Leanpub Header

Skip to main content

Apache CloudStack — A Production Deployment Guide

Part 1 — Foundations · Building a Sovereign Cloud on Apache CloudStack 4.22.1.0 LTS

When a license renewal lands at 567% of last year's bill, renting your infrastructure stops being a strategy. This is the escape tunnel: a complete production build of Apache CloudStack 4.22 LTS — KVM, Ceph, SONiC leaf-spine — across a three-city UK estate, written by an engineer with 32 years of building the real thing. Own your cloud down to the last packet.

Minimum price

$19.99

$34.99

You pay

Author earns

$

Also available for 1 book credit with a Reader Membership

Buying multiple copies for your team? See below for a discount!

PDF
EPUB
About

About

About the Book

For a decade the industry outsourced its thinking and treated hypervisors like electricity. Then the landlord changed the locks. When the renewal letter lands at 567% of last year's bill, it isn't a price rise — for many organisations it's an extinction event.

This book is the escape tunnel. It follows a fictional UK publisher, Leaf Spine Books, out of a strangling licensing model and onto a sovereign platform they own down to the last packet: Apache CloudStack 4.22.1.0 LTS on KVMCeph storage deployed with cephadm, and a SONiC leaf-spine fabric on open networking switches — a three-city estate (Manchester, London, Leeds)

.

Part 1 — Foundations (Chapters 1–18) takes you from the renewal letter to a live, multi-zone production cloud:

  • Design and economics — the full three-city blueprint: hardware, VLAN and IP plans, GPU capacity from day one, and honest arithmetic on what sovereignty actually costs
  • A lab you can break — the whole design in miniature on one second-hand server, so every mistake costs an evening rather than a career
  • The production build — hardened Ubuntu hosts, a MariaDB Galera control-plane database, HA management servers, DRBD/NFS secondary storage, and a six-node NVMe Ceph RBD cluster, each layer drilled against real failure before the next goes on top
  • The cloud goes live — zone deployment, KVM compute clusters, GPU passthrough, first guest workloads, VPC multi-tier networking, and the SONiC fabric built for real
  • Running it like you mean it — multi-zone expansion, federated monitoring, sovereign alerting, backup and disaster recovery with an independent-fate cluster, and cost optimisation that turns raw usage into a defensible bill

Every number is labelled for what it is — measured, forecast, or illustration — and every procedure is meant to be rehearsed in a lab before it touches production. The method is yours to take, adapt, and run on hardware you own.

Team Discounts

Team Discounts

Get a team discount on this book!

  • Up to 3 members

    Minimum price
    $59.00
    Suggested price
    $85.00
  • Up to 5 members

    Minimum price
    $99.00
    Suggested price
    $139
  • Up to 10 members

    Minimum price
    $174
    Suggested price
    $244
  • Up to 15 members

    Minimum price
    $249
    Suggested price
    $349
  • Up to 25 members

    Minimum price
    $374
    Suggested price
    $524

Author

About the Author

Michael Hinsley

Mike Hinsley has spent more than three decades with his hands on real infrastructure — from electronics and engineering through operations, security, cloud and SaaS — and has never lost the habit of wanting to understand the machine all the way down. He is the founder of a UK infrastructure consultancy that helps organisations escape per‑core licensing lock‑in by migrating from VMware/Broadcom to sovereign, self‑owned platforms built on Apache CloudStack, with documented client savings of up to 94%. His guiding principle is one he calls GYOCYO — Grow Your Own, Cook Your Own: own the means of a capability rather than rent it as a finished product. He lives it literally. From a smallholding in rural Cheshire he runs large‑scale aquaponics, IoT‑monitored beehives, and a 28.8 kW solar array backed by 90 kWh of battery storage — the same instrument‑everything, owe‑nothing‑to‑anyone thinking he brings to enterprise clients, proven first on his own land. His HIVE‑DC concept — a data centre in a beehive — grew directly out of that overlap. Mike previously presented "Aquaponics, Apiculture, and Advanced Networking with Apache CloudStack" at the CloudStack European User Group in London. He publishes under the Leaf Spine Books imprint, and is preparing to establish a sustainable‑technology education centre uniting aquaponics, beekeeping and cloud infrastructure under one roof.

