Translated using DeepL

Machine-translated page for increased accessibility for English questioners.

Stratus.FI logo

Stratus.FI is a private cloud for users in Finland, built on OpenNebula software.

It can be used as an environment for experimentation and quick testing, but also for the production use of software which, for various reasons, cannot be installed directly on servers managed by CVT FI (such as Anxur or Aisa). We also provide support for its large-scale use for teaching purposes.

Upon request to, a group of users can also be created in Stratus.FI, which we can populate manually or synchronise with a group in the Faculty Administration (see the groups in GitLab for some rough inspiration). This group can then act as the owner group for machines or other resources.

Contents


Quotas and usage policies

Our aim is to enable users to utilise a larger amount of computing resources on a short-term basis (up to approximately 10 virtual machines). This will give users the opportunity to try out, for example, distributed applications. Quotas for system resources are therefore set to accommodate this type of usage. Detailed information on quotas can be found in the web interface under User Settings in the Quotas section, or in the Faculty Administration application under ‘Overview of personal information’.

Please be considerate of other users: the current hardware does not have the capacity to allow every FI user to continuously utilise all resources up to the limit of their quota at any one time. The set quotas therefore do not apply to virtual machines running continuously. If we detect virtual machines running for longer than a day, or for a few days at most, we will shut down these machines and subsequently delete their disks.

If you require a test or production virtual machine running for a longer period, a short-term increase in computing resources beyond the limit, or are considering using Stratus.FI for teaching purposes, please contact the system administrator at unix@fi.muni.cz .

When using virtual machines, please bear in mind that the Rules of Operation also apply here, in particular the prohibition on running publicly accessible network services without prior approval from the head of CVT FI.

VCPU vs CPU: When allocating resources to a virtual machine, two parameters, amongst others, are set: VCPU and CPU. The integer VCPU parameter indicates how many processors the virtual machine will see, i.e. across how many cores of the host computer it will be able to distribute its workload. The actual CPU parameter is less important – it is used to indicate roughly how much computing capacity this VM will occupy on average over the long term. In short: if you only need parallel processing power intermittently, set only the VCPU. For more on this and the RUNNING quota options, see also the ‘Did You Know?’ section on our blog.

If you are experiencing quota-exceedance errors but are not actually utilising the resources, please contact us at. Unfortunately, OpenNebula does not handle quota tracking and utilisation reliably, and it is sometimes necessary to recalculate actual quota usage.


Log in

The Stratus.FI cloud web interface can be found at the following URL:

https://stratus.fi.muni.cz/

Log in to the web interface using your faculty login and password (find out more about your faculty account and changing your password here).


Cloud versus User view

The Stratus.FI web interface is available to users in two versions: the simpler Cloud View and the more complex User View, which has more controls. This guide assumes that the user is using the User View. You can switch between them by clicking on the U or C icon in the left-hand sidebar.


Configuring the user’s context

Pre-installed virtual machine images are configured to retrieve certain information from the user’s settings, such as an SSH key. It is therefore necessary to set these parameters before actually creating a virtual machine.

SSH key for the root account

If you do not already have one, create an SSH key, for example on Aise, using the command:

ssh-keygen -t ed25519

The private key will be saved to the file `$HOME/.ssh/id_ed25519 ` and the public key to the file `id_ed25519.pub`. When creating the key, you can specifya passphrase, which will be required every time you use the SSH key.

On the main page of the web interface, click on the icon with a letter in the bottom left-hand menu (this will vary depending on your login), then click on ‘Profile Settings’. In the user settings, click on the ‘Security’ section in the left-hand column; in the ‘SSH key’ section, locate the ‘SSH public key’ field, then click on the pencil icon on the right-hand side of the field and copy the public key – the contents of the file ‘id_ed25519.pub ’ – into the form field using your mouse. Confirm by pressing the Enter key.


I want a pre-installed virtual machine

Use the following procedure if you need to test something on a machine that is already fully installed (run or compile your own version of some software, for example) and do not want to waste time installing and configuring the operating system.

Configure your user context as described in the previous chapter.

Open the Stratus.FI homepage (from any other Stratus.FI page, click on ‘Instances → VMs’ in the top left-hand drop-down panel).

