OpenContrail Overview Architecture & Demo

Similar documents
OPEN CONTRAIL ARCHITECTURE GEORGIA TECH SDN EVENT

Juniper JN0-410 Exam. Volume: 65 Questions. Question No: 1 What are two valid service VMs in a service chain? (Choose two.) A.

Introduction to Neutron. Network as a Service

Quantum, network services for Openstack. Salvatore Orlando Openstack Quantum core developer

BRKDCT-1253: Introduction to OpenStack Daneyon Hansen, Software Engineer

Architecture and terminology

Best Practice Deployment of F5 App Services in Private Clouds. Henry Tam, Senior Product Marketing Manager John Gruber, Sr. PM Solutions Architect

Build Cloud like Rackspace with OpenStack Ansible

Cloud Networking (VITMMA02) Network Virtualization: Overlay Networks OpenStack Neutron Networking

Part2: Let s pick one cloud IaaS middleware: OpenStack. Sergio Maffioletti

Contrail Cloud Platform Architecture

DPDK Summit 2016 OpenContrail vrouter / DPDK Architecture. Raja Sivaramakrishnan, Distinguished Engineer Aniket Daptari, Sr.

Contrail Cloud Platform Architecture

Accelerating Contrail vrouter

OpenStack Networking Services and Orchestration 2015 BROCADE COMMUNICATIONS SYSTEMS, INC. COMPANY PROPRIETARY INFORMATION

TungstenFabric (Contrail) at Scale in Workday. Mick McCarthy, Software Workday David O Brien, Software Workday

FROM SDN TO CLOUD NETWORKING. Bob Muglia EXECUTIVE VICE PRESIDENT, SOFTWARE SOLUTIONS DIVISION

Neutron: peeking behind the curtains

Network Mul,tenancy in Xen- based Clouds. Chiradeep Vi;al CloudStack Commi;er Citrix Sep

Flexible NFV WAN interconnections with Neutron BGP VPN

Accelerating vrouter Contrail

JN0-210.juniper. Number: JN0-210 Passing Score: 800 Time Limit: 120 min.

Provisioning Overlay Networks

Nexus 1000V in Context of SDN. Martin Divis, CSE,

NephOS. A Single Turn-key Solution for Public, Private, and Hybrid Clouds

CS-580K/480K Advanced Topics in Cloud Computing. OpenStack

"Charting the Course... H8Q14S HPE Helion OpenStack. Course Summary

NephOS. A Single Turn-key Solution for Public, Private, and Hybrid Clouds

VMWARE SOLUTIONS AND THE DATACENTER. Fredric Linder

Contrail Release Release Notes

SDN+NFV Next Steps in the Journey

WELCOME. Chicago Juniper Users Group SEPT 18TH, 2013

Contrail Release Release Notes

BCS EXIN Foundation Certificate in OpenStack Software Syllabus

Open vswitch in Neutron

Contrail Release Release Notes

Contrail Sandbox Tutorial Script

CONTAINERS AND MICROSERVICES WITH CONTRAIL

Cisco Virtual Topology System (VTS)

Openstack Networking Design

Network Automation: Options & Possibilities 2016 BROCADE COMMUNICATIONS SYSTEMS, INC.

Contrail Release Release Notes

Session objectives and takeaways

Building NFV Solutions with OpenStack and Cisco ACI

Neutron networking with RHEL OpenStack Platform. Nir Yechiel Senior Technical Product Manager, OpenStack Red Hat

Exploring Cloud Security, Operational Visibility & Elastic Datacenters. Kiran Mohandas Consulting Engineer

CONTRAIL NETWORKING. Product Description. Product Overview

Minimal OpenStack Starting Your OpenStack Journey

Case Study on Enterprise Private Cloud

Ethernet Fabrics- the logical step to Software Defined Networking (SDN) Frank Koelmel, Brocade

LAB EXERCISE: RedHat OpenShift with Contrail 5.0

Xen and CloudStack. Ewan Mellor. Director, Engineering, Open-source Cloud Platforms Citrix Systems

Cloud Networking From Theory to Practice. Ivan Pepelnjak NIL Data Communications

Managing Demand Spikes in a highly flexible and agile deployment

Road to Private Cloud mit OpenStack Projekterfahrungen

OpenStack Ceilometer. Tong Li (IBM) Brad Topol (IBM)

Data Center Configuration. 1. Configuring VXLAN

Fully Scalable Networking with MidoNet

Cisco Virtual Networking Solution for OpenStack

Introduction To OpenStack. Haim Ateya Group Manager, EMC

OpenStack. Architecture and Operation. OpenStack Tutorial Day 2. Kasidit Chanchio Vasabilab, Thammasat University

OpenStack Network Design using Cisco Solutions Shannon McFarland CCIE #5245 Principal

Gluon: An Enabler for NFV

DEPLOYING NFV: BEST PRACTICES

Alternatives for Improving OpenStack Networking to Address NFV Needs

Project Calico v3.2. Overview. Architecture and Key Components. Project Calico provides network security for containers and virtual machine workloads.

Xen*, SDN and Apache Cloudstack. Sebastien Goasguen, Apache CloudStack Citrix EMEA August 28 th 2012 Xen Summit

Provisioning Overlay Networks

File system, 199 file trove-guestagent.conf, 40 flavor-create command, 108 flavor-related APIs list, 280 show details, 281 Flavors, 107

SDN TO BE OR NOT TO BE. Uwe Richter SE Director Russia/CIS, East and South East Europe

Več kot SDN - SDA arhitektura v uporabniških omrežjih

Building a Big IaaS Cloud. David /

Using PCE for path computation, PCEP for device config and BGP-LS for topology discovery vcpe

Cloud Essentials for Architects using OpenStack

Building a Video Optimized Private Cloud Platform on Cisco Infrastructure Rohit Agarwalla, Technical

Simplify Container Networking With ican. Huawei Cloud Network Lab

70-745: Implementing a Software-Defined Datacenter

Cisco VTS. Enabling the Software Defined Data Center. Jim Triestman CSE Datacenter USSP Cisco Virtual Topology System

OpenStack Networking: Where to Next?

METAFABRIC ARCHITECTURE A SIMPLE, OPEN, AND SMART NETWORK FOR THE DATA CENTER

IP Fabric Reference Architecture

Baremetal with Apache CloudStack

Deploying TeraVM in an OpenStack Environment

Contrail Networking: Evolve your cloud with Containers

Dockercon 2017 Networking Workshop

Contrail Networking. Product Description. Data Sheet. Product Overview

Network Automation using Contrail Cloud (NACC)

Layer-4 to Layer-7 Services

Project Calico v3.1. Overview. Architecture and Key Components

Virtualization Design

Network Virtualization

Application Centric Microservices Ken Owens, CTO Cisco Intercloud Services. Redhat Summit 2015

Apache CloudStack. Sebastien Goasguen Open Source Office,

Weiterentwicklung von OpenStack Netzen 25G/50G/100G, FW-Integration, umfassende Einbindung. Alexei Agueev, Systems Engineer

Upcoming Services in OpenStack Rohit Agarwalla, Technical DEVNET-1102

Distributed Systems. 31. The Cloud: Infrastructure as a Service Paul Krzyzanowski. Rutgers University. Fall 2013

OpenStack and OpenDaylight, the Evolving Relationship in Cloud Networking Charles Eckel, Open Source Developer Evangelist

Windows Server System Center Azure Pack

Contrail plugin for Fuel Documentation

Integration of Hypervisors and L4-7 Services into an ACI Fabric. Azeem Suleman, Principal Engineer, Insieme Business Unit

Transcription:

www.opencontrail.org OpenContrail Overview Architecture & Demo Qasim Arham Oct, 2014

Agenda Introduction OpenStack Architecture and Overview OpenContrail and OpenStack Integration OpenStack Neutron Overview OpenContrail Architecture How to configure OpenContrail Overlay Network Demo

http://www.openstack.org/software OpenStack Overview Dashboard (Horizon) Networking (Neutron) Object Storage Computing (Nova) Identity (Keystone) Image Service (Glance)

Value Visibility to End Users OpenStack as IaaS End Users Application Developer SaaS PaaS Network Architects IaaS

OpenStack Overview (Grizzly) Network (Neutron) OpenStack GUI Dashboard (Horizon) Provides Network Connectivity Image Repo (Glance) Provides UI for Services & Modules Compute (Nova) Block Storage (Cinder) Provides Authentication And service catalog for All Services & Modules Object Storage (Swift) Identity (Keystone)

OpenStack Overview (Havana) Network (Neutron) OpenStack GUI Dashboard (Horizon) Provides Network Connectivity Provides UI for Services & Modules Image Repo (Glance) Block Storage (Cinder) Compute (Nova) Provides Authentication And service catalog for All Services & Modules Object Storage (Swift) Heat (Orchestration) Ceilometer (Metering) Identity (Keystone)

OpenStack Architecture Overview OpenStack GUI Horizon GUI Keystone (Identity/Access Mgmt) Keystone Server Keystone DB Glance (Image Service) API SRV Registry Glance DB Queue Nova Compute (Orchestration) API SRV Scheduler Conductor Nova DB. Swift (Object Storage) Neutron Plugin API SRV Proxy Object Store VMs Spawned Neutron Server DHCP/IPAM Neutron DB API SRV Cinder Vol Cinder (Block Storage) Scheduler Queue Storage Cinder DB Nova Agent VM01 VM02 VM03 Hypervisor Compute Neutron Plugin/ Agent

OpenStack Architecture Overview (cont.) HTTP RabbitMQ SQL iscsi OpenStack GUI Horizon GUI Keystone (Identity/Access Mgmt) Keystone Server Keystone DB Glance (Image Service) API SRV Registry Glance DB Queue API SRV Nova Compute (Orchestration) Scheduler Conductor Nova DB. Swift (Object Storage) Neutron Plugin API SRV Proxy Object Store Neutron Server DHCP/IPAM Neutron DB Cinder (Block Storage) VM01 API SRV Cinder DB Scheduler Queue Storage Cinder Vol Nova Compute Agent Hypervisor Compute Neutron Plugin/ Agent

Contrail/OpenStack Overview (Grizzly) Network (vrouter) Controller (Contrail) CFMG (Contrail) Analytics (Contrail) Contrail GUI Configuration and Analytics OpenStack GUI Dashboard (Horizon) Image Repo (Glance) Provides UI for Services & Modules Compute (Nova) Block Storage (Cinder) Provides Authentication And service catalog for All Services & Modules Object Storage (Swift) Identity (Keystone)

Contrail Architecture XMPP Orchestrator (OpenStack) XMPP Analytics REST Analytics Configuration Contrail Controller Configuration IF-MAP Control IBGP Control BGP + NetConf Compute (vrouter) Gateway (MX, EX, QFX) Service (SRX, Firefly)

Get VM Image to Spawn OpenContrail Integration with OpenStack User Logs in, Create tenant (Projects), Create IPAM, Create Virtual Network, Launch VMs OpenStack GUI Contrail GUI Horizon GUI Contrail GUI Authentication, Authorization, etc. Keystone (Identity/Access Mgmt) Launch VM/Instance Networking Interaction (VN,IPAM,Port, VIF..etc.) Glance (Image Service) Nova Compute (Orchestration) Neutron Plugin Contrail Config API SRV Scheduler. Contrail Control Swift (Object Storage) Select Compute to spawn Instance (VM) Get Virtual Network Info Cinder (Block Storage) Block Storage Assignment Spawn VM Info VMs Spawned VM01 VM03 VM02 DHCP Bi-directional Message Bus (XMPP Interaction) Contrail Agent Nova Agent Hypervisor vrouter Storage Compute Plug(Tap Interfaces, Instance ID )

OpenContrail Integration with OpenStack Horizon Scripts (API) Nova API Nova Scheduler 1. Create an Instance (VM info, Network, IPAM, Policies, etc.) Neutron Plugin Neutron Driver 4. Create VM Interface 6. Publish VM Intf on IFMap Configuration Control 2. Schedule an Instance on the Compute 3. VM Network properties 7. VM Interface Config Over XMPP Nova Compute Compute Driver Virtual-IF Driver 5. Add Port Compute Virtual Router Contrail Agent vrouter (Kernel)

OpenStack Neutron "network-as-a-service SDN

OpenStack Neutron Neutron: Pluggable, scalable, API-driven network and IP Management Provides a rich and tenant-facing API for defining network connectivity and addressing in the cloud

