Hitachi Ops Center Admin (10.8.0)
Hitachi Ops Center Admin (10.8.0)
Administrator
10.8.0
MK-99ADM000-11
October 2021
© 2019, 2021 Hitachi, Ltd. All rights reserved.
No part of this publication may be reproduced or transmitted in any form or by any means, electronic or mechanical, including copying and recording,
or stored in a database or retrieval system for commercial purposes without the express written permission of Hitachi, Ltd., or Hitachi Vantara LLC
(collectively “Hitachi”). Licensee may make copies of the Materials provided that any such copy is: (i) created as an essential step in utilization of the
Software as licensed and is used in no other manner; or (ii) used for archival purposes. Licensee may not make any other copies of the Materials.
“Materials” mean text, data, photographs, graphics, audio, video and documents.
Hitachi reserves the right to make changes to this Material at any time without notice and assumes no responsibility for its use. The Materials contain
the most current information available at the time of publication.
Some of the features described in the Materials might not be currently available. Refer to the most recent product announcement for information about
feature and product availability, or contact Hitachi Vantara LLC at [Link]
Notice: Hitachi products and services can be ordered only under the terms and conditions of the applicable Hitachi agreements. The use of Hitachi
products is governed by the terms of your agreements with Hitachi Vantara LLC.
By using this software, you agree that you are responsible for:
1. Acquiring the relevant consents as may be required under local privacy laws or otherwise from authorized employees and other individuals; and
2. Verifying that your data continues to be held, retrieved, deleted, or otherwise processed in accordance with relevant laws.
Notice on Export Controls. The technical data and technology inherent in this Document may be subject to U.S. export control laws, including the
U.S. Export Administration Act and its associated regulations, and may be subject to export or import regulations in other countries. Reader agrees to
comply strictly with all such regulations and acknowledges that Reader has the responsibility to obtain licenses to export, re-export, or import the
Document and any Compliant Products.
Hitachi and Lumada are trademarks or registered trademarks of Hitachi, Ltd., in the United States and other countries.
AIX, AS/400e, DB2, Domino, DS6000, DS8000, Enterprise Storage Server, eServer, FICON, FlashCopy, GDPS, HyperSwap, IBM, Lotus, MVS, OS/
390, PowerHA, PowerPC, RS/6000, S/390, System z9, System z10, Tivoli, z/OS, z9, z10, z13, z14, z/VM, and z/VSE are registered trademarks or
trademarks of International Business Machines Corporation.
Active Directory, ActiveX, Bing, Excel, Hyper-V, Internet Explorer, the Internet Explorer logo, Microsoft, the Microsoft Corporate Logo, MS-DOS,
Outlook, PowerPoint, SharePoint, Silverlight, SmartScreen, SQL Server, Visual Basic, Visual C++, Visual Studio, Windows, the Windows logo,
Windows Azure, Windows PowerShell, Windows Server, the Windows start button, and Windows Vista are registered trademarks or trademarks of
Microsoft Corporation. Microsoft product screen shots are reprinted with permission from Microsoft Corporation.
All other trademarks, service marks, and company names in this document or website are properties of their respective owners.
Copyright and license information for third-party and open source software used in Hitachi Vantara products can be found at https://
[Link]/en-us/company/[Link].
Preface......................................................................................................5
Intended Audience...............................................................................................5
Product version....................................................................................................5
Release notes......................................................................................................5
Document conventions........................................................................................ 5
Conventions for storage capacity values............................................................. 7
Accessing product documentation.......................................................................8
Getting help..........................................................................................................8
Comments............................................................................................................8
Contents
Hitachi Ops Center Administrator Getting Started Guide 3
Enabling SSO with the Ops Center portal...............................................37
Updating the Ops Center connection......................................................38
Setting up SSL..............................................................................................38
Setting up SSL when Ops Center Administrator is running on the
same server as Common Services......................................................... 38
Generating and installing a signed SSL certificate................................. 39
Installing a custom signed SSL certificate.............................................. 40
Changing the si token authentication time-out in Ops Center
Administrator................................................................................................ 41
Enabling and downloading audit logs...........................................................41
Changing the Docker network address........................................................ 42
Excluding directories from virus scanning.................................................... 42
Creating Ops Center Users, User Groups, and Roles................................. 42
Logging on to Ops Center Administrator........................................................... 43
Logging on when Ops Center Administrator is not available............................. 45
Contents
Hitachi Ops Center Administrator Getting Started Guide 4
Preface
Hitachi Ops Center Administrator is an infrastructure management solution that unifies
storage management solutions such as storage provisioning, data protection, and storage
management; simplifies the management of large-scale data centers by providing smarter
software services; and is extensible to provide better programmability and control.
Intended Audience
This document is intended for system administrators, Hitachi Vantara representatives, and
authorized service providers who configure and operate Virtual Storage Platform storage
systems with Hitachi Ops Center Administrator.
