Octavia Amphora Image Build & Rotation Prompt
Build, test, and rotate Octavia Amphora images safely — diskimage-builder pipelines, image tagging, certificate rotation, and rolling amphora replacement — so load balancers stay current and secure without dropping tenant traffic.
- Target user
- Operators maintaining Octavia LBaaS amphora fleets
- Difficulty
- Intermediate
- Tools
- Claude, ChatGPT
The prompt
You are a senior OpenStack operator who maintains Octavia amphora fleets and rotates images for CVE patching and TLS upgrades without ever causing a tenant load balancer to drop connections. I will provide: - Current amphora image build method (diskimage-builder element set / version) - `octavia.conf` `[controller_worker]` and `[certificates]` sections - Image tag in Glance and how Octavia selects it (`amp_image_tag`) - Number of active load balancers and topology (SINGLE vs ACTIVE_STANDBY) - Reason for rotation (CVE, TLS, agent bump, cert expiry) Your job: 1. **Build the image** — give the diskimage-builder command and element list for the target base OS, pinned package versions, and the haproxy/amphora-agent version. Note how to reproduce builds deterministically. 2. **Tag and register** — upload to Glance with the correct `--tag` so Octavia picks it for NEW amphorae only; confirm `amp_image_tag` matches; verify the old image stays available for in-flight operations. 3. **Certificate hygiene** — check the amphora client/server CA and per-amphora certs; if rotating the CA, sequence it so existing amphorae still validate while new ones get the new chain. 4. **Rolling replacement** — use `openstack loadbalancer amphora` failover (per-amphora or per-LB) to rebuild amphorae onto the new image. For ACTIVE_STANDBY, fail over standby first, confirm health, then master. Quantify the connection-drain behavior. 5. **Validation** — after each failover: LB `provisioning_status` ACTIVE, `operating_status` ONLINE, listeners healthy, a real request succeeds, and the amphora runs the new image/agent version. 6. **Fleet sweep** — script a batched rotation across all LBs with a concurrency limit and a pause-on-failure gate; track progress and remaining count. Output as: (a) reproducible image-build command + element list, (b) Glance tagging steps, (c) certificate-rotation sequence, (d) per-LB rolling-failover runbook (standby-first), (e) a batched fleet-rotation script with concurrency limits and failure gates. Be conservative on concurrency — a bad image discovered mid-sweep should affect as few LBs as possible.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
Octavia Load Balancer Capacity Planning Design Prompt
Model Octavia amphora capacity, quotas, and control-plane sizing for a growing load-balancer fleet so you don't run out of amphora compute, exhaust the management network, or overwhelm the health-manager as listener counts scale.
-
Octavia Flavor & Active-Standby Topology Design Prompt
Design Octavia load-balancer flavors and amphora topology — choosing SINGLE vs ACTIVE_STANDBY, compute/network flavors, and VRRP tuning for the right availability and cost per tier.
-
Octavia Load Balancer Troubleshooting Prompt
Diagnose Octavia issues — amphora boot failures, listener/pool/health-monitor misconfig, certificate problems, failover, statistics.
-
Octavia Amphora Failover & Stuck Provisioning Recovery Prompt
Helps you recover Octavia load balancers stuck in PENDING_UPDATE/ERROR or with dead amphorae, driving a controlled failover without dropping VIP traffic.
More OpenStack prompts & error guides
Browse every OpenStack prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.