Skip to content

Instantly share code, notes, and snippets.

@jay-johnson
Last active June 25, 2018 04:12
Show Gist options
  • Select an option

  • Save jay-johnson/1d5106e5d116b870302ccc96a43282a5 to your computer and use it in GitHub Desktop.

Select an option

Save jay-johnson/1d5106e5d116b870302ccc96a43282a5 to your computer and use it in GitHub Desktop.
Installing OCP with Virtual Box
imagetouse=/home/jay/Documents/ocp-3.9.ova
vmname=ocp
nicname=enp7s0

vboxmanage controlvm ${vmname} poweroff
vboxmanage unregistervm ${vmname} --delete
vboxmanage import ${imagetouse} --options keepallmacs --vsys 0 --cpus 4 --vsys 0 --memory 16000 --vmname ${vmname}
vboxmanage modifyvm ${vmname} --nic1 nat
vboxmanage modifyvm ${vmname} --nic1 bridged --bridgeadapter1 ${nicname}
vboxmanage showvminfo ${vmname}
vboxmanage startvm ${vmname} --type headless
vboxmanage list runningvms
"ocp" {fd4f4b84-5893-4e7c-b6ff-1c043971a696}
Determine guest vm's IP (I had to use Virtual Box over X11 to get mine - there's probably a way to look it up though)
jay@antinex:~$ ssh root@192.168.0.35
The authenticity of host '192.168.0.35 (192.168.0.35)' can't be established.
ECDSA key fingerprint is SHA256:YsVKN4fvSNUlfI3GwcUvRnpSD6GPXfjOQouoDxeQBuI.
Are you sure you want to continue connecting (yes/no)? yes
Warning: Permanently added '192.168.0.35' (ECDSA) to the list of known hosts.
root@192.168.0.35's password: 
Last login: Wed May 23 00:02:17 2018
[root@localhost ~]# 
echo "openshift_master_identity_providers=[{'name': 'htpasswd_auth', 'login': 'true', 'challenge': 'true', 'kind': 'HTPasswdPasswordIdentityProvider', 'filename': '/etc/origin/master/htpasswd'}]" >> /etc/ansible/hosts

Configure Persistent Volumes

mkdir /exports/postgres-antinex; mkdir /exports/redis-antinex; chown nfsnobody:nfsnobody /exports -R; chmod 777 /exports -R; echo '/exports/postgres-antinex *(rw,root_squash)' >> /etc/exports; echo '/exports/redis-antinex *(rw,root_squash)' >> /etc/exports; exportfs -rf
mkdir: cannot create directory ‘/exports/postgres-antinex’: File exists
mkdir: cannot create directory ‘/exports/redis-antinex’: File exists

Verify the NFS mounts:

cat /etc/exports
/exports/etcd *(rw,root_squash)
/exports/postgres-antinex *(rw,root_squash)
/exports/redis-antinex *(rw,root_squash)
[root@ocp39 ~]# showmount -e
Export list for ocp39.homelab.com:
/exports/redis-antinex    *
/exports/postgres-antinex *
/exports/etcd             *
[root@ocp39 ~]# 
htpasswd -c htpasswd admin
htpasswd -c htpasswd trex
cp -f /root/htpasswd /etc/origin/master/htpasswd 
systemctl restart atomic-openshift-master-*
oc adm policy add-cluster-role-to-user cluster-admin admin
cluster role "cluster-admin" added: "admin"
oc adm policy add-cluster-role-to-user cluster-admin trex
cluster role "cluster-admin" added: "trex"

Add MAC to router for static ip

[root@localhost ~]# ifconfig | grep enp -A 4 | grep ether | awk '{print $2}'
08:00:27:38:01:2e
[root@localhost ~]# 
[root@localhost ~]# ifconfig | grep enp -A 2 | grep "inet " | awk '{print $2}'
192.168.0.35
[root@localhost ~]# 

Run OpenShift Ansible Playbooks on OCP

ansible-playbook /usr/share/ansible/openshift-ansible/playbooks/prerequisites.yml
ansible-playbook /usr/share/ansible/openshift-ansible/playbooks/openshift-service-catalog/config.yml

