oVirt ืชื•ืš 2 ืฉืขื•ืช. ื—ืœืง 3. ื”ื’ื“ืจื•ืช ื ื•ืกืคื•ืช

ื‘ืžืืžืจ ื–ื”, ื ื‘ื—ืŸ ืžืกืคืจ ื”ื’ื“ืจื•ืช ืื•ืคืฆื™ื•ื ืœื™ื•ืช ืืš ืฉื™ืžื•ืฉื™ื•ืช:

ืžืืžืจ ื–ื” ื”ื•ื ื”ืžืฉืš, ื”ืชื—ืœ ืœืจืื•ืช oVirt ื‘ืขื•ื“ ืฉืขืชื™ื™ื ื—ืœืง ืž- 1 ะธ ื—ืœืง 2.

ืžืืžืจื™ื

  1. ืžื‘ื•ื
  2. ื”ืชืงื ืช ื”ืžื ื”ืœ (ืžื ื•ืข ืื•ื•ื•ื™ืจื˜) ื•ื”ื™ืคืจื•ื•ื™ื–ื•ืจื™ื (ืžืืจื—ื™ื)
  3. ื”ื’ื“ืจื•ืช ื ื•ืกืคื•ืช - ืื ื—ื ื• ื›ืืŸ

ื”ื’ื“ืจื•ืช ืžื ื”ืœ ื ื•ืกืคื•ืช

ืžื˜ืขืžื™ ื ื•ื—ื•ืช, ื ืชืงื™ืŸ ื—ื‘ื™ืœื•ืช ื ื•ืกืคื•ืช:

$ sudo yum install bash-completion vim

ื›ื“ื™ ืœืืคืฉืจ ื”ืฉืœืžื” ืื•ื˜ื•ืžื˜ื™ืช ืฉืœ ืคืงื•ื“ื•ืช ื”ืฉืœืžืช bash, ืขื‘ื•ืจ ืœ-bash.

ื”ื•ืกืคืช ืฉืžื•ืช DNS ื ื•ืกืคื™ื

ื–ื” ื™ื™ื“ืจืฉ ื›ืืฉืจ ืืชื” ืฆืจื™ืš ืœื”ืชื—ื‘ืจ ืœืžื ื”ืœ ื‘ืืžืฆืขื•ืช ืฉื ื—ืœื•ืคื™ (CNAME, ื›ื™ื ื•ื™, ืื• ืจืง ืฉื ืงืฆืจ ืœืœื ืกื™ื•ืžืช ื“ื•ืžื™ื™ืŸ). ืžื˜ืขืžื™ ืื‘ื˜ื—ื”, ื”ืžื ื”ืœ ืžืืคืฉืจ ืจืง ื—ื™ื‘ื•ืจื™ื ืœืจืฉื™ืžืช ื”ืฉืžื•ืช ื”ืžื•ืชืจื™ื.

ืฆื•ืจ ืงื•ื‘ืฅ ืชืฆื•ืจื”:

$ sudo vim /etc/ovirt-engine/engine.conf.d/99-custom-sso-setup.conf

ื”ืชื•ื›ืŸ ื”ื‘ื:

SSO_ALTERNATE_ENGINE_FQDNS="ovirt.example.com some.alias.example.com ovirt"

ื•ื”ืคืขืœ ืžื—ื“ืฉ ืืช ื”ืžื ื”ืœ:

$ sudo systemctl restart ovirt-engine

ื”ื’ื“ืจืช ืื™ืžื•ืช ื‘ืืžืฆืขื•ืช AD

ืœ-oVirt ื‘ืกื™ืก ืžืฉืชืžืฉื™ื ืžื•ื‘ื ื”, ืืš ื ืชืžื›ื™ื ื’ื ืกืคืงื™ LDAP ื—ื™ืฆื•ื ื™ื™ื, ื›ื•ืœืœ. ืžื•ึนื“ึธืขึธื”.

ื”ื“ืจืš ื”ืคืฉื•ื˜ื” ื‘ื™ื•ืชืจ ืœืชืฆื•ืจื” ื˜ื™ืคื•ืกื™ืช ื”ื™ื ืœื”ืคืขื™ืœ ืืช ื”ืืฉืฃ ื•ืœื”ืคืขื™ืœ ืžื—ื“ืฉ ืืช ื”ืžื ื”ืœ:

$ sudo yum install ovirt-engine-extension-aaa-ldap-setup
$ sudo ovirt-engine-extension-aaa-ldap-setup
$ sudo systemctl restart ovirt-engine

ื“ื•ื’ืžื” ืœืืฉืฃ
$ sudo ovirt-engine-extension-aaa-ldap-setup
ื™ื™ืฉื•ืžื™ LDAP ื–ืžื™ื ื™ื:
...
3 - Active Directory
...
ื‘ื‘ืงืฉื” ืชื‘ื—ืจ: 3
ืื ื ื”ื–ืŸ ืืช ืฉื ื™ืขืจ Active Directory: example.com

