连接 PAYG 实例
In the major public cloud providers (AWS, Azure), SUSE:
-
提供 SLES、SLES for SAP 等产品的自定义 PAYG 产品映像。
-
为以 PAYG 形式提供的产品操作按区域 RMT 服务器镜像储存库
本文介绍如何将现有 PAYG 实例连接到 SUSE Multi-Linux Manager 服务器,并提供了有关从实例收集身份凭证的基本信息。此类连接是为了提取身份验证数据,以使 SUSE Multi-Linux Manager 服务器能够连接到云 RMT 主机。之后,SUSE Multi-Linux Manager 服务器便可以访问 RMT 主机上尚未提供 SCC 组织身份凭证的产品。
在使用 PAYG 功能之前,请确保:
-
PAYG 实例是从正确的 SUSE 产品映像(例如 SLES、SLES for SAP、SLE HPC)启动的,以便能够访问所需储存库
-
SUSE Multi-Linux Manager 服务器可以直接或通过堡垒连接到 PAYG 实例(最好位于同一区域)
-
已配置基本的 SCC 帐户。请在中输入您的有效 SCC 身份凭证。无论要引导的是哪个 PAYG 实例,都需要使用此帐户来访问 SUSE Multi-Linux Manager 客户端工具。
-
If you bootstrap the PAYG instance to SUSE Multi-Linux Manager, it will disable its PAYG repositories then add repositories from where it mirrored the data from the RMT server. The final result will be PAYG instances acquiring the same repositories from the RMT servers but through the SUSE Multi-Linux Manager server itself. Of course repositories can still be setup primarily from SCC.
1. 连接 PAYG 实例
-
在 SUSE Multi-Linux Manager Web UI 中,导航到,然后单击 添加 PAYG。
-
Start with the page section
PAYG connection Description. -
In the
Descriptionfield, add the description. -
Move to the page section
Instance SSH connection data. -
In the
Hostfield, enter the instance DNS or IP address to connect from SUSE Multi-Linux Manager. -
In the
SSH Portfield, enter the port number or use default value 22. -
In the
Userfield, enter the username as specified in the cloud. -
In the
Passwordfield, enter the password. -
In the
SSH Private Keyfield, enter the instance key. -
In the
SSH Private Key Passphrasefield, enter the key passphrase.
|
身份验证密钥必须采用 PEM 格式。 |
如果您要通过 SSH 堡垒连接实例而不是直接连接,请执行过程:添加 SSH 堡垒连接数据。
否则,请执行过程:完成 PAYG 连接。
-
Navigate to the page section
Bastion SSH connection data. -
In the
Hostfield, enter the bastion hostname. -
In the
SSH Portfield, enter the bastion port number. -
In the
Userfield, enter the bastion username. -
In the
Passwordfield, enter the bastion password. -
In the
SSH Private Keyfield, enter the bastion key. -
In the
SSH Private Key Passphrasefield, enter the bastion key passphrase.
Complete the setup process with 过程:完成 PAYG 连接.
-
要完成添加新 PAYG 连接数据的过程,请单击 创建。
-
Return to PAYG connection data
Detailspage. The updated connection status is displayed on the top section namedInformation. -
Connection status is shown in
Admin > Setup Wizard > Pay-as-you-goscreen too. -
If the authentication data for the instance are correct, the column
Statusshows "Credentials successfully updated."
|
If the invalid data are entered at any point, the newly created instance is shown in |
一旦服务器上有可用的身份验证信息,可用产品列表即会更新。
Available products are all versions of the same product family and architecture as the one installed in the PAYG instance. For example, if the instance has the SUSE Linux Enterprise Server 15 SP1 product installed, SUSE Linux Enterprise Server 15 SP2, SUSE Linux Enterprise Server 15 SP3, SUSE Linux Enterprise Server 15 SP4 and SUSE Linux Enterprise Server 15 SP5 are automatically shown in Admin > Setup Wizard > Products.
当有产品显示为可用时,用户便可选中该产品名称旁边的复选框并单击 添加产品,将产品添加到 SUSE Multi-Linux Manager 中。
After the success message you can verify the newly added channels in the Web UI, by navigating to Software > Channel List > All.
To monitor the syncing progress of each channel, check the log files in the /var/log/rhn/reposync directory on the SUSE Multi-Linux Manager Server.
|
如果 PAYG 实例和某个 SCC 订阅都提供了某个产品,该产品在产品列表中只会显示一次。 同步属于该产品的通道后,相关数据可能仍会来自 SCC 订阅,而不会来自 Pay-As-You-Go 实例。 |
2. 实例身份凭证收集状态
SUSE Multi-Linux Manager 服务器使用从实例收集的身份凭证来连接 RMT 服务器,并通过 reposync 下载软件包。Taskomatic 会使用定义的 SSH 连接数据每 10 分钟刷新一次这些身份凭证。RMT 服务器连接始终使用从 PAYG 实例收集的最新已知身份验证身份凭证。
The status of the PAYG instance credentials collect is shown in the column Status or on the instance details page. When the instance is not reachable, the credential update process will fail.
如果无法访问实例,身份凭证更新过程将会失败,并且在刷新操作第二次失败后,身份凭证将变成无效状态。当身份凭证无效后,通道的同步将会失败。为了避免出现此问题,请让连接的实例保持运行状态。
除非明确删除了 SSH 连接数据,否则 PAYG 实例将始终连接到 SUSE Multi-Linux Manager 服务器。要删除实例的 SSH 连接数据,请执行 [proc-deleting-connection-data-to-instance]。
并非在任何时间都可从 SUSE Multi-Linux Manager 服务器访问 PAYG 实例。
-
如果实例存在但已停止,系统将使用最新的已知身份凭证尝试连接实例。 身份凭证的有效时长取决于云提供商。
-
如果实例不再存在,但在 SUMA 中仍保持注册状态,其身份凭证将不再有效,身份验证将会失败。 “状态”列中会显示错误消息。
错误消息只会指出实例不再可用。云提供商需要对实例的状态进行进一步诊断。
|
在 PAYG 实例中进行以下任意操作或更改都将导致身份凭证失效:
* 去除 zypper 身份凭证文件
* 去除导入的证书
* removing cloud-specific entries from |
3. 将 PAYG 系统注册为客户端
您可以将从中收集身份凭证的 PAYG 实例注册为 Salt 客户端。需要为实例注册有效的云连接,否则它将无法访问通道。如果用户去除相关云软件包,身份凭证收集可能会停止工作。
首先,将 PAYG 实例设置为收集身份验证数据,以使其可以同步通道。
该过程的其余步骤与非公有云客户端的步骤相同,包括同步通道、自动创建引导脚本、创建激活密钥,以及启动注册。
有关注册客户端的详细信息,请参见 客户端注册。
4. 查错
- 检查身份凭证
-
-
如果脚本无法收集身份凭证,将会在日志和 Web UI 中提供正确的错误消息。
-
If the credentials are not working,
reposyncshould show the proper error.
-
- Using
registercloudguest -
-
Refreshing or changing the
registercloudguestconnection to the public cloud update infrastructure should not interfere with the credentials usage. -
Running
registercloudguest --cleanwill cause problems if no new cloud connection is registered with the cloud guest command.
-