Kupanga maziko a IT osalolera zolakwika. Gawo 1 - kukonzekera kutumiza gulu la oVirt 4.3
Owerenga akuitanidwa kuti adziΕ΅e bwino ndi mfundo zomanga zowonongeka zowonongeka kwa bizinesi yaying'ono mkati mwa malo amodzi a deta, zomwe zidzakambidwe mwatsatanetsatane mndandanda waufupi wa nkhani.
Kuyamba
Ndi Data center (Data Processing Center) ikhoza kumveka ngati:
choyikira chanu mu "chipinda chanu cha seva" pamalo abizinesi, chomwe chimakwaniritsa zofunikira zochepa zoperekera magetsi ndi kuziziritsa kwa zida, komanso mutha kugwiritsa ntchito intaneti kudzera mwa othandizira awiri odziyimira pawokha;
rack yobwereka yokhala ndi zida zake, yomwe ili pamalo enieni a data - otchedwa. collocation, yomwe imagwirizana ndi Gawo la III kapena IV, komanso lomwe limatsimikizira magetsi odalirika, kuziziritsa komanso kugwiritsa ntchito intaneti kosalekeza;
zida zobwereketsa kwathunthu mu Tier III kapena IV data center.
Malo ogona omwe mungasankhire ndi munthu payekhapayekha, ndipo nthawi zambiri zimatengera zinthu zingapo zazikulu:
Chifukwa chiyani bizinesi ikufuna maziko ake a IT?
Kodi bizinesiyo ikufuna chiyani kwenikweni kuchokera kuzinthu za IT (kudalirika, scalability, management, etc.);
kuchuluka kwa ndalama zoyambira muzinthu za IT, komanso mtundu wanji wamtengo wake - capital (zomwe zikutanthauza kuti mumagula zida zanu), kapena zogwirira ntchito (zida nthawi zambiri zimabwereka);
kukonzekera m'mphepete mwa bizinesi yokha.
Zambiri zitha kulembedwa pazifukwa zomwe zimalimbikitsa lingaliro la bizinesi kuti lipange ndikugwiritsa ntchito zida zake za IT, koma cholinga chathu ndikuwonetsa momwe tingapangire zida izi kuti zikhale zololera zolakwika ndikusunga ndalama. - kuchepetsa mtengo kugula mapulogalamu amalonda, kapena kuwapewa konse.
Monga momwe machitidwe a nthawi yayitali amasonyezera, sikoyenera kupulumutsa pa hardware, popeza stingy amalipira kawiri, ndipo ngakhale zambiri. Koma kachiwiri, hardware yabwino ndi malingaliro chabe, ndipo pamapeto pake zomwe mungagule ndi ndalama zingati zimatengera luso la bizinesi ndi "dyera" la kayendetsedwe kake. Komanso, mawu akuti "umbombo" ayenera kumveka m'lingaliro labwino la liwu, popeza ndi bwino kuyika ndalama mu hardware pa siteji koyamba, kuti musakhale ndi mavuto aakulu ndi thandizo lake ndi makulitsidwe, popeza poyamba zolakwa kukonzekera ndi. kusungirako ndalama zambiri kungapangitse kuti pakhale ndalama zambiri kuposa pamene mukuyamba ntchitoyo.
Kotero, deta yoyambirira ya polojekitiyi:
pali bizinesi yomwe yasankha kupanga tsamba lake lawebusayiti ndikubweretsa zochitika zake pa intaneti;
kampaniyo inaganiza zobwereka choyikapo kuti iziyika zida zake pamalo abwino ovomerezeka ovomerezeka malinga ndi muyezo wa Tier III;
kampaniyo idaganiza kuti isasunge zambiri pa Hardware, motero idagula zida zotsatirazi ndi chitsimikizo chowonjezereka ndi chithandizo:
Zida mndandanda
ma seva awiri akuthupi a Dell PowerEdge R640 motere:
mapurosesa awiri a Intel Xeon Gold 5120
512 GB RAM
ma disks awiri a SAS mu RAID1, kuti akhazikitse OS
4-port 1G network khadi
makhadi awiri a 2-port 10G network
imodzi 2-doko FC HBA 16G.
