Red Hatã®ç¦å²¡ãªãã£ã¹ã§ã½ãªã¥ã¼ã·ã§ã³ã¢ã¼ããã¯ãããã¦ããç°ä¸å¸æ©ã§ããOpenShift 4.1ãUPIã§ãã¢ã¡ã¿ã«ç°å¢ã«ã¤ã³ã¹ãã¼ã«ããæ¹æ³ã«ã¤ãã¦è§£èª¬ãã¾ããåºæ¬çã«ã¯ã¤ã³ã¹ãã¼ã«ããã¥ã¡ã³ãã®è¦ç´ã«ãªãã¾ãããåãã¦OpenShiftã«è§¦ããæ¹ã«ãåãããããããã«é ã追ã£ã¦èª¬æãã¦ããã¾ãã*1
ãªããAWSã¸ã®UPIã¤ã³ã¹ãã¼ã«ã«ã¤ãã¦ã¯ãåã®è¨äºã§æãããæ¸ããã¦ãã¾ãã®ã§ãã¡ããåèã«ãã¦ãã ããã
2019/10/30追è¨ã OpenShift 4.2ãGAã«ãªãã¾ããã®ã§ã4.1ããã®å¤æ´ç¹ã«ã¤ãã¦ä¸è¨ã®è¨äºã«ã¾ã¨ãã¾ããã
æ¬è¨äºã®ç« ç«ã¦ã¯ãã®ããã«ãªãã¾ãã
- UPIã¤ã³ã¹ãã¼ã«ã®æ¦è¦
- UPIã¤ã³ã¹ãã¼ã«ã®äºåæºå
- UPIã¤ã³ã¹ãã¼ã«ã®å®æ½æé
- åèï¼è¸ã¿å°ãµã¼ãã¼ã®æ§ç¯
ã´ã¼ã«ã¯ãæä½æ¥ã§ãã¢ã¡ã¿ã«ç°å¢ã«OpenShift 4.1ãã¤ã³ã¹ãã¼ã«ãæé ã«ã¤ãã¦ç解ãããã§ãã
UPIã¤ã³ã¹ãã¼ã«ã®æ¦è¦
ã¾ããOpenShift 4.1ã®UPIã¤ã³ã¹ãã¼ã«ã®æ¦è¦ãã説æãã¦ããã¾ãã
ããã¥ã¡ã³ã
ã¤ã³ã¹ãã¼ã«æ¹æ³ã«ã¤ãã¦è¨è¼ãããããã¥ã¡ã³ãã¯æ¥æ¬èªãè±èªã©ã¡ããããã¾ããæ¬è¨äºã§ã¯ä¸è¨ã®æ¥æ¬èªããã¥ã¡ã³ãã対象ã¨ãã¾ãã*2
第3章 ベアメタルへのインストール OpenShift Container Platform 4.1 | Red Hat Customer Portal
IPI/UPIã«ã¤ãã¦
OpenShift 4ã®ã¤ã³ã¹ãã¼ã«æ¹æ³ã¯IPIã¨UPIã®2種é¡ãããã¾ããIPIã¯ãInstaller Provisioned Infrastructureãã®ç¥ã§ãèªåã§ã¤ã³ãã©ç°å¢ãä½æãã¦ã¤ã³ã¹ãã¼ã«ãè¡ãæ¹æ³ã§ãã
ããã«å¯¾ãUPIã¯ãUser Provisioned Infrastructureãã®ç¥ã§ãã¦ã¼ã¶ã¼ãã¤ã³ãã©ç°å¢ãäºåã«ç¨æãã¦ã¤ã³ã¹ãã¼ã«ãè¡ãæ¹æ³ã§ããã¦ã¼ã¶ã¼ãç°å¢ãæºåããæéã¯ããã¾ãããèªç±ã«ç¨æããç°å¢ã«ã¤ã³ã¹ãã¼ã«ãè¡ããã¨ãã§ãã¾ããç¾æç¹ã§UPIã§å¯¾å¿ãã¦ããã¤ã³ã¹ãã¼ã«ç°å¢ã¯ä¸è¨ã®éãã§ãã*3*4
- AWS
- VMware vSphere
- ãã¢ã¡ã¿ã«
UPIã¤ã³ã¹ãã¼ã«æ§æ
UPIã§ã¯ã¦ã¼ã¶ã¼ãèªç±ã«ç°å¢ãç¨æã§ããåé¢ãå¿ è¦ãªè¦ä»¶ãæºããã¤ã³ãã©ã®ç¥èãç¡ãã¨ãã©ã®ããã«ã¤ã³ãã©ç°å¢ãæ§æããã°ãããæ©ããã¨ã¨æãã¾ãã ããã§ãæ¬è¨äºã§ã¯ä¸è¨ã®æ¤è¨¼ç°å¢ããµã³ãã«ã¨ãã¦èª¬æãé²ãã¦ããã¾ãã*5
UPIã¤ã³ã¹ãã¼ã«ã®äºåæºå
次ã«ãæ§æã«å¿ è¦ãªãã®ã«ã¤ãã¦èª¬æãã¦ããã¾ããUPIã¤ã³ã¹ãã¼ã«ã«ããã¦ããããä¸çªæéã®ããããã¤ã³ãã«ãªãã¾ãã ãã®äºåæºåããã£ã¡ãã¨åºæ¥ã¦ããã°ãã¤ã³ã¹ãã¼ã«ä½æ¥èªä½ã¯ããã»ã©æéã¯ãããã¾ããã*6
ãã¼ãã®æºå
UPIã¤ã³ã¹ãã¼ã«ã§å¿ è¦ãªãã¼ãã®æ å ±ã¯ä¸è¨ã®éãã§ãã
ãã·ã³ | å°æ° | OS | vCPU | RAM | ã¹ãã¬ã¼ã¸ | åè |
---|---|---|---|---|---|---|
Bootstrap Node | 1 | RHCOS | 4 | 16GB | 120GB | UPIã¤ã³ã¹ãã¼ã«æã®ã¿å¿ è¦ |
Master Node | 3 | RHCOS | 4 | 16GB | 120GB | 3å°å¿ é |
Worker Node | 2 | RHCOS | 2 | 8GB | 120GB | 2å°ä»¥ä¸ |
- ã¤ã³ã¹ãã¼ã«ããæ¤è¨¼ç®çã ãã§ããã°ãBootstrap Nodeã®RAM容éã¯ããå°ãä¸ãã¦ã大ä¸å¤«ã§ã
- OSã¯å ¨ã¦ãRHEL CoreOSï¼RHCOSï¼ãã使ç¨ãã¾ã*7
ã¤ã³ã¹ãã¼ã©ã¼ãã¤ã¡ã¼ã¸ã®å ¥æ
ãã®è¨äºã®æ¤è¨¼ç°å¢ã§ã¯RHCOSã¯ISOèµ·åãBIOSãã·ã³ã使ç¨ãã¾ãã å®éã«å¿ è¦ãªãã¡ã¤ã«ã®ä¾ã¯ä¸è¨ã®ããã«ãªãã¾ãã
åå | ã¤ã³ã¹ãã¼ã«oré ç½®å | å®éã®ãã¡ã¤ã«å(åè: v4.1.3) | åè |
---|---|---|---|
oc client | è¸ã¿å°ãµã¼ãã¼*8 | openshift-client-linux-4.1.3.tar.gz | linux,mac,windowsçæã |
openshift-install | è¸ã¿å°ãµã¼ãã¼*9 | openshift-install-linux-4.1.3.tar.gz | linux,macçæã |
RHCOS ISOã¤ã¡ã¼ã¸ | Bootstrap,Master,Worker Node | rhcos-4.1.0-x86_64-installer.iso | OpenShiftã®ãªãªã¼ã¹ãã¼ã¸ã§ã³ã¨ å¿ ãããä¸è´ãããã®ã§ã¯ããã¾ããã*10 |
