Instalacija distribuiranog LeoFS objektnog skladišta otpornog na greške, kompatibilnog sa klijentima koji koriste S3, NFS

Prema Opennet: LeoFS — distribuirana pohrana objekata otpornih na greške LeoFS, kompatibilan s klijentima koji koriste Amazon S3 API i REST-API, a podržava i način rada NFS servera. Postoje optimizacije za pohranjivanje i malih i vrlo velikih objekata, postoji ugrađeni mehanizam za keširanje, a moguća je i replikacija skladišta između podatkovnih centara. Ciljevi projekta uključuju postizanje 99.9999999% pouzdanosti kroz redundantnu replikaciju duplikata i eliminisanje jedne tačke kvara. Kod projekta je napisan na Erlangu.

LeoFS se sastoji od tri komponente:

  • LeoFS Storage — služi operacijama dodavanja, preuzimanja i brisanja objekata i metapodataka, odgovoran je za obavljanje replikacije, oporavka i stavljanje u red zahtjeva klijenta.
  • LeoFS Gateway — služi HTTP zahtjeve i preusmjerava odgovore klijentima koristeći REST-API ili S3-API, osigurava keširanje najpotrebnijih podataka u memoriji i na disku.
  • LeoFS Manager — prati rad LeoFS Gateway i LeoFS Storage čvorova, prati status čvorova i provjerava kontrolne sume. Garantuje integritet podataka i visoku dostupnost skladištenja.

U ovom postu ćemo instalirati Leofs koristeći ansible-playbook i testirati S3, NFS.

Ako pokušate da instalirate LeoFS koristeći službene playbooks, naići ćete na razne greške: 1,2. U ovom postu ću napisati šta je potrebno učiniti da se ove greške izbjegnu.

Tamo gdje ćete pokrenuti ansible-playbook, morate instalirati netcat.

Primjer inventara

Primjer inventara (u spremištu hosts.sample):

# Please check roles/common/vars/leofs_releases for available versions


# nodename of leo_manager_0 and leo_manager_1 are set at group_vars/all

[leo_storage] [email protected] [email protected] [email protected] [email protected]

[leo_gateway] [email protected] [email protected]


Priprema servera

Onemogućavanje Selinuxa. Nadam se da će zajednica kreirati Selinux politike za LeoFS.

    - name: Install libselinux as prerequisite for SELinux Ansible module
        name: "{{item}}"
        state: latest
        - libselinux-python
        - libsemanage-python

    - name: Disable SELinux at next reboot
        state: disabled

    - name: Set SELinux in permissive mode until the machine is rebooted
      command: setenforce 0
      ignore_errors: true
      changed_when: false

postavljanje netcat и redhat-lsb-core. netcat potrebno za leofs-adm, redhat-lsb-core potrebno za određivanje verzije OS-a ovdje.

    - name: Install Packages
      yum: name={{ item }} state=present
        - nmap-ncat
        - redhat-lsb-core

Kreiranje korisničkih leofova i dodavanje u grupu kotača

    - name: Create user leofs
        name: leofs
        state: present

    - name: Allow 'wheel' group to have passwordless sudo
        dest: /etc/sudoers
        state: present
        regexp: '^%wheel'
        line: '%wheel ALL=(ALL) NOPASSWD: ALL'
        validate: 'visudo -cf %s'

    - name: Add the user 'leofs' to group 'wheel'
        name: leofs
        groups: wheel
        append: yes

Instaliranje Erlanga

    - name: Remote erlang- install with yum
      yum: name=

Punu verziju ispravljenog Ansible playbook-a možete pronaći ovdje:

Instalacija, konfiguracija, pokretanje

Zatim izvodimo kako je napisano bez build_leofs.yml

## Install LeoFS
$ ansible-playbook -i hosts install_leofs.yml

## Config LeoFS
$ ansible-playbook -i hosts config_leofs.yml

## Start LeoFS
$ ansible-playbook -i hosts start_leofs.yml

Provjera statusa klastera na Primary LeoManageru

leofs-adm status

Primarni i sekundarni se mogu vidjeti u zapisnicima ansible-playbook-a

Izlaz će biti otprilike ovako

 [System Confiuration]
 Item                              | Value    
 Basic/Consistency level
                    system version | 1.4.3
                        cluster Id | leofs_1
                             DC Id | dc_1
                    Total replicas | 2
          number of successes of R | 1
          number of successes of W | 1
          number of successes of D | 1
 number of rack-awareness replicas | 0
                         ring size | 2^128
 Multi DC replication settings
 [mdcr] max number of joinable DCs | 2
 [mdcr] total replicas per a DC    | 1
 [mdcr] number of successes of R   | 1
 [mdcr] number of successes of W   | 1
 [mdcr] number of successes of D   | 1
 Manager RING hash
                 current ring-hash | a0314afb
                previous ring-hash | a0314afb

