ืืืืืจ ืื, ื ืืื ืืกืคืจ ืืืืจืืช ืืืคืฆืืื ืืืืช ืื ืฉืืืืฉืืืช:
ืืืืฆืขืืช ืฉืืืช ืืืืคืืื ืขืืืจ ืืื ืื ;ืืืืืจ ืืืืืช ืืืืฆืขืืช Active Directory ;Mutlipathing ;ื ืืืื ืฆืจืืืช ืืฉืื ;ืืืืคืช ืชืขืืืช SSL ;ืืืกืื ืืืจืืืื ;ืืืฉืง ื ืืืื ืืืจื (ืงืืงืคืื) ;ืจืฉืชืืช VLAN ;HPE ืกืคืฆืืคื .
ืืืืจ ืื ืืื ืืืฉื, ืืชืื ืืจืืืช oVirt ืืขืื ืฉืขืชืืื
ืืืืจืื
ืืืื ืืชืงื ืช ืืื ืื (ืื ืืข ืืืืืืจื) ืืืืคืจืืืืืืจืื (ืืืจืืื) - ืืืืจืืช ื ืืกืคืืช - ืื ืื ื ืืื
ืืืืจืืช ืื ืื ื ืืกืคืืช
ืืืขืื ื ืืืืช, ื ืชืงืื ืืืืืืช ื ืืกืคืืช:
$ sudo yum install bash-completion vim
ืืื ืืืคืฉืจ ืืฉืืื ืืืืืืืืช ืฉื ืคืงืืืืช ืืฉืืืช bash, ืขืืืจ ื-bash.
ืืืกืคืช ืฉืืืช DNS ื ืืกืคืื
ืื ืืืืจืฉ ืืืฉืจ ืืชื ืฆืจืื ืืืชืืืจ ืืื ืื ืืืืฆืขืืช ืฉื ืืืืคื (CNAME, ืืื ืื, ืื ืจืง ืฉื ืงืฆืจ ืืื ืกืืืืช ืืืืืื). ืืืขืื ืืืืื, ืืื ืื ืืืคืฉืจ ืจืง ืืืืืจืื ืืจืฉืืืช ืืฉืืืช ืืืืชืจืื.
ืฆืืจ ืงืืืฅ ืชืฆืืจื:
$ sudo vim /etc/ovirt-engine/engine.conf.d/99-custom-sso-setup.conf
ืืชืืื ืืื:
SSO_ALTERNATE_ENGINE_FQDNS="ovirt.example.com some.alias.example.com ovirt"
ืืืคืขื ืืืืฉ ืืช ืืื ืื:
$ sudo systemctl restart ovirt-engine
ืืืืจืช ืืืืืช ืืืืฆืขืืช AD
ื-oVirt ืืกืืก ืืฉืชืืฉืื ืืืื ื, ืื ื ืชืืืื ืื ืกืคืงื LDAP ืืืฆืื ืืื, ืืืื. ืืึนืึธืขึธื.
ืืืจื ืืคืฉืืื ืืืืชืจ ืืชืฆืืจื ืืืคืืกืืช ืืื ืืืคืขืื ืืช ืืืฉืฃ ืืืืคืขืื ืืืืฉ ืืช ืืื ืื:
$ sudo yum install ovirt-engine-extension-aaa-ldap-setup
$ sudo ovirt-engine-extension-aaa-ldap-setup
$ sudo systemctl restart ovirt-engine
ืืืืื ืืืฉืฃ
$ sudo ovirt-engine-extension-aaa-ldap-setup
ืืืฉืืื LDAP ืืืื ืื:
...
3 - Active Directory
...
