Showing posts with label neutron. Show all posts
Showing posts with label neutron. Show all posts

Monday, October 9, 2017

Provisioning an OpenStack Instance by making a CURL REST API call to NOVA API Openstack Ocata

Provisioning an OpenStack Instance by making a CURL REST API call to NOVA API Openstack Ocata


# make a rest API call to the keystone to get an authentication token 
# first get an authentication token making an API call to Keystone REST API
# This Auth token will be used in the further REST API calls in the POST header as X-Auth-Token

# get an auth tokem
curl -d '
   {"auth": {
      "tenantName": "admin",
      "passwordCredentials": {
        "username": "admin",
        "password": "secretpassword"
       }
     }
   }' \
   -H "Content-type: application/json" \
   "http://11.11.1.158:5000/v2.0/tokens" | python -mjson.tool

# the above CURL command generates an AUTH token. This Auth token is used in the subsequent CURL request as needed. Please note that the Auth tokens are valid for 1 hour.
# this also generates the endpoint information to which the username (above admin) has access to

this is a string as "gAAAAABZ2b60ayDnimL-T8Mxmpu195zodM3772pl6n6eb_1rZWS5H-3MUrMZm6rQqk4juJ3DymcfCGETm3jw__JKY2yfD8UkINGdq7a0aXUzbNDoCQnXJjVGTjjchYpsxjGC_eWD2MyUZwo5ITp_0NPNWxpbUw12hn2GX85umjqIgbqOEvV3BpM"




# Make an API call to Nova REST API
# the URL contains the Nova Port 8774 and the admin tenant project ID as f4b62d0d71f44126bd22c2f04251b3f1
# Also the -H for Content-type application/json is here 
# the -d shows the JSON body data that has to be sent by the CURL POST call to the Nova API
# Please note that the appropriate security group for the instance can be sent to the NOVA API in the JSON data 


curl -X POST http://11.11.1.158:8774/v2.1/f4b62d0d71f44126bd22c2f04251b3f1/servers -H "X-Auth-Token: gAAAAABZ2b60ayDnimL-T8Mxmpu195zodM3772pl6n6eb_1rZWS5H-3MUrMZm6rQqk4juJ3DymcfCGETm3jw__JKY2yfD8UkINGdq7a0aXUzbNDoCQnXJjVGTjjchYpsxjGC_eWD2MyUZwo5ITp_0NPNWxpbUw12hn2GX85umjqIgbqOEvV3BpM" -H "Content-Type: application/json" -d '{"server": {"min_count": 1, "flavorRef": "1", "name": "foobar", "imageRef": "d66b73e7-cb0c-42c5-bf73-d5bbdf245da5", "max_count": 1, "networks": [ { "uuid": "13e0d04f-9f41-46ae-8dfa-adea11dea898"} ] }}'


# Get the list of all the Floating IP currently if you want to use an existing free Floating IP
# Make an API call to Neutron REST API
# the URL contains the Nova Port 9696 and the admin tenant project ID as f4b62d0d71f44126bd22c2f04251b3f1
# Also the -H for Content-type application/json is here 


curl -X GET "http://11.11.1.158:9696/v2.0/floatingips" -H "X-Auth-Token: gAAAAABZ2b60ayDnimL-T8Mxmpu195zodM3772pl6n6eb_1rZWS5H-3MUrMZm6rQqk4juJ3DymcfCGETm3jw__JKY2yfD8UkINGdq7a0aXUzbNDoCQnXJjVGTjjchYpsxjGC_eWD2MyUZwo5ITp_0NPNWxpbUw12hn2GX85umjqIgbqOEvV3BpM"


#Creation of a floating IP also the association


# Make an API call to Neutron REST API
# the URL contains the Nova Port 9696 and the admin tenant project ID as f4b62d0d71f44126bd22c2f04251b3f1
# Also the -H for Content-type application/json is here
# This has the X-Auth-Token with the Authentication token that is sent as the header

curl -X POST http://11.11.1.158:9696/v2.0/floatingips -H "X-Auth-Token: gAAAAABZ2b60ayDnimL-T8Mxmpu195zodM3772pl6n6eb_1rZWS5H-3MUrMZm6rQqk4juJ3DymcfCGETm3jw__JKY2yfD8UkINGdq7a0aXUzbNDoCQnXJjVGTjjchYpsxjGC_eWD2MyUZwo5ITp_0NPNWxpbUw12hn2GX85umjqIgbqOEvV3BpM" -d '{
    "floatingip": {
        "floating_network_id": "27d8c6cd-f905-48db-bcc7-d36f36bfecc7",
        "port_id": "9f761f26-c49b-40ef-a568-18a2d0ff25bb",
        "description": "floating ip for testing"
    }
}'


Creation of a Nova Instance using the HEAT API Openstack Ocata and use Neutron API to associate a Floating IP

Creation of a Nova Instance using the HEAT API Openstack Ocata and use Neutron API to associate a Floating IP


# get an auth tokem
curl -d '
   {"auth": {
      "tenantName": "admin",
      "passwordCredentials": {
        "username": "admin",
        "password": "secretpassword"
       }
     }
   }' \
   -H "Content-type: application/json" \
   "http://11.11.1.158:5000/v2.0/tokens" | python -mjson.tool

# the above CURL command generates an AUTH token. This Auth token is used in the subsequent CURL request as needed. Please note that the Auth tokens are valid for 1 hour.
# this also generates the endpoint information to which the username (above admin) has access to

this is a string as "gAAAAABZ2dm6mYkFyY_YL2Dko47Ha8H_GPL-bowgPBfCN2Qec3N5ITRf5MwhIzsAxUtH0IQIN3BE9gUNR2fRIppAYSyiZQ09NsDsU6AdBJXTpgte6P-Rc3prhveDBU8DdwGxaBcllJwbjjy1lL3MbciXyWgX4ZIj1quMKwdqZZ57hEx_lt9FRLw"
   
# get all the stacks for the admin tenant, here the tenant ID for admin project is f4b62d0d71f44126bd22c2f04251b3f1
# the header in the CURL GET call to the HEAT API as X-Auth-Token has the AUTH key generated earlier


curl -X GET http://11.11.1.158:8004/v1/f4b62d0d71f44126bd22c2f04251b3f1/stacks -H "X-Auth-Token: gAAAAABZ2dm6mYkFyY_YL2Dko47Ha8H_GPL-bowgPBfCN2Qec3N5ITRf5MwhIzsAxUtH0IQIN3BE9gUNR2fRIppAYSyiZQ09NsDsU6AdBJXTpgte6P-Rc3prhveDBU8DdwGxaBcllJwbjjy1lL3MbciXyWgX4ZIj1quMKwdqZZ57hEx_lt9FRLw"

# CURL POST call to the HEAT API of openstack with the headers as content-type as application/json.
# there is one more header (-H) having the X-Auth-Token which has the authentication token generared previously
# Please note that in the JSON body being sent to the HEAT API you can also appropriately add the Security Group for the instance to be attached to

curl -X POST http://11.11.1.158:8004/v1/f4b62d0d71f44126bd22c2f04251b3f1/stacks -H "Content-type: application/json" -H "X-Auth-Token: gAAAAABZ2hB-tNCYYZ71ESKM_4QCU_PrrlYYb4winxKe6E-3qpUPx8eHaxWhNypwKupKSvHU3_KZpkZswd0jQ3QFIVDMqDpqbOIBwajb3CiP_Q6JVtp6Neu892n23pAYjrntk3VnuWxJX3zqjNTFxECziYtAmFoYIhp5rRFjqmR9escAOFflLFg" -d \
'{
    "stack_name": "teststack",
    "template": {
        "heat_template_version": "2017-02-24",
        "description": "Simple template to test heat commands",
        "resources": {
            "restapiheatstackservers": {
                "type": "OS::Nova::Server",
                "properties": {
                    "key_name": "key",
                    "flavor": "m1.tiny",
                    "image": "d66b73e7-cb0c-42c5-bf73-d5bbdf245da5",
                    "networks": [
                      {
                        "network": "internal0"
                      }
                     ]
                }
            }
        }
    },
    "timeout_mins": 60
}'

# Stack result of the curl command that is shown as the above CURL POST creates the stack

{"stack": {"id": "8202c7a1-3011-4b7c-87d1-93a470c34101", "links": [{"href": "http://11.11.1.158:8004/v1/f4b62d0d71f44126bd22c2f04251b3f1/stacks/teststack/8202c7a1-3011-4b7c-87d1-93a470c34101", "rel": "self"}]}}

