Single Node Install on RHEL¶
To get started installing HPE Morpheus Software on RHEL/RedHat a few prerequisite items are required.
Choose whether the appliance or your organization will manage the host firewall. See RHEL firewall behavior before the first reconfigure.
Make sure the machine is self resolvable to its own hostname.
For RHEL 7.x, the Optional RPMs repo needs to be added for Reconfigure to succeed. It does not need to be added For RHEL 8.x, as the Optional RPMs repo is now part of the appstream repo that is enabled by default in RHEL 8.x.
RHEL 7.x Amazon:
yum-config-manager --enable rhel-7-server-rhui-optional-rpmsRHEL 7.x:
yum-config-manager --enable rhel-7-server-optional-rpms
Note
For Amazon users a Redhat subscription is not required if the appropriate yum REGION repository is added instead as demonstrated above.
The RedHat Enterprise Linux server needs to be registered and activated with Redhat subscription. The server optional rpms repo needs to be enabled as well.
RHEL firewall behavior¶
By default, morpheus-ctl reconfigure runs the appliance firewall recipe. On RHEL 7 and later, the recipe stops and disables firewalld, installs the appropriate iptables services package, enables iptables, writes the appliance IPv4 rules, and links them at /etc/sysconfig/iptables. The default input policy generated by the appliance is ACCEPT. Review the resulting policy before exposing the host to an untrusted network.
To retain a customer-managed firewall such as firewalld, add the following to /etc/morpheus/morpheus.rb before the first reconfigure:
firewall['enabled'] = false
firewall['ipv4'] = false
firewall['enabled'] = false prevents the firewall recipe from running. Setting only firewall['ipv4'] = false is not sufficient to retain firewalld because the RHEL portion of the enabled recipe still manages the firewall services. After disabling appliance firewall management, configure the required rules with your organization’s firewall tooling. Use the canonical Ports and Protocols table to determine which ports apply to the deployment.
Warning
Disabling appliance firewall management does not create, validate, or preserve a customer firewall policy. Validate access from an administrative session before disconnecting, and maintain the policy through your normal operating-system configuration process. Do not rely on custom iptables changes surviving a later reconfigure or upgrade.
To check if the server has been activated please run the subscription-manager version. Subscription manager will return the version plus the python dependency version.
If the server has not been registered and activated then the subscription manager version will return the below message.
sudo subscription-manager version
server type: This system is currently not registered
subscription management server: 0.9.51.24.-1
subscription-manager: 1.10.14-7.el7 python-rhsm: 1.10.12-2.el7
When a server has been registered and activated with Redhat the subscription manager will return the below message.
sudo subscription-manager version
server type: Red Hat Subscription Management
subscription management server: 0.9.51.24-1
subscription-manager: 1.10.14-7.el7 python-rhsm: 1.10.12-2.el7
If the subscription manager re-turns the message This system is currently not registered please follow the below steps to register the server.
Tip
To register the server you will need to have sudo permissions [Member of the Wheel group] or root access to the server. You will also need your Redhat registered email address and password.
subscription-manager register
sudo subscription-manager register
Username: redhat@example.com
Password: . subscription-manager auto --attach
Note
This can take a minute to complete
sudo subscription-manager attach --auto
Installed Product Current Status: Product Name: Red Hat Enterprise Linux
Server Status: Subscribed
To check to see if the RHEL server has the Red Hat Enterprise Linux 7 Server - Optional (RPMs) repo enabled please run the following command to return the repo status.
Tip
To check the server repos you will need to have sudo permissions [Member of the Wheel group] or root access to the server.
sudo yum repolist all | grep "rhel-7-server-optional-rpms" rhel-7-server-optional-rpms/7Server/x86_64 disabled
If the repo status was returned as disabled then you will need to enable the repo using the subscription manager like below.
sudo subscription-manager repos --enable rhel-7-server-optional-rpms
Repository 'rhel-7-server-optional-rpms' is enabled for this system.
The message Repo 'rhel-7-server-optional-rpms' is enabled for this system. will appear after enabling the repo. This will confirm that the repo has been enabled.
Next simply download the relevant .rpm package for installation. This package can be acquired from morpheushub.com.
Tip
Use the wget command to directly download the package to your appliance server. i.e. wget https://downloads.morpheusdata.com/path/to/package.rpm
Next we must install the package onto the machine and configure the morpheus services:
sudo rpm -i morpheus-appliance_x.x.x-1_amd64.rpm
sudo morpheus-ctl reconfigure
Once the installation is complete the web interface will automatically start up. By default it will be resolvable at https://your_machine_name and in many cases this may not be resolvable from your browser. The url can be changed by editing /etc/morpheus/morpheus.rb and changing the value of appliance_url. After this has been changed simply run:
sudo morpheus-ctl reconfigure
sudo morpheus-ctl stop morpheus-ui
sudo morpheus-ctl start morpheus-ui
Open (or refresh) the appliance URL in your browser and wait for the UI loading screen to finish. The morpheus-ui service can take a few minutes to become available. Only if the UI does not load or the loading screen stalls, run morpheus-ctl tail morpheus-ui or inspect /var/log/morpheus/morpheus-ui/current.
There are additional install settings that can be viewed in the Additional Configuration Options section.
Once the browser is pointed to the appliance a first time setup wizard will be presented. Please follow the on screen instructions by creating the master account. From there you will be presented with the license settings page where a license can be applied for use (if a license is required you may request one or purchase one by contacting your sales representative).
More details on setting up infrastructure can be found throughout this guide.
Tip
If any issues occur it may be prudent to check the morpheus log for details at /var/log/morpheus/morpheus-ui/current.