|
| 1 | +# Testing Windows Server Insider Preview |
| 2 | + |
| 3 | +## About the lab |
| 4 | + |
| 5 | +In following lab you will test latest Windows Server Insider Preview features announced at following blog: https://techcommunity.microsoft.com/discussions/windowsserverinsiders/announcing-windows-server-vnext-preview-build-29621/4536572 |
| 6 | + |
| 7 | +You will create 2 node S2D cluster and inside the cluster you will create single, empty VM to test Trusted Launch for VMs. You can then add real vhd and test thigs such as TPM and live migration across cluster nodes. |
| 8 | + |
| 9 | +## Labconfig |
| 10 | + |
| 11 | +```PowerShell |
| 12 | +$LabConfig=@{AllowedVLANs="1-10,711-719" ; DomainAdminName='LabAdmin'; AdminPassword='LS1setup!' ; DCEdition='4'; Internet=$true; AdditionalNetworksConfig=@(); VMs=@()} |
| 13 | +
|
| 14 | +#Windows Server Insider S2D nodes |
| 15 | +$LABConfig.VMs += @{ VMName = "S2D1" ; Configuration = 'S2D' ; ParentVHD = 'WinSrvInsiderCore_29621.vhdx' ; HDDNumber = 4 ; HDDSize= 1TB ; MemoryStartupBytes= 4GB; VMProcessorCount="MAX" ; vTPM=$true ; NestedVirt=$true } |
| 16 | +$LABConfig.VMs += @{ VMName = "S2D2" ; Configuration = 'S2D' ; ParentVHD = 'WinSrvInsiderCore_29621.vhdx' ; HDDNumber = 4 ; HDDSize= 1TB ; MemoryStartupBytes= 4GB; VMProcessorCount="MAX" ; vTPM=$true ; NestedVirt=$true } |
| 17 | +
|
| 18 | +#Management machine |
| 19 | +$LabConfig.VMs += @{ VMName = 'Management' ; ParentVHD = 'WinSrvInsider_29621.vhdx'; MGMTNICs=1 ; AddToolsVHD=$True } |
| 20 | + |
| 21 | +``` |
| 22 | + |
| 23 | + |
| 24 | + |
| 25 | + |
| 26 | + |
| 27 | + |
| 28 | +## Prerequisites |
| 29 | + |
| 30 | +### Create Insider Lab Environment |
| 31 | + |
| 32 | +To create insider parent image, download latest iso from [Windows Server Insiders Downloads](https://www.microsoft.com/en-us/software-download/windowsinsiderpreviewserver) and then follow steps in [01-Creating First Lab](../../HandsOnLabs/01-CreatingFirstLab/readme.md) with Labconfig above. |
| 33 | + |
| 34 | +### Build your cluster |
| 35 | + |
| 36 | +Once you're logged in the management machine, simply paste following PowerShell to build simple 2-node cluster |
| 37 | + |
| 38 | +```PowerShell |
| 39 | +#region Variables |
| 40 | + #servers list |
| 41 | + $Servers="S2D1","S2D2" |
| 42 | + #Cluster Name |
| 43 | + $ClusterName="S2D-Cluster" |
| 44 | + #Witness Server |
| 45 | + $WitnessServer="DC" |
| 46 | +#endregion |
| 47 | +
|
| 48 | +#region install keys and activate servers |
| 49 | +
|
| 50 | +$LicenseKey="2KNJJ-33Y9H-2GXGX-KMQWH-G6H67" |
| 51 | +
|
| 52 | + cscript c:\windows\system32\slmgr.vbs /ipk $using:LicenseKey |
| 53 | + cscript c:\windows\system32\slmgr.vbs /ato |
| 54 | +
|
| 55 | +Invoke-Command -ComputerName $Servers -ScriptBlock { |
| 56 | + cscript c:\windows\system32\slmgr.vbs /ipk $using:LicenseKey |
| 57 | + cscript c:\windows\system32\slmgr.vbs /ato |
| 58 | +} |
| 59 | +
|
| 60 | +#check status |
| 61 | +Get-CimInstance SoftwareLicensingProduct -CimSession $Servers | |
| 62 | + Where-Object { $_.PartialProductKey -and $_.ApplicationID -eq '55c92734-d682-4d71-983e-d6ec3f16059f' } | |