# get the nova instance Port IP details
# This makes a CURL GET call to the NOVA API for the tenant ID. 
# Please note that the URL also contains the ID of the Nova Instance created by the previous HEAT API call
# this is to get the port_id of the instance created by the previous heat API Call

curl -X GET http://11.11.1.158:8774/v2.1/f4b62d0d71f44126bd22c2f04251b3f1/servers/94d359d4-5ea2-42ac-9d0c-afe5d58bb956/os-interface -H "X-Auth-Token: gAAAAABZ2hB-tNCYYZ71ESKM_4QCU_PrrlYYb4winxKe6E-3qpUPx8eHaxWhNypwKupKSvHU3_KZpkZswd0jQ3QFIVDMqDpqbOIBwajb3CiP_Q6JVtp6Neu892n23pAYjrntk3VnuWxJX3zqjNTFxECziYtAmFoYIhp5rRFjqmR9escAOFflLFg" | python -mjson.tool


# Associate the floating IP to the Instance port ID
# this is a CURL POST request to the Neutron API on port 9696 that is neutron port
# the header contains the -H for the content-type as application/json 
# the header also contains (the other -H option) to send the X-Auth-Token to the Neutron REST API

curl -X POST http://11.11.1.158:9696/v2.0/floatingips -H "Content-type: application/json" -H "X-Auth-Token: gAAAAABZ2hB-tNCYYZ71ESKM_4QCU_PrrlYYb4winxKe6E-3qpUPx8eHaxWhNypwKupKSvHU3_KZpkZswd0jQ3QFIVDMqDpqbOIBwajb3CiP_Q6JVtp6Neu892n23pAYjrntk3VnuWxJX3zqjNTFxECziYtAmFoYIhp5rRFjqmR9escAOFflLFg" -d \
'{
    "floatingip": {
        "floating_network_id": "27d8c6cd-f905-48db-bcc7-d36f36bfecc7",
        "port_id": "298951f4-238c-4f16-ac5b-15d42b3a2d57",
        "description": "floating ip for testing"
    }
}'


Sunday, October 8, 2017

OpenStack Neutron Lbaasv2 LoadBalancer on Ocata

Neutron LBaaSv2 LoadBalancer on OpenStack Ocata

Flow of steps

pre-requisites:

1) 1 External/Public network and subnet has to be created
2) 1 Internal network and subnet has to be created
3) At least 2 Instances have to be up and running with the HTTP server running in them
4) Router has to be have the gateway set
5) Router routing the traffic between the external and the internal subnets


Creation of loadbalancer:

1) Load balancer can be created in the external/or internal network. Here we will create the load balancer in the internal subnet . Here Create the load balancer and the LB VIP
2) Add the LBVIP port to the correct security Group
3) Creation of the listener for the loadbalancer
4) Create the load balancer pool
5) Add the mebers to the LB pool
6) Create a floating IP
7) Associate the floating IP to the LBVIP
8) Confirm the functioning of the curl requests at the floating IP
9) Create a load balancer health monitor




1) Load balancer can be created in the external/or internal network. Here we will create the load balancer in the internal subnet . Here Create the load balancer and the LB VIP

[root@controllero HeatOrchestrationTemplates(keystone_admin)]# neutron subnet-list
neutron CLI is deprecated and will be removed in the future. Use openstack CLI instead.
+--------------------------------------+-----------+----------------------------------+----------------+---------------------------------------------------+
| id                                   | name      | tenant_id                        | cidr           | allocation_pools                                  |
+--------------------------------------+-----------+----------------------------------+----------------+---------------------------------------------------+
| c8e87357-9408-4144-aa7d-79c869033802 | internal0 | f4b62d0d71f44126bd22c2f04251b3f1 | 192.168.1.0/24 | {"start": "192.168.1.21", "end": "192.168.1.254"} |
| d36fa454-0c96-4b8b-b754-f5605536304c | public0   | f4b62d0d71f44126bd22c2f04251b3f1 | 172.16.0.0/16  | {"start": "172.16.90.1", "end": "172.16.100.254"} |
+--------------------------------------+-----------+----------------------------------+----------------+---------------------------------------------------+
[root@controllero HeatOrchestrationTemplates(keystone_admin)]#

create the load balancer and add the loadbalancer LBVIP port to the correct Security Group

[root@controllero HeatOrchestrationTemplates(keystone_admin)]# neutron lbaas-loadbalancer-create --name lb1 internal0
neutron CLI is deprecated and will be removed in the future. Use openstack CLI instead.
Created a new loadbalancer:
+---------------------+--------------------------------------+
| Field               | Value                                |
+---------------------+--------------------------------------+
| admin_state_up      | True                                 |
| description         |                                      |
| id                  | f49f94a6-2359-4c61-aa80-726ba18124a2 |
| listeners           |                                      |
| name                | lb1                                  |
| operating_status    | OFFLINE                              |
| pools               |                                      |
| provider            | haproxy                              |
| provisioning_status | PENDING_CREATE                       |
| tenant_id           | f4b62d0d71f44126bd22c2f04251b3f1     |
| vip_address         | 192.168.1.25                         |
| vip_port_id         | 5f6a54ea-917d-4c4a-88e0-988caf6aae36 |
| vip_subnet_id       | c8e87357-9408-4144-aa7d-79c869033802 |
+---------------------+--------------------------------------+
[root@controllero HeatOrchestrationTemplates(keystone_admin)]#



