PageSourceSearch

https://archive-os-3-29.netlify.app/assets/js/1d6b519a.a3e2a408.js

js archive-os-3-29.netlify.app collected 2026-10-03 10:31:24 UTC 36,505 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunktigera_docs=self.webpackChunktigera_docs||[]).push([["5785"],{14763(e,n,s){s.r(n),s.d(n,{metadata:()=>a,default:()=>h,frontMatter:()=>d,contentTitle:()=>r,toc:()=>c,assets:()=>o});var a=JSON.parse('{"id":"networking/openstack/service-ips","title":"Service IPs","description":"Use a floating or fixed IP for a Calico-networked VM.","source":"@site/calico_versioned_docs/version-3.29/networking/openstack/service-ips.mdx","sourceDirName":"networking/openstack","slug":"/networking/openstack/service-ips","permalink":"/calico/3.29/networking/openstack/service-ips","draft":false,"unlisted":false,"editUrl":"https://github.com/tigera/docs/edit/main/calico_versioned_docs/version-3.29/networking/openstack/service-ips.mdx","tags":[],"version":"3.29","frontMatter":{"description":"Use a floating or fixed IP for a Calico-networked VM."},"sidebar":"calicoSidebar","previous":{"title":"Floating IPs","permalink":"/calico/3.29/networking/openstack/floating-ips"},"next":{"title":"Host routes","permalink":"/calico/3.29/networking/openstack/host-routes"}}'),t=s(70689),i=s(3413);let d={description:"Use a floating or fixed IP for a Calico-networked VM."},r="Service IPs",o={},c=[{value:"Creating a test VM",id:"creating-a-test-vm",level:2},{value:"Adding a service IP to the Neutron port as an extra fixed IP",id:"adding-a-service-ip-to-the-neutron-port-as-an-extra-fixed-ip",level:2},{value:"Moving the service IP to another VM",id:"moving-the-service-ip-to-another-vm",level:2}];function l(e){let n={a:"a",code:"code",h1:"h1",h2:"h2",header:"header",li:"li",ol:"ol",p:"p",pre:"pre",ul:"ul",...(0,i.R)(),...e.components};return(0,t.jsxs)(t.Fragment,{children:[(0,t.jsx)(n.header,{children:(0,t.jsx)(n.h1,{id:"service-ips",children:"Service IPs"})}),"\n",(0,t.jsx)(n.p,{children:"Calico supports two approaches for assigning a service IP to a\nCalico-networked VM:"}),"\n",(0,t.jsxs)(n.ul,{children:["\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsx)(n.p,{children:"using a floating IP"}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsx)(n.p,{children:"using an additional fixed IP on the relevant Neutron port."}),"\n"]}),"\n"]}),"\n",(0,t.jsx)(n.p,{children:"Both of these are standard Neutron practice - in other words, operations that\nhave long been supported on the Neutron API. They are not Calico-specific,\nexcept insofar as the Calico driver needs to implement some of the low-level\noperations that are needed to make the expected semantics work."}),"\n",(0,t.jsx)(n.p,{children:"The key semantic difference between those approaches is that:"}),"\n",(0,t.jsxs)(n.ul,{children:["\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsx)(n.p,{children:"With a floating IP, the target VM itself is not aware of the service IP.\nInstead, data sent to the floating IP is DNAT'd, to the target VM's fixed IP,\nbefore that data reaches the target VM. So the target VM only ever sees data\naddressed to its fixed IP."}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsx)(n.p,{children:"With the service IP as an additional fixed IP, the target VM is (and must be)\naware of the service IP, because data addressed to the service IP reaches the\ntarget VM without any DNAT."}),"\n"]}),"\n"]}),"\n",(0,t.jsxs)(n.p,{children:["The use of floating IPs is already well known, so we won't labour how to use\nthose here. For some additional information on how Calico supports floating\nIPs, see ",(0,t.jsx)(n.a,{href:"/calico/3.29/networking/openstack/floating-ips",children:"Floating IPs"}),"."]}),"\n",(0,t.jsx)(n.p,{children:"The use and maintenance of additional fixed IPs, however, is not so well\nknown, so in the following transcripts we demonstrate this approach for\nassigning a service IP to a Calico-networked VM."}),"\n",(0,t.jsx)(n.p,{children:"We begin by creating a test VM that will be the target of the service IP."}),"\n",(0,t.jsx)(n.h2,{id:"creating-a-test-vm",children:"Creating a test VM"}),"\n",(0,t.jsxs)(n.ol,{children:["\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsx)(n.p,{children:"Check the name of the available CirrOS image."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"nova image-list\n"})}),"\n",(0,t.jsx)(n.p,{children:"It should return a list of the images and their names."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{children:"WARNING: Command image-list is deprecated and will be removed after Nova 15.0.0 is released. Use python-glanceclient or openstackclient instead.\n+--------------------------------------+---------------------+--------+--------+\n| ID                                   | Name                | Status | Server |\n+--------------------------------------+---------------------+--------+--------+\n| b69ab3bd-2bbc-4086-b4ae-f01d9f6b5078 | cirros-0.3.2-x86_64 | ACTIVE |        |\n| 866879b9-532b-44c6-a547-ac59de68df2d | ipv6_enabled_
