컴퓨트 노드에 Open vSwitch 에이전트를 설치하고 nova-compute 가 Neutron 을 쓰도록 연결한다. 컨트롤러 노드 설치를 먼저 끝낸다. 컴퓨트 노드는 데이터베이스에 붙지 않으므로 [database] 절은 쓰지 않는다.
바꿔 넣을 값
| 자리 | 값 |
|---|---|
NEUTRON_PASS · RABBIT_PASS |
미리 정한 비밀번호 |
PROVIDER_BRIDGE_NAME |
공급자 OVS 브리지 이름. 컨트롤러와 같은 이름을 쓴다. 예: br-provider |
PROVIDER_INTERFACE_NAME |
공급자 물리 인터페이스. 예: eth1 |
OVERLAY_INTERFACE_IP_ADDRESS |
이 노드의 관리용 IP. 예: 10.0.0.31 |
Ubuntu 24.04
apt install neutron-openvswitch-agent
CentOS Stream 9 · RHEL 9
dnf install openstack-neutron-openvswitch
/etc/neutron/neutron.conf
[DEFAULT]
transport_url = rabbit://openstack:RABBIT_PASS@controller
[oslo_concurrency]
lock_path = /var/lib/neutron/tmp
/etc/neutron/plugins/ml2/openvswitch_agent.ini
[ovs]
bridge_mappings = provider:PROVIDER_BRIDGE_NAME
local_ip = OVERLAY_INTERFACE_IP_ADDRESS
[agent]
tunnel_types = vxlan
l2_population = true
[securitygroup]
enable_security_group = true
firewall_driver = openvswitch
#firewall_driver = iptables_hybrid
공급자 브리지를 만들고 물리 인터페이스를 붙인다.
ovs-vsctl add-br PROVIDER_BRIDGE_NAME
ovs-vsctl add-port PROVIDER_BRIDGE_NAME PROVIDER_INTERFACE_NAME
firewall_driver = iptables_hybrid 를 쓰는 경우에만 net.bridge.bridge-nf-call-iptables · net.bridge.bridge-nf-call-ip6tables 가 1 이어야 한다.
/etc/nova/nova.conf 에 [neutron] 절을 넣는다.
[neutron]
auth_url = http://controller:5000
auth_type = password
project_domain_name = Default
user_domain_name = Default
region_name = RegionOne
project_name = service
username = neutron
password = NEUTRON_PASS
Ubuntu 24.04
systemctl restart nova-compute
systemctl restart neutron-openvswitch-agent
CentOS Stream 9 · RHEL 9
systemctl restart openstack-nova-compute.service
systemctl enable neutron-openvswitch-agent.service
systemctl start neutron-openvswitch-agent.service
RHEL 계열에서 firewalld 를 쓰면 VXLAN 포트를 연다.
firewall-cmd --permanent --add-port=4789/udp
firewall-cmd --reload
컨트롤러 노드에서 실행한다.
. admin-openrc
openstack network agent list
컴퓨트 노드의 Open vSwitch agent 가 Alive 로 보이면 된다.
CentOS Stream 8 · Victoria 에서는 Linux bridge 에이전트를 썼다.
yum install -y openstack-neutron-linuxbridge ebtables ipset
/etc/neutron/plugins/ml2/linuxbridge_agent.ini
[linux_bridge]
physical_interface_mappings = provider:PROVIDER_INTERFACE_NAME
[vxlan]
enable_vxlan = true
local_ip = OVERLAY_INTERFACE_IP_ADDRESS
l2_population = true
[securitygroup]
enable_security_group = true
firewall_driver = neutron.agent.linux.iptables_firewall.IptablesFirewallDriver
/etc/sysctl.conf
net.bridge.bridge-nf-call-iptables = 1
net.bridge.bridge-nf-call-ip6tables = 1
systemctl restart openstack-nova-compute.service
systemctl enable neutron-linuxbridge-agent.service
systemctl start neutron-linuxbridge-agent.service