Skip to content

Service deployment

Zarquan edited this page Jul 18, 2023 · 16 revisions

The configuration for these machines comes from the heliodines private git repository, a copy of which is installed at /var/local/projects/heliodines/git.

Physical machines

Physical networks

The physical trop01 hyper-visor machine has two physical network interfaces, br0 and br1.



        br0     Link encap:Ethernet  HWaddr 0c:c4:7a:35:12:06  
                inet addr:  Bcast:  Mask:
                inet6 addr: fe80::ec4:7aff:fe35:1206/64 Scope:Link

        br1     Link encap:Ethernet  HWaddr 0c:c4:7a:35:12:07  
                inet addr:  Bcast:  Mask:
                inet6 addr: fe80::ec4:7aff:fe35:1207/64 Scope:Link

Interface br0 is connected to the local VLAN created for the rack of machines in the ROE machine room, and interface br1 is connected to the internal VLAN for the SQLServer databases.

The source configuration for these interfaces comes from the heliodines private git repository at /var/local/projects/heliodines/git/src/cfg/tropo/trop02/etc/network/interfaces.


    less /var/local/projects/heliodines/git/src/cfg/tropo/trop02/etc/network/interfaces 

        # This file describes the network interfaces available on your system
        # and how to activate them. For more information, see interfaces(5).

        # The loopback network interface
        auto lo
        iface lo inet loopback

        # Public interface
        auto br0
        iface br0 inet static
            # dns-* options are implemented by the resolvconf package, if installed
            # Configure bridge port and STP.
            bridge_ports eth0
            bridge_fd 0
            bridge_stp off
            bridge_maxwait 0

        # Private interface
        auto br1
        iface br1 inet static
            # Configure bridge port and STP.
            bridge_ports eth1
            bridge_fd 0
            bridge_stp off
            bridge_maxwait 0

Both of these interfaces are configured as bridges with static IP addresses, allowing them to be used as routes to access hosts on other networks.

The br0 interface is allocated an external public IP address,, on the address range, providing access to/from the public internet.

The br1 interface is allocated an internal IP address,, on the network, providing access to the SQLServer databases inside ROE.

Each of these interfaces also has a corresponding port that inherits the MAC address and IP address of the bridge, creating an internal interface that the OS on the physical hyper-visor machine can use.



        eth0    Link encap:Ethernet  HWaddr 0c:c4:7a:35:12:06  

        eth1    Link encap:Ethernet  HWaddr 0c:c4:7a:35:12:07  

Virtual networks

The physical trop01 hyper-visor machine is running two virtual networks created by the libvirt system.


    virsh \
        --connection 'qemu:///system' \

         Name                 State      Autostart     Persistent
         bridged              active     yes           yes
         default              active     yes           yes

The source configuration for these virtual networks comes from the heliodines private git repository at /var/local/projects/heliodines/git/src/cfg/tropo/trop02/etc/libvirt/qemu/networks/.


    ls /var/local/projects/heliodines/git/src/cfg/tropo/trop02/etc/libvirt/qemu/networks/


The bridged network is configured as a forwarding bridge connected to the external br0 interface.


    less /var/local/projects/heliodines/git/src/cfg/tropo/trop02/etc/libvirt/qemu/networks/bridged.xml

        <network ipv6='yes'>
          <forward mode='bridge'/>
          <bridge name='br0'/>

This configuration means any virtual machines connected to the bridged network is effectively connected to the external br0 bridge interface on the ROE machine room VLAN. This means that the virtual machine can use this interface for outbound access the to external public internet, and, if the virtual machine is given a public IP address within the range, then it can also be reached by inbound traffic from the public internet.

The default network is configured as a standard libvirt NAT network with slots for 8 virtual machines.


    less /var/local/projects/heliodines/git/src/cfg/tropo/trop02/etc/libvirt/qemu/networks/default.xml

        <network ipv6='yes'>
          <forward mode='nat'>
              <port start='1024' end='65535'/>
          <bridge name='virbr0' stp='off' delay='0'/>
          <mac address='52:54:00:02:02:01'/>
          <ip family='ipv4' address='' netmask=''>
              <range start='' end=''/>
              <host mac='52:54:00:02:02:08' ip=''  name='Araybwyn'/>
              <host mac='52:54:00:02:02:09' ip=''  name='Lothigometh'/>
              <host mac='52:54:00:02:02:0A' ip='' name='Ulov'/>
              <host mac='52:54:00:02:02:0B' ip='' name='Dwiema'/>
              <host mac='52:54:00:02:02:0C' ip='' name='Ibalehar'/>
              <host mac='52:54:00:02:02:0D' ip='' name='Eterathiel'/>
              <host mac='52:54:00:02:02:0E' ip='' name='Siamond'/>
              <host mac='52:54:00:02:02:0F' ip='' name='Acilamwen'/>

The MAC addresses and IP addresses for the NAT network on each of the hyper-visor machines, trop01 to trop04, are allocated within specific ranges.

| hyper-visor |  MAC address range  |  IP address range  |
|    trop01   |  52:54:00:02:01:xx  |  |
|    trop02   |  52:54:00:02:02:xx  |  |
|    trop03   |  52:54:00:02:03:xx  |  |
|    trop04   |  52:54:00:02:04:xx  |  |

This pattern makes it easier to identify which physical hyper-visor an IP or MAC address from a network trace belongs to.

