# Installing on Kolla Openstack

## 1] Plan for Deployment

{% hint style="info" %}
Please ensure that the Trilio Appliance has been updated to the latest maintenance release before continuing the installation.
{% endhint %}

> Refer to the below-mentioned acceptable values for the placeholders **`triliovault_tag`** and **`kolla_base_distro`** , in this document as per the Openstack environment:

| Openstack Version | triliovault\_tag | kolla\_base\_distro     |
| ----------------- | ---------------- | ----------------------- |
| Victoria          | 4.3.2-victoria   | <p>ubuntu<br>centos</p> |
| Wallaby           | 4.3.2-wallaby    | <p>ubuntu<br>centos</p> |
| Yoga              | 4.3.2-yoga       | <p>ubuntu<br>centos</p> |
| Zed               | 4.3.2-zed        | <p>ubuntu<br>rocky</p>  |

### 1.1] Select backup target type

Backup target storage is used to store backup images taken by Trilio and details needed for configuration:

Following backup target types are supported by Trilio. Select one of them and get it ready before proceeding to the next step.

a) NFS

Need NFS share path

b) Amazon S3

\- S3 Access Key\
\- Secret Key\
\- Region\
\- Bucket name

c) Other S3 compatible storage (Like, Ceph based S3)

\- S3 Access Key\
\- Secret Key\
\- Region\
\- Endpoint URL (Valid for S3 other than Amazon S3)\
\- Bucket name

## 2] Clone Trilio Deployment Scripts

Clone triliovault-cfg-scripts GitHub repository on Kolla ansible server at '/root' or any other directory of your preference. Afterwards, copy Trilio Ansible role into Kolla-ansible roles directory

```
git clone -b 4.3.2 https://github.com/trilioData/triliovault-cfg-scripts.git
cd triliovault-cfg-scripts/kolla-ansible/

# For Centos and Ubuntu
cp -R ansible/roles/triliovault /usr/local/share/kolla-ansible/ansible/roles/
```

## 3] Hook Trilio deployment scripts to Kolla-ansible deploy scripts

### 3.1] Add Trilio global variables to globals.yml

```
## For Centos and Ubuntu
- Take backup of globals.yml
cp /etc/kolla/globals.yml /opt/

- If the OpenStack release is other than 'zed' append below Trilio global variables to globals.yml
cat ansible/triliovault_globals.yml >> /etc/kolla/globals.yml

- If the OpenStack release is ‘zed' append below Trilio global variables to globals.yml
cat ansible/triliovault_globals_zed.yml >> /etc/kolla/globals.yml
```

### 3.2] Add Trilio passwords to kolla passwords.yaml

Append `triliovault_passwords.yml` to `/etc/kolla/passwords.yml`. Passwords are empty. Set these passwords manually in the `/etc/kolla/passwords.yml`.

```
## For Centos and Ubuntu
- Take backup of passwords.yml
cp /etc/kolla/passwords.yml /opt/

- Append Trilio global variables to passwords.yml 
cat ansible/triliovault_passwords.yml >> /etc/kolla/passwords.yml

- Edit '/etc/kolla/passwords.yml', go to end of the file and set trilio passwords.
```

### 3.3] Append Trilio site.yml content to kolla ansible’s site.yml

```
# For Centos and Ubuntu
- Take backup of site.yml
cp /usr/local/share/kolla-ansible/ansible/site.yml /opt/

# If the OpenStack release is ‘yoga' append below Trilio code to site.yml  
cat ansible/triliovault_site_yoga.yml >> /usr/local/share/kolla-ansible/ansible/site.yml    

# If the OpenStack release is other than 'yoga' append below Trilio code to site.yml 
cat ansible/triliovault_site.yml >> /usr/local/share/kolla-ansible/ansible/site.yml                                                            
```

### 3.4] Append triliovault\_inventory.txt to your cloud’s kolla-ansible inventory file.

```
For example:
If your inventory file name path '/root/multinode' then use following command.

cat ansible/triliovault_inventory.txt >> /root/multinode
```

### 3.5] Configure multi-IP NFS

{% hint style="info" %}
This step is only required when the multi-IP NFS feature is used to connect different datamovers to the same NFS volume through multiple IPs
{% endhint %}

On kolla-ansible server node, change directory

```
cd triliovault-cfg-scripts/common/
```

Edit file '`triliovault_nfs_map_input.yml`' in the current directory and provide compute host and NFS share/ip map.

