-
Notifications
You must be signed in to change notification settings - Fork 5
/
easyStack_yoga.sh
2011 lines (1766 loc) · 66.8 KB
/
easyStack_yoga.sh
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
#!/bin/sh
export LC_ALL=en_US.utf8
DEBUG="True"
MY_IP=$(ip a | awk '/inet.*internal/{split($2,a,"/");{if(a[1]!="127.0.0.1") print a[1]}}'|head -1)
TENANT_IP=$(ip a|awk '/inet.*tenant/{split($2,a,"/");{if(a[1]!="127.0.0.1") print a[1]}}'|head -1)
REGION="Region0571"
DBPASSWD="***upyun***"
DBROOTPW="***upyun***"
LVM_VOLUME="nvme-disk"
GPUNAME="geforce_rtx_4090"
##############################################
if [ -z $MY_IP ] ;then
MY_IP=$(ip a | awk '/inet.*global/{split($2,a,"/");{if(a[1]!="127.0.0.1") print a[1]}}'|head -1)
TENANT_IP=$MY_IP
fi
CCVIP=$MY_IP
readonly SSHPORT=65422
readonly MY_PORT=3306
readonly ZONE="Asia/Shanghai"
readonly VERSION="yoga"
readonly CPU_RATIO=10
readonly MEM_RATIO=1
readonly MY_UUID="9a3b92a-4f84-34gh-89zv-7de9346qwxr"
readonly CPU_NUMS=`grep -c "vendor_id" /proc/cpuinfo`
# 配置颜色
readonly RED_COL="\\033[1;31m" # red color
readonly GREEN_COL="\\033[32;1m" # green color
readonly BLUE_COL="\\033[34;1m" # blue color
readonly YELLOW_COL="\\033[33;1m" # yellow color
readonly NORMAL_COL="\\033[0;39m"
readonly RDO_URL="https://repos.fedorapeople.org/repos/openstack/archived/openstack-yoga/rdo-release-yoga-1.el8.noarch.rpm"
# 如果不是root,就退出
if [ `whoami` != "root" ]; then
echo "You should be as root."
exit 0
fi
grep -wEq "vmx|svm" /proc/cpuinfo
if [ $? = 0 ];then
lsmod |grep -qw kvm
[ $? = 0 ] && VIRT_TYPE="kvm"
fi
##############################################
check_kvm(){
IOMMU="intel_iommu=on iommu=pt"
KVM="kvm_intel nested=1"
grep -iq '^model name.*amd ' /proc/cpuinfo
if [ $? = 0 ] ;then
IOMMU="amd_iommu=on iommu=pt"
KVM="kvm_amd nested=1"
fi
[ -s /etc/modprobe.d/kvm.conf ] && sed -r -i '/ignore_msrs/d; /nested/d' /etc/modprobe.d/kvm.conf
echo -en "options kvm ignore_msrs=1\noptions $KVM\n" >> /etc/modprobe.d/kvm.conf
}
##############################################
check_env(){
if [ ! -s ~/.easystackrc ];then
echo -en "Input Host Name ${YELLOW_COL} [ $(hostname) ] ${NORMAL_COL}: " && read VARIABLE
[ ! -z "$VARIABLE" ] && HOSTNAME=$VARIABLE
echo -en "Input Region No ${YELLOW_COL} [ $REGION ] ${NORMAL_COL}: " && read VARIABLE
[ ! -z "$VARIABLE" ] && REGION=$VARIABLE
echo -en "Input Local IP ${YELLOW_COL} [ $MY_IP ] ${NORMAL_COL}: " && read VARIABLE
if [ ! -z "$VARIABLE" ];then
VALID_CHECK=$(echo $VARIABLE|awk -F. '$1<=255&&$2<=255&&$3<=255&&$4<=255{print "yes"}')
if [ ! -z $VALID_CHECK ] && [ $VALID_CHECK = "yes" ];then
MY_IP=$VARIABLE
else
echo "IP Format Error!" && exit 0
fi
fi
echo -en "Does it MySQL Cluster? ${YELLOW_COL} [ Y|N ] ${NORMAL_COL}: " && read -n 1 VARIABLE
if [ ! -z ${VARIABLE} ] && [ ${VARIABLE,,} = "y" ];then
i=1
while [ $i -le 3 ];do
echo -en "\n${YELLOW_COL}$i node ip address${NORMAL_COL}: " && read VARIABLE
if [ ! -z "$VARIABLE" ];then
VALID_CHECK=$(echo $VARIABLE|awk -F. '$1<=255&&$2<=255&&$3<=255&&$4<=255{print "yes"}')
if [ ! -z $VALID_CHECK ] && [ $VALID_CHECK = "yes" ];then
GLERA_SRV+="$VARIABLE,"
((i++))
else
echo "IP Format error!"
fi
fi
done
GLERA_SRV=${GLERA_SRV%,}
else
echo -en "\nCompute Node."
