1. Installing ManageIQ

Installing ManageIQ consists of the following steps:

  1. Downloading the appliance for your environment as a virtual machine image template.

  2. Setting up a virtual machine based on the appliance.

  3. Configuring the ManageIQ appliance.

After you have completed all the procedures in this guide, you will have a working environment on which additional customizations and configurations can be performed.

1.1. Obtaining the Appliance

  1. In a browser, navigate to manageiq.org/download.

  2. Select Google Compute Engine from the --Choose your platform-- list.

  3. Select Stable from the --Choose a release-- list.

  4. Follow the instructions to download the appliance.

1.2. Uploading the Appliance on Google Compute Engine

When the ManageIQ Google Compute Engine appliance has finished downloading to your system, upload the appliance to Google Compute Engine.

To upload the ManageIQ Google Compute Engine appliance file you will need: * 44 GB of storage space. * 12 GB RAM. * 4 vCPUs.

You can upload the appliance with the following steps:

  1. Log in to the Google Cloud Platform dashboard.

  2. Click on Home in the top left of the screen.

  3. Click GCE products services to show the Products and Services menu. Click Storage.

  4. Create a bucket by clicking Create Bucket, and configure the following details:

    1. Enter a unique Name for the bucket using lower case alphanumeric characters, hyphens, and/or underscores.

    2. Configure your location from the dropdown list.

    3. Click Create.

  5. Click Upload Files and browse to the location of the ManageIQ Google Compute Engine appliance you downloaded. Select the tar.gz file on your local machine, and click Open to begin the upload.

  6. When the upload is complete, click GCE products services Products & services  Compute Engine on the left menu.

  7. Create an image by clicking Images from the left menu, then Create Image. Fill in the following details about the image:

    1. Enter a unique Name for the image using lower case alphanumeric characters and/or hyphens.

    2. Add a Description if desired.

    3. Configure Encryption if desired. This defaults to Automatic (recommended).

    4. In Source, use the dropdown to select Cloud Storage file. This shows the Cloud Storage file field.

    5. In Cloud Storage file, click Browse to bring up the Select object window. Select the bucket containing the image you uploaded and click the > symbol to locate the tar.gz image inside the bucket. Select the image and click Select.

    6. Click Create. Creating the image will take a few minutes. When the image is created, the screen will refresh and the new image will appear in the Images list.

  8. Create a virtual machine instance by navigating to VM instances  Create Instance, and configure the following fields:

    1. Enter a unique Name for the virtual machine instance using lower case alphanumeric characters and/or hyphens.

    2. Select the Zone closest to your location.

    3. Under Boot disk, click Change to bring up the Boot disk window. Click the Your Image tab and select the disk you previously created. Click Select.

    4. Under Firewall, select the check box for Allow HTTPS traffic.

    5. Click GCE ManagementSSHkeysManagement, disk, networking, SSH keys. Then, click the SSH Keys tab, add your entire SSH public key data in the Username box.

    6. Configure any other fields as desired, and click Create.

Your new virtual machine instance, as well as the external IP address for accessing the ManageIQ interface, appears under VM instances.

2. Configuring ManageIQ

After installing ManageIQ and running it for the first time, you must perform some basic configuration. To configure ManageIQ, you must at a minimum:

  1. Add a disk to the infrastructure hosting your appliance.

  2. Configure the database.

Configure the ManageIQ appliance using the internal appliance console.

2.1. Accessing the Appliance Console

  1. Start the appliance and open a terminal console.

  2. Log in to the appliance using the SSH key.

  3. Enter the appliance_console command. The ManageIQ appliance summary screen displays.

  4. Press Enter to manually configure settings.

  5. Press the number for the item you want to change, and press Enter. The options for your selection are displayed.

  6. Follow the prompts to make the changes.

  7. Press Enter to accept a setting where applicable.

The ManageIQ appliance console automatically logs out after five minutes of inactivity.

2.2. Configuring a Worker Appliance

You can use multiple appliances to facilitate horizontal scaling, as well as for dividing up work by roles. Accordingly, configure an appliance to handle work for one or many roles, with workers within the appliance carrying out the duties for which they are configured. You can configure a worker appliance through the terminal. The following steps demonstrate how to join a worker appliance to an appliance that already has a region configured with a database.

  1. Start the appliance and open a terminal console.

  2. Log in to the appliance using the SSH key.

  3. Enter the appliance_console command. The ManageIQ appliance summary screen displays.

  4. Press Enter to manually configure settings.

  5. Select 5) Configure Database from the menu.

  6. You are prompted to create or fetch a security key. Since this is not the first ManageIQ appliance, choose 2) Fetch key from remote machine. For worker and multi-region setups, use this option to copy key from another appliance.

    All ManageIQ appliances in a multi-region deployment must use the same key.