{% hint style="info" %}
*If IP addresses are used in the kolla-ansible inventory file then you should use same IP addresses in 'triliovault\_nfs\_map\_input.yml' file too. If you used hostnames there then you need to use same hostnames here in nfs map input file.*

*Compute host names or IP addresses that you are using in nfs map input file here should match with kolla-ansible inventory file entries.*
{% endhint %}

`vi triliovault_nfs_map_input.yml`

The triliovault\_nfs\_map\_imput.yml is explained [here](https://docs.trilio.io/openstack/t4o-4.3/deployment/multi-ip-nfs-backup-target-mapping-file-configuration).

Update `PyYAML` on the kolla-ansible server node only

```
pip3 install -U pyyaml
```

Expand the map file to create one to one mapping of compute and nfs share.

```
python ./generate_nfs_map.py
```

Result will be in file - '`triliovault_nfs_map_output.yml`'

Validate output map file

Open file '`triliovault_nfs_map_output.yml`

`vi triliovault_nfs_map_output.yml`

available in the current directory and validate that all compute nodes are covered with all necessary nfs shares.

Append this output map file to 'triliovault\_globals.yml'\
File Path: '/home/stack/triliovault-cfg-scripts/kolla-ansible/ansible/triliovault\_globals.yml’

```
cat triliovault_nfs_map_output.yml >> ../kolla-ansible/ansible/triliovault_globals.yml
```

Ensure to set multi\_ip\_nfs\_enabled in \_\_ triliovault\_globals.yml file to yes

## 4] Edit globals.yml to set Trilio parameters

Edit `/etc/kolla/globals.yml` file to fill Trilio backup target and build details.\
You will find the Trilio related parameters at the end of `globals.yml` file.\
Details like Trilio build version, backup target type, backup target details, etc need to be filled out.

Following is the list of parameters that the usr needs to edit.

