LINUXOR.SK ... open source notes ...

NetApp - API Services: the nspawn container

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

NetApp Solution · Config document · referenced from Unified Manager and API Services

notePasswords are placeholders. The container is built by hand and is not a platform either vendor supports.

How the systemd-nspawn container for OnCommand API Services was built on a RHEL 7.4 host: a root tree made with rpm and yum --installroot, first start, the service, the firewall, and the installation of the product inside.

ItemValue
Runs ondc1-a-vcocm002.adm.example.net, as root; lines marked "in the container" run inside api_container
Container root/chroot/api, on the data disk mounted at /chroot
Machine nameapi_container
Product versionOnCommand API Services 2.0.0, MySQL Community 5.7, OpenJDK 1.8
Operating systemRHEL 7.4, host and container

The command set

bash
# --- 1. Host: data disk -------------------------------------------------------
mkdir -p /opt/netapp/data
# One primary partition over the whole 100 GB disk (interactive: n, p, 1,
# defaults, w).
fdisk /dev/vdb
vgcreate vg01 /dev/vdb1
vgdisplay -v vg01
lvcreate -L 99G -n lv_data vg01
ls -l /dev/mapper/vg01-lv_data
mkfs.ext4 /dev/vg01/lv_data
# Line added to /etc/fstab:
#   /dev/mapper/vg01-lv_data   /chroot   ext4   defaults   0 2
vi /etc/fstab
mount -a

# --- 2. Host: build the root tree ---------------------------------------------
# yumdownloader comes from yum-utils.
yum install yum-utils
mkdir -p /chroot/api
mkdir -p /chroot/api/var/lib/rpm
# Empty RPM database, then the release package of the distribution.
rpm --root /chroot/api --initdb
yumdownloader --destdir=/tmp redhat-release
rpm --root /chroot/api -ivh --nodeps /tmp/redhat-release*rpm
# Tools, systemd and dbus, Java, and the group "Minimal Install".
yum --installroot=/chroot/api -y install zip p7zip unzip systemd dbus mc bind-utils net-tools
yum --installroot=/chroot/api -y install java-1.8.0-openjdk
yum --installroot=/chroot/api group install "Minimal Install"

# --- 3. Host: repositories inside the tree ------------------------------------
cd /chroot/api/_install
wget http://repo.mysql.com/yum/mysql-5.7-community/el/7/x86_64/mysql57-community-release-el7-7.noarch.rpm
yum --installroot=/chroot/api -y install /chroot/api/_install/mysql57-community-release-el7-7.noarch.rpm
cp /etc/yum.repos.d/rhel-7-server-rpms.repo /chroot/api/etc/yum.repos.d/
cp /etc/yum.repos.d/epel.repo /chroot/api/etc/yum.repos.d/

# --- 4. First start, without booting -------------------------------------------
# SELinux permissive for this step only.
setenforce 0
systemd-nspawn -D /chroot/api/ --machine api_container
# In the container: root password, and allow "machinectl login api_container".
passwd
echo "pts/0" >> /etc/securetty
# Leaving the shell stops the container.
logout
setenforce 1

# --- 5. Test boot ---------------------------------------------------------------
# -b boots the tree as a full system.
systemd-nspawn -D /chroot/api/ --machine api_container -b --network-bridge=bridge0 --network-veth
# In the container: move the SSH daemon to another port.
# Line changed in /etc/ssh/sshd_config:
#   Port 3333
vi /etc/ssh/sshd_config
# Kill the container: Ctrl and ] three times.

# --- 6. Host: the container as a service ---------------------------------------
# The unit is its own Config document.
vi /etc/systemd/system/api_container.service
systemctl add-wants multi-user api_container

# --- 7. Host: firewall -----------------------------------------------------------
firewall-cmd --permanent --add-port=8443/tcp
firewall-cmd --permanent --add-port=2222/tcp
firewall-cmd --reload

# --- 8. In the container: CA certificates --------------------------------------
# A prepared bundle of the internal CA certificates with its install script.
cd /_install
unzip ./ca.zip
chmod +x ./ca.sh
./ca.sh

# --- 9. In the container: accounts ----------------------------------------------
groupadd maintenance
adduser --shell /bin/maintenance-user-shell.sh --home /home/umadmin -g maintenance umadmin
passwd umadmin
adduser jboss
passwd jboss

# --- 10. In the container: install API Services --------------------------------
chmod +x /_install/OnCommand-API-services-2.0.0.bin
export http_proxy="10.11.16.113:3128"
export https_proxy="10.11.16.113:3128"
export ftp_proxy="10.11.16.113:3128"
export SSL_CERT_FILE=/etc/pki/ca-trust/source/anchors/proxy_ca_self.crt
export no_proxy="127.0.0.1, localhost,.adm.example.net,.example.net"
yum remove MariaDB-common
cd /_install
# Interactive. Answers as given:
#   install OnCommand API Services            : y
#   password for admin user                   : <API_ADMIN_PASSWORD>
#   port for OnCommand API Services           : 8443 (default)
#   port for the Jboss service (default 80)   : 8080
./OnCommand-API-services-2.0.0.bin

The unit of section 6 is api_container.service; the certificate follows in API Services: Java keystore.

Three things in the listing do not agree with each other, and the notes leave them so.

WhereWhat
Sections 5 and 7sshd_config in the container says port 3333; the firewall and the design open 2222
Sections 5 and 6The test boot uses a bridge and a veth pair; the service has no network option and therefore shares the host's network
Section 3The directory /chroot/api/_install is used before any command creates it

The notes end with two experiments that are not part of the build: moving MySQL to port 3360, which the application did not follow, and the kernel argument user_namespace.enable=1. Both are described in the Article.

Checked against Active IQ Unified Manager 9.18

As builtToday
OnCommand API Services 2.0End of support. The last version, 2.2, reached end of availability on 2020-05-14 and end of version support on 2021-04-30
A separate REST front end for the monitoring systemThe REST APIs of Unified Manager and its API gateway, which passes ONTAP REST calls through with Unified Manager credentials

There is nothing left to compare the build with: the product no longer exists, and with it the reason for the container.

← solutionz