SUSE Multi-Linux Manager Proxy Deployment

本指南将简要介绍在 SL Micro 6.1 或 SUSE Linux Enterprise Server 15 SP7 上部署 SUSE Multi-Linux Manager 5.1 代理容器的过程,并假定您已成功部署 SUSE Multi-Linux Manager 5.1 服务器。

SL Micro is only supported as regular minion (default contact method) for the time being. We are working on managing it as Salt SSH client (salt-ssh contact method), too.

It is possible to convert existing client to proxy. For more information, see 将客户端转换为 MLM 代理.

To successfully deploy a new proxy, follow the procedure:

Procedure: Deploying proxy
  1. 查看硬件要求。

  2. 在服务器上同步 SL Micro 6.1 或 SUSE Linux Enterprise Server 15 SP7 父通道和代理扩展子通道。

  3. 在裸机上安装 SL Micro 或 SUSE Linux Enterprise Server。

  4. 创建带有代理扩展的 Salt 激活密钥。

  5. Bootstrap the proxy as a client with the default connection method.

  6. 生成代理配置。

  7. 将服务器中的代理配置传输到代理。

  8. 在代理上安装软件包。

  9. 使用代理配置将客户端作为代理注册到 SUSE Multi-Linux Manager。

代理容器主机支持的操作系统

容器主机支持的操作系统为 SL Micro 6.1 和 SUSE Linux Enterprise Server 15 SP7。

容器主机

容器主机是配备了容器引擎(例如 Podman)的服务器,可用于管理和部署容器。这些容器包含应用程序及其必备组件(例如库),但不包含完整的操作系统,因此体量很小。此设置可确保应用程序能够在不同环境中以一致的方式运行。容器主机为这些容器提供必要的资源,例如 CPU、内存和存储。

1. Hardware requirements for the proxy

有关部署 SUSE Multi-Linux Manager 代理的硬件要求,请参见 installation-and-upgrade:hardware-requirements.adoc#proxy-hardware-requirements

2. Synchronize the parent and proxy extension child channels

This section presumes that you have already entered your organization credentials under the Admin  Setup Wizard  Organization Credentials in the server’s Web UI. Products are listed on the Admin  Setup Wizard  Products page. This channel must be fully synchronized on the server, with the child channel Proxy as an extension option selected.

Procedure: Synchronizing the parent channel and proxy extension
  1. 在 SUSE Multi-Linux Manager Web UI 中,选择管理  产品

  2. 在产品页面上的过滤字段中输入 SL Micro 或 SUSE Linux Enterprise Server。

  3. 接下来,在下拉列表中选择所需的体系结构,在本示例中为 x86-64。

  4. In the Product Description field select the SL Micro 6.1 or SUSE Linux Enterprise Server 15 SP7 checkbox then use the drop-down to select the SUSE Multi-Linux Manager Proxy Extension 5.1 x86_64 extension.

  5. 单击 添加产品 按钮。

  6. 等待同步完成。

3. Prepare the SUSE Multi-Linux Manager proxy host

在下面的小节中,您需要准备 SLE Micro 或 SUSE Linux Enterprise Server 代理主机。

3.1. 准备 SL Micro 6.1 主机

3.1.1. 下载安装媒体

过程:下载安装媒体
  1. 访问 https://www.suse.com/download/sle-micro/,找到 SL Micro 6.1 的安装媒体,并下载相应媒体文件。

  2. Prepare a DVD or USB flash drive with the downloaded .iso image for installation.

3.1.2. 安装 SL Micro 6.1

有关虚拟机或物理机的准备工作详细信息,请参见 SL Micro 部署指南

过程:安装 SL Micro 6.1
  1. 插入包含 SLE Micro 6.1 安装映像的 DVD 或 USB 闪存盘(USB 磁盘或密钥)。

  2. 引导或重引导您的系统。

  3. Use the arrow keys to select Installation.

  4. 调整键盘和语言。

  5. Click the checkbox to accept the license agreement.

  6. Click Next to continue.

  7. 跳过注册步骤。SL Micro 6.1 权利已包含在 SUSE Multi-Linux Manager 权利中,因此不需要单独的注册代码。

  8. 单击 下一步 继续。

  9. On the NTP Configuration page click Next.

  10. On the Authentication for the System page enter a password for the root user. Click Next.

  11. On the Installation Settings page click Install.

将 SL Micro 6.1 和 SUSE Multi-Linux Manager 5.1 安装为扩展的过程到此完成。

3.1.3. 更新系统

过程:更新系统
  1. root 身份登录。

  2. 运行 transactional-update

    transactional-update
  3. 重引导。

SL Micro 设计为默认自动更新,并会在应用更新后重引导。但是,这种行为对于 SUSE Multi-Linux Manager 环境而言是不利的。为了防止服务器自动更新,SUSE Multi-Linux Manager 会在引导过程中禁用 transactional-update 计时器。

如果您希望保留 SL Micro 的默认行为,请运行以下命令来启用计时器:

systemctl enable --now transactional-update.timer

要继续部署,请参见 Configure custom persistent storage

3.2. 准备 SUSE Linux Enterprise Server 15 SP7 主机

或者,您也可以在 SUSE Linux Enterprise Server 15 SP7 上部署 SUSE Multi-Linux Manager。

下面的过程介绍安装流程的主要步骤。

3.2.1. 在 SUSE Linux Enterprise Server 上安装 SUSE Multi-Linux Manager 扩展

过程:在 SUSE Linux Enterprise Server 上安装 SUSE Multi-Linux Manager 扩展
  1. Locate and download SUSE Linux Enterprise Server 15 SP7 .iso at https://www.suse.com/download/sles/.

  2. 确保您拥有主机操作系统 (SUSE Linux Enterprise Server 15 SP7) 和扩展的注册代码

  3. 启动 SUSE Linux Enterprise Server 15 SP7 的安装流程。

    1. On the Language, keyboard and product selection select the product to install.

    2. On the License agreement read the agreement and check I Agree to the License Terms.

  4. 跳过注册步骤。

  5. Click Next to continue.

    请注意,对于 SUSE Linux Enterprise Server 15 SP7,您需要在服务器上配置有效的 SUSE Linux Enterprise Server 订阅。

  6. In the screen Extensions and Modules Selection check the following:

    • Basesystem 模块

    • Containers 模块

  7. 单击 下一步 继续。

  8. 完成安装。

  9. 安装完成后,以 root 身份登录新安装的服务器。

  10. 更新系统(可选,如果在安装期间未将系统设置为自动下载更新):

    zypper up
  11. 重引导。

要继续部署,请参见 Configure custom persistent storage

4. Configure custom persistent storage

Configuring persistent storage is optional, but it is the only way to avoid serious trouble with container full disk conditions. If custom persistent storage is required for your infrastructure, use the mgr-storage-proxy tool.

For more information, see mgr-storage-proxy --help. This tool simplifies creating the container storage and Squid cache volumes.

如下所示使用命令:

mgr-storage-proxy <存储磁盘设备>

例如:

mgr-storage-proxy /dev/nvme1n1

This command will create the persistent storage volumes at /var/lib/containers/storage/volumes.

有关详细信息,请参见

5. 为代理创建激活密钥

过程:创建激活密钥
  1. 导航到系统  激活密钥,然后单击 创建密钥

  2. Create an activation key for the proxy host with SL Micro 6.1 or SUSE Linux Enterprise Server 15 SP7 as the parent channel. This key should include all recommended channels and the proxy as an extension child channel.

  3. Proceed to boostrapping the proxy host as a default client.

Ensure the Proxy is assigned only to original vendor channels.

Assigning cloned channels is not supported at this moment.

6. 将代理主机作为客户端进行引导

过程:引导代理主机
  1. 选择系统  引导

  2. 填写代理主机的相关字段。

  3. 从下拉列表中选择上一步骤中创建的激活密钥。

  4. 单击 引导

  5. 等待引导过程成功完成。检查 Salt 菜单,确认 Salt 密钥已列出并已接受。

  6. 如果操作系统是 SL Micro,则重引导代理主机。

  7. 系统列表中选择主机,并在所有事件完成后再次触发重引导(如果是 SL Micro 系统)以完成初始配置。

过程:更新代理主机
  1. 系统列表中选择主机,并应用所有补丁以将其更新。

  2. 如果操作系统是 SL Micro,则重引导代理主机。

7. 生成代理配置

SUSE Multi-Linux Manager 代理的配置归档由 SUSE Multi-Linux Manager 服务器生成。每个附加代理都需要自身的配置归档。

对于容器化 SUSE Multi-Linux Manager 代理,您必须构建新的代理配置文件,然后重新部署容器以使更改生效。此流程适用于更新设置(包括 SSL 证书)。

对于 Podman 部署,在生成此代理配置之前,必须将 SUSE Multi-Linux Manager 代理的容器主机作为客户端注册到 SUSE Multi-Linux Manager 服务器。

If a proxy FQDN is used to generate a proxy container configuration that is not a registered client (as in the Kubernetes use case), a new system entry will appear in system list. This new entry will be shown under previously entered Proxy FQDN value and will be of Foreign system type.

外围服务器始终使用第三方 SSL 证书。如果中心服务器已为外围服务器生成证书,则还需为外围数据库生成证书。在中心服务器上,为每台待迁移的外围服务器运行以下命令。

mgrctl exec -ti -- rhn-ssl-tool --gen-server --dir="/root/ssl-build" --set-country="COUNTRY" \
  --set-state="STATE" --set-city="CITY" --set-org="ORGANIZATION" \
  --set-org-unit="ORGANIZATION UNIT" --set-email="name@example.com" \
  --set-hostname=PROXY --set-cname="proxy.example.com"

需要使用的文件包括: * /root/ssl-build/RHN-ORG-TRUSTED-SSL-CERT as the root CA, * /root/ssl-build/<hostname>/server.crt as the proxy certificate and * /root/ssl-build/<hostname>/server.key as the proxy certificate’s key.

7.1. 使用 Web UI 生成代理配置

过程:使用 Web UI 生成代理容器配置
  1. 在 Web UI 中,导航到系统  代理配置,然后填写所需数据。

  2. In the Proxy FQDN field type fully qualified domain name for the proxy.

  3. In the Parent FQDN field type fully qualified domain name for the SUSE Multi-Linux Manager Server or another SUSE Multi-Linux Manager Proxy.

  4. In the Proxy SSH port field type SSH port on which SSH service is listening on SUSE Multi-Linux Manager Proxy. Recommended is to keep default 8022.

  5. In the Max Squid cache size [MB] field type maximal allowed size for Squid cache. Recommended is to use at most 80% of available storage for the containers.

    2 GB 表示默认的代理 squid 缓存大小。需要根据您的环境调整此大小。

In the SSL certificate selection list choose if new server certificate should be generated for SUSE Multi-Linux Manager Proxy or an existing one should be used. You can consider generated certificates as SUSE Multi-Linux Manager builtin (self signed) certificates.

+

然后根据所做的选择提供用于生成新证书的签名 CA 证书的路径,或者要用作代理证书的现有证书及其密钥的路径。

+

The CA certificates generated by the server are stored in the /var/lib/containers/storage/volumes/root/_data/ssl-build directory.

+

有关现有或自定义证书的详细信息以及企业和中间证书的概念,请参见 导入 SSL 证书

  1. Click Generate to register a new proxy FQDN in the SUSE Multi-Linux Manager Server and generate a configuration archive (config.tar.gz) containing details for the container host.

  2. 片刻之后,系统会显示文件可供下载。请将此文件保存在本地。

7.2. Generate Proxy Configuration With spacecmd and Self-Signed Certificate

You can generate a Proxy configuration using spacecmd.

过程:使用 spacecmd 和自我签名证书生成代理配置
  1. 通过 SSH 连接到您的容器主机。

  2. 执行以下命令(替换其中的服务器和代理 FQDN):

    mgrctl exec -ti 'spacecmd proxy_container_config_generate_cert -- dev-pxy.example.com dev-srv.example.com 2048 email@example.com -o /tmp/config.tar.gz'
  3. 从服务器容器复制生成的配置:

    mgrctl cp server:/tmp/config.tar.gz .

7.3. Generate Proxy Configuration With spacecmd and Custom Certificate

You can generate a Proxy configuration using spacecmd for custom certificates rather than the default self-signed certificates.

过程:使用 spacecmd 和自定义证书生成代理配置
  1. 通过 SSH 连接到您的服务器容器主机。

  2. 执行以下命令(替换其中的服务器和代理 FQDN):

    for f in ca.crt proxy.crt proxy.key; do
      mgrctl cp $f server:/tmp/$f
    done
    mgrctl exec -ti 'spacecmd proxy_container_config -- -p 8022 pxy.example.com srv.example.com 2048 email@example.com /tmp/ca.crt /tmp/proxy.crt /tmp/proxy.key -o /tmp/config.tar.gz'
  3. 如果您的设置使用中间 CA,请同时复制该证书,并在命令中通过 -i 选项(可根据需要多次提供)包含该证书:

    mgrctl cp intermediateCA.pem server:/tmp/intermediateCA.pem
    mgrctl exec -ti 'spacecmd proxy_container_config -- -p 8022 -i /tmp/intermediateCA.pem pxy.example.com srv.example.com 2048 email@example.com /tmp/ca.crt /tmp/proxy.crt /tmp/proxy.key -o /tmp/config.tar.gz'
  4. 从服务器容器复制生成的配置:

    mgrctl cp server:/tmp/config.tar.gz .

8. 传输代理配置

Web UI 将生成配置归档。需要在代理容器主机上提供此归档。

过程:复制代理配置
  1. If not already done, copy the configuration archive (config.tar.gz) generated in the previous step from the server container to the server host:

    mgrctl cp server:/root/config.tar.gz .
  2. 将服务器主机中的文件复制到代理主机(如果还未执行此操作):

    scp config.tar.gz <代理 FQDN>:/root

9. 安装软件包并启用 podman

Before using proxy, some packages need to be present on host and podman needs to be running.

过程:准备前置条件
  1. 在代理主机上,确保已安装以下软件包:

    • podman

    • mgrpxy-bash-completion

    • suse-multi-linux-manager-5.1-x86_64-proxy-httpd-image

    • suse-multi-linux-manager-5.1-x86_64-proxy-salt-broker-image

    • suse-multi-linux-manager-5.1-x86_64-proxy-squid-image

    • suse-multi-linux-manager-5.1-x86_64-proxy-ssh-image

    • suse-multi-linux-manager-5.1-x86_64-proxy-tftpd-image

  2. 重引导系统或运行以下命令,启动代理主机上的 Podman 服务:

    systemctl enable --now podman.service
  3. 在代理主机上使用以下命令安装代理:

    mgrpxy install podman config.tar.gz

10. Start the SUSE Multi-Linux Manager proxy

Container can now be started with the mgrpxy command:

过程:启动代理并检查状态
  1. 调用以下命令启动代理:

    mgrpxy start
  2. 调用以下命令检查容器状态:

    mgrpxy status

    Five SUSE Multi-Linux Manager Proxy containers should be present and should be part of the proxy-pod container pod:

    • proxy-salt-broker

    • proxy-httpd

    • proxy-tftpd

    • proxy-squid

    • proxy-ssh

11. Use a custom container image for a service

By default, the SUSE Multi-Linux Manager Proxy suite is configured to use the same image version and registry path for each of its services. However, it is possible to override the default values for a specific service using the install parameters ending with -tag and -image.

例如:

mgrpxy install podman --httpd-tag 0.1.0 --httpd-image registry.opensuse.org/uyuni/proxy-httpd /path/to/config.tar.gz

It adjusts the configuration file for the httpd service, where registry.opensuse.org/uyuni/proxy-httpds is the image to use and 0.1.0 is the version tag, before restarting it.

要重置为默认值,请再次运行 install 命令但不要指定这些参数:

mgrpxy install podman /path/to/config.tar.gz

此命令首先将所有服务的配置重置为全局默认值,然后重新装载配置。