ืื ื ื‘ื—ืจ ืคืจื•ื˜ื•ืงื•ืœ ืœืฉื™ืžื•ืฉ (startTLS, ldaps, plain) [startTLS]:
ืื ื ื‘ื—ืจ ืฉื™ื˜ื” ืœืงื‘ืœืช ืื™ืฉื•ืจ CA ืžืงื•ื“ื“ PEM (ืงื•ื‘ืฅ, ื›ืชื•ื‘ืช ืืชืจ, ืžื•ื˜ื‘ืข, ืžืขืจื›ืช, ืœื ืžืื•ื‘ื˜ื—): ื›ืชื•ื‘ืช ื”ืืชืจ
ื›ืชื•ื‘ืช ื”ืืชืจ: wwwca.example.com/myRootCA.pem
ื”ื–ืŸ ืืช DN ื”ืžืฉืชืžืฉ ื‘ื—ื™ืคื•ืฉ (ืœื“ื•ื’ืžื” uid=username,dc=example,dc=com ืื• ื”ืฉืืจ ืจื™ืง ืขื‘ื•ืจ ืื ื•ื ื™ืžื™): CN=oVirt-Engine,CN=Users,DC=example,DC=com
ื”ื–ืŸ ืกื™ืกืžืช ืžืฉืชืžืฉ ืœื—ื™ืคื•ืฉ: *ืกื™ืกืžื”*
[ ืžื™ื“ืข ] ื ื™ืกื™ื•ืŸ ืœืื’ื“ ื‘ืืžืฆืขื•ืช 'CN=oVirt-Engine,CN=Users,DC=example,DC=com'
ื”ืื ืืชื” ืžืชื›ื•ื•ืŸ ืœื”ืฉืชืžืฉ ื‘ื›ื ื™ืกื” ื™ื—ื™ื“ื” ืœืžื›ื•ื ื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช (ื›ืŸ, ืœื) [ื›ืŸ]:
ืื ื ืฆื™ื™ืŸ ืืช ืฉื ื”ืคืจื•ืคื™ืœ ืฉื™ื”ื™ื” ื’ืœื•ื™ ืœืžืฉืชืžืฉื™ื [example.com]:
ืื ื ืกืคืง ืื™ืฉื•ืจื™ื ืœื‘ื“ื™ืงืช ื–ืจื™ืžืช ื”ื›ื ื™ืกื”:
ื”ื›ื ืก ืฉื ืžืฉืชืžืฉ: someAnyUser
ื”ื–ืŸ ืกื™ืกืžืช ืžืฉืชืžืฉ:
...
[ ืžื™ื“ืข ] ืจืฆืฃ ื”ื›ื ื™ืกื” ื‘ื•ืฆืข ื‘ื”ืฆืœื—ื”
...
ื‘ื—ืจ ืจืฆืฃ ื‘ื“ื™ืงื” ืœื‘ื™ืฆื•ืข (ืกื™ื•ื, ื‘ื™ื˜ื•ืœ, ื”ืชื—ื‘ืจื•ืช, ื—ื™ืคื•ืฉ) [ื‘ื•ืฆืข]:
[ ืžื™ื“ืข ] ืฉืœื‘: ื”ื’ื“ืจืช ื”ืขืกืงื”
...
ืชืงืฆื™ืจ ืชืฆื•ืจื”
...

ื”ืฉื™ืžื•ืฉ ื‘ืืฉืฃ ืžืชืื™ื ืœืจื•ื‘ ื”ืžืงืจื™ื. ืขื‘ื•ืจ ืชืฆื•ืจื•ืช ืžื•ืจื›ื‘ื•ืช, ื”ื”ื’ื“ืจื•ืช ืžืชื‘ืฆืขื•ืช ื‘ืื•ืคืŸ ื™ื“ื ื™. ืคืจื˜ื™ื ื ื•ืกืคื™ื ื‘ืชื™ืขื•ื“ oVirt, ืžืฉืชืžืฉื™ื ื•ืชืคืงื™ื“ื™ื. ืœืื—ืจ ื—ื™ื‘ื•ืจ ื”ืžื ื•ืข ื‘ื”ืฆืœื—ื” ืœ-AD, ื™ื•ืคื™ืข ืคืจื•ืคื™ืœ ื ื•ืกืฃ ื‘ื—ืœื•ืŸ ื”ื—ื™ื‘ื•ืจ, ื•ื‘- ื”ืจืฉืื•ืช ืœืื•ื‘ื™ื™ืงื˜ื™ ืžืขืจื›ืช ื™ืฉ ืืช ื”ื™ื›ื•ืœืช ืœื”ืขื ื™ืง ื”ืจืฉืื•ืช ืœืžืฉืชืžืฉื™ ื•ืงื‘ื•ืฆื•ืช AD. ื™ืฉ ืœืฆื™ื™ืŸ ืฉื”ืžื“ืจื™ืš ื”ื—ื™ืฆื•ื ื™ ืฉืœ ืžืฉืชืžืฉื™ื ื•ืงื‘ื•ืฆื•ืช ื™ื›ื•ืœ ืœื”ื™ื•ืช ืœื ืจืง AD, ืืœื ื’ื IPA, eDirectory ื•ื›ื•'.