BIOSãã¡ã¤ã« | è¸ã¿å°ãµã¼ãã¼ï¼Webå ¬éãã£ã¬ã¯ããªï¼ | rhcos-4.1.0-x86_64-metal-bios.raw.gz | BIOS,UEFIçæã ãã¼ã¸ã§ã³ã«ã¤ãã¦ã¯RHCOSã¨åæ§ |
- oc client,openshift-installã¯ãå±éãã¦READMEãåèã«ãã¤ããªãã¡ã¤ã«ãé ç½®ãã¦ãã ãã
- RHCOS ISOã¤ã¡ã¼ã¸ã¯ãç¨æãããã¢ã¡ã¿ã«ã®ãã¼ãã«åããã¦ãã¡ãã£ã¢ãISOèµ·åãã§ããããã«ãã¦ãã ãã
- BIOSãã¡ã¤ã«ã¯ããã®å¾ã®Web Serverã®é ç®ãåèã«ãã¦ãã¡ã¤ã«ãé ç½®ãã¦ãã ãã
â»â»â» 製åã®ãã¦ã³ãã¼ãã«ã¤ãã¦ã¯ã試ç¨ãè©ä¾¡ã«é¢ãã解説è¨äºãã§ãã¾ããã®ã§ãã¡ããåç §ãã ãããâ»â»â»
ãããã¯ã¼ã¯è¦ä»¶
UPIã¤ã³ã¹ãã¼ã«ã«å¿
è¦ãªãããã¯ã¼ã¯ã®è¦ä»¶ã«ã¤ãã¦èª¬æãã¾ãã
対å¿ããããã¥ã¡ã³ãã¯ã3.1.4. ã¦ã¼ã¶ã¼ã«ãã£ã¦ãããã¸ã§ãã³ã°ãããã¤ã³ãã©ã¹ãã©ã¯ãã£ã¼ã®ä½æ
ã§ãã
1. åºæ¬è¦ä»¶
æ¤è¨¼ç°å¢ã«ãããæ¤è¨¼ç¨ãããã¯ã¼ã¯
å
ã§ã¯ãåãã¼ãã®å
¨ã¦ã®éä¿¡ãéãæ§æã¨ãªãã¾ãã*11
ã¾ããæ¤è¨¼ç¨ãããã¯ã¼ã¯
ããã¤ã³ã¿ã¼ãããã¸ã¯èªç±ã«éä¿¡ãã§ããæ§æã§ãã*12
2. ãããã¯ã¼ã¯è¨è¨
æ¤è¨¼ç¨ãããã¯ã¼ã¯
ãè¨ããå ´åã¯ãOpenShiftã®å
é¨ã§ä½¿ç¨ãããããã¯ã¼ã¯ã¢ãã¬ã¹ã¨è¢«ããªãããã«ããå¿
è¦ãããã¾ãã
ããã¥ã¡ã³ãã§ã¯ä¸è¨ã®ã¢ãã¬ã¹ãä¾ã¨ãã¦è¼ã£ã¦ãã¾ãã
- 10.128.0.0/14 ï¼
ã¯ã©ã¹ã¿ã¼ãããã¯ã¼ã¯
ï¼Pod IP ã®å²ãå½ã¦ã«ä½¿ç¨ããã IP ã¢ãã¬ã¹ã®ãããã¯ï¼ - 172.30.0.0/16ï¼
ãµã¼ãã¹ãããã¯ã¼ã¯
ï¼ãµã¼ãã¹ IP ã¢ãã¬ã¹ã«ä½¿ç¨ãã IP ã¢ãã¬ã¹ãã¼ã«ï¼
æ¤è¨¼ç°å¢ã§ãä¸è¨ããã®ã¾ã¾ä½¿ç¨ãã¾ããæ¤è¨¼ç°å¢ã®ãããã¯ã¼ã¯è¨è¨ã¯ä¸è¨ã®ããã«ãªãã¾ãã
- 192.168.1.0/24ï¼
社å ãããã¯ã¼ã¯
- 172.16.0.0/24ï¼
æ¤è¨¼ç¨ãããã¯ã¼ã¯
3. DHCP
RHCOSãã·ã³ã¯ååèµ·åæã«DHCPã«ããIPã¢ãã¬ã¹ã®å²ãå½ã¦ãå¿ è¦ã§ãã æ¤è¨¼ç°å¢ã§ã¯ãMACã¢ãã¬ã¹ãæå®ãã¦åºå®ã§ãã¹ãåãIPã¢ãã¬ã¹ãå²ãå½ã¦ãæ¹æ³ãè¡ãã¾ãã
æ¤è¨¼ç°å¢ã®DHCPã®è¨å®ä¾ã¯ä¸è¨ã®ããã«ãªãã¾ãã
ãã·ã³ | ãã¹ãå | IPã¢ãã¬ã¹ | ãµãããããã¹ã¯ | ã²ã¼ãã¦ã§ã¤ | DNSãµã¼ãã¼ |
---|---|---|---|---|---|
Bootstrap Node | bootstrap.test.example.local | 172.16.0.100 | 255.255.255.0 | 172.16.0.1 | 172.16.0.1 |
Master Node | master-0.test.example.local master-1.test.example.local master-2.test.example.local |
172.16.0.101 172.16.0.102 172.16.0.103 |
255.255.255.0 | 172.16.0.1 | 172.16.0.1 |
Worker Node | worker-0.test.example.local worker-1.test.example.local |
172.16.0.104 172.16.0.105 |
255.255.255.0 | 172.16.0.1 | 172.16.0.1 |
4. DNS
ä¸è¨ã®æå®ãããã¬ã³ã¼ãã®åå解決ãå¿ é ã§ãã
ã³ã³ãã¼ãã³ã | ã¬ã³ã¼ã | 対象ãã¼ã |
---|---|---|
Kubernetes API | api.<cluster_name>.<base_domain> api-int.<cluster_name>.<base_domain> |
Bootstrap,Master |
Routes | *.apps.<cluster_name>.<base_domain> |
Worker |
etcd | etcd-<index>.<cluster_name>.<base_domain> _etcd-server-ssl._tcp.<cluster_name>.<base_domain> |
Master |
æ¤è¨¼ç°å¢ã§ç»é²ããDNSã®è¨å®ä¾ã¯ä¸è¨ã®ããã«ãªãã¾ãã
ãã¹ãå | IPã¢ãã¬ã¹ | åè |
---|---|---|
api.test.example.local |
192.168.1.21 | LBã®å¤å´ã¢ãã¬ã¹ãæå® |
api-int.test.example.local |
172.16.0.1 | LBã®å å´ã¢ãã¬ã¹ãæå® |
*.apps.test.example.local |
172.16.0.1 | LBã®å å´ã¢ãã¬ã¹ãæå®ãã¯ã¤ã«ãã«ã¼ãDNSã¬ã³ã¼ãã |
etcd-0.test.example.local |
