Get in Touch

Course Outline

1. Introduction to OpenStack - 2h
● Evolution of cloud computing and OpenStack
● Key cloud characteristics
● Cloud deployment models
○ private, public, hybrid
○ on-premise, IaaS, PaaS, SaaS
● Implementing public and private clouds with OpenStack
● Open source and commercial OpenStack distributions
● OpenStack deployment architectures
● The OpenStack ecosystem
○ Modules
○ Underlying tools
○ Integrations
● OpenStack lifecycle

● OpenStack certification pathways
● Virtual machine lab environment for this course


2. Practical OpenStack administration workshop
● OpenStack fundamentals ~0.5h
○ Core components (Keystone, Glance, Nova, Neutron, Cinder, Swift,
Heat)
○ Interacting with the OpenStack cloud
○ Daemon behavior and API communication flows
● Keystone - Identity management ~1h
○ Keystone architecture
○ Authentication methods and backends
○ Token types and management
○ Authorization mechanisms in OpenStack - roles and oslo.policy
○ Keystone resources - domains, projects, users
○ Openrc and clouds.yaml - Configuring CLI clients
○ OpenStack service catalog
○ Registering new OpenStack services
○ The OpenStack quota system
● Glance - Image service ~1.5h
○ Cloud-optimized images
○ Image attributes (properties, metadata, format, container)
○ Uploading and retrieving images
○ Sharing images
○ Glance image storage options
○ Protected images
○ Configuring image service quotas
○ Validating Glance services
● Neutron - Networking ~2-3h
○ Architecture and Neutron services
○ The ML2 plugin
○ Networking on compute nodes - analysis
○ Networking concepts and tools utilized by Neutron
○ Core Neutron network resource types
○ Managing tenant networks and subnets
○ Managing security groups and rules
○ East-West routing
○ Network namespaces
○ Managing external and provider networks
○ North-South routing
○ Floating IP management
○ Managing network quotas
○ Fundamental network troubleshooting (namespaces, tcpdump, etc.)
○ Networking quotas
○ Validating Neutron services
● Nova - Compute service ~2-3h
○ Hypervisor interfaces

○ Keypair management
○ Flavour management
○ Flavors and CPU topology
○ Instance parameters
○ Provisioning instances
○ Verifying launched instances
○ Snapshotting
○ Instance administration
○ Resizing instances
○ Assigning floating IPs
○ Interactive console and console logs
○ Assigning security groups
○ Compute quotas
○ Retrieving statistics from Nova
○ Placement API and Nova Cells v2
○ Placement API and instance scheduling
○ Placement API client commands
○ Validating Nova services
● Cinder - Block Storage ~2-3h
○ Volume parameters
○ Creating volumes
○ Volume administration
○ Attaching volumes to Nova instances
○ Managing volume snapshots
○ Managing volume backups
○ Internals of snapshots and backups in Cinder
○ Transferring volumes between projects
○ Restoring backups
○ Managing volume quotas
○ Adding new storage backends
○ QoS limits in Cinder
○ LVM, storage arrays, and Ceph storage backends
○ Ceph in OpenStack
○ Integrating Ceph and Cinder
○ Best practices for Ceph deployments
○ Validating Cinder services
● Barbican - Key Management Service ~2h
○ Barbican architecture
○ Storing passphrases
○ Generating and storing symmetric encryption keys
○ Volume encryption mechanisms
○ Configuring Cinder storage types for volume encryption
○ Limitations of volume encryption
○ Storing X.509 certificate bundles
● Swift - Object Storage (quick review for COA exam) <1h
○ Swift components and processes
○ Managing containers and objects
○ Managing access control lists

○ Setting object expiration rules
○ The Ring and storage policies
○ Monitoring available storage capacity
○ Configuring quotas
○ Validating Swift services
● Octavia - Load Balancing-as-a-service ~2-3h
○ Architecture
○ Objects and request flows
○ Octavia flavors
○ Octavia Availability Zones
○ Creating HTTP load balancers
○ Creating TCP load balancers
○ Creating HTTPS passthrough load balancers
○ Listeners, Pools, and Health Monitors
○ Layer 7 load balancing in Octavia
○ Building the Amphora image
○ Load Balancer Failover
○ Networking and Monitoring details
○ Troubleshooting Octavia
● Heat - Orchestration ~1-2h
○ Heat Orchestration Templates and their components
○ Creating Heat stacks
○ Verifying Heat stacks
○ Updating Heat stacks
○ Validating Heat services
● Basic troubleshooting ~2h
○ Analyzing log files
○ Centralized logging
○ Debugging OpenStack client queries
○ Managing the OpenStack database
○ Backing up OpenStack
○ Analyzing compute node status
○ Analyzing instance status
○ Analyzing the AMQP broker (RabbitMQ)
○ Metadata services
○ General methodologies for diagnosing OpenStack issues
○ Troubleshooting network issues
○ Troubleshooting network performance
○ Instance backup and recovery

3. Advanced Topics
● Hardware considerations and capacity planning ~2h
○ Compute hardware
○ Network design
○ Storage design
○ Flavour sizing
○ Resource overcommitment

● Role system - authorization in OpenStack ~2h
○ Creating custom roles as member role extensions
○ policy.yaml - Authorization for API calls
● Highly Available control plane ~1h
○ High Availability in OpenStack services
○ HA database
○ HA message queue
● Cloud partitioning and scheduler filters ~1h
○ Rationale and implementation of cloud partitions (host-aggregates)
○ Nova scheduler filters
● Workload migration ~1h
○ Cold and live migration
○ Tuning live migration
● OpenStack monitoring and telemetry <1h
○ Ceilometer service
○ External monitoring
● Advanced cloud and hypervisor features <1h
○ CPU pinning and NUMA architecture
○ SR-IOV
● Cloud-init and image customization <1h
○ Metadata Service
● Block storage backends <1h
○ LVM
○ Ceph RBD
○ Physical appliances
○ Storage network considerations
● Upgrading OpenStack <1h
○ Upgrade strategies and procedures
○ Zero-downtime upgrades
● Bare-metal provisioning with OpenStack <1h
○ Ironic module
○ Undercloud and overcloud concepts
● The future of OpenStack
4. Deep-dive into Neutron and OVN backend ~6-8h
● OVN architecture
● OVN components
● ML2 - Comparing OVN and OvS drivers
● Top-down OVN networking
○ OpenStack logic (Neutron database)
○ Northbound database
○ Southbound database
○ Logical datapath pipelines
○ Logical flows
○ OpenFlow flows
● Neutron networks and OVN logical switches
○ Logical ports and their types
○ Switching flows

● Neutron routers and OVN logical routers
○ NAT types
○ Routing flows
● Neutron subnets and native DHCP
○ DHCP flows
● Security groups in OVN
○ ACLs and Port Groups
○ Security group flows
○ Port security in OVN
● Overview of OVN Northbound tables
● Information flow in OVN
○ Neutron DB, OVN NB and SB DBs, OpenFlow at OvS
● Logical flow tracing
○ Defining microflows
○ L2 tracing
○ L3 tracing
○ DHCP tracing
● Physical flows - OpenFlow
○ Physical lifecycle of a VM-originated packet
● Physical tracing
○ Tracing hypothetical packets
○ Tracing real packets
● Displaying the Open vSwitch database and resources

 35 Hours

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories