Sun Logo




Logical Domains (LDoms) 1.0.1 Administration Guide

820-3268-10


Contents

Figures

Tables

Examples

Preface

Overview of the Logical Domains Software

Hypervisor and Logical Domains

Logical Domains Manager

Roles for Logical Domains

Command-Line Interface

Virtual Input/Output

Virtual Network

Virtual Storage

Virtual Consoles

Dynamic Reconfiguration

Delayed Reconfiguration

Persistent Configurations

Security

Security Considerations

Solaris Security Toolkit and the Logical Domains Manager

Hardening

Minimizing Logical Domains

Authorization

Auditing

Compliance

Installing and Enabling Software

Upgrading to LDoms 1.0.1 Software

procedure iconsmall spaceTo Upgrade to LDoms 1.0.1 Software

Freshly Installing Software on the Control Domain

procedure iconsmall spaceTo Install the Solaris 10 OS

procedure iconsmall spaceTo Upgrade System Firmware

procedure iconsmall spaceTo Upgrade System Firmware Without an FTP Server

procedure iconsmall spaceTo Downgrade System Firmware

Downloading Logical Domains Manager and Solaris Security Toolkit

procedure iconsmall spaceTo Download the Logical Domains Manager, Solaris Security Toolkit, and Logical Domains MIB

Installing Logical Domains Manager and Solaris Security Toolkit

Using the Installation Script to Install the Logical Domains Manager 1.0.1 and Solaris Security Toolkit 4.2 Software

Using JumpStart to Install the Logical Domains Manager 1.0.1 and Solaris Security Toolkit 4.2 Software

Installing Logical Domains Manager and Solaris Security Toolkit Software Manually

procedure iconsmall spaceTo Install Using the install-ldm Script With No Options

procedure iconsmall spaceTo Install Using the install-ldm Script With the -d Option

procedure iconsmall spaceTo Install Using the install-ldm Script With the -d none Option

procedure iconsmall spaceTo Install Using the install-ldm Script With the -p Option

procedure iconsmall spaceTo Set Up a JumpStart Server

procedure iconsmall spaceTo Install Using JumpStart Software

procedure iconsmall spaceTo Install the Logical Domains Manager (LDoms) 1.0.1 Software Manually

procedure iconsmall space(Optional) To Install the Solaris Security Toolkit 4.2 Software Manually

procedure iconsmall space(Optional) To Harden the Control Domain Manually

procedure iconsmall spaceTo Validate Hardening

procedure iconsmall spaceTo Undo Hardening

Enabling the Logical Domains Manager Daemon

procedure iconsmall spaceTo Enable the Logical Domains Manager Daemon

Creating Authorization and Profiles and Assigning Roles for User Accounts

Managing User Authorizations

Managing User Profiles

Assigning Roles to Users

procedure iconsmall spaceTo Add an Authorization for a User

procedure iconsmall spaceTo Delete All Authorizations for a User

procedure iconsmall spaceTo Add a Profile for a User

procedure iconsmall spaceTo Delete All Profiles for a User

procedure iconsmall spaceTo Create a Role and Assign the Role to a User

Setting Up Services and Logical Domains

Output Messages

Sun UltraSPARC T1 Processors

Sun UltraSPARC T2 Processors

Creating Default Services

procedure iconsmall spaceTo Create Default Services

Initial Configuration of the Control Domain

procedure iconsmall spaceTo Set Up the Control Domain

Rebooting to Use Logical Domains

procedure iconsmall spaceTo Reboot to Use Logical Domains

Enabling Networking Between the Control/Service Domain and Other Domains

procedure iconsmall spaceTo Configure the Virtual Switch as the Primary Interface

Enabling the Virtual Network Terminal Server Daemon

procedure iconsmall spaceTo Enable the Virtual Network Terminal Server Daemon

Creating and Starting a Guest Domain

procedure iconsmall spaceTo Create and Start a Guest Domain

Jump-Starting a Guest Domain

Other Information and Tasks

Accessing the ldm(1M) Man Page

procedure iconsmall spaceTo Access the ldm(1M) Man Page

Restrictions on Entering Names in the CLI

File Names (file) and Variable Names (var_name)

Virtual Disk Server file|device and Virtual Switch device Names

Configuration Name (config_name)

