openSUSE Leap Micro 6.1へのSUSE Multi-Linux Managerプロキシの配備

このガイドでは、SUSE Multi-Linux Manager 5.1プロキシの配備プロセスの概要について説明します。このガイドでは、SUSE Multi-Linux Manager 5.1サーバが正常に配備済みであることを想定しています。正常に配備するには、次のアクションを実行します。

チェックリスト: プロキシの配備
  1. ハードウェア要件を確認します。

  2. openSUSE Leap Micro 6.1をベアメタルマシンにインストールします。

  3. プロキシをSalt Minionとしてブートストラップします。

  4. プロキシ設定を生成します。

  5. サーバからプロキシへのプロキシ設定の転送

  6. プロキシ設定を使用して、Salt MinionをプロキシとしてSUSE Multi-Linux Managerに登録します。

プロキシコンテナホストでサポートされるオペレーティングシステム

コンテナホストでサポートされているオペレーティングシステムはopenSUSE Leap Micro 6.1です。

コンテナホスト

コンテナホストは、コンテナを管理および配備できるPodmanなどのコンテナエンジンを搭載したサーバです。これらのコンテナは、アプリケーションと、ライブラリなどの重要な部品を保持しますが、完全なオペレーティングシステムは保持しないため軽量です。このセットアップにより、アプリケーションは異なる環境でも同じように動作します。CPU、メモリ、ストレージなど、これらのコンテナに必要なリソースはコンテナホストが提供します。

1. プロキシのハードウェア要件

次の表に、SUSE Multi-Linux Managerプロキシを配備するためのハードウェア要件を示します。

Table 1. プロキシのハードウェア要件
Hardware Details Recommendation

CPU

x86-64, ARM

Minimum 2 dedicated 64-bit CPU cores

RAM

Minimum

2 GB

Recommended

8 GB

Disk Space

/ (root directory)

Minimum 40 GB

/var/lib/containers/storage/volumes

Minimum 100 GB, Storage requirements should be calculated for the number of ISO distribution images, containers, and bootstrap repositories you will use.

2. コンテナホストの一般的な要件

一般的な要件については、一般的な要件を参照してください。

openSUSE Leap Micro 6.1サーバはインストールメディアからインストールする必要があります。この手順については、以下で説明します。

3. コンテナホストの要件

CPU、RAM、およびストレージの要件については、ハードウェア要件を参照してください。

クライアントがFQDNドメイン名を解決できることを保証するには、コンテナ化されたプロキシとホストマシンの両方が、機能しているDNSサーバにリンクされている必要があります。さらに、リバース参照が正しく設定されていることを確認することも重要です。

4. コンテナで使用するためにUyuniツールをインストールする

プロシージャ: UyuniツールをopenSUSE Leap Micro 6.1にインストールする
  1. ローカルホストで、端末のウィンドウを開くか、openSUSE Leap Micro 6.1が実行される仮想マシンを起動します。

  2. ログインします。

  3. Enter the transactional-update shell:

    transactional-update shell
  4. 次のリポジトリをopenSUSE Leap Micro 6.1サーバに追加します。

    zypper ar https://download.opensuse.org/repositories/systemsmanagement:/Uyuni:/Stable/images/repo/Uyuni-Proxy-POOL-$(arch)-Media1/ uyuni-proxy-stable
  5. リポジトリのリストを更新してキーを受け入れます。

    zypper ref
  6. コンテナツールをインストールします。

    zypper in mgrpxy mgrpxy-bash-completion uyuni-storage-setup-proxy

    Alternatively you may install mgrpxy-zsh-completion or mgrpxy-fish-completion.

  7. トランザクションシェルを終了します。

    transactional update # exit
  8. ホストを再起動します。

Uyuniコンテナユーティリティの詳細については、Uyuniコンテナユーティリティを参照してください。

5. カスタム永続ストレージの設定

This step is optional. However, if custom persistent storage is required for your infrastructure, use the mgr-storage-proxy tool.

For more information, see mgr-storage-proxy --help. This tool simplifies creating the container storage and Squid cache volumes.

このコマンドは次のように使用します。

mgr-storage-proxy <storage-disk-device>

例:

mgr-storage-proxy /dev/nvme1n1

This command will create the persistent storage volumes at /var/lib/containers/storage/volumes.