Get the port ID for the LBVIP Port

neutron port-list | grep 192.168.1.32

or VIP port ID is also seen the neutron lbaas-loadbalancer-show <loadbalancer_name>

2) Add the LBVIP port to the correct security Group

List the security groups, here we will add the port LBVIP port to the security group sec1

[root@controllero HeatOrchestrationTemplates(keystone_admin)]# openstack security group rule list sec1
+--------------------------------------+-------------+-----------+------------+-----------------------+
| ID                                   | IP Protocol | IP Range  | Port Range | Remote Security Group |
+--------------------------------------+-------------+-----------+------------+-----------------------+
| 3fedb1d3-d761-43b1-a75f-0904fb18bca9 | None        | None      |            | None                  |
| 8fc3c034-59dc-4b6d-9813-7c63b5b38b3d | icmp        | 0.0.0.0/0 |            | None                  |
| 93873455-2728-420c-a247-697d158bcadd | tcp         | 0.0.0.0/0 | 443:443    | None                  |
| a420ba1f-b2bf-4fb4-b38e-58bf26506c7c | None        | None      |            | None                  |
| f0620bb9-007c-46eb-ac5c-2cf7f2d64573 | tcp         | 0.0.0.0/0 | 80:80      | None                  |
| f75ded09-0f3f-444a-9472-f5064d0f7b1c | tcp         | 0.0.0.0/0 | 22:22      | None                  |
+--------------------------------------+-------------+-----------+------------+-----------------------+
[root@controllero HeatOrchestrationTemplates(keystone_admin)]#


Apply these rules to the load balancer LBVIP port. Please note that the security group allows for incoming traffics at port TCP/443 80 and SSH (22)
Here port 80 is needed.

neutron port-update --security-group sec1 654859c7-30f3-4c06-90fe-073c9de2d00e

This is of the format associate

neutron port-update --security-group <Security Group Name> <Neutron Port ID of LBVIP>

[root@controllero HeatOrchestrationTemplates(keystone_admin)]# neutron port-update --security-group sec1 5f6a54ea-917d-4c4a-88e0-988caf6aae36
neutron CLI is deprecated and will be removed in the future. Use openstack CLI instead.
Updated port: 5f6a54ea-917d-4c4a-88e0-988caf6aae36
[root@controllero HeatOrchestrationTemplates(keystone_admin)]#

--

3) Creation of the listener for the loadbalancer


neutron lbaas-listener-create --name listener-lb1 --loadbalancer lb1 --protocol HTTP --protocol-port 80


Created a new listener:
+---------------------------+------------------------------------------------+
| Field                     | Value                                          |
+---------------------------+------------------------------------------------+
| admin_state_up            | True                                           |
| connection_limit          | -1                                             |
| default_pool_id           |                                                |
| default_tls_container_ref |                                                |
| description               |                                                |
| id                        | 01fc9c48-9232-4ed7-9c62-d3950bbf1b39           |
| loadbalancers             | {"id": "f49f94a6-2359-4c61-aa80-726ba18124a2"} |
| name                      | listener-lb1                                   |
| protocol                  | HTTP                                           |
| protocol_port             | 80                                             |
| sni_container_refs        |                                                |
| tenant_id                 | f4b62d0d71f44126bd22c2f04251b3f1               |
+---------------------------+------------------------------------------------+
[root@controllero HeatOrchestrationTemplates(keystone_admin)]#



Ping the LBVIP to ensure that the LBVIP is UP


[root@controllero HeatOrchestrationTemplates(keystone_admin)]# ip netns exec qdhcp-13e0d04f-9f41-46ae-8dfa-adea11dea898 ping 192.168.1.25
PING 192.168.1.25 (192.168.1.25) 56(84) bytes of data.
64 bytes from 192.168.1.25: icmp_seq=1 ttl=64 time=0.455 ms
64 bytes from 192.168.1.25: icmp_seq=2 ttl=64 time=0.044 ms
^C
--- 192.168.1.25 ping statistics ---
2 packets transmitted, 2 received, 0% packet loss, time 999ms
rtt min/avg/max/mdev = 0.044/0.249/0.455/0.206 ms
[root@controllero HeatOrchestrationTemplates(keystone_admin)]#



4) Create the load balancer pool

The pool here is created with the loadbalancer created in the previous step. Also the Load Balance Algorithm --lb_algorithm has been set to ROUND_ROBIN.
The Load Balancer pool is supposed to balance the HTTP protocol type traffic.



Creation of the loadbalancerpool

[root@controllero HeatOrchestrationTemplates(keystone_admin)]# neutron lbaas-pool-create --lb-algorithm ROUND_ROBIN --protocol HTTP --listener listener-lb1 --name lbpool1
neutron CLI is deprecated and will be removed in the future. Use openstack CLI instead.
Created a new pool:
+---------------------+------------------------------------------------+
| Field               | Value                                          |
+---------------------+------------------------------------------------+
| admin_state_up      | True                                           |
| description         |                                                |
| healthmonitor_id    |                                                |
| id                  | 83a53986-628c-4a4f-a880-2272e09d5201           |
| lb_algorithm        | ROUND_ROBIN                                    |
| listeners           | {"id": "01fc9c48-9232-4ed7-9c62-d3950bbf1b39"} |
| loadbalancers       | {"id": "f49f94a6-2359-4c61-aa80-726ba18124a2"} |
| members             |                                                |
| name                | lbpool1                                        |
| protocol            | HTTP                                           |
| session_persistence |                                                |
| tenant_id           | f4b62d0d71f44126bd22c2f04251b3f1               |
+---------------------+------------------------------------------------+
[root@controllero HeatOrchestrationTemplates(keystone_admin)]#



5) Add the mebers to the LB pool

there are 2 CentOS instances running HTTP web servers and having unique /var/www/html/index.html
These will be added to the load balancer pool as members

These are having the private IPs in 192.168.1.0/24 subnet as seen here

[root@controllero HeatOrchestrationTemplates(keystone_admin)]# openstack server list | grep -i centos
| 5b5a0a20-3f5c-4cd5-bde0-444bb63ff95f | testcentosstack2-server-xc2hlgc3oosv | ACTIVE | internal0=192.168.1.23, 172.16.90.8  | centos7_64_qcow2 |
| d0de51a6-e4f2-4b99-9b8c-a6b27507d5b1 | testcentosstack-server-axiq4otdn55b  | ACTIVE | internal0=192.168.1.31, 172.16.90.7  | centos7_64_qcow2 |
[root@controllero HeatOrchestrationTemplates(keystone_admin)]#


Add these as the members to the loadbalancer pool


Both the members above are added to the LB Pool lbaaspool1 with the port 80 (HTTP)
[root@controllero HeatOrchestrationTemplates(keystone_admin)]# neutron lbaas-member-create --subnet internal0 --address 192.168.1.23 --protocol-port 80 lbpool1
neutron CLI is deprecated and will be removed in the future. Use openstack CLI instead.
Created a new member:
+----------------+--------------------------------------+
| Field          | Value                                |
+----------------+--------------------------------------+
| address        | 192.168.1.23                         |
| admin_state_up | True                                 |
| id             | b0fea681-b4d5-48c5-8b28-24257f5dbec8 |
| name           |                                      |
| protocol_port  | 80                                   |
| subnet_id      | c8e87357-9408-4144-aa7d-79c869033802 |
| tenant_id      | f4b62d0d71f44126bd22c2f04251b3f1     |
| weight         | 1                                    |
+----------------+--------------------------------------+
[root@controllero HeatOrchestrationTemplates(keystone_admin)]# neutron lbaas-member-create --subnet internal0 --address 192.168.1.31 --protocol-port 80 lbpool1
neutron CLI is deprecated and will be removed in the future. Use openstack CLI instead.
Created a new member:
+----------------+--------------------------------------+
| Field          | Value                                |
+----------------+--------------------------------------+
| address        | 192.168.1.31                         |
| admin_state_up | True                                 |
| id             | 55441528-fa80-441c-9386-a391e3d318d8 |
| name           |                                      |
| protocol_port  | 80                                   |
| subnet_id      | c8e87357-9408-4144-aa7d-79c869033802 |
| tenant_id      | f4b62d0d71f44126bd22c2f04251b3f1     |
| weight         | 1                                    |
+----------------+--------------------------------------+

Do a CURL using the appripriate namespace to see if the LBVIP gives the curl results

[root@controllero HeatOrchestrationTemplates(keystone_admin)]# ip netns
qlbaas-f49f94a6-2359-4c61-aa80-726ba18124a2
qrouter-6990c5d3-c327-4739-95f9-440b96f4c2ea
qdhcp-13e0d04f-9f41-46ae-8dfa-adea11dea898
qdhcp-27d8c6cd-f905-48db-bcc7-d36f36bfecc7
[root@controllero HeatOrchestrationTemplates(keystone_admin)]# ip netns exec qdhcp-13e0d04f-9f41-46ae-8dfa-adea11dea898 curl http://192.168.1.25
welcome from testcentosstack-server-axiq4otdn55b
[root@controllero HeatOrchestrationTemplates(keystone_admin)]#

[root@controllero HeatOrchestrationTemplates(keystone_admin)]# ip netns exec qdhcp-13e0d04f-9f41-46ae-8dfa-adea11dea898 curl http://192.168.1.25
welcome from testcentosstack2-server-xc2hlgc3oosv
[root@controllero HeatOrchestrationTemplates(keystone_admin)]#




6) Create a floating IP

The floating IP has to be created in the external/public network

[root@controllero HeatOrchestrationTemplates(keystone_admin)]# neutron floatingip-create public0
neutron CLI is deprecated and will be removed in the future. Use openstack CLI instead.
Created a new floatingip:
+---------------------+--------------------------------------+
| Field               | Value                                |
+---------------------+--------------------------------------+
| created_at          | 2017-10-09T04:12:14Z                 |
| description         |                                      |
| fixed_ip_address    |                                      |
| floating_ip_address | 172.16.90.14                         |
| floating_network_id | 27d8c6cd-f905-48db-bcc7-d36f36bfecc7 |
| id                  | 7c1a068f-d9cc-4827-b4c6-f19fa8ca03b1 |
| port_id             |                                      |
| project_id          | f4b62d0d71f44126bd22c2f04251b3f1     |
| revision_number     | 1                                    |
| router_id           |                                      |
| status              | DOWN                                 |
| tenant_id           | f4b62d0d71f44126bd22c2f04251b3f1     |
| updated_at          | 2017-10-09T04:12:14Z                 |
+---------------------+--------------------------------------+
[root@controllero HeatOrchestrationTemplates(keystone_admin)]#


7) Associate the floating IP to the LBVIP

For this get the Neutron port_id for the LBVIP floating IP that was created
Then Associate the floating IP to the port_id of the LBVIP

Find the portID of the LBVIP
Here the first column IP is the port ID


[root@controllero HeatOrchestrationTemplates(keystone_admin)]# neutron port-list | grep 192.168.1.32
neutron CLI is deprecated and will be removed in the future. Use openstack CLI instead.
| 654859c7-30f3-4c06-90fe-073c9de2d00e | loadbalancer-6901f941-dac5-4e96-afcd-abf1f55776d1 | f4b62d0d71f44126bd22c2f04251b3f1 | fa:16:3e:1d:93:8e | {"subnet_id": "c8e87357-9408-4144-aa7d-79c869033802", "ip_address": "192.168.1.32"} |
[root@controllero HeatOrchestrationTemplates(keystone_admin)]#

[root@controllero HeatOrchestrationTemplates(keystone_admin)]# neutron lbaas-loadbalancer-show lb1
neutron CLI is deprecated and will be removed in the future. Use openstack CLI instead.
+---------------------+------------------------------------------------+
| Field               | Value                                          |
+---------------------+------------------------------------------------+
| admin_state_up      | True                                           |
| description         |                                                |
| id                  | f49f94a6-2359-4c61-aa80-726ba18124a2           |
| listeners           | {"id": "01fc9c48-9232-4ed7-9c62-d3950bbf1b39"} |
| name                | lb1                                            |
| operating_status    | ONLINE                                         |
| pools               | {"id": "83a53986-628c-4a4f-a880-2272e09d5201"} |
| provider            | haproxy                                        |
| provisioning_status | ACTIVE                                         |
| tenant_id           | f4b62d0d71f44126bd22c2f04251b3f1               |
| vip_address         | 192.168.1.25                                   |
| vip_port_id         | 5f6a54ea-917d-4c4a-88e0-988caf6aae36           |
| vip_subnet_id       | c8e87357-9408-4144-aa7d-79c869033802           |
+---------------------+------------------------------------------------+
[root@controllero HeatOrchestrationTemplates(keystone_admin)]#


Associate the floating IP to the LBVIP Port ID


neutron floatingip-associate 7c1a068f-d9cc-4827-b4c6-f19fa8ca03b1 654859c7-30f3-4c06-90fe-073c9de2d00e

here the command syntax is like neutron floatingip-associate <ID of the floating IP> <Neutron Port ID of the LBVIP Port>


see the association

[root@controllero HeatOrchestrationTemplates(keystone_admin)]# neutron floatingip-show 7c1a068f-d9cc-4827-b4c6-f19fa8ca03b1
neutron CLI is deprecated and will be removed in the future. Use openstack CLI instead.
+---------------------+--------------------------------------+
| Field               | Value                                |
+---------------------+--------------------------------------+
| created_at          | 2017-10-09T04:12:14Z                 |
| description         |                                      |
| fixed_ip_address    | 192.168.1.25                         |
| floating_ip_address | 172.16.90.14                         |
| floating_network_id | 27d8c6cd-f905-48db-bcc7-d36f36bfecc7 |
| id                  | 7c1a068f-d9cc-4827-b4c6-f19fa8ca03b1 |
| port_id             | 5f6a54ea-917d-4c4a-88e0-988caf6aae36 |
| project_id          | f4b62d0d71f44126bd22c2f04251b3f1     |
| revision_number     | 4                                    |
| router_id           | 6990c5d3-c327-4739-95f9-440b96f4c2ea |
| status              | ACTIVE                               |
| tenant_id           | f4b62d0d71f44126bd22c2f04251b3f1     |
| updated_at          | 2017-10-09T06:38:30Z                 |
+---------------------+--------------------------------------+
[root@controllero HeatOrchestrationTemplates(keystone_admin)]#



8) Confirm the functioning of the curl requests at the floating IP

[root@win2k12r2 ~]# curl http://172.16.90.14
welcome from testcentosstack-server-axiq4otdn55b
[root@win2k12r2 ~]# curl http://172.16.90.14
welcome from testcentosstack2-server-xc2hlgc3oosv
[root@win2k12r2 ~]#



9) Create a load balancer health monitor


Here the health monitor is created with the delay of 2second, max retries of 2 and timeout of 5 seconds in the load balancer pool

[root@controllero HeatOrchestrationTemplates(keystone_admin)]# neutron lbaas-healthmonitor-create --delay 2 --timeout 5 --max-retries 2 --type HTTP  --pool lbpool1 --name lbmon1
neutron CLI is deprecated and will be removed in the future. Use openstack CLI instead.
Created a new healthmonitor:
+------------------+------------------------------------------------+
| Field            | Value                                          |
+------------------+------------------------------------------------+
| admin_state_up   | True                                           |
| delay            | 2                                              |
| expected_codes   | 200                                            |
| http_method      | GET                                            |
| id               | aeb9ba02-9808-4772-983b-973a39f3a9f1           |
| max_retries      | 2                                              |
| max_retries_down | 3                                              |
| name             | lbmon1                                         |
| pools            | {"id": "83a53986-628c-4a4f-a880-2272e09d5201"} |
| tenant_id        | f4b62d0d71f44126bd22c2f04251b3f1               |
| timeout          | 5                                              |
| type             | HTTP                                           |
| url_path         | /                                              |
+------------------+------------------------------------------------+
[root@controllero HeatOrchestrationTemplates(keystone_admin)]#


Saturday, March 25, 2017

OpenStack Newton Pakcstack bug on Neutron Manifest run Wrong number of arguments given (1 for 2) in openstacksetup.log

The error appearing in the openstack-setup.log

PuppetError: Error appeared during Puppet run: controller1.example.com_network.pp
Error: member(): Wrong number of arguments given (1 for 2) at /var/tmp/packstack/6b760137219c43bc8e7f4365e9778689/modules/packstack/manifests/neutron/ovs_agent.pp:29 on node controller1.example.com
You will find full trace in log /var/tmp/packstack/20170325-051853-oQnZA6/manifests/controller1.example.com_network.pp.log

2017-03-25 05:21:52::INFO::shell::94::root:: [compute1.example.com] Executing script:
rm -rf /var/tmp/packstack/7ee6b5f014df46f982a179d372186bc8
2017-03-25 05:21:52::INFO::shell::94::root:: [controller1.example.com] Executing script:
rm -rf /var/tmp/packstack/6b760137219c43bc8e7f4365e9778689