2-controller storage system Dell MD3820f, yolumikizidwa kudzera pa FC 16G mwachindunji kwa makamu a Dell;
Rack, UPS, PDU, maseva a console amaperekedwa ndi data center.
Monga tikuwonera, zida zomwe zilipo zili ndi chiyembekezo chabwino chakukula kopingasa komanso kowongoka, ngati bizinesiyo imatha kupikisana ndi makampani ena omwe ali ndi mbiri yofananira pa intaneti, ndikuyamba kupeza phindu, lomwe lingathe kuyikidwamo pakukulitsa chuma chambiri mpikisano. ndi kukula kwa phindu.
Ndi zida ziti zomwe tingawonjezere ngati bizinesi ikufuna kuwonjezera magwiridwe antchito a gulu lathu lamakompyuta:
tili ndi malo ambiri osungiramo ma doko pa masinthidwe a 2960X, zomwe zikutanthauza kuti titha kuwonjezera ma seva ambiri;
gulani ma switch awiri owonjezera a FC kuti mulumikizane ndi machitidwe osungira ndi ma seva owonjezera kwa iwo;
ma seva omwe alipo akhoza kukwezedwa - onjezani kukumbukira, m'malo mwa mapurosesa ndi amphamvu kwambiri, gwirizanitsani ndi intaneti ya 10G pogwiritsa ntchito ma adapter omwe alipo;
Mutha kuwonjezera mashelufu owonjezera a disk kumalo osungira ndi mtundu wofunikira wa disk - SAS, SATA kapena SSD, kutengera katundu wokonzedwa;
mutatha kuwonjezera ma switch a FC, mutha kugula njira ina yosungiramo kuti muwonjezere mphamvu zambiri za disk, ndipo ngati mutagula njira yapadera ya Remote Replication kwa izo, mukhoza kukhazikitsa kubwereza kwa deta pakati pa machitidwe osungiramo mkati mwa malo omwewo a data komanso pakati pa malo a deta ( koma izi zadutsa kale mkati mwa nkhaniyo);
Palinso masiwichi amtundu wachitatu - Cisco 3850, yomwe ingagwiritsidwe ntchito ngati phata lololera zolakwika pamayendedwe othamanga kwambiri pakati pa maukonde amkati. Izi zidzathandiza kwambiri m'tsogolomu pamene zomangamanga zamkati zikukula. 3850 ilinso ndi ma doko a 10G, omwe angagwiritsidwe ntchito pambuyo pake pokweza zida zanu zapaintaneti ku liwiro la 10G.
Popeza tsopano palibe paliponse popanda virtualization, ndithudi tidzakhala muzochitika, makamaka popeza iyi ndi njira yabwino kwambiri yochepetsera mtengo wogula ma seva okwera mtengo pazinthu zamagulu amtundu uliwonse (ma seva a pa intaneti, ma database, ndi zina zotero), zomwe sizikhala nthawi zonse. zabwino kwambiri zimagwiritsidwa ntchito ngati katundu wochepa, ndipo izi ndi zomwe zidzachitike kumayambiriro kwa polojekitiyi.
Kuphatikiza apo, virtualization ili ndi zabwino zina zambiri zomwe zingakhale zothandiza kwambiri kwa ife: Kulekerera kwa VM motsutsana ndi kulephera kwa seva ya hardware, Kusuntha kwamoyo pakati pa ma hardware cluster node pakukonza kwawo, kugawa kwamanja kapena kugawa pakati pamagulu amagulu, ndi zina zotero.