ืจื™ื‘ื•ื™ ื“ืจื›ื™ื

ื‘ืกื‘ื™ื‘ืช ื™ื™ืฆื•ืจ, ืžืขืจื›ืช ื”ืื—ืกื•ืŸ ื—ื™ื™ื‘ืช ืœื”ื™ื•ืช ืžื—ื•ื‘ืจืช ืœืžืืจื— ื‘ืืžืฆืขื•ืช ื ืชื™ื‘ื™ ืงืœื˜/ืคืœื˜ ืžืจื•ื‘ื™ื, ืขืฆืžืื™ื™ื, ืžืจื•ื‘ื™ื. ื›ื›ืœืœ, ื‘-CentOS (ื•ืœื›ืŸ oVirt'e) ืื™ืŸ ื‘ืขื™ื•ืช ื‘ื‘ื ื™ื™ืช ืžืกืคืจ ื ืชื™ื‘ื™ื ืœืžื›ืฉื™ืจ (find_multipaths ื›ืŸ). ื”ื’ื“ืจื•ืช ื ื•ืกืคื•ืช ืขื‘ื•ืจ FCoE ืžืชื•ืืจื•ืช ื‘ ื—ืœืง 2. ื›ื“ืื™ ืœืฉื™ื ืœื‘ ืœื”ืžืœืฆื” ืฉืœ ื™ืฆืจืŸ ื”ืื—ืกื•ืŸ - ืจื‘ื™ื ืžืžืœื™ืฆื™ื ืœื”ืฉืชืžืฉ ื‘ืžื“ื™ื ื™ื•ืช ื”-round robin, ื‘ืขื•ื“ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ Enterprise Linux 7 ืžืฉืชืžืฉ ื‘ื–ืžืŸ ืฉื™ืจื•ืช.

ืขืœ ื”ื“ื•ื’ืžื” ืฉืœ 3PAR
ื•ืœืชืขื“ HPE 3PAR Red Hat Enterprise Linux, CentOS Linux, Oracle Linux ื•-OracleVM Server ืžื“ืจื™ืš ืœื™ื™ืฉื•ื EL ื ื•ืฆืจ ื›ืžืืจื— ืขื Generic-ALUA Persona 2, ืฉืขื‘ื•ืจื• ื”ืขืจื›ื™ื ื”ื‘ืื™ื ืžื•ื–ื ื™ื ื‘ื”ื’ื“ืจื•ืช /etc/multipath.conf:

defaults {
           polling_interval      10
           user_friendly_names   no
           find_multipaths       yes
          }
devices {
          device {
                   vendor                   "3PARdata"
                   product                  "VV"
                   path_grouping_policy     group_by_prio
                   path_selector            "round-robin 0"
                   path_checker             tur
                   features                 "0"
                   hardware_handler         "1 alua"
                   prio                     alua
                   failback                 immediate
                   rr_weight                uniform
                   no_path_retry            18
                   rr_min_io_rq             1
                   detect_prio              yes
                   fast_io_fail_tmo         10
                   dev_loss_tmo             "infinity"
                 }
}

ืœืื—ืจ ืžื›ืŸ ื ื™ืชื ืช ื”ืคืงื•ื“ื” ืœื”ืคืขืœื” ืžื—ื“ืฉ:

systemctl restart multipathd

oVirt ืชื•ืš 2 ืฉืขื•ืช. ื—ืœืง 3. ื”ื’ื“ืจื•ืช ื ื•ืกืคื•ืช
ืื•ืจื–. 1 ื”ื™ื ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืฉืœ ืžื“ื™ื ื™ื•ืช ื”ืงืœื˜/ืคืœื˜ ืžืจื•ื‘ื”.

oVirt ืชื•ืš 2 ืฉืขื•ืช. ื—ืœืง 3. ื”ื’ื“ืจื•ืช ื ื•ืกืคื•ืช
ืื•ืจื–. 2 - ืžื“ื™ื ื™ื•ืช I/O ืžืจื•ื‘ื” ืœืื—ืจ ื”ื—ืœืช ื”ื”ื’ื“ืจื•ืช.

ื”ื’ื“ืจืช ื ื™ื”ื•ืœ ืฆืจื™ื›ืช ื—ืฉืžืœ

ืžืืคืฉืจ ืœืš ืœื‘ืฆืข, ืœืžืฉืœ, ืื™ืคื•ืก ืงืฉื™ื— ืฉืœ ื”ืžื›ื•ื ื” ืื ื”ืžื ื•ืข ืœื ื™ื›ื•ืœ ืœืงื‘ืœ ืชื’ื•ื‘ื” ืžื”ืžืืจื— ื‘ืžืฉืš ื–ืžืŸ ืจื‘. ืžื™ื•ืฉื ื‘ืืžืฆืขื•ืช ืกื•ื›ืŸ ื”ื’ื“ืจ.

