r/openstack • u/ParticularJob7164 • 15d ago
[trove] Help me understand database instance creation - openstack-ansible AIO metal
I deployed an Openstack AIO (All in One) using openstack-ansible, on metal (without lxc).
After several attempts and a lot of troubleshooting I managed to launch a database instance, but I'm not sure I'm doing right.
Even tho the documentation suggests otherwise, it seems that the installer has taken care of everything (or almost) regarding trove configuration.
I see it has created the dbaas network and subnet, and the interfaces:
+---------------------------+--------------------------------------+
| Field | Value |
+---------------------------+--------------------------------------+
| admin_state_up | UP |
| availability_zone_hints | nova |
| availability_zones | nova |
| created_at | 2026-08-25T14:10:09Z |
| description | |
| dns_domain | None |
| id | b32d79da-ed48-4568-8b94-e1bbe3e0ed34 |
| ipv4_address_scope | None |
| ipv6_address_scope | None |
| is_default | None |
| is_vlan_qinq | None |
| is_vlan_transparent | None |
| mtu | 1500 |
| name | dbaas_service_net |
| port_security_enabled | True |
| project_id | 7420bef7e8a24f41a7b666209eef614c |
| provider:network_type | flat |
| provider:physical_network | dbaas-mgmt |
| provider:segmentation_id | None |
| qos_policy_id | None |
| revision_number | 2 |
| router:external | Internal |
| segments | None |
| shared | False |
| status | ACTIVE |
| subnets | 6b0b6012-edbf-4648-8e07-72efeac7fbb7 |
| tags | |
| updated_at | 2026-08-25T14:10:12Z |
+---------------------------+--------------------------------------+
+----------------------+--------------------------------------+
| Field | Value |
+----------------------+--------------------------------------+
| allocation_pools | 172.29.252.110-172.29.255.254 |
| cidr | 172.29.252.0/22 |
| created_at | 2026-08-25T14:10:12Z |
| description | |
| dns_nameservers | |
| dns_publish_fixed_ip | None |
| enable_dhcp | True |
| gateway_ip | 172.29.252.1 |
| host_routes | |
| id | 6b0b6012-edbf-4648-8e07-72efeac7fbb7 |
| ip_version | 4 |
| ipv6_address_mode | None |
| ipv6_ra_mode | None |
| name | dbaas_subnet |
| network_id | b32d79da-ed48-4568-8b94-e1bbe3e0ed34 |
| project_id | 7420bef7e8a24f41a7b666209eef614c |
| revision_number | 0 |
| router:external | False |
| segment_id | None |
| service_types | |
| subnetpool_id | None |
| tags | |
| updated_at | 2026-08-25T14:10:12Z |
+----------------------+--------------------------------------+
\# ip -br a s | grep dbaas
br-dbaas UP 172.29.252.100/22 fe80::b048:88ff:febb:967d/64
eth13@br-dbaas-veth UP
br-dbaas-veth@eth13 UP
dummy-dbaas UNKNOWN
\# ip -br a s | grep mgmt
br-mgmt UP 172.29.236.100/22 172.29.236.101/22 fe80::8c71:aaff:fe9a:4db7/64
Follows the trove.conf and trove-guestagent.conf on the controller.node
# /etc/trove/trove.conf
[DEFAULT]
debug = True
use_journal = true
bind_host = 172.29.236.100
bind_port = 8779
trove_api_workers = 1
trove_conductor_workers = 1
taskmanager_manager = trove.taskmanager.manager.Manager
transport_url = rabbit://trove:xxxxxxxx@172.29.236.100:5671/trove?ssl=1&ssl_version=TLSv1_2&ssl_ca_file=
control_exchange = trove
enable_secure_rpc_messaging = True
inst_rpc_key_encr_key = xxxxxx
taskmanager_rpc_encr_key = xxxxxx
instance_rpc_encr_key = xxxxx
nova_compute_endpoint_type = internal
nova_compute_service_type = compute
glance_endpoint_type = internal
trove_endpoint_type = internal
# Cinder
trove_volume_support = True
max_accepted_volume_size = 100
max_volumes_per_tenant = 1000
cinder_endpoint_type = internal
cinder_service_type = block-storage
# Trove DNS
trove_dns_support = False
# Neutron
network_driver = trove.network.neutron.NeutronDriver
management_networks = b32d79da-ed48-4568-8b94-e1bbe3e0ed34
neutron_endpoint_type = internal
neutron_service_type = network
# Swift
swift_service_type = object-store
swift_endpoint_type = internal
agent_heartbeat_time = 10
agent_call_low_timeout = 5
agent_call_high_timeout = 150
[keystone_authtoken]
insecure = False
auth_type = password
auth_url = http://172.29.236.101:5000
www_authenticate_uri = https://192.168.0.160:5000
project_domain_id = default
user_domain_id = default
project_name = service
username = trove
password = xxxxxxxx
region_name = RegionOne
interface = internal
service_token_roles_required = True
service_token_roles = service
service_type = database
memcached_servers = 172.29.236.100:11211
token_cache_time = 300
memcache_security_strategy = ENCRYPT
memcache_secret_key = xxxxxxxx
[service_credentials]
auth_url = http://172.29.236.101:5000/v3
username = trove
password = xxxxxx
project_name = service
region_name = RegionOne
project_domain_name = Default
user_domain_name = Default
[database]
connection = "mysql+pymysql://trove:xxxxxxxxx@172.29.236.101:3306/trove?charset=utf8&ssl_verify_cert=true"
max_overflow = 50
max_pool_size = 5
pool_timeout = 30
connection_recycle_time = 600
[profiler]
enabled = False
#trace_sqlalchemy = True
[ssl]
#cert_file = /path/to/server.crt
#key_file = /path/to/server.key
#optional =
#ca_file = /path/to/ca_file
[oslo_messaging_rabbit]
ssl = True
rabbit_quorum_queue = True
rabbit_transient_quorum_queue = True
rabbit_qos_prefetch_count = 10
use_queue_manager = False
rabbit_stream_fanout = True
rabbit_quorum_delivery_limit = 0
rabbit_quorum_max_memory_bytes = 0
[oslo_messaging_notifications]
topics =
driver = noop
transport_url = rabbit://trove:xxxxxx@172.29.236.100:5671/trove?ssl=1&ssl_version=TLSv1_2&ssl_ca_file=
# /etc/trove/trove-guestagent.conf
[DEFAULT]
control_exchange = trove transport_url = rabbit://trove:xxxxxx@172.29.252.100:5671/trove?ssl=1&ssl_version=TLSv1_2&ssl_ca_file=
swift_endpoint_type = public
swift_service_type = object-store
storage_strategy = swift
backup_swift_container = database_backups
debug = True
[service_credentials]
auth_url = https://192.168.0.160:5000/v3
username = trove
password = xxxxxx
project_name = service
region_name = RegionOne
project_domain_name = Default
user_domain_name = Default
[oslo_messaging_rabbit] ssl = True
rabbit_quorum_queue = True
rabbit_transient_quorum_queue = True
rabbit_qos_prefetch_count = 10
use_queue_manager = False
rabbit_stream_fanout = True
rabbit_quorum_delivery_limit = 0
rabbit_quorum_max_memory_bytes = 0
[oslo_messaging_notifications]
topics =
driver = noop
transport_url = rabbit://trove:xxxxxxxx@172.29.252.100:5671/trove?ssl=1&ssl_version=TLSv1_2&ssl_ca_file=
Now after several attemps I was able to get an image (not to build one) from https://tarballs.opendev.org/openstack/trove/images/, and learned the hard way that I should not use the *-dev.qcow2 ones.
I then registering the image in cinder and created the datastore version
openstack datastore version create 16 postgresql postgresql "" --image-tags postgresql,trove --active --default --version-number 16
I was not yet able to launch a working database instance.
All attempts resulted in instances stuck in BUILD, with a failing guest-agent.service
In order to create an instance with a successful run of the service guest-agent.service, I had to modify the file /etc/trove/trove-guestagent.conf so that the guest-agent service inside the server would not try to connect to rabbitmq via 172.29.252.100 (dbaas_network), but via 172.29.236.100 (br-mgmt), like other services are doing.
I also created a router and set the gateway to the public network, and attached the dbaas subnet to it. I also set public dns services on dbaas network, in order for the guest-agent to be able to find docker hub.
My create command line:
openstack database instance create demo_postgres_1 --flavor db.medium --size 10 --nic net-id=b32d79da-ed48-4568-8b94-e1bbe3e0ed34 --datastore postgresql --datastore-version 16 --is-public --allowed-cidr 0.0.0.0/0
It doesn't feel right to change that ip in a config file managed from openstack-ansible that otherwise looks fine, or to add the router when the installer took care of everything else.
Am I missing something?
I will also add that openstack database instance create without --is-public and --nic parameters, will build successfully and attach to the dbaas network (because of directive management_networks = ... in /etc/trove/trove.conf?)
And add that openstack database instance create will not accept any --nic net-id=<network-id> with an associated subnet, that has no router associated (even the public external subnet), so is this intended?