2์‹œ๊ฐ„ ์•ˆ์— ๋ฒ„ํ‹ฐ์„ธ์š”. 3๋ถ€. ์ถ”๊ฐ€ ์„ค์ •

์ด ๋ฌธ์„œ์—์„œ๋Š” ์„ ํƒ ์‚ฌํ•ญ์ด์ง€๋งŒ ์œ ์šฉํ•œ ์—ฌ๋Ÿฌ ์„ค์ •์„ ์‚ดํŽด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.

์ด ๊ธฐ์‚ฌ๋Š” ๊ณ„์†๋ฉ๋‹ˆ๋‹ค. ์‹œ์ž‘ ๋ถ€๋ถ„์€ 2์‹œ๊ฐ„ ํ›„ oVirt๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”. ะงะฐัั‚ัŒ 1 ะธ ์ผ๋ถ€ 2.

์กฐํ•ญ

  1. ์†Œ๊ฐœ
  2. ๊ด€๋ฆฌ์ž(ovirt-engine) ๋ฐ ํ•˜์ดํผ๋ฐ”์ด์ €(ํ˜ธ์ŠคํŠธ) ์„ค์น˜
  3. ์ถ”๊ฐ€ ์„ค์ • - ํ˜„์žฌ ์œ„์น˜

์ถ”๊ฐ€ ๊ด€๋ฆฌ์ž ์„ค์ •

ํŽธ์˜๋ฅผ ์œ„ํ•ด ์ถ”๊ฐ€ ํŒจํ‚ค์ง€๋ฅผ ์„ค์น˜ํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค.

$ sudo yum install bash-completion vim

๋ช…๋ น ์™„์„ฑ์„ ํ™œ์„ฑํ™”ํ•˜๋ ค๋ฉด bash-completion์„ bash๋กœ ์ „ํ™˜ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

์ถ”๊ฐ€ DNS ์ด๋ฆ„ ์ถ”๊ฐ€

์ด๋Š” ๋Œ€์ฒด ์ด๋ฆ„(CNAME, ๋ณ„์นญ ๋˜๋Š” ๋„๋ฉ”์ธ ์ ‘๋ฏธ์‚ฌ๊ฐ€ ์—†๋Š” ์งง์€ ์ด๋ฆ„)์„ ์‚ฌ์šฉํ•˜์—ฌ ๊ด€๋ฆฌ์ž์— ์—ฐ๊ฒฐํ•ด์•ผ ํ•  ๋•Œ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. ๋ณด์•ˆ์ƒ์˜ ์ด์œ ๋กœ ๊ด€๋ฆฌ์ž๋Š” ํ—ˆ์šฉ๋œ ์ด๋ฆ„ ๋ชฉ๋ก์„ ์‚ฌ์šฉํ•œ ์—ฐ๊ฒฐ๋งŒ ํ—ˆ์šฉํ•ฉ๋‹ˆ๋‹ค.

๊ตฌ์„ฑ ํŒŒ์ผ์„ ๋งŒ๋“ญ๋‹ˆ๋‹ค.

$ sudo vim /etc/ovirt-engine/engine.conf.d/99-custom-sso-setup.conf

๋‹ค์Œ ๋‚ด์šฉ :

SSO_ALTERNATE_ENGINE_FQDNS="ovirt.example.com some.alias.example.com ovirt"

๊ด€๋ฆฌ์ž๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•ฉ๋‹ˆ๋‹ค.

$ sudo systemctl restart ovirt-engine

AD๋ฅผ ํ†ตํ•œ ์ธ์ฆ ์„ค์ •

oVirt์—๋Š” ์‚ฌ์šฉ์ž ๊ธฐ๋ฐ˜์ด ๋‚ด์žฅ๋˜์–ด ์žˆ์ง€๋งŒ ์™ธ๋ถ€ LDAP ๊ณต๊ธ‰์ž๋„ ์ง€์›๋ฉ๋‹ˆ๋‹ค. ๊ธฐ์› ํ›„.

์ผ๋ฐ˜์ ์ธ ๊ตฌ์„ฑ์„ ์œ„ํ•œ ๊ฐ€์žฅ ๊ฐ„๋‹จํ•œ ๋ฐฉ๋ฒ•์€ ๋งˆ๋ฒ•์‚ฌ๋ฅผ ์‹œ์ž‘ํ•˜๊ณ  ๊ด€๋ฆฌ์ž๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค.

$ sudo yum install ovirt-engine-extension-aaa-ldap-setup
$ sudo ovirt-engine-extension-aaa-ldap-setup
$ sudo systemctl restart ovirt-engine

์ฃผ์ธ์˜ ์ž‘ํ’ˆ์˜ ์˜ˆ
$ sudo ovirt-์—”์ง„-ํ™•์žฅ-aaa-ldap-์„ค์ •
์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ LDAP ๊ตฌํ˜„:
...
3 - ์•กํ‹ฐ๋ธŒ ๋””๋ ‰ํ† ๋ฆฌ
...
์„ ํƒ ํ•ด์ฃผ์„ธ์š”: 3
Active Directory ํฌ๋ฆฌ์ŠคํŠธ ์ด๋ฆ„์„ ์ž…๋ ฅํ•˜์„ธ์š”. example.com

