openSUSE Leap Micro 6.1へのSUSE Multi-Linux Managerプロキシの配備
このガイドでは、SUSE Multi-Linux Manager 5.1プロキシの配備プロセスの概要について説明します。このガイドでは、SUSE Multi-Linux Manager 5.1サーバが正常に配備済みであることを想定しています。正常に配備するには、次のアクションを実行します。
-
ハードウェア要件を確認します。
-
openSUSE Leap Micro 6.1をベアメタルマシンにインストールします。
-
プロキシをSalt Minionとしてブートストラップします。
-
プロキシ設定を生成します。
-
サーバからプロキシへのプロキシ設定の転送
-
プロキシ設定を使用して、Salt MinionをプロキシとしてSUSE Multi-Linux Managerに登録します。
|
プロキシコンテナホストでサポートされるオペレーティングシステム
コンテナホストでサポートされているオペレーティングシステムはopenSUSE Leap Micro 6.1です。
|
1. プロキシのハードウェア要件
次の表に、SUSE Multi-Linux Managerプロキシを配備するためのハードウェア要件を示します。
| Hardware | Details | Recommendation |
|---|---|---|
CPU |
x86-64, ARM |
Minimum 2 dedicated 64-bit CPU cores |
RAM |
Minimum |
2 GB |
Recommended |
8 GB |
|
Disk Space |
|
Minimum 40 GB |
|
Minimum 100 GB, Storage requirements should be calculated for the number of ISO distribution images, containers, and bootstrap repositories you will use. |
2. コンテナホストの一般的な要件
一般的な要件については、一般的な要件を参照してください。
openSUSE Leap Micro 6.1サーバはインストールメディアからインストールする必要があります。この手順については、以下で説明します。
3. コンテナホストの要件
CPU、RAM、およびストレージの要件については、ハードウェア要件を参照してください。
|
クライアントがFQDNドメイン名を解決できることを保証するには、コンテナ化されたプロキシとホストマシンの両方が、機能しているDNSサーバにリンクされている必要があります。さらに、リバース参照が正しく設定されていることを確認することも重要です。 |
4. コンテナで使用するためにUyuniツールをインストールする
-
ローカルホストで、端末のウィンドウを開くか、openSUSE Leap Micro 6.1が実行される仮想マシンを起動します。
-
ログインします。
-
Enter the
transactional-update shell:transactional-update shell
-
次のリポジトリをopenSUSE Leap Micro 6.1サーバに追加します。
zypper ar https://download.opensuse.org/repositories/systemsmanagement:/Uyuni:/Stable/images/repo/Uyuni-Proxy-POOL-$(arch)-Media1/ uyuni-proxy-stable
-
リポジトリのリストを更新してキーを受け入れます。
zypper ref
-
コンテナツールをインストールします。
zypper in mgrpxy mgrpxy-bash-completion uyuni-storage-setup-proxyAlternatively you may install
mgrpxy-zsh-completionormgrpxy-fish-completion. -
トランザクションシェルを終了します。
transactional update # exit
-
ホストを再起動します。
Uyuniコンテナユーティリティの詳細については、Uyuniコンテナユーティリティを参照してください。
5. カスタム永続ストレージの設定
This step is optional. However, if custom persistent storage is required for your infrastructure, use the mgr-storage-proxy tool.
For more information, see mgr-storage-proxy --help. This tool simplifies creating the container storage and Squid cache volumes.
このコマンドは次のように使用します。
mgr-storage-proxy <storage-disk-device>
例:
mgr-storage-proxy /dev/nvme1n1
|
This command will create the persistent storage volumes at 詳細については、以下を参照してください。 |
6. Minionとしてのプロキシホストのブートストラップ
-
を選択します。
-
プロキシホストのフィールドに入力します。
-
ドロップダウンから、前のステップで作成したアクティベーションキーを選択します。
-
+ ブートストラップをクリックします。
-
ブートストラッププロセスが正常に完了するまで待ちます。Saltメニューをチェックし、Salt Minionキーが一覧表示されていて受け入れられていることを確認します。
-
プロキシホストを再起動します。
-
すべてのイベントが終了したら、システムの一覧からホストを選択して2回目の再起動をトリガし、オンボーディングを完了します。
-
システムの一覧からホストを選択し、すべてのパッチを適用してホストを更新します。
-
プロキシホストを再起動します。
7. プロキシ設定の生成
SUSE Multi-Linux Managerプロキシの設定アーカイブはSUSE Multi-Linux Managerサーバによって生成されます。追加のプロキシごとに専用の設定アーカイブが必要です。
|
このプロキシ設定を生成する前に、SUSE Multi-Linux ManagerプロキシのコンテナホストをSalt MinionとしてSUSE Multi-Linux Managerサーバに登録する必要があります。 |
次のタスクを実行します。
-
プロキシ設定ファイルを生成します。
-
設定をプロキシに転送します。
-
Start the Proxy with the
mgrpxycommand.
