Course Outline
1. Foundational Overview of OpenStack - 2h
● Historical evolution of cloud computing and the OpenStack project
● Core characteristics of cloud infrastructure
● Cloud service models
○ Private, public, and hybrid architectures
○ On-premise, IaaS, PaaS, and SaaS paradigms
● Deployment strategies for public and private clouds utilizing OpenStack
● Open source versus commercial OpenStack distributions
● Standard deployment models for OpenStack environments
● The OpenStack ecosystem
○ Core modules
○ Foundational tooling
○ Integration capabilities
● OpenStack lifecycle management
● OpenStack certification framework
● Laboratory environment (VM) configuration for this curriculum
2. Practical OpenStack Administration Workshop
● OpenStack Fundamentals ~0.5h
○ Core components (Keystone, Glance, Nova, Neutron, Cinder, Swift,
Heat)
○ Interaction patterns with the OpenStack cloud platform
○ Daemon operations and API communication workflows
● Keystone - Identity Management Service ~1h
○ Keystone architectural design
○ Authentication mechanisms and supported backends
○ Token classification and lifecycle management
○ Authorization frameworks in OpenStack - roles and oslo.policy
○ Keystone resource hierarchy - domains, projects, and users
○ Openrc and clouds.yaml - Command-line client configuration
○ OpenStack service catalog management
○ Registration of new OpenStack services
○ Quota enforcement system in OpenStack
● Glance - Image Service ~1.5h
○ Image optimization for cloud environments
○ Image attributes (properties, metadata, format, and container)
○ Procedures for uploading and retrieving images
○ Image sharing protocols
○ Glance image storage repositories
○ Protection mechanisms for images
○ Quota management for the image service
○ Verification of Glance service integrity
● Neutron - Networking ~2-3h
○ Architectural overview and Neutron service components
○ ML2 plugin functionality
○ Network operations within compute nodes - analytical review
○ Networking concepts and tooling utilized by Neutron
○ Fundamental Neutron network resource types
○ Administration of tenant networks and subnets
○ Management of security groups and rules
○ East-West traffic routing
○ Network namespace isolation
○ Management of external and provider networks
● North-South traffic routing
○ Floating IP administration
○ Network quota enforcement
○ Basic network diagnostics (namespaces, tcpdump, etc.)
○ Networking quota configuration
○ Verification of Neutron service operations
● Nova - Compute Service ~2-3h
○ Hypervisor interfaces
○ Keypair administration
○ Flavor configuration
○ Flavors and CPU topology mapping
○ Instance parameter definition
○ Instance provisioning
○ Verification of spawned instances
○ Snapshot management
○ Instance lifecycle administration
○ Instance resizing operations
○ Assignment of floating IPs
○ Interactive console and console log access
○ Security group application
○ Compute resource quotas
○ Retrieval of statistics from Nova
○ Placement API and Nova Cells v2 architecture
○ Placement API and instance scheduling logic
○ Placement API client commands
○ Verification of Nova service health
● Cinder - Block Storage ~2-3h
○ Volume parameter configuration
○ Volume creation
○ Volume management
○ Attachment of volumes to Nova instances
○ Volume snapshot administration
○ Volume backup management
○ Internal mechanics of snapshots and backups in Cinder
○ Transfer of volumes between projects
○ Restoration of backups
○ Volume quota administration
○ Integration of new storage backends
○ QoS (limits) enforcement in Cinder
○ LVM, storage array, and Ceph storage backends
● Ceph integration within OpenStack
○ Integration of Ceph and Cinder
○ Best practices for Ceph deployments
○ Verification of Cinder service status
● Barbican - Key Management Service - ~2h
○ Barbican architectural framework
○ Secure storage of passphrases
○ Generation and storage of symmetric encryption keys
○ Volume encryption mechanisms
○ Configuration of Cinder storage types for volume encryption
○ Limitations associated with volume encryption
○ Storage of X.509 certificate bundles
● Swift - Object Storage (Brief overview for COA exam) <1h
○ Swift components and processes
○ Administration of containers and objects
○ Management of access control lists