Neutron Networking API Functionalities Network An isolated L2 Segment, analogous to VLAN in the physical networking world. Subnet A block of v4 or v6 IP addresses and associated configuration state. Port A connection point for attaching a single device, such as a NIC of a virtual server to a virtual network. Virtual Router & NAT Local & External networks

Neutron Architecture API Overview Pluggable Back-End using Vif OVS Plugin Linux Bridge Plugin NEC Plugin Big Switch Plugin Hyper-V Plugin Brocade Plugin OpenContrail Gateway Service Firewall Service REST API Neutron

Neutron Components Neutron Server - API L3 Agent DHCP Agent Data Base Queue Plugin Agent

Neutron Plugin & Agent Summary OVS NICIRA OpenContrail RYU Others Flat VLAN GRE XMPP/ BGP GRE VxLAN OpenF low/o VS??? OpenStack Neutron dnsmasq NAT Router IPTables??? HAprox y F5??? DHCP AGENT L3 AGENT Firewall AGENT L-B AGENT

Floating IP (Neutron) OpenStack Cluster Instance 1 VM1 Internal Private Pool (VN1) 10.1.1.0/24 Instance 2 VM2 Floating POOL (Public) 75.1.1.0/24 30.0.0.1 Instance 3 VM3 NAT Router (L2/L3) Basic L3 router construct to route between L2 networks Provides a gateway to external networks Support for SNAT and Floating IPs

Security Group Security Groups Allows L3-L4 packet filtering for security policies to protect the instances (VMs) Collection of network access rules that specify traffic allowed to and from a VM Associated with a VM at startup If not specified, a VM is assigned to the default Security Group, which allows traffic from all other members of the group VM can be associated with many Security Groups Security Group rule specifies: Source of traffic (IP/CIDR or another Security Group) Protocol (TCP, UDP, ICMP, etc.) Destination port on VM SSH TCP RTP

Physical Network Design (OpenStack Architecture) Public/Provider Network eth1 eth1 eth1 Compute Cluster eth1 Swift Cluster eth1 Compute Network Controller / Endpoint node Block Storage Block Storage Block Storage eth0 eth0 eth0 eth0 eth0 eth0 Private Storage Management iscsi

OpenContrail Architecture

OpenContrail What is OpenContrail? SDN solution Automates and orchestrates highly scalable virtual networks Network programmability NFV Big data analytics Open system architecture Visualization Two primary drivers Cloud networking NFV in service provider network

Two Main Components Contrail Controller Control plane Logically centralized, physically distributed Management, control, and analytics Manages the vrouters Contrail vrouter Forwarding plane Extends physical network to virtual overlay network Provides Layer 2 and Layer 3 services

Bridging Physical and Virtual Networks Virtual Networks Implemented on top of physical networks Replaces VLAN-based isolation Virtual networks isolated from each other unless permitted by security polices Provides multi-tenancy in a virtualized data center MPLS L3VPN and EVPN technologies Used to implement NFV

Overlay Networking Overlay Networking Physical underlay network Routers and switches Provides IP connectivity Uniform low-latency, non-blocking, high-bandwidth connectivity No per-tenant state Virtual overlay network vrouters create overlay network on top of the underlay network Per-tenant state MPLS over GRE tunnels MPLS over UDP tunnels VXLAN tunnels

Example ( 1 site) Contrail within a data center MPLS over GRE tunnel automatically setup when VMs are deployed VN to VN communication requires a security policy VN-A Contrail VN-B vrouter vrouter Compute 1 Compute 2 A-1 B-1 B-2 A-2

Example ( 2 Sites) Data Centers connected over the WAN One tunnel per vrouter connection Contrail WAN Compute 1 Compute 2 vrouter vrouter vrouter vrouter Compute 3 A-1 B-1 A-2 C-1 C-2 B-2 A-3 B-3 Data Center 1 Data Center 2 Compute 4

Contrail Architecture XMPP Orchestrator (OpenStack) XMPP Analytics REST Analytics Configuration Contrail Controller Configuration IF-MAP Control IBGP Control BGP + NetConf Compute (vrouter) Gateway (MX, EX, QFX) Service (SRX, Firefly)

