NetApp - Unified Manager 9.4: installation on RHEL 7
NetApp Solution · Config document · referenced from Unified Manager and API Services
umadmin; it is changed at the first login to the web interface.The installation of OnCommand Unified Manager 9.4 on a RHEL 7.5 virtual machine built from a hardened baseline: data disk, the baseline's obstacles, repositories, packages, the product and the firewall.
| Item | Value |
|---|---|
| Runs on | dc1-a-vcocm001.adm.example.net, as root |
| Virtual machine | 2 vCPU, 10240 MB RAM, 32 GB OS disk, 100 GB data disk, VLAN 1024 |
| Also applied to | DC2-A-VCOCM001 at site 2 according to the design; the notes hold no separate log |
| Product version | OnCommand Unified Manager 9.4, MySQL Community 5.7.23, OpenJDK 1.8 |
| Operating system | RHEL 7.5 |
The command set
# --- 1. Data disk: partition, LVM, file system ------------------------------- mkdir -p /opt/netapp # One primary partition over the whole 100 GB disk (interactive: n, p, 1, # defaults, w). fdisk /dev/vdb vgcreate vg01 /dev/vdb1 vgdisplay -v vg01 lvcreate -L 99G -n lv_data vg01 ls -l /dev/mapper/vg01-lv_data mkfs.ext4 /dev/vg01/lv_data # Line added to /etc/fstab: # # Data disk for Netapp OnCommand Unified Manager # /dev/mapper/vg01-lv_data /opt/netapp ext4 defaults 0 2 vi /etc/fstab mount -a # --- 2. Prerequisites: move the baseline out of the way ---------------------- # The baseline mounts /usr read-only. mount -o remount,rw /usr # Replace the MariaDB-common libraries of the custom repository with the # stock RHEL 7 mariadb-libs. yum --disablerepo=* --enablerepo=cobbler-rhel-7-server-rpms swap MariaDB-common mariadb-libs # Keep MariaDB packages of the custom repository out for good. Line added to # the section [cobbler-custom-rpms] of /etc/yum.repos.d/cobbler.repo: # exclude=MariaDB* vi /etc/yum.repos.d/cobbler.repo # --- 3. Packages --------------------------------------------------------------- yum install wget yum install zip p7zip unzip java-1.8.0-openjdk # --- 4. MySQL Community repository, through the proxy ------------------------- export http_proxy="10.11.16.113:3128" export https_proxy="10.11.16.113:3128" export ftp_proxy="10.11.16.113:3128" export SSL_CERT_FILE=/etc/pki/tls/certs/ca-bundle.crt export no_proxy="127.0.0.1, localhost,.adm.example.net,.example.net" cd /tmp wget http://repo.mysql.com/yum/mysql-5.7-community/el/7/x86_64/mysql57-community-release-el7-7.noarch.rpm yum install ./mysql57-community-release-el7-7.noarch.rpm # --- 5. Maintenance group and user ------------------------------------------- # The password must be the installer's expected default at this point, # otherwise the installation fails. groupadd maintenance adduser --shell /bin/maintenance-user-shell.sh --home /home/umadmin -g maintenance umadmin passwd umadmin # --- 6. Installation ------------------------------------------------------------ # The ZIP from the vendor's support site is placed in a directory per version. cd /opt/netapp/install/9.4 unzip ./OnCommandUnifiedManager-rhel7-9.4.zip # Pre-installation check, then read its log. ./pre_install_check.sh less ./pre_install_check.log # Six product RPMs; mysql-community-server comes as a dependency. yum install *.rpm # --- 7. Firewall ---------------------------------------------------------------- firewall-cmd --permanent --add-service=https firewall-cmd --permanent --add-port=3306/tcp firewall-cmd --reload # --- 8. Daily removal of recording files --------------------------------------- # The script is its own Config document. vi /etc/cron.daily/ocie-recording-cleaning chmod +x /etc/cron.daily/ocie-recording-cleaning chmod 700 /etc/cron.daily/ocie-recording-cleaning
The script of section 8 is ocie-recording-cleaning. Everything after this listing was done in the web interface and is described in the Article.
An older copy of the notes installs Unified Manager 7.2P1 on RHEL 7.4 into a systemd-nspawn container and opens more ports (HTTP, 8080, 2222). That is not what this listing shows; the container method survives in API Services: the nspawn container.
Checked against Active IQ Unified Manager 9.18
| As built | Today |
|---|---|
| OnCommand Unified Manager 9.4 | Renamed Active IQ Unified Manager with version 9.6. The current documentation version is 9.18 |
| RHEL 7.5 | RHEL 8.x and 9.6, x86_64, base environment "Server with GUI", on a dedicated server |
MySQL Community 5.7.23 from the mysql57-community repository | MySQL Community Edition 8.4.10 from the MySQL repository |
java-1.8.0-openjdk | OpenJDK 17.0.14; only one Java version may be installed |
| 2 vCPU, 10 GB RAM, 100 GB data disk | Recommended: 4 CPUs, 12 GB RAM, 150 GB of disk, of which 100 GB for /opt/netapp/data, and at least 10 GB in /tmp |
MariaDB-common swapped for the stock libraries, the custom repository excluded | Still the rule: the required third-party software must not be installed from repositories other than the listed ones |
firewall-cmd --permanent --add-service=https | Unchanged |
firewall-cmd --permanent --add-port=3306/tcp | Was needed only for API Services, which no longer exists; not re-checked |
User umadmin in group maintenance | Still present |
Nothing in this listing can be reused as it stands: operating system, database and Java are all two major versions on. The fight with a hardened baseline would be the same, since the product still insists on a dedicated server and its own repositories.