์‚ฌ์šฉํ•  ํ”„๋กœํ† ์ฝœ์„ ์„ ํƒํ•˜์„ธ์š”(startTLS, ldaps, plain). [์‹œ์ž‘TLS]:
PEM์œผ๋กœ ์ธ์ฝ”๋”ฉ๋œ CA ์ธ์ฆ์„œ๋ฅผ ์–ป๊ธฐ ์œ„ํ•œ ๋ฐฉ๋ฒ•์„ ์„ ํƒํ•˜์‹ญ์‹œ์˜ค(ํŒŒ์ผ, URL, ์ธ๋ผ์ธ, ์‹œ์Šคํ…œ, ์•ˆ์ „ํ•˜์ง€ ์•Š์Œ): URL
URL : wwwca.example.com/myRootCA.pem
๊ฒ€์ƒ‰ ์‚ฌ์šฉ์ž DN์„ ์ž…๋ ฅํ•˜์„ธ์š”(์˜ˆ: uid=username,dc=example,dc=com ๋˜๋Š” ์ต๋ช…์˜ ๊ฒฝ์šฐ ๋น„์›Œ ๋‘์„ธ์š”). CN=oVirt-Engine,CN=์‚ฌ์šฉ์ž,DC=์˜ˆ,DC=com
๊ฒ€์ƒ‰ ์‚ฌ์šฉ์ž ๋น„๋ฐ€๋ฒˆํ˜ธ ์ž…๋ ฅ: *๋น„๋ฐ€๋ฒˆํ˜ธ*
[ ์ •๋ณด ] 'CN=oVirt-Engine,CN=Users,DC=example,DC=com'์„ ์‚ฌ์šฉํ•˜์—ฌ ๋ฐ”์ธ๋”ฉ์„ ์‹œ๋„ํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.
๊ฐ€์ƒ ๋จธ์‹ ์— Single Sign-On์„ ์‚ฌ์šฉํ•˜์‹œ๊ฒ ์Šต๋‹ˆ๊นŒ?(์˜ˆ, ์•„๋‹ˆ์š”) [์˜ˆ]:
์‚ฌ์šฉ์ž์—๊ฒŒ ํ‘œ์‹œ๋  ํ”„๋กœํ•„ ์ด๋ฆ„์„ ์ง€์ •ํ•˜์„ธ์š”. [example.com]:
๋กœ๊ทธ์ธ ํ๋ฆ„์„ ํ…Œ์ŠคํŠธํ•˜๋ ค๋ฉด ์ž๊ฒฉ ์ฆ๋ช…์„ ์ž…๋ ฅํ•˜์„ธ์š”.
์‚ฌ์šฉ์ž ์ด๋ฆ„ ์ž…๋ ฅ: someAnyUser
์‚ฌ์šฉ์ž ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์ž…๋ ฅํ•˜์„ธ์š”:
...
[์ •๋ณด] ๋กœ๊ทธ์ธ ์‹œํ€€์Šค๊ฐ€ โ€‹โ€‹์„ฑ๊ณต์ ์œผ๋กœ ์‹คํ–‰๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
...
์‹คํ–‰ํ•  ํ…Œ์ŠคํŠธ ์‹œํ€€์Šค ์„ ํƒ(์™„๋ฃŒ, ์ค‘๋‹จ, ๋กœ๊ทธ์ธ, ๊ฒ€์ƒ‰) [์™„๋ฃŒ]:
[์ •๋ณด] ๋‹จ๊ณ„: ๊ฑฐ๋ž˜ ์„ค์ •
...
๊ตฌ์„ฑ ์š”์•ฝ
...

๋งˆ๋ฒ•์‚ฌ๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์€ ๋Œ€๋ถ€๋ถ„์˜ ๊ฒฝ์šฐ์— ์ ํ•ฉํ•ฉ๋‹ˆ๋‹ค. ๋ณต์žกํ•œ ๊ตฌ์„ฑ์˜ ๊ฒฝ์šฐ ์„ค์ •์ด ์ˆ˜๋™์œผ๋กœ ์ˆ˜ํ–‰๋ฉ๋‹ˆ๋‹ค. oVirt ๋ฌธ์„œ์— ๋Œ€ํ•œ ์ž์„ธํ•œ ๋‚ด์šฉ์€ ์‚ฌ์šฉ์ž ๋ฐ ์—ญํ• . ์—”์ง„์„ AD์— ์„ฑ๊ณต์ ์œผ๋กœ ์—ฐ๊ฒฐํ•˜๋ฉด ์—ฐ๊ฒฐ ์ฐฝ๊ณผ ํƒญ์— ์ถ”๊ฐ€ ํ”„๋กœํ•„์ด ๋‚˜ํƒ€๋‚ฉ๋‹ˆ๋‹ค. ๊ถŒํ•œ ์‹œ์Šคํ…œ ๊ฐœ์ฒด์—๋Š” AD ์‚ฌ์šฉ์ž ๋ฐ ๊ทธ๋ฃน์— ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•˜๋Š” ๊ธฐ๋Šฅ์ด ์žˆ์Šต๋‹ˆ๋‹ค. ์‚ฌ์šฉ์ž ๋ฐ ๊ทธ๋ฃน์˜ ์™ธ๋ถ€ ๋””๋ ‰ํ„ฐ๋ฆฌ๋Š” AD๋ฟ๋งŒ ์•„๋‹ˆ๋ผ IPA, eDirectory ๋“ฑ์ผ ์ˆ˜๋„ ์žˆ์Šต๋‹ˆ๋‹ค.