Readers of this document should be familiar with the following:
■ RAID storage systems and their basic functions.
■ Volume creation and management.
■ Pool creation and management.
■ Parity group creation and management.
Product version
This document revision applies to Hitachi Ops Center Administrator version 10.8.0 or later.
Release notes
Read the release notes before installing and using this product. They may contain
requirements or restrictions that are not fully described in this document or updates or
corrections to this document.
Release notes are located on Support Connect at [Link]
Documents.
Document conventions
This document uses the following typographic conventions:
Preface
Hitachi Ops Center Administrator Getting Started Guide 5
Document conventions
Convention Description
pairdisplay -g group
(For exceptions to this convention for variables, see the entry for
angle brackets.)
Status-<report-name><file-version>.csv
■ Variables in headings.
| vertical bar Indicates that you have a choice between two or more options or
arguments. Examples:
[ a | b ] indicates that you can choose a, b, or nothing.
{ a | b } indicates that you must choose either a or b.
Preface
Hitachi Ops Center Administrator Getting Started Guide 6
Conventions for storage capacity values
Logical capacity values (for example, logical device capacity, cache memory capacity) are
calculated based on the following values:
Preface
Hitachi Ops Center Administrator Getting Started Guide 7
Accessing product documentation
Getting help
The Hitachi Vantara Support Website is the destination for technical support of products and
solutions sold by Hitachi Vantara. To contact technical support, log on to the Hitachi Vantara
Support Website for contact information: [Link]
[Link].
Hitachi Vantara Community is a global online community for Hitachi Vantara customers,
partners, independent software vendors, employees, and prospects. It is the destination to
get answers, discover insights, and make connections. Join the conversation today! Go to
[Link], register, and complete your profile.
Comments
Please send us your comments on this document to [Link]@[Link].
Include the document title and number, including the revision level (for example, -07), and
refer to specific sections and paragraphs whenever possible. All comments become the
property of Hitachi Vantara LLC.
Thank you!
Preface
Hitachi Ops Center Administrator Getting Started Guide 8
Chapter 1: Hitachi Ops Center Administrator
environment
The Ops Center Administrator environment must meet minimum requirements to support
management of various storage systems, servers, and fabric switches.
Note:
■ Use the product installers
when running Hyper-V or
KVM.
■ Only VMware supports OVA
installations.
CPU 4 vCPUs
Port requirements
The following lists the port requirements for Ops Center Administrator.
80/tcp Used for accessing the Ops Center Administrator UI from Ops Center
Administrator clients.
443/tcp Used for accessing the Ops Center Administrator UI from Ops Center
Administrator clients.
161/tcp Reserved.
161/udp Reserved.
162/tcp Reserved.
162/udp Used for receiving SNMP traps from supported storage systems and file
servers.
You cannot change the settings by using Ops Center Administrator. If
products using these ports are installed on the same computer, change the
settings of those products.
In an environment with firewalls set up in the network that connects the Ops Center
Administrator server, Ops Center Administrator clients, and storage systems, you must
register ports used by Ops Center products as firewall exceptions.
Table 2 Port numbers to register as firewall exceptions between the Administrator
server and the Administrator client
Originator Destination
Originator Destination
Originator Destination
Originator Destination
Table 4 Port numbers to register as firewall exceptions between the Ops Center
Administrator client and storage systems
Originator Destination
Port
number Machine Port number Machine Remarks
any/tcp Ops Center 5443/tcp ■ VSP 5000 For VSP 5000 series
Administrator series and VSP G1x00,
client F1500, this setting is
■ VSP E series
required when running
■ VSP G1x00, the raidinf command
F1500 on the Ops Center
■ VSP G200, G/ Administrator client.
F400, G/F600,
G/F800 (SVP)
■ VSP N series
models (SVP)
Originator Destination
Port
number Machine Port number Machine Remarks
Table 5 Port numbers to register as firewall exceptions between the Ops Center
Administrator server and the Ops Center Protector server
Originator Destination
Port Port
number Machine number Machine Remarks
Table 6 Port numbers to register as firewall exceptions between the Ops Center
Administrator server and AD authentication servers
Originator Destination
Port Port
number Machine number Machine Remarks
Table 7 Port numbers to register as firewall exceptions between the Ops Center
Administrator server and fabric switches
Originator Destination
Port Port
number Machine number Machine Remarks
Table 8 Port numbers to register as firewall exceptions between the Ops Center
Administrator server and SNMP managers
Originator Destination
Port Port
number Machine number Machine Remarks
TLS
The supported version of TLS is 1.2.
Supported microcode/firmware
Ops Center Administrator supports the following:
■ VSP 5200, 5600, 5200H, 5600H with microcode version 90-08-0x or later.