| 63 | + Select-Object Name, Description, LicenseStatus, PartialProductKey, PSComputerName, |
| 64 | + @{N='LicenseStatusText';E={ |
| 65 | + switch ($_.LicenseStatus) { |
| 66 | + 0 {'Unlicensed'} |
| 67 | + 1 {'Licensed'} |
| 68 | + 2 {'OOBGrace'} |
| 69 | + 3 {'OOTGrace'} |
| 70 | + 4 {'NonGenuineGrace'} |
| 71 | + 5 {'Notification'} |
| 72 | + 6 {'ExtendedGrace'} |
| 73 | + default {'Unknown'} |
| 74 | + } |
| 75 | + }} |
| 76 | +#endregion |
| 77 | +
|
| 78 | +#region install required features |
| 79 | + #install features for management (assuming you are running these commands on Windows Server with GUI) |
| 80 | + Install-WindowsFeature -Name NetworkATC,RSAT-Clustering,RSAT-Clustering-Mgmt,RSAT-Clustering-PowerShell,RSAT-Hyper-V-Tools,RSAT-Feature-Tools-BitLocker-BdeAducExt,RSAT-AD-PowerShell,RSAT-AD-AdminCenter,RSAT-DHCP,RSAT-DNS-Server |
| 81 | +
|
| 82 | + #install roles and features on servers |
| 83 | + #install Hyper-V using DISM if Install-WindowsFeature fails (if nested virtualization is not enabled install-windowsfeature fails) |
| 84 | + Invoke-Command -ComputerName $servers -ScriptBlock { |
| 85 | + $Result=Install-WindowsFeature -Name "Hyper-V" -ErrorAction SilentlyContinue |
| 86 | + if ($result.ExitCode -eq "failed"){ |
| 87 | + Enable-WindowsOptionalFeature -FeatureName Microsoft-Hyper-V -Online -NoRestart |
| 88 | + } |
| 89 | + } |
| 90 | + #define and install other features |
| 91 | + $features="Failover-Clustering","RSAT-Clustering-PowerShell","Hyper-V-PowerShell","NetworkATC","Data-Center-Bridging","RSAT-DataCenterBridging-LLDP-Tools","FS-SMBBW","System-Insights","RSAT-System-Insights" |
| 92 | + Invoke-Command -ComputerName $servers -ScriptBlock {Install-WindowsFeature -Name $using:features} |
| 93 | +#endregion |
| 94 | +
|
| 95 | +#region restart servers to apply |
| 96 | + Restart-Computer $servers -Protocol WSMan -Wait -For PowerShell -Force |
| 97 | + Start-Sleep 20 #Failsafe as Hyper-V needs 2 reboots and sometimes it happens, that during the first reboot the restart-computer evaluates the machine is up |
| 98 | + #make sure computers are restarted |
| 99 | + Foreach ($Server in $Servers){ |
| 100 | + do{$Test= Test-NetConnection -ComputerName $Server -CommonTCPPort WINRM}while ($test.TcpTestSucceeded -eq $False) |
| 101 | + } |
| 102 | +#endregion |
| 103 | +
|
| 104 | +#region Create cluster |
| 105 | + #Create Cluster |
| 106 | + New-Cluster -Name $ClusterName -Node $servers |
| 107 | + Start-Sleep 5 |
| 108 | + Clear-DnsClientCache |
| 109 | +
|
| 110 | + ##Configure Witness on WitnessServer |
| 111 | + #Create new directory |
| 112 | + $WitnessName=$Clustername+"Witness" |
| 113 | + Invoke-Command -ComputerName $WitnessServer -ScriptBlock {new-item -Path c:\Shares -Name $using:WitnessName -ItemType Directory -ErrorAction Ignore} |
| 114 | + $accounts=@() |
| 115 | + $accounts+="$env:userdomain\$ClusterName$" |
| 116 | + $accounts+="$env:userdomain\$env:USERNAME" |
| 117 | + #$accounts+="$env:userdomain\Domain Admins" |