๋‹ค์ค‘ ๊ฒฝ๋กœ

ํ”„๋กœ๋•์…˜ ํ™˜๊ฒฝ์—์„œ๋Š” ์Šคํ† ๋ฆฌ์ง€ ์‹œ์Šคํ…œ์ด ์—ฌ๋Ÿฌ ๊ฐœ์˜ ๋…๋ฆฝ์ ์ธ ์—ฌ๋Ÿฌ I/O ๊ฒฝ๋กœ๋ฅผ ํ†ตํ•ด ํ˜ธ์ŠคํŠธ์— ์—ฐ๊ฒฐ๋˜์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ผ๋ฐ˜์ ์œผ๋กœ CentOS(๋ฐ oVirt)์—์„œ๋Š” ์žฅ์น˜์— ๋Œ€ํ•œ ์—ฌ๋Ÿฌ ๊ฒฝ๋กœ๋ฅผ ์กฐํ•ฉํ•˜๋Š” ๋ฐ ๋ฌธ์ œ๊ฐ€ ์—†์Šต๋‹ˆ๋‹ค(find_multipaths yes). FCoE์— ๋Œ€ํ•œ ์ถ”๊ฐ€ ์„ค์ •์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค. 2 ๋ถ€๋ถ„. ์Šคํ† ๋ฆฌ์ง€ ์‹œ์Šคํ…œ ์ œ์กฐ์—…์ฒด์˜ ๊ถŒ์žฅ ์‚ฌํ•ญ์— ์ฃผ๋ชฉํ•  ํ•„์š”๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค. ๋งŽ์€ ์‚ฌ๋žŒ๋“ค์ด ๋ผ์šด๋“œ ๋กœ๋นˆ ์ •์ฑ… ์‚ฌ์šฉ์„ ๊ถŒ์žฅํ•˜์ง€๋งŒ Enterprise Linux 7์—์„œ๋Š” ๊ธฐ๋ณธ์ ์œผ๋กœ ์„œ๋น„์Šค ์‹œ๊ฐ„์ด ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.

3PAR์„ ์˜ˆ๋กœ ์‚ฌ์šฉ
๊ทธ๋ฆฌ๊ณ  ๋ฌธ์„œ HPE 3PAR Red Hat Enterprise Linux, CentOS Linux, Oracle Linux ๋ฐ OracleVM ์„œ๋ฒ„ ๊ตฌํ˜„ ๊ฐ€์ด๋“œ EL์€ Generic-ALUA Persona 2๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํ˜ธ์ŠคํŠธ๋กœ ์ƒ์„ฑ๋˜๋ฉฐ /etc/multipath.conf ์„ค์ •์— ๋‹ค์Œ ๊ฐ’์ด ์ž…๋ ฅ๋ฉ๋‹ˆ๋‹ค.

defaults {
           polling_interval      10
           user_friendly_names   no
           find_multipaths       yes
          }
devices {
          device {
                   vendor                   "3PARdata"
                   product                  "VV"
                   path_grouping_policy     group_by_prio
                   path_selector            "round-robin 0"
                   path_checker             tur
                   features                 "0"
                   hardware_handler         "1 alua"
                   prio                     alua
                   failback                 immediate
                   rr_weight                uniform
                   no_path_retry            18
                   rr_min_io_rq             1
                   detect_prio              yes
                   fast_io_fail_tmo         10
                   dev_loss_tmo             "infinity"
                 }
}

๊ทธ๋Ÿฐ ๋‹ค์Œ ๋‹ค์‹œ ์‹œ์ž‘ํ•˜๋ผ๋Š” ๋ช…๋ น์ด ์ œ๊ณต๋ฉ๋‹ˆ๋‹ค.

systemctl restart multipathd

2์‹œ๊ฐ„ ์•ˆ์— ๋ฒ„ํ‹ฐ์„ธ์š”. 3๋ถ€. ์ถ”๊ฐ€ ์„ค์ •
์Œ€. 1์€ ๊ธฐ๋ณธ ๋‹ค์ค‘ I/O ์ •์ฑ…์ž…๋‹ˆ๋‹ค.

2์‹œ๊ฐ„ ์•ˆ์— ๋ฒ„ํ‹ฐ์„ธ์š”. 3๋ถ€. ์ถ”๊ฐ€ ์„ค์ •
์Œ€. 2 - ์„ค์ • ์ ์šฉ ํ›„ ๋‹ค์ค‘ I/O ์ •์ฑ….

์ „์› ๊ด€๋ฆฌ ์„ค์ •

์˜ˆ๋ฅผ ๋“ค์–ด, ์—”์ง„์ด ์˜ค๋žซ๋™์•ˆ ํ˜ธ์ŠคํŠธ๋กœ๋ถ€ํ„ฐ ์‘๋‹ต์„ ๋ฐ›์„ ์ˆ˜ ์—†๋Š” ๊ฒฝ์šฐ ๋จธ์‹ ์˜ ํ•˜๋“œ์›จ์–ด ์žฌ์„ค์ •์„ ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. Fence Agent๋ฅผ ํ†ตํ•ด ๊ตฌํ˜„๋ฉ๋‹ˆ๋‹ค.

์ปดํ“จํŒ… -> ํ˜ธ์ŠคํŠธ -> HOST โ€” ํŽธ์ง‘ -> ์ „์› ๊ด€๋ฆฌ๋ฅผ ์„ ํƒํ•œ ๋‹ค์Œ "์ „์› ๊ด€๋ฆฌ ํ™œ์„ฑํ™”"๋ฅผ ํ™œ์„ฑํ™”ํ•˜๊ณ  ์—์ด์ „ํŠธ๋ฅผ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค. โ€” "ํŽœ์Šค ์—์ด์ „ํŠธ ์ถ”๊ฐ€" -> +.

์œ ํ˜•(์˜ˆ: iLO5์˜ ๊ฒฝ์šฐ ilo4๋ฅผ ์ง€์ •ํ•ด์•ผ ํ•จ), ipmi ์ธํ„ฐํŽ˜์ด์Šค์˜ ์ด๋ฆ„/์ฃผ์†Œ ๋ฐ ์‚ฌ์šฉ์ž ์ด๋ฆ„/์•”ํ˜ธ๋ฅผ ๋‚˜ํƒ€๋ƒ…๋‹ˆ๋‹ค. ๋ณ„๋„์˜ ์‚ฌ์šฉ์ž(์˜ˆ: oVirt-PM)๋ฅผ ์ƒ์„ฑํ•˜๊ณ  iLO์˜ ๊ฒฝ์šฐ ํ•ด๋‹น ์‚ฌ์šฉ์ž์—๊ฒŒ ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•˜๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค.

  • ๋กœ๊ทธ์ธ
  • ์›๊ฒฉ ์ฝ˜์†”
  • ๊ฐ€์ƒ ์ „์› ๋ฐ ์žฌ์„ค์ •
  • ๊ฐ€์ƒ ๋ฏธ๋””์–ด
  • iLO ์„ค์ • ๊ตฌ์„ฑ
  • ์‚ฌ์šฉ์ž ๊ณ„์ • ๊ด€๋ฆฌ

์™œ ๊ทธ๋Ÿฐ์ง€ ๋ฌป์ง€ ๋งˆ์‹ญ์‹œ์˜ค. ๊ฒฝํ—˜์ ์œผ๋กœ ์„ ํƒ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์ฝ˜์†” ํŽœ์‹ฑ ์—์ด์ „ํŠธ์—๋Š” ๋” ์ ์€ ๊ถŒํ•œ์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.

์•ก์„ธ์Šค ์ œ์–ด ๋ชฉ๋ก์„ ์„ค์ •ํ•  ๋•Œ ์—์ด์ „ํŠธ๋Š” ์—”์ง„์ด ์•„๋‹ˆ๋ผ "์ด์›ƒ" ํ˜ธ์ŠคํŠธ(์†Œ์œ„ ์ „์› ๊ด€๋ฆฌ ํ”„๋ก์‹œ)์—์„œ ์‹คํ–‰๋œ๋‹ค๋Š” ์ ์„ ๋ช…์‹ฌํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ฆ‰, ํด๋Ÿฌ์Šคํ„ฐ์— ๋…ธ๋“œ๊ฐ€ ํ•˜๋‚˜๋งŒ ์žˆ๋Š” ๊ฒฝ์šฐ ์ „์› ๊ด€๋ฆฌ๊ฐ€ ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค ~ํ•˜์ง€ ์•Š์„ ๊ฒƒ์ด๋‹ค.

SSL ์„ค์ •

์ „์ฒด ๊ณต์‹ ์ง€์นจ - in ์„ ์  ์„œ๋ฅ˜ ๋น„์น˜, ๋ถ€๋ก D: oVirt ๋ฐ SSL - oVirt ์—”์ง„ SSL/TLS ์ธ์ฆ์„œ ๊ต์ฒด.

์ธ์ฆ์„œ๋Š” ํšŒ์‚ฌ CA ๋˜๋Š” ์™ธ๋ถ€ ์ƒ์šฉ ์ธ์ฆ ๊ธฐ๊ด€์—์„œ ์ œ๊ณต๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ค‘์š” ์ฐธ๊ณ  ์‚ฌํ•ญ: ์ธ์ฆ์„œ๋Š” ๊ด€๋ฆฌ์ž์— ์—ฐ๊ฒฐํ•˜๊ธฐ ์œ„ํ•œ ๊ฒƒ์ด๋ฉฐ ์—”์ง„๊ณผ ๋…ธ๋“œ ๊ฐ„์˜ ํ†ต์‹ ์— ์˜ํ–ฅ์„ ์ฃผ์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ์—”์ง„์—์„œ ๋ฐœ๊ธ‰ํ•œ ์ž์ฒด ์„œ๋ช…๋œ ์ธ์ฆ์„œ๋ฅผ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.

์š”๊ตฌ ์‚ฌํ•ญ :

  • PEM ํ˜•์‹์˜ ๋ฐœ๊ธ‰ CA ์ธ์ฆ์„œ(์ „์ฒด ์ฒด์ธ์ด ๋ฃจํŠธ CA๊นŒ์ง€ ํฌํ•จ)(์‹œ์ž‘์˜ ํ•˜์œ„ ๋ฐœ๊ธ‰ CA๋ถ€ํ„ฐ ๋์˜ ๋ฃจํŠธ๊นŒ์ง€)
  • ๋ฐœ๊ธ‰ CA์—์„œ ๋ฐœ๊ธ‰ํ•œ Apache์šฉ ์ธ์ฆ์„œ(๋˜ํ•œ ์ „์ฒด CA ์ธ์ฆ์„œ ์ฒด์ธ์œผ๋กœ ๋ณด์™„๋จ)
  • ๋น„๋ฐ€๋ฒˆํ˜ธ๊ฐ€ ์—†๋Š” Apache์šฉ ๊ฐœ์ธ ํ‚ค์ž…๋‹ˆ๋‹ค.

๋ฐœ๊ธ‰ CA๊ฐ€ subca.example.com์ด๋ผ๋Š” CentOS๋ฅผ ์‹คํ–‰ํ•˜๊ณ  ์žˆ๊ณ  ์š”์ฒญ, ํ‚ค ๋ฐ ์ธ์ฆ์„œ๊ฐ€ /etc/pki/tls/ ๋””๋ ‰ํ„ฐ๋ฆฌ์— ์žˆ๋‹ค๊ณ  ๊ฐ€์ •ํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.

๋ฐฑ์—…์„ ์ˆ˜ํ–‰ํ•˜๊ณ  ์ž„์‹œ ๋””๋ ‰ํ„ฐ๋ฆฌ๋ฅผ ๋งŒ๋“ญ๋‹ˆ๋‹ค.

$ sudo cp /etc/pki/ovirt-engine/keys/apache.key.nopass /etc/pki/ovirt-engine/keys/apache.key.nopass.`date +%F`
$ sudo cp /etc/pki/ovirt-engine/certs/apache.cer /etc/pki/ovirt-engine/certs/apache.cer.`date +%F`
$ sudo mkdir /opt/certs
$ sudo chown mgmt.mgmt /opt/certs

์ธ์ฆ์„œ๋ฅผ ๋‹ค์šด๋กœ๋“œํ•˜๊ณ  ์›Œํฌ์Šคํ…Œ์ด์…˜์—์„œ ์ˆ˜ํ–‰ํ•˜๊ฑฐ๋‚˜ ๋‹ค๋ฅธ ํŽธ๋ฆฌํ•œ ๋ฐฉ๋ฒ•์œผ๋กœ ์ „์†กํ•˜์‹ญ์‹œ์˜ค.

[myuser@mydesktop] $ scp -3 [email protected]:/etc/pki/tls/cachain.pem [email protected]:/opt/certs
[myuser@mydesktop] $ scp -3 [email protected]:/etc/pki/tls/private/ovirt.key [email protected]:/opt/certs
[myuser@mydesktop] $ scp -3 [email protected]/etc/pki/tls/certs/ovirt.crt [email protected]:/opt/certs

๊ฒฐ๊ณผ์ ์œผ๋กœ ๋‹ค์Œ 3๊ฐœ ํŒŒ์ผ์ด ๋ชจ๋‘ ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค.

$ ls /opt/certs
cachain.pem  ovirt.crt  ovirt.key

์ธ์ฆ์„œ ์„ค์น˜

ํŒŒ์ผ์„ ๋ณต์‚ฌํ•˜๊ณ  ์‹ ๋ขฐ ๋ชฉ๋ก์„ ์—…๋ฐ์ดํŠธํ•ฉ๋‹ˆ๋‹ค.

$ sudo cp /opt/certs/cachain.pem /etc/pki/ca-trust/source/anchors
$ sudo update-ca-trust
$ sudo rm /etc/pki/ovirt-engine/apache-ca.pem
$ sudo cp /opt/certs/cachain.pem /etc/pki/ovirt-engine/apache-ca.pem
$ sudo cp /opt/certs/ovirt03.key /etc/pki/ovirt-engine/keys/apache.key.nopass
$ sudo cp /opt/certs/ovirt03.crt /etc/pki/ovirt-engine/certs/apache.cer
$ sudo systemctl restart httpd.service

๊ตฌ์„ฑ ํŒŒ์ผ ์ถ”๊ฐ€/์—…๋ฐ์ดํŠธ:

$ sudo vim /etc/ovirt-engine/engine.conf.d/99-custom-truststore.conf
ENGINE_HTTPS_PKI_TRUST_STORE="/etc/pki/java/cacerts"
ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD=""
$ sudo vim /etc/ovirt-engine/ovirt-websocket-proxy.conf.d/10-setup.conf
SSL_CERTIFICATE=/etc/pki/ovirt-engine/certs/apache.cer
SSL_KEY=/etc/pki/ovirt-engine/keys/apache.key.nopass
$ sudo vim /etc/ovirt-imageio-proxy/ovirt-imageio-proxy.conf
# Key file for SSL connections
ssl_key_file = /etc/pki/ovirt-engine/keys/apache.key.nopass
# Certificate file for SSL connections
ssl_cert_file = /etc/pki/ovirt-engine/certs/apache.cer

๊ทธ๋Ÿฐ ๋‹ค์Œ ์˜ํ–ฅ์„ ๋ฐ›๋Š” ๋ชจ๋“  ์„œ๋น„์Šค๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•ฉ๋‹ˆ๋‹ค.