Virtual machines

There are 5 virtual machines running on trop02.


    virsh \
        --connect 'qemu:///system' \

         Id    Name                           State
         2     Acilamwen                      running
         3     Lothigometh                    running
         4     Ulov                           running
         5     Eterathiel                     running
         6     Ibalehar                       running

Two of them, Acilamwen and Eterathiel, are running services for the TAP services the rest do not have any active containers.

Acilamwen is running the front-end Apache HTTP proxy in a container.


    ssh Acilamwen \
        docker ps

        Tue 18 Jul 16:11:48 BST 2023
        CONTAINER ID        IMAGE                     COMMAND                  CREATED             STATUS              PORTS                NAMES
        9683ea05bb04        firethorn/apache:latest   "/usr/local/bin/http…"   2 years ago         Up 4 weeks>80/tcp   apache

Eterathiel is running the back-end components that make up the Firethorn webservice.


    ssh Eterathiel \
        docker ps

        Tue 18 Jul 16:12:56 BST 2023
        CONTAINER ID        IMAGE                           COMMAND                  CREATED             STATUS                PORTS               NAMES
        a9775b40354e        firethorn/ogsadai:2.1.36        "/bin/sh -c '/var/lo…"   5 days ago          Up 5 days (healthy)   8080/tcp            ft_jarmila.1.4yzmmuh6jfiqvw4tmslylzox8
        aca731144335        firethorn/firethorn:2.1.36      "/bin/sh -c '/var/lo…"   5 days ago          Up 5 days (healthy)   8080/tcp            ft_gillian.1.14o28ydavjbctxh8sirh1yp1i
        6216fd3ef158        firethorn/firethorn-py:2.1.36   "python3"                4 weeks ago         Up 4 weeks                                ft_firethorn-py.1.rxfuqi2evdpkeeixz6khdhvin
        97980c766d5d        firethorn/postgres:2.1.36       "docker-entrypoint.s…"   4 weeks ago         Up 4 weeks            5432/tcp            ft_carolina.1.zx12opk1k05luhlbkza0pa37l
        a562c255b7de        firethorn/postgres:2.1.36       "docker-entrypoint.s…"   4 weeks ago         Up 4 weeks            5432/tcp            ft_bethany.1.sibtonwiibkdc7v08fpazjrt7

OS and software

The virtual machines are configured to be a minimal Linux install needed to be a Docker host, plus some system administration tools to help with debugging network issues. The last set of notes I have that cover creating a new VM image are from October 2018, 20181016-02-update-vmimage.txt, which matches the qcow2 backing file for Acilamwen.


    virsh \
        --connect 'qemu:///system' \
        dumpxml \
            'Acilamwen' \
    | xmllint \
        --xpath '//disk[@device="disk"]' \

    <disk type="file" device="disk">
      <driver name="qemu" type="qcow2"/>
      <source file="/libvirt/storage/live/Acilamwen.qcow"/>
      <backingStore type="file" index="1">
        <format type="qcow2"/>
        <source file="/var/lib/libvirt/images/base/fedora-28-32G-docker-base-20181016.qcow"/>
      <target dev="vda" bus="virtio"/>
      <alias name="virtio-disk0"/>
      <address type="pci" domain="0x0000" bus="0x00" slot="0x04" function="0x0"/>

It doesn't look like they have been updated since then.


    ssh Acilamwen \
        cat /etc/redhat-release
        sudo yum history

        Tue 18 Jul 16:20:48 BST 2023
        Fedora release 28 (Twenty Eight)

        ID     | Command line             | Date and time    | Action(s)      | Altered
             2 | -y install docker-ce     | 2018-10-16 13:41 | Install        |    3 EE
             1 |                          | 2018-10-16 13:37 | Install        |  435 EE


Network interfaces

Acilamwen should have one network connection to the default NAT network, and one connection to the public internet, using a connection to the br0 external interface on the physical hyper-visor via the bridged virtual network.

The last set of notes I have on configuring the network on Acilamwen are from February 2021, 20210208-01-float-deploy.txt, describing the process for adding a floating point IP address to the VM following a reboot of the host hyper-visor.

Docker containers


Network interfaces

Docker containers

Clone this wiki locally