| 118 | + New-SmbShare -Name $WitnessName -Path "c:\Shares\$WitnessName" -FullAccess $accounts -CimSession $WitnessServer |
| 119 | + #Set NTFS permissions |
| 120 | + Invoke-Command -ComputerName $WitnessServer -ScriptBlock {(Get-SmbShare $using:WitnessName).PresetPathAcl | Set-Acl} |
| 121 | + #Set Quorum |
| 122 | + Set-ClusterQuorum -Cluster $ClusterName -FileShareWitness "\\$WitnessServer\$WitnessName" |
| 123 | +#endregion |
| 124 | +
|
| 125 | +#region Configure networking with NetATC https://techcommunity.microsoft.com/t5/networking-blog/network-atc-what-s-coming-in-azure-stack-hci-22h2/ba-p/3598442 |
| 126 | + #make sure NetATC,FS-SMBBW and other required features are installed on servers |
| 127 | + Invoke-Command -ComputerName $Servers -ScriptBlock { |
| 128 | + Install-WindowsFeature -Name NetworkATC,Data-Center-Bridging,RSAT-Clustering-PowerShell,RSAT-Hyper-V-Tools,FS-SMBBW |
| 129 | + } |
| 130 | +
|
| 131 | + #in virtual environment, then skip RDMA config |
| 132 | +
|
| 133 | + Import-Module NetworkATC |
| 134 | + #virtual environment (skipping RDMA config) |
| 135 | + $AdapterOverride = New-NetIntentAdapterPropertyOverrides |
| 136 | + $AdapterOverride.NetworkDirect = 0 |
| 137 | + Add-NetIntent -ClusterName $ClusterName -Name ConvergedIntent -Management -Compute -Storage -AdapterName "Ethernet","Ethernet 2" -AdapterPropertyOverrides $AdapterOverride -Verbose #-StorageVlans 1,2 |
| 138 | +
|
| 139 | +
|
| 140 | + #check |
| 141 | + Start-Sleep 20 #let intent propagate a bit |
| 142 | + Write-Output "applying intent" |
| 143 | + do { |
| 144 | + $status=Get-NetIntentStatus -ClusterName $ClusterName |
| 145 | + Write-Host "." -NoNewline |
| 146 | + Start-Sleep 5 |
| 147 | + } while ($status.ConfigurationStatus -contains "Provisioning" -or $status.ConfigurationStatus -contains "Retrying") |
| 148 | +
|
| 149 | + #remove if necessary |
| 150 | + <# |
| 151 | + Invoke-Command -ComputerName $servers[0] -ScriptBlock { |
| 152 | + $intents = Get-NetIntent |
| 153 | + foreach ($intent in $intents){ |
| 154 | + Remove-NetIntent -Name $intent.IntentName |
| 155 | + } |
| 156 | + } |
| 157 | + #> |
| 158 | +
|
| 159 | + #if deploying in VMs, some nodes might fail (quarantined state) and even CNO can go to offline ... go to cluadmin and fix |
| 160 | + #Get-ClusterNode -Cluster $ClusterName | Where-Object State -eq down | Start-ClusterNode -ClearQuarantine |
| 161 | +#endregion |
| 162 | +
|
| 163 | +#region Enable S2D |
| 164 | + #Enable-ClusterS2D |
| 165 | + Enable-ClusterS2D -CimSession $ClusterName -confirm:0 -Verbose |
| 166 | +
|
| 167 | +#endregion |
| 168 | +
|
| 169 | +#region create sample volumes |
| 170 | + #create 1TB volume on each node |
| 171 | + foreach ($Server in $Servers){ |
| 172 | + New-Volume -StoragePoolFriendlyName "S2D on $ClusterName" -FriendlyName $Server -Size 1TB -CimSession $ClusterName |
| 173 | + } |
| 174 | +
|
| 175 | + #align volumes ownership to with servers |
| 176 | + foreach ($Server in $Servers){ |
| 177 | + Move-ClusterSharedVolume -Name "Cluster Virtual Disk ($Server)" -Node $Server -Cluster $ClusterName |
| 178 | + } |