GLERA_SRV=
fi
echo
echo -en "Input Provider Device ${YELLOW_COL} [ $PROVIDER_INTERFACE ] ${NORMAL_COL}: \n"
A_LISTS=$(nmcli device | awk '/connected/{print $1}')
select choice in $A_LISTS; do
if [ ! -z $choice ];then
PROVIDER_INTERFACE=$choice
break
fi
done
echo -en "Input Storage Backend ${YELLOW_COL} [ $STORE_BACKEND ] ${NORMAL_COL}: \n"
A_LISTS="LVM Ceph"
select choice in $A_LISTS; do
if [ ! -z $choice ];then
STORE_BACKEND=${choice,,}
break
fi
done
echo -en "Choos Node Role ${YELLOW_COL} [ $NODE_TYPE ] ${NORMAL_COL}: \n"
A_LISTS="ALL Control Network Compute"
select choice in $A_LISTS; do
case $choice in
ALL)
NODE_TYPE="all"
break;;
Control)
NODE_TYPE="control"
break;;
Network)
NODE_TYPE="network"
break;;
Compute)
NODE_TYPE="compute"
break;;
*)
echo "Choose again ";;
esac
done
if [[ $(lspci -nn| sed -r -n '/VGA.*NVIDIA/s@.*\[(.*)\].*\[.*@\1@gp'|tr ' ' '_'|sort -u) =~ ^[0-9]* ]];then
echo -en "Input GPU Name${YELLOW_COL} [ $GPUNAME ] ${NORMAL_COL}: " && read VARIABLE
[ ! -z "$VARIABLE" ] && GPUNAME=$VARIABLE
fi
CCVIP=`echo $HOSTNAME|awk -F. '{print "cc."$(NF-1)"."$NF}'`
DBVIP=`echo $HOSTNAME|awk -F. '{print "db."$(NF-1)"."$NF}'`
NETVIP=`echo $HOSTNAME|awk -F. '{print "net."$(NF-1)"."$NF}'`
cat > ~/.easystackrc <<EOF
HOSTNAME="$HOSTNAME"
NODE_TYPE="$NODE_TYPE"
REGION="$REGION"
CCVIP="$CCVIP"
DBVIP="$DBVIP"
MY_IP="$MY_IP"
VIRT_TYPE="${VIRT_TYPE:-"qemu"}"
PROVIDER_INTERFACE="${PROVIDER_INTERFACE/@*/}"
GLERA_SRV="${GLERA_SRV%,}"
MEMCACHES="$CCVIP:11211"
STORE_BACKEND=$STORE_BACKEND
GPUNAME="${GPUNAME,,}"
NOVA_URL="http://$CCVIP:8774/v2.1"
IMAGE_URL="http://$CCVIP:9292/v2"
VOLUME_URL="http://$CCVIP:8776/v3"
NEUTRON_URL="http://$NETVIP:9696"
OCTAVIA_URL="http://$CCVIP:9876"
PLACEMENT_URL="http://$CCVIP:8778"
KEYS_AUTH_URL="http://$CCVIP:5000/v3"
KEYS_ADMIN_URL="http://$CCVIP:35357/v3"
EOF
fi
##############################################
check_kvm
echo -en "${GREEN_COL}-------------- Individual Parameters ---------------${NORMAL_COL}\n"
cat ~/.easystackrc
grep -iq $VERSION /etc/yum.repos.d/ -r -l
if [ $? = 0 ];then
echo -en "${YELLOW_COL}---------------- Are you sure? -----------------${NORMAL_COL}\n\n"
else
echo -en "\n${GREEN_COL}========= $0 ${YELLOW_COL}adjust_sys ${GREEN_COL} =========${NORMAL_COL}\n\n"
exit 0
fi
}
##############################################
readonly ADMIN_SETTING="admin|XXX|admin|service" # user|pass|role|tenant
readonly SCRIPT="easyStack_$VERSION.sh"
readonly COMMAND=`pwd`"/$SCRIPT"
# 配置参数保存目录
readonly KS_DIR="/var/lib/keystone"
readonly KS_RCONFIG="$KS_DIR/ks_rc_"
readonly KS_TOKEN_PRE="$KS_DIR/ks_token_"
readonly KS_USER_PRE="$KS_DIR/ks_userid_"
readonly KS_ROLE_PRE="$KS_DIR/ks_roleid_"
readonly KS_SERV_PRE="$KS_DIR/ks_servid_"
readonly KS_TENANT_PRE="$KS_DIR/ks_tenantid_"
############## function begin #################
ADMIN_USER=`echo $ADMIN_SETTING|cut -d"|" -f1`
#ADMIN_PASS=`echo "$ADMIN_USER@@$DBPASSWD" | md5sum | cut -c1-15`
ADMIN_PASS="$ADMIN_USER@$DBPASSWD"
ADMIN_ROLE=`echo $ADMIN_SETTING|cut -d"|" -f3`
TENANT_NAME=`echo $ADMIN_SETTING|cut -d"|" -f4`
# 导入 admin凭证
[ -s $KS_RCONFIG$ADMIN_USER ] && source $KS_RCONFIG$ADMIN_USER
[ -s ~/.easystackrc ] && source ~/.easystackrc
mkinitrd_vfio(){
# ls -adl /sys/kernel/iommu_groups/*
# lspci -s 01:00.0 -k
check_kvm
GPUVID=$(lspci -nn | sed -r -n '/NVIDIA/s@(.*)\[(.*)\].*@\1 \2@gp'|awk -v ORS="," '{print $NF}')
[ -s /etc/modprobe.d/vfio.conf ] && sed -r -i '/vfio-pci/d' /etc/modprobe.d/vfio.conf
echo "options vfio-pci ids=${GPUVID%,}" >> /etc/modprobe.d/vfio.conf
if [ -s /etc/modprobe.d/blacklist-gpu.conf ]; then
for dev in snd_hda_intel amd76x_edac vga16fb nouveau rivafb nvidiafb rivatv nvidia;do
sed -r -i "/$dev/d" /etc/modprobe.d/blacklist-gpu.conf
done
fi
for dev in snd_hda_intel amd76x_edac vga16fb nouveau rivafb nvidiafb rivatv nvidia;do
echo "blacklist $dev" >> /etc/modprobe.d/blacklist-gpu.conf
done
grep -q "iommu=" /etc/default/grub
if [ $? = 0 ] ;then
sed -r -i "/GRUB_CMDLINE_LINUX/s@=\"(.*) (intel_iommu|amd_iommu).*\"@=\"\1 $IOMMU vfio-pci.ids=${GPUVID%,} vfio_iommu_type1.allow_unsafe_interrupts=1 modprobe.blacklist=nvidiafb,nouveau\"@g" /etc/default/grub
else
sed -r -i "/GRUB_CMDLINE_LINUX/s@=\"(.*)\"@=\"\1 $IOMMU vfio-pci.ids=${GPUVID%,} vfio_iommu_type1.allow_unsafe_interrupts=1 modprobe.blacklist=nvidiafb,nouveau\"@g" /etc/default/grub
