NetApp - API Services: the nspawn container
NetApp Solution · Config document · referenced from Unified Manager and API Services
How the systemd-nspawn container for OnCommand API Services was built on a RHEL 7.4 host: a root tree made with rpm and yum --installroot, first start, the service, the firewall, and the installation of the product inside.
| Item | Value |
|---|---|
| Runs on | dc1-a-vcocm002.adm.example.net, as root; lines marked "in the container" run inside api_container |
| Container root | /chroot/api, on the data disk mounted at /chroot |
| Machine name | api_container |
| Product version | OnCommand API Services 2.0.0, MySQL Community 5.7, OpenJDK 1.8 |
| Operating system | RHEL 7.4, host and container |
The command set
# --- 1. Host: data disk ------------------------------------------------------- mkdir -p /opt/netapp/data # One primary partition over the whole 100 GB disk (interactive: n, p, 1, # defaults, w). fdisk /dev/vdb vgcreate vg01 /dev/vdb1 vgdisplay -v vg01 lvcreate -L 99G -n lv_data vg01 ls -l /dev/mapper/vg01-lv_data mkfs.ext4 /dev/vg01/lv_data # Line added to /etc/fstab: # /dev/mapper/vg01-lv_data /chroot ext4 defaults 0 2 vi /etc/fstab mount -a # --- 2. Host: build the root tree --------------------------------------------- # yumdownloader comes from yum-utils. yum install yum-utils mkdir -p /chroot/api mkdir -p /chroot/api/var/lib/rpm # Empty RPM database, then the release package of the distribution. rpm --root /chroot/api --initdb yumdownloader --destdir=/tmp redhat-release rpm --root /chroot/api -ivh --nodeps /tmp/redhat-release*rpm # Tools, systemd and dbus, Java, and the group "Minimal Install". yum --installroot=/chroot/api -y install zip p7zip unzip systemd dbus mc bind-utils net-tools yum --installroot=/chroot/api -y install java-1.8.0-openjdk yum --installroot=/chroot/api group install "Minimal Install" # --- 3. Host: repositories inside the tree ------------------------------------ cd /chroot/api/_install wget http://repo.mysql.com/yum/mysql-5.7-community/el/7/x86_64/mysql57-community-release-el7-7.noarch.rpm yum --installroot=/chroot/api -y install /chroot/api/_install/mysql57-community-release-el7-7.noarch.rpm cp /etc/yum.repos.d/rhel-7-server-rpms.repo /chroot/api/etc/yum.repos.d/ cp /etc/yum.repos.d/epel.repo /chroot/api/etc/yum.repos.d/ # --- 4. First start, without booting ------------------------------------------- # SELinux permissive for this step only. setenforce 0 systemd-nspawn -D /chroot/api/ --machine api_container # In the container: root password, and allow "machinectl login api_container". passwd echo "pts/0" >> /etc/securetty # Leaving the shell stops the container. logout setenforce 1 # --- 5. Test boot --------------------------------------------------------------- # -b boots the tree as a full system. systemd-nspawn -D /chroot/api/ --machine api_container -b --network-bridge=bridge0 --network-veth # In the container: move the SSH daemon to another port. # Line changed in /etc/ssh/sshd_config: # Port 3333 vi /etc/ssh/sshd_config # Kill the container: Ctrl and ] three times. # --- 6. Host: the container as a service --------------------------------------- # The unit is its own Config document. vi /etc/systemd/system/api_container.service systemctl add-wants multi-user api_container # --- 7. Host: firewall ----------------------------------------------------------- firewall-cmd --permanent --add-port=8443/tcp firewall-cmd --permanent --add-port=2222/tcp firewall-cmd --reload # --- 8. In the container: CA certificates -------------------------------------- # A prepared bundle of the internal CA certificates with its install script. cd /_install unzip ./ca.zip chmod +x ./ca.sh ./ca.sh # --- 9. In the container: accounts ---------------------------------------------- groupadd maintenance adduser --shell /bin/maintenance-user-shell.sh --home /home/umadmin -g maintenance umadmin passwd umadmin adduser jboss passwd jboss # --- 10. In the container: install API Services -------------------------------- chmod +x /_install/OnCommand-API-services-2.0.0.bin export http_proxy="10.11.16.113:3128" export https_proxy="10.11.16.113:3128" export ftp_proxy="10.11.16.113:3128" export SSL_CERT_FILE=/etc/pki/ca-trust/source/anchors/proxy_ca_self.crt export no_proxy="127.0.0.1, localhost,.adm.example.net,.example.net" yum remove MariaDB-common cd /_install # Interactive. Answers as given: # install OnCommand API Services : y # password for admin user : <API_ADMIN_PASSWORD> # port for OnCommand API Services : 8443 (default) # port for the Jboss service (default 80) : 8080 ./OnCommand-API-services-2.0.0.bin
The unit of section 6 is api_container.service; the certificate follows in API Services: Java keystore.
Three things in the listing do not agree with each other, and the notes leave them so.
| Where | What |
|---|---|
| Sections 5 and 7 | sshd_config in the container says port 3333; the firewall and the design open 2222 |
| Sections 5 and 6 | The test boot uses a bridge and a veth pair; the service has no network option and therefore shares the host's network |
| Section 3 | The directory /chroot/api/_install is used before any command creates it |
The notes end with two experiments that are not part of the build: moving MySQL to port 3360, which the application did not follow, and the kernel argument user_namespace.enable=1. Both are described in the Article.
Checked against Active IQ Unified Manager 9.18
| As built | Today |
|---|---|
| OnCommand API Services 2.0 | End of support. The last version, 2.2, reached end of availability on 2020-05-14 and end of version support on 2021-04-30 |
| A separate REST front end for the monitoring system | The REST APIs of Unified Manager and its API gateway, which passes ONTAP REST calls through with Unified Manager credentials |
There is nothing left to compare the build with: the product no longer exists, and with it the reason for the container.