All Other Names

Using ldm list Subcommands

Machine-Readable Output

Flag Definitions

Utilization Statistic Definition

Examples of Various Lists

Listing Constraints

procedure iconsmall spaceTo Show Syntax Usage for ldm Subcommands

procedure iconsmall spaceTo Show Software Versions (-V)

procedure iconsmall spaceTo Generate a Short List

procedure iconsmall spaceTo Generate a Long List (-l)

procedure iconsmall spaceTo Generate an Extended List (-e)

procedure iconsmall spaceTo Generate a Parseable, Machine-Readable List (-p)

procedure iconsmall spaceTo Show the Status of a Domain

procedure iconsmall spaceTo List a Variable

procedure iconsmall spaceTo List Bindings

procedure iconsmall spaceTo List Configurations

procedure iconsmall spaceTo List Devices

procedure iconsmall spaceTo List Services

procedure iconsmall spaceTo List Constraints for One Domains

procedure iconsmall spaceTo List Constraints in XML Format

procedure iconsmall spaceTo List Constraints in a Machine-Readable Format

The ldm stop-domain Command Can Time Out If the Domain Is Heavily Loaded

Determining the Solaris Network Interface Name Corresponding to a Virtual Network Device

procedure iconsmall spaceTo Find Solaris OS Network Interface Name

Assigning MAC Addresses Automatically or Manually

Range of MAC Addresses Assigned to Logical Domains Software

Automatic Assignment Algorithm

Duplicate MAC Address Detection

Freed MAC Addresses

Manual Allocation of MAC Addresses

procedure iconsmall spaceTo Allocate a MAC Address Manually

CPU and Memory Address Mapping

CPU Mapping

Memory Mapping

Examples of CPU and Memory Mapping

procedure iconsmall spaceTo Determine the CPU Number

procedure iconsmall spaceTo Determine the Real Memory Address

Configuring Split PCI Express Bus to Use Multiple Logical Domains

procedure iconsmall spaceTo Create a Split PCI Configuration

Enabling the I/O MMU Bypass Mode on a PCI Bus

Using Console Groups

procedure iconsmall spaceTo Combine Multiple Consoles Into One Group

Moving a Logical Domain From One Server to Another

procedure iconsmall spaceTo Set Up Domains to Move

procedure iconsmall spaceTo Move the Domain

Removing Logical Domains

procedure iconsmall spaceTo Remove All Guest Logical Domains

Operating the Solaris OS With Logical Domains

Power-Cycling a Server

Result of an OpenBoot power-off Command

Result of a Solaris OS shutdown Command

Result of a Solaris OS Break Key Sequence (L1-A)

Results from Halting or Rebooting the Control Domain

Some format(1M) Command Options Do Not Work With Virtual Disks

procedure iconsmall spaceTo Save Your Current Logical Domain Configurations to the SC First

Using LDoms With ALOM CMT

procedure iconsmall spaceTo Reset the Logical Domain Configuration to the Default or Another Configuration

Enabling and Using BSM Auditing

procedure iconsmall spaceTo Use the enable-bsm.fin Finish Script

procedure iconsmall spaceTo Use the Solaris OS bsmconv(1M) Command

procedure iconsmall spaceTo Verify that BSM Auditing is Enabled

procedure iconsmall spaceTo Disable Auditing

procedure iconsmall spaceTo Print Audit Output

procedure iconsmall spaceTo Rotate Audit Logs

Configuring Virtual Switch and Service Domain for NAT and Routing

procedure iconsmall spaceTo Set Up the Virtual Switch to Provide External Connectivity to Domains

Using ZFS With Virtual Disks

Creating a Virtual Disk on Top of a ZFS Volume

Using ZFS Over a Virtual Disk

Using ZFS for Boot Disks

procedure iconsmall spaceTo Create a Virtual Disk on Top of a ZFS Volume

procedure iconsmall spaceTo Use ZFS Over a Virtual Disk

procedure iconsmall spaceTo Use ZFS for Boot Disks

Using Volume Managers in a Logical Domains Environment

Using Virtual Disks on Top of Volume Managers

Note on Using Virtual Disks on Top of SVM

Note on Using Virtual Disks When VxVM Is Installed

Using Volume Managers on Top of Virtual Disks

Using ZFS on Top of Virtual Disks

Using SVM on Top of Virtual Disks

Using VxVM on Top of Virtual Disks

Configuring IPMP in a Logical Domains Environment

Configuring Virtual Network Devices into an IPMP Group in a Logical Domain

Configuring and Using IPMP in the Service Domain

Glossary