{"id":2263,"date":"2018-02-08T04:36:04","date_gmt":"2018-02-08T09:36:04","guid":{"rendered":"http:\/\/blog.domb.net\/?p=2263"},"modified":"2018-02-09T02:44:35","modified_gmt":"2018-02-09T07:44:35","slug":"openshift-on-rhv-automated-secure-and-transparent","status":"publish","type":"post","link":"https:\/\/blog.domb.net\/?p=2263","title":{"rendered":"OpenShift on RHV Automated, Secure and Transparent"},"content":{"rendered":"<p><span style=\"font-weight: 400\">Red Hat Virtualization and the OpenShift Container Platform go far back. Both products are very well integrated and share security features like svirt and cgroups which are a core security component of Red Hat Enterprise Linux. Svirt allows you to run your virtual instances as well as containers in full tenant isolation mode whereas cgroups makes sure your resource are isolated properly. Another very useful integration of Red Hat Virtualization \u00a0and the OpenShift Container Platform is the ability to view containers from within the Red Hat Virtualization Manager. This features comes very handy if you want to understand on what nodes your containers are running.<\/span><\/p>\n<p><span style=\"font-weight: 400\">In the past 2 years we have been working hard on building ansible modules for RHV which enable automated builds of the RHV core infrastructure like the Red Hat Virtualization Manager, the Datacenter, Clusters, Hosts, Storage and networks as well as the virtual resources on top of Red Hat Virtualization. <\/span><\/p>\n<p><span style=\"font-weight: 400\">This blog post will walk you through how you can make use of ansible to install the OpenShift Container Platform fully automated on Red Hat Virtualization with a single push of a button. <\/span><\/p>\n<p><span style=\"font-weight: 400\">For the ansible playbooks to work in your environment you will need clone the following github repository: <\/span><\/p>\n<p><a href=\"https:\/\/github.com\/ldomb\/OpenShiftOnRHV\"><span style=\"font-weight: 400\">https:\/\/github.com\/ldomb\/OpenShiftOnRHV<\/span><\/a><\/p>\n<p><span style=\"font-weight: 400\">and meet the following pre requirements: <\/span><\/p>\n<ul>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">A RHEL 7.4 golden image with DHCP enabled<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">A working DHCP server in your environment<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">A DNS server with pre populated DNS names<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">The openshift-ansible roles \/ playbooks<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">RHV 4.1 or 4.2 <\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">DNS entries for the haproxy load balancer as well as infrastructure nodes once build<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400\">Once you have fulfilled the above requirements you can go ahead and configure the variables in the directory group_vars\/all\/vars as well as group_vars\/all\/vault. <\/span><\/p>\n<p><span style=\"font-weight: 400\">The following variables will need to be adjusted:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">key: <\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">db_size<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">db_vol_name<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">template_name<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">datastore<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">cluster<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">rhvm_addr: &#8220;{{ vault_rhvm_addr }}&#8221;<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">rhv_user: &#8220;{{ vault_rhv_user }}&#8221;<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">rhv_pass: &#8220;{{ vault_rhv_pass }}&#8221;<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">network_name: ovirtmgmt<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">rhn_user: &#8220;{{ vault_rhn_user }}&#8221;<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">rhn_pass: &#8220;{{ vault_rhn_pass }}&#8221;<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">rhn_pool: 8a85f98660c55a380160c2fa572d302b<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">openshift_master_default_subdomain: apps.local.redhat-demo.com<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400\">The architecture for the production grade installation of OpenShift on RHV will look as follows: <\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2264\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/OpenShift-RHV-Architecture.png\" alt=\"\" width=\"731\" height=\"746\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/OpenShift-RHV-Architecture.png 731w, https:\/\/blog.domb.net\/wp-content\/uploads\/OpenShift-RHV-Architecture-294x300.png 294w\" sizes=\"auto, (max-width: 731px) 100vw, 731px\" \/><\/p>\n<p><span style=\"font-weight: 400\">To build the OpenShift Container Platform on RHV based on the above architecture you won\u2019t need to adjust the master playbook ocp-deploy-rhv.yml as all the variables are already set.<\/span><\/p>\n<p><span style=\"font-weight: 400\">The installation of the OpenShift Container Platform on RHV can now be launched. The following recording shows the entire process of the installation. \u00a0<\/span><\/p>\n<p><iframe loading=\"lazy\" title=\"Red Hat OpenShift Container Platform on Red Hat Virtualization build by Ansible\" width=\"640\" height=\"360\" src=\"https:\/\/www.youtube.com\/embed\/enIJtUP5WZc?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/p>\n<p><span style=\"font-weight: 400\">Once the installation is done you will not only be able to login and build containers on the OpenShift Container Platform but also view the containers in the RHVM portal.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Red Hat Virtualization and the OpenShift Container Platform go far back. Both products are very well integrated and share security features like svirt and cgroups which are a core security component of Red Hat Enterprise Linux. Svirt allows you to run your virtual instances as well as containers in full tenant isolation mode whereas cgroups&#8230;<\/p>\n","protected":false},"author":2,"featured_media":2027,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"footnotes":""},"categories":[64,76,4],"tags":[67,55,72],"class_list":["post-2263","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ansible","category-openshift","category-virtualization","tag-ansible","tag-openshift","tag-rhv"],"_links":{"self":[{"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/posts\/2263","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.domb.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2263"}],"version-history":[{"count":6,"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/posts\/2263\/revisions"}],"predecessor-version":[{"id":2272,"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/posts\/2263\/revisions\/2272"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/media\/2027"}],"wp:attachment":[{"href":"https:\/\/blog.domb.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2263"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.domb.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2263"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.domb.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2263"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}