$ sudo systemctl restart ovirt-provider-ovn.service
$ sudo systemctl restart ovirt-imageio-proxy
$ sudo systemctl restart ovirt-websocket-proxy
$ sudo systemctl restart ovirt-engine.service

์ค€๋น„๊ฐ€ ๋œ! ์ด์ œ ๊ด€๋ฆฌ์ž์— ์—ฐ๊ฒฐํ•˜์—ฌ ์„œ๋ช…๋œ SSL ์ธ์ฆ์„œ๋กœ ์—ฐ๊ฒฐ์ด ๋ณดํ˜ธ๋˜๋Š”์ง€ ํ™•์ธํ•  ์ฐจ๋ก€์ž…๋‹ˆ๋‹ค.

์•„์นด์ด๋น™

๊ทธ๋…€ ์—†์ด ์šฐ๋ฆฌ๋Š” ์–ด๋””์— ์žˆ์„๊นŒ์š”? ์ด ์„น์…˜์—์„œ๋Š” ๊ด€๋ฆฌ์ž ์•„์นด์ด๋น™์— ๋Œ€ํ•ด ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค. VM ์•„์นด์ด๋น™์€ ๋ณ„๋„์˜ ๋ฌธ์ œ์ž…๋‹ˆ๋‹ค. ํ•˜๋ฃจ์— ํ•œ ๋ฒˆ ์•„์นด์ด๋ธŒ ๋ณต์‚ฌ๋ณธ์„ ๋งŒ๋“ค๊ณ  NFS๋ฅผ ํ†ตํ•ด ISO ์ด๋ฏธ์ง€๋ฅผ ๋ฐฐ์น˜ํ•œ ๋™์ผํ•œ ์‹œ์Šคํ…œ(mynfs1.example.com:/exports/ovirt-backup)์— ์ €์žฅํ•ฉ๋‹ˆ๋‹ค. ์—”์ง„์ด ์‹คํ–‰๋˜๋Š” ๋™์ผํ•œ ๋จธ์‹ ์— ์•„์นด์ด๋ธŒ๋ฅผ ์ €์žฅํ•˜๋Š” ๊ฒƒ์€ ๊ถŒ์žฅ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

autofs๋ฅผ ์„ค์น˜ํ•˜๊ณ  ํ™œ์„ฑํ™”ํ•ฉ๋‹ˆ๋‹ค.

$ sudo yum install autofs
$ sudo systemctl enable autofs
$ sudo systemctl start autofs

์Šคํฌ๋ฆฝํŠธ๋ฅผ ์ž‘์„ฑํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.

$ sudo vim /etc/cron.daily/make.oVirt.backup.sh

๋‹ค์Œ ๋‚ด์šฉ :

#!/bin/bash

datetime=`date +"%F.%R"`
backupdir="/net/mynfs01.example.com/exports/ovirt-backup"
filename="$backupdir/`hostname --short`.`date +"%F.%R"`"
engine-backup --mode=backup --scope=all --file=$filename.data --log=$filename.log
#uncomment next line for autodelete files older 30 days 
#find $backupdir -type f -mtime +30 -exec rm -f {} ;

ํŒŒ์ผ์„ ์‹คํ–‰ ๊ฐ€๋Šฅํ•˜๊ฒŒ ๋งŒ๋“ค๊ธฐ:

$ sudo chmod a+x /etc/cron.daily/make.oVirt.backup.sh

์ด์ œ ๋งค์ผ ๋ฐค ๊ด€๋ฆฌ์ž ์„ค์ • ์•„์นด์ด๋ธŒ๋ฅผ ๋ฐ›๊ฒŒ ๋ฉ๋‹ˆ๋‹ค.

ํ˜ธ์ŠคํŠธ ๊ด€๋ฆฌ ์ธํ„ฐํŽ˜์ด์Šค

์กฐ์ข…์„ โ€” Linux ์‹œ์Šคํ…œ์„ ์œ„ํ•œ ์ตœ์‹  ๊ด€๋ฆฌ ์ธํ„ฐํŽ˜์ด์Šค์ž…๋‹ˆ๋‹ค. ์ด ๊ฒฝ์šฐ ESXi ์›น ์ธํ„ฐํŽ˜์ด์Šค์™€ ์œ ์‚ฌํ•œ ์—ญํ• ์„ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค.

2์‹œ๊ฐ„ ์•ˆ์— ๋ฒ„ํ‹ฐ์„ธ์š”. 3๋ถ€. ์ถ”๊ฐ€ ์„ค์ •
์Œ€. 3 โ€” ํŒจ๋„์˜ ๋ชจ์Šต.

์„ค์น˜๋Š” ๋งค์šฐ ๊ฐ„๋‹จํ•ฉ๋‹ˆ๋‹ค. Cockpit ํŒจํ‚ค์ง€์™€ Cockpit-ovirt-dashboard ํ”Œ๋Ÿฌ๊ทธ์ธ์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.

$ sudo yum install cockpit cockpit-ovirt-dashboard -y

์กฐ์ข…์„ ํ™œ์„ฑํ™”:

$ sudo systemctl enable --now cockpit.socket

๋ฐฉํ™”๋ฒฝ ์„ค์ •:

sudo firewall-cmd --add-service=cockpit
sudo firewall-cmd --add-service=cockpit --permanent

์ด์ œ ํ˜ธ์ŠคํŠธ์— ์—ฐ๊ฒฐํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค: https://[ํ˜ธ์ŠคํŠธ IP ๋˜๋Š” FQDN]:9090

VLAN

๋„คํŠธ์›Œํฌ์— ๋Œ€ํ•œ ์ž์„ธํ•œ ๋‚ด์šฉ์€ ๋‹ค์Œ์—์„œ ์ฝ์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์„ ์  ์„œ๋ฅ˜ ๋น„์น˜. ๋งŽ์€ ๊ฐ€๋Šฅ์„ฑ์ด ์žˆ์Šต๋‹ˆ๋‹ค. ์—ฌ๊ธฐ์„œ๋Š” ๊ฐ€์ƒ ๋„คํŠธ์›Œํฌ ์—ฐ๊ฒฐ์— ๋Œ€ํ•ด ์„ค๋ช…ํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค.

๋‹ค๋ฅธ ์„œ๋ธŒ๋„ท์„ ์—ฐ๊ฒฐํ•˜๋ ค๋ฉด ๋จผ์ € ๊ตฌ์„ฑ(๋„คํŠธ์›Œํฌ -> ๋„คํŠธ์›Œํฌ -> ์ƒˆ๋กœ ๋งŒ๋“ค๊ธฐ)์—์„œ ์„ค๋ช…ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์—ฌ๊ธฐ์„œ๋Š” ์ด๋ฆ„๋งŒ ํ•„์ˆ˜ ํ•„๋“œ์ž…๋‹ˆ๋‹ค. ๋จธ์‹ ์ด ์ด ๋„คํŠธ์›Œํฌ๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•˜๋Š” VM ๋„คํŠธ์›Œํฌ ํ™•์ธ๋ž€์ด ํ™œ์„ฑํ™”๋˜์–ด ์žˆ์ง€๋งŒ ์—ฐ๊ฒฐํ•˜๋ ค๋ฉด ํƒœ๊ทธ๋ฅผ ํ™œ์„ฑํ™”ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. VLAN ํƒœ๊ทธ ํ™œ์„ฑํ™”, VLAN ๋ฒˆํ˜ธ๋ฅผ ์ž…๋ ฅํ•˜๊ณ  ํ™•์ธ์„ ํด๋ฆญํ•˜์„ธ์š”.

์ด์ œ ์ปดํ“จํŒ… ํ˜ธ์ŠคํŠธ -> ํ˜ธ์ŠคํŠธ -> kvmNN -> ๋„คํŠธ์›Œํฌ ์ธํ„ฐํŽ˜์ด์Šค -> ํ˜ธ์ŠคํŠธ ๋„คํŠธ์›Œํฌ ์„ค์ •์œผ๋กœ ์ด๋™ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ํ• ๋‹น๋˜์ง€ ์•Š์€ ๋…ผ๋ฆฌ ๋„คํŠธ์›Œํฌ์˜ ์˜ค๋ฅธ์ชฝ์—์„œ ์ถ”๊ฐ€๋œ ๋„คํŠธ์›Œํฌ๋ฅผ ํ• ๋‹น๋œ ๋…ผ๋ฆฌ ๋„คํŠธ์›Œํฌ๋กœ ์™ผ์ชฝ์œผ๋กœ ๋“œ๋ž˜๊ทธํ•ฉ๋‹ˆ๋‹ค.

2์‹œ๊ฐ„ ์•ˆ์— ๋ฒ„ํ‹ฐ์„ธ์š”. 3๋ถ€. ์ถ”๊ฐ€ ์„ค์ •
์Œ€. 4 - ๋„คํŠธ์›Œํฌ๋ฅผ ์ถ”๊ฐ€ํ•˜๊ธฐ ์ „.

2์‹œ๊ฐ„ ์•ˆ์— ๋ฒ„ํ‹ฐ์„ธ์š”. 3๋ถ€. ์ถ”๊ฐ€ ์„ค์ •
์Œ€. 5 - ๋„คํŠธ์›Œํฌ๋ฅผ ์ถ”๊ฐ€ํ•œ ํ›„.

์—ฌ๋Ÿฌ ๋„คํŠธ์›Œํฌ๋ฅผ ํ˜ธ์ŠคํŠธ์— ์ผ๊ด„ ์—ฐ๊ฒฐํ•˜๋ ค๋ฉด ๋„คํŠธ์›Œํฌ ์ƒ์„ฑ ์‹œ ๋ผ๋ฒจ์„ ํ• ๋‹นํ•˜๊ณ , ๋ผ๋ฒจ๋ณ„๋กœ ๋„คํŠธ์›Œํฌ๋ฅผ ์ถ”๊ฐ€ํ•˜๋Š” ๊ฒƒ์ด ํŽธ๋ฆฌํ•ฉ๋‹ˆ๋‹ค.

