juju deploy ovn-central
Discuss this charm
Share your thoughts on this charm with the community on discourse.
The ovn-central charm provides the Northbound and Southbound OVSDB Databases
and the Open Virtual Network (OVN) central control daemon (
ovn-northd). It is
used in conjunction with either the ovn-chassis
subordinate charm or the ovn-dedicated-chassis
Note: The OVN charms are supported starting with OpenStack Train.
OVN makes use of Public Key Infrastructure (PKI) to authenticate and authorize
control plane communication. The charm therefore requires a Certificate
Authority to be present in the model as represented by the
Note: The ovn-central charm requires a minimum of three units to operate.
This charm supports the use of Juju network spaces.
By binding the
ovsdb-peer endpoints you can
influence which interface will be used for communication with consumers of the
Southbound DB, Cloud Management Systems (CMS) and cluster internal
juju deploy -n 3 --series focal \ --bind "''=oam-space ovsdb=data-space" \ ovn-central
OVN RBAC and securing the OVN services
The charm enables RBAC in the OVN Southbound database by default. The RBAC feature enforces authorization of individual chassis connecting to the database, and also restricts database operations.
In the event of an individual chassis being compromised, RBAC will make it more difficult to leverage database access for compromising other parts of the network.
The charm automatically enables the firewall and will allow traffic from its cluster peers to port 6641, 6643, 6644 and 16642. CMS clients will be allowed to talk to port 6641.
Anyone will be allowed to connect to port 6642.
Please report bugs on Launchpad.
For general questions please refer to the OpenStack Charm Guide.