About image-based deployments for single-node OpenShift
You can manually generate a configuration ISO by using the openshift-install program. Attach the configuration ISO to your preinstalled target host to complete the deployment.
Deploying a single-node OpenShift cluster using the openshift-install program
You can use the openshift-install program to configure and deploy a host that you preinstalled with an image-based installation. To configure the target host with site-specific details, you must create the following resources:
- The
install-config.yamlinstallation manifest - The
image-based-config.yamlmanifest
The openshift-install program uses these resources to generate a configuration ISO that you attach to the preinstalled target host to complete the deployment.
For more information about the specifications for the image-based-config.yaml manifest, see "Reference specifications for the image-based-config.yaml manifest".
Prerequisites
- You preinstalled a host with single-node OpenShift using an image-based installation.
- You downloaded the latest version of the
openshift-installprogram. - You created a pull secret to authenticate pull requests. For more information, see "Using image pull secrets".
Procedure
-
Create a working directory by running the following:
$ mkdir <working_directory>where
<working_directory>is the name of your working directory, for exampleibi-config-iso-workdir. -
Create the installation manifest:
-
Create a YAML file that defines the
install-configmanifest, as in the following example:apiVersion: v1metadata:name: sno-cluster-namebaseDomain: host.example.comcompute:- architecture: amd64hyperthreading: Enabledname: workerreplicas: 0controlPlane:architecture: amd64hyperthreading: Enabledname: masterreplicas: 1networking:machineNetwork:- cidr: 192.168.200.0/24#- cidr: fd01::/64platform:none: {}fips: falsecpuPartitioningMode: "AllNodes"pullSecret: '{"auths":{"<your_pull_secret>"}}}'sshKey: 'ssh-rsa <your_ssh_pub_key>'For dual-stack networking, you can specify both IPv4 and IPv6 CIDRs using a list format in the
machineNetworkfield. The first CIDR in the list is the primary address family and must match the primary address family of the seed cluster.warningIf your cluster deployment requires a proxy configuration, you must do the following:
- Create a seed image from a seed cluster featuring a proxy configuration. The proxy configurations do not have to match.
- Configure the
machineNetworkfield in your installation manifest.
-
Save the file in your working directory.
-
-
Optional. Create a configuration template in your working directory by running the following command:
$ openshift-install image-based create config-template --dir ibi-config-iso-workdir/Example output:
INFO Config-Template created in: ibi-config-iso-workdirThe command creates the
image-based-config.yamlconfiguration template in your working directory:## Note: This is a sample ImageBasedConfig file showing# which fields are available to aid you in creating your# own image-based-config.yaml file.#apiVersion: v1beta1kind: ImageBasedConfigmetadata:name: example-image-based-configadditionalNTPSources:- 0.rhel.pool.ntp.org- 1.rhel.pool.ntp.orghostname: change-to-hostnamereleaseRegistry: quay.io# networkConfig contains the network configuration for the host in NMState format.# See https://nmstate.io/examples.html for examples.networkConfig:interfaces:- name: eth0type: ethernetstate: upmac-address: 00:00:00:00:00:00ipv4:enabled: trueaddress:- ip: 192.168.122.2prefix-length: 23dhcp: false -
Edit your configuration file: Example
image-based-config.yamlfile:## Note: This is a sample ImageBasedConfig file showing# which fields are available to aid you in creating your# own image-based-config.yaml file.#apiVersion: v1beta1kind: ImageBasedConfigmetadata:name: sno-cluster-nameadditionalNTPSources:- 0.rhel.pool.ntp.org- 1.rhel.pool.ntp.orghostname: host.example.comreleaseRegistry: quay.io# networkConfig contains the network configuration for the host in NMState format.# See https://nmstate.io/examples.html for examples.networkConfig:interfaces:- name: ens1f0type: ethernetstate: upipv4:enabled: truedhcp: falseauto-dns: falseaddress:- ip: 192.168.200.25prefix-length: 24ipv6:enabled: falsedns-resolver:config:server:- 192.168.15.47- 192.168.15.48routes:config:- destination: 0.0.0.0/0metric: 150next-hop-address: 192.168.200.254next-hop-interface: ens1f0 -
Create the configuration ISO in your working directory by running the following command:
$ openshift-install image-based create config-image --dir ibi-config-iso-workdir/Example output:
INFO Adding NMConnection file <ens1f0.nmconnection>INFO Consuming Install Config from target directoryINFO Consuming Image-based Config ISO configuration from target directoryINFO Config-Image created in: ibi-config-iso-workdir/authView the output in the working directory:
Example output:
ibi-config-iso-workdir/├── auth│ ├── kubeadmin-password│ └── kubeconfig└── imagebasedconfig.iso -
Attach the
imagebasedconfig.isoto the preinstalled host using your preferred method and restart the host to complete the configuration process and deploy the cluster.
Verification
When the configuration process completes on the host, access the cluster to verify its status.
