将 SUSE Multi-Linux Manager 代理部署为虚拟机 - VMware
本节提供用于将 SUSE Multi-Linux Manager 5.2 代理部署为映像的虚拟机设置。将使用 VMware 作为此安装的沙箱。
1. 可用映像
|
部署 SUSE Multi-Linux Manager 代理的首选方法是使用以下可用映像之一。所有工具都已包含在这些映像中,因而大大简化了部署。 |
SUSE Multi-Linux Manager 5.2 代理的映像可在 SUSE Multi-Linux Manager 5.2 VM 映像中找到。
|
自定义的 SUSE Multi-Linux Manager 5.2 VM 映像仅适用于 SL Micro 6.2。要在 SUSE Linux Enterprise Server 15 SP7 上运行该产品,请使用从 https://www.suse.com/download/sles/ 获取的标准 SUSE Linux Enterprise Server 15 SP7 安装媒体,并在其上启用 SUSE Multi-Linux Manager 5.2 扩展。 |
|
For more information on preparing raw images, see https://documentation.suse.com/sle-micro/6.2/html/Micro-deployment-raw-images-virtual-machines/index.html#deployment-preparing-configuration-device. For additional information on the self install images, see https://documentation.suse.com/sle-micro/6.2/html/Micro-deployment-selfinstall-images/index.html |
| 体系结构 | 映像格式 |
|---|---|
aarch64 |
qcow2、vmdk |
x86_64 |
qcow2、vmdk、raw、Self Installer |
2. 虚拟机设置 - VMware
本节说明 VMware 配置,重点介绍如何在 VMware 环境中创建对 SUSE Multi-Linux Manager 代理存储分区至关重要的额外虚拟磁盘。
|
本节指定了最低要求。这些要求适用于快速测试安装,例如包含一个客户端的代理。 如果您想要使用生产环境,并且需要有关磁盘空间的背景信息,请参见 硬件要求。 |
-
Download SUSE Multi-Linux Manager Proxy
.vmdkfile then transfer a copy to your VMware storage. -
Make a copy of uploaded
.vmdkfile using VMware web interface. This will convert provided.vmdkfile to the format suitable for vSphere hypervisor. -
Create and name a new virtual machine based on the Guest OS Family
Linuxand Guest OS Version SUSE Linux Enterprise 15 (64-bit). -
Add an additional
Hard Disk 2of 100 GB (or more). -
配置满足最低要求的 RAM 和 CPU 数量。*)
-
根据需要设置网络适配器。
-
启动 VM,然后按照首次引导对话框中的提示操作(键盘布局、许可协议、时区、root 的口令)。
-
安装完成后,以 root 身份登录。
-
继续阅读下一节。
3. 注册 SL Micro 和 SUSE Multi-Linux Manager 5.2 代理
-
引导虚拟机。
-
以
root身份登录。 -
在 SCC 中注册 SL Micro。
transactional-update register -r <注册代码> -e <您的电子邮件地址>
-
重引导。
-
在 SUSE Customer Center 中注册 SUSE Multi-Linux Manager 5.2 代理。
transactional-update register -p Multi-Linux-Manager-Proxy/5.2/x86_64 -r <REGCODE>
-
重引导。
-
更新系统:
transactional-update
-
如果已应用更新,请重引导。
-
This step is optional. However, if custom persistent storage is required for your infrastructure, use the
mgr-storage-proxytool. For more information, seemgr-storage-proxy --help. This tool simplifies creating the container volumes.-
如下所示使用命令:
mgr-storage-proxy <存储磁盘设备>
例如:
mgr-storage-proxy /dev/nvme1n1
This command will move the persistent storage volumes at
/var/lib/containers/storage/volumesto the specified storage device.有关详细信息,请参见
-
4. 为代理创建激活密钥
导航到,然后单击 创建密钥。
为代理主机创建激活密钥,并使用 SL Micro 6.2 或 SUSE Linux Enterprise Server 15 SP7 作为父通道。该密钥应包含所有建议的通道,并包含代理作为扩展子通道。
Proceed to boostrapping the proxy host as a
defaultclient.
|
Ensure the Proxy is assigned only to original vendor channels. Assigning cloned channels is not supported at this moment. |
5. 生成代理配置
SUSE Multi-Linux Manager 代理的配置归档由 SUSE Multi-Linux Manager 服务器生成。每个附加代理都需要自身的配置归档。
对于容器化 SUSE Multi-Linux Manager 代理,您必须构建新的代理配置文件,然后重新部署容器以使更改生效。此流程适用于更新设置(包括 SSL 证书)。
|
对于 Podman 部署,在生成此代理配置之前,必须将 SUSE Multi-Linux Manager 代理的容器主机作为客户端注册到 SUSE Multi-Linux Manager 服务器。 |
If a proxy FQDN is used to generate a proxy container configuration that is not a registered client (as in the Kubernetes use case), a new system entry will appear in system list. This new entry will be shown under previously entered Proxy FQDN value and will be of Foreign system type.
|
Peripheral servers are always using third-party SSL certificates. If the hub server has generated the certificates for the peripheral server, it needs to generate the certificate of each proxy too. On the hub server, run the following command.
需要使用的文件包括:
|
5.1. 使用 Web UI 生成代理配置
在 Web UI 中,导航到,然后填写所需数据:
In the
Proxy FQDNfield type fully qualified domain name for the proxy.In the
Parent FQDNfield type fully qualified domain name for the SUSE Multi-Linux Manager Server or another SUSE Multi-Linux Manager Proxy.In the
Proxy SSH portfield type SSH port on which SSH service is listening on SUSE Multi-Linux Manager Proxy. Recommended is to keep default 8022.In the
Max Squid cache size [MB]field type maximal allowed size for Squid cache. Recommended is to use at most 80% of available storage for the containers.
2 GB 表示默认的代理 squid 缓存大小。需要根据您的环境调整此大小。
In the
SSL certificateselection list choose if a new server certificate should be generated for SUSE Multi-Linux Manager Proxy, an existing one should be used, or the SSL part should be skipped entirely. You can consider generated certificates as SUSE Multi-Linux Manager builtin (self signed) certificates. If SUSE Multi-Linux Manager server runs on Kubernetes, the generated certificate option is not possible and replaced with no SSL certificate as they are managed outside the containers.Depending on the choice then provide either path to signing CA certificate to generate a new certificate or path to an existing certificate and its key to be used as proxy certificate. If the SSL part is skipped, the resulting configuration archive does not carry
server_crt,server_keyorca_crt; the deployment is then responsible for providing the proxy certificate and root CA out-of-band (for Kubernetes deployments this means creatingproxy-certanduyuni-camanually — see the TLS setup section of the Kubernetes proxy deployment page).The CA certificates generated by the server are stored in the
/var/lib/containers/storage/volumes/root/_data/ssl-builddirectory.有关现有或自定义证书的详细信息以及企业和中间证书的概念,请参见 导入 SSL 证书。
Click Generate to register a new proxy FQDN in the SUSE Multi-Linux Manager Server and generate a configuration archive (
config.tar.gz) containing details for the container host.片刻之后,系统会显示文件可供下载。请将此文件保存在本地。
5.2. Generate Proxy Configuration With spacecmd and Self-Signed Certificate
You can generate a Proxy configuration using spacecmd. This is only possible if SUSE Multi-Linux Manager server runs on podman and has a self-signed root CA certificate.
通过 SSH 连接到您的容器主机。
执行以下命令(替换其中的服务器和代理 FQDN):
mgrctl exec -ti 'spacecmd proxy_container_config_generate_cert -- dev-pxy.example.com dev-srv.example.com 2048 email@example.com -o /tmp/config.tar.gz'从服务器容器复制生成的配置:
mgrctl cp server:/tmp/config.tar.gz
5.3. Generate Proxy Configuration With spacecmd and Custom Certificate
You can generate a Proxy configuration using spacecmd for custom certificates rather than the default self-signed certificates.
通过 SSH 连接到您的服务器容器主机。
Execute the following commands, replacing the Server and Proxy FQDN:
for f in ca.crt proxy.crt proxy.key; do mgrctl cp $f server:/tmp/$f done mgrctl exec -ti 'spacecmd proxy_container_config -- -p 8022 pxy.example.com srv.example.com 2048 email@example.com /tmp/ca.crt /tmp/proxy.crt /tmp/proxy.key -o /tmp/config.tar.gz'如果您的设置使用中间 CA,请同时复制该证书,并在命令中通过
-i选项(可根据需要多次提供)包含该证书:mgrctl cp intermediateCA.pem server:/tmp/intermediateCA.pem mgrctl exec -ti 'spacecmd proxy_container_config -- -p 8022 -i /tmp/intermediateCA.pem pxy.example.com srv.example.com 2048 email@example.com /tmp/ca.crt /tmp/proxy.crt /tmp/proxy.key -o /tmp/config.tar.gz'从服务器容器复制生成的配置:
mgrctl cp server:/tmp/config.tar.gz
5.4. Generate Proxy Configuration With spacecmd and no Certificate
You can generate a Proxy configuration using spacecmd with no TLS certificates. This is needed for SUSE Multi-Linux Manager running on Kubernetes as the certificates are handled outside of the containers.
通过 SSH 连接到您的服务器容器主机。
Execute the following commands, replacing the Server and Proxy FQDN:
for f in ca.crt proxy.crt proxy.key; do mgrctl cp $f server:/tmp/$f done mgrctl exec -ti 'spacecmd proxy_container_config_nossl -- -p 8022 pxy.example.com srv.example.com 2048 email@example.com -o /tmp/config.tar.gz'从服务器容器复制生成的配置:
mgrctl cp server:/tmp/config.tar.gz
6. 传输代理配置
Web UI 将生成配置归档。需要在代理容器主机上提供此归档。
If not already done, copy the configuration archive (
config.tar.gz) generated in the previous step from the server container to the server host:mgrctl cp server:/root/config.tar.gz将服务器主机中的文件复制到代理主机(如果还未执行此操作):
scp config.tar.gz <代理 FQDN>:/root
7. 启动 SUSE Multi-Linux Manager 5.2 代理
Container can now be started with the mgrpxy command:
-
调用以下命令启动代理:
mgrpxy start
-
调用以下命令检查容器状态:
mgrpxy status
Five SUSE Multi-Linux Manager Proxy containers should be present and should be part of the
proxy-podcontainer pod:-
proxy-salt-broker
-
proxy-httpd
-
proxy-tftpd
-
proxy-squid
-
proxy-ssh
-
7.1. 为服务使用自定义容器映像
By default, the SUSE Multi-Linux Manager Proxy suite is set to use the same image version and registry path for each of its services. However, it is possible to override the default values for a specific service using the install parameters ending with -tag and -image.
例如,可以按如下方式使用此命令:
mgrpxy install podman --httpd-tag 0.1.0 --httpd-image registry.opensuse.org/uyuni/proxy-httpd /path/to/config.tar.gz
It adjusts the configuration file for the httpd service, where registry.opensuse.org/uyuni/proxy-httpds is the image to use and 0.1.0 is the version tag, before restarting it.
要重置为默认值,请再次运行 install 命令但不要指定这些参数:
mgrpxy install podman /path/to/config.tar.gz
此命令首先将所有服务的配置重置为全局默认值,然后重新装载配置。