1"use strict";(self.webpackChunktigera_docs=self.webpackChunktigera_docs||[]).push([["5923"],{16510:function(e,n,t){t.r(n),t.d(n,{frontMatter:()=>s,toc:()=>l,default:()=>d,metadata:()=>o,assets:()=>c,contentTitle:()=>a});var o=JSON.parse('{"id":"getting-started/openstack/installation/verification","title":"Verify your deployment","description":"Quick steps to test that your Calico-based OpenStack deployment is running correctly.","source":"@site/calico_versioned_docs/version-3.28/getting-started/openstack/installation/verification.mdx","sourceDirName":"getting-started/openstack/installation","slug":"/getting-started/openstack/installation/verification","permalink":"/calico/3.28/getting-started/openstack/installation/verification","draft":false,"unlisted":false,"editUrl":"https://github.com/tigera/docs/edit/main/calico_versioned_docs/version-3.28/getting-started/openstack/installation/verification.mdx","tags":[],"version":"3.28","frontMatter":{"description":"Quick steps to test that your Calico-based OpenStack deployment is running correctly."},"sidebar":"calicoSidebar","previous":{"title":"DevStack","permalink":"/calico/3.28/getting-started/openstack/installation/devstack"},"next":{"title":"Non-cluster hosts","permalink":"/calico/3.28/getting-started/bare-metal/"}}'),i=t(37937),r=t(17869);let s={description:"Quick steps to test that your Calico-based OpenStack deployment is running correctly."},a="Verify your deployment",c={},l=[{value:"Prerequisites",id:"prerequisites",level:2},{value:"Procedure",id:"procedure",level:2},{value:"Troubleshooting",id:"troubleshooting",level:2},{value:"VMs cannot DHCP",id:"vms-cannot-dhcp",level:3},{value:"Routes are missing in the FIB.",id:"routes-are-missing-in-the-fib",level:3},{value:"VMs Cannot Ping Non-VM IPs",id:"vms-cannot-ping-non-vm-ips",level:3},{value:"VMs Cannot Ping Other VMs",id:"vms-cannot-ping-other-vms",level:3},{value:"Web UI Shows Error Boxes Saying "Error: Unable to get quota info" and/or "Error: Unable to get volume limit"",id:"web-ui-shows-error-boxes-saying-error-unable-to-get-quota-info-andor-error-unable-to-get-volume-limit",level:3},{value:"Cannot create instances, error log says "could not open /dev/net/tun: Operation not permitted"",id:"cannot-create-instances-error-log-says-could-not-open-devnettun-operation-not-permitted",level:3}];function h(e){let n={a:"a",code:"code",em:"em",h1:"h1",h2:"h2",h3:"h3",header:"header",li:"li",p:"p",pre:"pre",ul:"ul",...(0,r.R)(),...e.components};return(0,i.jsxs)(i.Fragment,{children:[(0,i.jsx)(n.header,{children:(0,i.jsx)(n.h1,{id:"verify-your-deployment",children:"Verify your deployment"})}),"\n",(0,i.jsx)(n.p,{children:"This document takes you through the steps you can perform to verify that\na Calico-based OpenStack deployment is running correctly."}),"\n",(0,i.jsx)(n.h2,{id:"prerequisites",children:"Prerequisites"}),"\n",(0,i.jsx)(n.p,{children:"This document requires you have the following things:"}),"\n",(0,i.jsxs)(n.ul,{children:["\n",(0,i.jsx)(n.li,{children:"SSH access to the nodes in your Calico-based OpenStack deployment."}),"\n",(0,i.jsx)(n.li,{children:"Access to an administrator account on your Calico-based\nOpenStack deployment."}),"\n"]}),"\n",(0,i.jsx)(n.h2,{id:"procedure",children:"Procedure"}),"\n",(0,i.jsx)(n.p,{children:"Begin by creating several instances on your OpenStack deployment using\nyour administrator account. Confirm that these instances all launch and\ncorrectly obtain IP addresses."}),"\n",(0,i.jsx)(n.p,{children:"You'll want to make sure that your new instances are evenly striped\nacross your hypervisors. On your control node, run:"}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-bash",children:"nova list --fields host\n"})}),"\n",(0,i.jsx)(n.p,{children:"Confirm that there is an even spread across your compute nodes. If there\nisn't, it's likely that an error has happened in either nova or Calico\non the affected compute nodes. Check the logs on those nodes for more\nlogging, and report your difficulty on the mailing list."