| Parameter                              | Defaults/choices                                                                                                                                                                         | comments                                                                                                                                                                                                                                                                                                                                             |
| -------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| triliovault\_tag                       | \<triliovault\_tag >                                                                                                                                                                     | Use the triliovault tag as per your Kolla openstack version. Exact tag is mentioned in the 1st step                                                                                                                                                                                                                                                  |
| horizon\_image\_full                   | Uncomment                                                                                                                                                                                | <p>By default, Trilio Horizon container would not get deployed.</p><p>Uncomment this parameter to deploy Trilio Horizon container instead of Openstack Horizon container.</p>                                                                                                                                                                        |
| triliovault\_docker\_username          | \<dockerhub-login-username>                                                                                                                                                              | <p>Default docker user of Trilio<br>(read permission only).<br>Get the Dockerhub login credentials from Trilio Sales/Support team</p>                                                                                                                                                                                                                |
| triliovault\_docker\_password          | \<dockerhub-login-password>                                                                                                                                                              | <p>Password for default docker user of Trilio<br>Get the Dockerhub login credentials from Trilio Sales/Support team</p>                                                                                                                                                                                                                              |
| triliovault\_docker\_registry          | **Default value:** docker.io                                                                                                                                                             | <p>Edit this value if a different container registry for Trilio containers is to be used.<br>Containers need to be pulled from docker.io and pushed to chosen registry first.</p>                                                                                                                                                                    |
| triliovault\_backup\_target            | <ul><li><code>nfs</code></li><li><code>amazon\_s3</code></li><li>other\_s3\_compatible</li></ul>                                                                                         | <p><code>nfs</code> if the backup target is NFS</p><p><code>amazon\_s3</code> if the backup target is Amazon S3</p><p><code>other\_s3\_compatible</code> if the backup target type is S3 but not amazon S3.</p>                                                                                                                                      |
| multi\_ip\_nfs\_enabled                | <p>yes<br>no<br>default: no</p>                                                                                                                                                          | This parameter is valid only If you want to use multiple IP/endpoints based NFS share/shares as backup target for TriloVault.                                                                                                                                                                                                                        |
| triliovault\_nfs\_shares               | \<NFS-IP/FQDN>:/\<NFS path>                                                                                                                                                              | NFS share path example: ‘192.168.122.101:/nfs/tvault’                                                                                                                                                                                                                                                                                                |
| triliovault\_nfs\_options              | <p><code>'nolock,soft,timeo=180,</code><br><code>intr,lookupcache=none'</code>.<br>for Cohesity nfs: <code>'nolock,soft,timeo=600,intr,lookupcache=none,nfsvers=3,retrans=10</code>'</p> | <p>-These parameter set NFS mount options.<br>-Keep default values, unless a special requirement exists.</p>                                                                                                                                                                                                                                         |
| triliovault\_s3\_access\_key           | S3 Access Key                                                                                                                                                                            | Valid for `amazon_s3` and                                                                                                                                                                                                                                                                                                                            |
| triliovault\_s3\_secret\_key           | S3 Secret Key                                                                                                                                                                            | Valid for `amazon_s3` and `other_s3_compatible`                                                                                                                                                                                                                                                                                                      |
| triliovault\_s3\_region\_name          | <ul><li><strong>Default value:</strong> us-east-1</li><li>S3 Region name</li></ul>                                                                                                       | <p>Valid for <code>amazon\_s3</code> and <code>other\_s3\_compatible</code></p><p>If s3 storage doesn't have region parameter keep default</p>                                                                                                                                                                                                       |
| triliovault\_s3\_bucket\_name          | S3 Bucket name                                                                                                                                                                           | Valid for `amazon_s3` and `other_s3_compatible`                                                                                                                                                                                                                                                                                                      |
| triliovault\_s3\_endpoint\_url         | S3 Endpoint URL                                                                                                                                                                          | Valid for `other_s3_compatible` only                                                                                                                                                                                                                                                                                                                 |
| triliovault\_s3\_ssl\_enabled          | <ul><li>True</li><li>False</li></ul>                                                                                                                                                     | <p>Valid for <code>other\_s3\_compatible</code> only</p><p>Set true for SSL enabled S3 endpoint URL</p>                                                                                                                                                                                                                                              |
| triliovault\_s3\_ssl\_cert\_file\_name | s3-cert.pem                                                                                                                                                                              | <p>Valid for <code>other\_s3\_compatible</code> only with SSL enabled and self signed certificates</p><p>OR issued by a private authority.<br>In this case, copy the <code>ceph s3 ca chain file</code> to<code>/etc/kolla/config/triliovault/</code></p><p>directory on ansible server. Create this directory if it does not exist already.<br></p> |
| triliovault\_copy\_ceph\_s3\_ssl\_cert | <ul><li>True</li><li>False</li></ul>                                                                                                                                                     | <p>Valid for <code>other\_s3\_compatible</code> only</p><p>Set to True when:<br>SSL enabled with self-signed certificates or issued by a private authority.</p>                                                                                                                                                                                      |

In the case of a different registry than docker hub, Trilio containers need to be pulled from docker.io and pushed to preferred registries.

Following are the triliovault container image URLs for **4.3** releases\*\*.\*\*\
Replace **`kolla_base_distro`** and **`triliovault_tag`** variables with their values.\\

> This {{ kolla\_base\_distro }} variable can be either 'centos' or 'ubuntu' depends on your base OpenStack distro

{% hint style="info" %}
Trilio supports the **Source-based** containers from the **OpenStack Yoga** release \*\*\*\* onwards.
{% endhint %}

Below are the **Source-based** OpenStack deployment images

<pre><code>
<strong>1. docker.io/trilio/kolla-{{ kolla_base_distro }}-trilio-datamover:{{ triliovault_tag }}
</strong>2. docker.io/trilio/kolla-{{ kolla_base_distro }}-trilio-datamover-api:{{ triliovault_tag }}
3. docker.io/trilio/kolla-{{ kolla_base_distro }}-trilio-horizon-plugin:{{ triliovault_tag }}

## EXAMPLE from Kolla Ubuntu source based OpenStack
docker.io/trilio/kolla-ubuntu-trilio-datamover:{{ triliovault_tag }}
docker.io/trilio/kolla-ubuntu-trilio-datamover-api:{{ triliovault_tag }}
docker.io/trilio/kolla-ubuntu-trilio-horizon-plugin:{{ triliovault_tag }}
</code></pre>

Below are the **Binary-based** OpenStack deployment images

```
1. docker.io/trilio/kolla-{{ kolla_base_distro }}-trilio-datamover:{{ triliovault_tag }}
2. docker.io/trilio/kolla-{{ kolla_base_distro }}-trilio-datamover-api:{{ triliovault_tag }}
3. docker.io/trilio/{{ kolla_base_distro }}-binary-trilio-horizon-plugin:{{ triliovault_tag }}

## EXAMPLE from Kolla Ubuntu binary based OpenStack
docker.io/trilio/kolla-ubuntu-trilio-datamover:{{ triliovault_tag }}
docker.io/trilio/kolla-ubuntu-trilio-datamover-api:{{ triliovault_tag }}
docker.io/trilio/ubuntu-binary-trilio-horizon-plugin:{{ triliovault_tag }}
```

## 5] Enable Trilio Snapshot mount feature

To enable Trilio's Snapshot mount feature it is necessary to make the Trilio Backup target available to the nova-compute and nova-libvirt containers.

Edit `/usr/local/share/kolla-ansible/ansible/roles/nova-cell/defaults/main.yml` and find `nova_libvirt_default_volumes` variables. Append the Trilio mount bind `/var/trilio:/var/trilio:shared` to the list of already existing volumes.

For a default Kolla installation, will the variable look as follows afterward:

```
nova_libvirt_default_volumes:
  - "{{ node_config_directory }}/nova-libvirt/:{{ container_config_directory }}/:ro"
  - "/etc/localtime:/etc/localtime:ro"
  - "{{ '/etc/timezone:/etc/timezone:ro' if ansible_os_family == 'Debian' else '' }}"
  - "/lib/modules:/lib/modules:ro"
  - "/run/:/run/:shared"
  - "/dev:/dev"
  - "/sys/fs/cgroup:/sys/fs/cgroup"
  - "kolla_logs:/var/log/kolla/"
  - "libvirtd:/var/lib/libvirt"
  - "{{ nova_instance_datadir_volume }}:/var/lib/nova/"
  - "
{% if enable_shared_var_lib_nova_mnt | bool %}/var/lib/nova/mnt:/var/lib/nova/mnt:shared{% endif %}



"
  - "nova_libvirt_qemu:/etc/libvirt/qemu"
  - "{{ kolla_dev_repos_directory ~ '/nova/nova:/var/lib/kolla/venv/lib/python' ~ distro_python_version ~ '/site-packages/nova' if nova_dev_mode | bool else '' }
  - "/var/trilio:/var/trilio:shared"
```

Next, find the variable `nova_compute_default_volumes` in the same file and append the mount bind `/var/trilio:/var/trilio:shared` to the list.

After the change will the variable look for a default Kolla installation as follows:

```
nova_compute_default_volumes:
  - "{{ node_config_directory }}/nova-compute/:{{ container_config_directory }}/:ro"
  - "/etc/localtime:/etc/localtime:ro"
  - "{{ '/etc/timezone:/etc/timezone:ro' if ansible_os_family == 'Debian' else '' }}"
  - "/lib/modules:/lib/modules:ro"
  - "/run:/run:shared"
  - "/dev:/dev"
  - "kolla_logs:/var/log/kolla/"
  - "
{% if enable_iscsid | bool %}iscsi_info:/etc/iscsi{% endif %}"
  - "libvirtd:/var/lib/libvirt"
  - "{{ nova_instance_datadir_volume }}:/var/lib/nova/"
  - "{% if enable_shared_var_lib_nova_mnt | bool %}/var/lib/nova/mnt:/var/lib/nova/mnt:shared{% endif %}


"
  - "{{ kolla_dev_repos_directory ~ '/nova/nova:/var/lib/kolla/venv/lib/python' ~ distro_python_version ~ '/site-packages/nova' if nova_dev_mode | bool else '' }}"
  - "/var/trilio:/var/trilio:shared"
```

In case of using Ironic compute nodes one more entry need to be adjusted in the same file.\
Find the variable `nova_compute_ironic_default_volumes` and append trilio mount `/var/trilio:/var/trilio:shared` to the list.

After the changes the variable will looks like the following:

```
nova_compute_ironic_default_volumes:
  - "{{ node_config_directory }}/nova-compute-ironic/:{{ container_config_directory }}/:ro"
  - "/etc/localtime:/etc/localtime:ro"
  - "{{ '/etc/timezone:/etc/timezone:ro' if ansible_os_family == 'Debian' else '' }}"
  - "kolla_logs:/var/log/kolla/"
  - "{{ kolla_dev_repos_directory ~ '/nova/nova:/var/lib/kolla/venv/lib/python' ~ distro_python_version ~ '/site-packages/nova' if nova_dev_mode | bool else '' }}"
  - "/var/trilio:/var/trilio:shared"
```

## 6] Pull Trilio container images

Activate the login into dockerhub for Trilio tagged containers.