ืืืงืฉื ืชืืืจ: 3
ืื ื ืืื ืืช ืฉื ืืขืจ Active Directory: example.com
ืื ื ืืืจ ืคืจืืืืงืื ืืฉืืืืฉ (startTLS, ldaps, plain) [startTLS]:
ืื ื ืืืจ ืฉืืื ืืงืืืช ืืืฉืืจ CA ืืงืืื PEM (ืงืืืฅ, ืืชืืืช ืืชืจ, ืืืืืข, ืืขืจืืช, ืื ืืืืืื): ืืชืืืช ืืืชืจ
ืืชืืืช ืืืชืจ:
ืืื ืืช DN ืืืฉืชืืฉ ืืืืคืืฉ (ืืืืืื uid=username,dc=example,dc=com ืื ืืฉืืจ ืจืืง ืขืืืจ ืื ืื ืืื): CN=oVirt-Engine,CN=Users,DC=example,DC=com
ืืื ืกืืกืืช ืืฉืชืืฉ ืืืืคืืฉ: *ืกืืกืื*
[ ืืืืข ] ื ืืกืืื ืืืื ืืืืฆืขืืช 'CN=oVirt-Engine,CN=Users,DC=example,DC=com'
ืืื ืืชื ืืชืืืื ืืืฉืชืืฉ ืืื ืืกื ืืืืื ืืืืื ืืช ืืืจืืืืืืืช (ืื, ืื) [ืื]:
ืื ื ืฆืืื ืืช ืฉื ืืคืจืืคืื ืฉืืืื ืืืื ืืืฉืชืืฉืื [example.com]:
ืื ื ืกืคืง ืืืฉืืจืื ืืืืืงืช ืืจืืืช ืืื ืืกื:
ืืื ืก ืฉื ืืฉืชืืฉ: someAnyUser
ืืื ืกืืกืืช ืืฉืชืืฉ:
...
[ ืืืืข ] ืจืฆืฃ ืืื ืืกื ืืืฆืข ืืืฆืืื
...
ืืืจ ืจืฆืฃ ืืืืงื ืืืืฆืืข (ืกืืื, ืืืืื, ืืชืืืจืืช, ืืืคืืฉ) [ืืืฆืข]:
[ ืืืืข ] ืฉืื: ืืืืจืช ืืขืกืงื
...
ืชืงืฆืืจ ืชืฆืืจื
...
ืืฉืืืืฉ ืืืฉืฃ ืืชืืื ืืจืื ืืืงืจืื. ืขืืืจ ืชืฆืืจืืช ืืืจืืืืช, ืืืืืจืืช ืืชืืฆืขืืช ืืืืคื ืืื ื. ืคืจืืื ื ืืกืคืื ืืชืืขืื oVirt,
ืจืืืื ืืจืืื
ืืกืืืืช ืืืฆืืจ, ืืขืจืืช ืืืืกืื ืืืืืช ืืืืืช ืืืืืจืช ืืืืจื ืืืืฆืขืืช ื ืชืืื ืงืื/ืคืื ืืจืืืื, ืขืฆืืืืื, ืืจืืืื. ืืืื, ื-CentOS (ืืืื oVirt'e) ืืื ืืขืืืช ืืื ืืืช ืืกืคืจ ื ืชืืืื ืืืืฉืืจ (find_multipaths ืื). ืืืืจืืช ื ืืกืคืืช ืขืืืจ FCoE ืืชืืืจืืช ื
ืขื ืืืืืื ืฉื 3PAR
ืืืชืขื
defaults {
polling_interval 10
user_friendly_names no
find_multipaths yes
}
devices {
device {
vendor "3PARdata"
product "VV"
path_grouping_policy group_by_prio
path_selector "round-robin 0"
path_checker tur
features "0"
hardware_handler "1 alua"
prio alua
failback immediate
rr_weight uniform
no_path_retry 18
rr_min_io_rq 1
detect_prio yes
fast_io_fail_tmo 10
dev_loss_tmo "infinity"
}
}
ืืืืจ ืืื ื ืืชื ืช ืืคืงืืื ืืืคืขืื ืืืืฉ:
systemctl restart multipathd
ืืืจื. 1 ืืื ืืจืืจืช ืืืืื ืฉื ืืืื ืืืช ืืงืื/ืคืื ืืจืืื.
ืืืจื. 2 - ืืืื ืืืช I/O ืืจืืื ืืืืจ ืืืืช ืืืืืจืืช.
