ON THIS PAGE
APM Installation
APM Installation Overview
Juniper Address Pool Manager (APM) is an automated, centralized, container-based cloud-native application that network operators and administrators use to manage IP prefix resources. APM works with managed broadband network gateways (BNGs) to monitor address pools on BNGs. When the number of free addresses drops below a set threshold, the BNG raises an alarm. The alarm triggers APM to allocate unused prefixes from its global list of prefixes and provision a subset of the prefixes to the BNG as new pools.
APM can be installed on a single geography setup or on a multiple geography setup. The installation requirements and installation process for these two types of setups are different. See the followings sections for the requirements for your APM setup:
The term BNG in this document also applies to the BNG CUPS Controller.
You can deploy APM on any hardware that meets the requirements. The following sections describe:
-
APM installation requirements
-
How to install APM
-
How to adjust APM setup parameters
APM Installation Requirements
To install APM, you need the following hardware and software requirements listed in this section.
- APM Requirements for a Single Geography Setup
- APM Requirements for a Multiple Geography Setup
- Additional Requirements
APM Requirements for a Single Geography Setup
APM installs on a single geography setup. A single geography setup consists of a multinode Kubernetes cluster. The cluster nodes may be physical or virtual machines. For availability, the cluster must have the Kubernetes control plane function running on at least three nodes and the worker function running on at least three nodes. For node economy, the Kubernetes control plane and worker functions can be combined to run on the same node (a combined node).
APM has been qualified against the single geography cluster described in Table 1.
| Category | Details |
|---|---|
|
Kubernetes cluster |
The Kubernetes cluster requires the following:
|
|
Jump host |
The jump host requires the
following:
|
|
Jump host software |
The jump host requires the following software:
|
|
Storage |
A storage class named jnpr-bbe-storage. |
|
Network load balancer address |
Up to 2 addresses, one for APMi (the service interface between the BNG and APM) and one for Management (SSH CLI access, optional) |
|
Registry storage |
Each APM release requires approximately 2 GiB of container images. |
APM Requirements for a Multiple Geography Setup
A multiple geography setup consists of two separate multinode Kubernetes clusters. The cluster nodes may be physical or virtual machines. For availability, each cluster must have the Kubernetes control plane function running on at least three nodes and the worker function running on at least three nodes. For node economy, the Kubernetes control plane and worker functions may be combined to run on the same node (combined node). Each of the two clusters is geographically separated, so that service impacting events affecting one cluster do not affect the other.
Each cluster is a workload cluster. The workload clusters provide a redundant platform on which APM runs.
For PoC installations, you cannot use the BBE cloudsetup utility to build the clusters used in a multiple geography setup. To build a PoC multiple geography setup, a separate procedure is available through support.
APM has been qualified against the multiple geography cluster described in Table 2 .
| Category | Details |
|---|---|
|
Cluster |
A multiple geography cluster consists of 2 workload clusters with each cluster consisting of at least 3 combined nodes. Note:
Make sure that the cluster and service CIDRs for each workload cluster do not overlap. The internal networks of each workload cluster are connected by a Submariner IP tunnel. The internal CIDRs must be distinct. |
|
Workload cluster |
Each workload cluster requires the following:
This specification establishes a cluster that can run APM as well as its companion applications such as BNG CUPS Controller and BBE Event Collection and Visualization simultaneously. |
|
Jump host |
The jump host requires the
following:
|
|
Jump host software |
The jump host requires the following software:
|
|
Storage |
A storage class named jnpr-bbe-storage |
|
Network load balancer addresses |
Up to 2 addresses, one for APMi (the service interface between the BNG and APM) and one for Management (SSH CLI access, optional) |
|
Registry storage |
Each APM release requires approximately 2 GiB of container images. |
In a single geography APM setup, you can make some basic assumptions about the cluster's parameters. You can use a quick start tool like BBE Cloudsetup to create a single geography APM. The construction of a production environment APM setup with multiple geographies and multiple clusters requires much more input from you to build.
Additional Requirements
The BNG is a Juniper Networks MX Series Junos OS router or a Juniper BNG CUPS Controller (BNG CUPS Controller).
We recommend the following releases:-
Junos OS Release 23.4R2-S7 or later
-
BNG CUPS Controller 26.2R2 or later
For APM, confirm that you have a juniper.net user account with permissions to download the APM software package. Download and install the APM software from a machine that will not be part of the Kubernetes cluster.
Prepare for APM Installation in a Single Geography Setup
Use the procedures in this section to install a single geography APM for the first time.
Before you begin, confirm that you have met the requirements for the APM installation.
We recommend that you use a secure connection between APM and the BNG.
Before starting the APM installation, make sure that you have the following information:
Required Information:
- Container registry details:
-
If you are using a Rancher Kubernetes Engine2 or BBE Cloudsetup created cluster:
-
External registry address
-
External registry port number (usually 5000)
-
-
If you are using a Red Hat OpenShift Container Platform cluster:
-
External registry (FQDN)
-
Internal (Docker) registry address
-
Internal (Docker) registry port number
-
-
Optional Information:
- APM initial configuration file. If a configuration file is not supplied, a basic configuration file is automatically generated.
- Storage class name for persistent volume claim (PVC) creation (default is jnpr-bbe-storage).
- PVC Size (default is 90 MiB).
- Archival configuration details. This is required if you are planning to mirror a
copy of the APM configuration to an external server.
-
Either the name of the SSH private key file or the name of the Kubernetes secret that is present in the jnpr-apm namespace containing the SSH private key.
-
The SCP URL of the server where the configuration file will be archived. An SCP URL takes the form of
scp://user-login@server-fqdn:server-port/absolute-file-path(for example,scp://user@host1.mydomain.com:30443/home/user/configs/apm).
-
- Syslog server details. This is required if you are planning to export APM logs
to an external syslog collector. Note:
If BBE Event Collection and Visualization is detected running on the target cluster, the address and port values of the ECAV deployment will be suggested as the default.
-
Syslog server address.
-
Syslog server port number.
-
-
APMi Details—You may optionally provide a specific IP address to use as the external load balancer IP address for APMi on the workload cluster. If a specific address is not provided, APM attempts to allocate an external address from the network load balancer's default pool:
-
External IP address—Enter an unused IP address from a subnet that the cluster nodes and the entities are connected to.
- Port (default is 20557)
- TLS details. You will need one of the following:
-
None (insecure)
-
Either the key and certificate files, or the name of the Kubernetes secret that is present in the jnpr-apm namespace that contains the key and certificate information.
-
-
-
Service Account Name—The name of the Kubernetes service account used to bind certain operational privileges to the mgmt microservice. If a service account name is not provided, APM creates a service account named apm-svca during rollout.
-
SSH service type—If SSH access to the mgmt microservice is specified (
ssh <ip>:<port>), you must specify whether the service should be created as a node port (NodePort) service or a load balancer (LoadBalancer) service. If LoadBalancer is selected, a MetalLB pool is created containing the supplied external IP address. The load balancer service created at rollout is assigned the external IP address from the newly created MetalLB pool. -
DBSync service type—The
apm multi-cluster statusAPM utility command collects the state to display from the DBSync microservice through a Kubernetes service. By default, a node port service is created for this purpose. If you selectLoadBalancer, you are prompted for an external IP address and a MetalLB pool is created containing the supplied external IP address. TheLoadBalancerservice created at rollout is assigned the external IP address from the newly created MetalLB pool. - Number of worker processes for the provman microservice (default is 3).
Install the APM Application (Single Geography)
You use the procedure in this section if you are installing a single geography APM.
Start APM in a Single Geography Setup
Use this procedure to configure and start APM in a single geography setup.
Prepare for APM Installation in a Multiple Geography Setup
Use the installation procedures in this section for an APM setup that consists of multiple APMs that are located in different geographical locations.
Before you begin, confirm that you meet the requirements for the APM installation (see Table 2).
Prerequisites
Before starting the APM installation, make sure that you have the following information:
For descriptions of the following information, see Table 3.
Required Information:
-
The cluster context names of the workload clusters.
For example, your context output might look like the following:
kubectl config get-contexts CURRENT NAME CLUSTER AUTHINFO NAMESPACE * workload-1 workload-1 workload-1 workload-2 workload-2 workload-2 -
Container registry details for each cluster:
Note:You must collect the following information for all the clusters.
-
External registry address
-
External registry port number (usually 5000)
-
Optional Information:
- APM initial configuration file. If a configuration file is not supplied, a basic configuration file is automatically generated.
- Storage class name for persistent volume claim (PVC) creation (default is jnpr-bbe-storage).
- PVC Size (default is 90 MiB).
- Archival configuration details. This is required if you are planning to
mirror a copy of the APM configuration to an external server.
-
Either the name of the SSH private key file or the name of the Kubernetes secret that is present in the jnpr-apm namespace containing the SSH private key.
-
The Secure Copy Protocol (SCP) URL of the server where the configuration file will be archived. An SCP URL takes the form of
scp://user-login@server-fqdn:server-port/absolute-file-path(for example,scp://user@host1.mydomain.com:30443/home/user/configs/apm).
-
- Syslog server details. This is required if you are planning to export
APM logs to an external syslog collector. Note:
If BBE Event Collection and Visualization is detected running on the target cluster, the address and port values of the ECAV deployment will be suggested as the default.
-
Syslog server address.
-
Sysylog server port number.
-
-
APMi Details—You can provide a specific IP address to use as the external load balancer IP address for the APMi on each workload cluster. If a specific address is not provided, APM attempts to allocate an external address from the network load balancer's default pool:
-
External IP address—Enter an unused IP address from a subnet that the cluster nodes and the entities are connected to.
- Port (default is 20557)
- TLS details. You will need one of the following:
-
None (insecure)
-
Either the key and certificate files, or the name of the Kubernetes secret that is present in the jnpr-apm namespace that contains the key and certificate information.
-
-
-
Inter-operator backup channel details (for multiple geography setups only)—It is recommended that you setup a backup channel over a different subnet other than the primary subnet on which the workload clusters connect (and the Submariner tunnel connects over).
-
External IP address—Enter an unused IP address from the backup subnet that the cluster nodes of each geography are connected to.
- TLS details. You will need one of the following:
-
None (insecure)
-
Either the key and certificate files, or the name of the Kubernetes secret that is present in the jnpr-apm namespace that contains the key and certificate information.
-
-
-
Service account name—The name of the Kubernetes service account used to bind certain operational privileges to the mgmt microservice. If a service account name is not provided, APM creates a service account named apm-svca during rollout.
-
DBSync service type—The
apm multi-cluster statusAPM utility command collects the state to display from the DBSync microservice through a Kubernetes service. By default, a node port service is created for this purpose. If you selectLoadBalancer, you are prompted for an external IP address and a MetalLB pool is created containing the supplied external IP address. TheLoadBalancerservice created at rollout is assigned the external IP address from the newly created MetalLB pool. - Number of worker processes for the provman microservice (default is 3).
Install the APM Application (Multiple Geography Setup)
Start APM in a Multiple Geography Setup
Use this procedure to configure and to start APM in a multiple geography setup.