-
Web UIで、に移動し、必要なデータを入力します。
-
In the
Proxy FQDNfield type fully qualified domain name for the proxy. -
In the
Parent FQDNfield type fully qualified domain name for the SUSE Multi-Linux Manager Server or another SUSE Multi-Linux Manager Proxy. -
In the
Proxy SSH portfield type SSH port on which SSH service is listening on SUSE Multi-Linux Manager Proxy. Recommended is to keep default 8022. -
In the
Max Squid cache size [MB]field type maximal allowed size for Squid cache. Typically this should be at most 60% of available storage for the containers. In theSSL certificateselection list choose if new server certificate should be generated for SUSE Multi-Linux Manager Proxy or an existing one should be used. You can consider generated certificates as SUSE Multi-Linux Manager builtin (self signed) certificates.選択に応じて、新しい証明書を生成するための署名CA証明書へのパス、またはプロキシ証明書として使用される既存の証明書とそのキーへのパスのいずれかを指定します。
The CA certificates generated on the server are stored in the
/var/lib/containers/storage/volumes/root/ssl-builddirectory.既存の証明書またはカスタム証明書、および企業証明書と中間証明書の概念の詳細については、SSL証明書のインポートを参照してください。
-
生成をクリックして、SUSE Multi-Linux Managerサーバに新しいプロキシFQDNを登録し、コンテナホストの詳細を含む設定アーカイブを生成します。
-
しばらくすると、ダウンロードするファイルが表示されます。このファイルをローカルに保存します。
8. プロキシ設定の転送
Web UIで、設定アーカイブが生成されます。このアーカイブは、コンテナホストで利用できるようにする必要があります。
-
サーバコンテナからサーバのホストOSにファイルをコピーします。
mgrctl cp server:/root/config.tar.gz .
-
サーバのホストOSからプロキシホストにファイルをコピーします。
scp config.tar.gz <proxy-FQDN>:/root
-
次のコマンドを使用してプロキシをインストールします。
mgrpxy install podman config.tar.gz
9. SUSE Multi-Linux Manager 5.1プロキシの起動
Container can now be started with the mgrpxy command:
-
次のコマンドを呼び出してプロキシを起動します。
mgrpxy start
-
次のコマンドを呼び出してコンテナのステータスを確認します。
mgrpxy status
Five SUSE Multi-Linux Manager Proxy containers should be present and should be part of the
proxy-podcontainer pod:-
proxy-salt-broker
-
proxy-httpd
-
proxy-tftpd
-
proxy-squid
-
proxy-ssh
-
9.1. サービスにカスタムコンテナイメージを使用する
By default, the SUSE Multi-Linux Manager Proxy suite is set to use the same image version and registry path for each of its services. However, it is possible to override the default values for a specific service using the install parameters ending with -tag and -image.
たとえば、次のように使用します。
mgrpxy install podman --httpd-tag 0.1.0 --httpd-image registry.opensuse.org/uyuni/proxy-httpd /path/to/config.tar.gz
It adjusts the configuration file for the httpd service, where registry.opensuse.org/uyuni/proxy-httpds is the image to use and 0.1.0 is the version tag, before restarting it.
値をデフォルトにリセットするには、これらのパラメータを指定せずにもう一度installコマンドを実行します。
mgrpxy install podman /path/to/config.tar.gz
このコマンドは、すべてのサービスの設定をグローバルデフォルトにリセットして再ロードします。