Setting Up AWS VMR Cloud Images
This section will walk you through the steps required to get a single Solace Virtual Message Router (VMR) cloud images running in Amazon Web Services (AWS) and ready for messaging.
- Step 1: Start VMR Instance in AWS
- Step 2: Access the Solace CLI
- Step 3: Review VMR Configuration Defaults
- Additional VMR Cloud Image Configuration
- You have access to AWS.
For Evaluation and Enterprise VMR editions, the system resources that you provision for the VM automatically determines the number of client connections to the VMR that can be made. If you provision:
- 30 GB of disk space, 4 GB of RAM, and two vCPUs—a maximum of 1,000 client connections are possible. This is the minimum required system resources.
- 30 GB of disk space, 12 GB of RAM, and four vCPUs or greater—a maximum of 10,000 client connections are possible.
For Community VMR editions, a maximum of 100 client connections is permitted. Increasing the system requirements will not increase the number of available client connections.
- The minimum supported instance type for a Solace VMR message routing node is m4.large with a storage value type IO1 with 3000 IOPS. For a monitoring node, the minimum supported instance type is m4.large with a storage volume type IO1.
Performance in AWS will vary depending on instance type and storage configuration. Solace has characterized that deterministic performance is achieved using an instance type of m4.10xlarge with a storage volume type IO1 with 10,000 IOPs. AWS provides different instance types between m4.large and m4.10xlarge which may be suitable for your requirements.
- To deploy VMRs in high-availability (HA) redundancy groups, you must set up three separate VMR instances as discussed in this section, and then configure them appropriately as a group. For more information on how to configure existing VMRs as an HA group, see Managing VMR Redundancy.
To start a Solace VMR instance in AWS, perform the following steps:
- Obtain a Solace Amazon Machine Image (AMI) package for the type of VMR edition you will use.
For Evaluation and Community VMR editions, you must download the AMI through a Solace-provided link. For Enterprise edition VMRs, Solace makes the AMI for AWS directly available to your AWS account.
- For an Evaluation and Community VMR edition, do the following:
- Go to dev.solace.com/downloads/, then in the VMR Community Edition or VMR Evaluation Edition areas, select Cloud Images.
- Under AMI for Amazon Web Services, select an AWS region appropriate for you, then after you accept the license agreement, you will be emailed a link that will take you to the AWS Instance Launch Wizard.
- For an Enterprise VMR edition, do the following:
- Log in to your AWS account, and from the main AWS dashboard, select EC2, then click Launch Instance.
- In the Choose AMI screen, select My AMIs, then select Ownership, and enable Shared with Me.
- Find the Solace AMI (the image name has a format of
soltr-<version>-vmr-enterprise-cloud), then click Select.
In the Configure Instance Details screen, choose an appropriate Amazon Virtual Private Cloud (VPC) and subnet, and then click Next: Add Storage.
For information about VPCs and subnets, refer to AWS documentation.
- In the Configure Instance Details screen, configure the VPC, then click Next: Add Storage.
- In the Add Storage screen, select a sufficiently-sized volume, and then click Next: Tag Instance.
- In the Tag Instance screen, add tags as appropriate to keep your VMR instances organized, then click Next: Configure Security Group.
The following example uses Name, Owner, and Version but you can choose any tags that make sense for your application.
- In the Configure Security Group screen, create an appropriate security rule for each port that the VMR uses for a service to enable connectivity to your VMR, and then click Review and Launch.
For information on the default ports the VMR uses, refer to VMR Configuration Defaults. The example below includes rules for all service ports that the VMR may use. Alternatively you may only expose the services required for your application.
- AWS can provide a private and public IP address. These addresses must be considered in the security group configuration.
- If you will be using the VMR in an HA redundancy group with other VMRs, you must create security rules for ports 5404, 5405, and 8741.
- In the Review Screen, review your instance. Ignore the warnings, and click Launch.
- The instance will start. In the dialog box that starts, choose an authentication key pair for the VMR instance, which can be used for this first login to the VMR, and then click Launch Instance.
The EC2 dashboard will show your VMR instance under Instances. Here you can find the external and internal IP address of the instance. (For more information, refer to IP Addressing in Cloud Instances.)
To log into the Linux Host shell, enter the following command:
ssh -p 2222 -i <auth_key> sysadmin@<public_ip>
You can access the Solace CLI from the console in the Linux host environment. This is done through the Solace Control Utility.
When you first access the Solace CLI, you should do the following:
- set a password for the admin user, which has access to all CLI commands
- determine the VMR’s IP address so that you can enable remote access
To access the Solace CLI, do the following:
- To enter the Solace CLI from the console in the Linux host environment, enter the following command in the Linux host shell.
[sysadmin@solace ~]$ solacectl cli
A CLI banner and prompt appears.
>prompt, you are at the User EXEC level of the Solace CLI command structure.
- Within the Solace CLI, enter the following commands to create an admin user named
solace(configure)# create username admin password <password>
solace(configure/username)# global-access-level admin
- To determine the IP address assigned to the VMR, enter the following command:
solace> show ip vrf management
The displayed output lists the IP address assigned to the VMR (listed for
eth0:1), which can be used to remotely manage the VMR (that is, not from the VM console).
- To remotely access the Solace CLI for the VMR, you can now ssh to port 22 of the VMR’s IP address and login in as the
Tip: In addition to the admin CLI User, you can create additional CLI and file transfer users through the Solace CLI in the manner described in Managing Management User Authentication/Authorization.
Unlike a Solace appliance, by default, a VMR starts with a basic configuration that has most common services enabled and ready for use. This basic configuration and the default ports that are used can be modified as required. For details, see VMR Configuration Defaults.
You now have a VMR cloud image with a basic configuration that is ready for messaging tasks. However, there are additional configuration tasks that you can perform. At this stage, you should do the following:
- Review the extra configuration tasks specific to VMR images presented on the Additional VMR Image Configuration page.
These additional configurations allow you to further customize your VMR cloud image to better suit your particular use-case and to make it more suitable for a production deployment.
- Begin to configure and manage the VMR image’s messaging operations through the Solace CLI in the same manner as you would other Solace messaging routers (say, a Solace messaging appliance or a Solace VMR Docker container). For information on how to perform these configuration and management tasks, see the topics in the Router Configuration category of the Solace customer documentation.