詳細については、以下を参照してください。

6. Minionとしてのプロキシホストのブートストラップ

タスク: プロキシホストのブートストラップ
  1. システム  ブートストラップを選択します。

  2. プロキシホストのフィールドに入力します。

  3. ドロップダウンから、前のステップで作成したアクティベーションキーを選択します。

  4. + ブートストラップをクリックします。

  5. ブートストラッププロセスが正常に完了するまで待ちます。Saltメニューをチェックし、Salt Minionキーが一覧表示されていて受け入れられていることを確認します。

  6. プロキシホストを再起動します。

  7. すべてのイベントが終了したら、システムの一覧からホストを選択して2回目の再起動をトリガし、オンボーディングを完了します。

タスク: プロキシホストの更新
  1. システムの一覧からホストを選択し、すべてのパッチを適用してホストを更新します。

  2. プロキシホストを再起動します。

7. プロキシ設定の生成

SUSE Multi-Linux Managerプロキシの設定アーカイブはSUSE Multi-Linux Managerサーバによって生成されます。追加のプロキシごとに専用の設定アーカイブが必要です。

このプロキシ設定を生成する前に、SUSE Multi-Linux ManagerプロキシのコンテナホストをSalt MinionとしてSUSE Multi-Linux Managerサーバに登録する必要があります。

次のタスクを実行します。

プロシージャ:
  1. プロキシ設定ファイルを生成します。

  2. 設定をプロキシに転送します。

  3. Start the Proxy with the mgrpxy command.

タスク: Web UIを使用したプロキシコンテナ設定の生成
  1. Web UIで、システム  プロキシの設定に移動し、必要なデータを入力します。

  2. In the Proxy FQDN field type fully qualified domain name for the proxy.

  3. In the Parent FQDN field type fully qualified domain name for the SUSE Multi-Linux Manager Server or another SUSE Multi-Linux Manager Proxy.

  4. In the Proxy SSH port field type SSH port on which SSH service is listening on SUSE Multi-Linux Manager Proxy. Recommended is to keep default 8022.

  5. In the Max Squid cache size [MB] field type maximal allowed size for Squid cache. Typically this should be at most 60% of available storage for the containers. In the SSL certificate selection list choose if new server certificate should be generated for SUSE Multi-Linux Manager Proxy or an existing one should be used. You can consider generated certificates as SUSE Multi-Linux Manager builtin (self signed) certificates.

    選択に応じて、新しい証明書を生成するための署名CA証明書へのパス、またはプロキシ証明書として使用される既存の証明書とそのキーへのパスのいずれかを指定します。

    The CA certificates generated on the server are stored in the /var/lib/containers/storage/volumes/root/ssl-build directory.

    既存の証明書またはカスタム証明書、および企業証明書と中間証明書の概念の詳細については、SSL証明書のインポートを参照してください。

  6. 生成をクリックして、SUSE Multi-Linux Managerサーバに新しいプロキシFQDNを登録し、コンテナホストの詳細を含む設定アーカイブを生成します。

  7. しばらくすると、ダウンロードするファイルが表示されます。このファイルをローカルに保存します。

8. プロキシ設定の転送

Web UIで、設定アーカイブが生成されます。このアーカイブは、コンテナホストで利用できるようにする必要があります。

タスク: プロキシ設定のコピー
  1. サーバコンテナからサーバのホストOSにファイルをコピーします。

    mgrctl cp server:/root/config.tar.gz .
  2. サーバのホストOSからプロキシホストにファイルをコピーします。

    scp config.tar.gz <proxy-FQDN>:/root
  3. 次のコマンドを使用してプロキシをインストールします。

    mgrpxy install podman config.tar.gz

9. SUSE Multi-Linux Manager 5.1プロキシの起動

Container can now be started with the mgrpxy command:

タスク: プロキシの起動とステータスの確認
  1. 次のコマンドを呼び出してプロキシを起動します。

    mgrpxy start
  2. 次のコマンドを呼び出してコンテナのステータスを確認します。

    mgrpxy status

    Five SUSE Multi-Linux Manager Proxy containers should be present and should be part of the proxy-pod container pod:

    • proxy-salt-broker

    • proxy-httpd

    • proxy-tftpd

    • proxy-squid

    • proxy-ssh

9.1. サービスにカスタムコンテナイメージを使用する

By default, the SUSE Multi-Linux Manager Proxy suite is set to use the same image version and registry path for each of its services. However, it is possible to override the default values for a specific service using the install parameters ending with -tag and -image.

たとえば、次のように使用します。

mgrpxy install podman --httpd-tag 0.1.0 --httpd-image registry.opensuse.org/uyuni/proxy-httpd /path/to/config.tar.gz

It adjusts the configuration file for the httpd service, where registry.opensuse.org/uyuni/proxy-httpds is the image to use and 0.1.0 is the version tag, before restarting it.

値をデフォルトにリセットするには、これらのパラメータを指定せずにもう一度installコマンドを実行します。

mgrpxy install podman /path/to/config.tar.gz

このコマンドは、すべてのサービスの設定をグローバルデフォルトにリセットして再ロードします。