fi
grep -q "Amy" /boot/grub2/grub.cfg
if [ $? = 0 ];then
grep -q "iommu=" /boot/grub2/grub.cfg
if [ $? = 0 ] ;then
sed -r -i "/vmlinuz.*AmyC /s@=(.*) (intel_iommu|amd_iommu).*@=\1 $IOMMU vfio-pci.ids=${GPUVID%,} vfio_iommu_type1.allow_unsafe_interrupts=1 modprobe.blacklist=nvidiafb,nouveau@g" /boot/grub2/grub.cfg
else
sed -r -i "/vmlinuz.*AmyC /s@=(.*)@=\1 $IOMMU vfio-pci.ids=${GPUVID%,} vfio_iommu_type1.allow_unsafe_interrupts=1 modprobe.blacklist=nvidiafb,nouveau@g" /boot/grub2/grub.cfg
fi
else
grub2-mkconfig -o /boot/grub2/grub.cfg
grub2-mkconfig -o /boot/efi/EFI/centos/grub.cfg
fi
if [ ! -s /etc/dracut.conf.d/10-vfio.conf ];then
echo force_drivers+=\" vfio vfio_iommu_type1 vfio_pci vfio_virqfd\" > /etc/dracut.conf.d/10-vfio.conf
dracut -f --kver `uname -r`
fi
}
adjust_sys(){
# 禁用SELinux
echo -en "${YELLOW_COL}---------------- Check SELinux/Firewall/Repo/Yoga -----------------${NORMAL_COL}\n\n"
setenforce 0
grubby --update-kernel ALL --args selinux=0
sed -r -i '/^SELINUX=/s:.*:SELINUX=disabled:' /etc/sysconfig/selinux
sed -r -i '/^SELINUX=/s:.*:SELINUX=disabled:' /etc/selinux/config
grep 114.114.114 /etc/resolv.conf
[ $? == 0 ] || ( echo "nameserver 114.114.114.114" > /etc/resolv.conf)
# 修改为阿里源 或 mirrors.bfsu.edu.cn
sed -r -i -e 's|^mirrorlist=|#mirrorlist=|g' \
-e '/^baseurl/s|(.*releasever)/(.*)|baseurl=https://mirrors.aliyun.com/centos-vault/8.5.2111/\2|g' \
/etc/yum.repos.d/CentOS-*.repo
dnf install -y epel-release.noarch
# 安装rdo仓库
grep -iq $VERSION /etc/yum.repos.d/ -r -l
if [ $? != 0 ];then
dnf install -y $RDO_URL
fi
dnf install -y python3-openstackclient python3-libvirt libvirt wget tar rsyslog supervisor pciutils chrony screen bind-utils vim-enhanced stress --enablerepo=epel
# 配置主机名
sed -r -i "/$HOSTNAME/d" /etc/hosts
echo -en "$MY_IP \t $HOSTNAME\n" >> /etc/hosts
hostnamectl --static set-hostname $HOSTNAME
hostnamectl --pretty set-hostname $HOSTNAME
hostnamectl --transient set-hostname $HOSTNAME
echo "$HOSTNAME" > /proc/sys/kernel/hostname
if [ -s /network.info ];then
sed -r -i '/^HOSTNAME/d' /network.info
sed -r -i "1i HOSTNAME=\"$HOSTNAME\"" /network.info
fi
# 配置ssh的密钥访问
if [ ! -d ~/.ssh ];then
ssh-keygen -t rsa -b 4096 -P "" -f ~/.ssh/id_rsa
curl -X GET -o ~/.ssh/authorized_keys http://devops.upyun.com/authorized_keys
fi
if [ ! -s ~/.ssh/config ];then
cat > ~/.ssh/config <<EOF
StrictHostKeyChecking no
UserKnownHostsFile /dev/null
User root
Port $SSHPORT
Identityfile ~/.ssh/id_rsa
EOF
fi
if [ -s ~/.ssh/authorized_keys ];then
grep -iqE "shaohy|shaohaiyang" /root/.ssh/authorized_keys
[ $? = 1 ] && curl -X GET -o ~/.ssh/authorized_keys http://devops.upyun.com/authorized_keys
else
curl -X GET -o ~/.ssh/authorized_keys http://devops.upyun.com/authorized_keys
fi
chmod 0400 ~/.ssh/*
grep -iqE "shaohy|shaohaiyang" /root/.ssh/authorized_keys
[ $? = 0 ] && sed -r -i "/#Port 22/s^.*^Port $SSHPORT^g;/^PasswordAuthentication/s^yes^no^g" /etc/ssh/sshd_config
# 配置终端字符集
localectl set-locale LANG=en_US.UTF8
cat > /etc/locale.conf <<EOF
LANG=en_US.utf8
LC_CTYPE=en_US.utf8
EOF
sed -r -i '/nofile/d' /etc/security/limits.conf
cat > /etc/security/limits.d/20-nproc.conf <<EOF
* soft nproc 10240
root soft nproc unlimited
EOF
sed -r -i '/^automatic_/d' /etc/dnf/dnf.conf
cat >> /etc/dnf/dnf.conf <<EOF
# 禁用 automatic updates
automatic_config=false
automatic_upgrade=false
EOF
### set timezone and language
ln -snf /usr/share/zoneinfo/$ZONE /etc/localtime
timedatectl set-timezone $ZONE
timedatectl set-ntp 1
timedatectl set-local-rtc 0
chronyc makestep
sed -r -i -e '/DefaultLimitCORE/s^.*^DefaultLimitCORE=infinity^g' \
-e '/DefaultLimitNOFILE/s^.*^DefaultLimitNOFILE=100000^g' \
-e '/DefaultLimitNPROC/s^.*^DefaultLimitNPROC=100000^g' /etc/systemd/system.conf
sed -r -i -e 's@weekly@daily@g;s@^rotate.*@rotate 7@g;s@^#compress.*@compress@g' /etc/logrotate.conf
sed -r -i -e '/Compress=/s@.*@Compress=yes@g;/MaxRetentionSec=/s@.*@MaxRetentionSec=2week@g' \
-e '/MaxLevelStore=/s@.*@MaxLevelStore=debug@g; /MaxLevelSyslog=/s@.*@MaxLevelSyslog=err@g' \
-e '/SystemMaxUse=/s@.*@SystemMaxUse=10G@g;/SystemMaxFileSize=/s@.*@SystemMaxFileSize=1G@g' \
-e '/RuntimeMaxUse=/s@.*@RuntimeMaxUse=8G@g;/RuntimeMaxFileSize=/s@.*@RuntimeMaxFileSize=1G@g' \
