Installing a cluster on Google Cloud in a disconnected environment with user-provisioned infrastructure¶
In OpenShift Container Platform version 4.22, you can install a cluster on Google Cloud that uses infrastructure that you provide and an internal mirror of the installation release content.
Warning
While you can install an OpenShift Container Platform cluster by using mirrored installation release content, your cluster still requires internet access to use the Google Cloud APIs.
The steps for performing a user-provided infrastructure install are outlined here. Several Infrastructure Manager templates are provided to assist in completing these steps or to help model your own. You are also free to create the required resources through other methods.
Warning
The steps for performing a user-provisioned infrastructure installation are provided as an example only. Installing a cluster with infrastructure you provide requires knowledge of the cloud provider and the installation process of OpenShift Container Platform. Several Infrastructure Manager templates are provided to assist in completing these steps or to help model your own. You are also free to create the required resources through other methods; the templates are just an example.
Prerequisites¶
-
You reviewed details about the OpenShift Container Platform installation and update processes. For more information, see "Installation and update".
-
You read the documentation on selecting a cluster installation method and preparing it for users. For more information, see "Selecting a cluster installation method and preparing it for users".
-
You created a registry on your mirror host and obtained the
imageContentSourcesdata for your version of OpenShift Container Platform. For more information, see "Mirroring images for a disconnected installation".Warning
Because the installation media is on the mirror host, you can use that computer to complete all installation steps.
-
If you use a firewall, you configured it to allow the sites that your cluster requires access to. While you might need to grant access to more sites, you must grant access to
*.googleapis.comandaccounts.google.com. For more information, see "Configuring your firewall for OpenShift Container Platform". -
If the cloud identity and access management (IAM) APIs are not accessible in your environment, or if you do not want to store an administrator-level credential secret in the
kube-systemnamespace, you can manually create and maintain long-term credentials. For more information, see "Manually creating long-term credentials".
Additional resources
- Installation and update
- Selecting a cluster installation method and preparing it for users
- Mirroring images for a disconnected installation
- Configuring your firewall for OpenShift Container Platform
- Manually creating long-term credentials
About installations in restricted networks¶
You can install OpenShift Container Platform 4.22 in a restricted network without an active internet connection to obtain software components. Restricted network installations can use installer-provisioned or user-provisioned infrastructure, depending on the cloud platform to which you are installing the cluster.
If you choose to perform a restricted network installation on a cloud platform, you still require access to its cloud APIs. Some cloud functions, such as Amazon Web Service’s Route 53 DNS and IAM services, require internet access. Depending on your network, you might require less internet access for an installation on bare-metal hardware, Nutanix, or on VMware vSphere.
To complete a restricted network installation, you must create a registry that mirrors the contents of the OpenShift image registry and contains the installation media. You can create this registry on a mirror host, which can access both the internet and your closed network, or by using other methods that meet your restrictions.
Warning
Because of the complexity of the configuration for user-provisioned installations, consider completing a standard user-provisioned infrastructure installation before you try a restricted network installation using user-provisioned infrastructure. Completing this test installation might make it easier to isolate and troubleshoot any issues that might arise during your installation in a restricted network.
Additional limits¶
Clusters in restricted networks have the following additional limitations and restrictions:
- The
ClusterVersionstatus includes anUnable to retrieve available updateserror. - By default, you cannot use the contents of the Developer Catalog because you cannot access the required image stream tags.
Internet access for OpenShift Container Platform¶
In OpenShift Container Platform 4.22, you require access to the internet to obtain the images that are necessary to install your cluster.
You must have internet access to perform the following actions:
- Access Red Hat Hybrid Cloud Console to download the installation program and perform subscription management. If the cluster has internet access and you do not disable Telemetry, that service automatically entitles your cluster.
- Access Quay.io to obtain the packages that are required to install your cluster.
- Obtain the packages that are required to perform cluster updates.
Configuring your Google Cloud project¶
Before you can install OpenShift Container Platform, you must configure a Google Cloud project to host it. Proper project configuration provides the API services, service account, and permissions that the installation requires.
Creating a Google Cloud project¶
To install OpenShift Container Platform, you must create a project in your Google Cloud account to host the cluster.
Procedure
-
Create a project to host your OpenShift Container Platform cluster. See Creating and Managing Projects in the Google Cloud documentation.
Warning
Your Google Cloud project must use the Premium Network Service Tier if you are using installer-provisioned infrastructure. The Standard Network Service Tier is not supported for clusters installed using the installation program. The installation program configures internal load balancing for the
api-int.<cluster_name>.<base_domain>URL; the Premium Tier is required for internal load balancing.
Enabling API services in Google Cloud¶
You must enable several API services in your Google Cloud project to complete OpenShift Container Platform installation.
Prerequisites
- You created a project to host your cluster.
Procedure
-
Enable the following required API services in the project that hosts your cluster. You can also enable optional API services which are not required for installation. See Enabling services in the Google Cloud documentation.