1image  | ACTIVE |        |\n+--------------------------------------+---------------------+--------+--------+\n"})}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsx)(n.p,{children:"Boot a VM."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"nova boot --flavor m1.tiny --image cirros-0.3.2-x86_64 --nic net-name=demo-net testvm1\n"})}),"\n",(0,t.jsx)(n.p,{children:"The response should look similar to the following."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{children:"+--------------------------------------+------------------------------------------------------------+\n| Property                             | Value                                                      |\n+--------------------------------------+------------------------------------------------------------+\n| OS-DCF:diskConfig                    | MANUAL                                                     |\n| OS-EXT-AZ:availability_zone          | nova                                                       |\n| OS-EXT-SRV-ATTR:host                 | -                                                          |\n| OS-EXT-SRV-ATTR:hypervisor_hostname  | -                                                          |\n| OS-EXT-SRV-ATTR:instance_name        | instance-0000000d                                          |\n| OS-EXT-STS:power_state               | 0                                                          |\n| OS-EXT-STS:task_state                | scheduling                                                 |\n| OS-EXT-STS:vm_state                  | building                                                   |\n| OS-SRV-USG:launched_at               | -                                                          |\n| OS-SRV-USG:terminated_at             | -                                                          |\n| accessIPv4                           |                                                            |\n| accessIPv6                           |                                                            |\n| adminPass                            | HKLzcUT5L52B                                               |\n| config_drive                         |                                                            |\n| created                              | 2017-01-13T13:50:32Z                                       |\n| flavor                               | m1.tiny (1)                                                |\n| hostId                               |                                                            |\n| id                                   | b6d8a3c4-9674-4972-9151-11107b60d622                       |\n| image                                | cirros-0.3.2-x86_64 (b69ab3bd-2bbc-4086-b4ae-f01d9f6b5078) |\n| key_name                             | -                                                          |\n| metadata                             | {}                                                         |\n| name                                 | testvm1                                                    |\n| os-extended-volumes:volumes_attached | []                                                         |\n| progress                             | 0                                                          |\n| security_groups                      | default                                                    |\n| status                               | BUILD                                                      |\n| tenant_id                            | 26778b0f745143c5a9b0c7e1a621bb80                           |\n| updated                              | 2017-01-13T13:50:32Z                                       |\n| user_id                              | 7efbea74c20a4eeabc00b7740aa4d353                           |\n+--------------------------------------+------------------------------------------------------------+\n"})}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsx)(n.p,{children:"Check when the VM has booted:"}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"nova list\n"})}),"\n",(0,t.jsx)(n.p,{children:"You should see your VM with the following statuses."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{children:"+--------------------------------------+---------+--------+------------+-------------+----------------------------------------------+\n| ID                                   | Name    | Status | Task State | Power State | Networks                                     |\n+--------------------------------------+---------+--------+------------+-------------+----------------------------------------------+\n| b6d8a3c4-9674-4972-9151-11107b60d622 | testvm1 | ACTIVE | -          | Running     | demo-net=10.28.0.13, fd5f:5d21:845:1c2e:2::d |\n+--------------------------------------+---------+--------+------------+-------------+----------------------------------------------+\n"})}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsx)(n.p,{children:"Use the following command to obtain the status of the VM."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"nova show testvm1\n"})}),"\n",(0,t.jsx)(n.p,{children:"It should return something like the following."