ืžื—ืฉื‘ -> ืžืืจื—ื™ื -> HOST - ืขืจื•ืš -> ื ื™ื”ื•ืœ ืฆืจื™ื›ืช ื—ืฉืžืœ, ื•ืœืื—ืจ ืžื›ืŸ ื”ืคืขืœ ืืช "ื”ืคืขืœ ื ื™ื”ื•ืœ ืฆืจื™ื›ืช ื—ืฉืžืœ" ื•ื”ื•ืกืฃ ืกื•ื›ืŸ - "ื”ื•ืกืฃ ืกื•ื›ืŸ ื’ื“ืจ" -> +.

ืฆื™ื™ืŸ ืืช ื”ืกื•ื’ (ืœื“ื•ื’ืžื”, ืขื‘ื•ืจ iLO5, ืขืœื™ืš ืœืฆื™ื™ืŸ ilo4), ืืช ื”ืฉื/ื”ื›ืชื•ื‘ืช ืฉืœ ืžืžืฉืง ื”-ipmi ื•ืืช ืฉื ื”ืžืฉืชืžืฉ/ื”ืกื™ืกืžื”. ืžื•ืžืœืฅ ืœื™ืฆื•ืจ ืžืฉืชืžืฉ ื ืคืจื“ (ืœื“ื•ื’ืžื”, oVirt-PM) ื•ื‘ืžืงืจื” ืฉืœ iLO ืœืชืช ืœื• ื”ืจืฉืื•ืช:

  • ื”ืชื—ื‘ืจื•ืช
  • ืงื•ื ืกื•ืœื” ืžืจื—ื•ืง
  • ื›ื•ื— ื•ืื™ืคื•ืก ื•ื™ืจื˜ื•ืืœื™
  • ืžื“ื™ื” ื•ื™ืจื˜ื•ืืœื™ืช
  • ื”ื’ื“ืจ ืืช ื”ื’ื“ืจื•ืช iLO
  • ื ื™ื”ื•ืœ ื—ืฉื‘ื•ื ื•ืช ืžืฉืชืžืฉ

ืืœ ืชืฉืืœื• ืœืžื” ื–ื” ื›ืš, ื–ื” ื ื‘ื—ืจ ื‘ืื•ืคืŸ ืืžืคื™ืจื™. ืกื•ื›ืŸ ื’ื™ื“ื•ืจ ื”ืงื•ื ืกื•ืœื•ืช ื“ื•ืจืฉ ืงื‘ื•ืฆื” ืงื˜ื ื” ื™ื•ืชืจ ืฉืœ ื–ื›ื•ื™ื•ืช.

ื‘ืขืช ื”ื’ื“ืจืช ืจืฉื™ืžื•ืช ื‘ืงืจืช ื’ื™ืฉื”, ื™ืฉ ืœื–ื›ื•ืจ ื›ื™ ื”ืกื•ื›ืŸ ืื™ื ื• ืคื•ืขืœ ืขืœ ื”ืžื ื•ืข, ืืœื ืขืœ ื”ืžืืจื— "ื”ืฉื›ืŸ" (ืžื” ืฉื ืงืจื Power Management Proxy), ื›ืœื•ืžืจ, ืื ื™ืฉ ืจืง ืฆื•ืžืช ืื—ื“ ื‘- ืืฉื›ื•ืœ, ื ื™ื”ื•ืœ ืฆืจื™ื›ืช ื”ื—ืฉืžืœ ื™ืขื‘ื•ื“ ืœื.

ื”ื’ื“ืจืช SSL

ื”ื•ืจืื•ืช ืจืฉืžื™ื•ืช ืžืœืื•ืช - ื‘ ืชื™ืขื•ื“, ื ืกืคื— ื“': oVirt ื•-SSL - ื”ื—ืœืคืช ืชืขื•ื“ืช oVirt Engine SSL/TLS.

ื”ืื™ืฉื•ืจ ื™ื›ื•ืœ ืœื”ื™ื•ืช ืž-CA ื”ืืจื’ื•ื ื™ ืฉืœื ื• ืื• ืž-CA ืžืกื—ืจื™ ื—ื™ืฆื•ื ื™.

ื”ืขืจื” ื—ืฉื•ื‘ื”: ื”ืชืขื•ื“ื” ื ื•ืขื“ื” ืœื”ืชื—ื‘ืจ ืœืžื ื”ืœ, ืœื ืชืฉืคื™ืข ืขืœ ื”ืื™ื ื˜ืจืืงืฆื™ื” ื‘ื™ืŸ ื”ืžื ื•ืข ื•ื”ืฆืžืชื™ื - ื”ื ื™ืฉืชืžืฉื• ื‘ืชืขื•ื“ื•ืช ื‘ื—ืชื™ืžื” ืขืฆืžื™ืช ืฉื”ื•ื ืคืงื• ืขืœ ื™ื“ื™ ื”ืžื ื•ืข.