Logical Architecture & Interface Overview Contrail Logical Architecture OpenStack GUI Contrail GUI Server2 Contrail CFMG/Analytics/GUI Control Plane (IF-MAP) Control Plane (IF-MAP) Control Plane (Sandesh) Server3 Contrail Controller Control Plane (IBGP) Control Plane (XMPP) Control Plane (IBGP) Server4 Contrail Controller Control Plane (XMPP) MX-GW Data Plane MPLSoGRE Server5 Contrail vrouter Data Plane MPLSoGRE Server6 Contrail vrouter VM01 VM02 VM03 VM01 VM02 VM03

Contrail Stack Compute and vrouter Customer OSS/BSS OpenStack CloudStack REST APIs (Configuration, Operational, Analytics) Analytics Engine Analytics Engine Analytics Engine Configuration s Control Plane Control Plane Control Plane Compute (vrouter) Gateway (MX, EX, QFX) Service (SRX, Firefly)

Contrail vrouter (SW Overview) Compute (vrouter) Replaces the Linux bridge or OVS module in Hypervisor kernel Performs bridging (E-VPN) and routing (L3VPN) Performs network services like security policies, NAT, multicast, mirroring, and load balancing No need for Service s or L2/L3 gateways for routing, broadcast, multicast, or NAT Routes automatically leaked into VRFs based on policy Multiple interfaces support on VMs Multiples interface support from Compute s to switching fabric Contrail vrouter supervisor-vrouter contrail-vrouter contrail-vrouter-nodemgr Support Servcies libvirtd Nova Servcies openstack-nova-compute

Contrail Stack: Control Layer Customer OSS/BSS OpenStack CloudStack REST APIs (Configuration, Operational, Analytics) Analytics Engine Analytics Engine Analytics Engine Configuration Control Plane Control Plane Control Plane Compute (vrouter) Gateway (MX, EX, QFX) Service (SRX, Firefly)

Contrail Controller (SW Overview) Control All Control s are active-active Each vrouter uses XMPP to connect with multiple Control s for redundancy Each Control connects to multiple Configuration s for redundancy BGP and NetConf is used to connect with physical gateway routers or Service s Control s federate using BGP Control s can run different software versions for test-before-deploy and live upgrades Contrail Config ssupervisor-config contrail-api contrail-config-nodemgr contrail-discovery contrail-schema contrail-svc-monitor contrail-zookeeper Ifmap redis-config Contrail Database supervisord-contrail-database contrail-database Contrail Control supervisor-control contrail-control contrail-control-nodemgr supervisor-dns contrail-dns contrail-named Quantum Servcies quantum-server Support Servcies rabbitmq-server

Route Distribution Control Plane (XMPP) 10.1.1.2: NH = 151.10.10.1; LBL = 17 Configuration IF-MAP Control REST API 10.1.1.1: NH = 70.10.10.1; LBL = 39 Outer MAC headers left out to reduce clutter Control Plane (XMPP) 10.1.1.1: NH = 70.10.10.1; LBL = 39 10.1.1.2: NH = 151.10.10.1; LBL = 17 PubDstIP PubSrcIP PriDstIP PriSrcIP 150.10.10.1 70.10.10.1 GRE LBL=17 10.1.1.2 10.1.1.1 PAYLOAD IP Network 70.10.10.1 151.10.10.1 vrouter Agent 10.1.1.2: NH = 151.10.10.1; LBL = 17 VRF (Dynamic Tunnel Encapsulation) 10.1.1.1: NH = 70.10.10.1; LBL = 39 (Dynamic Tunnel Encapsulation) VRF vrouter Agent PriDstIP PriSrcIP 10.1.1.2 10.1.1.1 PAYLOAD VM-A VM-B PriDstIP PriSrcIP 10.1.1.2 10.1.1.1 PAYLOAD Compute 1 10.1.1.1 10.1.1.2 Compute 2