In the top right-hand corner of the page, click the blue ‘+ Create VM’ button.

Choose from the list of pre-installed operating systems (such as AlmaLinux, Fedora or Debian) and click on your chosen system.

Note: Templates with ‘[CVTFI] ’ in their name, owned by theoneadminaccount, are templates created by us; they are intended for users and should have contextualisation packages installed, which means they should have a working network and it should be possible to log in to them as root via SSH using a key from the user’s context. So, if you encounter any issues with a template marked in this way, please do not hesitate to contact us and we will try to resolve it with you.

Note: If this is a production virtual machine, select the ‘Instantiate as persistent’ option (see ‘Creating disks’ for more details). We also strongly recommend using a distribution with long-term support (e.g. AlmaLinux or Debian).

In the middle section of the page, enter a name for the virtual machine you are creating (for example, Test AlmaLinux); if applicable, tick the ‘Instantiate as persistent’ box below the field for entering the machine name, and click the blue ‘Next’ button in the bottom right-hand corner.

On the right, click the blue ‘Finish’ button.

Wait until a green rectangle labelled ‘Running’ appears next to the name of the virtual machine you have just created, replacing the orange one (you can refresh the view using the icon showing two arrows in a circle in the top right-hand corner).

Once the virtual machine is active, you can, from within the FI internal network (for example, via Aisa, Anxur, Wi-Fi or the faculty VPN; see also Access to the FI network) to, for example, try logging in via SSH to the IP address displayed for the virtual machine you have created (if the template uses SSH contextualisation, it will have an SSH server and an IP address). To access the machine’s console, click on it and then click Console → VNC at the top.

Note: For the first login to [CVTFI] instances of Unix OS templates, you must use SSH or change the machine’s configuration as described in the section ‘First login using a password’. When you click on your VM, you will see the ‘IP’ entry in the ‘Info’ tab. To log in as root , use: ssh root@IP. You can then easily set a root password (e.g. using: sudo passwd root) and use VNC for subsequent logins.

For newly instantiated machines, we recommend updating the packages, particularly if you plan to use the machine long-term, and restarting the machine to ensure the updates take full effect.

Newly created virtual machines are assigned a NAT-restricted private IPv4 address and a public IPv6 address (but without internet access enabled). You can read more about the technical solution on our blog on the ISe portal.

If you would like to use such a virtual machine on a more permanent basis and require a larger disk, it is possible to increase the size, but the disk must be attached to a running VM for this operation (you can increase the size in the Storage tab).

Configuring parameters for physical CPUs

As mentioned in the CPU and VCPU section, there are two different attributes for CPU utilisation limits. Both of these limits are initially set to the same value, based on the value of the VCPU template parameter. To conserve resources and your quota, we recommend reducing the CPU limit for individual VMs:
  • In the left-hand panel, select Instances → VMs.
  • Select your newly instantiated VM from the VM menu.
  • Click through to the Info tab.
  • In the central panel, locate the Capacity section and click the pencil icon to the right of the section heading.
  • Change the CPU setting to your chosen value (a value of 0.2 should be sufficient for most VMs).
  • Click the blue ‘Continue’ button at the bottom right.

First login using a password

Note: This procedure applies only to Unix VMs.

Encrypted password for the root account

Create an encrypted version of the password for the virtual machine, for example by running the command `openssl passwd -1 | base64 ` on Aise or another Linux distribution:

xlogin@aisa$ openssl passwd -1 | base64
Password: correct horse battery staple
Retype password: correct horse battery staple
JDEkeGp6N...QMQo=
xlogin@aisa$

If you wish to access the VM via VNC, you will need to set up access:

  • In the left-hand panel, select Instances → VMs.
  • Click on your VM.
  • At the top, click on VM State, select Power off from the menu, and confirm by clicking the blue Power off button.
  • From the tabs under the top menu, select ‘Configuration’.
  • Click on Update Configuration (under the tabs menu).
  • In the new window that opens, select the Context tab.
  • Scroll down and click on ‘Context Custom Variables’ in the bottom-left corner.
  • In the empty field on the left, enter CRYPTED_PASSWORD_BASE64 and in the field on the right, enter the encrypted form (JDEkeGp6N...QMQo=) of your password, which you generated in the previous step.
  • Click on [+] at the end of the row you are editing.
  • Click on the blue Continue button in the bottom right-hand corner.
  • Start the VM by selecting VM State → Resume in the top right-hand corner.

Production virtual machines

Production virtual machines are generally subject to higher demands:

  • The operation of a production virtual machine is subject to the consent of a member of staff or a PhD student at the Faculty of Informatics.
  • VM configuration – please consider whether it is appropriate or advisable to allow the VM configuration to be inherited from the virtualisation settings, particularly regarding the password and SSH key.
  • Monitoring – responsibility for operation and monitoring lies with the machine owner, but upon request we can provide monitoring via our Nagios.
  • Central log collection – configure logs to be sent to the central syslog.
  • IPv6 – we strongly prefer that the machine also operates over IPv6 and has an IPv6 address in DNS.
  • Is a public IPv4 address necessary? – Is it really necessary to have a public IPv4 address? If the machine will only communicate within the FI network, or if it is mainly for hostname assignment, we will allocate a private IPv4 address.
  • Correct HTTPS configuration – see our guide.
  • Updates – the machine must be kept up to date. We recommend choosing the distribution you run (LTS) accordingly.

Contents of the production VM request

  • VM name and ID – the name and number of the virtual machine in Stratus.FI.
  • Machine hostname – the production machine will be assigned a name within the fi.muni.cz domain: please specify your preference (in this case, state it in the subject line); otherwise, we will assign one.
  • Services running – which ports you wish to allow on the faculty firewall (UDP/TCP? From the entire internet, only from MU, only from FI?).
  • Procedure for changing the IP address – to assign a ‘production’ IP address, unix@fi must replace the virtual machine’s network interfaces. This will result in an outage and a change to the VM’s network configuration. Please let us know if this step needs to be coordinated in any way, or whether the switchover can take place at any time.

I want to install my own operating system

Creating disks

For your virtual machine, you will need installation media (a CD-ROM image), a system disk and, if required, a volatile disk for temporary data, such as swap space. You can view the available disks by clicking on Storage → Images in the left-hand menu.

If you cannot find the installation media for your chosen operating system amongst the available disks, you can create one:

  • In the left-hand menu, select Storage → Images,
  • click on + Create Image in the top right-hand corner,
  • enter the disc name (for example, CentOS 7.1511 netinst.iso) and, if desired, a description,
  • and select Read-only CD-ROM as the type.
  • From the drop-down menu below the ‘Type’ field, select ‘Upload’ and upload the ISO image from your computer,
  • click the blue ‘Next’ button,
  • select ‘cephds’ as thedatastore,
  • click the blue ‘Next’ button,
  • click the blue ‘Next’ button again,
  • click the blue ‘Finish’ button.

The newly created disk should appear in the list of available disks. To save disk space, make the ISO image you have mounted available to other users where possible: click on the relevant entry in the list of disks and, in the access rights section on the right-hand side of the page, add the ‘Use’ permission for both ‘Group ’ and ‘Other’.

Create the system disk in a similar way. On the Storage → Images page, click on + Create Image, enter a disk name (for example, MyTest) and, if desired, a description. Select ‘Operating System image’ as the type. Important: tick the ‘Make Persistent’ checkbox . (Non-persistent image: instances created from this image use a copy-on-write copy of the image. When the VM is terminated, any changes made are lost. Persistent image: can only be used by a single VM; changes made are retained even after the VM is terminated.) Next, in the field below ‘Type’, select ‘Empty disk image ’ and enter the size. On the next page, select ‘cephds’ as the storage. Click through the remaining pages and complete the action by clicking ‘Finish’.

Virtual machine template

Stratus.FI (OpenNebula) uses templates to define what a virtual machine should look like. Templates are primarily intended for situations where you need to efficiently create a large number of identical virtual machines, for example for load balancing. However, every virtual machine must have a template, even if we know in advance that it will only ever run in a single instance.

In the left-hand menu, select Templates → VM Templates to view a list of available templates (all your own and public ones). Click the blue ‘+ Create VM Template’ button in the top right-hand corner to create a new template. Leave the ‘Hypervisor’ setting as ‘KVM’. Enter a name for the template and the default memory size. Next, scroll down and set the ‘Virtual CPU’ option to 1. ‘ ’ Click the blue ‘Next’ button in the bottom right-hand corner.