172.16.0.101 | ã·ã¹ãã å
é¨ã§etcd-0,1,2ã§åºå®åã§åå解決ãè¡ãã®ã§ã Master Nodeã®ãã¹ãåã¨ã¯å¥ã§ç»é²å¿ è¦ |
etcd-1.test.example.local |
172.16.0.102 | åä¸ |
etcd-2.test.example.local |
172.16.0.103 | åä¸ |
ã¬ã³ã¼ã | åªå 度 | éã¿ | ãã¼ã | DNSå |
---|---|---|---|---|
_etcd-server-ssl._tcp.test.example.local |
0 | 10 | 2380 | etcd-0.test.example.local |
_etcd-server-ssl._tcp.test.example.local |
0 | 10 | 2380 | etcd-1.test.example.local |
_etcd-server-ssl._tcp.test.example.local |
0 | 10 | 2380 | etcd-2.test.example.local |
5. Load Balancer
ä¸è¨ã®ãã¼ãçªå·ã®ãã¼ããã©ã³ãµã¼ãå¿ è¦ã§ã
ç¨é | ãã¼ãçªå· | 対象ãã¼ã |
---|---|---|
Kubernetes APIServer | 6443 | Bootstrap,Master |
ãã·ã³è¨å®ãµã¼ãã¼ | 22623 | Bootstrap,Master |
ingressã«ã¼ã¿ã¼ã®httpã¢ã¯ã»ã¹ç¨ | 80 | Worker |
ingressã«ã¼ã¿ã¼ã®httpsã¢ã¯ã»ã¹ç¨ | 443 | Worker |
æ¤è¨¼ç°å¢ã§ç»é²ããLoad Balancerã®è¨å®ã¯ä¸è¨ã®ããã«ãªãã¾ã
ãã¼ãçªå· | SSL | ããã¯ã¨ã³ã |
---|---|---|
6443 | Yes | bootstrap.test.example.local master-0.test.example.local master-1.test.example.local master-2.test.example.local |
22623 | Yes | bootstrap.test.example.local master-0.test.example.local master-1.test.example.local master-2.test.example.local |
80 | - | worker-0.test.example.local worker-1.test.example.local |
443 | Yes | worker-0.test.example.local worker-1.test.example.local |
- ãã¼ãã¹ãã©ããããã»ã¹çµäºå¾ã¯Bootstrap Nodeã®è¨å®ã¯ä¸è¦ã§ãã®ã§ãLoad Balancerã®ç»é²ããåé¤ã§ãã¾ã
6. Web Server
ããã¥ã¡ã³ãã«ã¯è©³ç´°ãªè¨è¼ã¯ããã¾ããããã¤ã³ã¹ãã¼ã«ä½æ¥ã«å¿
è¦ãªãã¡ã¤ã«ãHTTPãµã¼ãã¼ã«é
ç½®ããå¿
è¦ãããã¾ãã
æ¤è¨¼ç°å¢ã§ã¯ãnginx
ã§Web Serverã稼åããWebå
¬éãã£ã¬ã¯ããªã«å¿
è¦ãªãã¡ã¤ã«ã®é
ç½®ãè¡ãã¾ãã
ãªããnginx
ã®ãã¼ãçªå·ã¯Load Balancerã®è¨å®ã¨è¢«ããªãããã«ãæ¤è¨¼ç°å¢ã§ã¯TCP 80
â8008
ã¸å¤æ´ãã¦ãã¾ãã*13
æ¤è¨¼ç°å¢ã§ä½¿ç¨ããWebå ¬éãã£ã¬ã¯ããªã®ãµã³ãã«ã¯ä¸è¨ã®ããã«ãªãã¾ãã
/usr/share/nginx/html/ âââ ocp   âââ rhcos   âââ ignitions   â  âââ bootstrap.ign   â  âââ master.ign   â  âââ worker.ign   âââ images   âââ latest   â  âââ bios.raw.gz -> ../release/410/rhcos-4.1.0-x86_64-metal-bios.raw.gz   âââ release   âââ 410   âââ rhcos-4.1.0-x86_64-metal-bios.raw.gz
- ignitions以ä¸ã®*.ign ãã¡ã¤ã«ã¯ããã®å¾ã®ã¤ã³ã¹ãã¼ã«ä½æ¥ã§ä½æãããã®ãé ç½®ãã¾ã
- CoreOS Imageã®å ã®ãã¡ã¤ã«åã¯é·ãã®ã§ããªã³ã¯ã§ç縮åã«ãã¦ãã¾ãããªãã¼ã ãã¦é ç½®ãã¦ãåé¡ããã¾ããã*14
è¸ã¿å°ãµã¼ãã¼
æ¤è¨¼ç°å¢ã§ã¯ãRHEL8ã®ãµã¼ãã¼ã1å°ç¨æãã¦ãããã¯ã¼ã¯è¦ä»¶ã§å¿ è¦ãªãµã¼ãã¹ãå ¨ã¦ããã§ç¨¼åãã¦ãã¾ãã è¸ã¿å°ãµã¼ãã¼ã¨ãã¦åããã¹ããå¿ è¦ãªè¦ä»¶ã¯ä¸è¨ã®éãã§ãã
- 2ã¤ã®ãããã¯ã¼ã¯ã«ã¼ãï¼
社å ãããã¯ã¼ã¯
ãæ¤è¨¼ç¨ãããã¯ã¼ã¯
ã«æ¥ç¶ï¼ - 社å ãããã¯ã¼ã¯ããã¤ã³ã¿ã¼ãããã¸ã¢ã¯ã»ã¹ãå¯è½ãªåºå®IPãä¸ã¤
- ãããã¯ã¼ã¯è¦ä»¶ã§ä¸ãããµã¼ãã¹ã稼åã§ãããªã½ã¼ã¹ãæã¤ãã·ã³
詳細ãªè¨å®å 容ã«ã¤ãã¦ã¯ãè¨äºã®æå¾ã®ãåèï¼è¸ã¿å°ãµã¼ãã¼ã®æ§ç¯ããåèã«ãã¦ãã ããã
æä½ç«¯æ«
社å
ãããã¯ã¼ã¯
ããè¸ã¿å°ãµã¼ãã¼ãçµç±ãã¦ãæ¤è¨¼ç¨ãããã¯ã¼ã¯