Kwa zida zogulidwa ndi bizinesi, kutumizidwa kwa gulu la VMware vSphere lomwe likupezeka kwambiri limadziwonetsa, koma popeza pulogalamu iliyonse yochokera ku VMware imadziwika ndi ma tag ake amtengo wa "kavalo", tidzagwiritsa ntchito pulogalamu yaulere yowongolera - oVirt, pamaziko omwe chinthu chodziwika bwino koma chogulitsa kale chimapangidwa - rhev.
Software oVirt Zofunikira kuphatikiza zinthu zonse zamapangidwe kukhala chinthu chimodzi kuti athe kugwira ntchito mosavuta ndi makina omwe amapezeka kwambiri - awa ndi nkhokwe, kugwiritsa ntchito intaneti, ma seva oyimira, owerengera, ma seva osonkhanitsira mitengo ndi ma analytics, ndi zina zambiri, ndiko kuti, zomwe tsamba lawebusayiti la bizinesi yathu lili ndi.
Gawo 4 Kukhazikitsa stack ya Cisco 3850, kukonza ma intranet routing.
Gawo 1. Kukonzekera kutumiza gulu la oVirt 4.3
Kukonzekera koyambira koyambira
Kukhazikitsa ndi kukonza OS ndiye gawo losavuta kwambiri. Pali zolemba zambiri zamomwe mungayikitsire bwino ndikusintha OS, ndiye palibe chifukwa choyesera kupereka china chake chokhudza izi.
Chifukwa chake, tili ndi makamu awiri a Dell PowerEdge R640 omwe tiyenera kukhazikitsa Os ndikuchita zoikamo zoyambira kuti tigwiritse ntchito ngati ma hypervisors oyendetsa makina pafupifupi mu gulu la oVirt 4.3.
Popeza tikukonzekera kugwiritsa ntchito pulogalamu yaulere ya oVirt yopanda malonda, OS idasankhidwa kuti itumize makamu. CentOS 7.7, ngakhale ma OS ena akhoza kukhazikitsidwa pa makamu a oVirt:
zomangamanga zapadera zochokera ku RHEL, zomwe zimatchedwa. oVirt Node;
OS Oracle Linux, chilimwe 2019 zidalengezedwa zakuthandizira ntchito ya oVirt pa izo.
Musanayike OS ndikulimbikitsidwa:
sinthani mawonekedwe a netiweki a iDRAC pa makamu onse awiri;
sinthani BIOS ndi iDRAC firmware kumitundu yaposachedwa;
sinthani System Profile ya seva, makamaka mumayendedwe a Performance;
sinthani RAID kuchokera ku ma disks am'deralo (RAID1 ikulimbikitsidwa) kuti muyike OS pa seva.
Kenako timayika OS pa diski yomwe idapangidwa kale kudzera pa iDRAC - kukhazikitsa ndikwabwinobwino, palibe mphindi zapadera mmenemo. Kufikira ku seva ya seva kuti muyambe kuyika OS kutha kupezekanso kudzera pa iDRAC, ngakhale palibe chomwe chimakulepheretsani kulumikiza chowunikira, kiyibodi ndi mbewa molunjika ku seva ndikuyika OS kuchokera pa drive drive.
Pambuyo kukhazikitsa OS, timapanga zoikamo zake zoyambirira:
systemctl enable network.service
systemctl start network.service
systemctl status network.service
systemctl stop NetworkManager
systemctl disable NetworkManager
systemctl status NetworkManager
Kuti muyambe kukhazikitsa OS, muyenera kukonza mawonekedwe aliwonse amtundu pa seva kuti mutha kugwiritsa ntchito intaneti kuti musinthe OS ndikuyika mapulogalamu ofunikira. Izi zitha kuchitika pa nthawi ya kukhazikitsa Os ndi pambuyo pake.