ืืืืจืช ื ืืืื ืฆืจืืืช ืืฉืื
ืืืคืฉืจ ืื ืืืฆืข, ืืืฉื, ืืืคืืก ืงืฉืื ืฉื ืืืืื ื ืื ืืื ืืข ืื ืืืื ืืงืื ืชืืืื ืืืืืจื ืืืฉื ืืื ืจื. ืืืืฉื ืืืืฆืขืืช ืกืืื ืืืืจ.
ืืืฉื -> ืืืจืืื -> HOST - ืขืจืื -> ื ืืืื ืฆืจืืืช ืืฉืื, ืืืืืจ ืืื ืืคืขื ืืช "ืืคืขื ื ืืืื ืฆืจืืืช ืืฉืื" ืืืืกืฃ ืกืืื - "ืืืกืฃ ืกืืื ืืืจ" -> +.
ืฆืืื ืืช ืืกืื (ืืืืืื, ืขืืืจ iLO5, ืขืืื ืืฆืืื ilo4), ืืช ืืฉื/ืืืชืืืช ืฉื ืืืฉืง ื-ipmi ืืืช ืฉื ืืืฉืชืืฉ/ืืกืืกืื. ืืืืืฅ ืืืฆืืจ ืืฉืชืืฉ ื ืคืจื (ืืืืืื, oVirt-PM) ืืืืงืจื ืฉื iLO ืืชืช ืื ืืจืฉืืืช:
- ืืชืืืจืืช
- ืงืื ืกืืื ืืจืืืง
- ืืื ืืืืคืืก ืืืจืืืืื
- ืืืื ืืืจืืืืืืช
- ืืืืจ ืืช ืืืืจืืช iLO
- ื ืืืื ืืฉืืื ืืช ืืฉืชืืฉ
ืื ืชืฉืืื ืืื ืื ืื, ืื ื ืืืจ ืืืืคื ืืืคืืจื. ืกืืื ืืืืืจ ืืงืื ืกืืืืช ืืืจืฉ ืงืืืฆื ืงืื ื ืืืชืจ ืฉื ืืืืืืช.
ืืขืช ืืืืจืช ืจืฉืืืืช ืืงืจืช ืืืฉื, ืืฉ ืืืืืจ ืื ืืกืืื ืืื ื ืคืืขื ืขื ืืื ืืข, ืืื ืขื ืืืืจื "ืืฉืื" (ืื ืฉื ืงืจื Power Management Proxy), ืืืืืจ, ืื ืืฉ ืจืง ืฆืืืช ืืื ื- ืืฉืืื, ื ืืืื ืฆืจืืืช ืืืฉืื ืืขืืื ืื.
ืืืืจืช SSL
ืืืจืืืช ืจืฉืืืืช ืืืืืช - ื
ืืืืฉืืจ ืืืื ืืืืืช ื-CA ืืืจืืื ื ืฉืื ื ืื ื-CA ืืกืืจื ืืืฆืื ื.
ืืขืจื ืืฉืืื: ืืชืขืืื ื ืืขืื ืืืชืืืจ ืืื ืื, ืื ืชืฉืคืืข ืขื ืืืื ืืจืืงืฆืื ืืื ืืื ืืข ืืืฆืืชืื - ืื ืืฉืชืืฉื ืืชืขืืืืช ืืืชืืื ืขืฆืืืช ืฉืืื ืคืงื ืขื ืืื ืืื ืืข.
ืืจืืฉืืช:
- ืืืฉืืจ ื-CA ืืื ืคืืง ืืคืืจืื PEM, ืขื ืื ืืฉืจืฉืจืช ื-CA ืืฉืืจืฉ (ืืืื ืคืงื ืืืคืืคื ืืืชืืื ืืขื ืืฉืืจืฉ ืืกืืฃ);
- ืืืฉืืจ ืืืคืฆ'ื ืฉืืื ืคืง ืขื ืืื ื-CA ืืื ืคืืง (ืื ืืื ืขื ืื ืฉืจืฉืจืช ืชืขืืืืช ื-CA);
- ืืคืชื ืคืจืื ืขืืืจ Apache, ืืื ืกืืกืื.