ã«ã¢ã¯ã»ã¹ããããã«ä½¿ç¨ãã¾ãã
社å
ãããã¯ã¼ã¯
ã®ã«ã¼ã¿ã¼ãªã©ã«æ¤è¨¼ç¨ãããã¯ã¼ã¯
ã¸ã®ã«ã¼ãã£ã³ã°ã®è¿½å ãé£ããå ´åã¯ãæä½ç«¯æ«ã«éçã«ã¼ãã追å ãã¦å¯¾å¿ãã¦ãã ããã
- SSH Clientï¼è¸ã¿å°ãµã¼ãã¼ã«ãã°ã¤ã³ãã¦openshift-installã³ãã³ãã®å®è¡ãä»ãè¸ã¿å°ãµã¼ãã¼ããåãã¼ãã«SSHæ¥ç¶ãã¦ãããã°æä½ããã°ç¢ºèªãªã©ã*15
- Webãã©ã¦ã¶ ï¼æ°è¦ã¯ã©ã¹ã¿ä½æå¾ãWeb Consoleã¸ã®æ¥ç¶ç¨ã
SSHãã¼ãã¢ã®æºå
ãã®ä½æ¥ã§ã¯ãåãã¼ãã«å¯¾ãã¦SSHå
¬ééµèªè¨¼ã§ã¢ã¯ã»ã¹ããããã«å¿
è¦ãªSSHãã¼ãã¢ã®ä½æãè¡ãã¾ãã
対å¿ããããã¥ã¡ã³ãã¯ã3.1.5. SSH ãã©ã¤ãã¼ããã¼ã®çæããã³ã¨ã¼ã¸ã§ã³ãã¸ã®è¿½å
ã§ãã
æå®ããSSHå
¬ééµããåãã¼ãï¼Bootstrap,Master,Workerï¼ã®core
ã¦ã¼ã¶ã¼ã® ~/.ssh/authorized_keys
ã«è¿½å ããã¾ãã*16
ããã¥ã¡ã³ãã§ã¯ä¸è¨ã®ã³ãã³ããä¾ã¨ãã¦è¼ã£ã¦ãã¾ãã
$ ssh-keygen -t rsa -b 4096 -N '' -f ~/.ssh/new_rsa
- ããã¥ã¡ã³ãã§ã¯ãã¼ã®çæå¾ã«ssh-agentã®èµ·åã®æé ãããã¾ãããUPIã¤ã³ã¹ãã¼ã«ãããç®çã«ããã¦ã¯å¿ é ã§ã¯ããã¾ããã®ã§ãé£ã°ãã¦ã大ä¸å¤«ã§ãã*17
UPIã¤ã³ã¹ãã¼ã«ã®å®æ½æé
ãããããå®éã®ã¤ã³ã¹ãã¼ã«ä½æ¥ã«ã¤ãã¦èª¬æãã¦ããã¾ãã
ã¤ã³ã¹ãã¼ã«ã®ã¹ããã
ã¤ã³ã¹ãã¼ã«ã®é²è¡ã¯ä¸è¨ã®é ã§è¡ãã¾ããã¾ããåé ç®ã¯ããã¥ã¡ã³ãã®3.1.8ã3.1.15ã«å¯¾å¿ãã¾ãã åé ç®ã®ä½æ¥å 容ã¯åºæ¬çã«ããã¥ã¡ã³ãéãã¨ãªãã¾ãã®ã§ã詳細ã¯ããã¥ã¡ã³ãã®è©²å½ç®æãåç §ãã ããã
1. æºå
é ç® | 対å¿ããã¥ã¡ã³ãç« | |
---|---|---|
1.a | ã¤ã³ã¹ãã¼ã«è¨å®ãã¡ã¤ã«ã®æåä½æ | 3.1.8 |
1.b | Ignition è¨å®ãã¡ã¤ã«ã®ä½æ | 3.1.9 |
1.c | Red Hat Enterprise Linux CoreOS (RHCOS) ãã·ã³ã®ä½æ | 3.1.10 |
â» 1.bã§ä½æããIgnition è¨å®ãã¡ã¤ã«ã«ã¯ã24 æéå¾ã«æéãåãã証ææ¸ãå«ã¾ãã¾ããä¸ãä¸24æéãè¶ ãã¦ã¤ã³ã¹ãã¼ã«ãå®è¡ããå ´åã¯ãå度1.bããè¡ã£ã¦ãã ããã
2. ã¤ã³ã¹ãã¼ã«ä½æ¥
é ç® | Bootstrap Node | 対å¿ããã¥ã¡ã³ãç« | |
---|---|---|---|
2.a | ã¯ã©ã¹ã¿ã¼ã®ä½æ | å¿ è¦ | 3.1.11 |
2.b | ã¯ã©ã¹ã¿ã¼ã¸ã®ãã°ã¤ã³ | ä¸è¦ | 3.1.12 |
2.c | ãã·ã³ã® CSR ã®æ¿èª | ä¸è¦ | 3.1.13 |
2.d | Operator ã®åæè¨å® | ä¸è¦ | 3.1.14 |
2.e | UPIã®ã¤ã³ã¹ãã¼ã«ã®å®äº | ä¸è¦ | 3.1.15 |
1.a ã¤ã³ã¹ãã¼ã«è¨å®ãã¡ã¤ã«ã®æåä½æ
ãã®ä½æ¥ã¯è¸ã¿å°ãµã¼ãã¼ã§è¡ãã¾ãã
ããã§ã®ä½æ¥ã®ç®æ¨ã¯ãã¤ã³ã¹ãã¼ã«ãã£ã¬ã¯ããªã®ä½æã¨ãã¤ã³ã¹ãã¼ã«è¨å®ãã¡ã¤ã«install-config.yaml
ãä½æãããã¨ã§ãã注æç¹ã¯ãããã¥ã¡ã³ãã«ãè¨è¿°ãããéããinstall-config.yaml
ãã¤ã³ã¹ãã¼ã«ãã£ã¬ã¯ããªä»¥å¤ã«ä¿åãã¦ãããã¨ã§ãã
- ã¤ã³ã¹ãã¼ã«ãã£ã¬ã¯ããªï¼
bare-metal
$ mkdir bare-metal $ vi install-config.yaml $ cp install-config.yaml bare-metal/
æ¤è¨¼ç°å¢ã®install-config.yaml
ã¯ä¸è¨ã®ãããªå
容ã«ãªãã¾ãã*18
- ãã¡ã¤ã³å:
example.local
- ã¯ã©ã¹ã¿åï¼
test
apiVersion: v1 baseDomain: example.local compute: - hyperthreading: Enabled name: worker replicas: 0 controlPlane: hyperthreading: Enabled name: master replicas: 3 metadata: name: test networking: clusterNetworks: - cidr: 10.128.0.0/14 hostPrefix: 23 networkType: OpenShiftSDN serviceNetwork: - 172.30.0.0/16 platform: none: {} pullSecret: '{"auths":{"cloud.openshift.com":{"auth": ..<çç¥>.. ==","email":"XXX@XXX"}}}' sshKey: 'ssh-rsa AAAA...'
