Course Outline
1. Introduction to OpenStack
-
The history of cloud computing and OpenStack
-
Key cloud characteristics
-
Cloud service models
-
Private, public, and hybrid clouds
-
On-premise, IaaS, PaaS, and SaaS
-
-
Public and private cloud deployments utilizing OpenStack
-
Open-source and commercial OpenStack distributions
-
OpenStack deployment strategies
-
The OpenStack ecosystem
-
Core modules
-
Underlying tools
-
Integrations
-
-
OpenStack lifecycle management
-
OpenStack certification pathways
-
Dedicated OpenStack lab (VM) for this course
2. Hands-on OpenStack Administration Workshop
-
Familiarization with OpenStack
-
Core OpenStack components (Keystone, Glance, Nova, Neutron, Cinder, Swift, Heat)
-
Interacting with the OpenStack cloud
-
OpenStack daemons and API communication flows
-
-
Keystone - Identity Management Service
-
Keystone architecture
-
Authentication methods and available backends
-
Token types and management
-
Authorization in OpenStack using roles and oslo.policy
-
Keystone resources: domains, projects, and users
-
Configuring CLI clients via Openrc and clouds.yaml
-
The OpenStack service catalog
-
Integrating new OpenStack services
-
The quota system within OpenStack
-
-
Glance - Image Service
-
Images tailored for the cloud environment
-
Image attributes (properties, metadata, format, container)
-
Uploading and downloading images
-
Sharing images across projects
-
Glance image storage options
-
Protected images
-
Managing image service quotas
-
Validating Glance services
-
-
Neutron - Networking
-
Neutron architecture and services
-
The ML2 plugin
-
Networking analysis on compute nodes
-
Networking concepts and tools utilized by Neutron
-
Fundamental Neutron network resource types
-
Managing tenant networks and subnets
-
Managing security groups and rules
-
East-West routing
-
Network namespaces
-
Managing external and provider networks
-
North-South routing
-
Floating IP management
-
Role-based access control within Neutron
-
Managing network quotas
-
Internals of SDN and NFV (iptables, ip route, OVS)
-
Basic network troubleshooting (namespaces, tcpdump, etc.)
-
Networking quota configuration
-
Verification of Neutron services
-
-
Nova - Compute Service
-
Hypervisor interfaces
-
Keypair management
-
Flavour management
-
Flavors and CPU topology
-
Instance parameters
-
Creating instances
-
Validating spawned instances
-
Snapshot creation
-
Instance administration
-
Resizing instances
-
Assigning floating IPs
-
Interactive console and console logging
-
Applying security groups
-
Internals of security groups and port security features (iptables)
-
Internals of L3 routers
-
Compute quota management
-
Retrieving statistics from Nova
-
Placement API and Nova Cells v2
-
Placement API and instance scheduling
-
Placement API client commands
-
Verification of Nova services
-
-
Cinder - Block Storage
-
Volume parameters
-
Creating volumes
-
Volume administration
-
Attaching volumes to Nova instances
-
Managing volume snapshots
-
Managing volume backups
-
Internals of snapshots and backups in Cinder
-
Transferring volumes between projects
-
Restoring from backups
-
Managing volume quotas
-
Adding new storage backends
-
QoS implementation in Cinder
-
LVM, storage array, and Ceph storage backends
-
Ceph integration in OpenStack
-
Integrating Ceph with Cinder
-
Best practices for Ceph deployments
-
Verification of Cinder services
-
-
Barbican - Key Management Service
-
Barbican architecture
-
Storing passphrases
-
Generating and storing symmetric encryption keys
-
Volume encryption mechanisms
-
Configuring Cinder storage types for volume encryption
-
Limitations of volume encryption
-
Storing X.509 certificate bundles
-
-
Swift - Object Storage
-
Swift components and processes
-
Managing containers and objects
-
Managing access control lists
-
Configuring object expiration
-
The Ring and storage policies
-
Monitoring available storage capacity
-
Configuring quotas
-
Verification of Swift services
-
-
Heat - Orchestration
-
Heat Orchestration Templates and their components
-
Creating Heat stacks
-
Validating Heat stacks
-
Updating Heat stacks
-
Verification of Heat services
-
-
Basic Troubleshooting
-
Analyzing log files
-
Centralized logging
-
Debugging OpenStack client queries
-
Managing the OpenStack database
-
Extracting information from service databases
-
Backing up OpenStack
-
Analyzing compute node status
-
Analyzing instance status
-
Troubleshooting instances on compute nodes (libvirt)
-
Analyzing the AMQP broker (RabbitMQ)
-
Troubleshooting RabbitMQ
-
Metadata services
-
General methodologies for diagnosing OpenStack issues
-
Troubleshooting network issues
-
Troubleshooting network performance
-
Instance backup and recovery
-
3. Advanced Topics
-
Octavia - Load Balancing-as-a-Service
-
Architecture
-
Objects and request flows
-
Octavia flavors
-
Octavia Availability Zones
-
Creating HTTP load balancers
-
Creating TCP load balancers
-
Creating HTTPS passthrough load balancers
-
Listeners, Pools, and Health Monitors
-
Layer 7 load balancing in Octavia
-
Building Amphora images
-
LB Failover
-
Networking and monitoring details
-
Troubleshooting Octavia
-
-
Hardware considerations and capacity planning
-
Compute hardware requirements
-
Network design
-
Storage design
-
Flavor sizing
-
Resource overcommitment strategies
-
-
Highly Available Control Plane
-
HA for OpenStack services
-
HA database configuration
-
HA message queue setup
-
Active-Active vs. Active-Passive deployments
-
Multi-region deployments
-
-
Cloud partitioning and scheduler filters
-
Implementing cloud partitions (host-aggregates): rationale and methods
-
Nova scheduler filters
-
In-depth analysis of filter code
-
-
Workload migration
-
Cold and live migration
-
Optimizing live migration
-
Migration exercises and troubleshooting
-
-
Policies and authorization in OpenStack
-
Oslo.policy
-
Creating meaningful roles using policy files
-
Verifying API access for specific users
-
-
In-depth OpenStack Networking (SDN) (2-3 hours)
-
Network types (local, flat, vlan, vxlan, gre)
-
Detailed network flow and architecture in various Neutron deployments
-
East-West traffic in tenant networks
-
North-South traffic in tenant networks
-
Traffic in provider-only deployments
-
-
Neutron plugins
- Linux Bridge
- Open vSwitch
-
OVS troubleshooting and exercises
-
Troubleshooting security groups (iptables, tcpdump)
-
Port-security adjustments and vIP management
-
Distributed Virtual Routers
-
LBaaS and the Octavia project
-
VPNaaS
-
-
OpenStack monitoring and telemetry
-
Ceilometer service
-
External monitoring solutions
-
-
Advanced cloud and hypervisor features
-
CPU pinning and NUMA architecture
-
SR-IOV
-
-
Cloud-init and image customization
-
Metadata Service
-
Retrieving information from the metadata service
-
-
Block storage backends
-
LVM
-
Ceph RBD
-
Physical appliances
-
Storage network considerations
-
-
Upgrading OpenStack
-
Upgrade strategies and procedures
-
Zero-downtime upgrades
-
-
Bare-metal provisioning with OpenStack
-
Ironic module
-
Undercloud and overcloud concepts
-
-
Various exercises on troubleshooting OpenStack clusters
-
Sample examination tasks
-
The future of OpenStack
Requirements
- Fundamental Linux administration skills
- Essential networking knowledge
- Basic understanding of cloud computing concepts
Testimonials (1)
communication, knowledge from experience, solve problems,