:26:18 +0200 | [diff] [blame] | 165 | resume_guests_state_on_host_boot: False |
Filip Pytloun | 4a72d79 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 166 | bind: |
| 167 | vnc_address: 172.20.0.100 |
| 168 | vnc_port: 6080 |
| 169 | vnc_name: openstack.domain.com |
| 170 | vnc_protocol: http |
| 171 | database: |
| 172 | engine: mysql |
| 173 | host: 127.0.0.1 |
| 174 | port: 3306 |
| 175 | name: nova |
| 176 | user: nova |
| 177 | password: pwd |
| 178 | identity: |
| 179 | engine: keystone |
| 180 | host: 127.0.0.1 |
| 181 | port: 35357 |
| 182 | user: nova |
| 183 | password: pwd |
| 184 | tenant: service |
| 185 | message_queue: |
| 186 | engine: rabbitmq |
| 187 | host: 127.0.0.1 |
| 188 | port: 5672 |
| 189 | user: openstack |
| 190 | password: pwd |
| 191 | virtual_host: '/openstack' |
| 192 | image: |
| 193 | engine: glance |
| 194 | host: 127.0.0.1 |
| 195 | port: 9292 |
| 196 | network: |
| 197 | engine: neutron |
| 198 | host: 127.0.0.1 |
| 199 | port: 9696 |
| 200 | identity: |
| 201 | engine: keystone |
| 202 | host: 127.0.0.1 |
| 203 | port: 35357 |
| 204 | user: neutron |
| 205 | password: pwd |
| 206 | tenant: service |
| 207 | qemu: |
| 208 | max_files: 4096 |
| 209 | max_processes: 4096 |
| 210 | |
| 211 | Nova services on compute node with OpenContrail |
| 212 | |
| 213 | .. code-block:: yaml |
| 214 | |
| 215 | nova: |
| 216 | compute: |
| 217 | enabled: true |
| 218 | ... |
| 219 | networking: contrail |
| 220 | |
Jiri Konecny | e31f2c5 | 2016-04-14 17:16:02 +0200 | [diff] [blame] | 221 | |
Filip Pytloun | 4a72d79 | 2015-10-06 16:28:32 +0200 | [diff] [blame] | 222 | Nova services on compute node with memcached caching |
| 223 | |
| 224 | .. code-block:: yaml |
| 225 | |
| 226 | nova: |
| 227 | compute: |
| 228 | enabled: true |
| 229 | ... |
| 230 | cache: |
| 231 | engine: memcached |
| 232 | members: |
| 233 | - host: 127.0.0.1 |
| 234 | port: 11211 |
| 235 | - host: 127.0.0.1 |
| 236 | port: 11211 |
| 237 | |
Jiri Konecny | e31f2c5 | 2016-04-14 17:16:02 +0200 | [diff] [blame] | 238 | |
| 239 | Client-side RabbitMQ HA setup |
| 240 | |
| 241 | .. code-block:: yaml |
| 242 | |
| 243 | nova: |
| 244 | controller: |
| 245 | .... |
| 246 | message_queue: |
| 247 | engine: rabbitmq |
| 248 | members: |
| 249 | - host: 10.0.16.1 |
| 250 | - host: 10.0.16.2 |
| 251 | - host: 10.0.16.3 |
| 252 | user: openstack |
| 253 | password: pwd |
| 254 | virtual_host: '/openstack' |
| 255 | .... |
| 256 | |
maxstack | 39e6aca | 2016-05-04 13:50:13 +0000 | [diff] [blame] | 257 | |
| 258 | Nova with ephemeral configured with Ceph |
| 259 | |
| 260 | .. code-block:: yaml |
| 261 | |
| 262 | nova: |
| 263 | compute: |
| 264 | enabled: true |
| 265 | ... |
| 266 | ceph: |
| 267 | ephemeral: yes |
| 268 | rbd_pool: nova |
| 269 | rbd_user: nova |
| 270 | secret_uuid: 03006edd-d957-40a3-ac4c-26cd254b3731 |
| 271 | |
| 272 | |
Jiri Broulik | 0ce9fc9 | 2017-02-01 23:10:40 +0100 | [diff] [blame] | 273 | Client role |
| 274 | ----------- |
| 275 | |
| 276 | Nova flavors |
| 277 | |
| 278 | .. code-block:: yaml |
| 279 | |
| 280 | nova: |
| 281 | client: |
| 282 | enabled: true |
| 283 | server: |
| 284 | identity: |
| 285 | flavor: |
Jiri Broulik | 70d9e3f | 2017-02-15 18:37:13 +0100 | [diff] [blame] | 286 | flavor1: |
Jiri Broulik | 0ce9fc9 | 2017-02-01 23:10:40 +0100 | [diff] [blame] | 287 | flavor_id: 10 |
| 288 | ram: 4096 |
| 289 | disk: 10 |
| 290 | vcpus: 1 |
Jiri Broulik | 70d9e3f | 2017-02-15 18:37:13 +0100 | [diff] [blame] | 291 | flavor2: |
| 292 | flavor_id: auto |
| 293 | ram: 4096 |
| 294 | disk: 20 |
| 295 | vcpus: 2 |
Jiri Broulik | 0ce9fc9 | 2017-02-01 23:10:40 +0100 | [diff] [blame] | 296 | identity1: |
| 297 | flavor: |
| 298 | ... |
| 299 | |
Jiri Broulik | 70d9e3f | 2017-02-15 18:37:13 +0100 | [diff] [blame] | 300 | |
| 301 | Availability zones |
| 302 | |
| 303 | .. code-block:: yaml |
| 304 | |
| 305 | nova: |
| 306 | client: |
| 307 | enabled: true |
| 308 | server: |
| 309 | identity: |
| 310 | availability_zones: |
| 311 | - availability_zone_01 |
| 312 | - availability_zone_02 |
| 313 | |
Damian Szeluga | 5dca0f0 | 2017-04-13 17:27:15 +0200 | [diff] [blame] | 314 | |
| 315 | |
| 316 | Aggregates |
| 317 | |
| 318 | .. code-block:: yaml |
| 319 | |
| 320 | nova: |
| 321 | client: |
| 322 | enabled: true |
| 323 | server: |
| 324 | identity: |
| 325 | aggregates: |
| 326 | - aggregate1 |
| 327 | - aggregate2 |
| 328 | |
Petr Jediný | d855ef2 | 2017-03-06 22:24:33 +0100 | [diff] [blame] | 329 | SR-IOV |
Jakub Pavlik | 39a0594 | 2017-02-13 23:03:08 +0100 | [diff] [blame] | 330 | ------ |
| 331 | |
| 332 | Add PciPassthroughFilter into scheduler filters and NICs on specific compute nodes. |
| 333 | |
| 334 | .. code-block:: yaml |
| 335 | |
| 336 | nova: |
| 337 | controller: |
| 338 | sriov: true |
| 339 | scheduler_default_filters: "DifferentHostFilter,RetryFilter,AvailabilityZoneFilter,RamFilter,CoreFilter,DiskFilter,ComputeFilter,ComputeCapabilitiesFilter,ImagePropertiesFilter,ServerGroupAntiAffinityFilter,ServerGroupAffinityFilter,PciPassthroughFilter" |
| 340 | |
| 341 | nova: |
| 342 | compute: |
| 343 | sriov: |
| 344 | nic_one: |
| 345 | devname: eth1 |
| 346 | physical_network: physnet1 |
| 347 | |
Jakub Pavlik | 26fb85c | 2017-02-16 22:29:22 +0100 | [diff] [blame] | 348 | CPU pinning & Hugepages |
| 349 | ----------------------- |
| 350 | |
| 351 | CPU pinning of virtual machine instances to dedicated physical CPU cores. |
| 352 | Hugepages mount point for libvirt. |
| 353 | |
| 354 | .. code-block:: yaml |
| 355 | |
| 356 | nova: |
| 357 | controller: |
| 358 | scheduler_default_filters: "DifferentHostFilter,RetryFilter,AvailabilityZoneFilter,RamFilter,CoreFilter,DiskFilter,ComputeFilter,ComputeCapabilitiesFilter,ImagePropertiesFilter,ServerGroupAntiAffinityFilter,ServerGroupAffinityFilter,NUMATopologyFilter,AggregateInstanceExtraSpecsFilter" |
| 359 | |
| 360 | nova: |
| 361 | compute: |
| 362 | vcpu_pin_set: 2,3,4,5 |
| 363 | hugepages: |
| 364 | mount_points: |
| 365 | - path: /mnt/hugepages_1GB |
| 366 | - path: /mnt/hugepages_2MB |
Jiri Broulik | 0ce9fc9 | 2017-02-01 23:10:40 +0100 | [diff] [blame] | 367 | |
Michel Nederlof | 171c7ac | 2017-04-13 12:54:14 +0200 | [diff] [blame] | 368 | Custom Scheduler filters |
| 369 | ------------------------ |
| 370 | |
| 371 | If you have a custom filter, that needs to be included in the scheduler, then you can include it like so: |
| 372 | |
| 373 | .. code-block:: yaml |
| 374 | |
| 375 | nova: |
| 376 | controller: |
| 377 | scheduler_custom_filters: |
| 378 | - my_custom_driver.nova.scheduler.filters.my_custom_filter.MyCustomFilter |
| 379 | |
| 380 | # Then add your custom filter on the end (make sure to include all other ones that you need as well) |
| 381 | scheduler_default_filters: "DifferentHostFilter,RetryFilter,AvailabilityZoneFilter,RamFilter,CoreFilter,DiskFilter,ComputeFilter,ComputeCapabilitiesFilter,ImagePropertiesFilter,ServerGroupAntiAffinityFilter,ServerGroupAffinityFilter,PciPassthroughFilter,MyCustomFilter" |
| 382 | |
Michel Nederlof | eb566f6 | 2017-04-21 15:37:47 +0200 | [diff] [blame] | 383 | Hardware Trip/Unmap Support |
| 384 | --------------------------- |
| 385 | |
| 386 | To enable TRIM support for ephemeral images (thru nova managed images), libvirt has this option. |
