Creating ConfigMap objects for the image-based upgrade with the Lifecycle Agent using GitOps ZTP
Create your OADP resources, extra manifests, and custom catalog sources wrapped in a ConfigMap object to prepare for the image-based upgrade.
Creating OADP resources for the image-based upgrade with GitOps ZTP
Prepare your OADP resources to restore your application after an upgrade.
Prerequisites
- You have provisioned one or more managed clusters with GitOps ZTP.
- You have logged in as a user with
cluster-adminprivileges. - You have generated a seed image from a compatible seed cluster.
- You have created a separate partition on the target cluster for the container images that is shared between stateroots. For more information, see "Configuring a shared container partition between ostree stateroots when using GitOps ZTP".
- You have deployed a version of Lifecycle Agent that is compatible with the version used with the seed image.
- You have installed the OADP Operator, the
DataProtectionApplicationCR, and its secret on the target cluster. - You have created an S3-compatible storage solution and a ready-to-use bucket with proper credentials configured. For more information, see "Installing and configuring the OADP Operator with GitOps ZTP".
- The
openshift-adpnamespace for the OADPConfigMapobject must exist on all managed clusters and the hub for the OADPConfigMapto be generated and copied to the clusters.
Procedure
-
Ensure that your Git repository that you use with the ArgoCD policies application contains the following directory structure:
├── source-crs/│ ├── ibu/│ │ ├── ImageBasedUpgrade.yaml│ │ ├── PlatformBackupRestore.yaml│ │ ├── PlatformBackupRestoreLvms.yaml│ │ ├── PlatformBackupRestoreWithIBGU.yaml├── ...├── kustomization.yamlThe
source-crs/ibu/PlatformBackupRestoreWithIBGU.yamlfile is provided in the ZTP container image.PlatformBackupRestoreWithIBGU.yaml
apiVersion: velero.io/v1kind: Backupmetadata:name: acm-klusterletannotations:lca.openshift.io/apply-label: "apps/v1/deployments/open-cluster-management-agent/klusterlet,v1/secrets/open-cluster-management-agent/bootstrap-hub-kubeconfig,rbac.authorization.k8s.io/v1/clusterroles/klusterlet,v1/serviceaccounts/open-cluster-management-agent/klusterlet,scheduling.k8s.io/v1/priorityclasses/klusterlet-critical,rbac.authorization.k8s.io/v1/clusterroles/open-cluster-management:klusterlet-work:ibu-role,rbac.authorization.k8s.io/v1/clusterroles/open-cluster-management:klusterlet-admin-aggregate-clusterrole,rbac.authorization.k8s.io/v1/clusterrolebindings/klusterlet,operator.open-cluster-management.io/v1/klusterlets/klusterlet,apiextensions.k8s.io/v1/customresourcedefinitions/klusterlets.operator.open-cluster-management.io,v1/secrets/open-cluster-management-agent/open-cluster-management-image-pull-credentials"labels:velero.io/storage-location: defaultnamespace: openshift-adpspec:includedNamespaces:- open-cluster-management-agentincludedClusterScopedResources:- klusterlets.operator.open-cluster-management.io- clusterroles.rbac.authorization.k8s.io- clusterrolebindings.rbac.authorization.k8s.io- priorityclasses.scheduling.k8s.ioincludedNamespaceScopedResources:- deployments- serviceaccounts- secretsexcludedNamespaceScopedResources: []---apiVersion: velero.io/v1kind: Restoremetadata:name: acm-klusterletnamespace: openshift-adplabels:velero.io/storage-location: defaultannotations:lca.openshift.io/apply-wave: "1"spec:backupName:acm-klusterletnoteIf your
multiclusterHubCR does not have.spec.imagePullSecretdefined and the secret does not exist on theopen-cluster-management-agentnamespace in your hub cluster, removev1/secrets/open-cluster-management-agent/open-cluster-management-image-pull-credentialsfrom themetadata.annotations.lca.openshift.io/apply-labelvalue in theacm-klusterletBackupCR.noteIf you perform the image-based upgrade directly on managed clusters, use the
PlatformBackupRestore.yamlfile.If you use LVM Storage to create persistent volumes, you can use the
source-crs/ibu/PlatformBackupRestoreLvms.yamlprovided in the ZTP container image to back up your LVM Storage resources.PlatformBackupRestoreLvms.yaml
apiVersion: velero.io/v1kind: Backupmetadata:labels:velero.io/storage-location: defaultname: lvmclusternamespace: openshift-adpspec:includedNamespaces:- openshift-storageincludedNamespaceScopedResources:- lvmclusters- lvmvolumegroups- lvmvolumegroupnodestatuses---apiVersion: velero.io/v1kind: Restoremetadata:name: lvmclusternamespace: openshift-adplabels:velero.io/storage-location: defaultannotations:lca.openshift.io/apply-wave: "2"spec:backupName:lvmcluster- The
lca.openshift.io/apply-wavevalue must be lower than the values specified in the applicationRestoreCRs.
- The
-
If you need to restore applications after the upgrade, create the OADP
BackupandRestoreCRs for your application in theopenshift-adpnamespace:-
Create the OADP CRs for cluster-scoped application artifacts in the
openshift-adpnamespace: Example OADP CRs for cluster-scoped application artifacts for LSO and {LVMS}apiVersion: velero.io/v1kind: Backupmetadata:annotations:lca.openshift.io/apply-label: "apiextensions.k8s.io/v1/customresourcedefinitions/test.example.com,security.openshift.io/v1/securitycontextconstraints/test,rbac.authorization.k8s.io/v1/clusterroles/test-role,rbac.authorization.k8s.io/v1/clusterrolebindings/system:openshift:scc:test"name: backup-app-cluster-resourceslabels:velero.io/storage-location: defaultnamespace: openshift-adpspec:includedClusterScopedResources:- customresourcedefinitions- securitycontextconstraints- clusterrolebindings- clusterrolesexcludedClusterScopedResources:- Namespace---apiVersion: velero.io/v1kind: Restoremetadata:name: test-app-cluster-resourcesnamespace: openshift-adplabels:velero.io/storage-location: defaultannotations:lca.openshift.io/apply-wave: "3"spec:backupName:backup-app-cluster-resources- Replace the example resource names in the
lca.openshift.io/apply-labelfield with your actual resources. - The value in the
lca.openshift.io/apply-wavefield must be higher than the value in the platformRestoreCRs and lower than the value in the application namespace-scopedRestoreCR.
- Replace the example resource names in the
-
Create the OADP CRs for your namespace-scoped application artifacts in the
source-crs/custom-crsdirectory: Example OADP CRs namespace-scoped application artifacts when LSO is usedapiVersion: velero.io/v1kind: Backupmetadata:labels:velero.io/storage-location: defaultname: backup-appnamespace: openshift-adpspec:includedNamespaces:- testincludedNamespaceScopedResources:- secrets- persistentvolumeclaims- deployments- statefulsets- configmaps- cronjobs- services- job- poddisruptionbudgets- <application_custom_resources>excludedClusterScopedResources:- persistentVolumes---apiVersion: velero.io/v1kind: Restoremetadata:name: test-appnamespace: openshift-adplabels:velero.io/storage-location: defaultannotations:lca.openshift.io/apply-wave: "4"spec:backupName:backup-app- Define custom resources for your application in the
includedNamespaceScopedResourcesfield.
Example OADP CRs namespace-scoped application artifacts when LVM Storage is used
apiVersion: velero.io/v1kind: Backupmetadata:labels:velero.io/storage-location: defaultname: backup-appnamespace: openshift-adpspec:includedNamespaces:- testincludedNamespaceScopedResources:- secrets- persistentvolumeclaims- deployments- statefulsets- configmaps- cronjobs- services- job- poddisruptionbudgets- <application_custom_resources>includedClusterScopedResources:- persistentVolumes- logicalvolumes.topolvm.io- volumesnapshotcontents---apiVersion: velero.io/v1kind: Restoremetadata:name: test-appnamespace: openshift-adplabels:velero.io/storage-location: defaultannotations:lca.openshift.io/apply-wave: "4"spec:backupName:backup-apprestorePVs: truerestoreStatus:includedResources:- logicalvolumeswhere:
<application_custom_resources>: Define custom resources for your application.persistentVolumes: Required field.logicalvolumes.topolvm.io: Required field.volumesnapshotcontents: Optional if you use LVM Storage volume snapshots.restoreStatus.includedResources: Required field for restoring logical volumes.
warningThe same version of the applications must function on both the current and the target release of OpenShift Container Platform.
- Define custom resources for your application in the
-
-
Create a
kustomization.yamlwith the following content:apiVersion: kustomize.config.k8s.io/v1beta1kind: KustomizationconfigMapGenerator:- files:- source-crs/ibu/PlatformBackupRestoreWithIBGU.yaml#- source-crs/custom-crs/ApplicationClusterScopedBackupRestore.yaml#- source-crs/custom-crs/ApplicationApplicationBackupRestoreLso.yamlname: oadp-cmnamespace: openshift-adpgeneratorOptions:disableNameSuffixHash: truewhere:
configMapGenerator- Creates the
oadp-cmConfigMapobject on the hub cluster withBackupandRestoreCRs.
namespace: openshift-adp- The namespace must exist on all managed clusters and the hub for the OADP
ConfigMapto be generated and copied to the clusters.
- Push the changes to your Git repository.
Additional resources
- Configuring a shared container partition between ostree stateroots when using GitOps ZTP
- Installing and configuring the OADP Operator with GitOps ZTP
Labeling extra manifests for the image-based upgrade with GitOps ZTP
Label your extra manifests so that the Lifecycle Agent can extract resources that are labeled with the lca.openshift.io/target-ocp-version: <target_version> label.
Prerequisites
- You have provisioned one or more managed clusters with GitOps ZTP.
- You have logged in as a user with
cluster-adminprivileges. - You have generated a seed image from a compatible seed cluster.
- You have created a separate partition on the target cluster for the container images that is shared between stateroots. For more information, see "Configuring a shared container directory between ostree stateroots when using GitOps ZTP".
- You have deployed a version of Lifecycle Agent that is compatible with the version used with the seed image.
Procedure
-
Label your required extra manifests with the
lca.openshift.io/target-ocp-version: <target_version>label in your existing sitePolicyGenTemplateCR:apiVersion: ran.openshift.io/v1kind: PolicyGenTemplatemetadata:name: example-snospec:bindingRules:sites: "example-sno"du-profile: "4.15"mcp: "master"sourceFiles:- fileName: SriovNetwork.yamlpolicyName: "config-policy"metadata:name: "sriov-nw-du-fh"labels:lca.openshift.io/target-ocp-version: "4.15"spec:resourceName: du_fhvlan: 140- fileName: SriovNetworkNodePolicy.yamlpolicyName: "config-policy"metadata:name: "sriov-nnp-du-fh"labels:lca.openshift.io/target-ocp-version: "4.15"spec:deviceType: netdeviceisRdma: falsenicSelector:pfNames: ["ens5f0"]numVfs: 8priority: 10resourceName: du_fh- fileName: SriovNetwork.yamlpolicyName: "config-policy"metadata:name: "sriov-nw-du-mh"labels:lca.openshift.io/target-ocp-version: "4.15"spec:resourceName: du_mhvlan: 150- fileName: SriovNetworkNodePolicy.yamlpolicyName: "config-policy"metadata:name: "sriov-nnp-du-mh"labels:lca.openshift.io/target-ocp-version: "4.15"spec:deviceType: vfio-pciisRdma: falsenicSelector:pfNames: ["ens7f0"]numVfs: 8priority: 10resourceName: du_mh- fileName: DefaultCatsrc.yamlpolicyName: "config-policy"metadata:name: default-cat-sourcenamespace: openshift-marketplacelabels:lca.openshift.io/target-ocp-version: "4.15"spec:displayName: default-cat-sourceimage: quay.io/example-org/example-catalog:v1where:
lca.openshift.io/target-ocp-version- Ensure that this label matches either the y-stream or the z-stream of the target OpenShift Container Platform version that is specified in the
spec.seedImageRef.versionfield of theImageBasedUpgradeCR. The Lifecycle Agent only applies the CRs that match the specified version.
DefaultCatsrc.yaml- If you do not want to use custom catalog sources, remove this entry.
- Push the changes to your Git repository.
Additional resources