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{children:"+--------------------------------------+------------------------------------------------------------+\n| Property                             | Value                                                      |\n+--------------------------------------+------------------------------------------------------------+\n| OS-DCF:diskConfig                    | MANUAL                                                     |\n| OS-EXT-AZ:availability_zone          | neil-fv-0-ubuntu-kilo-compute-node01                       |\n| OS-EXT-SRV-ATTR:host                 | neil-fv-0-ubuntu-kilo-compute-node01                       |\n| OS-EXT-SRV-ATTR:hypervisor_hostname  | neil-fv-0-ubuntu-kilo-compute-node01                       |\n| OS-EXT-SRV-ATTR:instance_name        | instance-0000000d                                          |\n| OS-EXT-STS:power_state               | 1                                                          |\n| OS-EXT-STS:task_state                | -                                                          |\n| OS-EXT-STS:vm_state                  | active                                                     |\n| OS-SRV-USG:launched_at               | 2017-01-13T13:50:39.000000                                 |\n| OS-SRV-USG:terminated_at             | -                                                          |\n| accessIPv4                           |                                                            |\n| accessIPv6                           |                                                            |\n| config_drive                         |                                                            |\n| created                              | 2017-01-13T13:50:32Z                                       |\n| demo-net network                     | 10.28.0.13, fd5f:5d21:845:1c2e:2::d                        |\n| flavor                               | m1.tiny (1)                                                |\n| hostId                               | bf3ce3c7146ba6cafd43be
103886de8755e2b5c8e9f71aa9bfafde9a0   |\n| id                                   | b6d8a3c4-9674-4972-9151-11107b60d622                       |\n| image                                | cirros-0.3.2-x86_64 (b69ab3bd-2bbc-4086-b4ae-f01d9f6b5078) |\n| key_name                             | -                                                          |\n| metadata                             | {}                                                         |\n| name                                 | testvm1                                                    |\n| os-extended-volumes:volumes_attached | []                                                         |\n| progress                             | 0                                                          |\n| security_groups                      | default                                                    |\n| status                               | ACTIVE                                                     |\n| tenant_id                            | 26778b0f745143c5a9b0c7e1a621bb80                           |\n| updated                              | 2017-01-13T13:50:39Z                                       |\n| user_id                              | 7efbea74c20a4eeabc00b7740aa4d353                           |\n+--------------------------------------+------------------------------------------------------------+\n"})}),"\n",(0,t.jsx)(n.p,{children:"In this example, the VM has been given a fixed IP of 10.28.0.13."}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsx)(n.p,{children:"Let's look at the corresponding Neutron port."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"neutron port-list\n"})}),"\n",(0,t.jsx)(n.p,{children:"It should look something like the following."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{children:'+--------------------------------------+------+-------------------+------------------------------------------------------------------------------------------------+\n| id                                   | name | mac_address       | fixed_ips                                                                                      |\n+--------------------------------------+------+-------------------+------------------------------------------------------------------------------------------------+\n| 656b3617-570d-473e-a5dd-90b61cb0c49f |      | fa:16:3e:4d:d5:25 |                                                                                                |\n| 9a7e0868-da7a-419e-a7ad-9d37e11091b8 |      | fa:16:3e:28:a9:a4 | {"subnet_id": "0a1221f2-e6ed-413d-a040-62a266bd0d8f", "ip_address": "10.28.0.13"}              |\n|                                      |      |                   | {"subnet_id": "345fec2e-6493-44de-a489-97b755c16dd4", "ip_address": "fd5f:5d21:845:1c2e:2::d"} |\n| a4b26bcc-ba94-4033-a9fc-edaf151c0c20 |      | fa:16:3e:74:46:bd |                                                                                                |\n| a772a5e1-2f13-4fc3-96d5-fa1c29717637 |      | fa:16:3e:c9:c6:8f |                                                                                                |\n+--------------------------------------+------+-------------------+------------------------------------------------------------------------------------------------+\n'})}),"\n"]}),"\n"]}),"\n",(0,t.jsx)(n.h2,{id:"adding-a-service-ip-to-the-neutron-port-as-an-extra-fixed-ip",children:"Adding a service IP to the Neutron port as an extra fixed IP"}),"\n",(0,t.jsxs)(n.p,{children:["Now we want to set up a service IP - let's say ",(0,t.jsx)(n.code,{children:"10.28.0.23"})," - that\ninitially points to that VM, ",(0,t.jsx)(n.code,{children:"testvm1"}),"."]