| 387 | |
| 388 | .. code-block:: yaml |
| 389 | |
| 390 | nova: |
| 391 | compute: |
| 392 | libvirt: |
| 393 | hw_disk_discard: unmap |
| 394 | |
| 395 | In order to actually utilize this feature, the following metadata must be set on the image as well, so the SCSI unmap is supported. |
| 396 | |
| 397 | .. code-block:: bash |
| 398 | |
| 399 | glance image-update --property hw_scsi_model=virtio-scsi <image> |
| 400 | glance image-update --property hw_disk_bus=scsi <image> |
Filip Pytloun | 5bc9e9f | 2017-02-02 13:05:40 +0100 | [diff] [blame] | 401 | |
Thom Gerdes | ec00afd | 2017-04-07 18:06:59 +0000 | [diff] [blame] | 402 | libvirt CPU mode |
| 403 | ---------------- |
| 404 | |
| 405 | Allow setting the model of CPU that is exposed to a VM. This allows better |
| 406 | support live migration between hypervisors with different hardware, among other |
| 407 | things. Defaults to host-passthrough. |
| 408 | |
| 409 | .. code-block:: yaml |
| 410 | |
| 411 | nova: |
| 412 | compute: |
| 413 | cpu_mode: host-model |
| 414 | |
Michel Nederlof | f7eefb2 | 2017-07-10 11:14:33 +0200 | [diff] [blame^] | 415 | Nova compute workarounds |
| 416 | ------------------------ |
| 417 | |
| 418 | Live snapshotting is disabled by default in nova. To enable this, it needs a manual switch. |
| 419 | |
| 420 | From manual: |
| 421 | |
| 422 | .. code-block:: yaml |
| 423 | |
| 424 | # When using libvirt 1.2.2 live snapshots fail intermittently under load |
| 425 | # (likely related to concurrent libvirt/qemu operations). This config |
| 426 | # option provides a mechanism to disable live snapshot, in favor of cold |
| 427 | # snapshot, while this is resolved. Cold snapshot causes an instance |
| 428 | # outage while the guest is going through the snapshotting process. |
| 429 | # |
| 430 | # For more information, refer to the bug report: |
| 431 | # |
| 432 | # https://bugs.launchpad.net/nova/+bug/1334398 |
| 433 | |
| 434 | Configurable pillar data: |
| 435 | |
| 436 | .. code-block:: yaml |
| 437 | |
| 438 | nova: |
| 439 | compute: |
| 440 | workarounds: |
| 441 | disable_libvirt_livesnapshot: False |
| 442 | |
Thom Gerdes | ec00afd | 2017-04-07 18:06:59 +0000 | [diff] [blame] | 443 | |
Filip Pytloun | 5bc9e9f | 2017-02-02 13:05:40 +0100 | [diff] [blame] | 444 | Documentation and Bugs |
| 445 | ====================== |
| 446 | |
| 447 | To learn how to install and update salt-formulas, consult the documentation |
| 448 | available online at: |
| 449 | |
| 450 | http://salt-formulas.readthedocs.io/ |
| 451 | |
| 452 | In the unfortunate event that bugs are discovered, they should be reported to |
| 453 | the appropriate issue tracker. Use Github issue tracker for specific salt |
| 454 | formula: |
| 455 | |
| 456 | https://github.com/salt-formulas/salt-formula-nova/issues |
| 457 | |
| 458 | For feature requests, bug reports or blueprints affecting entire ecosystem, |
| 459 | use Launchpad salt-formulas project: |
| 460 | |
| 461 | https://launchpad.net/salt-formulas |
| 462 | |
| 463 | You can also join salt-formulas-users team and subscribe to mailing list: |
| 464 | |
| 465 | https://launchpad.net/~salt-formulas-users |
| 466 | |
| 467 | Developers wishing to work on the salt-formulas projects should always base |
| 468 | their work on master branch and submit pull request against specific formula. |
| 469 | |
| 470 | https://github.com/salt-formulas/salt-formula-nova |
| 471 | |
| 472 | Any questions or feedback is always welcome so feel free to join our IRC |
| 473 | channel: |
| 474 | |
| 475 | #salt-formulas @ irc.freenode.net |