Next, click on the ‘Storage’ tab. Click ‘Attach disk’ and select ‘Image’. Select the disk you created earlier. Click the blue ‘Next’, then click the blue ‘Finish’. Add the disk containing the operating system ISO image in the same way. You can also add a ‘Volatile’ disk in a similar manner. After clicking ‘Attach disk ’, select ‘Volatile’. You can choose a type such as ‘swap’. This disk is not a standalone image; it is always recreated when the template is instantiated. One suitable use case is as swap space. If you are installing Windows, you may also need to attach the Virtio Windows drivers.

On the second tab, Network, you configure the virtual machine’s network interfaces. Click Attach NIC; in the Select a network section, select 503-usrpriv; do not change the rest of the network settings.

The third tab, ‘OS & CPU’, controls, amongst other things, the boot order of the disks. To install the operating system from a CD-ROM image, select this image first (in the ‘Boot order’ section, tick the box for booting from DISK1 and drag this disk to the top of the list). Then tick the empty disk you have created (DISK0) and place it in the second position below DISK1.

You do not need to configure anything else on the other tabs at this stage; simply click the blue ‘Next’ button, then click ‘Finish’.

Start the virtual machine

Using the template you have created, you can create (instance) a virtual machine. Select the relevant template from the list by clicking on its row, then click on ( ▷ ) at the top of the template’s details page. Here, you can still change certain parameters for a specific instance; this is mainly used when customising ready-made, pre-installed images and templates. Simply click the blue ‘Next’ button, then click ‘Finish’.

The newly created virtual machine is visible in the list of virtual machines: Instances → VMs in the left-hand menu. The assigned network addresses are also shown here. When installing a new operating system, set up the network statically; copy this information into the installer. For production virtual machines, it is better to use contextualisation packages, which configure the system automatically, such as addon-context-linux and addon-context-windows.

Don’t forget to set a limit on the physical CPUs.

You can access the virtual machine’s console via Console → VNC from the page showing your virtual machine’s details. Here you can continue with the system installation.

After installation

Once the installation is complete, you simply need to enable booting from the disk. Shut down the installed virtual machine (click the ‘VM State’ button at the top of the virtual machine’s details page, then select ‘Undeploy’). Next, select the Configuration tab at the top of the page, click Update Configuration and change the boot order ( DISK0 should be first if you followed the instructions). Save the changes by clicking the blue Continue button at the top of the page. You can then start the virtual machine by clicking the blue ‘VM State’ → ‘Resume’ button. Alternatively, you can achieve a similar result by completely deleting the virtual machine (the persistent disk remains), modifying the template, and creating a new instance.

Useful configuration

Finally, we recommend checking the list of tips for installing a machine on the FI network. It contains useful advice, both general in nature and specific to utilising certain services available on the faculty network.


XML-RPC API (Terraform, etc.)

More advanced users can also make use ofthe XML-RPC API, provided by the OpenNebula software. It is accessible from within the FI network (e.g. from the Aisa server) viahttps://stratus.fi.muni.cz:2634/. Please authenticate using your faculty login details.

This API is supported in several programming languages (see the link above or see Python) or, for example, in the Terraform tool. A minimalist example for the Python modulepyone:


import pyone
from pprint import pprint

one = pyone.OneServer("https://stratus.fi.muni.cz:2634/RPC2", session = "filogin:fipasswd")
vminfo = one.vm.info(1234) # some virtual machine ID
pprint(vars(vminfo))

Hardware

Stratus.FI consists of three monitoring (control) nodes and just under twenty host nodes, which also provide storage via the distributed Ceph system. The nodes run the AlmaLinux operating system.

The guest nodes span several generations. Example hardware specifications:

  • Gigabyte chassis and motherboard
  • Two 128-thread AMD EPYC 7543 processors with a clock speed of 2800 MHz
  • Two 7.68 TB NVMe drives for the system and Ceph
  • Two 12 TB rotational drives for Ceph
  • Connected to the network at 10 Gbit/s full-duplex
  • 1 TiB of DDR4 RAM running at 3200 MT/s

Links