}),"\n",(0,t.jsxs)(n.ol,{children:["\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsx)(n.p,{children:"One way to do that is to add the service IP as a second 'fixed IP' on the Neutron port."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"neutron port-update --fixed-ip subnet_id=0a1221f2-e6ed-413d-a040-62a266bd0d8f,ip_address=10.28.0.13 \\\n--fixed-ip subnet_id=0a1221f2-e6ed-413d-a040-62a266bd0d8f,ip_address=10.28.0.23 9a7e0868-da7a-419e-a7ad-9d37e11091b8\n"})}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsx)(n.p,{children:"It should return a confirmation message."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{children:"Updated port: 9a7e0868-da7a-419e-a7ad-9d37e11091b8\n"})}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsx)(n.p,{children:"Use the following command to get more information about the port."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"neutron port-show 9a7e0868-da7a-419e-a7ad-9d37e11091b8\n"})}),"\n",(0,t.jsx)(n.p,{children:"It should return a table like the following."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{children:'+-----------------------+-----------------------------------------------------------------------------------+\n| Field                 | Value                                                                             |\n+-----------------------+-----------------------------------------------------------------------------------+\n| admin_state_up        | True                                                                              |\n| allowed_address_pairs |                                                                                   |\n| binding:host_id       | neil-fv-0-ubuntu-kilo-compute-node01                                              |\n| binding:profile       | {}                                                                                |\n| binding:vif_details   | {"port_filter": true, "mac_address": "00:61:fe:ed:ca:fe"}                         |\n| binding:vif_type      | tap                                                                               |\n| binding:vnic_type     | normal                                                                            |\n| device_id             | b6d8a3c4-9674-4972-9151-11107b60d622                                              |\n| device_owner          | compute:None                                                                      |\n| extra_dhcp_opts       |                                                                                   |\n| fixed_ips             | {"subnet_id": "0a1221f2-e6ed-413d-a040-62a266bd0d8f", "ip_address": "10.28.0.13"} |\n|                       | {"subnet_id": "0a1221f2-e6ed-413d-a040-62a266bd0d8f", "ip_address": "10.28.0.23"} |\n| id                    | 9a7e0868-da7a-419e-a7ad-9d37e11091b8                                              |\n| mac_address           | fa:16:3e:28:a9:a4                                                                 |\n| name                  |                                                                                   |\n| network_id            | 60651076-af2a-4c6d-8d64-500b53a4e547                                              |\n| security_groups       | 75fccd0a-ef3d-44cd-91ec-ef22941f50f5                                              |\n| status                | ACTIVE                                                                            |\n| tenant_id             | 26778b0f745143c5a9b0c7e1a621bb80                                                  |\n+-----------------------+-----------------------------------------------------------------------------------+\n'})}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsx)(n.p,{children:"Now look at local IP routes."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"ip r\n"})}),"\n",(0,t.jsxs)(n.p,{children:["We see that we have a route to ",(0,t.jsx)(n.code,{children:"10.28.0.23"}),"."]}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{children:"default via 10.240.0.1 dev eth0  proto static  metric 100\n10.28.0.13 via 192.168.8.3 dev l2tpeth8-1  proto bird\n10.28.0.23 via 192.168.8.3 dev l2tpeth8-1  proto bird\n[...]\n"})}),"\n",(0,t.jsx)(n.p,{children:"Note that, on the machine where we're running these commands:"}),"\n",(0,t.jsxs)(n.ul,{children:["\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsxs)(n.p,{children:["BIRD is running, peered with the BIRDs that Calico runs on each compute node.