pullSecret:
ã«ã¯ãä¸è¨ã®ãã¼ã¸ããCopy Pull Secret
ãæ¼ãã¦ã³ãã¼ããå
容ãè²¼ãä»ãã¾ãã
https://cloud.redhat.com/openshift/install/metal/user-provisioned
sshKey:
ã«ã¯ãäºåæºåã§ç¨æããSSHå
¬ééµã®å
容ï¼~/.ssh/new_rsa.pub
ï¼ãè²¼ãä»ãã¾ãã
1.b Ignition è¨å®ãã¡ã¤ã«ã®ä½æ
å¼ãç¶ããã®ä½æ¥ãè¸ã¿å°ãµã¼ãã¼ã§è¡ãã¾ãã ããã§è¡ããã¨ã¯ã1.aã§ä½æããå 容ãå ã«ãã¤ã³ã¹ãã¼ã«ã«å¿ è¦ãªIgnition è¨å®ãã¡ã¤ã«ãªã©ãä½æãã¾ãã è¡ããã¨ã¯ä¸è¨ã®ã³ãã³ãã1è¡å®è¡ããã ãã§ãã
$ openshift-install create ignition-configs --dir=bare-metal
ãã®ã³ãã³ãã®å®è¡å¾ã«ãã¤ã³ã¹ãã¼ã«ãã£ã¬ã¯ããªå
ã®install-config.yaml
ã¯åé¤ããã¾ãã
å®è¡å¾ã®ã¤ã³ã¹ãã¼ã«ãã£ã¬ã¯ããªã¯ä¸è¨ã®ããã«ãªãã¾ãã
bare-metal âââ auth â âââ kubeadmin-password â âââ kubeconfig âââ bootstrap.ign âââ master.ign âââ metadata.json âââ worker.ign
ããã¥ã¡ã³ãã«ã¯è¨è¼ãããã¾ããããå®éã®æé ã§ã¯ä½æããåignitionãã¡ã¤ã«ãWeb Serverã®å ¬éãã£ã¬ã¯ããªã«ã³ãã¼ãã¾ãã æ¤è¨¼ç°å¢ã§ã¯ä¸è¨ã®ããã«ãªãã¾ãã
cp bare-metal/*ign /usr/share/nginx/html/ocp/rhcos/ignitions/
1.c Red Hat Enterprise Linux CoreOS (RHCOS) ãã·ã³ã®ä½æ
ãã®ä½æ¥ã¯åãã¼ãã®ã³ã³ã½ã¼ã«ç»é¢ã§è¡ãã¾ãã ããã§ã¯ãåãã¼ãã®ãã¼ã¹OSã®RHCOSãç¨æãã¦ãèµ·åâåæãã©ã¡ã¼ã¿ã¼ã®å ¥åãè¡ãã¨ããã¾ã§ãè¡ãã¾ãã
ç¨æããåãã¼ããISOã¤ã¡ã¼ã¸ã§èµ·åãã¾ãã ããã¥ã¡ã³ãã§ã¯èµ·åé ã«ç¹ã«æå®ã¯ããã¾ãããããã¼ãã¹ãã©ããããã»ã¹ã«ããã¦ãMaster,Worker NodeãBootsrap Nodeããã³ã³ãã£ã°ãã¡ã¤ã«ãåå¾ããããã»ã¹ãããã¾ãã èµ·åé ãè¨ããå ´åã¯ãBootstrap Nodeãå ã«èµ·åããã®ãæã¾ããã§ãã*19
ãã®å¾ã®æé ã¯å
¨ãã¼ãå
±éã§ãï¼ignition config URLã®æå®å
ãé¤ãï¼ã
ISOèµ·åå¾ãRHEL CoreOS Installerã®GUIç»é¢ã表示ããã¾ããInstall RHEL CoreOS
ãé¸æããã¦ãã¾ãã®ã§ããã®ã¾ã¾ã¨ã³ã¿ã¼ãã¼ãæ¼ãã¾ãã
次ã«ãCoreOS Image URLã®å ¥åãæ±ãããã¾ãã®ã§ãããã©ã«ãã®å ¥åå 容ãæ¶ãã¦æå®ã®URLãã¹ãå ¥åããã¨ã³ã¿ã¼ãã¼ãæ¼ãã¾ãã
- ãã®ã¿ã¤ãã³ã°ã§ãã¡ã¤ã«ã«ã¢ã¯ã»ã¹ã§ããããã§ãã¯ãè¡ããã¾ããã¨ã©ã¼ã«ãªãå ´åã¯ãURLãã¹ããã¼ãçªå·ã«ééããç¡ãã確èªãã¦ãã ãã
ããã«ãCoreOS ignition config URLã®å ¥åãæ±ãããã¾ããå ç¨ã¨åæ§ã«ãããã©ã«ãã®å ¥åå 容ãæ¶ãã¦æå®ã®URLãã¹ãå ¥åããã¨ã³ã¿ã¼ãã¼ãæ¼ãã¾ãã ããã§ã¯Bootstrap Nodeã®ignitionè¨å®ãã¡ã¤ã«ãæå®
- ããããå ç¨ã¨åæ§ã«ãã¡ã¤ã«ã«ã¢ã¯ã»ã¹ã§ããããã§ãã¯ãè¡ããã¾ãã
- æå®ãã *.ignãã¡ã¤ã«ã¯ãåãã¼ãã®ç¨®é¡ã«åããã¦å¤æ´ãã¾ã
æå¾ã«ãã¤ã³ã¹ãã¼ã«å
ããã¤ã¹ã®æå®ãæ±ãããã¾ããsda
ãé¸æããOK
ãæ¼ãã¾ãã
CoreOS Image ã®ãã¦ã³ãã¼ãå§ã¾ããåé¡ãªãåå¾ãå®äºããã¨èªåã§åèµ·åãè¡ãããRHEL CoreOSãèµ·åãã¾ãã ãã®ä½æ¥ãå ¨ãã¼ãã«ã¤ãã¦è¡ãã¾ãã
2.a ã¯ã©ã¹ã¿ã¼ã®ä½æ
ããããWeb Consoleã¸ã®ãã°ã¤ã³ã¾ã§ã¯ãè¸ã¿å°ãµã¼ãã¼ã§ã®ä½æ¥ã¨ãªãã¾ãã
åé 1.cã®çµäºæç¹ããããã¼ãã¹ãã©ããããã»ã¹ã¯èªåçã«é²è¡ãã¦ãã¾ãã ããã§ã¯ãä¸è¨ã®ã³ãã³ããå®è¡ãããã¼ãã¹ãã©ããããã»ã¹ã®é²è¡ã¨å®äºãã¢ãã¿ãªã³ã°ãã¾ãã
$ openshift-install --dir=bare-metal wait-for bootstrap-complete
ä¸è¨ã®ãããªè¡¨ç¤ºã«ãªãã¨ãã¼ãã¹ãã©ããããã»ã¹ãå®äºãããã¨ãåããã¾ãã
openshift-install --dir=bare-metal wait-for bootstrap-complete INFO Waiting up to 30m0s for the Kubernetes API at https://api.test.example.local:6443... INFO API v1.13.4+d4417a7 up INFO Waiting up to 30m0s for bootstrapping to complete... INFO It is now safe to remove the bootstrap resources
- 30å以ä¸æãã£ã¦ãå®äºããªãå ´åã¯ãäºåæºåãä¸è¶³ãééã£ã¦ããå¯è½æ§ãé«ãã§ãã
- éä¸ã§æ¢ãã¦ããç´ãå ´åã¯ã1.cã®ISOèµ·åããããç´ãã¾ã
2.b ã¯ã©ã¹ã¿ã¼ã¸ã®ãã°ã¤ã³
ããã§ã¯ãkubeadmin
èªè¨¼æ
å ±ãã¨ã¯ã¹ãã¼ãããããã©ã«ãã·ã¹ãã ã¦ã¼ã¶ã¼ã§ãã°ã¤ã³ã§ãããã¨ã確èªãã¾ãã
$ export KUBECONFIG=bare-metal/auth/kubeconfig $ oc whoami system:admin
oc whoami
ã®çµæãsystem:admin
ãè¿ã£ã¦ããã°å®äºã§ãã
ãã¼ãã¹ãã©ããããã»ã¹ã®å®äºç´å¾ããã ã¨ãã¨ã©ã¼ãè¿ã£ã¦ãããã¨ãããã¾ãããã®å ´åã¯ãå°ãæéãç½®ãã¦å度å®è¡ãã¾ãã
2.c ãã·ã³ã® CSR ã®æ¿èª
ããã§ã¯ãåãã¼ããã¯ã©ã¹ã¿ã«è¿½å ãããéã«ä½æããã証ææ¸ç½²åè¦æ±ããå ¨ã¦æ¿èªããã¦ããã確èªãã¾ãã
ã¾ããã¯ã©ã¹ã¿ã¼ã«ãã¼ãã追å ããã¦ããã確èªãã¾ã
$ oc get nodes NAME STATUS ROLES AGE VERSION master-0 Ready master 63m v1.13.4+b626c2fe1 master-1 Ready master 63m v1.13.4+b626c2fe1 master-2 Ready master 64m v1.13.4+b626c2fe1 worker-0 NotReady worker 76s v1.13.4+b626c2fe1 worker-1 NotReady worker 70s v1.13.4+b626c2fe1
証ææ¸ç½²åè¦æ±ã®æ¿èªç¶æ ã確èªãã¾ãã