Route Distribution: L3VPN REST API Config Mgmt. DC-1 Control Plane XMPP BGP Control s 10.1.1.2: NH = 80.20.20.1; LBL = 417 ;RD ;RT 10.1.1.2: NH = 80.20.20; LBL = 417 I-MBGP E-MBGP I-MBGP E-MBGP I-MBGP MPLS Outer Label IP Network 10.1.1.2: NH = 200.1.1.1; LBL = 317 ;RD ;RT Service 80.20.20.1 200.1.1.1 Provider 100.1.1.1 160.20.20.1 PriDstIP 10.1.1.2: NH = 100.1.1.1; LBL = 217 ;RD ;RT PubDstIP PubSrcIP PriDstIP PriSrcIP 80.20.20.1 100.1.1.1 MPLS PriSrcIP 10.1.1.2: NH = 160.20.20.1; LBL = 117 ;RD ;RT LBL=217 10.1.1.2 10.1.1.1 PAYLOAD IP Network 10.1.1.2: NH = 151.10.10.1; LBL = 17 ;RD ;RT BGP Control s 10.1.1.2: NH = 151.10.10.1; LBL = 17 PubDstIP PubSrcIP PriDstIP PriSrcIP 80.20.20.1 70.10.10.1 GRE LBL=417 10.1.1.2 10.1.1.1 PAYLOAD REST API 200.1.1.1 160.20.20.1 70.10.10.1 151.10.10.1 Config Mgmt. DC-2 Control Plane XMPP 151.20.20.1 160.20.20.1 GRE LBL=417 10.1.1.2 10.1.1.1 PAYLOAD 10.1.1.2: NH = 80.20.20.1; LBL = 417 PriDstIP PriSrcIP 10.1.1.2 10.1.1.1 PAYLOAD 10.1.1.2 VM-A VM-B Server 1 10.1.1.1 Server 2 10.1.1.1: NH = 80.20.20.1; LBL = 417 PriDstIP PriSrcIP 10.1.1.2 10.1.1.1 PAYLOAD

Route Distribution: E-VPN Control Plane (XMPP) MAC2: NH = 151.10.10.1; LBL = 17 Configuration IF-MAP Control REST API MAC1: NH = 70.10.10.1; LBL = 39 Control Plane (XMPP) MAC1: NH = 70.10.10.1; LBL = 39 MAC2: NH = 151.10.10.1; LBL = 17 PubDstIP PubSrcIP DstMAC SrcMAC 150.10.10.1 70.10.10.1 GRE LBL=17 MAC1 MAC2 PAYLOAD IP Network 70.10.10.1 151.10.10.1 vrouter Agent MAC2: NH = 151.10.10.1; LBL = 17 VRF (Dynamic Tunnel Encapsulation) MAC1: NH = 70.10.10.1; LBL = 39 (Dynamic Tunnel Encapsulation) VRF vrouter Agent DstMAC SrcMAC MAC2 MAC1 PAYLOAD VM VM DstMAC SrcMAC MAC2 MAC1 PAYLOAD Server 1 MAC1 MAC2 Server 2

Contrail Stack: Configuration s Customer OSS/BSS OpenStack CloudStack REST APIs (Configuration, Operational, Analytics) Analytics Engine Analytics Engine Analytics Engine Configuration s Control Plane Control Plane Control Plane Compute (vrouter) Gateway (MX, EX, QFX) Service (SRX, Firefly)

Contrail CFMG/Analytics/GUI (SW Overview) Contrail Database supervisord-contrail-database contrail-database Contrail Config ssupervisor-config contrail-api contrail-config-nodemgr contrail-discovery contrail-schema contrail-svc-monitor contrail-zookeeper Ifmap redis-config Support Servcies Mysqld Httpd Libvirtd rabbitmq-server memcached Contrail Web UI supervisor-webui contrail-webui contrail-webui-middleware redis-webui Contrail Analytics supervisor-analytics contrail-analytics-nodemgr contrail-collector contrail-opserver contrail-qe redis-query redis-sentinel redis-uve Horizon Services openstack-dashboard Keystone Services openstack-keystone Quantum Servcies quantum-server Cinder Services openstack-cinder-api openstack-cinder-scheduler Glance Services openstack-glance-api openstack-glance-registry Nova Servcies openstack-nova-api openstack-nova-cert openstack-nova-scheduler openstack-nova-conductor Configuration API server provides northbound REST interface -- orchestration system provisions using this API service DHT/NoSQL database is used for persistence and High Availability of configuration Schema transformer compiles the high level data model to low level model for vrouter, Service s, and Gateway Routers IF-MAP is used to represent the data-model -- Control s subscribe to a subset of the configuration