\nThat is what causes VM routes (including ",(0,t.jsx)(n.code,{children:"10.28.0.23"}),") to appear here."]}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsxs)(n.p,{children:["192.168.8.3 is the IP of the compute node that is hosting ",(0,t.jsx)(n.code,{children:"testvm1"}),"."]}),"\n"]}),"\n"]}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsxs)(n.p,{children:["We can also double check that ",(0,t.jsx)(n.code,{children:"10.28.0.23"})," has appeared as a local device\nroute on the relevant compute node."]}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"ip r\n"})}),"\n",(0,t.jsx)(n.p,{children:"It should return something like the following."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{children:"default via 10.240.0.1 dev eth0\n10.28.0.13 dev tap9a7e0868-da  scope link\n10.28.0.23 dev tap9a7e0868-da  scope link\n10.240.0.1 dev eth0  scope link\n192.168.8.0/24 dev l2tpeth8-3  proto kernel  scope link  src 192.168.8.3\n192.168.122.0/24 dev virbr0  proto kernel  scope link  src 192.168.122.1\n"})}),"\n",(0,t.jsxs)(n.p,{children:["We also need - because with this approach, data that is addressed to\n",(0,t.jsx)(n.code,{children:"10.28.0.23"})," will be routed to the VM without any NAT - to tell the VM\nitself that it has the extra ",(0,t.jsx)(n.code,{children:"10.28.0.23"})," address."]}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsx)(n.p,{children:"SSH into the VM."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"core@access-node$ ssh [email protected]\[email protected]'s password:\n"})}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsx)(n.p,{children:"From inside the VM, issue the following command to list the interfaces."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"ip a\n"})}),"\n",(0,t.jsx)(n.p,{children:"It should return something like the following."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{children:"1: lo: <LOOPBACK,UP,LOWER_UP> mtu 16436 qdisc noqueue\n    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00\n    inet 127.0.0.1/8 scope host lo\n    inet6 ::1/128 scope host\n       valid_lft forever preferred_lft forever\n2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast qlen 1000\n    link/ether fa:16:3e:28:a9:a4 brd ff:ff:ff:ff:ff:ff\n    inet 10.28.0.13/16 brd 10.28.255.255 scope global eth0\n    inet6 fe80::f816:3eff:fe28:a9a4/64 scope link\n       valid_lft forever preferred_lft forever\n"})}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsx)(n.p,{children:"Next, issue the following command."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"sudo ip a a 10.28.0.23/16 dev eth0\n"})}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsx)(n.p,{children:"List the interfaces again."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"ip a\n"})}),"\n",(0,t.jsx)(n.p,{children:"The interfaces should now look more like the following."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{children:"1: lo: <LOOPBACK,UP,LOWER_UP> mtu 16436 qdisc noqueue\n    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00\n    inet 127.0.0.1/8 scope host lo\n    inet6 ::1/128 scope host\n       valid_lft forever preferred_lft forever\n2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast qlen 1000\n    link/ether fa:16:3e:28:a9:a4 brd ff:ff:ff:ff:ff:ff\n    inet 10.28.0.13/16 brd 10.28.255.255 scope global eth0\n    inet 10.28.0.23/16 scope global secondary eth0\n    inet6 fe80::f816:3eff:fe28:a9a4/64 scope link\n       valid_lft forever preferred_lft forever\n"})}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsx)(n.p,{children:"Exit the SSH session."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{children:"Connection to 10.28.0.13 closed.\n"})}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsx)(n.p,{children:"And now we can access the VM on its service IP, as shown below."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"core@access-node$ ssh [email protected]\nThe authenticity of host '10.28.0.23 (10.28.0.23)' can't be established.\nRSA key fingerprint is 65:a5:b0:0c:e2:c4:ac:94:2a:0c:64:b8:bc:5a:aa:66.\nAre you sure you want to continue connecting (yes/no)? yes\n\nWarning: Permanently added '10.28.0.23' (RSA) to the list of known hosts.\[email protected]'s password:\n$\n"})}),"\n",(0,t.jsxs)(n.p,{children:["Note that we already have security set up that allows SSH to the instance from\nour access machine (",(0,t.jsx)(n.code,{children:"192.168.8.1"}),")."]}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsx)(n.p,{children:"You can check this by listing the security groups."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"neutron security-group-list\n"})}),"\n",(0,t.jsx)(n.p,{children:"It should return something like the following."