Installing Ops Manager on OpenStack
Page last updated:
This guide describes how to install Pivotal Platform on OpenStack with Pivotal Operations Manager and Pivotal Application Service (PAS).
OpenStack is a cloud operating system that controls large pools of compute, storage, and networking resources throughout a datacenter. For guidance on OpenStack service credential management, see Open Stack Security Documents below.
These documents provide a general reference for OpenStack service credential management.
This section describes the requirements for installing Pivotal Platform on OpenStack, including general requirements for installing Ops Manager with PAS as well as OpenStack requirements.
Note: You can install Pivotal Platform on OpenStack with the Pivotal Application Service (PAS) runtime. The Enterprise Pivotal Container Service (Enterprise PKS) runtime is not supported for OpenStack. For more information about PAS, see PAS Concepts. For more information about Enterprise PKS, see Enterprise Pivotal Container Service (Enterprise PKS).
For PAS-specific resource requirements, see PAS Resource Requirements.
The following are OpenStack requirements for deploying Ops Manager:
Ops Manager is supported on the OpenStack Ocata, Pike, Queens, Rocky, and Stein releases. OpenStack is a collection of inter-operable components and requires general OpenStack expertise to troubleshoot issues that may occur when installing Ops Manager on particular releases and distributions. To verify that your OpenStack platform is compatible with Ops Manager, use the OpenStack Validator tool. To access the OpenStack Validator tool, see CF OpenStack Validator on GitHub.
Pivotal recommends granting complete access to the OpenStack logs to the operator managing the Pivotal Platform installation process.
For OpenStack accounts for Pivotal Platform, Pivotal recommends following the principle of least privilege by scoping privileges to the most restrictive permissions possible for a given role.
You must have a dedicated OpenStack project, formerly known as an OpenStack tenant.
You must have Keystone access to the dedicated OpenStack project, including the following:
- Auth URL
- Username and password. The
PrimaryProjectfor the user must be the project you want to use to deploy Ops Manager. For more information, see Manage projects and users in the OpenStack documentation.
- Project name
- Region (with multiple availability zones if you require high availability)
- SSL certificate for your wildcard domain (see below)
You must have the ability to do the following in OpenStack:
- Create and modify VM flavors
- Enable DHCP if required
- Create a network and then connect that network with a router to an external network
- Create an external network with a pool of floating IP addresses
- Boot VMs directly from image
- Create two wildcard domains for separate system and app domains
The following are resource requirements for the dedicated OpenStack project:
- 118 GB of RAM
- 22 available instances
- 14 small VMs (1 vCPU, 1024 MB of RAM, 10 GB of root disk)
- 2 high-CPU VMs (2 vCPU, 1024 MB of RAM, 10 GB of root disk)
- 3 large VMs (4 vCPU, 16384 MB of RAM, 10 GB of root disk)
- 3 extra-large VMs (8 vCPU, 16 GB of RAM, 160 GB of ephemeral disk)
- 58 vCPUs
- 1 TB of storage
- Nova or Neutron networking with floating IP support
Note: By default, PAS deploys the number of VM instances required to run a highly available configuration of Pivotal Platform. If you are deploying a test or sandbox Pivotal Platform that does not require HA, then you can scale down the number of instances in your deployment. For information about the number of instances required to run a minimal, non-HA Pivotal Platform deployment, see Scaling PAS.
The following are requirements for the OpenStack Cinder back end:
- Pivotal Platform requires RAW root disk images. The Cinder back end for your OpenStack project must support RAW.
- Pivotal recommends that you use a Cinder back end that supports snapshots. This is required for some BOSH functionalities.
- Pivotal recommends enabling your Cinder back end to delete block storage asynchronously. If this is not possible, it must be able to delete multiple 20 GB volumes within 300 seconds.
The following are requirements for using an Overlay Network with VXLAN or GRE Protocols:
- If an overlay network is being used with VXLAN or GRE protocols, the MTU of the created VMs must be adjusted to the best practices recommended by the plugin vendor (if any).
- DHCP must be enabled in the internal network for the MTU to be assigned to the VMs automatically.
- Review Configuring PAS to adjust your MTU values.
- Failure to configure your overlay network correctly could cause Apps Manager to fail since applications will not be able to connect to the UAA.
Note: If you are using IPsec, your resource usage will increase by approximately 36 bytes. View the Installing IPsec topic for information, including setting correct MTU values.
To install Ops Manager on OpenStack with the PAS runtime, do the following:
Deploy Ops Manager. See Deploying Ops Manager on OpenStack.
Configure BOSH Director on OpenStack. See Configuring BOSH Director on OpenStack.
After completing the procedures above, configure a runtime.
For information about installing and configuring a runtime, see the following: