Wednesday, August 8, 2018

Math 1.  Mean, Sigma Notation, Standard Deviation and Variance, Percentile.

Mean

Mean is average - to find it - just sum and then divide to the count of summarized:
We want to find average days per months of the leap year:
First we find sum (add numbers):
31 + 29 + 31 + 30 + 31 + 30 + 31 + 31 + 30 + 31 + 30 + 31 = 366
We now that we added 12 numbers, now divide sum to the count of numbers:
366 / 12 = 30.5
So average months in leap year is having 30.5 days (Check: 30.5 * 12 = 366).

Find mean lowest temperature in Celsius in the 2017 year in Azerbaijan Ganja city:
Added lowest monthly temperatures:
- 2 - 1 + 2 + 7 + 12 + 17 + 20 + 19 + 15 + 10 + 4 + 0 = 103
Mean:
103 / 12 = 8.583 Celsius (Check: 8.583 * 12 = 102.996 ~ 103)

As you see we found mean of numbers which are of the same nature (days of the month in the first example and temperature in the month in the second example).

Sigma Notation

Σ this is sigma and it means - sum up what goes after sigma:

Σn - sum up all n's 
OK and where are n values, here there are:

    





This means sum n's and n's values are from n=1 to n=5, so:







Standard Deviation

Standard Deviation (STD) - is a measure of spread between numbers (how far are our numbers from the mean). 
To find STD (eg we have 5 flats in our building and have number of humans living in each flat (7,3,1,5,6) and we want to find STD):
  1. find mean: (7 + 3 + 1 + 5 + 6) / 5 = 4.4
  2. find differences: for each number - subtract the mean. This shows how far is this number from the mean and also shows if number lower or higher than mean:
    • 7 - 4.4 = 2.6
    • 3 - 4.4 =  -1.4
    • 1 - 4.4 = -3.4
    • 5 - 4.4 = 0.6
    • 6 - 4.4 = 1.6
  3. find squared differences: square each difference. Without this step the same negative and positive values (if any) will cancel each other and overall measure will be wrong:
    • 2.6 * 2.6 = 6.76
    • -1.4 * -1.4 = 1.96
    • -3.4 * -3.4 = 11.56
    • 0.6 * 0.6 = 0.36
    • 1.6 * 1.6 = 2.56
  4. find variance (mean of the squared differences):
    1. (6.76 + 1.96 + 11.56 + 0.36 + 2.56)/5 = 4.64
  5. find standard deviation: square root of variance:
    1. √4.64 =2.154065923 ~ 2.1541
  6. STD gives us a measure to think which number is normal (is between mean+STD & mean-STD), which is low (lower than mean-STD) or high (higher than mean+STD):
    • mean + STD = 4.4 + 2.1541 = 6.5541
    • mean - STD =  4.4 - 2.1541  = 2.2459
    • 2.2459 < 6.5541 < 7   => 7 is higher than normal for that building
    • 2.2459 < 3 < 6.5541   => 3 is normal for that building
    • 1 < 2.2459 < 6.5541   => 1 is lower than normal for that building
    • 2.2459 < 5 < 6.5541   => 5 is normal for that building
    • 2.2459 < 6 < 6.5541   => 6 is normal for that building

Percentile

Percentile - indicating the value below which a given percentage of data falls. Data itself is ordered form lower to the higher. So 95th percentile for men height is 187 cm (statistical measure), this means that 95% of men is lower than 187 cm and 5% of men is higher than 187 cm.

To find percentiles and corresponding values using nearest-rank method:

  1. order list of values, eg having list of number of humans living in 5 flats (7,3,1,5,6) : 
    • Ordered list: 1, 3, 5, 6, 7
    • Number of values N = 5
  2. find minimum, it will be 1st percentile: 1st is 1
  3. find maximum, it will be 100th percentile: 100th is 7
  4. to find  n-th percentile: n-th / 100 * N and then if not integer, round to the first higher number:
    • 25th = 25 / 100 * 5 = 1.25 ~ 2 
      • means 2nd number in list
      • so 25th percentile value is 3
    • 50th = 50 / 100 * 5 = 2.5 ~ 3 
      • means 3rd number in list
      • so 50th percentile value is 5
    • 75th = 75 / 100 * 5 = 3.75 ~ 4
      • means 4th number in list
      • so 75th percentile value is 6



















Tuesday, July 31, 2018

Python 1. Lambda, list and dictionary comprehensions.

Lambda 

Lambda is a small anonymous function which can accept any number of arguments but can only have one expression:

>>> g = lambda a,b,c :  a**b - c # literally this means lambda accepts a, b and c variables, and returns "a**b-c"
>>> g
<function <lambda> at 0x7fe8640b5410>
>>> g(1,2,3) # 1**2 - 3 = 1 - 3 = -2
-2
>>>

List comprehension

>>> squares = [n**2 for n in range(10)] 
>>> squares
[0, 1, 4, 9, 16, 25, 36, 49, 64, 81]
>>> squares = [ # more readable form of list comprehensions
... n**2 # like SQL SELECT
... for n in range(10) # like SQL FROM
... ]
>>> squares
[0, 1, 4, 9, 16, 25, 36, 49, 64, 81]
>>> squares = [
... n**2 # SELECT
... for n in range(10) # FROM
... if n%2 == 0 # WHERE
... ]
>>> squares
[0, 4, 16, 36, 64]
>>> type(squares)
<type 'list'>
>>> letters = [letter for idx,letter in enumerate("ABCDEFGHIJKLMNOPQRSTUVWXYZ")]
>>> letters
['A', 'B', 'C', 'D', 'E', 'F', 'G', 'H', 'I', 'J', 'K', 'L', 'M', 'N', 'O', 'P', 'Q', 'R', 'S', 'T', 'U', 'V', 'W', 'X', 'Y', 'Z']
>>> 

Dictionary comprehension

>>> test_dict = {index+1 : letter for index, letter in enumerate(letters)}
>>> test_dict
{1: 'A', 2: 'B', 3: 'C', 4: 'D', 5: 'E', 6: 'F', 7: 'G', 8: 'H', 9: 'I', 10: 'J', 11: 'K', 12: 'L', 13: 'M', 14: 'N', 15: 'O', 16: 'P', 17: 'Q', 18: 'R', 19: 'S', 20: 'T', 21: 'U', 22: 'V', 23: 'W', 24: 'X', 25: 'Y', 26: 'Z'}
>>> 

Friday, July 20, 2018

Linux 1. Using Linux screen utility.

Screen is utility allowing you to open several terminal instances inside a single terminal window connection.

To install screen:
yum install screen -y

Using screen

  1. Opening new screen session: 
    1. Create screen with default name (screen will be named <pid>.<tty>.<host>):
      1. screen
    2. Create screen with custom name (<pid>.<custom-name>), i.e. wget-download. This gives ability to distinguish between present screens by name:
      1. screen -S wget-download
  2. To view all screen options:
    1. hit and release Ctrl+A and then hit ?
  3. To detach (disconnect) from current screen (you'll see "[detached from ..]" message):
    1. hit and release Ctrl+A and then hit d
  4. To list all available screens (number left to the ".pts" is screen id). (Detached) means nobody connected, (Attached) means that somebody is currently in that screen:
    1. screen -ls
  5. To reattach (reconnect) to the needed screen:
    1. By id:
      1. screen -r 12215
    2. By custom-name:
      1. screen -r wget-download
    3. Connect to already attached screen:
      1. screen -d -r 12215
  6. To lock current screen (password of the local user will be needed):
    1. hit and release Ctrl+A and then hit x
  7. To work with nested screen (screen id remains the same but you can switch between nested screens and prompt will show: screen 0 / screen 1 etc. when switching):
    1. To create nested screen:
      1. being inside screen hit and release Ctrl+A and then hit c
    2. To switch between nested screens:
      1. being inside screen hit and release Ctrl+A and then hit n (for next nested screen) or p (for previous nested screen)
    3. To list all nested screens:
      1. being inside screen hit and release Ctrl+A and then hit " (double quote - Shift+single quote)
  8. To "kill" screen:
    1. to terminate current screen type exit
    2. to terminate any screen using it's id (scree id is system pid): 
      1. kill pid

Tuesday, July 3, 2018

ASA 1. Active/Standby Failover.