Required API services
| API service | Console service name |
|---|---|
| Compute Engine API | compute.googleapis.com |
| Cloud Resource Manager API | cloudresourcemanager.googleapis.com |
| Cloud DNS API | dns.googleapis.com |
| IAM Service Account Credentials API | iamcredentials.googleapis.com |
| Identity and Access Management (IAM) API | iam.googleapis.com |
| Service Usage API | serviceusage.googleapis.com |
| API service | Console service name |
|---|---|
| Google Cloud APIs | cloudapis.googleapis.com |
| Service Management API | servicemanagement.googleapis.com |
| Google Cloud Storage JSON API | storage-api.googleapis.com |
| Cloud Storage | storage-component.googleapis.com |
Configuring DNS for Google Cloud¶
Configure a public hosted zone in your Google Cloud account to provide DNS resolution and name lookup for your OpenShift Container Platform cluster.
To install OpenShift Container Platform, the Google Cloud account you use must have a dedicated public hosted zone in the same project that you host the OpenShift Container Platform cluster. This zone must be authoritative for the domain. The DNS service provides cluster DNS resolution and name lookup for external connections to the cluster.
Procedure
-
Identify your domain, or subdomain, and registrar. You can transfer an existing domain and registrar or obtain a new one through Google Cloud or another source.
Note
If you purchase a new domain, it can take time for the relevant DNS changes to propagate. For more information about purchasing domains through Google, see Google Domains.
-
Create a public hosted zone for your domain or subdomain in your Google Cloud project. See Creating public zones in the Google Cloud documentation.
Use an appropriate root domain, such as
openshiftcorp.com, or subdomain, such asclusters.openshiftcorp.com. -
Extract the new authoritative name servers from the hosted zone records. See Look up your Cloud DNS name servers in the Google Cloud documentation.
You typically have four name servers.
-
Update the registrar records for the name servers that your domain uses. For example, if you registered your domain to Google Domains, see the following topic in the Google Domains Help: How to switch to custom name servers.
-
If you migrated your root domain to Google Cloud DNS, migrate your DNS records. See Migrating to Cloud DNS in the Google Cloud documentation.
-
If you use a subdomain, follow your company’s procedures to add its delegation records to the parent domain. This process might include a request to your company’s IT department or the division that controls the root domain and DNS services for your company.
Google Cloud account limits¶
A default OpenShift Container Platform cluster consumes specific Google Cloud resource quotas that you might need to increase before installation, depending on your region and cluster size.
A default cluster, which contains three compute and three control plane machines, uses the following resources. Note that some resources are required only during the bootstrap process and are removed after the cluster deploys.
Google Cloud resources used in a default cluster
| Service | Component | Location | Total resources required | Resources removed after bootstrap |
|---|---|---|---|---|
| Service account | IAM | Global | 6 | 1 |
| Firewall rules | Networking | Global | 11 | 1 |
| Forwarding rules | Compute | Global | 2 | 0 |
| Health checks | Compute | Global | 2 | 0 |
| Images | Compute | Global | 1 | 0 |
| Networks | Networking | Global | 1 | 0 |
| Routers | Networking | Global | 1 | 0 |
| Routes | Networking | Global | 2 | 0 |
| Subnetworks | Compute | Global | 2 | 0 |
| Target pools | Networking | Global | 2 | 0 |
Note
If any of the quotas are insufficient during installation, the installation program displays an error that states both which quota was exceeded and the region.
Be sure to consider your actual cluster size, planned cluster growth, and any usage from other clusters that are associated with your account. The CPU, static IP addresses, and persistent disk SSD (storage) quotas are the ones that are most likely to be insufficient.
If you plan to deploy your cluster in one of the following regions, you will exceed the maximum storage quota and are likely to exceed the CPU quota limit:
asia-east2asia-northeast2asia-south1australia-southeast1europe-north1europe-west2europe-west3europe-west6northamerica-northeast1southamerica-east1us-west2
You can increase resource quotas from the Google Cloud console, but you might need to file a support ticket. Be sure to plan your cluster size early so that you can allow time to resolve the support ticket before you install your OpenShift Container Platform cluster.
Additional resources
Creating a service account in Google Cloud¶
OpenShift Container Platform requires a Google Cloud service account that provides authentication and authorization to access data in the Google APIs. If you do not have an existing IAM service account that contains the required roles in your project, you must create one.
Note
To reduce the scope of permissions granted to the main service account in your Google Cloud project while still being able to use the Google Cloud Container Storage Interface (CSI) Driver Operator, you can transfer the control of permissions from the project-wide service account to the control plane and compute node service accounts instead, thus reducing the scope of the permission. For more information, see Section Reducing permissions while using the Google Cloud CSI Driver Operator.
Prerequisites
- You created a project to host your cluster.
Procedure
-
Create a service account in the project that you use to host your OpenShift Container Platform cluster. See Creating a service account in the Google Cloud documentation.
-
Grant the service account the appropriate permissions. You can either grant the individual permissions that follow or assign the
Ownerrole to it. See Granting roles to a service account for specific resources.Note
While making the service account an owner of the project is the easiest way to gain the required permissions, it means that service account has complete control over the project. You must determine if the risk that comes from offering that power is acceptable.
-
You can create the service account key in JSON format, or attach the service account to a Google Cloud virtual machine. See Creating service account keys and Creating and enabling service accounts for instances in the Google Cloud documentation.
Note
If you use a virtual machine with an attached service account to create your cluster, you must set
credentialsMode: Manualin theinstall-config.yamlfile before installation.
Required Google Cloud roles¶
Your Google Cloud service account requires specific roles to install and manage an OpenShift Container Platform cluster, which you can scope based on your organization’s security requirements.
When you attach the Owner role to the service account that you create, you grant that service account all permissions, including those that are required to install OpenShift Container Platform. If your organization’s security policies require a more restrictive set of permissions, you can create a service account with the following permissions. If you deploy your cluster into an existing virtual private cloud (VPC), the service account does not require certain networking permissions, which are noted in the following lists:
The installation program requires the following roles:
- Compute Admin
- Role Administrator
- Security Admin
- Service Account Admin
- Service Account Key Admin
- Service Account User
- Storage Admin
Creating network resources during installation requires the following role:
- DNS Administrator
Using the Cloud Credential Operator in passthrough mode requires the following roles:
- Compute Load Balancer Admin
- Tag User
User-provisioned Google Cloud infrastructure requires the following role:
- Cloud Infrastructure Manager Admin
The following roles are applied to the service accounts that the control plane and compute machines use:
Google Cloud service account roles
| Account | Roles |
|---|---|
| Control Plane | roles/compute.instanceAdmin |
roles/compute.networkAdmin |
|
roles/compute.securityAdmin |
|
roles/storage.admin |
|
roles/iam.serviceAccountUser |
|
| Compute | roles/compute.viewer |
roles/storage.admin |
|
roles/artifactregistry.reader |
Required Google Cloud permissions for user-provisioned infrastructure¶
Your Google Cloud service account requires permissions to create and manage user-provisioned OpenShift Container Platform infrastructure. You can attach the Owner role to grant all permissions, or create a custom role with only the minimum permissions your organization’s security policies require.
If your organization’s security policies require a more restrictive set of permissions, you can create custom roles with the necessary permissions. The following permissions are required for the user-provisioned infrastructure for creating and deleting the OpenShift Container Platform cluster.
The following permissions are required for creating network resources:
compute.addresses.createcompute.addresses.createInternalcompute.addresses.deletecompute.addresses.getcompute.addresses.listcompute.addresses.usecompute.addresses.useInternalcompute.firewalls.createcompute.firewalls.deletecompute.firewalls.getcompute.firewalls.listcompute.forwardingRules.createcompute.forwardingRules.getcompute.forwardingRules.listcompute.forwardingRules.setLabelscompute.globalAddresses.createcompute.globalAddresses.getcompute.globalAddresses.usecompute.globalForwardingRules.createcompute.globalForwardingRules.getcompute.globalForwardingRules.setLabelscompute.networks.createcompute.networks.getcompute.networks.listcompute.networks.updatePolicycompute.networks.usecompute.routers.createcompute.routers.getcompute.routers.listcompute.routers.updatecompute.routes.listcompute.subnetworks.createcompute.subnetworks.getcompute.subnetworks.listcompute.subnetworks.usecompute.subnetworks.useExternalIp
The following permissions are required for creating load balancer resources:
compute.backendServices.createcompute.backendServices.getcompute.backendServices.listcompute.backendServices.updatecompute.backendServices.usecompute.regionBackendServices.createcompute.regionBackendServices.getcompute.regionBackendServices.listcompute.regionBackendServices.updatecompute.regionBackendServices.usecompute.targetPools.addInstancecompute.targetPools.createcompute.targetPools.getcompute.targetPools.listcompute.targetPools.removeInstancecompute.targetPools.usecompute.targetTcpProxies.createcompute.targetTcpProxies.getcompute.targetTcpProxies.use
The following permissions are required for creating DNS resources:
dns.changes.createdns.changes.getdns.managedZones.createdns.managedZones.getdns.managedZones.listdns.networks.bindPrivateDNSZonedns.resourceRecordSets.createdns.resourceRecordSets.listdns.resourceRecordSets.update