Chithunzi cha 10 - Intaneti Chithunzi cha 17 - Management (iDRAC, makina osungira, kasamalidwe ka ma switch) Chithunzi cha 32 - Network yopanga VM Chithunzi cha 33 - maukonde olumikizana (kwa makontrakitala akunja) Chithunzi cha 34 - VM test network Chithunzi cha 35 - VM developer network Chithunzi cha 40 - Monitoring network
Tisanayambe ntchito, nachi chithunzi pamlingo wa L2 chomwe tiyenera kufikapo:
Pakuyanjana kwa maukonde a oVirt makamu ndi makina enieni wina ndi mnzake, komanso kuyang'anira makina athu osungira, ndikofunikira kukonza masiwichi a Cisco 2960X.
Magulu a Dell apanga makhadi a netiweki a 4-port, chifukwa chake, ndikofunikira kukonza kulumikizana kwawo ndi Cisco 2960X pogwiritsa ntchito kulumikizana kosalekeza kwa netiweki, pogwiritsa ntchito gulu la madoko amtaneti kukhala mawonekedwe omveka, ndi protocol ya LACP ( 802.3ad):
madoko awiri oyambilira omwe ali pagulu amakonzedwa munjira yolumikizirana ndikulumikizidwa ndi switch ya 2960X - mawonekedwe omveka awa adzakonzedwa. mlatho ndi adilesi yoyang'anira olandila, kuyang'anira, kulumikizana ndi makamu ena mugulu la oVirt, idzagwiritsidwanso ntchito pakusamuka kwa Live kwa makina enieni;
madoko awiri achiwiri pa khamu nawonso kukhazikitsidwa mumalowedwe omangika ndi olumikizidwa kwa 2960X - pa mawonekedwe zomveka ntchito oVirt, milatho adzalengedwa m'tsogolo (mu VLANs lolingana) kumene makina pafupifupi adzakhala chikugwirizana.
madoko onse a netiweki, mkati mwa mawonekedwe omwewo omveka, adzakhala achangu, i.e. magalimoto pamwamba pawo akhoza kupatsirana nthawi imodzi, munjira yokhazikika.
zokonda pa netiweki pamagulumagulu ziyenera kukhala ZOMWEZO, kupatula ma adilesi a IP.
Kukonzekera koyambira koyambira 2960X ndi madoko ake
2960X#show switch stack-ring speed
Stack Ring Speed : 20G
Stack Ring Configuration: Full
Stack Ring Protocol : FlexStack
2960X#show switch stack-ports
Switch # Port 1 Port 2
-------- ------ ------
1 Ok Ok
2 Ok Ok
2960X#show switch neighbors
Switch # Port 1 Port 2
-------- ------ ------
1 2 2
2 1 1
2960X#show switch detail
Switch/Stack Mac Address : 0cd0.f8e4.Π₯Π₯Π₯Π₯
Mac persistency wait time: Indefinite
H/W Current
Switch# Role Mac Address Priority Version State
----------------------------------------------------------
*1 Master 0cd0.f8e4.Π₯Π₯Π₯Π₯ 15 4 Ready
2 Member 0029.c251.Π₯Π₯Π₯Π₯ 14 4 Ready
Stack Port Status Neighbors
Switch# Port 1 Port 2 Port 1 Port 2
--------------------------------------------------------
1 Ok Ok 2 2
2 Ok Ok 1 1
4) Kukhazikitsa mwayi wa SSH ku stack 2960X
Kuti tisamalire stack kudzera pa SSH, tidzagwiritsa ntchito IP 172.20.1.10 yokonzedwera SVI (kusintha mawonekedwe enieni) Chithunzi cha VLAN17.
Ngakhale kuli koyenera kugwiritsa ntchito doko lodzipatulira pa switch pazifukwa zowongolera, iyi ndi nkhani ya zomwe amakonda komanso kuthekera kwake.