■ VSP 5100, 5500, 5100H, 5500H with microcode version 90-01-4x or later.
■ VSP E990 with microcode version 93-01-0x or later.
■ VSP E590, E790, E590H, E790H with microcode version 93-03-21 or later.
■ VSP G/F350, G/F370, G/F700, G/F900 with firmware version 88-01-0x or later.
■ VSP G200, G/F400, G/F600, G/F800 with microcode version 83-04-2x or later.
■ VSP G1x00, F1500 with microcode version 80-05-2x or later.
■ VSP N series with microcode version 83-06-0x or later.
Note: After a storage system firmware/microcode upgrade, any new features are
not supported until you upgrade Ops Center Administrator.
Supported servers
You can use Hitachi Ops Center Administrator to provision storage to servers running the
following operating systems:
®
■ VMware
®
■ Windows
™
■ HP-UX
™
■ Oracle Solaris
®
■ NetBSD
®
■ TRU64 UNIX
®
■ Novell NetWare
® ®
■ IBM AIX
®
■ Linux
®
■ IRIX
Resource Scale
Storage systems 50
Servers 10,000
Note: After modifying the /etc/hosts file, run the following command to
restart the container service. For the Docker service, run:
# systemctl restart docker
For the Podman service, run:
# systemctl restart rainier
● Make sure that you have a user account with Ops Center Common Services that has
the "Application Administrator" role to run the script.
# sysctl net.ipv4.ip_forward
net.ipv4.ip_forward = 1
# sysctl [Link]-nf-call-iptables
[Link]-nf-call-iptables = 1
# firewall-cmd --reload
# firewall-cmd --reload
● Set ExecReload.
Delegate=yes
KillMode=process
● Set Restart.
Restart=on-failure
Refer to the example provided for general information about the [Link] file.
■ The available space on the server is 100 GiB (recommended). This additional capacity is
required for the installer file and container runtime requirements for image installation.
After installation is complete, the required space is reduced to 80 GiB.
■ 16 GiB RAM
Procedure
1. In the Linux environment, configure the network interface that will access Ops Center
Administrator.
Ops Center Administrator supports user interface and API access by using an IPv4
address.
2. Copy the tar file [Link] from the installation
media to any folder in the Linux environment and unzip it.
3. Navigate to the unzipped folder and run [Link].
At the prompts, enter the following:
a. Enter the username for the installer:
Enter sysadmin
e. If you want to register Ops Center Administrator with Ops Center Common
Services during installation, enter y at the prompt:
You are then prompted to enter a user name and password for Ops Center
Common Services and the name and description of the Ops Center Administrator
instance to register.
The installation may take a few minutes. At completion, messages indicate the following:
■ The application was successfully added.
■ The API is ready.
■ Any pre-existing app manager containers have been removed.
If the installation produces any warnings, they may point to the cause of the problem. Correct
any issues the installer identifies, delete any Ops Center Administrator containers and
images, and start the installation again.
To remove files, run the command:
rm -f /opt/rainier/bin/rainier-getlogs
rm -f /opt/rainier/bin/rainier-replace-jdk
To remove container images and containers that you do not manage, run these commands
with the root account (use podman instead of docker depending on your container runtime):
1. docker stop $(docker ps --format "{{.ID}} {{.Image}}" -a | grep
"rdocker:6000/" | awk '{ print $1 }')
2. docker rm -fv $(docker ps --format "{{.ID}} {{.Image}}" -a | grep
"rdocker:6000/" | awk '{ print $1 }')
3. docker rmi $(docker images --format "{{.ID}} {{.Repository}}" |
grep "rdocker:6000/" | awk '{ print $1 }')
4. docker volume rm nginx-certificates
5. docker volume rm nginx-certificates-override
6. docker volume rm nginx-confd
7. docker volume rm nginx-log
If, after powering on or running ip-change, you attempt to execute to the container:
If the Ops Center Administrator installation succeeded, but registering with Ops Center
Common Services failed, run the setupcommonservice command after the upgraded Ops
Center Administrator goes online.
Next steps
Required
■ Change the root password as described in Changing the root password immediately after
installation (on page 33).
■ Log on to Ops Center Administrator to verify the installation.
■ Generate and install a signed SSL certificate. By default, the Ops Center Administrator
installation package comes with a self-signed certificate that you can use to initially log in
to Ops Center Administrator.
Optional
■ For information on using the [Link] file, see Example [Link] file for
use with the application installer (on page 27).
■ For more information on changing the Ops Center Administrator port number, see
Modifying the Ops Center Administrator port in virtual appliance manager (on page 28).