○ Configuration of object expiration
○ The Ring and storage policy implementation
○ Monitoring of available storage capacity
○ Quota configuration
○ Verification of Swift service operations
● Octavia - Load Balancing-as-a-Service ~2-3h
○ Architectural design
○ Object models and request flow
● Octavia flavor definitions
○ Octavia Availability Zones
○ Creation of HTTP load balancers
○ Creation of TCP load balancers
○ Creation of HTTPS passthrough load balancers
○ Configuration of Listeners, Pools, and Health Monitors
○ Layer 7 load balancing in Octavia
○ Construction of Amphora images
● Load balancer failover procedures
○ Networking and monitoring details
○ Troubleshooting Octavia operations
● Heat - Orchestration ~1-2h
○ Heat Orchestration Template structure and components
○ Creation of Heat stacks
○ Verification of Heat stack integrity
○ Updating Heat stacks
○ Verification of Heat service functionality
● Fundamental Troubleshooting ~2h
○ Analysis of log files
○ Implementation of centralized logging
○ Debugging OpenStack client queries
○ Administration of OpenStack databases
○ Backup strategies for OpenStack
○ Analysis of compute node status
○ Analysis of instance status
○ Analysis of AMQP broker (RabbitMQ)
○ Metadata service operations
● General methodologies for diagnosing OpenStack issues
○ Troubleshooting network connectivity problems
○ Optimization of network performance
○ Instance backup and recovery protocols
3. Advanced Topics
● Hardware Considerations and Capacity Planning ~2h
○ Compute hardware requirements
○ Network architecture design
● Storage architecture design
○ Flavor sizing optimization
○ Resource overcommitment strategies
● Role System - Authorization in OpenStack ~2h
○ Creation of new roles as member role extensions
○ policy.yaml - Authorization of API calls
● Highly Available Control Plane ~1h
○ High availability implementation in OpenStack services
● High availability database configuration
○ High availability message queue setup
● Cloud Partitioning and Scheduler Filters ~1h
○ Rationale and implementation of cloud partitions (host-aggregates)
○ Nova scheduler filter configuration
● Workload Migration ~1h
○ Cold and live migration techniques
○ Live migration tuning
● OpenStack Monitoring and Telemetry <1h
● Ceilometer service implementation
○ External monitoring integration
● Advanced Cloud/Hypervisor Features <1h
○ CPU pinning and NUMA architecture
● SR-IOV implementation
● Cloud-init and Image Customization <1h
○ Metadata Service integration
● Block Storage Backends <1h
○ LVM configuration
● Ceph RBD implementation
○ Physical appliance management
● Storage network considerations
● OpenStack Upgrade Procedures <1h
○ Upgrade strategies and procedural guidelines
● Zero-downtime upgrade implementation
● Bare-Metal Provisioning with OpenStack <1h
○ Ironic module integration
● Undercloud and overcloud concepts
● Future development trajectory of OpenStack
4. In-Depth Analysis of Neutron and OVN Backend - ~6-8h
● OVN architectural framework
● OVN component breakdown
● ML2 - OVN versus OvS driver comparison
● Top-down OVN networking analysis
○ OpenStack logic (Neutron database)
● Northbound database structure
○ Southbound database structure
● Logical datapath pipelines
○ Logical flow mechanisms
● OpenFlow flow implementation
● Mapping Neutron networks to OVN logical switches
○ Logical ports and their classifications
● Switching flow analysis
● Mapping Neutron routers to OVN logical routers
○ NAT type configurations
● Routing flow analysis
● Mapping Neutron subnets to native DHCP
○ DHCP flow mechanisms
● Security groups within OVN
○ ACLs and Port Group implementation
● Security group flow analysis
○ Port security mechanisms in OVN
● Summary of OVN Northbound tables
● Information flow within OVN
○ Neutron DB, OVN NB and SB DB, and OpenFlow at OvS
● Logical flow tracing methodologies
○ Definition of microflows
● L2 tracing techniques
○ L3 tracing techniques
● DHCP tracing techniques
● Physical flows - OpenFlow implementation
○ Physical lifecycle of VM-originated packets
● Physical tracing methodologies
○ Tracing of hypothetical packets
● Tracing of real-world packets
● Display of Open vSwitch database and resources
Testimonials (1)
communication, knowledge from experience, solve problems,