/etc/systemd/journald.conf
grep MAILTO= /etc/ -r -l | xargs sed -r -i '/MAILTO=/s@=.*@=@'
sed -r -i '/^CRONDARGS=/s@=.*@="-s -m off"@g' /etc/sysconfig/crond
systemctl disable --now rpcbind.target rpcbind.service rpcbind.socket firewalld postfix irqbalance tuned sssd
# 固定版本yum-versionlock
POWERTOOLS=$(grep -i '\[powertools\]' /etc/yum.repos.d/*.repo | sed -r -n 's@.*\[(.*)\].*@\1@gp'|sort -u|head -1)
dnf config-manager --set-disabled epel
dnf config-manager --set-enabled $POWERTOOLS
# 开启透明大页
cat >> /etc/sysctl.conf <<EOF
net.ipv4.ip_forward=1
net.ipv4.conf.all.rp_filter=0
net.bridge.bridge-nf-call-iptables=1
net.bridge.bridge-nf-call-ip6tables=1
EOF
echo always > /sys/kernel/mm/transparent_hugepage/enabled
echo never > /sys/kernel/mm/transparent_hugepage/defrag
echo 0 > /sys/kernel/mm/transparent_hugepage/khugepaged/defrag
sed -r -i '/PS1=/d' /root/.bashrc
echo "PS1='[\u@\H \W]\\$ '" >> /root/.bashrc
ln -snf /root/.bashrc /root/.bash_profile
}
# 安装openstack控制器组件
control_init(){
POWERTOOLS=$(grep -i '\[powertools\]' /etc/yum.repos.d/*.repo | sed -r -n 's@.*\[(.*)\].*@\1@gp'|sort -u|head -1)
grep -iq $VERSION /etc/yum.repos.d/ -r -l
if [ $? != 0 ] ;then
dnf install -y $RDO_URL
fi
for svc in httpd mariadb-server rabbitmq-server memcached nginx-mod-stream haproxy mod_ssl ebtables bridge-utils ipset python3-mod_wsgi python3-oauth2client python3-openstackclient ;do
echo -e "${YELLOW_COL}-> Installing $svc ... ${NORMAL_COL}"
dnf list installed | grep -iq $svc
[ $? != 0 ] && dnf --enablerepo=$POWERTOOLS --enablerepo=openstack-$VERSION install -y $svc
done
if [ ! -z "$GLERA_SRV" ];then
echo -e "${YELLOW_COL}-> Installing MariaDB Glera Cluster ... ${NORMAL_COL}"
dnf list installed | grep -iq mariadb-server-galera
[ $? != 0 ] && dnf --enablerepo=$POWERTOOLS --enablerepo=openstack-$VERSION install -y mariadb-server-galera
if [ -s /etc/my.cnf.d/galera.cnf ];then
sed -r -i '/shy_begin/, /shy_end/d' /etc/my.cnf.d/galera.cnf
sed -r -i "/^wsrep_provider/a ### shy_begin\nwsrep_provider_options=\"gmcast.listen_addr=tcp://$MY_IP:4567; gcs.fc_limit = 2048; gcs.fc_factor = 0.99; gcs.fc_master_slave = yes\"\nbind-address=\"$MY_IP\"\nwsrep_cluster_name=\"yoga_wsrep_db\"\nwsrep_cluster_address=\"gcomm://$GLERA_SRV\"\nwsrep_node_address=\"$MY_IP\"\nwsrep_slave_threads = 300\n### shy_end" /etc/my.cnf.d/galera.cnf
fi
fi
sed -r -i '/auth_gssapi.so/s@^@#@g' /etc/my.cnf.d/auth_gssapi.cnf
if [ -s /etc/my.cnf.d/mariadb-server.cnf ];then
sed -r -i '/shy_begin/, /shy_end/d' /etc/my.cnf.d/mariadb-server.cnf
sed -r -i "/pid-file/a ### shy_begin\nskip-name-resolve = 1\ndefault-storage-engine = innodb\ninnodb_file_per_table = on\nback_log = 10240\nmax_connections = 10240\nthread_cache_size = 10240\nmax_connect_errors = 10240\nthread_pool_idle_timeout = 7200\nconnect_timeout = 7200\nnet_read_timeout = 7200\nnet_write_timeout = 7200\ninteractive_timeout = 7200\nwait_timeout = 7200\nhost_cache_size = 0\nthread_pool_size = 1024\nquery_cache_size = 512M\nmax_allowed_packet = 512M\nnet_buffer_length = 1048576\ncollation-server = utf8_general_ci\ncharacter-set-server = utf8\nbind-address = $MY_IP\nport = $MY_PORT\n### shy_end" /etc/my.cnf.d/mariadb-server.cnf
fi
if [ -s /etc/sysconfig/memcached ];then
cat >/etc/sysconfig/memcached <<EOF
PORT="11211"
USER="memcached"
MAXCONN="4096"
CACHESIZE="256"
OPTIONS="-l 127.0.0.1,$MY_IP"
EOF
fi
if [ -s /etc/rabbitmq/rabbitmq.conf ];then
sed -r -i "/listeners.tcp.local /s@.*@listeners.tcp.local = $MY_IP:5672@g" /etc/rabbitmq/rabbitmq.conf
#[ -z "$GLERA_SRV" ] || sed -r -i "/management.tcp.ip/s@.*@management.tcp.ip = $MY_IP@g" /etc/rabbitmq/rabbitmq.conf
cat > /etc/rabbitmq/rabbitmq-env.conf<<EOF
RABBITMQ_NODE_IP_ADDRESS=$MY_IP
export ERL_EPMD_ADDRESS=$MY_IP
EOF
fi
cat > /etc/nginx/nginx.conf <<EOF
user nginx;
worker_processes auto;
error_log /var/log/nginx/error.log;
pid /run/nginx.pid;
include /usr/share/nginx/modules/*.conf;
events {
worker_connections 10240;
}
EOF
cat > /etc/haproxy/haproxy.cfg <<EOF
global
log 127.0.0.1 local2
chroot /var/lib/haproxy
pidfile /var/run/haproxy.pid
maxconn 10240
user haproxy
group haproxy
daemon
defaults
mode tcp
log global
retries 10
timeout queue 10m
timeout connect 10m
timeout check 30s
EOF
for svc in rabbitmq-server mariadb memcached ;do