[Unit]
Description=Docker Application Container Engine
Documentation=[Link]
BindsTo=[Link]
After=[Link] \
[Link] [Link]
Wants=[Link]
Requires=[Link]
[Service]
Type=notify
ExecStart=/usr/bin/dockerd \
--containerd=/run/containerd/[Link] \
––logopt max-size=50m --log-opt max-file=3
ExecReload=/bin/kill -s HUP $MAINPID
TimeoutSec=0
RestartSec=2
Restart=always
StartLimitBurst=3
StartLimitInterval=60s
LimitNOFILE=infinity
LimitNPROC=infinity
LimitCORE=infinity
TasksMax=infinity
Delegate=yes
KillMode=process
[Install]
WantedBy=[Link]
Procedure
1. Log in to virtual appliance manager using the IP address for your Ops Center
Administrator deployment: [Link]
The default credentials for an application installer installation are:
■ User name: sysadmin
■ Password: sysadmin
2. In the Network tab, enter the HTTPS port you want to use.
3. Click Submit.
Result
Ops Center Administrator automatically restarts. You can log in using the new URL:
[Link]
Procedure
1. From the installation media, deploy the Ops Center Administrator OVA to the ESXi host.
2. Change the VM memory size to the recommended value: 16 GiB RAM.
7. From the Virtual Appliance Manager menu, click Network to configure the network
settings.
a. If your data center is using the IP address scheme 192.168.*.*, make sure you
provide another IP range that is not currently used in your environment. This is the
specified range used by Ops Center Administrator.
b. Set the host name for the virtual machine.
c. Set DHCP to On.
d. Click Submit.
8. (Optional) From the Virtual Appliance Manager menu, click Time and add Network Time
Protocol (NTP) servers to the virtual machine.
Adding NTP servers verifies that the Ops Center Administrator servers are synchronized
with the storage system environment.
Next steps
■ Change the root password as described in Changing the root password immediately after
installation (on page 33).
■ Log in to Ops Center Administrator to verify the installation.
■ Generate and install a signed SSL certificate. By default, the Ops Center Administrator
installation package comes with a self-signed certificate that you can use for the initial log
in to Ops Center Administrator.
Procedure
1. From the installation media, deploy the Ops Center Administrator OVA to the ESXi host.
2. Change the VM memory size to the recommended value: 16 GiB RAM.
12. From the menu, click Network to configure the network settings.
a. If your data center is using the IP address scheme 192.168.*.*, make sure you
provide another IP range that is not currently used in your environment. This is the
specified range used by Ops Center Administrator.
13. (Optional) From the Virtual Appliance Manager menu, click Time and add Network Time
Protocol (NTP) servers to the virtual machine.
Adding NTP servers verifies that the Ops Center Administrator servers are synchronized
with the storage system environment.
Next steps
■ Change the root password as described in Changing the root password immediately after
installation (on page 33).
■ Log on to Ops Center Administrator and onboard a storage system.
■ Get a digitally signed SSL certificate from a trusted certificate authority (CA) by sending
the CA a certificate signing request (CSR). After you obtain the signed certificate, you can
import it to the server. By default, the Ops Center Administrator installation package
comes with a self-signed certificate that you can use to initially log on to Ops Center
Administrator.
Procedure
1. Either open an SSH connection to the VM or open the VMware console and press Alt
+F2 to reach the console.
Procedure
1. Open the Ops Center Administrator server console:
■ For VM installations, either open an SSH connection to the VM or open the VMware
console and press Alt+F2 to reach the console.
■ For physical server installations, open the command prompt.
■ For Ops Center preconfigured media or application installer installations, use the
sysadmin credentials.
■ For stand-alone preconfigured media installations, use the service credentials.
a. Enter <users> Password:
Enter the password for the user account.
Ops Center Administrator automatically restarts. Wait until the user interface is
accessible.
6. To confirm that the new value is applied to MEM USAGE of Elasticsearch, run the
following command:
Docker: docker stats
Podman: podman stats
Note: If you installed using the consolidated Ops Center OVA, Ops Center
Administrator is already registered with Common Services and you can skip this
section.
You can either set up SSO when installing or upgrading Ops Center Administrator, or you can
do it after.
■ To set up SSO during installation or upgrade, enter the required information during the
procedure. The installation or upgrade script prompts you to input the information, if
necessary.
■ To set up SSO after installation or upgrade, run the setupcommonservice command.
Refer to Registering the Ops Center Administrator server with Ops Center (on page 36)
to learn how to use the command. If the host name, IP address, or port number of the
server where Common Services is installed changes, you must register Ops Center
Administrator again.
Note: If you installed using the Ops Center OVA, Administrator is already
registered in Common Services.
Note: After modifying the /etc/hosts file, run the following command to
restart the
Docker service:
# systemctl restart docker
Podman service:
# systemctl restart rainier
● Ops Center Administrator server and the Common Services server are running.
● Ops Center Common Services server is running v10.0.0-01 or later.
● A user account exists with Common Services that has the "Application Administrator"
role to run the script.
