
Instead of using SSH to live migrate VM's use TLS as this is more secure and SSH migrations are deprecated. https://docs.openstack.org/nova/xena/admin/secure-live-migration-with-qemu-native-tls.html A pre-existing PKI (Public Key Infrastruture) setup is required. TLS live migrations require that all compute hosts can communcate with each other on port 16514 and port range 49152 to 49261. To enable TLS live migrations, both libvirt and QEMU require server and client certificates, the server certicicates is used to verify servers and the client cert is used by servers to authenticate clients. A single cert is created by the pki role, that can be used by both libvirt and QEMU for both client and server auth. The client, server and CA certifcates need to installed in a number of locations on each compute host: * For Libvirt https://libvirt.org/tlscerts.html * For QEMU https://github.com/libvirt/libvirt/blob/master/src/qemu/qemu.conf Depends-On: https://review.opendev.org/c/openstack/ansible-role-pki/+/815007 Depends-On: https://review.opendev.org/c/openstack/ansible-role-pki/+/815849 Depends-On: https://review.opendev.org/c/openstack/ansible-role-pki/+/816857 Change-Id: Iddbe8764bb6d3cd3eaee122b2d5ddc02fa3f7662
93 lines
2.3 KiB
YAML
93 lines
2.3 KiB
YAML
---
|
|
# Copyright 2015, Rackspace US, Inc.
|
|
#
|
|
# Licensed under the Apache License, Version 2.0 (the "License");
|
|
# you may not use this file except in compliance with the License.
|
|
# You may obtain a copy of the License at
|
|
#
|
|
# http://www.apache.org/licenses/LICENSE-2.0
|
|
#
|
|
# Unless required by applicable law or agreed to in writing, software
|
|
# distributed under the License is distributed on an "AS IS" BASIS,
|
|
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
# See the License for the specific language governing permissions and
|
|
# limitations under the License.
|
|
|
|
- name: Stop libvirt-bin
|
|
service:
|
|
name: "{{ libvirt_service_name }}"
|
|
enabled: yes
|
|
state: "stopped"
|
|
listen:
|
|
- Restart libvirt-bin
|
|
- "cert installed"
|
|
|
|
- name: Enable sockets when needed
|
|
service:
|
|
name: "{{ item.name | default(item) }}"
|
|
state: "{{ item.condition | default(False) | ternary('started', 'stopped') }}"
|
|
enabled: "{{ item.condition | default(False) }}"
|
|
masked: no
|
|
when:
|
|
- libvirtd_version is version('5.7', '>=')
|
|
with_items:
|
|
- name: libvirtd-tls.socket
|
|
condition: "{{ nova_libvirtd_listen_tls | bool }}"
|
|
- name: libvirtd-tcp.socket
|
|
condition: "{{ nova_libvirtd_listen_tcp | bool }}"
|
|
listen:
|
|
- Restart libvirt-bin
|
|
- "cert installed"
|
|
|
|
- name: Start libvirt-bin
|
|
service:
|
|
name: "{{ libvirt_service_name }}"
|
|
enabled: yes
|
|
state: "started"
|
|
listen:
|
|
- Restart libvirt-bin
|
|
- "cert installed"
|
|
|
|
- name: Stop services
|
|
service:
|
|
name: "{{ item.service_name }}"
|
|
enabled: yes
|
|
state: "stopped"
|
|
daemon_reload: yes
|
|
with_items: "{{ filtered_nova_services }}"
|
|
register: _stop
|
|
until: _stop is success
|
|
retries: 5
|
|
delay: 2
|
|
listen:
|
|
- "Restart nova services"
|
|
- "venv changed"
|
|
|
|
# NOTE (noonedeadpunk): Remove this task after Xena release
|
|
- name: Remove obsoleted policy.json
|
|
file:
|
|
path: "/etc/nova/policy.json"
|
|
state: absent
|
|
listen:
|
|
- "Restart nova services"
|
|
- "venv changed"
|
|
|
|
- name: Start services
|
|
service:
|
|
name: "{{ item.service_name }}"
|
|
enabled: yes
|
|
state: "started"
|
|
daemon_reload: yes
|
|
with_items: "{{ filtered_nova_services }}"
|
|
register: _start
|
|
until: _start is success
|
|
retries: 5
|
|
delay: 2
|
|
listen:
|
|
- "Restart nova services"
|
|
- "venv changed"
|
|
|
|
- meta: noop
|
|
listen: Manage LB
|
|
when: false
|