echo -e "${YELLOW_COL} -> Starting Service $svc ... ${NORMAL_COL}"
systemctl enable --now $svc
done
#scp /var/lib/rabbitmq/.erlang.cookie node:/var/lib/rabbitmq/.erlang.cookie
#rabbitmqctl stop_app
#rabbitmqctl reset
#rabbitmqctl forget_cluster_node ccm-01
#rabbitmqctl join_cluster rabbit@ccm-01
#rabbitmqctl start_app
rabbitmqctl change_password guest $DBPASSWD
rabbitmqctl set_permissions guest ".*" ".*" ".*"
rabbitmq-plugins enable rabbitmq_management
rabbitmqctl set_policy ha-all "^" '{"ha-mode":"all" , "ha-sync-mode":"automatic"}'
# grant all privileges on *.* to root@'100.100.%' identified by 'DBROOTPW' with grant option
echo -e "${YELLOW_COL} MySQL-> UPDATE user SET Password=PASSWORD(\"DBROOTPW\") WHERE User=\"root\"${NORMAL_COL}"
}
env_clean(){
echo -e "${YELLOW_COL}Neutron: Clean unused agent... ${NORMAL_COL}"
#openstack network agent list | awk '/XXX/{print $2}'|xargs -i openstack network agent delete {}
SRV=$(neutron agent-list | awk -v ORS=" " '/xxx/{print $2}')
[ -z "$SRV" ] || neutron agent-delete $SRV
echo -e "${YELLOW_COL}Compute: Clean unused nova agent... ${NORMAL_COL}"
#openstack compute service list | awk '/down/{print $2}'|xargs -i openstack compute service delete {}
SRV=$(openstack compute service list|awk -v ORS=" " '/down/{print $2}')
[ -z "$SRV" ] || openstack compute service delete $SRV
echo -e "${YELLOW_COL}Another function is not yet implemented ${NORMAL_COL}"
}
keystone_init(){
echo -e "${YELLOW_COL}Install KeyStone Identity v3${NORMAL_COL}"
for svc in keystone dashboard;do
svc="openstack-$svc"
echo -e "${YELLOW_COL}-> Installing $svc ... ${NORMAL_COL}"
dnf list installed | grep -iq $svc
[ $? != 0 ] && dnf install -y $svc
done
openssl rand -hex 10 > $KS_TOKEN_PRE$ADMIN_USER
mysql -uroot -p"$DBROOTPW" -e 'CREATE DATABASE IF NOT EXISTS keystone;'
mysql -uroot -p"$DBROOTPW" -e " \
GRANT ALL PRIVILEGES ON keystone.* TO 'keystone'@'localhost' IDENTIFIED BY '"$DBPASSWD"'; \
GRANT ALL PRIVILEGES ON keystone.* TO 'keystone'@'%' IDENTIFIED BY '"$DBPASSWD"'; "
cat > /etc/keystone/keystone.conf <<EOF
[DEFAULT]
[database]
connection = mysql+pymysql://keystone:$DBPASSWD@$DBVIP:$MY_PORT/keystone
[cache]
backend = oslo_cache.memcache_pool
enabled = true
memcache_servers = 127.0.0.1:11211
memcache_dead_retry = 30
memcache_socket_timeout = 30
memcache_pool_maxsize = 128
memcache_pool_unused_timeout = 180
memcache_pool_connection_get_timeout = 90
[token]
provider = fernet
EOF
if [ $(ls -al /var/lib/mysql/keystone/* | wc -l) -lt 10 ];then
su -s /bin/sh -c "keystone-manage db_sync" keystone
keystone-manage fernet_setup --keystone-user keystone --keystone-group keystone
keystone-manage credential_setup --keystone-user keystone --keystone-group keystone
keystone-manage bootstrap --bootstrap-service-name keystone --bootstrap-username admin --bootstrap-role-name admin \
--bootstrap-admin-url $KEYS_ADMIN_URL --bootstrap-internal-url $KEYS_AUTH_URL --bootstrap-public-url $KEYS_AUTH_URL \
--bootstrap-password $ADMIN_PASS --bootstrap-region-id $REGION --bootstrap-project-name $TENANT_NAME
fi
sed -r -i '/ServerName /d' /etc/httpd/conf/httpd.conf
sed -r -i "/^Listen/s@.*@Listen $MY_IP:8000@g" /etc/httpd/conf/httpd.conf
[ -s /etc/httpd/conf.d/ssl.conf ] && mv /etc/httpd/conf.d/ssl.conf /etc/httpd/conf.d/ssl.conf.old
echo "ServerName $CCVIP" >> /etc/httpd/conf/httpd.conf
> /var/www/html/index.html
sed -r -i '/WSGIApplicationGroup/d' /etc/httpd/conf.d/openstack-dashboard.conf
sed -r -i -e '/WSGISocketPrefix/a WSGIApplicationGroup %{GLOBAL}' -e 's@dashboard/wsgi>@dashboard>@g' \
-e '/^WSGIScriptAlias/s^.*^WSGIScriptAlias /dashboard /usr/share/openstack-dashboard/openstack_dashboard/wsgi.py^g' \
/etc/httpd/conf.d/openstack-dashboard.conf
sed -r -i "/^ALLOWED_HOSTS/s^.*^ALLOWED_HOSTS = ['*',]^g" /etc/openstack-dashboard/local_settings
sed -r -i "/^OPENSTACK_HOST/s^.*^OPENSTACK_HOST = \"$CCVIP\"^g" /etc/openstack-dashboard/local_settings
sed -r -i "/^TIME_ZONE/s^.*^TIME_ZONE = \"$ZONE\"^g" /etc/openstack-dashboard/local_settings
sed -r -i "/^OPENSTACK_KEYSTONE_URL/s^=.*^= \"$KEYS_AUTH_URL\"^g" /etc/openstack-dashboard/local_settings
sed -r -i -e '/WEBROOT/d' -e '/LOGIN_URL/d' -e '/LOGOUT_URL/d' -e '/LOGIN_REDIRECT_URL/d' \