To register Ops Center Administrator with the Hitachi Ops Center portal:
Procedure
1. Either open an SSH connection to the VM or open the VMware console and press
Alt+F2 to reach the console.
2. Log in as root.
3. Run the /opt/rainier/bin/setupcommonservice script with the following
parameters:
csUsername
The Common Services username (optional). If you do not specify the
csUsername option, you can input the Common Services username using
interactive mode.
csUri
The URL of the Common Services server (required).
applicationHostAddress
The Ops Center Administrator server host name or an IP address (required).
applicationPort
The Ops Center Administrator port number (required).
applicationName
The Ops Center Administrator name to display in the Ops Center portal
(required).
applicationDescription
A description of the Ops Center Administrator server to display in the Ops Center
portal (optional).
tlsVerify
Indicates that Ops Center Administrator must perform SSL certificate verification
when communicating with Ops Center. If set, you must select the csUriCACert
option (optional).
csUriCACert
The CA certificate file to use for certificate verification when communicating with
Ops Center. This option is mandatory if you set the tlsVerify option.
4. After the command runs successfully, Ops Center Administrator is shown in the portal.
Example
The following is an example of running the command:
Next steps
You can change the registered Ops Center Administrator server name and description in the
portal. If you want to change other properties such as host name, port number, and so on,
first remove Ops Center Administrator from the portal, and then run the script again with the
required parameters.
Note: After modifying the /etc/hosts file, run the following command to restart
the service:
Docker:
# systemctl restart docker
Podman:
# systemctl restart rainier
If you want to use an IP address instead of the host name of the Ops Center portal, do the
following on the Ops Center portal server:
Procedure
1. Log in to the server running the Ops Center portal.
2. Run the [Link] command on the server.
For details on the [Link] command, see the Hitachi Ops Center
Installation and Configuration Guide.
Result
You can now sign on to Ops Center Administrator from the Ops Center portal.
Setting up SSL
You can configure secure communications between each of the Ops Center servers and
clients. SSL certificates verify user identity and enhance security on the server. By default,
the server uses a self-signed certificate. You can get a digitally signed SSL certificate from a
trusted certificate authority (CA) by sending a certificate signing request (CSR). After you
obtain the signed certificate, you import it to the server.
Setting up SSL when Ops Center Administrator is running on the same server as
Common Services
Ops Center Administrator and the Ops Center Common Services must communicate over an
SSL connection. To use the Common Services, you must configure a secure connection in
the same way you configure secure connections with other servers. However, if Common
Services is on the same server as Ops Center Administrator, you can simplify the SSL
configuration by using the cssslsetup command. By using the cssslsetup command,
you can configure SSL communication for all Hitachi Ops Center products installed on the
same management server using a common secret key and server certificate.
For more information on the cssslsetup command and how to use it, see "Configuring SSL
communications by using the cssslsetup command" in the Hitachi Ops Center Installation and
Configuration Guide.
Procedure
1. Open the virtual machine console and log in using root credentials.
2. Note the hostname of the VM (#hostname).
3. Run the openssl command and provide the Authentication sha1 or sha256, depending
upon the required security. Give the Fully Qualified Domain Name for host name.
# openssl req -nodes -newkey rsa:2048 -sha256 -keyout [Link]
-out [Link]
The system returns the message: Generating a
2048 bit RSA private key
4. Provide the information as prompted. For some fields there is a default value. Enter
period ".", to leave a field blank.
■ Country Name (two-letter code)
■ State or Province Name (two-letter code)
■ Locality name (City)
■ Organization Name (Company)
■ Organizational Unit Name (Section or department)
■ Common Name (Your name or the server host name)
■ Email Address
5. When you receive the CSR file, send it to a certificate authority to obtain an SSL
certificate.
If you need help with this step, consult with customer support or an authorized service
provider.
6. Open a browser and enter the virtual appliance manager URL in the address bar.
For example, [Link]
7. Click Advanced.
8. Click the Certificate Settings tab.
9. Import the certificate into the server.
a. Open the signed certificate (received from the certificate authority) in a text editor.
b. Open the private key file (generated in step 2) in a text editor.
c. Copy the certificate file contents into the Certificate text box.
# cat [Link]
e. Copy the private key file contents into the Private Key text box in the virtual
appliance manager.
f. Click Submit.
Procedure
1. Log in using SSH to the Administrator server.
2. Get the [Link] file from the container:
a. Access the container by running the following command:
Docker: docker exec -it rainier-proxy-container-ip bash
Podman: podman exec -it rainier-proxy-container-ip bash
3. Navigate to the /tmp folder and run the following command to create the [Link]
file:
4. Send the [Link] file to the certification authority to get the [Link] file.
5. Open the Administrator virtual appliance manager UI.
6. From the Advanced menu, click Certificate Settings.
a. Copy the [Link] (from Step 4) content into the Certificate area.
b. Copy the [Link] content into the [Link] area.