 [State of Node(s)]
 type  |         node         |    state     | rack id |  current ring  |   prev ring    |          updated at         
  S    | [email protected]      | running      |         | a0314afb       | a0314afb       | 2019-12-05 10:33:47 +0000
  S    | [email protected]      | running      |         | a0314afb       | a0314afb       | 2019-12-05 10:33:47 +0000
  S    | [email protected]      | running      |         | a0314afb       | a0314afb       | 2019-12-05 10:33:47 +0000
  S    | [email protected]      | attached     |         |                |                | 2019-12-05 10:33:58 +0000
  G    | [email protected]      | running      |         | a0314afb       | a0314afb       | 2019-12-05 10:33:49 +0000
  G    | [email protected]      | running      |         | a0314afb       | a0314afb       | 2019-12-05 10:33:49 +0000

Kreiranje korisnika

Kreirajte leofs korisnika:

leofs-adm create-user leofs leofs

  access-key-id: 9c2615f32e81e6a1caf5
  secret-access-key: 8aaaa35c1ad78a2cbfa1a6cd49ba8aaeb3ba39eb

Spisak korisnika:

leofs-adm get-users
user_id     | role_id | access_key_id          | created_at                
_test_leofs | 9       | 05236                  | 2019-12-02 06:56:49 +0000
leofs       | 1       | 9c2615f32e81e6a1caf5   | 2019-12-02 10:43:29 +0000

Kreirajte kantu

Napravio kantu

leofs-adm add-bucket leofs 9c2615f32e81e6a1caf5

Bucket lista:

 leofs-adm get-buckets
cluster id   | bucket   | owner  | permissions      | created at                
leofs_1      | leofs    | leofs  | Me(full_control) | 2019-12-02 10:44:02 +0000

Konfigurisanje s3cmd

U polju HTTP Proxy server name navedite IP servera mrežnog prolaza

s3cmd --configure 

Enter new values or accept defaults in brackets with Enter.
Refer to user manual for detailed description of all options.

Access key and Secret key are your identifiers for Amazon S3. Leave them empty for using the env variables.
Access Key [9c2615f32e81e6a1caf5]: 
Secret Key [8aaaa35c1ad78a2cbfa1a6cd49ba8aaeb3ba39eb]: 
Default Region [US]: 

Use "" for S3 Endpoint and not modify it to the target Amazon S3.
S3 Endpoint []: 

Use "%(bucket)" to the target Amazon S3. "%(bucket)s" and "%(location)s" vars can be used
if the target S3 system supports dns based buckets.
DNS-style bucket+hostname:port template for accessing a bucket [%(bucket)]: leofs

Encryption password is used to protect your files from reading
by unauthorized persons while in transfer to S3
Encryption password: 
Path to GPG program [/usr/bin/gpg]: 

When using secure HTTPS protocol all communication with Amazon S3
servers is protected from 3rd party eavesdropping. This method is
slower than plain HTTP, and can only be proxied with Python 2.7 or newer
Use HTTPS protocol [No]: 

On some networks all internet access must go through a HTTP proxy.
Try setting it here if you can't connect to S3 directly
HTTP Proxy server name []: 
HTTP Proxy server port [8080]: 

New settings:
  Access Key: 9c2615f32e81e6a1caf5
  Secret Key: 8aaaa35c1ad78a2cbfa1a6cd49ba8aaeb3ba39eb
  Default Region: US
  S3 Endpoint:
  DNS-style bucket+hostname:port template for accessing a bucket: leofs
  Encryption password: 
  Path to GPG program: /usr/bin/gpg
  Use HTTPS protocol: False
  HTTP Proxy server name:
  HTTP Proxy server port: 8080

Test access with supplied credentials? [Y/n] Y
Please wait, attempting to list all buckets...
Success. Your access key and secret key worked fine :-)

Now verifying that encryption works...
Not configured. Never mind.

Save settings? [y/N] y
Configuration saved to '/home/user/.s3cfg'

Ako dobijete grešku GREŠKA: S3 greška: 403 (Pristup odbijen): Pristup odbijen:

s3cmd put s3://leofs/
upload: '' -> 's3://leofs/'  [1 of 1]
 382 of 382   100% in    0s     3.40 kB/s  done
ERROR: S3 error: 403 (AccessDenied): Access Denied

Zatim morate promijeniti signature_v3 u True u s2cmd konfiguraciji. Detalji u ovome problem.

Ako je signature_v2 False, tada će doći do greške poput ove:

WARNING: Retrying failed request: /?delimiter=%2F (getaddrinfo() argument 2 must be integer or string)
WARNING: Waiting 3 sec...
WARNING: Retrying failed request: /?delimiter=%2F (getaddrinfo() argument 2 must be integer or string)
WARNING: Waiting 6 sec...
ERROR: Test failed: Request failed for: /?delimiter=%2F

Testiranje opterećenja

Kreirajte datoteku od 1 GB

fallocate -l 1GB 1gb

Prenesite ga na Leofs

time s3cmd put 1gb s3://leofs/
real    0m19.099s
user    0m7.855s
sys 0m1.620s


leofs-adm du za 1 čvor:

leofs-adm du [email protected]
 active number of objects: 156
  total number of objects: 156
   active size of objects: 602954495
    total size of objects: 602954495
     ratio of active size: 100.0%
    last compaction start: ____-__-__ __:__:__
      last compaction end: ____-__-__ __:__:__

Vidimo da zaključak nije baš informativan.