-e '/OPENSTACK_KEYSTONE_DEFAULT_DOMAIN/d' -e '/^OPENSTACK_API_VERSIONS /d' \
-e '/^CACHES/d' -e '/OPENSTACK_KEYSTONE_MULTIDOMAIN_SUPPORT/d' \
/etc/openstack-dashboard/local_settings
cat >> /etc/openstack-dashboard/local_settings <<EOF
WEBROOT = '/dashboard/'
LOGIN_URL = '/dashboard/auth/login/'
LOGOUT_URL = '/dashboard/auth/logout/'
LOGIN_REDIRECT_URL = '/dashboard/'
OPENSTACK_KEYSTONE_MULTIDOMAIN_SUPPORT = True
OPENSTACK_KEYSTONE_DEFAULT_DOMAIN = 'Default'
OPENSTACK_API_VERSIONS = { "identity": 3, "volume": 3, "compute": 2, "image":2 }
CACHES = { 'default': { 'BACKEND': 'django.core.cache.backends.memcached.MemcachedCache', 'LOCATION': '$MEMCACHES', }, }
EOF
ln -snf /etc/openstack-dashboard /usr/share/openstack-dashboard/openstack_dashboard/conf
[ -L /etc/httpd/conf.d/wsgi-keystone.conf ] && rm -rf /etc/httpd/conf.d/wsgi-keystone.conf
cp -a /usr/share/keystone/wsgi-keystone.conf /etc/httpd/conf.d/wsgi-keystone.conf
sed -r -i "/Listen/s@(.*) (.*)@\1 $MY_IP:\2@g" /etc/httpd/conf.d/wsgi-keystone.conf
cp -a /etc/httpd/conf.d/wsgi-keystone.conf /etc/httpd/conf.d/wsgi-keystone-admin.conf
sed -r -i 's@5000@35357@g;s@-public@-admin@g' /etc/httpd/conf.d/wsgi-keystone-admin.conf
systemctl enable httpd && systemctl restart httpd
cat > $KS_RCONFIG$ADMIN_USER <<EOF
export OS_USER_DOMAIN_NAME=default
export OS_PROJECT_DOMAIN_NAME=default
export OS_PROJECT_NAME=$TENANT_NAME
export OS_USERNAME=$ADMIN_USER
export OS_PASSWORD=$ADMIN_PASS
export OS_AUTH_URL=$KEYS_AUTH_URL
export OS_IDENTITY_API_VERSION=3
export OS_IMAGE_API_VERSION=2
export OS_VOLUME_API_VERSION=3
EOF
sed -r -i '/OS_/d' ~/.bashrc
sed -r -i '/_TOKEN/d' ~/.bashrc
sed -r -i '/SERVICE_/d' ~/.bashrc
cat $KS_RCONFIG$ADMIN_USER >> ~/.bashrc
source $KS_RCONFIG$ADMIN_USER
$COMMAND keys_addproj $TENANT_NAME
}
keystone_add_proj(){
if [ $# -ne 2 ];then
echo "$SCRIPT keys_addproj project"
else
proj_name=$2
openstack project list | grep -wq "$proj_name"
if [ $? != 0 ] ;then
openstack project create --domain default --description "Service Project" $proj_name > $KS_TENANT_PRE$proj_name
tenant_id=$(awk -F'|' '/ id/{print $3}' $KS_TENANT_PRE$proj_name)
echo -e "${YELLOW_COL}Project added ID: $tenant_id ${NORMAL_COL}"
$COMMAND keys_addrole admin $proj_name admin
fi
# For all OpenStack releases after 2023-05-10, it is required that Nova be configured to send service token
openstack role show service | grep -iq service
[ $? = 0 ] || openstack role create service
fi
}
keystone_add_user(){
if [ $# -ne 4 ];then
echo "$SCRIPT keys_adduser user password project"
else
user_name=$2
user_pass=$3
proj_name=$4
openstack user list | grep -wq "$user_name"
[ $? = 0 ] || openstack user create --domain default --project $proj_name --password $user_pass $user_name > $KS_USER_PRE$user_name
user_id=$(awk -F'|' '/ id/{print $3}' $KS_USER_PRE$user_name)
echo -e "${YELLOW_COL}User ID: $user_id ${NORMAL_COL}"
fi
}
keystone_add_role(){
if [ $# -lt 3 ];then
echo "$SCRIPT keys_addrole user project role"
else
user_name=$2
proj_name=$3
role_name=$4
[ -z $role_name ] && role_name="admin"
# 使用admin角色将用户添加到服务项目中
openstack role add --project $proj_name --user $user_name service # send service token
openstack role add --project $proj_name --user $user_name $role_name > $KS_ROLE_PRE$user_name
fi
}
keystone_list(){
if [ $# -ne 2 ];then
echo "$SCRIPT keys_list user|role|tenant|service|endpoint"
else
type=$2
if [ $type = "all" ];then
for i in user role endpoint service;do
echo -e "${YELLOW_COL}******************** $i List ********************${NORMAL_COL}"
openstack $i list
echo
done
else
echo -e "${YELLOW_COL}******************** $type List *********************${NORMAL_COL}"
openstack "$type" list
fi
fi
}
keystone_add_service(){
if [ $# -ne 4 ];then
echo "$SCRIPT keys_addsrv service type desc"
else
service_name=$2
type=$3
desc=$4
openstack service list|grep -wq $service_name
[ $? = 0 ] || openstack service create --name $service_name --description "$desc" $type > $KS_SERV_PRE$service_name
serv_id=$(awk -F'|' '/ id/{print $3}' $KS_SERV_PRE$service_name)
echo -e "${YELLOW_COL}Service ID: $serv_id ${NORMAL_COL}"
fi
}
keystone_add_endpoint(){
if [ $# -ne 3 ];then
echo "$SCRIPT keys_addept service url project"
else
service_name=$2
url=$3
proj_name=$4
openstack endpoint list | grep -wq "$service_name"