ื“ืจื™ืฉื•ืช:

  • ืื™ืฉื•ืจ ื”-CA ื”ืžื ืคื™ืง ื‘ืคื•ืจืžื˜ PEM, ืขื ื›ืœ ื”ืฉืจืฉืจืช ืœ-CA ื”ืฉื•ืจืฉ (ืžื”ื”ื ืคืงื” ื”ื›ืคื•ืคื” ื‘ื”ืชื—ืœื” ื•ืขื“ ื”ืฉื•ืจืฉ ื‘ืกื•ืฃ);
  • ืื™ืฉื•ืจ ืœืืคืฆ'ื™ ืฉื”ื•ื ืคืง ืขืœ ื™ื“ื™ ื”-CA ื”ืžื ืคื™ืง (ื’ื ืžืœื ืขื ื›ืœ ืฉืจืฉืจืช ืชืขื•ื“ื•ืช ื”-CA);
  • ืžืคืชื— ืคืจื˜ื™ ืขื‘ื•ืจ Apache, ืœืœื ืกื™ืกืžื”.

ื ื ื™ื— ืฉื”-CA ื”ืžื ืคื™ืง ืฉืœื ื• ืžืจื™ืฅ CentOS, ื”ื ืงืจื subca.example.com, ื•ื”ื‘ืงืฉื•ืช, ื”ืžืคืชื—ื•ืช ื•ื”ืื™ืฉื•ืจื™ื ื ืžืฆืื™ื ื‘ืกืคืจื™ื™ื” /etc/pki/tls/.

ื‘ืฆืข ื’ื™ื‘ื•ื™ื™ื ื•ืฆื•ืจ ืกืคืจื™ื™ื” ื–ืžื ื™ืช:

$ sudo cp /etc/pki/ovirt-engine/keys/apache.key.nopass /etc/pki/ovirt-engine/keys/apache.key.nopass.`date +%F`
$ sudo cp /etc/pki/ovirt-engine/certs/apache.cer /etc/pki/ovirt-engine/certs/apache.cer.`date +%F`
$ sudo mkdir /opt/certs
$ sudo chown mgmt.mgmt /opt/certs

ื”ื•ืจื“ ืื™ืฉื•ืจื™ื, ื”ืคืขืœ ืื•ืชื ืžืชื—ื ืช ื”ืขื‘ื•ื“ื” ืฉืœืš ืื• ื”ืขื‘ืจ ืื•ืชื ื‘ื“ืจืš ื ื•ื—ื” ืื—ืจืช:

[myuser@mydesktop] $ scp -3 [email protected]:/etc/pki/tls/cachain.pem [email protected]:/opt/certs
[myuser@mydesktop] $ scp -3 [email protected]:/etc/pki/tls/private/ovirt.key [email protected]:/opt/certs
[myuser@mydesktop] $ scp -3 [email protected]/etc/pki/tls/certs/ovirt.crt [email protected]:/opt/certs

ื›ืชื•ืฆืื” ืžื›ืš, ืืชื” ืืžื•ืจ ืœืจืื•ืช ืืช ื›ืœ 3 ื”ืงื‘ืฆื™ื:

$ ls /opt/certs
cachain.pem  ovirt.crt  ovirt.key

ื”ืชืงื ืช ืชืขื•ื“ื•ืช

ื”ืขืชืง ืงื‘ืฆื™ื ื•ืขื“ื›ืŸ ืจืฉื™ืžื•ืช ืืžื•ืŸ:

$ sudo cp /opt/certs/cachain.pem /etc/pki/ca-trust/source/anchors
$ sudo update-ca-trust
$ sudo rm /etc/pki/ovirt-engine/apache-ca.pem
$ sudo cp /opt/certs/cachain.pem /etc/pki/ovirt-engine/apache-ca.pem
$ sudo cp /opt/certs/ovirt03.key /etc/pki/ovirt-engine/keys/apache.key.nopass
$ sudo cp /opt/certs/ovirt03.crt /etc/pki/ovirt-engine/certs/apache.cer
$ sudo systemctl restart httpd.service

ื”ื•ืกืฃ/ืขื“ื›ืŸ ืงื•ื‘ืฆื™ ืชืฆื•ืจื”:

$ sudo vim /etc/ovirt-engine/engine.conf.d/99-custom-truststore.conf
ENGINE_HTTPS_PKI_TRUST_STORE="/etc/pki/java/cacerts"
ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD=""
$ sudo vim /etc/ovirt-engine/ovirt-websocket-proxy.conf.d/10-setup.conf
SSL_CERTIFICATE=/etc/pki/ovirt-engine/certs/apache.cer
SSL_KEY=/etc/pki/ovirt-engine/keys/apache.key.nopass
$ sudo vim /etc/ovirt-imageio-proxy/ovirt-imageio-proxy.conf
# Key file for SSL connections
ssl_key_file = /etc/pki/ovirt-engine/keys/apache.key.nopass
# Certificate file for SSL connections
ssl_cert_file = /etc/pki/ovirt-engine/certs/apache.cer