  7. Choose 3) Join Region in External Database for the database location.

  8. Enter the database hostname or IP address when prompted.

  9. Enter the port number or leave blank for the default (5432).

  10. Enter the database name or leave blank for the default (vmdb_production).

  11. Enter the database username or leave blank for the default (root).

  12. Enter the chosen database user’s password.

  13. Confirm the configuration if prompted.

3. Logging In After Installing ManageIQ

Once ManageIQ is installed, you can log in and perform administration tasks.

Log in to ManageIQ for the first time after installing by:

  1. Navigate to the URL for the login screen. (https://xx.xx.xx.xx on the virtual machine instance)

  2. Enter the default credentials (Username: admin | Password: smartvm) for the initial login.

  3. Click Login.

3.1. Changing the Default Login Password

Change your password to ensure more private and secure access to ManageIQ.

  1. Navigate to the URL for the login screen. (https://xx.xx.xx.xx on the virtual machine instance)

  2. Click Update Password beneath the Username and Password text fields.

  3. Enter your current Username and Password in the text fields.

  4. Input a new password in the New Password field.

  5. Repeat your new password in the Verify Password field.

  6. Click Login.

Appendix A: Appendix

A.1. Appliance Console Command-Line Interface (CLI)

Currently, the appliance_console_cli feature is a subset of the full functionality of the appliance_console itself, and covers functions most likely to be scripted using the command-line interface (CLI).

  1. After starting the ManageIQ appliance, log in with a user name of root and the default password of smartvm. This displays the Bash prompt for the root user.

  2. Enter the appliance_console_cli or appliance_console_cli --help command to see a list of options available with the command, or simply enter appliance_console_cli --option <argument> directly to use a specific option.

Table 1. Database Configuration Options

Option

Description

--region (-r)

region number (create a new region in the database - requires database credentials passed)

--internal (-i)

internal database (create a database on the current appliance)

--dbdisk

database disk device path (for configuring an internal database)

--hostname (-h)

database hostname

--port

database port (defaults to 5432)

--username (-U)

database username (defaults to root)

--password (-p)

database password

--dbname (-d)

database name (defaults to vmdb_production)

Table 2. v2_key Options

Option

Description

--key (-k)

create a new v2_key

--fetch-key (-K)

fetch the v2_key from the given host

--force-key (-f)

create or fetch the key even if one exists

--sshlogin

ssh username for fetching the v2_key (defaults to root)

--sshpassword

ssh password for fetching the v2_key

Table 3. IPA Server Options

Option

Description

--host (-H)

set the appliance hostname to the given name

--ipaserver (-e)

IPA server FQDN

--ipaprincipal (-n)

IPA server principal (default: admin)

--ipapassword (-w)

IPA server password

--ipadomain (-o)

IPA server domain (optional). Will be based on the appliance domain name if not specified.

--iparealm (-l)

IPA server realm (optional). Will be based on the domain name of the ipaserver if not specified.

--uninstall-ipa (-u)

uninstall IPA client

  • In order to configure authentication through an IPA server, in addition to using Configure External Authentication (httpd) in the appliance_console, external authentication can be optionally configured via the appliance_console_cli (command-line interface).

  • Specifying --host will update the hostname of the appliance. If this step was already performed via the appliance_console and the necessary updates made to /etc/hosts if DNS is not properly configured, the --host option can be omitted.

Table 4. Certificate Options

Option

Description

--ca (-c)

CA name used for certmonger (default: ipa)

--postgres-client-cert (-g)

install certs for postgres client

--postgres-server-cert

install certs for postgres server

--http-cert

install certs for http server (to create certs/httpd* values for a unique key)

--extauth-opts (-x)

external authentication options

The certificate options augment the functionality of the certmonger tool and enable creating a certificate signing request (CSR), and specifying certmonger the directories to store the keys.

Table 5. Other Options

Option

Description

--logdisk (-l)

log disk path

--tmpdisk

initialize the given device for temp storage (volume mounted at /var/www/miq_tmp)

--verbose (-v)

print more debugging info

Example Usage
$ ssh root@appliance.test.company.com

To create a new database locally on the server using /dev/sdb:

# appliance_console_cli --internal --dbdisk /dev/sdb --region 0 --password smartvm

To copy the v2_key from a host some.example.com to local machine:

# appliance_console_cli --fetch-key some.example.com --sshlogin root --sshpassword smartvm

You could combine the two to join a region where db.example.com is the appliance hosting the database:

# appliance_console_cli --fetch-key db.example.com --sshlogin root --sshpassword smartvm --hostname db.example.com --password mydatabasepassword

To configure external authentication:

# appliance_console_cli --host appliance.test.company.com
                        --ipaserver ipaserver.test.company.com
                        --ipadomain test.company.com
                        --iparealm TEST.COMPANY.COM
                        --ipaprincipal admin
                        --ipapassword smartvm1

To uninstall external authentication:

# appliance_console_cli  --uninstall-ipa