The following permissions are required for creating Service Account resources:
iam.serviceAccountKeys.createiam.serviceAccountKeys.deleteiam.serviceAccountKeys.getiam.serviceAccountKeys.listiam.serviceAccounts.actAsiam.serviceAccounts.createiam.serviceAccounts.deleteiam.serviceAccounts.getiam.serviceAccounts.listresourcemanager.projects.getresourcemanager.projects.getIamPolicyresourcemanager.projects.setIamPolicy
The following permissions are required for creating compute resources:
compute.disks.createcompute.disks.getcompute.disks.listcompute.instanceGroups.createcompute.instanceGroups.deletecompute.instanceGroups.getcompute.instanceGroups.listcompute.instanceGroups.updatecompute.instanceGroups.usecompute.instances.createcompute.instances.deletecompute.instances.getcompute.instances.listcompute.instances.setLabelscompute.instances.setMetadatacompute.instances.setServiceAccountcompute.instances.setTagscompute.instances.usecompute.machineTypes.getcompute.machineTypes.list
The following permissions are required for creating storage resources:
storage.buckets.createstorage.buckets.deletestorage.buckets.getstorage.buckets.liststorage.objects.createstorage.objects.deletestorage.objects.getstorage.objects.list
The following permissions are required for creating health check resources:
compute.healthChecks.createcompute.healthChecks.getcompute.healthChecks.listcompute.healthChecks.useReadOnlycompute.httpHealthChecks.createcompute.httpHealthChecks.getcompute.httpHealthChecks.listcompute.httpHealthChecks.useReadOnlycompute.regionHealthChecks.createcompute.regionHealthChecks.getcompute.regionHealthChecks.useReadOnly
The following permissions are required to get Google Cloud zone and region related information:
compute.globalOperations.getcompute.regionOperations.getcompute.regions.getcompute.regions.listcompute.zoneOperations.getcompute.zones.getcompute.zones.list
The following permissions are required for checking services and quotas:
monitoring.timeSeries.listserviceusage.quotas.getserviceusage.services.list
The following IAM permission is required for installation:
iam.roles.get
The following permission is required when authenticating without a service account key:
iam.serviceAccounts.signBlob
The following permission is required when providing Key Management Service (KMS) key rings:
cloudkms.keyRings.list
The following Images permissions are required for installation:
compute.images.createcompute.images.deletecompute.images.getcompute.images.list
The following permission is optional for running gather bootstrap:
compute.instances.getSerialPortOutput
The following permissions are required for deleting network resources:
compute.addresses.deletecompute.addresses.deleteInternalcompute.addresses.listcompute.addresses.setLabelscompute.firewalls.deletecompute.firewalls.listcompute.forwardingRules.deletecompute.forwardingRules.listcompute.globalAddresses.deletecompute.globalAddresses.listcompute.globalForwardingRules.deletecompute.globalForwardingRules.listcompute.networks.deletecompute.networks.listcompute.networks.updatePolicycompute.routers.deletecompute.routers.listcompute.routes.listcompute.subnetworks.deletecompute.subnetworks.list
The following permissions are required for deleting load balancer resources:
compute.backendServices.deletecompute.backendServices.listcompute.regionBackendServices.deletecompute.regionBackendServices.listcompute.targetPools.deletecompute.targetPools.listcompute.targetTcpProxies.deletecompute.targetTcpProxies.list
The following permissions are required for deleting DNS resources:
dns.changes.createdns.managedZones.deletedns.managedZones.getdns.managedZones.listdns.resourceRecordSets.deletedns.resourceRecordSets.list
The following permissions are required for deleting Service Account resources:
iam.serviceAccounts.deleteiam.serviceAccounts.getiam.serviceAccounts.listresourcemanager.projects.getIamPolicyresourcemanager.projects.setIamPolicy
The following permissions are required for deleting compute resources:
compute.disks.deletecompute.disks.listcompute.instanceGroups.deletecompute.instanceGroups.listcompute.instances.deletecompute.instances.listcompute.instances.stopcompute.machineTypes.list
The following permissions are required for deleting storage resources:
storage.buckets.deletestorage.buckets.getIamPolicystorage.buckets.liststorage.objects.deletestorage.objects.list
The following permissions are required for deleting health check resources:
compute.healthChecks.deletecompute.healthChecks.listcompute.httpHealthChecks.deletecompute.httpHealthChecks.listcompute.regionHealthChecks.deletecompute.regionHealthChecks.list
The following Images permissions are required for deletion:
compute.images.deletecompute.images.list
The following permission is required to get Region related information:
compute.regions.get
The following Deployment Manager permissions are required:
- config.deployments.create
- config.deployments.delete
- config.deployments.get
- config.deployments.list
- config.operations.get
- config.resources.list
- cloudbuild.builds.create
- cloudbuild.builds.get
Additional resources
Supported Google Cloud regions¶
You can deploy an OpenShift Container Platform cluster to specific Google Cloud regions, which determine the physical location and available machine types for your cluster infrastructure.
You can deploy to the following Google Cloud regions:
africa-south1(Johannesburg, South Africa)asia-east1(Changhua County, Taiwan)asia-east2(Hong Kong)asia-northeast1(Tokyo, Japan)asia-northeast2(Osaka, Japan)asia-northeast3(Seoul, South Korea)asia-south1(Mumbai, India)asia-south2(Delhi, India)asia-southeast1(Jurong West, Singapore)asia-southeast2(Jakarta, Indonesia)australia-southeast1(Sydney, Australia)australia-southeast2(Melbourne, Australia)europe-central2(Warsaw, Poland)europe-north1(Hamina, Finland)europe-southwest1(Madrid, Spain)europe-west1(St. Ghislain, Belgium)europe-west2(London, England, UK)europe-west3(Frankfurt, Germany)europe-west4(Eemshaven, Netherlands)europe-west6(Zürich, Switzerland)europe-west8(Milan, Italy)europe-west9(Paris, France)europe-west12(Turin, Italy)me-central1(Doha, Qatar, Middle East)me-central2(Dammam, Saudi Arabia, Middle East)me-west1(Tel Aviv, Israel)northamerica-northeast1(Montréal, Québec, Canada)northamerica-northeast2(Toronto, Ontario, Canada)southamerica-east1(São Paulo, Brazil)southamerica-west1(Santiago, Chile)us-central1(Council Bluffs, Iowa, USA)us-east1(Moncks Corner, South Carolina, USA)us-east4(Ashburn, Northern Virginia, USA)us-east5(Columbus, Ohio)us-south1(Dallas, Texas)us-west1(The Dalles, Oregon, USA)us-west2(Los Angeles, California, USA)us-west3(Salt Lake City, Utah, USA)us-west4(Las Vegas, Nevada, USA)
Note
To determine which machine type instances are available by region and zone, see the Google documentation.
Installing and configuring CLI tools for Google Cloud¶
Before you deploy OpenShift Container Platform on Google Cloud with user-provisioned infrastructure, you must set up the required CLI tools to create and manage your cloud resources.
Prerequisites
- You created a project to host your cluster.
- You created a service account and granted it the required permissions.
Procedure
-
Install the following binaries in
$PATH:gcloudgsutil
See Install the latest Cloud SDK version in the Google Cloud documentation.
-
Authenticate using the
gcloudtool with your configured service account.See Authorizing with a service account in the Google Cloud documentation.
Requirements for a cluster with user-provisioned infrastructure¶
For a cluster that contains user-provisioned infrastructure, you must deploy all of the required machines. Reviewing these requirements before deployment helps you provision machines that meet the minimum resource needs of the cluster.
Required machines for cluster installation¶
You must specify the minimum required machines or hosts for your cluster so that your cluster remains stable if a node fails.
The smallest OpenShift Container Platform clusters require the following hosts:
Warning
For a cluster that has user-provisioned infrastructure, you must deploy all of the required machines.
Minimum required hosts
| Hosts | Description |
|---|---|
| One temporary bootstrap machine | The cluster requires the bootstrap machine to deploy the OpenShift Container Platform cluster on the three control plane machines. You can remove the bootstrap machine after you install the cluster. |
| Three control plane machines | The control plane machines run the Kubernetes and OpenShift Container Platform services that form the control plane. |
| At least two compute machines, which are also known as worker machines. | The workloads requested by OpenShift Container Platform users run on the compute machines. |
Warning
To maintain high availability of your cluster, use separate physical hosts for these cluster machines.
The bootstrap and control plane machines must use Red Hat Enterprise Linux CoreOS (RHCOS) as the operating system. However, the compute machines can use Red Hat Enterprise Linux CoreOS (RHCOS), Red Hat Enterprise Linux (RHEL) 8.6 and later.
RHCOS is based on Red Hat Enterprise Linux (RHEL) 9.8 and inherits all of its hardware certifications and requirements. See Red Hat Enterprise Linux technology capabilities and limits.
Minimum resource requirements for cluster installation¶
To ensure that your OpenShift Container Platform cluster runs as expected, each cluster machine must meet minimum CPU, memory, and storage requirements.
Minimum resource requirements
| Machine | Operating system | vCPU | Virtual RAM | Storage | Input/Output Per Second (IOPS) |
|---|---|---|---|---|---|
| Bootstrap | RHCOS | 4 | 16 GB | 100 GB | 300 |
| Control plane | RHCOS | 4 | 16 GB | 100 GB | 300 |
| Compute | RHCOS | 2 | 8 GB | 100 GB | 300 |
- One vCPU is equal to one physical core when simultaneous multithreading (SMT), or Hyper-Threading, is not enabled. When enabled, use the following formula to calculate the corresponding ratio: (threads per core × cores) × sockets = vCPUs.
- OpenShift Container Platform and Kubernetes are sensitive to disk performance, and Red Hat recommends faster storage, particularly for etcd on the control plane nodes which require a 10 ms p99 fsync duration. On many cloud platforms, storage size and IOPS scale together, so you might need to provision more storage to get enough performance.
- As with all user-provisioned installations, if you choose to use RHEL compute machines in your cluster, you take responsibility for all operating system life cycle management and maintenance, including performing system updates, applying patches, and completing all other required tasks. OpenShift Container Platform 4.10 and later do not support RHEL 7 compute machines.
Note
In OpenShift Container Platform version 4.22, RHCOS uses RHEL version 9.8, which updates the micro-architecture requirements. Each architecture requires the following minimum instruction set architectures (ISA):
- x86-64 architecture requires x86-64-v2 ISA
- ARM64 architecture requires ARMv8.0-A ISA
- ppc64le architecture requires IBM(R) Power9 ISA
- s390x architecture requires IBM(R) z14 ISA
For more information, see Architectures in the RHEL documentation.
If an instance type for your platform meets the minimum requirements for cluster machines, it is supported to use in OpenShift Container Platform.
Tested instance types for Google Cloud¶
OpenShift Container Platform supports specific Google Cloud instance types that have been validated for cluster deployment.
Note
Not all instance types are available in all regions and zones. For a detailed breakdown of which instance types are available in which zones, see regions and zones (Google documentation).
Some instance types require the use of Hyperdisk storage. If you use an instance type that requires Hyperdisk storage, all of the nodes in your cluster must support Hyperdisk storage, and you must change the default storage class to use Hyperdisk storage. For more information, see machine series support for Hyperdisk (Google documentation). For instructions on modifying storage classes, see the "GCE PersistentDisk (gcePD) object definition" section in the Dynamic Provisioning page in Storage.
See the following machine series:
A2A3C2C2DC3C3DC4E2M1N1N2N2DN4Tau T2D
Using custom machine types¶
If the predefined Google Cloud machine types do not meet your workload requirements, you can configure a custom machine type in the install-config.yaml file during OpenShift Container Platform installation.
Consider the following when using a custom machine type:
-
Similar to predefined instance types, custom machine types must meet the minimum resource requirements for control plane and compute machines. For more information, see "Minimum resource requirements for cluster installation".
-
The name of the custom machine type must adhere to the following syntax:
custom-<number_of_cpus>-<amount_of_memory_in_mb>For example,
custom-6-20480.
Creating the installation files for Google Cloud¶
To install OpenShift Container Platform on Google Cloud by using user-provisioned infrastructure, you must generate the files that the installation program needs to deploy your cluster and modify them so that the cluster creates only the machines that it will use.
You generate and customize the install-config.yaml file, Kubernetes manifests, and Ignition config files. You also have the option to first set up a separate var partition during the preparation phases of installation.
Creating a separate /var partition¶
To isolate growing storage for containers, etcd, or logs, you can optionally create a separate /var partition on worker nodes before you generate Ignition configs.
It is recommended that disk partitioning for OpenShift Container Platform be left to the installation program. However, there are cases where you might want to create separate partitions in a part of the filesystem that you expect to grow.
OpenShift Container Platform supports the addition of a single partition to attach storage to either the /var partition or a subdirectory of /var. For example:
/var/lib/containers: Holds container-related content that can grow as more images and containers are added to a system./var/lib/etcd: Holds data that you might want to keep separate for purposes such as performance optimization of etcd storage./var: Holds data that you might want to keep separate for purposes such as auditing.
Storing the contents of a /var directory separately makes it easier to grow storage for those areas as needed and reinstall OpenShift Container Platform at a later date and keep that data intact. With this method, you will not have to pull all your containers again, nor will you have to copy massive log files when you update systems.
Because /var must be in place before a fresh installation of Red Hat Enterprise Linux CoreOS (RHCOS), the following procedure sets up the separate /var partition by creating a machine config manifest that is inserted during the openshift-install preparation phases of an OpenShift Container Platform installation.
Warning
If you follow the steps to create a separate /var partition in this procedure, it is not necessary to create the Kubernetes manifest and Ignition config files again as described later in this section.
Procedure
-
Create a directory to hold the OpenShift Container Platform installation files:
-
Run
openshift-installto create a set of files in themanifestandopenshiftsubdirectories. Answer the system questions as you are prompted: -
Optional: Confirm that the installation program created manifests in the
clusterconfig/openshiftdirectory: -
Create a Butane config that configures the additional partition. For example, name the file
$HOME/clusterconfig/98-var-partition.bu, change the disk device name to the name of the storage device on theworkersystems, and set the storage size as appropriate. This example places the/vardirectory on a separate partition:variant: openshift version: 4.22.0 metadata: labels: machineconfiguration.openshift.io/role: worker name: 98-var-partition storage: disks: - device: /dev/disk/by-id/<device_name> partitions: - label: var start_mib: <partition_start_offset> size_mib: <partition_size> number: 5 filesystems: - device: /dev/disk/by-partlabel/var path: /var format: xfs mount_options: [defaults, prjquota] with_mount_unit: truewhere:
<device_name>- Specifies the storage device name of the disk that you want to partition.
<partition_start_offset>- Specifies the
start_mibparameter. When adding a data partition to the boot disk, a minimum value of 25000 MiB (Mebibytes) is recommended. The root file system is automatically resized to fill all available space up to the specified offset. If no value is specified, or if the specified value is smaller than the recommended minimum, the resulting root file system will be too small, and future reinstalls of RHCOS might overwrite the beginning of the data partition. <partition_size>- Specifies the size of the data partition in mebibytes.
storage.filesystems.mount_options- The
prjquotamount option must be enabled for filesystems used for container storage.
Note
When creating a separate
/varpartition, you cannot use different instance types for worker nodes, if the different instance types do not have the same device name. -
Create a manifest from the Butane config and save it to the
clusterconfig/openshiftdirectory. For example, run the following command: -
Run
openshift-installagain to create Ignition configs from a set of files in themanifestandopenshiftsubdirectories:You can now use the Ignition config files as input to the installation procedures to install Red Hat Enterprise Linux CoreOS (RHCOS) systems.
Creating the installation configuration file¶
You can customize the OpenShift Container Platform cluster you install on Google Cloud.
Prerequisites
- You have the OpenShift Container Platform installation program and the pull secret for your cluster. For a restricted network installation, these files are on your mirror host.
- You have the
imageContentSourcesvalues that were generated during mirror registry creation. - You have obtained the contents of the certificate for your mirror registry.
- Configure a Google Cloud account.
Procedure
-
Create the
install-config.yamlfile.-
Change to the directory that contains the installation program and run the following command:
-
<installation_directory>: For<installation_directory>, specify the directory name to store the files that the installation program creates.When specifying the directory:
-
Verify that the directory has the
executepermission. This permission is required to run Terraform binaries under the installation directory. -
Use an empty directory. Some installation assets, such as bootstrap X.509 certificates, have short expiration intervals, therefore you must not reuse an installation directory. If you want to reuse individual files from another cluster installation, you can copy them into your directory. However, the file names for the installation assets might change between releases. Use caution when copying installation files from an earlier OpenShift Container Platform version.
-
-
At the prompts, provide the configuration details for your cloud:
-
Optional: Select an SSH key to use to access your cluster machines.
Note
For production OpenShift Container Platform clusters on which you want to perform installation debugging or disaster recovery, specify an SSH key that your
ssh-agentprocess uses. -
Select gcp as the platform to target.
-
If you have not configured the service account key for your Google Cloud account on your computer, you must obtain it from Google Cloud and paste the contents of the file or enter the absolute path to the file.
-
Select the project ID to provision the cluster in. The default value is specified by the service account that you configured.
-
Select the region to deploy the cluster to.
-
Select the base domain to deploy the cluster to. The base domain corresponds to the public DNS zone that you created for your cluster.
-
Enter a descriptive name for your cluster.
-
-
-
Edit the
install-config.yamlfile to give the additional information that is required for an installation in a restricted network.-
Update the
pullSecretvalue to contain the authentication information for your registry:pullSecret: '{"auths":{"<mirror_host_name>:5000": {"auth": "<credentials>","email": "you@example.com"}}}'For
<mirror_host_name>, specify the registry domain name that you specified in the certificate for your mirror registry, and for<credentials>, specify the base64-encoded user name and password for your mirror registry. -
Add the
additionalTrustBundleparameter and value.additionalTrustBundle: | -----BEGIN CERTIFICATE----- ZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZ -----END CERTIFICATE-----The value must be the contents of the certificate file that you used for your mirror registry. The certificate file can be an existing, trusted certificate authority, or the self-signed certificate that you generated for the mirror registry.
-
Add the image content resources, which resemble the following YAML excerpt:
imageContentSources: - mirrors: - <mirror_host_name>:5000/<repo_name>/release source: quay.io/openshift-release-dev/ocp-release - mirrors: - <mirror_host_name>:5000/<repo_name>/release source: registry.redhat.io/ocp/releaseFor these values, use the
imageContentSourcesthat you recorded during mirror registry creation. -
Optionally, set the publishing strategy to
Internal:By setting this option, you create an internal Ingress Controller and a private load balancer.
-
-
Make any other modifications to the
install-config.yamlfile that you require.For more information about the parameters, see "Installation configuration parameters".
-
Back up the
install-config.yamlfile so that you can use it to install multiple clusters.Warning
The
install-config.yamlfile is consumed during the installation process. If you want to reuse the file, you must back it up now.
Additional resources
Enabling Shielded VMs¶
You can use Shielded VMs when installing your OpenShift Container Platform cluster. Shielded VMs have extra security features including secure boot, firmware and integrity monitoring, and rootkit detection.
For more information, see Google’s documentation on Shielded VMs.