1. Small FAQ

ASA Services Module is not considered in this blog post.
Failover can be Active/Active or Active/Standby. Active/Active failover must be setup in multi-context mode (per security context) and doesn't support VPN failover. Active/Standby failover supports VPN failover but all traffic goes only through ASA in active role (load-balancing is not supported). Primary and secondary units doesn't change their types (primary or secondary), only their state/role can change (i.e. secondary unit can be in active state/role due to primary unit fail).
Units have one dedicated physical port to be used as failover control link, this links must be interconnected (back-to-back without an intermediate switch). Failover control link is used for:
  1. initial failover peer discovery and negotiation
  2. replication of the configuration from active to the standby peer
  3. unit health monitoring
Both Active/Active and Active/Standby failover can be configured in stateless (no connections states are tracked) or stateful (packets and connections states are tracked and connections are not dropped when failover is done) manner. By default failover operates in stateless manner. To support stateful failover - Stateful Link must be setup.
Active unit accepts configuration changes and places the same commands to the standby unit, no configuration changes must be performed on a standby unit. If stateful failover is configured - active ASA monitors, builds and tears down all connections. Also this info also tracked and synchronized:
  1. stateful table for UDP and TCP connections
  2. ARP table and MAC mapping table
  3. routing table
  4. certain application inspection data
  5. most VPN data structures (only some client-less VPN info remains stateless)
When Active/Standby failover is used - for a  switchover to occur automatically - the active unit must become less operational than standby unit, at least one of following must occur:

  1. one of the internal (monitored) interfaces goes down
  2. an interface expansions slot fails
  3. an IPS, CSC or CX application module fails

Health messages by default are exchanged in 1 second interval. If failover control link fails, failover becomes disabled. By default, a switchover occurs when at least one interface on the active unit or within an active failover group fails.

Failover provides very effective first-hop redundancy capabilities by allowing the MAC and IP address pair on each data interface to move between the failover peers based on which unit is active at any given time. Because all physical interface connections and their configurations are identical between the members of a failover pair, active ASA unit switchovers are completely transparent to the adjacent network devices and endpoints. When you enable failover, the IP address configured on each data interface becomes the active one. When the active unit fails, the standby peer automatically assumes ownership of these addresses upon taking over the active role and seamlessly picks up transit traffic processing.

In Active/Standby failover secondary unit in active state remains active even if primary unit becomes operationally healthy. The primary unit takes over an active role only if secondary unit becomes unhealthy or if switchover is done manually.

All configuration changes must be done on the active unit (either in Primary or Secondary state).

2. Preparation

  1. When grouping two devices in failover, the following hardware parameters must be identical:
    1. exact model number
    2. number and type of physical interfaces must be the same (also expansion modules must be the same if any)
    3. all cables must be connected appropriate to the Layer 2 on both units for unit health monitoring to be held properly
    4. all hardware or software modules and software must be the same on both units
    5. amount of RAM and system flash must be the same on both units
    6. both failover peers should run the same software image during normal operation (different images are supported during upgrade) 
    7. prior to ASA8.3(1) licence features on both units must to be the same
    8. Cisco ASA 5505, ASA 5510, and ASA 5512-X appliances must have the Security Plus license installed.
    9. The state of the Encryption-3DES-AES license must match between the units. In other words, it must be either disabled or enabled on both failover peers.
  2. Choose roles for each ASA- one ASA will be primary and the other - secondary (i.e. old ASA - primary / new ASA - secondary). 
  3. Dedicate one physical interface (the same, i.e. Gi0/3 on both) on each unit for the failover control link and connect them back-to-back without an intermediate switch.  
  4. If you plan to use stateful failover - dedicate another physical interface to be used as stateful link
  5. Choose IP addresses for the primary and secondary units, used failover subnet cannot overlap with any data interfaces (one subnet per failover control and failover state links)
  6. Choose security key to encrypt failover traffic

3. Setup

3.1 Setup with separate physical interface for Failover Link and State Link

Start failover configuration on the primary node (also consider maintenance window as interface will go down while transiting to the failover active state - it takes roughly 1 minute to go into active state):
interface GigabitEthernet0/2
 no shutdown
interface GigabitEthernet0/3
 no shutdown
failover lan unit primary 
failover lan interface FailoverControl GigabitEthernet0/2 
failover link FailoverState GigabitEthernet0/3 
failover interface ip FailoverControl 172.20.0.1 255.255.255.0 standby 172.20.0.2 
failover interface ip FailoverState 172.20.1.1 255.255.255.0 standby 172.20.1.2 
failover ipsec pre-shared-key *****
failover 
     No Active mate detected
show failover | grep host
     This host: Primary - Active
     Other host: Secondary - Not Detected

Then configure failover on standby unit:
interface GigabitEthernet0/2
 no shutdown
interface GigabitEthernet0/3
 no shutdown
failover lan unit secondary 
failover lan interface FailoverControl GigabitEthernet0/2 
failover replication http 
failover link FailoverState GigabitEthernet0/3 
failover interface ip FailoverControl 172.20.0.1 255.255.255.0 standby 172.20.0.2 
failover interface ip FailoverState 172.20.1.1 255.255.255.0 standby 172.20.1.2 
failover ipsec pre-shared-key *****
failover 
     Detected an Active mate
     Beginning configuration replication from mate. 
     End configuration replication from mate.
show failover | grep host
     This host: Secondary - Standby Ready
     Other host: Other host: Primary - Active

The failover key command enables password failover encryption. Use either a string of letters, numbers, and punctuation with 1 to 63 characters or a hexadecimal value of up to 32 digits. Only use this option when running Cisco ASA Software versions earlier than 9.1(2) or deploying stateless failover.
IPSec site-to-site tunnel is more secure approach to failover link protection, so always use it in Cisco ASA Software version 9.1(2) and later. The failover ipsec pre-shared-key command enables this method of failover encryption. You must deploy stateful failover to use this feature. When using IPSec as encryption method - this tunnel is not counted in ASA maximum supported VPN count.

3.2 Setup with 1 redundant interface for both Failover Link and State Link

If you want to use redundant interface:
On primary unit:
interface GigabitEthernet0/2
 no shutdown
interface GigabitEthernet0/3
 no shutdown
interface Redundant 1
  member-interface GigabitEthernet 0/2
  INFO: security-level and IP address are cleared on GigabitEthernet0/2
  member-interface GigabitEthernet 0/3
  INFO: security-level and IP address are cleared on GigabitEthernet0/3
failover lan unit primary 
failover lan interface FailoverLink Redundant1
INFO: Non-failover interface config is cleared on Redundant1 and its sub-interfaces
failover interface ip FailoverLink 172.20.0.1 255.255.255.0 standby 172.20.0.2
failover link FailoverLink
failover ipsec pre-shared-key *****
failover 
     No Active mate detected
show failover | grep host
     This host: Primary - Active
     Other host: Secondary - Not Detected

Then configure failover on standby unit:
interface GigabitEthernet0/2
 no shutdown
interface GigabitEthernet0/3
 no shutdown
interface Redundant 1
  member-interface GigabitEthernet 0/2
  INFO: security-level and IP address are cleared on GigabitEthernet0/2
  member-interface GigabitEthernet 0/3
  INFO: security-level and IP address are cleared on GigabitEthernet0/3
failover lan unit secondary 
failover lan interface FailoverLink Redundant1
INFO: Non-failover interface config is cleared on Redundant1 and its sub-interfaces
failover interface ip FailoverLink 172.20.0.1 255.255.255.0 standby 172.20.0.2
failover link FailoverLink
failover ipsec pre-shared-key *****
failover 
     Detected an Active mate
     Beginning configuration replication from mate.
     End configuration replication from mate.
show failover | grep host
     This host: Secondary - Standby Ready
     Other host: Other host: Primary - Active

3.3 Disabling failover monitoring for interface

You can have an interface which can't be replicated (i.e. like fiber optic coming directly from an ISP). This interfaces must be unplugged from failed ASA and then plugged into currently active ASA. To exclude interface from the failover monitoring:
asa (config)# no monitor interface interface_name_here
By default, monitoring physical interfaces is enabled and monitoring subinterfaces is disabled. You can check this via: sh run all | grep monitor-interface

If you can replicate your interface (ex. Gi0/0), then on primary node:
# conf t
# int gi0/0
# ip address 192.168.0.1 255.255.255.0 standby 192.168.0.2
To check:
find name of the gi0/0:
sh nameif | grep G.*0/0
GigabitEthernet0/0       inside                   100
Check this name in failover:
sh failover | grep inside
  Interface inside (192.168.0.1): Normal (Monitored)
  Interface inside (192.168.0.2): Normal (Monitored)

You also can use standby IP to access node in Standby state.

4. Test and operate

Use the show failover command to monitor the operational state of the failover.
You can use show failover history command to investigate failover events.

Use failover execute mate command_to_execute_remotely to execute command on the standby unit (i.e.: failover exec mate show version | grep Serial). Do not execute configuration commands on the standby unit.

Use write standby - to restore standby unit proper state after accidentally performing configuration on a standby unit, this command replaces all configuration with the copy of the configuration from the active unit.

Use the failover active command on the standby unit to transit unit to the active state.
Use the no failover active command on the currently active unit  to transit unit to the standby state.

Thursday, May 17, 2018

Cluster 24. Resizing LVM image of the Virtual Machine.

On guest:
fdisk -l /dev/vda

Resize LV to be 20GB:
lvresize -L 21474836480b /dev/agrp-c01n02_vg0/vm-test
  Size of logical volume agrp-c01n02_vg0/vm-test changed from 15.00 GiB (3840 extents) to 20.00 GiB (5120 extents).
  Logical volume agrp-c01n02_vg0/vm-test successfully resized.

Find domain ID:
virsh list
 Id    Name                           State
----------------------------------------------------
 1     vm-test                 running

Resize vda of the guest:
virsh blockresize  --path /dev/agrp-c01n02_vg0/vm-test --size 21474836480b  1
Block device '/dev/agrp-c01n02_vg0/vm-test' is resized

On guest - check that vda is resized to the needed size:
lsblk -a | grep ^vda 
vda                         252:0    0   20G  0 disk 

View last partition index (here it's 2 because of vda2) on the guest:
lsblk -a | grep vda
vda                         252:0    0   20G  0 disk 
├─vda1                      252:1    0  500M  0 part /boot
└─vda2                      252:2    0 14.5G  0 part 

Find end of the last partition (text in bold is end - 31208) on the guest:
fdisk -l

Disk /dev/vda: 21.5 GB, 21474836480 bytes
16 heads, 63 sectors/track, 41610 cylinders
Units = cylinders of 1008 * 512 = 516096 bytes
Sector size (logical/physical): 512 bytes / 512 bytes
I/O size (minimum/optimal): 512 bytes / 512 bytes
Disk identifier: 0x000a4595

   Device Boot      Start         End      Blocks   Id  System
/dev/vda1   *           3        1018      512000   83  Linux
Partition 1 does not end on cylinder boundary.
/dev/vda2            1018       31208    15215616   8e  Linux LVM


Create new partition vda3 on the guest:
fdisk /dev/vda 
input n letter # for creating new partition
input p # for primary partition 
input 3 # for new partition index
input 31208 # for "First cylinder (1-41610, default 1):"
enter # to accept "Last cylinder, +cylinders or +size{K,M,G} (31208-41610, default 41610):"
input w # to save 

View current partition table on the guest:
partx -l /dev/vda
Re-read partition table:
partx -a /dev/vda # this will give "BLKPG: Device or resource busy" for already added partition
Check that we have device nodes for /dev/sdb itself and the partitions on it:
ls /dev/vda*
/dev/vda  /dev/vda1  /dev/vda2 /dev/vda3

Create PV and verify on the guest:
pvcreate /dev/vda3
  Physical volume "/dev/vda3" successfully created
pvs
 PV         VG       Fmt  Attr PSize  PFree
  /dev/vda2  VolGroup lvm2 a--  14.51g    0 
  /dev/vda3           lvm2 ---   5.00g 5.00g
Extend VG with new PV nad verify:
vgextend VolGroup /dev/vda3
  Volume group "VolGroup" successfully extended
pvs
  PV         VG       Fmt  Attr PSize  PFree
  /dev/vda2  VolGroup lvm2 a--  14.51g    0 
  /dev/vda3  VolGroup lvm2 a--   5.00g 5.00g

Extend LV size to the all available free space on the guest:
lvextend -l +100%FREE /dev/VolGroup/lv_root 
  Size of logical volume VolGroup/lv_root changed from 13.01 GiB (3330 extents) to 18.00 GiB (4609 extents).
  Logical volume lv_root successfully resized

Verify on the guest:
lvs
  LV      VG       Attr       LSize  Pool Origin Data%  Meta%  Move Log Cpy%Sync Convert
  lv_root VolGroup -wi-ao---- 18.00g                                                    
  lv_swap VolGroup -wi-ao----  1.50g 

Resize file system on the guest:
For ext type filesystem:
resize2fs /dev/VolGroup/lv_root
resize2fs 1.41.12 (17-May-2010)
Filesystem at /dev/VolGroup/lv_root is mounted on /; on-line resizing required
old desc_blocks = 1, new_desc_blocks = 2
Performing an on-line resize of /dev/VolGroup/lv_root to 4719616 (4k) blocks.
The filesystem on /dev/VolGroup/lv_root is now 4719616 blocks long.
For xfs filesystem:
xfs_growfs /dev/VolGroup/lv_root


Verify on guest:
df -h
Filesystem                                   Size  Used Avail Use% Mounted on
/dev/mapper/VolGroup-lv_root      18G  9.3G  7.5G  56% /
tmpfs                                           939M     0  939M   0% /dev/shm
/dev/vda1                                    477M   48M  405M  11% /boot

Thursday, May 10, 2018

Cluster 23. Converting qcow2 to LVM storage.

If you want target machine to remain working while we changing it's storage (it's only recommended for VM's which are NOT having their data updated continuously - like NTP server, if your VM data is updated continuously - you MUST stop the VM and then convert VM's storage and then start VM on the new storage, otherwise you will lose data):

virsh # entry to the virsh console
list # list all running VMs
 Id    Name                           State
----------------------------------------------------
 4     rntp                           running
 5     rftp                           running
 18    agisrv                         running
 19    squid                          running
 23    cc_replica                     running
 27    nagios                         running
 29    rvoip                          running
domblklist rntp # list block-devices for given VM name
Target     Source
------------------------------------------------
vda        /var/lib/libvirt/images/rntp.qcow2
hdc        -
domblkinfo rntp vda # view size for an image (we need "Capacity")
Capacity:       16106127360
Allocation:     1576611840
Physical:       1576611840
or:
qemu-img info /var/lib/libvirt/images/rntp.qcow2 # we need "virtual size"
image: /var/lib/libvirt/images/rntp.qcow2
file format: qcow2
virtual size: 15G (16106127360 bytes)
disk size: 1.5G
cluster_size: 65536

Create LV with needed size:
lvcreate -L 16106127360b -n vm01-rntp_0 agrp-c01n01_vg0

virsh dumpxml rntp > /root/rntp.xml
Calculate md5 checksum (md5 sums only verifies/works with the file content rather than the file name):
md5sum /var/lib/libvirt/images/rntp.qcow2 > rntp.md5
md5sum /root/rntp.xml >> rntp.md5

Copy qcow2 image to the destination node:
scp root@10.10.10.2:/var/lib/libvirt/images/rntp.qcow2  /var/lib/libvirt/images/
scp root@10.10.10.2:/root/rntp.xml  /etc/libvirt/qemu/
scp root@10.10.10.2:/root/rntp.md5  /root/

Verify md5 checksum (before that change location in the rntp.md5 file):
md5sum -c rntp.md5
/root/rntp.qcow2: OK
/root/rntp.xml: OK

Copying an image to a physical device:
The diskimage will need to be in raw format.
qemu-img convert -O raw rntp.qcow2 rntp.raw
Then you just dd it onto the hard drive.
dd if=rntp.raw of=/dev/agrp-c01n01_vg0/vm01-rntp_0
Or, let qemu-img directly write onto the drive in one command:
qemu-img convert -O raw rntp.qcow2 /dev/agrp-c01n01_vg0/vm01-rntp_0

Adapting the configuration file
Old situation:

     <disk type='file' device='disk'>
      <driver name='qemu' type='qcow2' cache='none'/>
      <source file='/var/lib/libvirt/images/rntp.qcow2'/>
      <target dev='vda' bus='virtio'/>
      <alias name='virtio-disk0'/>
      <address type='pci' domain='0x0000' bus='0x00' slot='0x05' function='0x0'/>
    </disk>

New situation:

    <disk type='file' device='disk'>
      <driver name='qemu' type='raw' cache='none' io='native'/>
      <source dev='/dev/agrp-c01n01_vg0/vm01-rntp_0'/>
      <target dev='vda' bus='virtio'/>
      <alias name='virtio-disk0'/>
      <address type='pci' domain='0x0000' bus='0x00' slot='0x05' function='0x0'/>
    </disk>

After this step, you should be able to start your virtual machine again. If the machine boots successfully, you can remove the old disk file (I suggest to stop machine on the previous location and then test new VM for a week and only after that delete old image file).