ืœืื—ืจ ืžื›ืŸ, ื”ืคืขืœ ืžื—ื“ืฉ ืืช ื›ืœ ื”ืฉื™ืจื•ืชื™ื ื”ืžื•ืฉืคืขื™ื:

$ sudo systemctl restart ovirt-provider-ovn.service
$ sudo systemctl restart ovirt-imageio-proxy
$ sudo systemctl restart ovirt-websocket-proxy
$ sudo systemctl restart ovirt-engine.service

ืžื•ึผื›ึธืŸ! ื–ื” ื”ื–ืžืŸ ืœื”ืชื—ื‘ืจ ืœืžื ื”ืœ ื•ืœื‘ื“ื•ืง ืฉื”ื—ื™ื‘ื•ืจ ืžืื•ื‘ื˜ื— ืขื ืชืขื•ื“ืช SSL ื—ืชื•ืžื”.

ื‘ืืจื›ื™ื•ืŸ

ืื™ืคื” ื‘ืœืขื“ื™ื”! ื‘ื—ืœืง ื–ื”, ื ื“ื‘ืจ ืขืœ ืืจื›ื™ื•ืŸ ื”ืžื ื”ืœ, ืืจื›ื™ื•ืŸ ื”-VM ื”ื•ื ื ื•ืฉื ื ืคืจื“. ื ื™ืฆื•ืจ ืขื•ืชืงื™ ืืจื›ื™ื•ืŸ ืคืขื ื‘ื™ื•ื ื•ื ืฉืžื•ืจ ืื•ืชื ืขืœ NFS, ืœืžืฉืœ, ื‘ืื•ืชื” ืžืขืจื›ืช ืฉื‘ื” ืžื™ืงืžื ื• ืืช ืชืžื•ื ื•ืช ื”-ISO - mynfs1.example.com:/exports/ovirt-backup. ืœื ืžื•ืžืœืฅ ืœืื—ืกืŸ ืืจื›ื™ื•ื ื™ื ืขืœ ืื•ืชื” ืžื›ื•ื ื” ืฉื‘ื” ืคื•ืขืœ ื”ืžื ื•ืข.

ื”ืชืงืŸ ื•ื”ืคืขืœ ืื•ื˜ื•ืžื˜ื™ื™ื:

$ sudo yum install autofs
$ sudo systemctl enable autofs
$ sudo systemctl start autofs

ืฆื•ืจ ืกืงืจื™ืคื˜:

$ sudo vim /etc/cron.daily/make.oVirt.backup.sh

ื”ืชื•ื›ืŸ ื”ื‘ื:

#!/bin/bash

datetime=`date +"%F.%R"`
backupdir="/net/mynfs01.example.com/exports/ovirt-backup"
filename="$backupdir/`hostname --short`.`date +"%F.%R"`"
engine-backup --mode=backup --scope=all --file=$filename.data --log=$filename.log
#uncomment next line for autodelete files older 30 days 
#find $backupdir -type f -mtime +30 -exec rm -f {} ;

ื”ืคื™ื›ืช ื”ืงื•ื‘ืฅ ืœืืคืฉืจื™ ื”ืคืขืœื”:

$ sudo chmod a+x /etc/cron.daily/make.oVirt.backup.sh

ื›ืขืช ื‘ื›ืœ ืขืจื‘ ื ืงื‘ืœ ืืจื›ื™ื•ืŸ ืฉืœ ื”ื’ื“ืจื•ืช ืžื ื”ืœ.

ืžืžืฉืง ื ื™ื”ื•ืœ ืžืืจื—

ืชื ื˜ื™ื™ืก ื”ื•ื ืžืžืฉืง ื ื™ื”ื•ืœ ืžื•ื“ืจื ื™ ืœืžืขืจื›ื•ืช ืœื™ื ื•ืงืก. ื‘ืžืงืจื” ื–ื”, ื”ื•ื ืžื‘ืฆืข ืชืคืงื™ื“ ื“ื•ืžื” ืœืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜ ืฉืœ ESXi.

oVirt ืชื•ืš 2 ืฉืขื•ืช. ื—ืœืง 3. ื”ื’ื“ืจื•ืช ื ื•ืกืคื•ืช
ืื•ืจื–. 3 - ืžืจืื” ื”ืคืื ืœ.

ื”ื”ืชืงื ื” ืคืฉื•ื˜ื” ืžืื•ื“, ืืชื” ืฆืจื™ืš ื—ื‘ื™ืœื•ืช ืฉืœ ืชื ื”ื˜ื™ื™ืก ื•ืืช ื”ืคืœืื’ื™ืŸ ืฉืœ ืœื•ื— ื”ืžื—ื•ื•ื ื™ื ืฉืœ ืชื ื”ื˜ื™ื™ืก:

$ sudo yum install cockpit cockpit-ovirt-dashboard -y

ื”ื—ืœืคืช ืชื ื”ื˜ื™ื™ืก:

$ sudo systemctl enable --now cockpit.socket

ื”ื’ื“ืจืช ื—ื•ืžืช ืืฉ:

sudo firewall-cmd --add-service=cockpit
sudo firewall-cmd --add-service=cockpit --permanent

ื›ืขืช ืืชื” ื™ื›ื•ืœ ืœื”ืชื—ื‘ืจ ืœืžืืจื—: https://[Host IP or FQDN]:9090

ืจืฉืชื•ืช VLAN

ืงืจื ืขื•ื“ ืขืœ ืจืฉืชื•ืช ื‘ ืชื™ืขื•ื“. ื™ืฉื ืŸ ืืคืฉืจื•ื™ื•ืช ืจื‘ื•ืช, ื›ืืŸ ื ืชืืจ ืืช ื”ื—ื™ื‘ื•ืจ ืฉืœ ืจืฉืชื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช.

ื›ื“ื™ ืœื—ื‘ืจ ืจืฉืชื•ืช ืžืฉื ื” ืื—ืจื•ืช, ืชื—ื™ืœื” ื™ืฉ ืœืชืืจ ืื•ืชืŸ ื‘ืชืฆื•ืจื”: ืจืฉืช -> ืจืฉืชื•ืช -> ื—ื“ืฉ, ื›ืืŸ ืจืง ื”ืฉื ื”ื•ื ืฉื“ื” ื—ื•ื‘ื”; ืชื™ื‘ืช ื”ืกื™ืžื•ืŸ ืจืฉืช VM, ื”ืžืืคืฉืจืช ืœืžื›ื•ื ื•ืช ืœื”ืฉืชืžืฉ ื‘ืจืฉืช ื–ื•, ืžื•ืคืขืœืช, ื•ื›ื“ื™ ืœื—ื‘ืจ ืืช ื”ืชื’, ืขืœื™ืš ืœื”ืคืขื™ืœ ืืคืฉืจ ืชื™ื•ื’ VLAN, ื”ื–ืŸ ืืช ืžืกืคืจ ื”-VLAN ื•ืœื—ืฅ ืขืœ ืื™ืฉื•ืจ.

ื›ืขืช ืขืœื™ืš ืœืขื‘ื•ืจ ืœ-Compute -> Hosts -> kvmNN -> Network Interfaces -> Setup Host Networks hosts. ื’ืจื•ืจ ืืช ื”ืจืฉืช ืฉื ื•ืกืคื” ืžื”ืฆื“ ื”ื™ืžื ื™ ืฉืœ ืจืฉืชื•ืช ืœื•ื’ื™ื•ืช ืœื ืžื•ืงืฆื•ืช ืœืฉืžืืœ ืืœ ืจืฉืชื•ืช ืœื•ื’ื™ื•ืช ืžื•ืงืฆื•ืช:

oVirt ืชื•ืš 2 ืฉืขื•ืช. ื—ืœืง 3. ื”ื’ื“ืจื•ืช ื ื•ืกืคื•ืช
ืื•ืจื–. 4 - ืœืคื ื™ ื”ื•ืกืคืช ื”ืจืฉืช.

oVirt ืชื•ืš 2 ืฉืขื•ืช. ื—ืœืง 3. ื”ื’ื“ืจื•ืช ื ื•ืกืคื•ืช
ืื•ืจื–. 5 - ืœืื—ืจ ื”ื•ืกืคืช ื”ืจืฉืช.

ืœื—ื™ื‘ื•ืจ ื”ืžื•ื ื™ ืฉืœ ืžืกืคืจ ืจืฉืชื•ืช ืœืžืืจื—, ื ื•ื— ืœื”ืงืฆื•ืช ืœื”ื ืชื•ื•ื™ืช/ื•ืช ื‘ืขืช ื™ืฆื™ืจืช ืจืฉืชื•ืช, ื•ืœื”ื•ืกื™ืฃ ืจืฉืชื•ืช ืœืคื™ ืชื•ื•ื™ื•ืช.