> Please get the Dockerhub login credentials from Trilio Sales/Support team

```
ansible -i multinode control -m shell -a "docker login -u <docker-login-username> -p <docker-login-password> docker.io"
```

Pull the Trilio container images from the dockerhub based on the existing inventory file. In the example is the inventory file named `multinode`.

```
kolla-ansible -i multinode pull --tags triliovault
```

## 7] Deploy Trilio

All that is left, is to run the deploy command using the existing inventory file. In the example is the inventory file named 'multinode'.

This is just an example command. You need to use your cloud deploy command.

```
kolla-ansible -i multinode deploy
```

{% hint style="info" %}
Post deployment for multipath enabled environment, log into respective datamover container and add uxsock\_timeout with value as 60000 (i.e. 60 sec) in /etc/multipath.conf. Restart datamover container
{% endhint %}

## 8] Verify Trilio deployment

Verify on the controller and compute nodes that the Trilio containers are in UP state.

Following is a sample output of commands from controller and compute nodes. `triliovault_tag` will have value as per the openstack release where deployment being done.

```
[controller] docker ps  | grep "trilio-"
a2a3593f76db   trilio/kolla-centos-trilio-datamover-api:<triliovault_tag>       "dumb-init --single-…"   23 hours ago    Up 23 hours    triliovault_datamover_api
5f573caa7b02   trilio/kolla-centos-trilio-horizon-plugin:<triliovault_tag>      "dumb-init --single-…"   23 hours ago    Up 23 hours              horizon

[compute] docker ps | grep "trilio-"
f6d443c2942c   trilio/kolla-centos-trilio-datamover:<triliovault_tag>          "dumb-init --single-…"   23 hours ago    Up 23 hours    triliovault_datamover
```

## 9] Troubleshooting Tips

### 9.1 ] Check Trilio containers and their startup logs

To see all TriloVault containers running on a specific node use the docker ps command.

```
docker ps -a | grep trilio
```

To check the startup logs use the docker logs \<container name> command.

```
docker logs trilio_datamover_api
docker logs trilio_datamover
```

### 9.2] Trilio Horizon tabs are not visible in Openstack

Verify that the Trilio Appliance is configured. The Horizon tabs are only shown, when a configured Trilio appliance is available.

Verify that the Trilio horizon container is installed and in a running state.

```
docker ps | grep horizon
```

### 9.3] Trilio Service logs

* Trilio datamover api service logs on datamover api node

```
/var/log/kolla/triliovault-datamover-api/dmapi.log
```

* Trilio datamover service logs on datamover node

```
/var/log/kolla/triliovault-datamover/tvault-contego.log
```

## 10. Change the nova user id on the Trilio Nodes

`Note: This step needs to be done on Trilio Appliance node. Not on OpenStack node.`

**Pre-requisite**:\
You should have already launched Trilio appliance VM

In Kolla openstack distribution, 'nova' user id on nova-compute docker container is set to '42436'. The 'nova' user id on the Trilio nodes need to be set the same. Do the following steps on all Trilio nodes:

1. Download the shell script that will change the user id
2. Assign executable permissions
3. Execute the script
4. Verify that 'nova' user and group id has changed to '42436'
5. After this step, you can proceed to 'Configuring Trilio' section.

```
## Download the shell script
$ curl -O https://raw.githubusercontent.com/trilioData/triliovault-cfg-scripts/master/common/nova_userid.sh

## Assign executable permissions
$ chmod +x nova_userid.sh

## Execute the shell script to change 'nova' user and group id to '42436'
$ ./nova_userid.sh

## Ignore any errors and verify that 'nova' user and group id has changed to '42436'
$ id nova
   uid=42436(nova) gid=42436(nova) groups=42436(nova),990(libvirt),36(kvm)
```

## 11. Advanced configurations - \[Optional]

11.1] We are using cinder's ceph user for interacting with Ceph cinder storage. This user name is defined using parameter - 'ceph\_cinder\_user' in the file '/etc/kolla/globals.yaml'.

If user wants to edit this parameter value they can do it. Impact will be, cinder's ceph user and triliovault datamover's ceph user will be updated upon next kolla-ansible deploy command.