ื ื ืื ืฉื-CA ืืื ืคืืง ืฉืื ื ืืจืืฅ CentOS, ืื ืงืจื subca.example.com, ืืืืงืฉืืช, ืืืคืชืืืช ืืืืืฉืืจืื ื ืืฆืืื ืืกืคืจืืื /etc/pki/tls/.
ืืฆืข ืืืืืืื ืืฆืืจ ืกืคืจืืื ืืื ืืช:
$ sudo cp /etc/pki/ovirt-engine/keys/apache.key.nopass /etc/pki/ovirt-engine/keys/apache.key.nopass.`date +%F`
$ sudo cp /etc/pki/ovirt-engine/certs/apache.cer /etc/pki/ovirt-engine/certs/apache.cer.`date +%F`
$ sudo mkdir /opt/certs
$ sudo chown mgmt.mgmt /opt/certs
ืืืจื ืืืฉืืจืื, ืืคืขื ืืืชื ืืชืื ืช ืืขืืืื ืฉืื ืื ืืขืืจ ืืืชื ืืืจื ื ืืื ืืืจืช:
[myuser@mydesktop] $ scp -3 [email protected]:/etc/pki/tls/cachain.pem [email protected]:/opt/certs
[myuser@mydesktop] $ scp -3 [email protected]:/etc/pki/tls/private/ovirt.key [email protected]:/opt/certs
[myuser@mydesktop] $ scp -3 [email protected]/etc/pki/tls/certs/ovirt.crt [email protected]:/opt/certs
ืืชืืฆืื ืืื, ืืชื ืืืืจ ืืจืืืช ืืช ืื 3 ืืงืืฆืื:
$ ls /opt/certs
cachain.pem ovirt.crt ovirt.key
ืืชืงื ืช ืชืขืืืืช
ืืขืชืง ืงืืฆืื ืืขืืื ืจืฉืืืืช ืืืื:
$ sudo cp /opt/certs/cachain.pem /etc/pki/ca-trust/source/anchors
$ sudo update-ca-trust
$ sudo rm /etc/pki/ovirt-engine/apache-ca.pem
$ sudo cp /opt/certs/cachain.pem /etc/pki/ovirt-engine/apache-ca.pem
$ sudo cp /opt/certs/ovirt03.key /etc/pki/ovirt-engine/keys/apache.key.nopass
$ sudo cp /opt/certs/ovirt03.crt /etc/pki/ovirt-engine/certs/apache.cer
$ sudo systemctl restart httpd.service
ืืืกืฃ/ืขืืื ืงืืืฆื ืชืฆืืจื:
$ sudo vim /etc/ovirt-engine/engine.conf.d/99-custom-truststore.conf
ENGINE_HTTPS_PKI_TRUST_STORE="/etc/pki/java/cacerts"
ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD=""
$ sudo vim /etc/ovirt-engine/ovirt-websocket-proxy.conf.d/10-setup.conf
SSL_CERTIFICATE=/etc/pki/ovirt-engine/certs/apache.cer
SSL_KEY=/etc/pki/ovirt-engine/keys/apache.key.nopass
$ sudo vim /etc/ovirt-imageio-proxy/ovirt-imageio-proxy.conf
# Key file for SSL connections
ssl_key_file = /etc/pki/ovirt-engine/keys/apache.key.nopass
# Certificate file for SSL connections
ssl_cert_file = /etc/pki/ovirt-engine/certs/apache.cer
ืืืืจ ืืื, ืืคืขื ืืืืฉ ืืช ืื ืืฉืืจืืชืื ืืืืฉืคืขืื:
$ sudo systemctl restart ovirt-provider-ovn.service
$ sudo systemctl restart ovirt-imageio-proxy
$ sudo systemctl restart ovirt-websocket-proxy
$ sudo systemctl restart ovirt-engine.service
ืืึผืึธื! ืื ืืืื ืืืชืืืจ ืืื ืื ืืืืืืง ืฉืืืืืืจ ืืืืืื ืขื ืชืขืืืช SSL ืืชืืื.