Procedure
1. Log in to the virtual appliance manager at [Link]
■ For Ops Center preconfigured media or application installer installations, use the
sysadmin credentials.
■ For stand-alone preconfigured media installations, use the service credentials.
Procedure
1. Log into the virtual appliance manager at [Link]
■ For Ops Center preconfigured media or application installer installations, use the
sysadmin credentials.
■ For stand-alone preconfigured media installations, use the service credentials.
Procedure
1. On the Ops Center Administrator server open /etc/sysconfig/docker.
2. Change the OPTIONS expression:
OPTIONS='--selinux-enable --bip=new_network_address'
For example:
OPTIONS='--selinux-enable --bip=[Link]/24'
# systemctl daemon-reload
Configure your antivirus application to exclude the following directories from scanning:
■ /opt/rainier
■ /var/logs
■ Volume data directory for container runtime:
● Docker: /var/lib/docker/volumes
● Podman: /var/lib/containers/storage
Procedure
1. Log in to Ops Center Common Services using Security Administrator role credentials,
and click log in.
2. Click (+) to create a user.
Role-Based Access Control (RBAC) either allows or denies users (and associated user
groups) access to Ops Center Administrator based on the existing mapping between
Common Services groups and Administrator-specific user roles.
The Security window shows the mappings from Administrator groups to user roles, which
you can modify. This window is accessible only when you are logged in through SSO (in
which case the legacy Security window is not accessible). If you logged in using the
legacy login window, you cannot access this window. To open the Security page, click the
Settings icon in the top-left corner of the UI.
Note: The administrators listed do not see any group mappings made using
legacy authentication. If the administrator registered AD using legacy
authentication, those groups and users have previous permissions set. The
permission/access varies based on the login method. If AD is also registered
in Ops Center, those groups must be given new permissions.
■ Log in from the login screen of the product – If your user group has been granted
permission in the product security page, you can log in to the dashboard from the product
login screen by clicking login with {auth-server}. If you do not have the required
permission, you may not be able to see the dashboard and are sent to the product login
screen.
■ Log in using the legacy mechanism – You can log in to the existing system in the same
manner you did in previous releases.
Log in and verify that the installation is successful by accessing the Ops Center Administrator
interface from a browser.
Procedure
1. Open a web browser.
2. Enter the URL for Ops Center Administrator in the address bar:
[Link]
where:
■ ip-address is the IP address of the Ops Center Administrator server.
■ port-number is the port number of the Ops Center Administrator server. The default
port number is 443.
Procedure
1. Start a web browser.
2. Enter the URL:
■ For VSP E990 storage systems, enter [Link]
storage/9360004XXXXX/[Link] (where the model number is '936000'
and '4XXXXX' indicates the system serial number)
■ For VSP 5000 series or VSP G1x00, F1500 storage systems, enter: [Link]
address-or-host-name-of-the-SVP/sanproject/[Link]
■ For VSP G200 storage systems, enter: [Link]
of-the-SVP/dev/storage/8320004XXXXX/[Link] (where the model
number is '8320004' and '4XXXXX' indicates the system serial number)
■ For VSP G/F400, G/F600 or VSP N400, N600 storage systems, enter:
[Link]
8340004XXXXX/[Link] (where the model number is '8340004' and
'4XXXXX' indicates the system serial number)
■ For VSP G/F800, VSP N800 storage systems, enter: [Link]
host-name-of-the-SVP/dev/storage/8360004XXXXX/[Link]
(where the model number is '8360004' and '4XXXXX' indicates the system serial
number)
■ For VSP G/F350 storage systems, enter [Link]
of-the-SVP/dev/storage/8820004XXXXX/[Link] (where the model
number is '882000' and '4XXXXX' indicates the system serial number).
■ For VSP G/F370, G/F700, G/F900 storage systems, enter [Link]
or-host-name-of-the-SVP/dev/storage/8860004XXXXX/[Link]
(where the model number is '886000' and '4XXXXX' indicates the system serial
number).
3. The following actions might be required to open the login dialog box, depending on your
environment:
■ If a message indicates that the enhanced security configuration is enabled on the
computer, select In the future, do not show this message and click OK.
■ If the SVP is set to support SSL-encrypted communication and security messages
appear, make sure the certificate is correct and follow the instructions in the dialog
box.
■ If a message indicates that certain web sites are blocked, make sure you have added
the SVP to the trusted sites zone.
Result
You are successfully logged in to Device Manager - Storage Navigator.
Note: If the login process fails three times by using the same user ID, Device
Manager - Storage Navigator stops responding for one minute. This is for security
purposes and is not a system failure. Wait, and then try again.