Which should result in output like:

TASK [container_runtime : include_tasks] ******************************************************************
skipping: [localhost.localdomain]

PLAY RECAP ************************************************************************************************
localhost                  : ok=11   changed=0    unreachable=0    failed=0   
localhost.localdomain      : ok=73   changed=5    unreachable=0    failed=0   


INSTALLER STATUS ******************************************************************************************
Initialization             : Complete (0:00:18)

[root@localhost ~]# 
# Remove previous login values cached in: 
# rm -rf ~/.kube
oc login -u system:admin https://ocp39.homelab.com:8443
oc status
In project default on server https://ocp39.homelab.com:8443

https://docker-registry-default.apps.homelab.com (passthrough) (svc/docker-registry)
  dc/docker-registry deploys docker.io/openshift3/ose-docker-registry:v3.9.27 
    deployment #1 deployed 22 minutes ago - 1 pod

svc/kubernetes - 172.30.0.1 ports 443->8443, 53->8053, 53->8053

https://registry-console-default.apps.homelab.com (passthrough) (svc/registry-console)
  dc/registry-console deploys registry.access.redhat.com/openshift3/registry-console:v3.9 
    deployment #1 deployed 21 minutes ago - 1 pod

svc/router - 172.30.132.198 ports 80, 443, 1936
  dc/router deploys docker.io/openshift3/ose-haproxy-router:v3.9.27 
    deployment #2 deployed 6 minutes ago - 1 pod
    deployment #1 deployed 22 minutes ago

View details with 'oc describe <resource>/<name>' or list everything with 'oc get all'.
C:\Users\Jay
λ minishift delete
You are deleting the Minishift VM: 'minishift'. Do you want to continue [y/N]?: y
Deleting the Minishift VM...
Minishift VM deleted.

C:\Users\Jay
λ
/etc/ansible/hosts

 # -------------------------------------------------------------------------------------
 #  Create an OSEv3 group that contains the master, nodes, etcd, and lb groups.
 #  The lb group lets Ansible configure HAProxy as the load balancing solution.
 #  Comment lb out if your load balancer is pre-configured.
 # -------------------------------------------------------------------------------------
[OSEv3:children]
masters
nodes
etcd
  
# -------------------------------------------------------------------------------------
#  Set variables common for all OSEv3 hosts
# -------------------------------------------------------------------------------------
[OSEv3:vars]
openshift_release=v3.9
package_version=3.9
ansible_ssh_user=root
openshift_enable_service_catalog=false
openshift_service_catalog_image_version=v3.9
openshift_deployment_type=openshift-enterprise
os_sdn_network_plugin_name=redhat/openshift-ovs-multitenant
openshift_master_identity_providers=[{'name': 'htpasswd_auth', 'login': 'true', 'challenge': 'true', 'kind': 'HTPasswdPasswordIdentityProvider', 'filename': '/etc/origin/master/htpasswd'}]
openshift_master_default_subdomain=apps.homelab.com
openshift_disable_check=memory_availability,disk_availability
openshift_hosted_etcd_storage_kind=nfs
openshift_hosted_etcd_storage_access_modes=["ReadWriteOnce"]
openshift_hosted_etcd_storage_host=localhost
openshift_hosted_etcd_storage_nfs_directory=/exports
openshift_hosted_etcd_storage_volume_name=etcd
openshift_hosted_etcd_storage_volume_size=10G
openshift_hosted_etcd_storage_labels={'storage': 'etcd'}
openshift_master_cluster_method=native
openshift_master_cluster_hostname=ocp39.homelab.com
openshift_master_cluster_public_hostname=ocp39.homelab.com
openshift_router_selector='router=true'

##############################
### host group for masters ###
##############################
[masters]
localhost.localdomain

###################################
### host group for etcd servers ###
###################################
[etcd]
localhost.localdomain

##################################################
### host group for nodes, includes region info ###
##################################################
[nodes]
localhost.localdomain openshift_node_labels="{'region': 'infra', 'zone': 'default', 'router': 'true', 'type': 'general'}" openshift_schedulable=True