| 179 | +#endregion |
| 180 | +
|
| 181 | +
|
| 182 | +
|
| 183 | +``` |
| 184 | + |
| 185 | + |
| 186 | + |
| 187 | + |
| 188 | +## Trusted Launch for virtual machines (TVMs) |
| 189 | + |
| 190 | +More information about Trusted Launch - https://techcommunity.microsoft.com/blog/windowsservernewsandbestpractices/announcing-trusted-launch-for-virtual-machines-for-windows-server-insiders/4537082 |
| 191 | + |
| 192 | +### Enable TVM feature |
| 193 | + |
| 194 | +```PowerShell |
| 195 | +$Servers="S2D1","S2D2" |
| 196 | +
|
| 197 | +Invoke-command -ComputerName $Servers -ScriptBlock { |
| 198 | + #Set registry keys |
| 199 | + New-Item -Path "HKLM:\SOFTWARE\Microsoft\AszIgvmAgent" -Force |
| 200 | + New-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\AszIgvmAgent" -Name "TvmWinServer" -Value 1 -PropertyType DWord -Force |
| 201 | + #enable feature |
| 202 | + Enable-WindowsOptionalFeature -Online -FeatureName "IsolatedGuestVm" -NoRestart |
| 203 | +} |
| 204 | +
|
| 205 | +``` |
| 206 | + |
| 207 | +### Validate if TVM is running |
| 208 | + |
| 209 | +```PowerShell |
| 210 | + Get-Service -ComputerName $Servers -Name "IGVmAgent" |
| 211 | +
|
| 212 | +``` |
| 213 | + |
| 214 | +### Create VM |
| 215 | + |
| 216 | +```PowerShell |
| 217 | + New-VM -Name "TVMTest01" -Generation 2 -GuestStateIsolationType TrustedLaunch -SwitchName (get-virtualswitch -cimsession $Servers[0]).Name -Path C:\ClusterStorage\S2D1\ -CimSession $Servers[0] |
| 218 | + #add as Highly Available |
| 219 | + Add-ClusterVirtualMachineRole -VirtualMachine "TVMTest01" -Cluster $ClusterName |
| 220 | + #Start |
| 221 | + Start-ClusterGroup -Name "TVMTest01" -Cluster $ClusterName |
| 222 | +``` |
| 223 | + |
| 224 | + |
| 225 | + |
| 226 | +### Test TVM - disable IGVmAgent |
| 227 | + |
| 228 | +```PowerShell |
| 229 | + Invoke-Command -ComputerName $Servers -ScriptBlock { |
| 230 | + Stop-Service -Name "IGVmAgent" |
| 231 | + } |
| 232 | + #restart VM |
| 233 | + Stop-ClusterGroup -Name "TVMTest01" -Cluster $ClusterName |
| 234 | + Start-ClusterGroup -Name "TVMTest01" -Cluster $ClusterName |
| 235 | +
|
| 236 | +``` |
| 237 | + |
| 238 | + |
| 239 | + |
| 240 | +### Test TVM - enable IGVmAgent Again |
| 241 | + |
| 242 | +```PowerShell |
| 243 | + Invoke-Command -ComputerName $Servers -ScriptBlock { |
| 244 | + Start-Service -Name "IGVmAgent" |
| 245 | + } |
| 246 | + #restart VMV |
| 247 | + Start-ClusterGroup -Name "TVMTest01" -Cluster $ClusterName |
| 248 | +
|
| 249 | +``` |
| 250 | + |
| 251 | + |
| 252 | + |
| 253 | +## Quick Machine recovery |
| 254 | + |
| 255 | +https://learn.microsoft.com/en-us/windows/configuration/quick-machine-recovery/ |
| 256 | + |
| 257 | + |
| 258 | +```PowerShell |
| 259 | +#run from management machine |
| 260 | +#Enable test mode |
| 261 | +reagentc.exe /SetRecoveryTestmode |
| 262 | +#Configure Windows to boot to Windows Recovery Environment on the next boot: |
| 263 | +reagentc.exe /BootToRe |
| 264 | +#reboot machine |
| 265 | +Restart-Computer |
| 266 | +
|
| 267 | +``` |
| 268 | + |
| 269 | + |
| 270 | + |
0 commit comments