Procedure
1. Edit the YUM configuration file:
If you need a proxy server only, without a user, add the following line to the [main]
section of the /etc/[Link] file:
PROXY=[Link]
If the proxy requires a user name and password, add the following lines to the
[Link].
proxy_username=yum-user
proxy_password=yum-user-password
Result
Your OS environment is updated.
Procedure
1. Edit the YUM configuration file:
If you need a proxy server only, without a user, add the following line to the [main]
section of the /etc/[Link].
PROXY=[Link]
If the proxy requires a user name and password, add the following lines to the
[Link] file.
proxy_username=yum-user
proxy_password=yum-user-password
cd /etc/[Link].d
mv [Link] [Link]
touch [Link]
[Link]
#
The mirror system uses the connecting IP address of the client and the
update status of each mirror to pick mirrors that are updated to and
geographically close to the client. You should use this for CentOS
updates
unless you are manually picking other mirrors.
#
If the mirrorlist= does not work for you, as a fall back you can try
the
remarked out baseurl= line instead.
#
#
[base]
name=CentOS-7.2.1511 - Base
baseurl=[Link]
gpgcheck=1
gpgkey=[Link]
#released updates
[updates]
name=CentOS-7.2.1511 - Updates
baseurl=[Link]
gpgcheck=1
gpgkey=[Link]
nslookup
Non-authoritative answer:
Name: [Link]
Address: [Link]
Name: [Link]
Address: [Link]
Result
Your container is updated.
Note: If you also want to upgrade the Docker version, upgrade Administrator first
and then upgrade Docker.
During installation, the following files are created under /tmp. Delete them if they
are no longer required:
■ Application log
■ Audit log
■ Backup file
The installation log is created under /var/logs/rainier-install.
Procedure
1. Either open an SSH connection to the VM or open the VMware console and press Alt
+F2 to reach the console.
2. Log in as root account.
3. Copy the tar file [Link] from the installation
media to any folder in the Linux environment and extract it. Navigate to the extracted
folder.
4. In the directory where the virtual appliance manager resides, run the command
sudo ./[Link]
5. Log in when prompted.
■ For Ops Center preconfigured media or application installer installations, use the
sysadmin credentials.
■ For stand-alone preconfigured media installations, use the service credentials.
Procedure
1. Choose one of the following installation methods:
■ Use the preconfigured media ISO to deploy an OVA. The OVA installation deploys a
VM with an operating system, Docker, and Ops Center Administrator.
■ Use the application installer to enable maximum control of the environment. The
installer must be deployed in a Docker-compatible or a Podman-compatible
environment that contains only the Ops Center Administrator application.
Note: If you use the json-file logging driver, set the maximum log size to
50 MiB and the maximum number of files to 5.
2. From the currently installed version, access the virtual appliance manager at:
[Link]
■ For application installer installations, use the sysadmin credentials.
■ For stand-alone preconfigured media installations, use the service credentials.
3. When the virtual appliance manager opens in the browser, click Backup to download a
backup file of the currently installed version. The file may take a few seconds to start
downloading.
Note: Ensure the virtual appliance manager log level is set to INFO before
you upgrade. If it is set it to DEBUG or TRACE, the upgrade may fail with
errors.
4. After downloading the backup file, shut down the currently installed version.
■ If you used the Ops Center Administrator installer method, delete the Ops Center
Administrator containers and images on the system before running the new installer.
Refer to Removing Ops Center Administrator (on page 64) for more information.
■ If you used the Appliance model, the VM containing Storage Advisor or Ops Center
Administrator is shut down at this time. You may want to determine a maintenance
window to do this because the Ops Center Administrator product is unavailable until
the upgrade is complete.
■ If the current version was deployed by using the application installer and if you want
to migrate to a different container runtime (for example, migrating Docker to
Podman), uninstall the old container runtime and then install the new container
runtime on the host OS.
5. Deploy the next version in the upgrade path, using the method of your choice (virtual
appliance or installer).
Follow the instructions in the Getting Started content until the product is initialized and
ready to use.
6. In the new instance of Ops Center Administrator, log in to the virtual appliance manager
by using the default credentials.
■ For application installer installations, use the sysadmin credentials.
■ For stand-alone preconfigured media installations, use the service credentials.
7. When the virtual appliance manager opens in the browser, click Restore. You are
prompted to upload the backup file that was downloaded earlier. Choose the file and
upload it to the new Ops Center Administrator instance.
The Ops Center Administrator appliance restarts. It may take up to an hour to restore
the configuration. After the appliance is running, the upgrade is complete. (Optional) If
the upgrade completed successfully, you can delete the VM containing the previous
version of Ops Center Administrator.
Note: Do not cancel the restore operation. Cancellation may corrupt the Ops
Center Administrator instance. The progress bar may indicate 100%
completion even though the operation has not completed.
8. Repeat this entire procedure for each version listed in the upgrade path until you reach
the latest version.