$ oc get csr
å ¨ã¦ã®é ç®ãã証æç¶æ ã«ãªã£ã¦ãããã¨ã確èªãã¾ã ããããªã£ã¦ããªããã°ãããã¥ã¡ã³ãã®æé ã§æåã§æ¿èªãè¡ãªã£ã¦ãã ããã*20
2.d Operator ã®åæè¨å®
ããã§ã¯ãå ¨ã¦ã®Operatorãæ£å¸¸ã«ç¨¼åãã¦ãããã¨ç¢ºèªãã¾ãã
$ watch -n5 oc get clusteroperators
ä¸è¨ã®ã³ãã³ãã§ã5ç§ãã¨ã«å®è¡ãããoc get clusteroperators
ã®çµæãã¢ãã¿ãªã³ã°ãã¾ãã
Operatorã次ã
ã¨ç«ã¡ä¸ãã£ã¦ããæ§åã確èªã§ãã¾ãã
æçµçã«å
¨ã¦ã®Operatorã®ã¹ãã¼ã¿ã¹ã«ããã¦AVAILABLE
ãTRUE
ãDEGRADED
ãFALSE
ã«ãªããã¨ãã´ã¼ã«ã§ãã*21
â»ã¹ãã¬ã¼ã¸ã®ã¤ã¡ã¼ã¸ã¬ã¸ã¹ããªã¼ã¸ã®æä¾ï¼å¯¾è±¡ããã¥ã¡ã³ãï¼3.1.14.1ï¼
image-registry
operatorã«ã¤ãã¦ã¯ãèªåçã«AVAILABLE
ãTRUE
ã«ã¯ãªãã¾ããã
ä¸è¨ã®ã³ãã³ããå®è¡ãã¦ã空ã®ãã£ã¬ã¯ããªãæå®ãã¾ãã
$ oc patch configs.imageregistry.operator.openshift.io cluster --type merge --patch '{"spec":{"storage":{"emptyDir":{}}}}'
ããã¥ã¡ã³ãã«ãè¨è¼ã¯ããã¾ããããã®ãªãã·ã§ã³ã¯å®ç¨¼åç¨ä»¥å¤ã®ã¯ã©ã¹ã¿ã¼ã«ã®ã¿è¨å®ãã¾ãã ãã®è¨äºã§ã¯ã¤ã³ã¹ãã¼ã«ã®å®äºãç®æ¨ã¨ãã¾ãã®ã§ããã®ãªãã·ã§ã³ãå®è¡ãã¾ãã æ¬çªéç¨æã¯é©åãªè¨å®ã«å¤æ´ãã¦ãã ããã 詳細ãªè¨å®æ¹æ³ã¯ä¸è¨ãåç §ã
2.4.2. ãã¢ã¡ã¿ã«ã®å ´åã®ã¬ã¸ã¹ããªã¼ã¹ãã¬ã¼ã¸ã®è¨å®
- Operatorãæ£å¸¸ã«èµ·åããç¶æ ã¯ä¸è¨ã®ããã«ãªãã¾ãã
# oc get clusteroperators NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE authentication 4.1.3 True False False 46s cloud-credential 4.1.3 True False False 12m cluster-autoscaler 4.1.3 True False False 12m console 4.1.3 True False False 4m17s dns 4.1.3 True False False 11m image-registry 4.1.3 True False False 7m17s ingress 4.1.3 True False False 7m34s kube-apiserver 4.1.3 True False False 11m kube-controller-manager 4.1.3 True False False 9m31s kube-scheduler 4.1.3 True False False 9m40s machine-api 4.1.3 True False False 12m machine-config 4.1.3 True False False 10m marketplace 4.1.3 True False False 7m26s monitoring 4.1.3 True False False 5m32s network 4.1.3 True False False 12m node-tuning 4.1.3 True False False 8m57s openshift-apiserver 4.1.3 True False False 8m54s openshift-controller-manager 4.1.3 True False False 11m openshift-samples 4.1.3 True False False 2m33s operator-lifecycle-manager 4.1.3 True False False 10m operator-lifecycle-manager-catalog 4.1.3 True False False 11m service-ca 4.1.3 True False False 11m service-catalog-apiserver 4.1.3 True False False 9m4s service-catalog-controller-manager 4.1.3 True False False 9m5s storage 4.1.3 True False False 8m6s
2.e UPIã®ã¤ã³ã¹ãã¼ã«ã®å®äº
ã¤ã³ã¹ãã¼ã«ä½æ¥ã®æçµæ®µéã§ãã åé 2.dã§å ¨ã¦ã®Operatorãæ£å¸¸ã«åä½ãã¦ãããã¨ã確èªå¾ãä¸è¨ã®ã³ãã³ããå®è¡ãã¾ãã
$ openshift-install --dir=bare-metal wait-for install-complete
ãã®å¾ãã¤ã³ã¹ãã¼ã«ããã»ã¹ãæ£å¸¸ã«å®äºããã¨ãWeb Consoleã¸ã®ãã°ã¤ã³æ å ±ã表示ããã¾ãã ããã§UPIã®ã¤ã³ã¹ãã¼ã«ä½æ¥ã¯å®äºã§ãã
INFO Waiting up to 30m0s for the cluster at https://api.test.example.local:6443 to initialize... INFO Waiting up to 10m0s for the openshift-console route to be created... INFO Install complete! INFO To access the cluster as the system:admin user when using 'oc', run 'export KUBECONFIG=/root/OCP/bare-metal/auth/kubeconfig' INFO Access the OpenShift web-console here: https://console-openshift-console.apps.test.example.local INFO Login to the console with user: kubeadmin, password: XXXXX-XXXXX-XXXXX-XXXXX
- æå¾ã«è¡¨ç¤ºããã
user: kubeadmin,password: XXXXX-XXXXX-XXXXX-XXXXX
ã使ç¨ãã¦ãWeb Consoleã¸ãã°ã¤ã³ãã¾ãã
Web Consoleã¸ã®ãã°ã¤ã³
æå¾ã«ãWebãã©ã¦ã¶ã§Web Consoleã«ã¢ã¯ã»ã¹ãã¦ãã¯ã©ã¹ã¿ãæ£å¸¸ã«ç¨¼åãã¦ããã確èªãã¾ãã æ¤è¨¼ç°å¢ã§ã¯ãä¸è¨ã®ã¢ãã¬ã¹ã«ã¢ã¯ã»ã¹ãã¾ãã
https://console-openshift-console.apps.test.example.local
ãã°ã¤ã³å¾ãAdministration > Cluster Status
ã§ã¯ã©ã¹ã¿ã¼ã®ã¹ãã¼ã¿ã¹ã«åé¡ãç¡ããã°æ£å¸¸ç¨¼åãã¦ãã¾ãã
ã¾ã¨ã
以ä¸ãOpenShift 4.1ããã¢ã¡ã¿ã«ç°å¢ã«ã¤ã³ã¹ãã¼ã«ããæé ã®ç´¹ä»ã§ããã ããããå ã¯OpenShiftã«å®éã«è§¦ããä¸çã«ãªãã¾ãã æ¯éã身è¿ãªç°å¢ã«OpenShiftãã¤ã³ã¹ãã¼ã«ãã¦ã©ãã©ã使ã£ã¦ã¿ã¦ä¸ããï¼
Let's get Big Ideas!
