Install and configure for Ubuntu¶
This section describes how to install and configure the DNS service for Ubuntu 16.04 (LTS).
Prerequisites¶
Before you install and configure the DNS service, you must create service credentials and API endpoints.
Source the
admincredentials to gain access to admin-only CLI commands:$ source admin-openrc
To create the service credentials, complete these steps:
Create the
designateuser:$ openstack user create --domain default --password-prompt designate
Add the
adminrole to thedesignateuser:$ openstack role add --project service --user designate admin
Create the designate service entities:
$ openstack service create --name designate --description "DNS" dns
Create the DNS service API endpoint:
$ openstack endpoint create --region RegionOne \ dns public http://controller:9001/
Install and configure components¶
Note
Default configuration files vary by distribution. You might need
to add these sections and options rather than modifying existing
sections and options. Also, an ellipsis (...) in the configuration
snippets indicates potential default configuration options that you
should retain.
Note
Architecture Overview
This guide uses separate IP addresses to illustrate Designate’s distributed architecture:
192.0.2.1 - Controller node running Designate services (designate-api, designate-central, designate-worker, designate-mdns)
192.0.2.2 - BIND9 DNS server
This separation shows how the components communicate and allows for deployment across multiple hosts. The configuration can be adapted for all-in-one deployments or more complex multi-server setups. Replace these documentation addresses with the addresses of your hosts. Run the BIND9 installation and configuration steps on the DNS server, and the Designate steps on the controller.
Install the packages:
# apt-get install designate
Create a
designatedatabase that is accessible by thedesignateuser. ReplaceDESIGNATE_DBPASSwith a suitable password:# mysql mysql> CREATE DATABASE designate CHARACTER SET utf8 COLLATE utf8_general_ci; mysql> GRANT ALL PRIVILEGES ON designate.* TO 'designate'@'localhost' \ IDENTIFIED BY 'DESIGNATE_DBPASS'; mysql> GRANT ALL PRIVILEGES ON designate.* TO 'designate'@'%' \ IDENTIFIED BY 'DESIGNATE_DBPASS';
Install the BIND9 packages:
# apt-get install bind9 bind9utils bind9-doc
Create an RNDC Key:
# mkdir -p /etc/designate # rndc-confgen -a -k designate -c /etc/designate/rndc.key -r /dev/urandom
Configure AppArmor to allow BIND9 to read the rndc key:
# echo "/etc/designate/rndc.key r," | sudo tee -a /etc/apparmor.d/local/usr.sbin.named # sudo systemctl reload apparmor
Note
The default AppArmor profile for BIND9 on Ubuntu (
/etc/apparmor.d/usr.sbin.named) includes read access to/etc/bind/** r,but does not include/etc/designate/. The above configuration adds the necessary permission for BIND9 to read the rndc key from/etc/designate/.Make RNDC available to the Designate worker on the controller:
# apt-get install bind9utils
If BIND9 runs on a separate host, securely copy its
/etc/designate/rndc.keyto the same path on the controller. The key must contain the same secret on both hosts. Ensure that BIND9 can read the key on the DNS server and thedesignateuser can read it on the controller, while other users cannot. The worker runsrndclocally to control the remote BIND9 server.Add the following options in the
/etc/bind/named.conf.optionsfile:Note
This example assumes the controller node (running Designate services) is at
192.0.2.1and the BIND9 DNS server is at192.0.2.2.... include "/etc/designate/rndc.key"; options { ... allow-new-zones yes; request-ixfr no; listen-on port 53 { 192.0.2.2; }; recursion no; allow-query { any; }; }; controls { inet 192.0.2.2 port 953 allow { 192.0.2.1; } keys { "designate"; }; };
allow-querypermits clients to query this authoritative DNS server. The RNDCcontrolsblock remains restricted to the controller.Restart the DNS service:
# systemctl restart bind9.service
Edit the
/etc/designate/designate.conffile and complete the following actions:In the
[service:api]section, configureauth_strategy:[service:api] listen = 0.0.0.0:9001 auth_strategy = keystone enable_api_v2 = True enable_api_admin = True enable_host_header = True enabled_extensions_admin = quotas, reports
In the
[keystone_authtoken]section, configure the following options:[keystone_authtoken] auth_type = password username = designate password = DESIGNATE_PASS project_name = service project_domain_name = Default user_domain_name = Default www_authenticate_uri = http://controller:5000/ auth_url = http://controller:5000/ memcached_servers = controller:11211
Replace
DESIGNATE_PASSwith the password you chose for thedesignateuser in the Identity service.In the
[DEFAULT]section, configureRabbitMQmessage queue access:[DEFAULT] # ... transport_url = rabbit://openstack:RABBIT_PASS@controller:5672/
Replace
RABBIT_PASSwith the password you chose for theopenstackaccount in RabbitMQ.In the
[storage:sqlalchemy]section, configure database access:[storage:sqlalchemy] connection = mysql+pymysql://designate:DESIGNATE_DBPASS@controller/designate
Replace
DESIGNATE_DBPASSwith the password you chose for thedesignatedatabase.Populate the designate database
# su -s /bin/sh -c "designate-manage database sync" designate
Start the designate central service and configure it to start when the system boots:
# systemctl start designate-central # systemctl enable designate-central
Note
The Designate API is served via WSGI using Apache or nginx. Configure your web server to serve the Designate WSGI application. See the DevStack configuration for reference examples.
Create a pools.yaml file in
/etc/designate/pools.yamlwith the following contents:Note
This configuration defines how Designate communicates with your DNS servers:
masters (192.0.2.1:5354): designate-mdns service from which BIND requests zone transfers
nameservers (192.0.2.2:53): BIND server that Designate queries to verify zone propagation
targets/options (192.0.2.2): BIND server that receives rndc commands from designate-worker
- name: default # The name is immutable. There will be no option to change the name after # creation and the only way will to change it will be to delete it # (and all zones associated with it) and recreate it. description: Default Pool attributes: {} # List out the NS records for zones hosted within this pool # This should be a record that is created outside of designate, that # points to the public IP of the BIND DNS server. ns_records: - hostname: ns1-1.example.org. priority: 1 # List out the nameservers for this pool. These are the actual BIND servers. # We use these to verify changes have propagated to all nameservers. nameservers: - host: 192.0.2.2 port: 53 # List out the targets for this pool. For BIND there will be one # entry for each BIND server, as we have to run rndc command on each server targets: - type: bind9 description: BIND9 Server 1 # List out the designate-mdns servers from which BIND servers should # request zone transfers (AXFRs) from. # This should be the IP of the controller node. # If you have multiple controllers you can add multiple masters # by running designate-mdns on them, and adding them here. masters: - host: 192.0.2.1 port: 5354 # BIND Configuration options options: host: 192.0.2.2 port: 53 rndc_host: 192.0.2.2 rndc_port: 953 rndc_key_file: /etc/designate/rndc.key
Update the pools:
# su -s /bin/sh -c "designate-manage pool update" designate
Install Designate Worker, producer and mini-dns
# apt install designate-worker designate-producer designate-mdns
Start the designate and mDNS services and configure them to start when the system boots:
# systemctl start designate-worker designate-producer designate-mdns # systemctl enable designate-worker designate-producer designate-mdns