If you move virtual machine from one machine to the other (both are not members of the same cluster) - use virsh define vm01-rntp.xml to create machine on the new location and then stop VM on the old location (virsh shutdown vm01-rntp) and disable VM autostart (rm /etc/libvirt/qemu/autostart/rntp.xml)

PS if you want to move virtual machine from CentOS 6 (libvirt 0.10.2) to CentOS 7 (libvirt 3.2.0) - xml file will not fit. Instead of using xml file - take any xml-dump file of virtual machine existing on CentOS 7 and replace needed xml attributes (<uuid> / <name> / <memory unit= / <currentMemory unit= / <vcpu placement= / <os> / <disk /  <interface ). 

Thursday, May 3, 2018

How many vCPU per pCPU.

virsh # nodeinfo
CPU model:           x86_64
CPU(s):              12
CPU frequency:       1200 MHz
CPU socket(s):       1
Core(s) per socket:  6
Thread(s) per core:  2
NUMA cell(s):        1
Memory size:         16741656 KiB


  • Socket - physical socket which the processor package sits in, on the motherboard
  • Processor package is what you get when you buy a single hardware processor.
  • Core - is a hardware term that describes the number of independent central processing units in a single computing component (Cores count = Sockets*Cores per socket)). vCPU count equals to the cores count
  • Thread - A Thread, or thread of execution, is a software term for the basic ordered sequence of instructions that can be passed through or processed by a single CPU core.
  • NUMA - Non-uniform memory access is a computer memory design used in multiprocessing, where the memory access time depends on the memory location relative to the processor. Under NUMA, a processor can access its own local memory faster than non-local memory (memory local to another processor or memory shared between processors). The benefits of NUMA are limited to particular workloads, notably on servers where the data is often associated strongly with certain tasks or users
  • ht Flag - Intel® Hyper-Threading Technology (Intel® HT Technology) delivers two processing threads per physical core - instructions are processed through two threads simultaneously,. Highly threaded applications can get more work done in parallel, completing tasks sooner. (also we see that Thread(s) per core equals to 2 - meaning that HT is enabled). Hyper-Threading doesn't double the performance, max performance increases are up to max 30%
  • CPU - equals Cores*Threads per core (in example case 6*2=12). vCPU count equals to CPU count

KVM uses Virtual CPU (vCPU) notion while assigning Processor CPU (pCPU) to the newly created virtual machine. vCPU is neither an OS thread nor a process.
Intel VT-x proposed a new mode methodology with two modes: VMX root mode and VMX non-root mode (VMX - Virtual Machine Extensions, this is set of CPU instructions added by Intel to their processors to support virtualization), for running host VMM (Virtual Machine Monitor=Hypervisor) and guest respectively.
Intel VT-x also contains a new structure: VMCS (Virtual Machine Control Structure - supports nested virtualization - a VM inside the VM ), which saves all information both host and guest need. VMCS is one per guest.
The guest code is running directly on CPU in VMX non-root mode. No software emulation layer for vCPU is needed. That’s why KVM has better performance, and there is no specific thread for guest.

A vCPU equates to 1 physical core, but (by default - rhel.link) when your VM attempts to process something, it can potentially run on any of the cores that happen to be available at that moment. The scheduler handles this, and the VM is not aware of it. You can assign multiple vCPUs to a VM which allows it to run concurrently across several cores. Cores are shared between all VMs as needed, so you could have a 4-core system, and 10 VMs running on it with 2 vCPUs assigned to each. VMs share all the cores in your system quite efficiently as determined by the scheduler. This is one of the main benefits of virtualization - making the most use of under-subscribed resources to power multiple OS instances.

The exact amount of CPU overcommitment a KVM host can accommodate will depend on the VMs and the applications they are running. A general guide for performance of {allocated vCPUs}:{total vCPU} from the Best Practices recommendations is:

  • 1:1 to 3:1 is no problem (the general recommendation is only using 1 vCPU per VM until you determine there is a need to add more than that. Over allocations of vCPU can cause lags in the VMs because too many are trying to use the same physical processors simultaneously. )
  • 3:1 to 5:1 may begin to cause performance degradation
  • 6:1 or greater is often going to cause a problem
So that if you will use overcommitment rate 3:1, then 12 vCPU (as in example) can be assigned as 36 vCPUs