åèï¼è¸ã¿å°ãµã¼ãã¼ã®æ§ç¯
æ¬è¨äºã®æ¤è¨¼ç°å¢ã§ä½¿ç¨ããè¸ã¿å°ãµã¼ãã¼ãæ§ç¯ããããã®è¨å®ã®ãµã³ãã«ãè¼ãã¦ããã¾ãã
RHELã®è¨å®
1. ãµãã¹ã¯ãªãã·ã§ã³ç»é²
# subscription-manager register # subscription-manager attach --pool <ID>
2. IPv6ç¡å¹åãIPv4ã«ã¼ãã£ã³ã°
# vi /etc/sysctl.d/99-custom.conf net.ipv6.conf.all.disable_ipv6 = 1 net.ipv4.ip_forward = 1 # sysctl -p /etc/sysctl.d/99-custom.conf
3. SELinux
# setsebool -P httpd_read_user_content 1 # setsebool -P haproxy_connect_any 1
4. ä¸è¦ãªãµã¼ãã¹ã®åæ¢
- avahi-daemon
systemctl disable avahi-daemon.service systemctl stop avahi-daemon*
- cups
# systemctl stop cups.service # systemctl disable cups.service
- rpcbind
# systemctl stop rpcbind.service # systemctl stop rpcbind.socket # systemctl disable rpcbind.service # systemctl disable rpcbind.socket
- libvirtd
# systemctl stop libvirtd.service # systemctl disable libvirtd.service
5. NICè¨å®
- 社å ãããã¯ã¼ã¯å´ï¼ens192ï¼
# nmcli con modify ens192 ipv4.method manual # nmcli con modify ens192 ipv4.addresses 192.168.1.21/24 # nmcli con modify ens192 ipv4.gateway 192.168.1.1 # nmcli con modify ens192 ipv4.dns 127.0.0.1 # nmcli con modify ens192 ipv6.method ignore
- æ¤è¨¼ç¨ãããã¯ã¼ã¯å´ï¼ens224ï¼
# nmcli con modify ens224 ipv4.method manual # nmcli con modify ens224 ipv4.addresses 172.16.0.1/24 # nmcli con modify ens224 ipv6.method ignore
firewalld
# firewall-cmd --set-default-zone=trusted # firewall-cmd --add-masquerade --zone=trusted --permanent # firewall-cmd --reload
dnsmasq
# vi /etc/dnsmasq.conf
- ãµã³ãã«ã³ã³ãã£ã°ï¼ã³ã¡ã³ãè¡ãé¤ãï¼
port=53 domain-needed bogus-priv resolv-file=/etc/resolv.dnsmasq no-poll address=/apps.test.example.local/172.16.0.1 user=dnsmasq group=dnsmasq no-dhcp-interface=ens192 expand-hosts domain=test.example.local dhcp-range=172.16.0.100,172.16.0.200,255.255.255.0,12h dhcp-host=XX:XX:XX:XX:XX:XX,bootstrap,172.16.0.100 dhcp-host=XX:XX:XX:XX:XX:XX,master-0,172.16.0.101 dhcp-host=XX:XX:XX:XX:XX:XX,master-1,172.16.0.102 dhcp-host=XX:XX:XX:XX:XX:XX,master-2,172.16.0.103 dhcp-host=XX:XX:XX:XX:XX:XX,worker-0,172.16.0.104 dhcp-host=XX:XX:XX:XX:XX:XX,worker-1,172.16.0.105 dhcp-option=option:dns-server,172.16.0.1 dhcp-leasefile=/var/lib/dnsmasq/dnsmasq.leases srv-host=_etcd-server-ssl._tcp.test.example.local,etcd-0.test.example.local,2380,0,10 srv-host=_etcd-server-ssl._tcp.test.example.local,etcd-1.test.example.local,2380,0,10 srv-host=_etcd-server-ssl._tcp.test.example.local,etcd-2.test.example.local,2380,0,10 log-dhcp log-facility=/var/log/dnsmasq.log conf-dir=/etc/dnsmasq.d,.rpmnew,.rpmsave,.rpmorig
- resolv.conf
# vi /etc/resolv.conf nameserver 127.0.0.1
- resolv.dnsmasq
# vi /etc/resolv.dnsmasq nameserver 192.168.1.1
- hosts
# vi /etc/hosts 127.0.0.1 localhost localhost.localdomain localhost4 localhost4.localdomain4 ::1 localhost localhost.localdomain localhost6 localhost6.localdomain6 #for OCP4 192.168.1.21 api 172.16.0.1 api-int 172.16.0.101 etcd-0 172.16.0.102 etcd-1 172.16.0.103 etcd-2
- ãµã¼ãã¹ç»é²ãèµ·å
# systemctl enable dnsmasq.service # systemctl start dnsmasq.service
HAproxy
# yum install haproxy # vi /etc/haproxy/haproxy.cfg
- ãµã³ãã«ã³ã³ãã£ã°ï¼global,defaultsã¯åæã³ã³ãã£ã°ããå¤æ´ç¡ããfrontend,backendã®ã¿è¨è¼ï¼