}),"\n",(0,i.jsxs)(n.p,{children:["Now, SSH into one of your compute nodes. We're going to verify that the\nFIB on the compute node has been correctly populated by Calico. To do\nthat, run the ",(0,i.jsx)(n.code,{children:"route"})," command. You'll get output something like this:"]}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{children:"Kernel IP routing table\nDestination Gateway Genmask Flags Metric Ref Use Iface\ndefault net-vl401-hsrp- 0.0.0.0 UG 0 0 0 eth0\n10.65.0.0 * 255.255.255.0 U 0 0 0 ns-b1163e65-42\n10.65.0.103 npt06.datcon.co 255.255.255.255 UGH 0 0 0 eth0\n10.65.0.104 npt09.datcon.co 255.255.255.255 UGH 0 0 0 eth0\n10.65.0.105 * 255.255.255.255 UH 0 0 0 tap242f8163-08\n10.65.0.106 npt09.datcon.co 255.255.255.255 UGH 0 0 0 eth0\n10.65.0.107 npt07.datcon.co 255.255.255.255 UGH 0 0 0 eth0\n10.65.0.108 npt08.datcon.co 255.255.255.255 UGH 0 0 0 eth0\n10.65.0.109 npt07.datcon.co 255.255.255.255 UGH 0 0 0 eth0\n10.65.0.110 npt06.datcon.co 255.255.255.255 UGH 0 0 0 eth0\n10.65.0.111 npt08.datcon.co 255.255.255.255 UGH 0 0 0 eth0\n10.65.0.112 * 255.255.255.255 UH 0 0 0 tap3b561211-dd\nlink-local * 255.255.0.0 U 1000 0 0 eth0\n172.18.192.0 * 255.255.255.0 U 0 0 0 eth0\n"})}),"\n",(0,i.jsxs)(n.p,{children:["You'll expect to see one route for each of the VM IP addresses in this\ntable. For VMs on other compute nodes, you should see that compute\nnode's IP address (or domain name) as the ",(0,i.jsx)(n.code,{children:"gateway"}),". For VMs on this\ncompute node, you should see ",(0,i.jsx)(n.code,{children:"*"})," as the ",(0,i.jsx)(n.code,{children:"gateway"}),", and the tap interface\nfor that VM in the ",(0,i.jsx)(n.code,{children:"Iface"})," field. As long as routes are present to all\nVMs, the FIB has been configured correctly. If any VMs are missing from\nthe routing table, you'll want to verify the state of the BGP\nconnection(s) from the compute node hosting those VMs."]}),"\n",(0,i.jsxs)(n.p,{children:["Having confirmed the FIB is present and correct, open the console for\none of the VM instances you just created. Confirm that the machine has\nexternal
1connectivity by pinging ",(0,i.jsx)(n.code,{children:"google.com"})," (or any other host you are\nconfident is routable and that will respond to pings). Additionally,\nconfirm it has internal connectivity by pinging the other instances\nyou've created (by IP)."]}),"\n",(0,i.jsx)(n.p,{children:"If all of these tests behave correctly, your Calico-based OpenStack\ndeployment is in good shape."}),"\n",(0,i.jsx)(n.h2,{id:"troubleshooting",children:"Troubleshooting"}),"\n",(0,i.jsx)(n.p,{children:"If you find that none of the advice below solves your problems, please\nuse our diagnostics gathering script to generate diagnostics, and then\nraise a GitHub issue against our repository. To generate the diags, run:"}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-bash",children:"/usr/bin/calico-diags\n"})}),"\n",(0,i.jsx)(n.h3,{id:"vms-cannot-dhcp",children:"VMs cannot DHCP"}),"\n",(0,i.jsxs)(n.p,{children:["This can happen if your iptables is configured to have a default DROP\nbehaviour on the INPUT or FORWARD chains. You can test this by running\n",(0,i.jsx)(n.code,{children:"iptables -L -t filter"})," and checking the output. You should see\nsomething that looks a bit like this:"]}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{children:"Chain INPUT (policy ACCEPT)\ntarget prot opt source destination\nACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED\nACCEPT icmp -- anywhere anywhere\nACCEPT all -- anywhere anywhere\nACCEPT tcp -- anywhere anywhere state NEW tcp dpt:ssh\nREJECT all -- anywhere anywhere reject-with icmp-host-prohibited\n\nChain FORWARD (policy ACCEPT)\ntarget prot opt source destination\nREJECT all -- anywhere anywhere reject-with icmp-host-prohibited\n\nChain OUTPUT (policy ACCEPT)\ntarget prot opt source destination\n"})}),"\n",(0,i.jsxs)(n.p,{children:["The important sections are ",(0,i.jsx)(n.code,{children:"Chain INPUT"})," and ",(0,i.jsx)(n.code,{children:"Chain FORWARD"}),". Each of\nthose needs to have a policy of ",(0,i.jsx)(n.code,{children:"ACCEPT"}),". In some systems, this policy\nmay be set to ",(0,i.jsx)(n.code,{children:"DENY"}),". To change it, run ",(0,i.jsx)(n.code,{children:"iptables -P <chain> ACCEPT"}),",\nreplacing ",(0,i.jsx)(n.code,{children:"<chain>"})," with either ",(0,i.jsx)(n.code,{children:"INPUT"})," or ",(0,i.jsx)(n.code,{children:"FORWARD"}),"."]}),"\n",(0,i.jsx)(n.p,{children:"Note that doing this may be considered a security risk in some networks.\nA future Calico enhancement will remove the requirement to perform this\nstep."}),"\n",(0,i.jsx)(n.h3,{id:"routes-are-missing-in-the-fib",children:"Routes are missing in the FIB."}),"\n",(0,i.jsxs)(n.p,{children:["If routes to some VMs aren't present when you run ",(0,i.jsx)(n.code,{children:"route"}),", this suggests\nthat your BGP sessions are not functioning correctly. Your BGP daemon\nshould have either an interactive console or a log. Open the relevant\none and check that all of your BGP sessions have come up appropriately\nand are replicating routes. If you're using a full mesh configuration,\nconfirm that you have configured BGP sessions with ",(0,i.jsx)(n.em,{children:"all"})," other Calico\nnodes."]}),"\n",(0,i.jsx)(n.h3,{id:"vms-cannot-ping-non-vm-ips",children:"VMs Cannot Ping Non-VM IPs"}),"\n",(0,i.jsx)(n.p,{children:"Assuming all the routes are present in the FIB (see above), this most\ncommonly happens because the gateway is not configured with routes to\nthe VM IP addresses. To get full Calico functionality the gateway should\nalso be a BGP peer of the compute nodes (or the route reflector)."}),"\n",(0,i.jsx)(n.p,{children:"Confirm that your gateway has routes to the VMs. Assuming it does, make\nsure that your gateway is also advertising those routes to its external\npeers. It may do this using eBGP, but it may also be using some other\nrouting protocol."}),"\n",(0,i.jsx)(n.h3,{id:"vms-cannot-ping-other-vms",children:"VMs Cannot Ping Other VMs"}),"\n",(0,i.jsx)(n.p,{children:"Before continuing, confirm that the two VMs are in security groups that\nallow inbou
1nd traffic from each other (or are both in the same security\ngroup which allows inbound traffic from itself). Traffic will not be\nrouted between VMs that do not allow inbound traffic from each other."}),"\n",(0,i.jsxs)(n.p,{children:["Assuming that the security group configuration is correct, confirm that\nthe machines hosting each of the VMs (potentially the same machine) have\nroutes to both VMs. If they do not, check out the troubleshooting\nsection ",(0,i.jsx)(n.a,{href:"#routes-are-missing-in-the-fib",children:"above"}),"."]}),"\n",(0,i.jsx)(n.h3,{id:"web-ui-shows-error-boxes-saying-error-unable-to-get-quota-info-andor-error-unable-to-get-volume-limit",children:'Web UI Shows Error Boxes Saying "Error: Unable to get quota info" and/or "Error: Unable to get volume limit"'}),"\n",(0,i.jsxs)(n.p,{children:["This is likely a problem encountered with mapping devices in ",(0,i.jsx)(n.code,{children:"cinder"}),",\nOpenStack's logical volume management component. Many of these can be\nresolved by restarting ",(0,i.jsx)(n.code,{children:"cinder"}),"."]}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-bash",children:"service cinder-volume restart\nservice cinder-scheduler restart\nservice cinder-api restart\n"})}),"\n",(0,i.jsx)(n.h3,{id:"cannot-create-instances-error-log-says-could-not-open-devnettun-operation-not-permitted",children:'Cannot create instances, error log says "could not open /dev/net/tun: Operation not permitted"'}),"\n",(0,i.jsxs)(n.p,{children:["This is caused by having not restarted libvirt after you add lines to\nthe end of ",(0,i.jsx)(n.code,{children:"/etc/libvirt/qemu.conf"}),". This can be fixed by either\nrebooting your entire system or running:"]}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-bash",children:"service libvirt-bin restart\n"})})]})}function d(e={}){let{wrapper:n}={...(0,r.R)(),...e.components};return n?(0,i.jsx)(n,{...e,children:(0,i.jsx)(h,{...e})}):h(e)}},17869:function(e,n,t){t.d(n,{R:()=>s,x:()=>a});var o=t(82645);let i={},r=o.createContext(i);function s(e){let n=o.useContext(r);return o.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function a(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(i):e.components||i:s(e.components),o.createElement(r.Provider,{value:n},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.