Contrail Stack: Analytics Engine Customer OSS/BSS OpenStack CloudStack REST APIs (Configuration, Operational, Analytics) Analytics Engine Analytics Engine Analytics Engine Configuration s Control Plane Control Plane Control Plane Compute (vrouter) Gateway (MX, EX, QFX) Service (SRX, Firefly)

Contrail CFMG/Analytics/GUI (SW Overview) Contrail Database supervisord-contrail-database contrail-database Contrail Config ssupervisor-config contrail-api contrail-config-nodemgr contrail-discovery contrail-schema contrail-svc-monitor contrail-zookeeper Ifmap redis-config Support Servcies Mysqld Httpd Libvirtd rabbitmq-server memcached Contrail Web UI supervisor-webui contrail-webui contrail-webui-middleware redis-webui Contrail Analytics supervisor-analytics contrail-analytics-nodemgr contrail-collector contrail-opserver contrail-qe redis-query redis-sentinel redis-uve Horizon Services openstack-dashboard Keystone Services openstack-keystone Quantum Servcies quantum-server Cinder Services openstack-cinder-api openstack-cinder-scheduler Glance Services openstack-glance-api openstack-glance-registry Nova Servcies openstack-nova-api openstack-nova-cert openstack-nova-scheduler openstack-nova-conductor Analytics API server provides northbound REST Interface for Applications SQL-style query language for NoSQL access -- object traces, flow records, syslog DHT/NoSQL database is used for scale and persistence Sandesh Protocol (XML over TCP) is used by all nodes (Control, Configuration, Compute, and physical network) to deposit data in the NoSQL DB Rules engine automatically collects operational state on specific events Collector supports NetFlow for non- Juniper devices Operational state of any node can be queried by the analytics engine

Analytics Access Through the Northbound API Configuration Virtual network (L2/L3) Security and QoS policies IPAM rules, floating IP Analyzer and mirroring Operational Control s and vrouters Datacenter gateway router Virtual router connected networks and ACLs Virtual router statistics Analytics Query tables Flow records System objects Aggregated traffic statistics

Contrail Stack: REST APIs Customer OSS/BSS OpenStack CloudStack REST APIs (Configuration, Operational, Analytics) Analytics Engine Analytics Engine Analytics Engine Configuration s Control Plane Control Plane Control Plane Compute (vrouter) Gateway (MX, EX, QFX) Service (SRX, Firefly)

APIs http://www.juniper.net/techpubs/en_us/releaseindependent/contrail/information-products/pathway-pages/apiserver/index.html

Contrail Stack: OpenStack Customer OSS/BSS OpenStack CloudStack REST APIs (Configuration, Operational, Analytics) Analytics Engine Analytics Engine Analytics Engine Configuration s Control Plane Control Plane Control Plane Compute (vrouter) Gateway (MX, EX, QFX) Service (SRX, Firefly)

OpenStack Horizon VM States: Scheduling Networking Spawning Active

Contrail Dashboard The Dashboard page shows a at a glance view of the Infrastructure components including the number of virtual routers, control nodes, analytics nodes, and Config nodes currently operational, bubble chart of virtual routers showing the CPU and memory utilization, logs, system information and alerts

OpenContrail References: Github link: https://github.com/juniper OpenContrail & DevStack: https://etherpad.openstack.org/p/contrail-devstack Configuring Contrail for OpenStack: https://github.com/juniper/contrail-controller/wiki/configuring-contrail-for-openstack OpenContrail Users Mailing List: http://lists.opencontrail.org/mailman/listinfo/users_lists.opencontrail.org OpenContrail Dev Mailing List: http://lists.opencontrail.org/mailman/listinfo/dev_lists.opencontrail.org

OpenContrail References: Network Virtualization Architecture Deep Dive http://opencontrail.org/network-virtualization-architecture-deep-dive/ Software architecture http://juniper.github.io/contrail-vnc/architecture.html http://opencontrail.org/blog/ http://juniper.github.io/contrail-vnc/readme.html Day One Book: http://www.amazon.com/day-one-understanding-opencontrail-architecture- ebook/dp/b00gtxgp7o/ref=sr_1_1?ie=utf8&qid=1386871850&sr=8-1&keywords=opencontrail