if [ $? != 0 ];then
openstack endpoint create --region $REGION $service_name public $url
openstack endpoint create --region $REGION $service_name internal $url
openstack endpoint create --region $REGION $service_name admin $url
fi
fi
}
glance_init(){
echo -e "${YELLOW_COL}Install Glance Images API v2${NORMAL_COL}"
for srv in qemu-img openstack-glance;do
dnf list installed | grep -iq $srv
[ $? != 0 ] && dnf install -y $srv
done
mysql -uroot -p"$DBROOTPW" -e 'CREATE DATABASE IF NOT EXISTS glance;'
mysql -uroot -p"$DBROOTPW" -e " \
GRANT ALL PRIVILEGES ON glance.* TO 'glance'@'localhost' IDENTIFIED BY '"$DBPASSWD"'; \
GRANT ALL PRIVILEGES ON glance.* TO 'glance'@'%' IDENTIFIED BY '"$DBPASSWD"'; "
cat > /etc/glance/glance-api.conf <<EOF
[DEFAULT]
debug = $DEBUG
bind_host = $MY_IP
transport_url = rabbit://guest:$DBPASSWD@$CCVIP:5672/
log_dir = /var/log/glance
[database]
connection = mysql+pymysql://glance:$DBPASSWD@$DBVIP:$MY_PORT/glance
[keystone_authtoken]
www_authenticate_uri = $KEYS_AUTH_URL
auth_url = $KEYS_ADMIN_URL
memcached_servers = $MEMCACHES
auth_type = password
project_domain_name = default
user_domain_name = default
project_name = service
username = glance
password = $ADMIN_PASS
[paste_deploy]
flavor = keystone
EOF
if [ $STORE_BACKEND = "ceph" ];then
cat >> /etc/glance/glance-api.conf <<EOF
[glance_store]
stores = rbd
default_store = rbd
rbd_store_pool = images
rbd_store_user = glance
show_image_direct_url = True
rbd_store_ceph_conf = /etc/ceph/ceph.conf
rbd_store_chunk_size = 8
EOF
else
cat >> /etc/glance/glance-api.conf <<EOF
[glance_store]
stores = file,http
default_store = file
filesystem_store_datadir = /var/lib/glance/images/
EOF
fi
if [ $(ls -al /var/lib/mysql/glance/* | wc -l) -lt 10 ];then
su -s /bin/sh -c "glance-manage db sync" glance
$COMMAND keys_adduser glance $ADMIN_PASS $TENANT_NAME
$COMMAND keys_addrole glance $TENANT_NAME
$COMMAND keys_addsrv glance image 'OpenStack Image Service'
$COMMAND keys_addept image $IMAGE_URL
fi
for svc in api ;do
systemctl enable --now openstack-glance-$svc
done
}
glance_add_image(){
if [ $# -ne 3 ];then
echo "$SCRIPT gls_add image_desc image_filename"
else
desc="$2"
filename=$3
FORMAT="--container-format bare --disk-format raw"
file $filename | grep -q -i 'iso'
[ $? = 0 ] && FORMAT="--container-format ovf --disk-format iso"
file $filename | grep -q -i 'qcow'
if [ $? = 0 ] ;then
FORMAT="--container-format ovf --disk-format qcow2"
# if [ $STORE_BACKEND = "ceph" ];then
# echo -e "${YELLOW_COL}Convert image from qcow -> raw with ceph support ${NORMAL_COL}"
# qemu-img convert -f qcow2 -O raw $filename ${filename}.raw
# FORMAT="--container-format bare --disk-format raw"
# filename=${filename}.raw
# fi
fi
openstack image create "$desc" --public $FORMAT --file $filename \
--property hw_disk_bus=scsi \
--property hw_qemu_guest_agent=yes \
--property hw_scsi_model=virtio-scsi \
--property os_require_quiesce=yes
fi
}
glance_list_image(){
openstack image list -f table --fit-width
}
glance_show_image(){
if [ $# -ne 2 ];then
echo "$SCRIPT gls_show image_id"
else
openstack image show "$2" -f table --fit-width --human-readable
fi
}
placement_init(){
if [ ${NODE_TYPE,,} != "compute" ];then
echo -e "${YELLOW_COL}Install PLACEMENT Component ${NORMAL_COL}"
dnf list installed | grep -iq openstack-placement-api
[ $? != 0 ] && dnf install -y openstack-placement-api
mysql -uroot -p"$DBROOTPW" -e 'CREATE DATABASE IF NOT EXISTS placement;'
mysql -uroot -p"$DBROOTPW" -e " \
GRANT ALL PRIVILEGES ON placement.* TO 'placement'@'localhost' IDENTIFIED BY '"$DBPASSWD"'; \
GRANT ALL PRIVILEGES ON placement.* TO 'placement'@'%' IDENTIFIED BY '"$DBPASSWD"'; "
cat > /etc/placement/placement.conf <<EOF
[placement_database]
connection = mysql+pymysql://placement:$DBPASSWD@$DBVIP:$MY_PORT/placement
[api]
auth_strategy = keystone
[keystone_authtoken]
auth_url = $KEYS_ADMIN_URL
memcached_servers = $MEMCACHES
auth_type = password
project_domain_name = default
user_domain_name = default
project_name = service
username = placement
password = $ADMIN_PASS
EOF
if [ $(ls -al /var/lib/mysql/placement/* | wc -l) -lt 10 ];then
su -s /bin/sh -c "placement-manage db sync" placement
$COMMAND keys_adduser placement $ADMIN_PASS $TENANT_NAME
