Configuring Fusion Data Foundation in dynamic mode

Configure Fusion Data Foundation in dynamic mode with dynamic storage devices.

Before you begin

  • Fusion Data Foundation service is installed with device type set to Dynamic, as instructed in Installing Fusion Data Foundation. For more information about local storage devices, see Dynamic storage devices.
  • Do not use GPU nodes to configure Fusion Data Foundation, as these nodes are dedicated for AI workloads.
  • Applicable for Microsoft Azure: If you intend to use StorageClass with performance plus enabled, you must create a StorageClass with enablePerformancePlus=True and select this StorageClass during deployment.

Procedure

  1. On the Local storage page of the IBM Fusion web console, click Get started to initiate configuration of the Fusion Data Foundation service.
    It redirects you to the Create StorageSystem page in the Red Hat® OpenShift® Container Platform web console.
    Note: Ensure that you are logged in to the Red Hat OpenShift Container Platform web console as an administrator.
  2. In the Backing storage page, select the following:
    1. Select the Use an existing StorageClass option.
    2. Select the Storage Class.

      You can choose gp2-csi or gp3-csi as the storage class.

    3. Click Next.
  3. In the Advanced Settings page, you can configure the following optional items:
    • Enable Network Files System

      Automatically enable NFS for the cluster

    • Use Ceph RBD as the default StorageClass

      Sets Ceph RBD as the default StorageClass, eliminating the need to manually annotate a StorageClass.

    • Set default StorageClass for virtualization

      Marks the RBD virtualization storage class as the default for KubeVirt VM disks (PVs) after installation.

    • Use external PostgreSQL [Technology preview]

      Enables the use of an external PostgreSQL instance. This provides a high-availability solution for the Multicloud Object Gateway, where the PostgreSQL pod is a single point of failure.

      Important:

      Fusion Data Foundation ships PostgreSQL images maintained by IBM, which are used to store metadata for the Multicloud Object Gateway. This PostgreSQL usage is at the application level.

      As a result, Fusion Data Foundation does not perform database-level optimizations or in-depth insights.

      If you have well-maintained and optimized PostgreSQL instance, then it is recommended to use it. Fusion Data Foundation supports external PostgreSQL instances.

      Any PostgreSQL-related issues requiring code changes or deep technical analysis may need to be addressed upstream. This could result in longer resolution times.

      1. Provide the following connection details:

        • Username
        • Password
        • Server name and Port
        • Database name
      2. Select Enable TLS/SSL checkbox to enable encryption for the Postgres server.
    • Enable automatic backup

      Allows automatic backup for the Multicloud Object Gateway metadata database.

      1. Select the backup frequency: Daily, Weekly, or Monthly.
      2. Specify the number of backups to retain.

        Note: This option is disabled if the Use external PostgreSQL option is selected.
      3. Click Next.
  4. On the Capacity and nodes tab, do as follows:
    1. Select a value for Requested Capacity from the drop-down list.
      By default, 2 TiB is set.
      Note: After you select the initial storage capacity, cluster expansion is performed only by using the selected usable capacity (three times the raw storage).
    2. In the Select Nodes tab, select at least three available nodes.
    3. In the Configure performance tab, select one of the following resource profiles:
      Important: Before selecting a resource profile, ensure to check the current availability of resources within the cluster. Opting for a higher resource profile in a cluster with insufficient resources might lead to installation failures.
      • Lean

        Use this in a resource constrained environment with minimum resources that are lower than the recommended. This profile minimizes resource consumption by allocating fewer CPUs and less memory.

      • Balanced (default)

        Use this when recommended resources are available. This profile provides a balance between resource consumption and performance for diverse workloads.

      • Performance

        Use this in an environment with sufficient resources to get the best performance. This profile is tailored for high performance by allocating ample memory and CPUs to ensure optimal execution of demanding workloads.

      For more information about resource requirements, see Resource requirements for performance profiles.

      Note: You can configure the resource profile even after the deployment by selecting the Configure performance from the options menu in the StorageSystems tab.
    4. Optional: Select the Taint nodes checkbox to dedicate the selected nodes for Fusion Data Foundation.

      For cloud platforms with multiple availability zones, ensure that the nodes are distributed across different locations or availability zones.

      If the nodes selected do not match the Fusion Data Foundation cluster requirement of an aggregated 30 CPUs and 72 GiB of RAM, a minimal cluster is deployed. For minimum starting node requirements, see Resource requirements.