Kukonza mwayi wa SSH pagulu la masiwichi:
ip default-gateway 172.20.1.2
interface vlan 17
ip address 172.20.1.10 255.255.255.0
hostname 2960X
ip domain-name hw.home-lab.ru
no ip domain-lookup
clock set 12:47:04 06 Dec 2019
crypto key generate rsa
ip ssh version 2
ip ssh time-out 90
line vty 0 4
session-timeout 60
exec-timeout 60 0
privilege level 15
logging synchronous
transport input ssh
line vty 5 15
session-timeout 60
exec-timeout 60 0
privilege level 15
logging synchronous
transport input ssh
aaa new-model
aaa authentication login default local
username cisco privilege 15 secret my_ssh_password
Konzani mawu achinsinsi kuti mulowe mwamwayi:
enable secret *myenablepassword*
service password-encryption
Kupanga NTP:
ntp server 85.21.78.8 prefer
ntp server 89.221.207.113
ntp server 185.22.60.71
ntp server 192.36.143.130
ntp server 185.209.85.222
show ntp status
show ntp associations
show clock detail
5) Konzani zolumikizira zomveka za Etherchannel ndi madoko akuthupi olumikizidwa ndi makamu. Kuti musamavutike, ma VLAN onse omwe akupezeka adzayatsidwa pazolumikizana zonse zomveka, koma nthawi zambiri zimalimbikitsidwa kuti zisinthe zomwe zikufunika:
Mukamaliza zoikamo pa okwana 2960 Π₯ ndi makamu, timayambitsanso maukonde pa makamu ndikuyang'ana magwiridwe antchito a mawonekedwe omveka.
pa wolandila:
systemctl restart network
cat /proc/net/bonding/bond1
Ethernet Channel Bonding Driver: v3.7.1 (April 27, 2011)
Bonding Mode: IEEE 802.3ad Dynamic link aggregation
Transmit Hash Policy: layer2+3 (2)
MII Status: up
MII Polling Interval (ms): 100
Up Delay (ms): 0
Down Delay (ms): 0
...
802.3ad info
LACP rate: fast
Min links: 0
Aggregator selection policy (ad_select): stable
System priority: 65535
...
Slave Interface: em2
MII Status: up
Speed: 1000 Mbps
Duplex: full
...
Slave Interface: em3
MII Status: up
Speed: 1000 Mbps
Duplex: full
pamtengo wosinthira 2960 Π₯:
2960X#show lacp internal
Flags: S - Device is requesting Slow LACPDUs
F - Device is requesting Fast LACPDUs
A - Device is in Active mode P - Device is in Passive mode
Channel group 1
LACP port Admin Oper Port Port
Port Flags State Priority Key Key Number State
Gi1/0/1 SA bndl 32768 0x1 0x1 0x102 0x3D
Gi2/0/1 SA bndl 32768 0x1 0x1 0x202 0x3D
2960X#sh etherchannel summary
Flags: D - down P - bundled in port-channel
I - stand-alone s - suspended
H - Hot-standby (LACP only)
R - Layer3 S - Layer2
U - in use N - not in use, no aggregation
f - failed to allocate aggregator
M - not in use, minimum links not met
m - not in use, port not aggregated due to minimum links not met
u - unsuitable for bundling
w - waiting to be aggregated
d - default port
A - formed by Auto LAG
Number of channel-groups in use: 11
Number of aggregators: 11
Group Port-channel Protocol Ports
------+-------------+-----------+-----------------------------------------------
1 Po1(SU) LACP Gi1/0/1(P) Gi2/0/1(P)
Kukonzekera koyambirira kwa ma netiweki olumikizirana kuti muzitha kuyang'anira zinthu zamagulu pa makamu alendo1 ΠΈ alendo2
Kukonza mawonekedwe omveka a BOND1 a kasamalidwe ndi mawonekedwe ake pa olandila:
Timayambanso maukonde pa makamu ndikuyang'ana maonekedwe awo kwa wina ndi mzake.