frontend K8s-api bind *:6443 option tcplog mode tcp default_backend api-6443 frontend Machine-config bind *:22623 option tcplog mode tcp default_backend config-22623 frontend Ingress-http bind *:80 option tcplog mode tcp default_backend http-80 frontend Ingress-https bind *:443 option tcplog mode tcp default_backend https-443 backend api-6443 mode tcp balance roundrobin option ssl-hello-chk server bootstrap bootstrap.test.example.local:6443 check server master-0 master-0.test.example.local:6443 check server master-1 master-1.test.example.local:6443 check server master-2 master-2.test.example.local:6443 check backend config-22623 mode tcp balance roundrobin server bootstrap bootstrap.test.example.local:22623 check server master-0 master-0.test.example.local:22623 check server master-1 master-1.test.example.local:22623 check server master-2 master-2.test.example.local:22623 check backend http-80 mode tcp balance roundrobin server worker-0 worker-0.test.example.local:80 check server worker-1 worker-1.test.example.local:80 check backend https-443 mode tcp balance roundrobin option ssl-hello-chk server worker-0 worker-0.test.example.local:443 check server worker-1 worker-1.test.example.local:443 check
- ãµã¼ãã¹ç»é²ãèµ·å
# systemctl enable haproxy.service # systemctl start haproxy.service
nginx
# yum install nginx # vi /etc/nginx/nginx.conf
- ãµã³ãã«ã³ã³ãã£ã°ï¼åæã³ã³ãã£ã°ããå¤æ´ç¹ã®ã¿è¨è¼ï¼
http { server { listen 8008 default_server; # ãã¼ãçªå·å¤æ´ï¼80->8008 # listen [::]:80 default_server; # ã³ã¡ã³ãã¢ã¦ã } disable_symlinks off; # 追å }
- ãµã¼ãã¹ç»é²ãèµ·å
# systemctl enable nginx # systemctl start nginx
*1:UPIã§ãã¢ã¡ã¿ã«ç°å¢ã¸ã®ã¤ã³ã¹ãã¼ã«ãã§ããããã«ãªãã¨ãOpenShift 4ã®åºæ¬ã®ã¢ã¼ããã¯ãã£ã«ã¤ãã¦ç解ãæ·±ã¾ããä»ã®ç°å¢ã¸ã®ã¤ã³ã¹ãã¼ã«ã«ãå¿ç¨ãã§ããããã«ãªãã¨æãã¾ã
*2:openshift.comã«ãè±èªã®ã¿ã§ããåæ§ã®ããã¥ã¡ã³ããããã¾ããRed Hat OpenShift Cluster Managerãããªã³ã¯ãã¦ããããã¥ã¡ã³ãã¯ãã¡ãã«ãªãã¾ããæ¬è¨äºã®å 容ã¨åããã¦èªã¿é²ãä¸ãããInstalling a cluster on bare metal - Installing on bare metal | Installing | OpenShift Container Platform 4.1
*3:Microsoft Azureä¸ã¸ã®ã¤ã³ã¹ãã¼ã«ã¯ç¾å¨Developer Previewã§ã
*4:ãã¹ãæ¸ã¿ã®ç°å¢æ å ±ã«ã¤ãã¦ã¯ãã¡ãï¼ã«ã¹ã¿ãã¼ãã¼ã¿ã«ã¸ã®ãã°ã¤ã³ãå¿ è¦ï¼https://access.redhat.com/articles/4128421
*5:ãã®è¨äºã®æ大ã®ãã¤ã³ãã¯ã³ã³ã§ããå¿ è¦æä½éã®æ§æãå¤æ´ã§ããã«OpenShift 4ãæ§ç¯ãããããã«éç¹ãããã¦ãã¾ã
*6:ç°å¢ã«ãå¯ãã¾ãããæå ã®æ¤è¨¼ç°å¢ã§ã¯20-30åç¨åº¦ã§ã¯ã©ã¹ã¿ã®ä½æãå®äºãã¾ã
*7:Worker Nodeã«RHEL7.6ã使ç¨ãããªãã·ã§ã³ãããã¾ã
*8:UPIã¤ã³ã¹ãã¼ã«å¾ã¯æä½ç«¯æ«ã«å°å ¥ãã¦ããããæä½ããã®ãããã§ã
*9:æä½ç«¯æ«ãMacãLinuxã§ããã°ããã§ã®å©ç¨ã¯å¯è½ã§ããããã®æ¤è¨¼ç°å¢ã§ã¯è¸ã¿å°ãµã¼ãã¼ä¸ã§ä½æ¥ãå®çµãããã¨ãæ³å®ãã¦æ§æãã¦ãã¾ã
*10:ããã¥ã¡ã³ãããï¼ãRHCOS ã¤ã¡ã¼ã¸ã¯ OpenShift Container Platform ã®åãªãªã¼ã¹ãã¨ã«å¤æ´ãããªãå¯è½æ§ãããã¾ããã¤ã³ã¹ãã¼ã«ãã OpenShift Container Platform ãã¼ã¸ã§ã³ã¨çãããããã以ä¸ã®ãã¼ã¸ã§ã³ã®å ã§æãæ°ãããã¼ã¸ã§ã³ã®ã¤ã¡ã¼ã¸ããã¦ã³ãã¼ãããå¿ è¦ãããã¾ããå©ç¨å¯è½ãªå ´åã¯ãOpenShift Container Platform ãã¼ã¸ã§ã³ã«ä¸è´ããã¤ã¡ã¼ã¸ã®ãã¼ã¸ã§ã³ã使ç¨ãã¾ããã
*11:å ¨ã¦ã®ãã·ã³éã§å¿ è¦ãªéä¿¡ãã¼ãã¯ããã¥ã¡ã³ãã«è¨è¼ãããã¾ãâ表3.1
*12:quay.ioããã®ã¤ã¡ã¼ã¸ãã«ã¨ãcloud.redhat.comã¸ã®Telemetryãã¼ã¿ã®éä¿¡ãå¿ è¦ã§ã
*13:SELinuxã§http_port_t ã«ç»é²ããã¦ããçªå·ã使ç¨
*14:ãªãªã¼ã¹ãå¢ãã¦ãå ´åãè¦è¶ãã¦æå®ããããããã«ãã¦ãã¾ã
*15:RHCOSã®åãã¼ãã¸ã¯å ¬ééµèªè¨¼æ¹å¼ã§ã®SSHæ¥ç¶ãå¿ è¦ã§ããSSH Agentã«å¯¾å¿ãã¦ãããã®ããã¿ã¼ã§ã
*16:ããã¥ã¡ã³ãã§ã¯ããã®ãã¼ã使ç¨ãã¦ãã¦ã¼ã¶ã¼ core ã¨ãã¦ãã¹ã¿ã¼ãã¼ãã«å¯¾ã㦠SSH ãå®è¡ã§ãã¾ãããã¨ããã¾ãããå®éã«ã¯Bootstrap,Master,Workerãã¥ãã®ãã¼ãã«ãSSHã§ã¢ã¯ã»ã¹ã§ãã¾ãã
*17:ãã°ã®ç¢ºèªãªã©ã®æé ã¯ã¾ãå¥è¨äºã§ã¾ã¨ããããã°ã¨æãã¾ã
*18:baseDomainï¼ãã¡ã¤ã³åï¼ã¨nameï¼ã¯ã©ã¹ã¿åï¼ä»¥å¤ã¯ããã¥ã¡ã³ãã®ãµã³ãã«éããpullSecretã¨sshKeyã®å 容ã¯ã·ã³ã°ã«ã¯ã©ã¼ãã¼ã·ã§ã³ã§å²ã¾ããããã«ã
*19:å ¨å°åæèµ·åã§ãåé¡ç¡ãã§ããã³ã³ãã£ã°ãã¡ã¤ã«ã®åå¾ãã§ããã¾ã§ãMaster,Worker Nodeã¯å¾ æ©ãã¾ãã
*20:ããã¾ã§çµé¨ä¸ã§ãããç¹°ãè¿ãæ°è¦ã¯ã©ã¹ã¿ãä½æãã¦ããä¸ã§ã¯ããã¯å¿ ãå ¨ã¦æ¿èªç¶æ ã«ãªã£ã¦ãã¾ããã
*21:ããã¥ã¡ã³ãã«ã¯ãå ¨ã¦ã®OperatorãAVAILABLEã®å ´åã¤ã³ã¹ãã¼ã«ãå®äºãããã¨ãã§ãã¾ããã¨è¨è¼ãããã¾ããå®éãä¸é¨ã«DEGRADEDãããç¶æ ã§ãã³ãã³ãä¸ã¯ã¤ã³ã¹ãã¼ã«å®äºã«ãªãã¾ããããããªãããWeb Consoleä¸ã§ã¯ã¨ã©ã¼ãçºçãã¦ããããOpenShiftã¨ãã¦ã®æ§ç¯ãæªå®äºã®ç¶æ ã«ãªããã¨ãããã¾ãã