$COMMAND keys_addrole placement $TENANT_NAME
$COMMAND keys_addsrv placement placement 'OpenStack Placement API'
$COMMAND keys_addept placement $PLACEMENT_URL
fi
echo -e "${YELLOW_COL}placement need a patch!!! ${NORMAL_COL}"
sed -r -i '/<Directory/, /Directory>/d' /etc/httpd/conf.d/00-placement-api.conf
cat > .patch <<EOF
<Directory /usr/bin>
<IfVersion >= 2.4>
Require all granted
</IfVersion>
<IfVersion < 2.4>
Order allow,deny
Allow from all
</IfVersion>
</Directory>
EOF
sed -r -i '/ErrorLog /r .patch' /etc/httpd/conf.d/00-placement-api.conf
sed -r -i "/Listen/s@.*@Listen $MY_IP:8778@g" /etc/httpd/conf.d/00-placement-api.conf
systemctl restart httpd
pip3 install osc-placement
echo -e "${YELLOW_COL}pip3 install osc-placement ${NORMAL_COL}"
echo -e "${YELLOW_COL}openstack --os-placement-api-version 1.6 trait list --sort-column name ${NORMAL_COL}"
fi
}
nova_init(){
placement_init
echo -e "${YELLOW_COL}Install *NOVA* Computer v2${NORMAL_COL}"
for svc in api metadata-api conductor novncproxy scheduler compute;do
svc="openstack-nova-$svc"
echo -e "${YELLOW_COL}-> Installing $svc ... ${NORMAL_COL}"
dnf list installed | grep -iq $svc
[ $? != 0 ] && dnf install -y $svc
done
# 如果有额外挂载的大硬盘,则把nova的实例目录迁移到新目录下
df -h|grep -wq /disk/$LVM_VOLUME
if [ $? = 0 ];then
if [ ! -L /var/lib/nova ];then
if [ ! -d /disk/$LVM_VOLUME/nova ] ;then
mv /var/lib/nova /disk/$LVM_VOLUME/
ln -snf /disk/$LVM_VOLUME/nova /var/lib/
fi
fi
chmod 1777 /disk/$LVM_VOLUME
fi
cat > /etc/nova/nova.conf <<EOF
[DEFAULT]
debug = $DEBUG
my_ip = $MY_IP
region_name = $REGION
initial_cpu_allocation_ratio = $CPU_RATIO
initial_ram_allocation_ratio = $MEM_RATIO
initial_disk_allocation_ratio = 1.0
#reserved_host_memory_mb = 10240
resume_guests_state_on_host_boot = true
metadata_host = \$my_ip
metadata_listen = \$my_ip
metadata_listen_port = 8775
osapi_compute_listen = \$my_ip
osapi_compute_listen_port = 8774
osapi_compute_workers = $((CPU_NUMS/4))
metadata_workers = $((CPU_NUMS/4))
# 允许在同一台机器上扩容
allow_resize_to_same_host = true
log-dir = /var/log/nova
state_path = /var/lib/nova
use_neutron = true
enabled_apis = osapi_compute
compute_driver = libvirt.LibvirtDriver
firewall_driver = nova.virt.firewall.NoopFirewallDriver
transport_url = rabbit://guest:$DBPASSWD@$CCVIP:5672/
[cache]
enabled = true
backend = oslo_cache.memcache_pool
memcache_servers = $CCVIP:11211
[conductor]
workers = $((CPU_NUMS/4))
[scheduler]
workers = $((CPU_NUMS/4))
[api_database]
connection = mysql+pymysql://nova:$DBPASSWD@$DBVIP:$MY_PORT/nova_api
[database]
connection = mysql+pymysql://nova:$DBPASSWD@$DBVIP:$MY_PORT/nova
[api]
auth_strategy = keystone
[service_user]
send_service_user_token = True
project_name = service
user_domain_name = default
project_domain_name = default
auth_type = password
username = nova
password = $ADMIN_PASS
auth_url = $KEYS_ADMIN_URL
[keystone_authtoken]
service_token_roles_required = True
service_token_roles = service
project_name = service
user_domain_name = default
project_domain_name = default
auth_type = password
username = nova
password = $ADMIN_PASS
memcached_servers = $MEMCACHES
auth_url = $KEYS_ADMIN_URL
www_authenticate_uri = $KEYS_AUTH_URL
[vnc]
enabled = true
server_listen = \$my_ip
server_proxyclient_address = \$my_ip
novncproxy_host = \$my_ip
novncproxy_port = 6080
# internet loadbalance ip
novncproxy_base_url = http://\$my_ip:6081/vnc_auto.html
[glance]
api_servers = ${IMAGE_URL%v2}
[oslo_concurrency]
lock_path = /var/lib/nova/tmp
[placement]
region_name = $REGION
project_domain_name = default
project_name = service
auth_type = password
user_domain_name = default
auth_url = $KEYS_ADMIN_URL
username = placement
password = $ADMIN_PASS
[filter_scheduler]
enabled_filters = AggregateInstanceExtraSpecsFilter, AvailabilityZoneFilter, ComputeFilter, ComputeCapabilitiesFilter, ImagePropertiesFilter, ServerGroupAntiAffinityFilter, ServerGroupAffinityFilter, PciPassthroughFilter
available_filters = nova.scheduler.filters.all_filters
[libvirt]
virt_type = $VIRT_TYPE
cpu_mode = host-passthrough
EOF
if [ $STORE_BACKEND = "ceph" ];then
dnf install -y python3-rbd ceph-common
cat >> /etc/nova/nova.conf <<EOF
#images_type = rbd
#images_rbd_pool = vms
#images_rbd_ceph_conf = /etc/ceph/ceph.conf
rbd_user = cinder
rbd_secret_uuid = $MY_UUID