ืœืื—ืจ ื™ืฆื™ืจืช ื”ืจืฉืช, ื”ืžืืจื—ื™ื ื™ืขื‘ืจื• ืœืžืฆื‘ Non Operational ืขื“ ืฉื”ืจืฉืช ืชืชื•ื•ืกืฃ ืœื›ืœ ืฆืžืชื™ ื”ืืฉื›ื•ืœ. ื”ืชื ื”ื’ื•ืช ื–ื• ืžื•ืคืขืœืช ืขืœ ื™ื“ื™ ื”ื“ื’ืœ Require All ื‘ื›ืจื˜ื™ืกื™ื™ื” Cluster ื‘ืขืช ื™ืฆื™ืจืช ืจืฉืช ื—ื“ืฉื”. ื‘ืžืงืจื” ื‘ื• ืื™ืŸ ืฆื•ืจืš ื‘ืจืฉืช ื‘ื›ืœ ื”ืฆืžืชื™ื ืฉืœ ื”ืืฉื›ื•ืœ, ื ื™ืชืŸ ืœื”ืฉื‘ื™ืช ืชื›ื•ื ื” ื–ื•, ื•ืื– ื”ืจืฉืช, ื‘ืขืช ื”ื•ืกืคืช ืžืืจื—, ืชื”ื™ื” ื‘ืฆื“ ื™ืžื™ืŸ ื‘ืกืขื™ืฃ Non Required ื•ืชื•ื›ืœ ืœื‘ื—ื•ืจ ืื ืœื—ื‘ืจ ืื•ืชื” ืืœ ืžืืจื— ืกืคืฆื™ืคื™.

oVirt ืชื•ืš 2 ืฉืขื•ืช. ื—ืœืง 3. ื”ื’ื“ืจื•ืช ื ื•ืกืคื•ืช
ืื•ืจื–. 6 - ื‘ื—ื™ืจืช ื”ืกื™ืžืŸ ืฉืœ ื“ืจื™ืฉืช ื”ืจืฉืช.

HPE ืกืคืฆื™ืคื™

ื›ืžืขื˜ ืœื›ืœ ื”ื™ืฆืจื ื™ื ื™ืฉ ื›ืœื™ื ื”ืžืฉืคืจื™ื ืืช ื”ืฉื™ืžื•ืฉื™ื•ืช ืฉืœ ื”ืžื•ืฆืจื™ื ืฉืœื”ื. ืฉื™ืžื•ืฉ ื‘-HPE ื›ื“ื•ื’ืžื”, AMS (ืฉื™ืจื•ืช ื ื™ื”ื•ืœ ืœืœื ืกื•ื›ืŸ, amsd ืขื‘ื•ืจ iLO5, hp-ams ืขื‘ื•ืจ iLO4) ื•-SSA (ืžื ื”ืœ ืื—ืกื•ืŸ ื—ื›ื, ืขื‘ื•ื“ื” ืขื ื‘ืงืจ ื“ื™ืกืง) ื•ื›ื•' ืฉื™ืžื•ืฉื™ื™ื.

ื—ื™ื‘ื•ืจ ืžืื’ืจ HPE
ื™ื™ื‘ื ืืช ื”ืžืคืชื— ื•ื—ื‘ืจ ืืช ืžืื’ืจื™ HPE:

$ sudo rpm --import https://downloads.linux.hpe.com/SDR/hpePublicKey2048_key1.pub
$ sudo vim /etc/yum.repos.d/mcp.repo

ื”ืชื•ื›ืŸ ื”ื‘ื:

[mcp]
name=Management Component Pack
baseurl=http://downloads.linux.hpe.com/repo/mcp/centos/$releasever/$basearch/current/
enabled=1
gpgkey=file:///etc/pki/rpm-gpg/GPG-KEY-mcp

[spp]
name=Service Pack for ProLiant
baseurl=http://downloads.linux.hpe.com/SDR/repo/spp/RHEL/$releasever/$basearch/current/
enabled=1
gpgkey=file:///etc/pki/rpm-gpg/GPG-KEY-mcp

ืฆืคื” ื‘ืชื•ื›ืŸ ื”ืžืื’ืจ ื•ื‘ืžื™ื“ืข ืขืœ ื”ื—ื‘ื™ืœื” (ืœืขื™ื•ืŸ):

$ sudo yum --disablerepo="*" --enablerepo="mcp" list available
$ yum info amsd

ื”ืชืงื ื” ื•ื”ืฉืงื”:

$ sudo yum install amsd ssacli
$ sudo systemctl start amsd

ื“ื•ื’ืžื” ืœื›ืœื™ ื”ืฉื™ืจื•ืช ืœืขื‘ื•ื“ื” ืขื ื‘ืงืจ ื“ื™ืกืง
oVirt ืชื•ืš 2 ืฉืขื•ืช. ื—ืœืง 3. ื”ื’ื“ืจื•ืช ื ื•ืกืคื•ืช

ื–ื” ื”ื›ืœ ืœืขืช ืขืชื”. ื‘ืžืืžืจื™ื ื”ื‘ืื™ื ืื ื™ ืžืชื›ื ืŸ ืœื›ืกื•ืช ื›ืžื” ืคืขื•ืœื•ืช ื•ื™ื™ืฉื•ืžื™ื ื‘ืกื™ืกื™ื™ื. ืœื“ื•ื’ืžื”, ืื™ืš ืœื™ืฆื•ืจ VDI ื‘-oVirt.

ืžืงื•ืจ: www.habr.com