Oracle RAC 11g on SUSE Linux - a two-node cluster on Hyper-V
In 2016 I built a two-node Oracle Real Application Clusters database on virtual machines that ran on somebody else's Hyper-V. The database itself was the smaller part of the work. Around it went a DNS server, because the cluster wants its names resolved a certain way, shared disks that had to carry the same name and owner on both nodes, an operating system prepared to the letter of Oracle's installation guide, and a backup product that had to be persuaded that two Linux servers and one database are three things.
This Solution is the whole of that build, written up from my working notes: two SUSE Linux Enterprise Server 11 SP3 nodes with five network roles each, five iSCSI LUNs turned into ASM disks with udev rules and ASMLib, Oracle Grid Infrastructure and Oracle Database 11.2.0.4 Standard Edition, an authoritative Knot DNS server on Debian, and Symantec Backup Exec 15 backing up the nodes and the database. Two things went wrong on the way and both are told in full: the root script of the Grid installation failed on this SUSE service pack until a patch was applied, and the second node could not join the cluster because the virtual network passed neither multicast nor broadcast.
The system in one picture
flowchart TB apps["Database clients"] subgraph cluster["Oracle RAC, cluster clsdb"] scan["SCAN oradb-scan, three addresses"] n1["oradb01: Grid Infrastructure, ASM, instance 1"] n2["oradb02: Grid Infrastructure, ASM, instance 2"] n1 <-- "interconnect, alias eth3:INT" --> n2 end subgraph san["Shared iSCSI LUNs"] crs["ORADB-CRS: disk group OCR"] data["ORADB-DATA01 and DATA02: disk group DATA"] fra["ORADB-FRA: disk group FRA"] ontrlg["ORADB-ONTRLG: disk group ONTRLG"] end dns["dns1: Knot DNS and NTP"] be["mng-backupsrv01: Backup Exec server"] apps -- "public network" --> scan scan --> n1 scan --> n2 n1 -- "iSCSI network" --> san n2 -- "iSCSI network" --> san n1 -- "management network" --> dns n2 -- "management network" --> dns be -- "backup network" --> n1 be -- "backup network" --> n2
The fictional environment
Every Article and every Config document uses the same names and addresses.
| Thing | Value |
|---|---|
| Domain | example.net |
| Nodes | oradb01, oradb02, SUSE Linux Enterprise Server 11 SP3 on Hyper-V |
Public network, eth1 | 10.30.10.0/24: nodes .11 and .12, VIPs .21 and .22, SCAN .31 to .33 |
Interconnect, alias eth3:INT | 10.30.20.0/24, names ending in -int |
Backup network, eth0 | 10.30.30.0/24, names ending in -bck |
Management network, eth3 | 10.30.40.0/24, names ending in -mng |
iSCSI network, eth4 | 10.30.50.0/24 |
| DNS and NTP server | dns1, 10.30.40.13, Debian 8.5 |
| Backup Exec server | mng-backupsrv01, 10.30.40.14 and 10.30.30.14 |
| Grid Infrastructure home, owner | /data/u01/app/grid11204, grid |
| Database home, owner | /data/u01/app/oracle/db11204, oracle |
| Cluster, database instances | clsdb, clsdb1 and clsdb2 |
Host, cluster, database, disk and account names are role names and were kept. The SCSI identifiers, the database identifier and the voting file identifier in the listings are made up.
Articles
Read in this order; it is the order the system was built in.
| # | Article | What it covers |
|---|---|---|
| 1 | Overview and design | What was built and from what, the homes and their owners, the build order, what the notes do not hold |
| 2 | Network and DNS plan | Five network roles, every name and address, and why the interconnect ended up as an alias on the management interface |
| 3 | DNS server: Knot | An authoritative Knot server with one forward and four reverse zones, tested by zone transfer, and what the transfers gave away |
| 4 | Operating system preparation | Packages, users and groups, kernel parameters, limits, time, directories, SSH keys |
| 5 | Storage and ASM disks | The local software volume, five shared LUNs, udev rules for names and ownership, ASMLib |
| 6 | Grid Infrastructure installation | The installer's questions, the root scripts and their order, checking the cluster |
| 7 | Grid patches and the multicast problem | A root script that failed on SLES 11 SP3, patches that helped and patches that did not, a network without multicast |
| 8 | Database software, listener and disk groups | The database home on both nodes, a second listener, three more disk groups |
| 9 | Database creation and user environments | DBCA for a RAC database, and shell profiles that switch between the two Oracle homes |
| 10 | Backup Exec agent | The Linux agent on both nodes: installation, logging, its configuration file, the Oracle instances it is told about |
| 11 | Backup Exec server and RAC backup | The virtual RAC node, the database account for backups, and the order of clicks that made the server accept it |
Configuration
Each document holds one file, one command set or one set of installer answers as it was used, with comments, the differences between the two nodes, and a check against the current release. Oracle's installers and the Backup Exec console leave no file to show, so their documents list what was answered, screen by screen.
DNS
Operating system
| Document | Explained in |
|---|---|
| Package installation commands | 4 |
| sysctl.conf, Oracle block | 4 |
| limits.conf, Oracle block | 4 |
| profile.local | 4 |
Storage
| Document | Explained in |
|---|---|
| fstab | 5 |
| udev rules for the ASM disks | 5 |
| udev rules for DM multipath, not used | 5 |
| ASMLib commands | 5 |
Grid Infrastructure
Database
Backup
| Document | Explained in |
|---|---|
| installralus session | 10 |
| ralus.cfg | 10 |
| beoratab | 10 |
| AgentConfig sessions | 10 |
| SQL for the DBID and the BACKUP_EXEC account | 11 |
| hosts file on the Backup Exec server | 11 |
| Backup Exec server settings | 11 |
What the write-up found
Reading the notes again ten years later turned up things I did not see when I wrote them. Each is told in its Article.
| Finding | Where |
|---|---|
The notes call the database csldb, clsdb and clsopdb, and the added listener opdb and CLSDB | 1 |
| The interconnect is an alias on the management interface, where Oracle wants an interface of its own for it | 2, 6 |
| The reverse zones name their primary server without the final dot, and three of the four have no NS record; the zone transfers show the result | 3 |
vm.hugetlb_shm_group is set twice, so only the second value counts, and no stack limit is set | 4 |
| The disk sizes in the plan, in the ASMLib discovery output and in ASMCA do not agree | 5 |
| The cumulative patches were applied against a problem that was in the network | 7 |
The profiles of oracle and grid test the user name against a string in typographic quotes, so their ulimit lines never run | 9 |
The dedicated database account for backups worked in the database and not in Backup Exec; sys was used in the end | 11 |
| The notes hold no backup job and no restore test | 11 |