Checking the Template Service Broker

oc get all -n openshift-template-service-broker
NAME           DESIRED   CURRENT   READY     UP-TO-DATE   AVAILABLE   NODE SELECTOR   AGE
ds/apiserver   1         1         1         1            1           region=infra    1m

NAME                 READY     STATUS    RESTARTS   AGE
po/apiserver-8fbt2   1/1       Running   0          1m

NAME            TYPE        CLUSTER-IP       EXTERNAL-IP   PORT(S)   AGE
svc/apiserver   ClusterIP   172.30.234.236   <none>        443/TCP   1m

Checking the Ansible Service Broker

[root@ocp39 ~]# oc get all -n openshift-ansible-service-broker
NAME                         REVISION   DESIRED   CURRENT   TRIGGERED BY
deploymentconfigs/asb        1          1         1         config
deploymentconfigs/asb-etcd   1          1         1         config

NAME              HOST/PORT                                                    PATH      SERVICES   PORT      TERMINATION   WILDCARD
routes/asb-1338   asb-1338-openshift-ansible-service-broker.apps.homelab.com             asb        1338      reencrypt     None

NAME                  READY     STATUS    RESTARTS   AGE
po/asb-1-d8nb9        1/1       Running   2          1m
po/asb-etcd-1-9q88k   1/1       Running   0          1m

NAME            DESIRED   CURRENT   READY     AGE
rc/asb-1        1         1         1         1m
rc/asb-etcd-1   1         1         1         1m

NAME           TYPE        CLUSTER-IP      EXTERNAL-IP   PORT(S)    AGE
svc/asb        ClusterIP   172.30.235.71   <none>        1338/TCP   2m
svc/asb-etcd   ClusterIP   172.30.8.60     <none>        2379/TCP   2m

Edit Persistent Volume Claims

oc edit pv etcd-volume

Export Environmental-Stripped PVC

oc get pvc postgres -o json --export=True > pvc.json

VM Aliases for Restoring OCP on Restart

alias pvc="oc get pvc"
alias pv="oc get pv"
alias pva="oc volume dc --all"
alias createvols="mkdir /pgdata; mkdir /exports/postgres-antinex; mkdir /exports/redis-antinex; chown nfsnobody:nfsnobody /exports -R; 

Create Volumes

function fixvols() {
	cp /etc/exports /etc/exports.bak
	clean_all="0"
	if [[ "${1}" == "-f" ]]; then
		clean_all="1"
	fi	
	mnts="/exports/postgres-antinex /exports/redis-antinex /pgdata /var/lib/pgadmin /run/httpd"
	for i in ${mnts}; do
		if [[ "${clean_all}" == "1" ]]; then
			if [[ -e ${i} ]]; then
				echo "- cleaning existing: ${i}"
				rm -rf ${i}
			fi
		fi
		if [[ ! -e ${i} ]]; then
			echo "mkdir: ${i}"
			mkdir ${i}
		fi
		echo "chown nfsnobody:nfsnobody ${i} -R"
		chown nfsnobody:nfsnobody ${i} -R
		echo "chmod 777 ${i} -R"
		chmod 777 ${i} -R
		test_exported=$(cat /etc/exports | grep "${i} " | wc -l)
		if [[ "${test_exported}" == "0" ]]; then
			if [[ -e ${i} ]]; then
				echo ""
				echo "${i} *(rw,root_squash)" >> /etc/exports
				test_exported=$(cat /etc/exports | grep "${i} " | wc -l)
				if [[ "${test_exported}" == "0" ]]; then
					echo "Failed to add ${i} to /etc/exports"
					echo "echo \"${i} *(rw,root_squash)\" >> /etc/exports"
					exit 1
				fi
			fi
		fi
	done

	echo "exports -rf"
	exportfs -rf
	echo ""

	echo "showmount -e"
	showmount -e
	echo ""
	
	echo "cat /etc/hosts"
	cat /etc/hosts
}

Tail the Atomic OpenShift Master API

journalctl -f -u atomic-openshift-master-api
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment