OpenStack and Kolla-Ansible
OpenStack is an open-source platform for building and managing cloud infrastructure. It can be operated through a web-based dashboard or through its command-line tools.
Cloud computing enables users to access computing resources over the internet. These resources include servers, storage, networking, and software. Common benefits include:
- Flexibility: Access resources from anywhere with an internet connection instead of visiting a physical server.
- Scalability: Scale resources more easily than with physical servers, which often require hardware upgrades.
- Cost efficiency: Avoid purchasing and maintaining an entire set of physical infrastructure.
- Accessibility: Access data and services remotely through the network.
- Operational convenience: Run applications without installing every dependency directly on the user's workstation.
OpenStack is made up of several core services:
- Keystone is the identity service. OpenStack components use it to authenticate and authorize access.
- Neutron provides networking and manages internal and external connectivity for the OpenStack cluster.
- Nova is the compute service responsible for creating and managing instances, or virtual machines.
- Glance stores operating system images used when creating instances.
- Cinder provides block storage volumes for OpenStack instances.
- Horizon is the web dashboard for managing an OpenStack environment.
- RabbitMQ is a message broker used to deliver messages between OpenStack services and their clients.
- Flexibility and customization: Customize the cloud environment to fit specific infrastructure requirements.
- Cost efficiency: Reduce total ownership costs with an open-source platform.
- Scalability: Scale horizontally by adding more machines as demand grows.
- Security: Use built-in security controls and extend them with additional policies or third-party services.
Kolla-Ansible is a deployment tool for running OpenStack in containers at production scale. It is designed to be scalable, fast to upgrade, and flexible to configure. Because it uses Ansible, Kolla-Ansible automates much of the deployment process while still allowing operators to select the services and networking options they need.
Key benefits include:
- Practical automation: Automate the deployment and configure only the services and options required, including TLS.
- Fewer manual errors: Reduce the risk of mistakes compared with a fully manual OpenStack deployment.
-
Install the dependencies required by OpenStack and Kolla-Ansible.
bashsudo apt-get install python3-dev python3-selinux python3-setuptools python3-venv gcc libffi-dev libssl-dev -y -
Create a Python virtual environment so library versions remain isolated from the host system, then activate it.
bash~$ python3 -m venv kolla-venv ~$ source kolla-venv/bin/activate -
Install Ansible and Kolla-Ansible for the OpenStack deployment.
bash(kolla-venv) student@controller:~$ pip install -U pip (kolla-venv) student@controller:~$ pip install 'ansible>=6,<8' (kolla-venv) student@controller:~$ pip install git+https://opendev.org/openstack/kolla-ansible@stable/2023.1 (kolla-venv) student@controller:~$ kolla-ansible install-deps -
Create the Kolla configuration directory and copy the sample
globals.ymlandpasswords.ymlfiles. These files define the options used during deployment. Then configureglobals.ymlas shown below.bash(kolla-venv) student@controller:~$ sudo mkdir -p /etc/kolla (kolla-venv) student@controller:~$ sudo chown $USER:$USER /etc/kolla (kolla-venv) student@controller:~$ cp -r kolla-venv/share/kolla-ansible/etc_examples/kolla/* /etc/kollayamlkolla_base_distro: "ubuntu" openstack_release: "2023.1" network_interface: "ens3" neutron_external_interface: "ens4" kolla_internal_vip_address: "{IP HOST}" neutron_plugin_agent: "openvswitch" enable_keystone: "yes" enable_horizon: "no" enable_neutron_provider_networks: "yes" enable_cinder: "yes" enable_cinder_backend_lvm: "yes" -
Copy the multinode inventory and define where each OpenStack component should run. In this example, the cluster has three nodes: one controller and two compute nodes.
bash(kolla-venv) student@controller:~$ cp kolla-venv/share/kolla-ansible/ansible/inventory/* . (kolla-venv) student@controller:~$ nano ~/multinodeyaml[control] pod-controller [network] pod-controller [compute] pod-compute1 pod-compute2 [monitoring] pod-controller [storage] pod-controller pod-compute1 pod-compute2 [deployment] localhost ansible_connection=local -
Configure Ansible.
bash(kolla-venv) student@controller:~$ sudo mkdir -p /etc/ansible (kolla-venv) student@controller:~$ sudo nano /etc/ansible/ansible.cfgyaml[defaults] host_key_checking=False pipelining=True forks=100 -
Generate passwords for the OpenStack services.
bash(kolla-venv) student@controller:~$ kolla-genpwd -
Create a physical volume and volume group for the Cinder storage backend.
bash(kolla-venv) student@controller:~$ sudo pvcreate /dev/vdb (kolla-venv) student@controller:~$ sudo vgcreate cinder-volumes /dev/vdb -
Bootstrap the servers. This prepares every node in the cluster and installs the dependencies required for the Kolla-Ansible deployment.
bash(kolla-venv) student@controller:~$ kolla-ansible -i ./multinode bootstrap-servers -
Run the pre-deployment checks.
bash(kolla-venv) student@controller:~$ kolla-ansible -i ./multinode prechecks -
Deploy the OpenStack cluster.
bash(kolla-venv) student@controller:~$ kolla-ansible -i ./multinode deploy -
Generate the
openrcfile used to authenticate to OpenStack through the CLI.bash(kolla-venv) student@controller:~$ kolla-ansible -i ./multinode post-deploy -
Install the Python OpenStack client, authenticate with
openrc, and verify the deployed services.bash(kolla-venv) student@controller:~$ pip install openstackclient (kolla-venv) student@controller:~$ source /etc/kolla/admin-openrc.sh (kolla-venv) student@controller:~$ openstack service list +----------------------------------+-------------+----------------+ | ID | Name | Type | +----------------------------------+-------------+----------------+ | 2016e0d3e67b47f9ab8941f18912b4ed | heat | orchestration | | 3cc9267de0774fc295f9ff99ad7098ad | glance | image | | 72f7b5292bbd4cf3aa2594ffe99cf409 | nova_legacy | compute_legacy | | 7bbcedc7b0504d79b7b15e4c3619374b | keystone | identity | | 9bea6c9b9a954d82a0531ba70b0331a6 | heat-cfn | cloudformation | | 9e8e74f5a48b493097014aafe5d82268 | neutron | network | | b4ed42fee5c64ba18b96a6603dbb5b36 | placement | placement | | c1f1b5c9fbc24b2ea564e7d8ce121ef9 | nova | compute | | f03eb26e51694df79fd86174e810f10c | cinderv3 | volumev3 | +----------------------------------+-------------+----------------+
Horizon can be installed automatically during the Kolla-Ansible deployment by setting enable_horizon to yes. Kolla-Ansible will then configure Horizon for you.
If you plan to integrate Horizon with the Yuyu billing plugin, deploy Horizon manually instead. See Yuyu Billing in OpenStack Horizon for the detailed procedure. For a TLS-secured deployment, see Secure Service OpenStack and Yuyu Billing OpenStack with TLS.