    5. Optional: Select the Enable automatic capacity scaling for your cluster checkbox.

      When automatic capacity scaling is enabled, additional raw capacity equivalent to the configured deployment size is automatically added to the cluster when the used capacity reaches 70%. This ensures your Fusion Data Foundation cluster scales seamlessly to meet demand.

      This option is disabled in lean profile mode, local mode, and external mode deployment.

      Important: Enabling automatic capacity scaling may incur additional costs for the underlying storage.

      Set the cluster expansion limit from the drop-down list. This defines the maximum capacity that the cluster can expand to in the cloud. Automatic scaling is suspended once this limit is reached.

    6. Click Next.
  5. Optional: On the Security and network tab, configure the following based on your requirement:
    1. Select Enable data encryption for block and file storage to enable encryption.
    2. Select one or both of the following Encryption level:
      • Cluster-wide encryption

        Encrypts the entire cluster (block and file).

      • StorageClass encryption

        Creates encrypted persistent volume (block only) using encryption enabled storage class.

    3. Optional: Select the Connect to an external key management service checkbox.

      This is optional for cluster-wide encryption.

      1. From the Key Management Service Provider drop-down list, either select Vault or Thales CipherTrust Manager (using KMIP).

        If you selected Vault, do to the next step. If you selected Thales CipherTrust Manager (using KMIP), do step 5.c.iii.

      2. Select either of the following Authentication Method:

        • Using Token authentication method
          1. Enter a unique Connection Name, host Address of the Vault server ('https://<hostname or ip>'), Port number, and Token.
          2. Expand Advanced Settings to enter additional settings and certificate details based on your Vault configuration:

            • Enter the Key Value secret path in Backend Path that is dedicated and unique to Fusion Data Foundation.
            • Optional: Enter TLS Server Name and Vault Enterprise Namespace.
            • Upload the respective PEM encoded certificate file to provide the CA Certificate, Client Certificate, and Client Private Key.
          3. Click Save and skip to step 5.c.iv.
        • Using Kubernetes authentication method
          1. Enter a unique Connection Name, host Address of the Vault server ('https://<hostname or ip>'), Port number, and Role name.
          2. Expand Advanced Settings to enter additional settings and certificate details based on your Vault configuration:

            • Enter the Key Value secret path in Backend Path that is dedicated and unique to Fusion Data Foundation.
            • Optional: Enter TLS Server Name, Authentication Path, and Vault Enterprise Namespace.
            • Upload the respective PEM encoded certificate file to provide the CA Certificate, Client Certificate, and Client Private Key.
          3. Click Save and skip to step 5.c.iv.
            Note: To enable key rotation for Vault KMS, run the following command:
            oc patch storagecluster ocs-storagecluster -n openshift-storage --type=json -p '[{"op": "add", "path":"/spec/encryption/keyRotation/enable", "value": true}]'
      3. To use Thales CipherTrust Manager (using KMIP) as the KMS provider, do the following steps:

        1. Enter a unique Connection Name for the Key Management service within the project.
        2. In the Address and Port sections, enter the IP of Thales CipherTrust Manager and the port where the KMIP interface is enabled. For example:
          • Address: 123.34.3.2
          • Port: 5696
        3. Upload the Client Certificate, CA certificate, and Client Private Key.
        4. If StorageClass encryption is enabled, enter the Unique Identifier to be used for encryption and decryption generated in the previous step.
        5. The TLS Server field is optional and used when there is no DNS entry for the KMIP endpoint. For example, kmip_all_<port>.ciphertrustmanager.local.
      4. Select In-transit encryption to enable in-transit encryption.
        1. Select a Network.
        2. Click Next.
  6. On the Review and create tab, review the configuration details.
    To modify any configuration settings, click Back to go back to the previous configuration page.
  7. Click Create StorageSystem.
    Note: When your deployment has five or more nodes, racks, or rooms, and when there are five or more number of failure domains present in the deployment, you can configure Ceph monitor counts based on the number of racks or zones. An alert is displayed in the notification panel or Alert Center of the Red Hat OpenShift Container Platform web console to indicate the option to increase the number of Ceph monitor counts. You can use the Configure option in the alert to configure the Ceph monitor counts. For more information, see Resolving low Ceph monitor count alert.
  8. Validate whether Fusion Data Foundation is successfully configured in dynamic mode by following the instructions that are mentioned in Verifying Fusion Data Foundation dynamic mode configuration.

What to do next