Overview
Onboarding a storage system in Ops Center Administrator is more than adding a storage
system to a list. You must add at least one server before you can provision volumes to the
server on the storage system.
In the following workflow, the recommended path is marked by the solid arrows. The dashed
arrows indicate the optional paths. Before a storage system is available for use in the
network, you must complete all of the tasks in the workflow.
Note: To receive storage systems alerts in Ops Center Administrator, the storage
system must be set to SNMPv3. If storage systems have SNMPv1 or SNMPv2c
settings configured, you can still manage onboarded storage systems, but alert
information for these storage systems is not shown in Ops Center Administrator.
For Ops Center Administrator to receive alerts from onboarded storage systems,
you must change the SNMP setting to SNMPv3 and add the Ops Center
Administrator server as an SNMP trap destination.
Procedure
1. On the Ops Center Administrator dashboard, click the plus sign (+) to add a storage
system.
2. Enter values for the following parameters in the Onboard Storage System window.
IP Address:
For a storage system with an SVP, enter the IP address (IPv4) of the external
service processor for the storage system you want to discover.
Note: If the storage system has a virtual SVP, you can specify the
SVP access port number following the IP address in the IP address
field. The syntax is IP-address:Port-number.
3. Click Submit.
4. (Optional) Onboard other storage systems.
Result
The Jobs tab is updated with a job called Create Storage System. If you are adding
multiple storage systems, there a job for each one.
Wait a while for Administrator to add the storage system. Refresh the Jobs tab to verify that
the storage system has been onboarded.
Next steps
■ Verify the storage system initial settings.
■ Create parity groups.
Note: Parity groups for the following storage systems are created outside of
Ops Center Administrator by a service representative:
■ VSP 5000 series
■ VSP G1x00, F1500
Procedure
1. On the Ops Center Administrator dashboard, select Fabric Switches to open the
Fabric Switches window.
2. Click the plus sign (+) to open the Add Fabric Switches window.
3. Enter the following information from the configuration of the switch you are adding:
■ Virtual Fabric ID: For Cisco switches, the VSAN ID. Not applicable to Brocade
switches.
■ Fabric Switch Type: Select Brocade or Cisco.
4. Click Submit.
Result
A job is created to add the fabric switch.
Adding servers
Add servers so you can attach volumes. You can add multiple server parameters from a file,
or add one server at a time.
Note: When you use Internet Explorer, limit the number of servers in a CSV
file to 500 servers. If the browser does not work, reduce the number of servers
and try again.
Procedure
1. On the Ops Center Administrator dashboard, click Servers. Then click the plus sign (+)
to open the Add Server window.
■ Click the plus sign (+) in the table to add a row and enter the required information for
Fibre Channel or iSCSI. You can add more servers by clicking the plus sign again.
■ (Optionally) You can use the WWN List to add/edit a server.
Next steps
Create volumes and attach them to the server.
Procedure (Docker)
1. docker stop $(docker ps --format "{{.ID}} {{.Image}}" -a | grep
"rdocker:6000/" | awk '{ print $1 }')
2. docker rm -fv $(docker ps --format "{{.ID}} {{.Image}}" -a | grep
"rdocker:6000/" | awk '{ print $1 }')
3. docker rmi $(docker images --format "{{.ID}} {{.Repository}}" |
grep "rdocker:6000/" | awk '{ print $1 }')
4. docker volume rm nginx-certificates
5. docker volume rm nginx-certificates-override
6. docker volume rm nginx-confd
7. docker volume rm nginx-log
Procedure (Podman)
1. Log in to the OS with the root user account.
2. systemctl stop rainier
3. systemctl disable rainier
4. podman rm -fv $(podman ps --format "{{.ID}} {{.Image}}" -a | grep
"rdocker:6000/" | awk '{ print $1 }') 2>/dev/null
5. podman rmi $(podman images --format "{{.ID}} {{.Repository}}" |
grep "rdocker:6000/" | awk '{ print $1 }')
6. podman volume rm nginx-certificates
7. podman volume rm nginx-certificates-override
8. podman volume rm nginx-confd
9. podman volume rm nginx-log
If you installed Ops Center Administrator with Podman, run the following commands:
1. sudo rm -rf /var/log/rainier-audit-log
2. sudo rm -rf /var/logs/rainier-elastic-store
3. sudo rm -rf /var/run/[Link]
4. sudo rm -f /etc/systemd/system/[Link]
If you have installed Ops Center Administrator with Podman, run the following commands as
well:
1. sudo rm -rf /var/log/rainier-audit-log
2. sudo rm -rf /var/logs/rainier-elastic-store
3. sudo rm -rf /var/run/[Link]
4. sudo rm -f /etc/systemd/system/[Link]
Note: For more information about removing storage systems, see the
documentation for the previous product.