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{children:"+--------------------------------------+---------+----------------------------------------------------------------------+\n| id                                   | name    | security_group_rules                                                 |\n+--------------------------------------+---------+----------------------------------------------------------------------+\n| 75fccd0a-ef3d-44cd-91ec-ef22941f50f5 | default | egress, IPv4                                                         |\n|                                      |         | egress, IPv6                                                         |\n|                                      |         | ingress, IPv4, 22/tcp, remote_ip_prefix: 192.168.8.1/32              |\n|                                      |         | ingress, IPv4, remote_group_id: 75fccd0a-ef3d-44cd-91ec-ef22941f50f5 |\n|                                      |         | ingress, IPv6, remote_group_id: 75fccd0a-ef3d-44cd-91ec-ef22941f50f5 |\n| 903d9936-ce72-4756-a2cc-7c95a846e7e5 | default | egress, IPv4                                                         |\n|                                      |         | egress, IPv6                                                         |\n|                                      |         | ingress, IPv4, 22/tcp, remote_ip_prefix: 192.168.8.1/32              |\n|                                      |         | ingress, IPv4, remote_group_id: 903d9936-ce72-4756-a2cc-7c95a846e7e5 |\n|                                      |         | ingress, IPv6, remote_group_id: 903d9936-ce72-4756-a2cc-7c95a846e7e5 |\n+--------------------------------------+---------+----------------------------------------------------------------------+\n"})}),"\n"]}),"\n"]}),"\n",(0,t.jsx)(n.h2,{id:"moving-the-service-ip-to-another-vm",children:"Moving the service IP to another VM"}),"\n",(0,t.jsx)(n.p,{children:"Service IPs are often used for HA, so need to be moved to target a different VM\nif the first one fails for some reason (or if the HA system just decides to\ncycle the active VM)."}),"\n",(0,t.jsxs)(n.ol,{children:["\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsx)(n.p,{children:"To demonstrate that we create a second test VM."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"nova boot --flavor m1.tiny --image cirros-0.3.2-x86_64 --nic net-name=demo-net testvm2\n"})}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsx)(n.p,{children:"List the VMs."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"nova list\n"})}),"\n",(0,t.jsx)(n.p,{children:"You should see the new VM in the list."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{children:"+--------------------------------------+---------+--------+------------+-------------+----------------------------------------------+\n| ID                                   | Name    | Status | Task State | Power State | Networks                                     |    
1+--------------------------------------+---------+--------+------------+-------------+----------------------------------------------+\n| b6d8a3c4-9674-4972-9151-11107b60d622 | testvm1 | ACTIVE | -          | Running     | demo-net=10.28.0.13, 10.28.0.23              |\n| bb4ef5e3-dc77-472e-af6f-3f0d8c3e5a6d | testvm2 | ACTIVE | -          | Running     | demo-net=10.28.0.14, fd5f:5d21:845:1c2e:2::e |\n+--------------------------------------+---------+--------+------------+-------------+----------------------------------------------+\n"})}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsx)(n.p,{children:"Check the ports."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"neutron port-list\n"})}),"\n",(0,t.jsx)(n.p,{children:"It should return something like the following."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{children:'+--------------------------------------+------+-------------------+------------------------------------------------------------------------------------------------+\n| id                                   | name | mac_address       | fixed_ips                                                                                      |\n+--------------------------------------+------+-------------------+------------------------------------------------------------------------------------------------+\n| 656b3617-570d-473e-a5dd-90b61cb0c49f |      | fa:16:3e:4d:d5:25 |                                                                                                |\n| 7627a298-a2db-4a1a-bc07-9f0f10f58363 |      | fa:16:3e:8e:dc:33 | {"subnet_id": "0a1221f2-e6ed-413d-a040-62a266bd0d8f", "ip_address": "10.28.0.14"}              |\n|                                      |      |                   | {"subnet_id": "345fec2e-6493-44de-a489-97b755c16dd4", "ip_address": "fd5f:5d21:845:1c2e:2::e"} |\n| 9a7e0868-da7a-419e-a7ad-9d37e11091b8 |      | fa:16:3e:28:a9:a4 | {"subnet_id": "0a1221f2-e6ed-413d-a040-62a266bd0d8f", "ip_address": "10.28.0.13"}              |\n|                                      |      |                   | {"subnet_id": "0a1221f2-e6ed-413d-a040-62a266bd0d8f", "ip_address": "10.28.0.23"}              |\n| a4b26bcc-ba94-4033-a9fc-edaf151c0c20 |      | fa:16:3e:74:46:bd |                                                                                                |\n| a772a5e1-2f13-4fc3-96d5-fa1c29717637 |      | fa:16:3e:c9:c6:8f |                                                                                                |\n+--------------------------------------+------+-------------------+------------------------------------------------------------------------------------------------+\n'})}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsx)(n.p,{children:"Remove the service IP from the first VM."