Hajde da vidimo gde se ovaj fajl nalazi.
leofs-adm gdje je leofs/1gb

leofs-adm whereis leofs/1gb
 del?  |         node         |             ring address             |    size    |   checksum   |  has children  |  total chunks  |     clock      |             when            
       | [email protected]      | 657a9f3a3db822a7f1f5050925b26270     |    976563K |   a4634eea55 | true           |             64 | 598f2aa976a4f  | 2019-12-05 10:48:15 +0000
       | [email protected]      | 657a9f3a3db822a7f1f5050925b26270     |    976563K |   a4634eea55 | true           |             64 | 598f2aa976a4f  | 2019-12-05 10:48:15 +0000

Aktivirajte NFS

Aktiviramo NFS na serveru Leo Gateway

Instalirajte nfs-utils na server i klijent

sudo yum install nfs-utils

Prema uputama, ispravit ćemo konfiguracijski fajl /usr/local/leofs/current/leo_gateway/etc/leo_gateway.conf

protocol = nfs

Na serveru pokrenite rpcbind i leofs-gateway

sudo service rpcbind start
sudo service leofs-gateway restart

Na serveru na kojem leo_manager radi, kreirajte bucket za NFS i generirajte ključ za povezivanje na NFS

leofs-adm add-bucket test 05236
leofs-adm gen-nfs-mnt-key test 05236 ip-адрес-nfs-клиента

Povezivanje na NFS

sudo mkdir /mnt/leofs
## for Linux - "sudo mount -t nfs -o nolock <host>:/<bucket>/<token> <dir>"
sudo mount -t nfs -o nolock ip-адрес-nfs-сервера-там-где-у-вас-установлен-gateway:/bucket/access_key_id/ключ-полученный-от-gen-nfs-mnt-key /mnt/leofs
sudo mount -t nfs -o nolock /mnt/leofs

Pregledajte prostor na disku putem NFS klijenta

Prostor na disku, uzimajući u obzir da svaki čvor za pohranu ima disk od 40 GB (3 pokrenuta čvora, 1 priključeni čvor):

df -hP
Filesystem                                                         Size  Used Avail Use% Mounted on   60G  3.6G   57G   6% /mnt/leofs

Instalacija LeoFS-a sa 6 skladišnih čvorova.

Inventar (bez graditelja):

# Please check roles/common/vars/leofs_releases for available versions

# nodename of leo_manager_0 and leo_manager_1 are set at group_vars/all

[leo_storage] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected]

[leo_gateway] [email protected] [email protected]


Izlaz leofs-adm status

 [System Confiuration]
 Item                              | Value    
 Basic/Consistency level
                    system version | 1.4.3
                        cluster Id | leofs_1
                             DC Id | dc_1
                    Total replicas | 2
          number of successes of R | 1
          number of successes of W | 1
          number of successes of D | 1
 number of rack-awareness replicas | 0
                         ring size | 2^128
 Multi DC replication settings
 [mdcr] max number of joinable DCs | 2
 [mdcr] total replicas per a DC    | 1
 [mdcr] number of successes of R   | 1
 [mdcr] number of successes of W   | 1
 [mdcr] number of successes of D   | 1
 Manager RING hash
                 current ring-hash | d8ff465e
                previous ring-hash | d8ff465e

 [State of Node(s)]
 type  |         node         |    state     | rack id |  current ring  |   prev ring    |          updated at         
  S    | [email protected]      | running      |         | d8ff465e       | d8ff465e       | 2019-12-06 05:18:29 +0000
  S    | [email protected]      | running      |         | d8ff465e       | d8ff465e       | 2019-12-06 05:18:29 +0000
  S    | [email protected]      | running      |         | d8ff465e       | d8ff465e       | 2019-12-06 05:18:30 +0000
  S    | [email protected]      | running      |         | d8ff465e       | d8ff465e       | 2019-12-06 05:18:29 +0000
  S    | [email protected]      | running      |         | d8ff465e       | d8ff465e       | 2019-12-06 05:18:29 +0000
  S    | [email protected]      | running      |         | d8ff465e       | d8ff465e       | 2019-12-06 05:18:29 +0000
  G    | [email protected]      | running      |         | d8ff465e       | d8ff465e       | 2019-12-06 05:18:31 +0000
  G    | [email protected]      | running      |         | d8ff465e       | d8ff465e       | 2019-12-06 05:18:31 +0000

Prostor na disku, uzimajući u obzir da svaki čvor za pohranu ima disk od 40 GB (6 aktivnih čvorova):

df -hP
Filesystem                                                         Size  Used Avail Use% Mounted on  120G  3.6G  117G   3% /mnt/leofs

Ako se koristi 5 skladišnih čvorova

[leo_storage] [email protected] [email protected] [email protected] [email protected] [email protected]

df -hP  100G  3.0G   97G   3% /mnt/leofs


Dnevnici se nalaze u imenicima /usr/local/leofs/current/*/log

Telegram kanal: SDS i Cluster FS