๋„คํŠธ์›Œํฌ๊ฐ€ ์ƒ์„ฑ๋œ ํ›„ ํ˜ธ์ŠคํŠธ๋Š” ๋„คํŠธ์›Œํฌ๊ฐ€ ํด๋Ÿฌ์Šคํ„ฐ์˜ ๋ชจ๋“  ๋…ธ๋“œ์— ์ถ”๊ฐ€๋  ๋•Œ๊นŒ์ง€ ๋น„์ž‘๋™ ์ƒํƒœ๋กœ ์ „ํ™˜๋ฉ๋‹ˆ๋‹ค. ์ด ๋™์ž‘์€ ์ƒˆ ๋„คํŠธ์›Œํฌ๋ฅผ ์ƒ์„ฑํ•  ๋•Œ ํด๋Ÿฌ์Šคํ„ฐ ํƒญ์˜ ๋ชจ๋‘ ์š”๊ตฌ ํ”Œ๋ž˜๊ทธ๋กœ ์ธํ•ด ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค. ํด๋Ÿฌ์Šคํ„ฐ์˜ ๋ชจ๋“  ๋…ธ๋“œ์—์„œ ๋„คํŠธ์›Œํฌ๊ฐ€ ํ•„์š”ํ•˜์ง€ ์•Š์€ ๊ฒฝ์šฐ ์ด ํ”Œ๋ž˜๊ทธ๋ฅผ ๋น„ํ™œ์„ฑํ™”ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋Ÿฐ ๋‹ค์Œ ๋„คํŠธ์›Œํฌ๊ฐ€ ํ˜ธ์ŠคํŠธ์— ์ถ”๊ฐ€๋˜๋ฉด ๋„คํŠธ์›Œํฌ๊ฐ€ ํ•„์š”ํ•˜์ง€ ์•Š์Œ ์„น์…˜์˜ ์˜ค๋ฅธ์ชฝ์— ํ‘œ์‹œ๋˜๋ฉฐ ์—ฐ๊ฒฐ ์—ฌ๋ถ€๋ฅผ ์„ ํƒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ํŠน์ • ํ˜ธ์ŠคํŠธ์— ๋ณด๋ƒ…๋‹ˆ๋‹ค.

2์‹œ๊ฐ„ ์•ˆ์— ๋ฒ„ํ‹ฐ์„ธ์š”. 3๋ถ€. ์ถ”๊ฐ€ ์„ค์ •
์Œ€. 6 - ๋„คํŠธ์›Œํฌ ์š”๊ตฌ ์‚ฌํ•ญ ์†์„ฑ์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.

HPE ํŠน์ •

๊ฑฐ์˜ ๋ชจ๋“  ์ œ์กฐ์—…์ฒด์—๋Š” ์ œํ’ˆ์˜ ์œ ์šฉ์„ฑ์„ ํ–ฅ์ƒ์‹œํ‚ค๋Š” ๋„๊ตฌ๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค. HPE๋ฅผ ์˜ˆ๋กœ ๋“ค๋ฉด AMS(Agentless Management Service, iLO5์šฉ amsd, iLO4์šฉ hp-ams) ๋ฐ SSA(Smart Storage Administrator, ๋””์Šคํฌ ์ปจํŠธ๋กค๋Ÿฌ์™€ ์ž‘๋™) ๋“ฑ์ด ์œ ์šฉํ•ฉ๋‹ˆ๋‹ค.

HPE ์ €์žฅ์†Œ ์—ฐ๊ฒฐ
ํ‚ค๋ฅผ ๊ฐ€์ ธ์˜ค๊ณ  HPE ๋ฆฌํฌ์ง€ํ† ๋ฆฌ๋ฅผ ์—ฐ๊ฒฐํ•ฉ๋‹ˆ๋‹ค.

$ sudo rpm --import https://downloads.linux.hpe.com/SDR/hpePublicKey2048_key1.pub
$ sudo vim /etc/yum.repos.d/mcp.repo

๋‹ค์Œ ๋‚ด์šฉ :

[mcp]
name=Management Component Pack
baseurl=http://downloads.linux.hpe.com/repo/mcp/centos/$releasever/$basearch/current/
enabled=1
gpgkey=file:///etc/pki/rpm-gpg/GPG-KEY-mcp

[spp]
name=Service Pack for ProLiant
baseurl=http://downloads.linux.hpe.com/SDR/repo/spp/RHEL/$releasever/$basearch/current/
enabled=1
gpgkey=file:///etc/pki/rpm-gpg/GPG-KEY-mcp

์ €์žฅ์†Œ ์ฝ˜ํ…์ธ  ๋ฐ ํŒจํ‚ค์ง€ ์ •๋ณด ๋ณด๊ธฐ(์ฐธ์กฐ์šฉ):

$ sudo yum --disablerepo="*" --enablerepo="mcp" list available
$ yum info amsd

์„ค์น˜ ๋ฐ ์‹คํ–‰:

$ sudo yum install amsd ssacli
$ sudo systemctl start amsd

๋””์Šคํฌ ์ปจํŠธ๋กค๋Ÿฌ ์ž‘์—…์„ ์œ„ํ•œ ์œ ํ‹ธ๋ฆฌํ‹ฐ์˜ ์˜ˆ
2์‹œ๊ฐ„ ์•ˆ์— ๋ฒ„ํ‹ฐ์„ธ์š”. 3๋ถ€. ์ถ”๊ฐ€ ์„ค์ •

์ง€๊ธˆ์€ ์—ฌ๊ธฐ๊นŒ์ง€์ž…๋‹ˆ๋‹ค. ๋‹ค์Œ ๊ธฐ์‚ฌ์—์„œ๋Š” ๋ช‡ ๊ฐ€์ง€ ๊ธฐ๋ณธ ์ž‘์—…๊ณผ ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ์— ๋Œ€ํ•ด ์ด์•ผ๊ธฐํ•  ๊ณ„ํš์ž…๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด oVirt์—์„œ VDI๋ฅผ ๋งŒ๋“œ๋Š” ๋ฐฉ๋ฒ•์ž…๋‹ˆ๋‹ค.

์ถœ์ฒ˜ : habr.com