[Solved] Nova LXD + Openstack

(Sergio Morales Acuña) #1

I been tasked with job of add a dedicated fleet of nodes with Nova LXD on a already running Openstack KVM Cluster.

That scenario is nothing new and I already have Nova LXC up and running, but sadly the integration between libvirtd and LXC offer limited functionallity.
Now I’m trying Nova LXD but I’m having some issues (probably related to my limited experiencie with LXD).

The most rare, is that when I launch a instance nova-compute consume a lot of CPU, takes a lot of time and fails.

Strace shows me that nova-compute is processing an anormal amount of data (probably the image). What is the correct format in this scenario? rootfs.tar.gz? or a typical cloud image in RAW format?

Checking this site I found people with Clouds implemented using Openstack and Nova LXD. Can you share tips and configurations?

Thanks in advance.


In the end I successfully extended my Openstack cluster to support LXD along side KVM on production. Some problems where related to my poor knowledge of LXD and other where bugs still presents in the the old version of the software (in my case, the control plane was Ocata) that needed fixes and special configurations on nova-compute and pylxd.

Thanks to all.

(Stéphane Graber) #2

@ajkavanagh can you take this one?

(Sergio Morales Acuña) #3

@ajkavanagh do think can help me with tips or config references of workings clouds with NovaLXD?


(Brian Mullan) #4

You might simultaneously ask about this topic to


Just a thought.

(Alex Kavanagh) #5

Hi @Sergio_Morales_Acuna

That sounds a bit odd. To help you a bit more, please could you indicate what versions you are running of:

  • Linux (and vendor/version)
  • LXD
  • OpenStack release (or master)
  • How you install OpenStack (Ansible, Juju, Devstack, something else?)

Also, if you could attach your nova.conf for the host with the nova-lxd config, that would be great.


(Goran Miskovic) #6

@Sergio_Morales_Acuna I deployed OpenStack Rocky on Bionic using Juju bundle OpenStack on LXD and having Nova LXD as the hypervisor.

There are some caveats and pitfalls. In this type of deployment (nested containers) you have to use btrfs as storage backend. You will have to enable bluestore with ceph-osd as well. Storage pool on the Nova Compute node would not be initialised properly and you will have to manually create btrfs storage pool on the Nova Compute node.

Have in mind that you cannot run both KVM and Nova LXD on the same Nova Compute node.

Let me know if I could provide further details.

(Sergio Morales Acuña) #7


I’m Running Ubuntu 16.04 with Ocata from Cloud Archive. For this node I’m using a manual installation of the components. The rest of the cluster has Kolla-Ansible.

Do I need a special configuration on LXD? In the previous iterations I encounter some issues like HostNotFound: Unable to connect to LXD daemon on nova compute.


Here’s the configuration:

debug = True
osapi_compute_listen =
osapi_compute_listen_port = 8774
osapi_compute_workers = 5
metadata_workers = 5
metadata_listen =
metadata_listen_port = 8775
use_neutron = True
firewall_driver = nova.virt.firewall.NoopFirewallDriver
default_availability_zone = cl-stgo-1
dhcp_domain = internal.NOOOP
default_floating_pool = Santiago
block_device_allocate_retries = 300
linuxnet_interface_driver = nova.network.linux_net.NeutronLinuxBridgeInterfaceDriver
allow_resize_to_same_host = true
my_ip =
transport_url = NOOOP
compute_driver = lxd.LXDDriver

use_forwarded_for = true

workers = 5

novncproxy_host =
novncproxy_port = 6080
vncserver_listen =
vncserver_proxyclient_address =
novncproxy_base_url = NOOOP

lock_path = /var/lib/nova/tmp

api_servers =
num_retries = 1
debug = False

catalog_info = volumev2:cinderv2:internalURL
os_region_name = RegionOne

url = NOOOP:9696
metadata_proxy_shared_secret = NOOOP
service_metadata_proxy = true
auth_url = NOOOP:35357/v3
auth_type = password
project_domain_name = default
user_domain_id = default
project_name = service
username = neutron
password = NOOOP

connection = NOOOP/nova
max_pool_size = 50
max_overflow = 1000
max_retries = -1

connection = NOOOP/nova_api
max_retries = -1

backend = oslo_cache.memcache_pool
enabled = True
memcache_servers =

auth_uri = NOOOP:5000
auth_url = NOOOP:35357
auth_type = password
project_domain_id = default
user_domain_id = default
project_name = service
username = nova
password = NOOOP
memcache_security_strategy = ENCRYPT
memcache_secret_key = NOOOP
memcached_servers =

compute = auto

driver = noop

helper_command = sudo nova-rootwrap /etc/nova/rootwrap.conf privsep-helper --config-file /etc/nova/nova.conf

debug = False

api_paste_config = /etc/nova/api-paste.ini

max_attempts = 10
discover_hosts_in_cells_interval = 60

auth_type = password
auth_url = NOOOP:35357
username = placement
password = NOOOP
user_domain_name = default
project_name = service
project_domain_name = default
os_region_name = RegionOne
os_interface = internal

fixed_key = NOOOP

(Sergio Morales Acuña) #8

Can you share your LXD configuration? and, What is the correct image format? rootfs tar? Thanks!

(Alex Kavanagh) #9

So the error HostNotFound: Unable to connect to LXD daemon essentially means that the nova-lxd <-> pylxd <-> lxd daemon is not being found, and I suspect, it’s pylxd not finding the socket for the local (to the host) LXD daemon.

Please could you provide the version for

  • LXD
  • OpenStack versions (e.g. for Ocata it will be something like 15.0.x.x for nova and nova-lxd)
  • pylxd on the host (either use pip freeze or the apt python package is python-pylxd)

If you log into the host and run lxc version it’ll tell you the version of LXD installed on that host.

Also, if you could describe how LXD is configured on the host, that would be very useful.

(Sergio Morales Acuña) #10

Thanks for the answer.

I found a problem with the LXD socket and its permissions (root:root). After a quick fix Nova (pylxd) is capable of connecting to socket and is sending the glance Image correctly to the LXD deamon (lxc image list show the correct UUID).

Now I’m facing a problem where neutron-linuxbridge-agent is not creating the tap interface (the bridge is been created just fine). With LXC+Libvirt NeutronLinuxBrigeAgent is working fine so I’m doing more troubleshooting on this environment.

About the versions:
NovaLXD: 15.0.2
NovaCompute: 15.1.5
pylxd: 2.2.4
LXD: 2.0.11 (default installation. profile: nictype: bridged, parent: lxdbro, type: nic)

Now it’s look like the creation of the neutron port is my main problem.

With NovaLXD, neutron agent is still responsible of creating the port and attaching it to the bridge?

Thanks for your help.

(Sergio Morales Acuña) #11

Quick update.

I’m in the same boat of: https://lists.linuxcontainers.org/pipermail/lxc-users/2018-August/014467.html

I’m looking into it but I think the problem is related to the versions involved.


(Alex Kavanagh) #12

Hi @Sergio_Morales_Acuna

Christmas intervened in our conversation! Did you manage to sort it out? I’m still wondering what the problem might have been?

Yes, the nova lxd driver uses the standard ComputeDriver.vif_driver.plug(...) function call to plug the network in.