ืืืจืืืื
ืืืคื ืืืขืืื! ืืืืง ืื, ื ืืืจ ืขื ืืจืืืื ืืื ืื, ืืจืืืื ื-VM ืืื ื ืืฉื ื ืคืจื. ื ืืฆืืจ ืขืืชืงื ืืจืืืื ืคืขื ืืืื ืื ืฉืืืจ ืืืชื ืขื NFS, ืืืฉื, ืืืืชื ืืขืจืืช ืฉืื ืืืงืื ื ืืช ืชืืื ืืช ื-ISO - mynfs1.example.com:/exports/ovirt-backup. ืื ืืืืืฅ ืืืืกื ืืจืืืื ืื ืขื ืืืชื ืืืื ื ืฉืื ืคืืขื ืืื ืืข.
ืืชืงื ืืืคืขื ืืืืืืืืื:
$ sudo yum install autofs
$ sudo systemctl enable autofs
$ sudo systemctl start autofs
ืฆืืจ ืกืงืจืืคื:
$ sudo vim /etc/cron.daily/make.oVirt.backup.sh
ืืชืืื ืืื:
#!/bin/bash
datetime=`date +"%F.%R"`
backupdir="/net/mynfs01.example.com/exports/ovirt-backup"
filename="$backupdir/`hostname --short`.`date +"%F.%R"`"
engine-backup --mode=backup --scope=all --file=$filename.data --log=$filename.log
#uncomment next line for autodelete files older 30 days
#find $backupdir -type f -mtime +30 -exec rm -f {} ;
ืืคืืืช ืืงืืืฅ ืืืคืฉืจื ืืคืขืื:
$ sudo chmod a+x /etc/cron.daily/make.oVirt.backup.sh
ืืขืช ืืื ืขืจื ื ืงืื ืืจืืืื ืฉื ืืืืจืืช ืื ืื.
ืืืฉืง ื ืืืื ืืืจื
ืืืจื. 3 - ืืจืื ืืคืื ื.
ืืืชืงื ื ืคืฉืืื ืืืื, ืืชื ืฆืจืื ืืืืืืช ืฉื ืชื ืืืืืก ืืืช ืืคืืืืื ืฉื ืืื ืืืืืื ืื ืฉื ืชื ืืืืืก:
$ sudo yum install cockpit cockpit-ovirt-dashboard -y
ืืืืคืช ืชื ืืืืืก:
$ sudo systemctl enable --now cockpit.socket
ืืืืจืช ืืืืช ืืฉ:
sudo firewall-cmd --add-service=cockpit
sudo firewall-cmd --add-service=cockpit --permanent
ืืขืช ืืชื ืืืื ืืืชืืืจ ืืืืจื: https://[Host IP or FQDN]:9090
ืจืฉืชืืช VLAN
ืงืจื ืขืื ืขื ืจืฉืชืืช ื
ืืื ืืืืจ ืจืฉืชืืช ืืฉื ื ืืืจืืช, ืชืืืื ืืฉ ืืชืืจ ืืืชื ืืชืฆืืจื: ืจืฉืช -> ืจืฉืชืืช -> ืืืฉ, ืืื ืจืง ืืฉื ืืื ืฉืื ืืืื; ืชืืืช ืืกืืืื ืจืฉืช VM, ืืืืคืฉืจืช ืืืืื ืืช ืืืฉืชืืฉ ืืจืฉืช ืื, ืืืคืขืืช, ืืืื ืืืืจ ืืช ืืชื, ืขืืื ืืืคืขืื ืืคืฉืจ ืชืืื VLAN, ืืื ืืช ืืกืคืจ ื-VLAN ืืืืฅ ืขื ืืืฉืืจ.
ืืขืช ืขืืื ืืขืืืจ ื-Compute -> Hosts -> kvmNN -> Network Interfaces -> Setup Host Networks hosts. ืืจืืจ ืืช ืืจืฉืช ืฉื ืืกืคื ืืืฆื ืืืื ื ืฉื ืจืฉืชืืช ืืืืืืช ืื ืืืงืฆืืช ืืฉืืื ืื ืจืฉืชืืช ืืืืืืช ืืืงืฆืืช:
ืืืจื. 4 - ืืคื ื ืืืกืคืช ืืจืฉืช.
ืืืจื. 5 - ืืืืจ ืืืกืคืช ืืจืฉืช.
ืืืืืืจ ืืืื ื ืฉื ืืกืคืจ ืจืฉืชืืช ืืืืจื, ื ืื ืืืงืฆืืช ืืื ืชืืืืช/ืืช ืืขืช ืืฆืืจืช ืจืฉืชืืช, ืืืืืกืืฃ ืจืฉืชืืช ืืคื ืชืืืืืช.
ืืืืจ ืืฆืืจืช ืืจืฉืช, ืืืืจืืื ืืขืืจื ืืืฆื Non Operational ืขื ืฉืืจืฉืช ืชืชืืืกืฃ ืืื ืฆืืชื ืืืฉืืื. ืืชื ืืืืช ืื ืืืคืขืืช ืขื ืืื ืืืื Require All ืืืจืืืกืืื Cluster ืืขืช ืืฆืืจืช ืจืฉืช ืืืฉื. ืืืงืจื ืื ืืื ืฆืืจื ืืจืฉืช ืืื ืืฆืืชืื ืฉื ืืืฉืืื, ื ืืชื ืืืฉืืืช ืชืืื ื ืื, ืืื ืืจืฉืช, ืืขืช ืืืกืคืช ืืืจื, ืชืืื ืืฆื ืืืื ืืกืขืืฃ Non Required ืืชืืื ืืืืืจ ืื ืืืืจ ืืืชื ืื ืืืจื ืกืคืฆืืคื.
ืืืจื. 6 - ืืืืจืช ืืกืืื ืฉื ืืจืืฉืช ืืจืฉืช.
HPE ืกืคืฆืืคื
ืืืขื ืืื ืืืฆืจื ืื ืืฉ ืืืื ืืืฉืคืจืื ืืช ืืฉืืืืฉืืืช ืฉื ืืืืฆืจืื ืฉืืื. ืฉืืืืฉ ื-HPE ืืืืืื, AMS (ืฉืืจืืช ื ืืืื ืืื ืกืืื, amsd ืขืืืจ iLO5, hp-ams ืขืืืจ iLO4) ื-SSA (ืื ืื ืืืกืื ืืื, ืขืืืื ืขื ืืงืจ ืืืกืง) ืืื' ืฉืืืืฉืืื.
ืืืืืจ ืืืืจ HPE
ืืืื ืืช ืืืคืชื ืืืืจ ืืช ืืืืจื HPE:
$ sudo rpm --import https://downloads.linux.hpe.com/SDR/hpePublicKey2048_key1.pub
$ sudo vim /etc/yum.repos.d/mcp.repo
ืืชืืื ืืื:
[mcp]
name=Management Component Pack
baseurl=http://downloads.linux.hpe.com/repo/mcp/centos/$releasever/$basearch/current/
enabled=1
gpgkey=file:///etc/pki/rpm-gpg/GPG-KEY-mcp
[spp]
name=Service Pack for ProLiant
baseurl=http://downloads.linux.hpe.com/SDR/repo/spp/RHEL/$releasever/$basearch/current/
enabled=1
gpgkey=file:///etc/pki/rpm-gpg/GPG-KEY-mcp
ืฆืคื ืืชืืื ืืืืืจ ืืืืืืข ืขื ืืืืืื (ืืขืืื):
$ sudo yum --disablerepo="*" --enablerepo="mcp" list available
$ yum info amsd
ืืชืงื ื ืืืฉืงื:
$ sudo yum install amsd ssacli
$ sudo systemctl start amsd
ืืืืื ืืืื ืืฉืืจืืช ืืขืืืื ืขื ืืงืจ ืืืกืง
ืื ืืื ืืขืช ืขืชื. ืืืืืจืื ืืืืื ืื ื ืืชืื ื ืืืกืืช ืืื ืคืขืืืืช ืืืืฉืืืื ืืกืืกืืื. ืืืืืื, ืืื ืืืฆืืจ VDI ื-oVirt.
ืืงืืจ: www.habr.com