前提条件
需要配置OpenStack成功连接OVN
/etc/chrony.conf:40:allow 172.18.3.245/18
/etc/my.cnf.d/openstack.cnf:2:bind-address = 172.18.3.245
/etc/nova/nova.conf:4:my_ip = 172.18.3.245
/etc/nova/nova.conf:7:my_ip = 172.18.3.245
/etc/nova/nova.conf:5244:novncproxy_base_url = http://172.18.3.245:6080/vnc_auto.html
/etc/etcd/etcd.conf:3:ETCD_LISTEN_PEER_URLS="http://172.18.3.245:2380"
/etc/etcd/etcd.conf:4:ETCD_LISTEN_CLIENT_URLS="http://172.18.3.245:2379"
/etc/etcd/etcd.conf:7:ETCD_INITIAL_ADVERTISE_PEER_URLS="http://172.18.3.245:2380"
/etc/etcd/etcd.conf:8:ETCD_ADVERTISE_CLIENT_URLS="http://172.18.3.245:2379"
/etc/etcd/etcd.conf:9:ETCD_INITIAL_CLUSTER="controller=http://172.18.3.245:2380"
/etc/neutron/plugins/ml2/openvswitch_agent.ini:153:local_ip = 172.18.3.245
/etc/neutron/plugins/ml2/ml2_conf.ini:164:ovn_nb_connection = tcp:172.18.3.157:6641
/etc/neutron/plugins/ml2/ml2_conf.ini:165:ovn_sb_connection = tcp:172.18.3.157:6642
-----------创建OpenStack需要的资源(步骤整理)--------------------------
1、OpenStack页面或者命令创建网络、子网、router、子网加入router接口
2、OVN中会生成VPC:neutron-3d4f9d09-ef84-46d6-93d9-2888b483a552
[root@cluster157-master-1 ~]# kubectl get vpc
"""
NAME STANDBY SUBNETS NAMESPACES
neutron-3d4f9d09-ef84-46d6-93d9-2888b483a552 true ["neutron-f7f96fb1-2e75-45c1-a430-d9b38c7f9f90"]
ovn-cluster true ["mimic-subnet","ovn-default","subnettest","join"]
vpc-1 true [] ["vpc-1-ns-test"]
vpc-2 true
""" ["vpc-2-ns-test"]
3、k8s里面创建OpenStack需要的命名空间、子网、pod等资源
(1)创建Namespace
cat <<EOF | kubectl apply -f -
apiVersion: v1
kind: Namespace
metadata:
name: openstack-192-168-ns
EOF
(2)修改vpc参数,添加命名空间
kubectl edit vpc neutron-3d4f9d09-ef84-46d6-93d9-2888b483a552
""""
apiVersion: kubeovn.io/v1
kind: Vpc
metadata:
creationTimestamp: "2023-08-23T08:35:05Z"
generation: 3
labels:
ovn.kubernetes.io/vpc_external: "true"
name: neutron-3d4f9d09-ef84-46d6-93d9-2888b483a552
resourceVersion: "41947303"
selfLink: /apis/kubeovn.io/v1/vpcs/neutron-3d4f9d09-ef84-46d6-93d9-2888b483a552
uid: 59e4f72a-6925-44c3-8bd6-bcef88dfd79d
spec:
namespaces:
- openstack-192-168-ns
status:
default: false
defaultLogicalSwitch: ""
router: neutron-3d4f9d09-ef84-46d6-93d9-2888b483a552
standby: true
subnets:
- neutron-bfbf522a-a616-4127-b771-62a19e13108c
- openstack-192-168-subnet
tcpLoadBalancer: ""
tcpSessionLoadBalancer: ""
udpLoadBalancer: ""
udpSessionLoadBalancer: ""
"""
(3)创建subnet
cat <<EOF | kubectl apply -f -
apiVersion: v1
kind: Subnet
apiVersion: kubeovn.io/v1
metadata:
name: openstack-192-168-subnet
spec:
vpc: neutron-3d4f9d09-ef84-46d6-93d9-2888b483a552
namespaces:
- openstack-192-168-ns
cidrBlock: 192.168.100.0/24
excludeIps:
- 192.168.100.1..192.168.100.100
natOutgoing: false
EOF
(4)创建Pod
cat <<EOF | kubectl apply -f -
apiVersion: v1
kind: Pod
metadata:
annotations:
ovn.kubernetes.io/logical_switch: openstack-192-168-subnet
name: openstack-192-168-pod1
namespace: openstack-192-168-ns
spec:
containers:
- image: kubeovn/kube-ovn:v1.8.0
command:
- "sleep"
- "604800"
imagePullPolicy: IfNotPresent
name: openstack-192-168-pod1
restartPolicy: Always
EOF
创建3个实例
查看ovn:kubectl-ko nbctl show
此处可以看到k8s和OpenStack的子网都被kube-ovn接管
--------------------------------k8s相关命令整理----------------------------------
1、创建资源app
cat <<EOF | kubectl apply -f -
apiVersion: v1
kind: Pod
metadata:
name: vpc-1-app-test1
namespace: vpc-1-ns-test
spec:
containers:
- image: kubeovn/kube-ovn:v1.8.0
command:
- "sleep"
- "604800"
imagePullPolicy: IfNotPresent
name: test
restartPolicy: Always
EOF
2、创建命名空间
方法1:kubectl create namespace test-env
方法2:cat <<EOF | kubectl apply -f -
apiVersion: v1
kind: Namespace
metadata:
name: ns111111
EOF
3、删除和查看pod、namespace
(1)删除资源
kubectl delete pod vpc-1-app-test -n vpc-1-ns-test
kubectl delete pod openstack-192-168-pod1 -n openstack-192-168-ns
kubectl delete Namespace ns111111
kubectl delete subnet openstack-192-168-subnet
(2)强制删除资源
kubectl patch subnets/openstack-192-168-subnet -p '{"metadata":{"finalizers":[]}}' --type=merge
(3)查看资源
kubectl get pods -A -o wide
kubectl get vpc
kubectl get namespace
kubectl get subnet
4、进入容器
kubectl exec -it -n default openstack-192-168-pod1 -- /bin/bash
5、编辑资源
kubectl edit pod -n vpc-1-ns-test vpc-1-app-test