-
Export the
kubeconfigenvironment variable to your kubeconfig file by running the following command:$ export KUBECONFIG=ibi-config-iso-workdir/auth/kubeconfig -
Verify that the cluster is responding by running the following command:
$ oc get nodesExample output:
NAME STATUS ROLES AGE VERSIONnode/sno-cluster-name.host.example.com Ready control-plane,master 5h15m v1.35.4
Additional resources
- Using image pull secrets
- Reference specifications for the
image-based-installation-config.yamlmanifest
Reference specifications for the image-based-config.yaml manifest
The following content describes the specifications for the image-based-config.yaml manifest.
The openshift-install program uses the image-based-config.yaml manifest to create a site-specific configuration ISO for image-based deployments of single-node OpenShift.
Required specifications
| Specification | Type | Description |
hostname |
string |
Define the name of the node for the single-node OpenShift cluster. |
Optional specifications
| Specification | Type | Description |
networkConfig |
string |
Specifies networking configurations for the host, for example: [source,yaml] ---- networkConfig: interfaces: - name: ens1f0 type: ethernet state: up ... ---- If you require static networking, you must install the nmstatectl library on the host that creates the live installation ISO. For further information about defining network configurations by using nmstate, see nmstate.io. [IMPORTANT] ==== The name of the interface must match the actual NIC name as shown in the operating system. ==== |
additionalNTPSources |
string |
Specifies a list of NTP sources for all cluster hosts. These NTP sources are added to any existing NTP sources in the cluster. You can use the hostname or IP address for the NTP source. |
releaseRegistry |
string |
Specifies the container image registry that you used for the release image of the seed cluster. |
nodeLabels |
map[string]string |
Specifies custom node labels for the single-node OpenShift node, for example: [source,yaml] ---- nodeLabels: node-role.kubernetes.io/edge: true environment: production ---- |
Configuring resources for extra manifests
You can optionally define additional resources in an image-based deployment for single-node OpenShift clusters.
Create the additional resources in an extra-manifests folder in the same working directory that has the install-config.yaml and image-based-config.yaml manifests.
Filenames for additional resources in the extra-manifests directory must not exceed 30 characters. Longer filenames might cause deployment failures.
The following example shows how to create a resource in the extra-manifests folder of your working directory to add an single-root I/O virtualization (SR-IOV) network to the deployment.
If you add more than one extra manifest, and the manifests must be applied in a specific order, you must prefix the filenames of the manifests with numbers that represent the required order. For example, 00-namespace.yaml, 01-sriov-extra-manifest.yaml, and so on.
Prerequisites
- You created a working directory with the
install-config.yamlandimage-based-config.yamlmanifests
Procedure
- Go to your working directory and create the
extra-manifestsfolder by running the following command:$ mkdir extra-manifests - Create the
SriovNetworkNodePolicyandSriovNetworkresources in theextra-manifestsfolder:-
Create a YAML file that defines the resources, as shown in the following example:
noteIf the cluster nodes include Intel vRAN Boost (VRB1 or VRB2) hardware, you can include a
SriovVrbClusterConfigresource in the extra manifests to configure the hardware.apiVersion: sriovnetwork.openshift.io/v1kind: SriovNetworkNodePolicymetadata:name: "example-sriov-node-policy"namespace: openshift-sriov-network-operatorspec:deviceType: vfio-pciisRdma: falsenicSelector:pfNames: [ens1f0]nodeSelector:node-role.kubernetes.io/master: ""mtu: 1500numVfs: 8priority: 99resourceName: example-sriov-node-policy---apiVersion: sriovnetwork.openshift.io/v1kind: SriovNetworkmetadata:name: "example-sriov-network"namespace: openshift-sriov-network-operatorspec:ipam: |-{}linkState: autonetworkNamespace: sriov-namespaceresourceName: example-sriov-node-policyspoofChk: "on"trust: "off"---apiVersion: sriovvrb.intel.com/v1kind: SriovVrbClusterConfigmetadata:name: confignamespace: vran-acceleration-operatorsspec:priority: 1nodeSelector:kubernetes.io/hostname: worker-nodeacceleratorSelector:pciAddress: 0000:07:00.0drainSkip: truephysicalFunction:pfDriver: vfio-pcivfDriver: vfio-pcivfAmount: 2bbDevConfig:vrb2:pfMode: falsenumVfBundles: 2maxQueueSize: 1024downlink4G:aqDepthLog2: 4numAqsPerGroups: 16numQueueGroups: 0uplink4G:aqDepthLog2: 4numAqsPerGroups: 16numQueueGroups: 0downlink5G:aqDepthLog2: 4numAqsPerGroups: 16numQueueGroups: 4uplink5G:aqDepthLog2: 4numAqsPerGroups: 16numQueueGroups: 4qfft:aqDepthLog2: 4numAqsPerGroups: 16numQueueGroups: 4qmld:aqDepthLog2: 4numAqsPerGroups: 64numQueueGroups: 4
-
Verification
- When you create the configuration ISO, you can view the reference to the extra manifests in the
.openshift_install_state.jsonfile in your working directory:"*configimage.ExtraManifests": {"FileList": [{"Filename": "extra-manifests/sriov-extra-manifest.yaml","Data": "YXBFDFFD..."}]}