Course Outline
1. Introduction to OpenStack
-
The history of cloud computing and OpenStack
-
Key features of the cloud
-
Cloud deployment models
-
Private, public, and hybrid clouds
-
On-premise, IaaS, PaaS, and SaaS
-
-
Public and private cloud deployments utilizing OpenStack
-
Open source versus commercial OpenStack distributions
-
OpenStack deployment architectures
-
The OpenStack ecosystem
-
Core modules
-
Underlying tools
-
Integrations
-
-
OpenStack lifecycle management
-
OpenStack certification pathways
-
The OpenStack lab environment (VM) for this course
2. Hands-on OpenStack administration workshop
-
Exploring OpenStack fundamentals
-
Core OpenStack components (Keystone, Glance, Nova, Neutron, Cinder, Swift, Heat)
-
Interacting with the OpenStack cloud
-
OpenStack daemons and API communication flows
-
-
Keystone: Identity Management Service
-
Keystone architecture
-
Authentication mechanisms and available backends
-
Token types and token management
-
Authorization in OpenStack using roles and oslo.policy
-
Keystone resources: domains, projects, and users
-
Configuring CLI clients via openrc and clouds.yaml
-
The OpenStack service catalog
-
Registering new OpenStack services
-
The quota system within OpenStack
-
-
Glance: Image Service
-
Images adapted for cloud environments
-
Image attributes (properties, metadata, format, container)
-
Uploading and downloading images
-
Sharing images
-
Glance image storage options
-
Protected images
-
Managing quotas for the image service
-
Verifying Glance services
-
-
Neutron: Networking
-
Architecture and Neutron services
-
The ML2 plugin
-
Networking on compute nodes - analysis
-
Networking concepts and tools utilized by Neutron
-
Fundamental Neutron network resource types
-
Managing tenant networks and subnets
-
Managing security groups and rules
-
East-West routing
-
Network namespaces
-
Managing external and provider networks
-
North-South routing
-
Floating IP management
-
Role-based access control in Neutron
-
Managing network quotas
-
Internals of SDN and NFV (iptables, ip route, OVS)
-
Basic network troubleshooting (namespaces, tcpdump, etc.)
-
Networking quotas
-
Verifying Neutron services
-
-
Nova: Compute Service
-
Hypervisor interfaces
-
Keypair management
-
Flavor management
-
Flavors and CPU topology
-
Instance parameters
-
Creating an instance
-
Verifying spawned instances
-
Snapshotting
-
Instance management
-
Resizing instances
-
Assigning floating IPs
-
Interactive console and console log
-
Security group assignment
-
Internals of security groups and port-security features (iptables)
-
Internals of L3 routers
-
Compute quotas
-
Retrieving statistics from Nova
-
Placement API and Nova Cells v2
-
Placement API and instance scheduling
-
Placement API client commands
-
Verifying Nova services
-
-
Cinder: Block Storage
-
Volume parameters
-
Creating volumes
-
Managing volumes
-
Attaching volumes to Nova instances
-
Managing volume snapshots
-
Managing volume backups
-
Internals of snapshots and backups in Cinder
-
Transferring volumes between projects
-
Restoring backups
-
Managing volume quotas
-
Adding new storage backends
-
QoS in Cinder
-
LVM, storage array, and Ceph storage backends
-
Ceph in OpenStack
-
Integrating Ceph and Cinder
-
Best practices for Ceph deployments
-
Verifying Cinder services
-
-
Barbican: Key Management Service
-
Barbican architecture
-
Storing passphrases
-
Generating and storing symmetric encryption keys
-
Volume encryption mechanisms
-
Configuring Cinder storage types for volume encryption
-
Limitations of volume encryption
-
Storing X.509 certificate bundles
-
-
Swift: Object Storage
-
Swift components and processes
-
Managing containers and objects
-
Managing access control lists
-
Setting up object expiration
-
The Ring and storage policies
-
Monitoring available storage space
-
Setting up quotas
-
Verifying Swift services
-
-
Heat: Orchestration
-
Heat Orchestration Templates and their components
-
Creating a Heat stack
-
Verifying a Heat stack
-
Updating a Heat stack
-
Verifying Heat services
-
-
Basic troubleshooting
-
Analyzing log files
-
Centralized logging
-
Debugging OpenStack client queries
-
Managing the OpenStack database
-
Extracting information from service databases
-
Backing up OpenStack
-
Analyzing compute node status
-
Analyzing instance status
-
Troubleshooting instances on compute nodes (libvirt)
-
Analyzing the AMQP broker (RabbitMQ)
-
Troubleshooting RabbitMQ
-
Metadata services
-
General approaches to diagnosing OpenStack issues
-
Troubleshooting network problems
-
Troubleshooting network performance
-
Instance backup and recovery
-
2. Advanced Topics
-
Octavia: Load Balancing as a Service
-
Architecture
-
Objects and request flow
-
Octavia flavors
-
Octavia Availability Zones
-
Creating HTTP load balancers
-
Creating TCP load balancers
-
Creating HTTPS passthrough load balancers
-
Listeners, Pools, and Health Monitors
-
Layer 7 load balancing in Octavia
-
Building the Amphora image
-
Load Balancer Failover
-
Networking and monitoring details
-
Troubleshooting Octavia
-
-
Hardware considerations and capacity planning
-
Compute hardware
-
Network design
-
Storage design
-
Flavor sizing
-
Resource overcommitment
-
-
Highly Available Control Plane
-
HA in OpenStack services
-
HA database
-
HA message queue
-
Active-Active vs Active-Passive deployments
-
Multi-region deployments
-
-
Cloud partitioning and scheduler filters
-
Implementing cloud partitions (host-aggregates): why and how
-
Nova scheduler filters
-
Detailed analysis of filter code
-
-
Workload migration
-
Cold and live migration
-
Tuning live migration
-
Migration exercises and troubleshooting
-
-
Policies and authorization in OpenStack
-
Oslo.policy
-
Creating meaningful new roles using policy files
-
Verifying API access for specific users
-
-
In-depth OpenStack networking (SDN) (2-3h)
-
Network types (local, flat, vlan, vxlan, gre)
-
Detailed network flow and architecture in various Neutron deployments
-
East-West traffic in tenant networks
-
North-South traffic in tenant networks
-
Traffic in provider-only deployments
-
-
Neutron plugins
- Linux Bridge
- Open vSwitch
-
OVS troubleshooting and exercises
-
Troubleshooting security groups (iptables, tcpdump)
-
Port-security adjustments and VIP management
-
Distributed Virtual Routers
-
LBaaS + Octavia project
-
VPNaaS
-
-
OpenStack monitoring and telemetry
-
Ceilometer service
-
External monitoring
-
-
Advanced cloud and hypervisor features
-
CPU pinning and NUMA architecture
-
SR-IOV
-
-
Cloud-init and image customization
-
Metadata Service
-
Retrieving information from the metadata service
-
-
Block storage backends
-
LVM
-
Ceph RBD
-
Physical appliances
-
Storage network considerations
-
-
Upgrading OpenStack
-
Upgrade strategies and procedures
-
Zero-downtime upgrades
-
-
Bare-metal provisioning with OpenStack
-
Ironic module
-
Undercloud and overcloud concepts
-
-
Various exercises on troubleshooting OpenStack clusters
-
Sample examination tasks
-
The future of OpenStack
Requirements
- Fundamental Linux administration capabilities
- Basic understanding of networking principles
- Foundational knowledge of the cloud computing paradigm
Testimonials (1)
communication, knowledge from experience, solve problems,