#mysql -uroot -p000000 >create database neutron; > grant all privileges on neutron.* to 'neutron'@'localhost' identified by '000000'; > grant all privileges on neutron.* to 'neutron'@'%' identified by '000000';
#. /root/admin-openrc
#openstack user create --domain default --password 000000 neutron #openstack role add --project service --user neutron admin #openstack service create --name neutron --description "OpenStack Networking" network
#openstack endpoint create --region RegionOne network public http://controller:9696 #openstack endpoint create --region RegionOne network internal http://controller:9696 #openstack endpoint create --region RegionOne network admin http://controller:9696
#yum -y install openstack-neutron openstack-neutron-ml2 openstack-neutron-linuxbridge ebtables
#vi /etc/neutron/neutron.conf 在 [database] 部分,配置数据库访问: connection = mysql+pymysql://neutron:000000@controller/neutron 在``[DEFAULT]``部分,添加以下内容 core_plugin = ml2 service_plugins = router allow_overlapping_ips = True rpc_backend = rabbit auth_strategy = keystone notify_nova_on_port_status_changes = True notify_nova_on_port_data_changes = True 在[oslo_messaging_rabbit]部分,配置 “RabbitMQ” 消息队列的链接: rabbit_host = controller rabbit_userid = openstack rabbit_password = 000000 在[keystone_authtoken]部分,配置认证服务访问 auth_uri = http://controller:5000 auth_url = http://controller:35357 memcached_servers = controller:11211 auth_type = password project_domain_name = default user_domain_name = default project_name = service username = neutron password = 000000 在[nova]部分,配置网络服务来通知计算节点的网络拓扑变化: auth_url = http://controller:35357 auth_type = password project_domain_name = default user_domain_name = default region_name = RegionOne project_name = service username = nova password = 000000 在 [oslo_concurrency] 部分,配置锁路径: lock_path = /var/lib/neutron/tmp
/etc/neutron/plugins/ml2/ml2_conf.ini
文件,配置启用flat,VLAN,GRE,LOCAL以及VXLAN网络:#vi /etc/neutron/plugins/ml2/ml2_conf.ini 在[ml2]下添加 type_drivers = flat,vlan,vxlan,gre,local tenant_network_types = vxlan mechanism_drivers = linuxbridge,l2population extension_drivers = port_security 在 [ml2_type_flat] 部分,配置公共虚拟网络为flat网络 flat_networks = provider 在 [ml2_type_vxlan] 部分,为私有网络配置VXLAN网络识别的网络范围: vni_ranges = 1:1000 在 [securitygroup] 部分,启用 ipset 增长安全组规则的高效性: enable_ipset = True
#vi /etc/neutron/plugins/ml2/linuxbridge_agent.ini 在 [linux_bridge] 部分,将公共虚拟网络和公共物理网络接口对应起来: physical_interface_mappings = provider:eth1 #注意,此处的eth1为基础环境配置中的200的网段 也就是 192.168.200.0/24 在 [vxlan] 部分,启用VXLAN覆盖网络,配置覆盖网络的物理网络接口的IP地址,启用layer-2 population: enable_vxlan = True local_ip = 192.168.100.10 #这里的IP地址是controller的管理网络 l2_population = True 在 [securitygroup] 部分,启用安全组并配置 Linuxbridge iptables firewall driver: enable_security_group = True firewall_driver = neutron.agent.linux.iptables_firewall.IptablesFirewallDriver
#vi /etc/neutron/l3_agent.ini 在[DEFAULT]下添加 interface_driver = neutron.agent.linux.interface.BridgeInterfaceDriver external_network_bridge =
/etc/neutron/dhcp_agent.ini
文件#vi /etc/neutron/dhcp_agent.ini 在[DEFAULT]下添加 interface_driver = neutron.agent.linux.interface.BridgeInterfaceDriver dhcp_driver = neutron.agent.linux.dhcp.Dnsmasq enable_isolated_metadata = True
/etc/neutron/metadata_agent.ini
文件#vi /etc/neutron/metadata_agent.ini 在``[DEFAULT]`` 部分,配置元数据主机以及共享密码: nova_metadata_ip = controller metadata_proxy_shared_secret = 000000
/etc/nova/nova.conf
文件#vi /etc/nova/nova.conf 在``[neutron]``部分,配置访问参数,启用元数据代理并设置密码: url = http://controller:9696 auth_url = http://controller:35357 auth_type = password project_domain_name = default user_domain_name = default region_name = RegionOne project_name = service username = neutron password = 000000 service_metadata_proxy = True metadata_proxy_shared_secret = 000000
# ln -s /etc/neutron/plugins/ml2/ml2_conf.ini /etc/neutron/plugin.ini
# su -s /bin/sh -c "neutron-db-manage --config-file /etc/neutron/neutron.conf --config-file /etc/neutron/plugins/ml2/ml2_conf.ini upgrade head" neutron
# systemctl restart openstack-nova-api.service
# yum -y install openstack-neutron-linuxbridge ebtables ipset
/etc/neutron/neutron.conf
文件#vi /etc/neutron/neutron.conf 在 “[DEFAULT]” 下添加 rpc_backend = rabbit auth_strategy = keystone 在[oslo_messaging_rabbit]下添加 rabbit_host = controller rabbit_userid = openstack rabbit_password = 000000 在[keystone_authtoken]下添加 auth_uri = http://controller:5000 auth_url = http://controller:35357 memcached_servers = controller:11211 auth_type = password project_domain_name = default user_domain_name = default project_name = service username = neutron password = 000000 在 [oslo_concurrency] 部分,配置锁路径: lock_path = /var/lib/neutron/tmp
/etc/neutron/plugins/ml2/linuxbridge_agent.ini
文件#vi /etc/neutron/plugins/ml2/linuxbridge_agent.ini 在 [linux_bridge] 部分,将公共虚拟网络和公共物理网络接口对应起来 physical_interface_mappings = provider:eth1 在 [vxlan] 部分,启用VXLAN覆盖网络,配置覆盖网络的物理网络接口的IP地址,启用layer-2 population: enable_vxlan = True local_ip = 192.168.100.20 l2_population = True 在 [securitygroup] 部分,启用安全组并配置 Linuxbridge iptables firewall driver: enable_security_group = True firewall_driver = neutron.agent.linux.iptables_firewall.IptablesFirewallDriver
/etc/nova/nova.conf
文件并完成下面的操做#vi /etc/nova/nova.conf 在[neutron]部分添加 url = http://controller:9696 auth_url = http://controller:35357 auth_type = password project_domain_name = default user_domain_name = default region_name = RegionOne project_name = service username = neutron password = 000000
# systemctl restart openstack-nova-compute.service neutron-linuxbridge-agent.service # systemctl enable neutron-linuxbridge-agent.service
#. /root/admin-openrc #neutron ext-list #neutron agent-list