Contents

Table of Contents

Sovereign Cloud

  1. On owning what you run

The Book in Full — Annotated Contents

  1. Volume 1 — Foundations (Chapters 1-18)
  2. Appendices

How This Book Is Proven

  1. The lab behind the book
  2. What actually happened
  3. Why you can check any of this
  4. What this means for you

Chapter 1: The Cost of Renting Your Existence

  1. Meet Leaf Spine Books — Understanding CloudStack Architecture Through Real-World Needs
  2. The Story: The Renewal Letter
  3. Understanding CloudStack: Building Blocks of Your Cloud
  4. System Virtual Machines: CloudStack’s Control Layer
  5. The Management Server: Brain of the Cloud
  6. Network Architecture: The Four Traffic Types
  7. CloudStack 4.22 LTS: Why This Release
  8. Basic vs Advanced Networking: A Critical Decision
  9. Hypervisor Selection: Why KVM?
  10. Storage Strategy: Why Ceph?
  11. The Road Ahead: Leaf Spine’s Implementation Journey
  12. Key Takeaways
  13. Questions to Answer Before Next Chapter
  14. Coming in Chapter 2
  15. Additional Resources

Chapter 2: Designing the Three-City UK Cloud

  1. From Whiteboard to Blueprint — Planning a Production-Grade Infrastructure
  2. The Story: Architecture Week
  3. Design Principles
  4. Geographic Layout
  5. Network Architecture
  6. VLAN and IP Architecture
  7. Hardware Specifications
  8. Deployment Overview per Site
  9. CloudStack Zone Architecture
  10. Security Architecture
  11. AI and GPU Strategy
  12. Automation with Ansible
  13. Cost Analysis
  14. Migration Path
  15. Disaster Recovery Strategy
  16. Capacity Planning
  17. Monitoring and Alerting
  18. Documentation Standards
  19. Next Steps
  20. Chapter Recap: 5 Key Takeaways
  21. Up Next
  22. References

Chapter 3: Building Your Learning Lab

  1. From One Second-Hand Server to a Cloud You Can Break
  2. Why a Lab at All
  3. The Story: Planning for the Future
  4. The Three-Phase Roadmap
  5. Phase 1: The Learning Lab
  6. The Miniature Estate
  7. Phase 2: Network Simulation
  8. Phase 3: Edge Computing
  9. Done When: the Phase 1 Finish Line
  10. Evolution to Production
  11. Key Takeaways
  12. Coming in Chapter 4
  13. Additional Resources

Chapter 3: Deployment Guide

  1. Building Manchester in Miniature — the Step-by-Step Companion
  2. How to Use This Guide
  3. Page One: the Setting Everything Depends On
  4. The Seven Phases
  5. Pre-Deployment Checklist
  6. Phase 1: Host Preparation
  7. Phase 2: Virtual Networks
  8. Phase 3: Provisioning the Seven VMs
  9. Phase 4: The Management Plane
  10. Phase 5: The Storage Cluster
  11. Phase 6: Secondary Storage
  12. Phase 7: Building the Manchester Zone

Chapter 3: Lab Exercises

  1. Graded Workouts for the Manchester Miniature
  2. How to Use This File
  3. Exercise 1: Know Your Estate
  4. Exercise 2: A Template Worth Keeping
  5. Exercise 3: Offerings and Storage Tags — rbd-dev Earns Its Keep
  6. Exercise 4: The Done-When Circuit
  7. Exercise 5: Guest Networks and the Virtual Router
  8. Exercise 6: Break-and-Rebuild Day
  9. Exercise 7: The Change-Window Rehearsal
  10. Challenge Projects
  11. Completion Criteria

Chapter 3: Troubleshooting Guide

  1. Diagnosis and Recovery for the Manchester Miniature
  2. How to Use This Guide
  3. The Method: Five Steps
  4. Section 1: First Boot — the Usual Suspects
  5. Section 2: Host Layer
  6. Section 3: Network Layer
  7. Section 4: Staged Drill One — the MTU Mismatch
  8. Section 5: Staged Drill Two — Losing Monitor Quorum
  9. Section 6: CloudStack Layer
  10. Section 7: Ceph Layer — the Lab-Scale WARN Taxonomy
  11. Section 8: The Diagnostic Sweep
  12. Section 9: Recovery — the Graduated Ladder
  13. Section 10: Getting Help

Chapter 3: VM Quick Reference

  1. The One-Page Card for the Manchester Miniature
  2. The Estate
  3. The Networks
  4. CloudStack Names (the production names, on purpose)
  5. Where the Secrets Live
  6. Getting In
  7. Daily Commands
  8. Quick Fixes → Troubleshooting Guide
  9. The Chapter 3 File Set

Chapter 3: The Ampere ARM Build

  1. The Manchester Miniature on ARM64 Silicon
  2. Why ARM at All
  3. The One Difference That Reshapes Everything
  4. The Other ARM Deltas, Briefly
  5. The Estate, Inverted
  6. The Build Sequence
  7. A Second Host, Later
  8. The GPUs, Honestly
  9. Done When, on ARM
  10. Key Takeaways
  11. The Chapter 3 File Set
  12. Additional Resources

Chapter 3: The Laptop Build

  1. The Manchester Miniature in a Rucksack
  2. Why a Laptop at All
  3. The One Constraint That Reshapes Everything
  4. The Estate, on a Diet
  5. The Laptop Deltas
  6. The Build Sequence
  7. Travelling With a Datacentre
  8. Network Simulation on the Move
  9. The Switch OS Question
  10. Done When, on a Laptop
  11. Key Takeaways
  12. The Chapter 3 File Set
  13. Additional Resources

Chapter 4: Infrastructure Preparation

  1. Building the Foundation — From Blueprint to Bare Metal
  2. The Story: Hands on the Hardware
  3. Part 1: Understanding the Infrastructure Stack
  4. Part 2: Ubuntu 24.04 LTS Installation
  5. Part 3: Post-Installation Baseline
  6. Part 4: Network Configuration with Netplan
  7. Part 5: Storage Preparation
  8. Part 6: System Optimisation
  9. Part 7: Security Hardening from First Boot
  10. Part 8: Logging Baseline
  11. Part 9: Documentation as Code
  12. Part 10: Verification
  13. Part 11: Replicating to London and Leeds
  14. 🔑 Chapter 4 — Key Takeaways
  15. What’s Next?

Chapter 5: MySQL High Availability

  1. The Database Layer — One Cluster, Two Cities, No Single Point of Failure
  2. The Story: The Heart of the Cloud
  3. Part 1: Understanding the Database Layer
  4. Part 2: The Design — Three Nodes, Two Cities
  5. Part 3: Preparing the Nodes
  6. Part 4: Installing MariaDB and Galera
  7. Part 5: Configuring the Cluster
  8. Part 6: Bootstrapping the Cluster
  9. Part 7: Creating the CloudStack Databases
  10. Part 8: The Single-Writer Routing Layer
  11. Part 9: Testing What We Built
  12. Part 10: Backups — for What Clustering Cannot Prevent
  13. Part 11: Monitoring, Verification, and the Record
  14. 🔑 Chapter 5 — Key Takeaways
  15. What’s Next?

Chapter 6: CloudStack Management Server

  1. The Brain Arrives — Installing the Control Plane on the Nodes That Already Hold Its Memory
  2. The Story: Switching On the Brain
  3. Part 1: What the Management Server Actually Is
  4. Part 2: Pre-Flight Checks and Firewall Doors
  5. Part 3: Database Housekeeping — Two Honest Reconciliations
  6. Part 4: Installing CloudStack on the First Node
  7. Part 5: Initialising the Schema — Without Borrowing Root
  8. Part 6: First Start — and First Contact
  9. Part 7: Nodes Two and Three — the Cluster Assembles
  10. Part 8: First Login
  11. Part 9: Three Front Doors, One Name
  12. Part 10: Testing What We Built — the Inherited Standard
  13. Part 11: Verification and the Record
  14. 🔑 Chapter 6 — Key Takeaways
  15. What’s Next?

Chapter 7: Secondary Storage

  1. The Repository That Rebuilds the Cloud — DRBD and NFS on Refurbished Metal
  2. The Story: The Library Question
  3. Part 1: Understanding Secondary Storage
  4. Part 2: The Design
  5. Part 3: Building the Replicated Filesystem
  6. Part 4: The NFS Service
  7. Part 5: Failover with Keepalived
  8. Part 6: Verification
  9. Part 7: Troubleshooting
  10. 🔑 Chapter 7 — Key Takeaways
  11. What’s Next?

Chapter 8: Primary Storage

  1. Where the VMs Actually Live — Ceph RBD on the NVMe Estate
  2. The Story: The Microseconds Chapter
  3. Part 1: Understanding Primary Storage
  4. Part 2: The Design
  5. Part 3: Deploying the Cluster
  6. Part 4: OSDs, the Pool, and the Credential
  7. Part 5: Firewall and Verification
  8. Part 6: The Drills
  9. Part 7: Troubleshooting
  10. 🔑 Chapter 8 — Key Takeaways
  11. What’s Next?

Chapter 9: Deploying CloudStack — The Zone Goes Live

  1. The Morning the Cloud Gets a Shape
  2. Where We Stand
  3. What This Chapter Is — and Is Not
  4. Part 1: The Shape of a Zone
  5. Part 2: The Toolbelt — UI, API, and an Honesty Box About the Wizard
  6. Part 3: Zone, Physical Network, and the Public Range
  7. Part 4: Pod and the Guest VLAN Range
  8. Part 5: The Cluster, Deliberately Empty
  9. Part 6: The Image Store — and the Auto-Seed Moment
  10. Part 7: Primary Storage — Staged, Verbatim, and One Honest Step Early
  11. Part 8: Verification, Then — and Only Then — Enablement
  12. Troubleshooting the Logical Build
  13. Chapter 9 Summary: Five Things to Hold On To
  14. The Values Card for Chapter 10
  15. What’s Next

Chapter 10: Adding KVM Compute Hosts — The Day the Stage Crew Arrives

  1. The Morning After the Map
  2. Where We Stand
  3. What This Chapter Is — and Is Not
  4. Part 1: The Shape of the Day
  5. Part 2: The Bridges — Three Labels on Two Bonds
  6. Part 3: The Hypervisor Stack
  7. Part 4: The CloudStack Agent and the Service User
  8. Part 5: Pre-Flight — Never Assume, Interrogate
  9. Part 6: Adding the First Host
  10. Part 7: The Cascade
  11. Part 8: The GPU Cluster
  12. Part 9: Verification — Extending the Zone Script
  13. Part 10: Drills — Break It While It’s Cheap
  14. Troubleshooting the Join
  15. Chapter 10 Summary: Five Things to Hold On To
  16. The Values Card for Chapter 11
  17. What’s Next

Chapter 11: Deploying Your First Guest VMs — Opening Night

  1. The Morning the Cloud Earned Its Keep
  2. Where We Stand
  3. What This Chapter Is — and Is Not
  4. Part 1: The Shape of the Day
  5. Part 2: Compute Offerings — The Shapes a VM May Take
  6. Part 3: Disk Offerings — Data That Outlives the VM
  7. Part 4: The GPU Placement Proof — Five Minutes That Retire an Assumption
  8. Part 5: The Guest Template — The SSVM Does the Fetching
  9. Part 6: Editorial’s Network — Where cloudbr2 Earns Its Keep
  10. Part 7: Deploying the Three Guests
  11. Part 8: Everyday Lifecycle — and One Thing the Old Book Got Wrong
  12. Part 9: Verification — Extending the Zone Script
  13. Troubleshooting the First Workload
  14. Chapter 11 Summary: Five Things to Hold On To
  15. The Values Card for Chapter 12
  16. What’s Next

Chapter 12: Advanced Networking — The SONiC Leaf-Spine Fabric

  1. Turning “Trust the Trunk” Into a Tested Data Plane
  2. The Story: The Promissory Notes Come Due
  3. Part 1: Why a Fabric, and Why This One
  4. Part 2: Building the Fabric in the Lab
  5. Part 3: The Underlay — One Routed Fabric
  6. Part 4: VLANs, the Host Trunk, and Making 10.100.0.1 Answer
  7. Part 5: Proving It — Discharging the IOUs
  8. Part 6: What the Fabric Costs — and Why It Runs Open SONiC
  9. The Fabric Is Real Now
  10. Values Card — What Chapter 12 Hands Forward

Chapter 13: Advanced Networking with VPCs — Walls Within the Walls

  1. Building Multi-Tier Isolation on the Fabric You Just Proved
  2. The Story: One Network Was Never Going to Be Enough
  3. Where We Stand
  4. What This Chapter Is — and Is Not
  5. Part 1: The Shape of the Day
  6. Part 2: VPCs, and the One Fact That Trips Everyone
  7. Part 3: Designing the Catalogue VPC — Addresses Before Anything
  8. Part 4: The VPC Offering and the VPC
  9. Part 5: The Tiers — Where the Lanes Multiply
  10. Part 6: Network ACLs — The Walls, Drawn Both Ways
  11. Part 7: The VPC as Code — Reproducible Walls
  12. Part 8: Deploying the Tiers, Proving the Walls, and Balancing the Load
  13. Part 9: Site-to-Site VPN — Extending the Private Space to Leeds
  14. Part 10: Verification — Extending the Zone Script
  15. Part 11: Troubleshooting — The Stateless Traps and Their Friends
  16. Part 12: Where This Goes — One Pattern, Many Tenants
  17. Chapter 13 Summary: Five Things to Hold On To
  18. The Values Card for Chapter 14
  19. What’s Next

Chapter 14: Multi-Zone Expansion

  1. The Cloud Grows a Map of the Country — Without Stretching a Single Fiction
  2. The Story: Three Cities, One Control Plane, No Long-Distance Lies
  3. Where We Stand
  4. What This Chapter Is — and Is Not
  5. Part 1: What “Multi-Zone” Means Here — and the Anti-Pattern It Is Not
  6. Part 2: The Site Inventories — Canonical Estate, Honest Addressing
  7. Part 3: Extending the Fabric — Leaf Pairs to the Manchester Spines
  8. Part 4: London’s Independent Ceph Cluster — the Chapter 8 Pattern, Four Nodes
  9. Part 5: Leeds’ Independent Ceph Cluster — Three Nodes, the Honest Floor
  10. Part 6: Bringing Up the London Zone — the Wizard, Now That We Understand It
  11. Part 7: Bringing Up the Leeds Zone — Building a Zone With No Front Door
  12. Part 8: The Region-Level VPC — Sharing a Design Without Sharing a Failure Domain
  13. Part 9: Verification Across Three Zones — Build-Time, Not the Monitoring Chapter
  14. Troubleshooting the Multi-Zone Build
  15. Chapter 14 Summary: Five Things to Hold On To
  16. The Values Card for Chapter 15
  17. What’s Next

Chapter 15: Monitoring & Operations

  1. Observability at Scale — One View of Three Zones
  2. The Story: Seven Dashboards Are Not a Dashboard
  3. Part 1: The Observability Problem at Estate Scale
  4. Part 2: The Estate Observability Hub
  5. Part 3: Instrumenting the Estate
  6. Part 4: Dashboards That Answer “How Is the Estate?”
  7. Part 5: Logs — Shipping the Estate’s Diary Somewhere Durable
  8. Part 6: Alerting Without a SaaS Pager
  9. Part 7: Incident Response and On-Call — the Runbooks Owe
  10. Part 8: Capacity Signals for Operations
  11. Part 9: Lab Exercise — One View of the Lab
  12. 🔑 Five Key Takeaways
  13. What’s Next?

Chapter 16: Backup & Disaster Recovery

  1. An Independent Copy That Does Not Share Fate
  2. The Story: The Night the Mirror Lied
  3. Part 1: Three Words People Use Interchangeably and Shouldn’t
  4. Part 2: Protection Tiers, and Why They Are Really a Storage-Media Decision
  5. Part 3: The Independent-Fate Backup Cluster
  6. Part 4: CloudStack Native Backup & Recovery — the Shipping KVM Workhorse
  7. Part 5: Cross-Site DR with rbd-mirror (Tier 1)
  8. Part 6: The Immutable Archive — RGW S3 Object Lock (Tier 3)
  9. Part 7: Database Disaster Recovery — Discharging the Chapter 5 Promise
  10. Part 8: What’s Coming in 4.23 — Native KVM Backups via Veeam
  11. Part 9: Restore Drills, Runbooks, and the Mars Test
  12. Five Key Takeaways
  13. What’s Next?

Chapter 17: Cost Optimisation & Capacity Planning

  1. Owning the Meter: What a Sovereign Cloud Actually Costs
  2. The Story: Does Owning This Thing Actually Pay?
  3. Part 1: You Cannot Manage What You Cannot Meter
  4. Part 2: What the Estate Actually Costs
  5. Part 3: The Escape That Pays
  6. Part 4: When the Migration Pays for Itself
  7. Part 5: Cost per Workload — From Architecture to Accountability
  8. Part 6: Return on Research — Finding the Idle Silicon
  9. Part 7: Seeing the Wall Before You Hit It
  10. Five Key Takeaways
  11. What’s Next
  12. Quality Improvements in This Version

Chapter 18: Your Cloud Journey Starts Now

  1. The Estate Is Built — Reflection, Consolidation, and the Road into Part 2
  2. The Story: After the Renewal Letter
  3. The Journey You’ve Taken
  4. What Sovereignty Actually Cost
  5. The Thesis: Not Only for the Few
  6. The Mars Test, One Last Time
  7. 🔀 Where You Go Next: Part 2
  8. 🔑 Key Takeaways
  9. Before You Close Part 1
  10. What Next, and Staying in Touch

Appendix A: Glossary

Appendix B — The Portable CloudStack Lab

  1. Running a Production-Grade Lab on a Laptop
  2. Introduction
  3. Hardware Requirements
  4. The Lab, Layer by Layer
  5. What’s Different on a Laptop
  6. The Reader Lab, As It Was Actually Built
  7. Connecting Real Hardware
  8. Performance Notes (Laptop-Specific)
  9. Backup and Recovery
  10. Use Cases
  11. Conclusion

Afterword — The Estate Is Yours Now

  1. About the author
  2. Stay in touch

The Leanpub 60 Day 100% Happiness Guarantee

Within 60 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.

See full terms...

Earn $8 on a $10 Purchase, and $16 on a $20 Purchase

We pay 80% royalties on purchases of $7.99 or more, and 80% royalties minus a 50 cent flat fee on purchases between $0.99 and $7.98. You earn $8 on a $10 sale, and $16 on a $20 sale. So, if we sell 5000 non-refunded copies of your book for $20, you'll earn $80,000.

(Yes, some authors have already earned much more than that on Leanpub.)

In fact, authors have earned over $15 million writing, publishing and selling on Leanpub.

Learn more about writing on Leanpub

Free Updates. DRM Free.

If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).

Most Leanpub books are available in PDF (for computers) and EPUB (for phones, tablets and Kindle). The formats that a book includes are shown at the top right corner of this page.

Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.

Learn more about Leanpub's ebook formats and where to read them

Write and Publish on Leanpub

You can use Leanpub to easily write, publish and sell in-progress and completed ebooks and online courses!

Leanpub is a powerful platform for serious authors, combining a simple, elegant writing and publishing workflow with a store focused on selling in-progress ebooks.

Leanpub is a magical typewriter for authors: just write in plain text, and to publish your ebook, just click a button. (Or, if you are producing your ebook your own way, you can even upload your own PDF and/or EPUB files and then publish with one click!) It really is that easy.

Learn more about writing on Leanpub