The workaround is to replace all the HOST parameters in the packstack answers file with the IP addresses instead of the hostnames

as below

[root@controller1 ~]# cat answers1.txt | grep 192.168.17
CONFIG_CONTROLLER_HOST=192.168.17.52
CONFIG_COMPUTE_HOSTS=192.168.17.61
CONFIG_NETWORK_HOSTS=192.168.17.52
CONFIG_SSL_CERT_SUBJECT_CN=192.168.17.52
CONFIG_SSL_CERT_SUBJECT_MAIL=admin@192.168.17.52
CONFIG_AMQP_HOST=192.168.17.52
CONFIG_MARIADB_HOST=192.168.17.52
CONFIG_MONGODB_HOST=192.168.17.52
CONFIG_REDIS_HOST=192.168.17.52
[root@controller1 ~]#



Relevant Redhat Bugzilla


https://bugs.launchpad.net/packstack/+bug/1635133

Friday, September 23, 2016

Neutron OpenvSwitch L2 agent on the nova Node not appearing in the neutron agent-list. MItaka huge time difference between the controller and the nova server



Neutron OpenvSwitch L2 agent on the nova Node not appearing in the neutron agent-list.


root@labnova:~[root@labnova ~]# neutron agent-list
+--------------------------------------+----------------------+------------------------+-------------------+-------+----------------+---------------------------+
| id                                   | agent_type           | host                   | availability_zone | alive | admin_state_up | binary                    |
+--------------------------------------+----------------------+------------------------+-------------------+-------+----------------+---------------------------+
| 31947b08-c7e4-4136-9559-f9d8bc31e1fb | DHCP agent           | labneutron.example.com | nova              | :-)   | True           | neutron-dhcp-agent        |
| 9d6bdf0b-3b11-4f46-9d67-ae49bc2ff968 | Loadbalancerv2 agent | labneutron.example.com |                   | :-)   | True           | neutron-lbaasv2-agent     |
| a94c66c6-d037-4080-ac0d-5cc8e8719729 | L3 agent             | labneutron.example.com | nova              | :-)   | True           | neutron-l3-agent          |
| c0c42fcd-5d6a-4618-8b3a-b71b79a639dc | Metadata agent       | labneutron.example.com |                   | :-)   | True           | neutron-metadata-agent    |
| c96830ca-7807-404c-8168-0627f1950afd | Open vSwitch agent   | labneutron.example.com |                   | :-)   | True           | neutron-openvswitch-agent |
| e49cea55-70cf-49b7-a8fe-91f2f227ebe8 | Open vSwitch agent   | labnova.example.com    |                   | xxx   | True           | neutron-openvswitch-agent |
+--------------------------------------+----------------------+------------------------+-------------------+-------+----------------+---------------------------+

Meanwhile appearing in the /var/log/neutron/server.log on the controller node.
2016-09-23 15:02:13.737 3828 ERROR neutron.db.agents_db [req-9628b672-43b1-4883-89a3-fec7511cb854 - - - - -] Message received from the host: labnova.example.com during the registration of Open vSwitch agent has a timestamp: 2016-09-20T22:55:24.425782. This differs from the current server timestamp: 2016-09-23T19:02:13.736852 by 245209.31107 seconds, which is more than the threshold agent downtime: 75.
2016-09-23 15:02:20.677 3828 WARNING neutron.plugins.ml2.drivers.l2pop.mech_driver [req-9628b672-43b1-4883-89a3-fec7511cb854 - - - - -] Unable to retrieve active L2 agent on host labnova.example.com
2016-09-23 15:02:21.138 3828 WARNING neutron.plugins.ml2.drivers.l2pop.mech_driver [req-9628b672-43b1-4883-89a3-fec7511cb854 - - - - -] Unable to retrieve active L2 agent on host labnova.example.com
2016-09-23 15:02:21.633 3828 WARNING neutron.plugins.ml2.drivers.l2pop.mech_driver [req-9628b672-43b1-4883-89a3-fec7511cb854 - - - - -] Unable to retrieve active L2 agent on host labnova.example.com


On the nova server the service neutron-openvswitch-agent had already been running.

#systemctl –a | grep -i  neutron-openvswitch-agent.service                                                                              loaded    active   running  

There was a date difference of 3 days on the controller and the nova node.
root@labnova:/etc/neutron/plugins/ml2[root@labnova ml2]# date
Tue Sep 20 18:57:26 EDT 2016

At the same time the date was on the controller server as

root@labcontroller:/var/log/neutron[root@labcontroller neutron]# date
Fri Sep 23 15:13:39 EDT 2016


The fix:

The fix was to restart the chronyd on the nova server to sync the time correctly with the NTP Source and restarting the neutron-openvswitch-agent.service running on the nova server labnova.