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"neutron port-update --fixed-ip subnet_id=0a1221f2-e6ed-413d-a040-62a266bd0d8f,ip_address=10.28.0.13 9a7e0868-da7a-419e-a7ad-9d37e11091b8\n"})}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsx)(n.p,{children:"And add it to the second."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"neutron port-update --fixed-ip subnet_id=0a1221f2-e6ed-413d-a040-62a266bd0d8f,ip_address=10.28.0.14 \\\n--fixed-ip subnet_id=0a1221f2-e6ed-413d-a040-62a266bd0d8f,ip_address=10.28.0.23 7627a298-a2db-4a1a-bc07-9f0f10f58363\n"})}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsxs)(n.p,{children:["SSH into ",(0,t.jsx)(n.code,{children:"testvm2"}),"."]}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"core@access-node$ ssh [email protected]\nThe authenticity of host '10.28.0.14 (10.28.0.14)' can't be established.\nRSA key fingerprint is 6a:02:7f:3a:bf:0c:91:de:c4:d6:e7:f6:81:3f:6a:85.\nAre you sure you want to continue connecting (yes/no)? yes\n\nWarning: Permanently added '10.28.0.14' (RSA) to the list of known hosts.\[email protected]'s password:\n"})}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsxs)(n.p,{children:["Tell ",(0,t.jsx)(n.code,{children:"testvm2"})," that it now has the service IP ",(0,t.jsx)(n.code,{children:"10.28.0.23"}),"."]}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"sudo ip a a 10.28.0.23/16 dev eth0\n"})}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsxs)(n.p,{children:["Now connections to ",(0,t.jsx)(n.code,{children:"10.28.0.23"})," go to ",(0,t.jsx)(n.code,{children:"testvm2"})]}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"core@access-node$ ssh [email protected]\n@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@\n@    WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!     @\n@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@\nIT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!\nSomeone could be eavesdropping on you right now (man-in-the-middle attack)!\nIt is also possible that a host key has just been changed.\nThe fingerprint for the RSA key sent by the remote host is\n6a:02:7f:3a:bf:0c:91:de:c4:d6:e7:f6:81:3f:6a:85.\nPlease contact your system administrator.\nAdd correct host key in /home/core/.ssh/known_hosts to get rid of this message.\nOffending RSA key in /home/core/.ssh/known_hosts:4\nRSA host key for 10.28.0.23 has changed and you have requested strict checking.\nHost key verification failed.\n"})}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsxs)(n.p,{children:["Remove the ",(0,t.jsx)(n.code,{children:"known_hosts"})," files."]}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"rm ~/.ssh/known_hosts\n"})}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsx)(n.p,{children:"Try again to SSH into the VM."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"core@access-node$ ssh [email protected]\nThe authenticity of host '10.28.0.23 (10.28.0.23)' can't be established.\nRSA key fingerprint is 6a:02:7f:3a:bf:0c:91:de:c4:d6:e7:f6:81:3f:6a:85.\nAre you sure you want to continue connecting (yes/no)? yes\n\nWarning: Permanently added '10.28.0.23' (RSA) to the list of known hosts.\[email protected]'s password:\n"})}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsx)(n.p,{children:"Check the host name."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"hostname\n"})}),"\n",(0,t.jsx)(n.p,{children:"It should return:"}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{children:"testvm2\n"})}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["\n",(0,t.jsx)(n.p,{children:"Check the interfaces."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{children:"ip a\n"})}),"\n",(0,t.jsx)(n.p,{children:"They should look something like the following."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{children:"1: lo: <LOOPBACK,UP,LOWER_UP> mtu 16436 qdisc noqueue\n    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00\n    inet 127.0.0.1/8 scope host lo\n    inet6 ::1/128 scope host\n       valid_lft forever preferred_lft forever\n2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast qlen 1000\n    link/ether fa:16:3e:8e:dc:33 brd ff:ff:ff:ff:ff:ff\n    inet 10.28.0.14/16 brd 10.28.255.255 scope global eth0\n    inet 10.28.0.23/16 scope global secondary eth0\n    inet6 fe80::f816:3eff:fe8e:dc33/64 scope link\n      valid_lft forever preferred_lft forever\n$\n"})}),"\n"]}),"\n"]})]})}function h(e={}){let{wrapper:n}={...(0,i.R)(),...e.components};return n?(0,t.jsx)(n,{...e,children:(0,t.jsx)(l,{...e})}):l(e)}},3413(e,n,s){s.d(n,{R:()=>d,x:()=>r});var a=s(16645);let t={},i=a.createContext(t);function d(e){let n=a.useContext(i);return a.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function r(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(t):e.components||t:d(e.components),a.createElement(i.Provider,{value:n},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.