Izi zimamaliza kasinthidwe ka masinthidwe a Cisco 2960X, ndipo ngati zonse zidachitika molondola, ndiye kuti tsopano tili ndi kulumikizana kwa maukonde azinthu zonse zachitukuko wina ndi mnzake pamlingo wa L2.
Kukhazikitsa Dell MD3820f yosungirako
Musanayambe ntchito yokonza zosungirako, ziyenera kulumikizidwa kale ndi ma switch a Cisco 2960 Π₯ control interfaces, komanso makamu alendo1 ΠΈ alendo2 kudzera pa FC.
Chithunzi chodziwika bwino cha momwe makina osungira ayenera kulumikizidwa ndi ma switch ambiri adaperekedwa m'mutu wapitawu.
Chithunzi cholumikizira makina osungira kudzera ku FC kwa omwe akukhala nawo ayenera kuwoneka motere:
Panthawi yolumikizana, muyenera kulemba ma adilesi a WWPN a makamu a FC HBA olumikizidwa ndi madoko a FC pamakina osungira - izi zidzakhala zofunikira kuti mtsogolo mukhazikitse kumangirira kwa makamu ku LUNs pamakina osungira.
Pamalo ogwirira ntchito a woyang'anira, tsitsani ndikuyika zofunikira pakuwongolera makina osungira a Dell MD3820f - PowerVault Modular Disk Storage Manager (Zithunzi za MDSM).
Timalumikizana nawo kudzera mu ma adilesi ake a IP, kenako timakonza ma adilesi athu kuchokera Chithunzi cha VLAN17, kuyang'anira olamulira kudzera pa TCP/IP:
Kusunga1:
ControllerA IP - 172.20.1.13, MASK - 255.255.255.0, Gateway - 172.20.1.2
ControllerB IP - 172.20.1.14, MASK - 255.255.255.0, Gateway - 172.20.1.2
Pambuyo kukhazikitsa maadiresi, pitani ku mawonekedwe osungirako zosungirako ndikuyika mawu achinsinsi, ikani nthawi, sinthani firmware kwa olamulira ndi ma disks, ngati kuli kofunikira, ndi zina zotero.
Momwe izi zimachitikira zikufotokozedwa mu kalozera woyang'anira Njira yosungirako
Konzani ma ID a doko a FC - Host Port Identifiers.
Pangani gulu lothandizira - Gulu la alendo ndikuwonjezera makamu athu awiri a Dell kwa izo.
Pangani gulu la disk ndi ma disks (kapena LUNs) mmenemo omwe adzasonyezedwe kwa makamu.
Konzani kuwonetsera kwa ma disks (kapena LUNs) a makamu.
Kuwonjeza olandila atsopano ndikumangirira zizindikiritso za doko la FC kwa iwo kumachitika kudzera pa menyu - Host Mappings -> Fotokozani -> Olandiraβ¦
Maadiresi a WWPN a makamu a FC HBA atha kupezeka, mwachitsanzo, mu maseva a iDRAC.
Chifukwa chake, tiyenera kupeza zinthu monga izi:
Kuwonjezera gulu latsopano la makamu ndi kumanga makamu kwa izo kumachitika kudzera menyu - Host Mappings -> Fotokozani -> Gulu la Hostβ¦
Kwa makamu, sankhani mtundu wa OS - Linux (DM-MP).
Pambuyo popanga gulu la alendo, kudzera pa tabu Ntchito Zosungira & Makope, pangani gulu la disk - Gulu la Disk, yokhala ndi mtundu kutengera zofunikira pakulekerera zolakwika, mwachitsanzo, RAID10, ndi momwemo ma disks enieni a kukula kofunikira:
Ndipo pomaliza, gawo lomaliza ndikuwonetsa ma disks (kapena LUNs) kwa omwe ali nawo.
Kuti muchite izi, dinani pa menyu - Host Mappings -> Mapu a mwezi -> Onjezerani ... Timagwirizanitsa ma disks enieni ndi makamu powapatsa manambala.