Note
Shielded VMs are currently not supported on clusters with 64-bit ARM infrastructures.
Procedure
-
Use a text editor to edit the
install-config.yamlfile before deploying your cluster and add one of the following stanzas:-
To use shielded VMs for only control plane machines:
-
To use shielded VMs for only compute machines:
-
To use shielded VMs for all machines:
-
Enable Confidential VMs¶
You can use Confidential VMs when installing your OpenShift Container Platform cluster. Confidential VMs encrypt data during processing.
For more information, see Google’s documentation on Confidential Computing. You can enable Confidential VMs and Shielded VMs at the same time, although they are not dependent on each other.
Note
Confidential VMs are currently not supported on 64-bit ARM architectures.
Procedure
-
Use a text editor to edit the
install-config.yamlfile before deploying your cluster and add one of the following stanzas:-
To use confidential VMs for only control plane machines:
controlPlane: platform: gcp: confidentialCompute: AMDEncryptedVirtualizationNestedPaging type: n2d-standard-8 onHostMaintenance: Terminatewhere:
confidentialCompute- Enables confidential VMs with AMD Secure Encrypted Virtualization Secure Nested Paging (AMD SEV-SNP). For more information about available options, see "Additional Google Cloud configuration parameters".
type- Specifies a machine type that supports Confidential VMs. Confidential VMs require the N2D, C2D, C3D, or C3 series of machine types. For more information on supported machine types, see Supported operating systems and machine types.
onHostMaintenance- Specifies the behavior of the VM during a host maintenance event, such as a hardware or software update. For a machine that uses Confidential VM, this value must be set to
Terminate, which stops the VM. Confidential VMs do not support live VM migration.
-
To use confidential VMs for only compute machines:
-
To use confidential VMs for all machines:
-
Additional resources
Configuring the cluster-wide proxy during installation¶
Production environments can deny direct access to the internet and instead have an HTTP or HTTPS proxy available. You can configure a new OpenShift Container Platform cluster to use a proxy by configuring the proxy settings in the install-config.yaml file.
Prerequisites
-
You have reviewed the sites that your cluster requires access to and determined whether any of them need to bypass the proxy. By default, the proxy handles all cluster egress traffic, including calls to hosting cloud provider APIs. You added sites to the
Proxyobject’sspec.noProxyfield to bypass the proxy if necessary.Note
The
Proxyobjectstatus.noProxyfield includes the values of thenetworking.machineNetwork[].cidr,networking.clusterNetwork[].cidr, andnetworking.serviceNetwork[]fields from your installation configuration.For installations on Amazon Web Services (AWS), Google Cloud, Microsoft Azure, and Red Hat OpenStack Platform (RHOSP), the
Proxyobjectstatus.noProxyfield also includes the instance metadata endpoint (169.254.169.254).
Procedure
-
Edit your
install-config.yamlfile and add the proxy settings. For example:apiVersion: v1 baseDomain: my.domain.com proxy: httpProxy: http://<username>:<pswd>@<ip>:<port> httpsProxy: https://<username>:<pswd>@<ip>:<port> noProxy: example.com additionalTrustBundle: | -----BEGIN CERTIFICATE----- <MY_TRUSTED_CA_CERT> -----END CERTIFICATE----- additionalTrustBundlePolicy: <policy_to_add_additionalTrustBundle> # ...where:
proxy.httpProxy- Specifies a proxy URL to use for creating HTTP connections outside the cluster. The URL scheme must be
http. proxy.httpsProxy- Specifies a proxy URL to use for creating HTTPS connections outside the cluster.
proxy.noProxy- Specifies a comma-separated list of destination domain names, IP addresses, or other network CIDRs to exclude from proxying. Preface a domain with
.to match subdomains only. For example,.y.commatchesx.y.com, but noty.com. Use*to bypass the proxy for all destinations. additionalTrustBundle- If you specify this value, the installation program generates a config map named
user-ca-bundlein theopenshift-confignamespace to hold the additional CA certificates. If you specifyadditionalTrustBundleand at least one proxy setting, theProxyobject references theuser-ca-bundleconfig map in thetrustedCAfield. The Cluster Network Operator then creates atrusted-ca-bundleconfig map that merges the contents specified for thetrustedCAparameter with the RHCOS trust bundle. You must set theadditionalTrustBundlefield unless an authority from the RHCOS trust bundle signs the proxy’s identity certificate. additionalTrustBundlePolicy- Specifies the policy that determines the configuration of the
Proxyobject to reference theuser-ca-bundleconfig map in thetrustedCAfield. The allowed values areProxyonlyandAlways. UseProxyonlyto reference theuser-ca-bundleconfig map only when you configure anhttp/httpsproxy. UseAlwaysto always reference theuser-ca-bundleconfig map. The default value isProxyonly. Optional parameter.
Note
The installation program does not support the proxy
readinessEndpointsfield. -
Save the file and reference it when installing OpenShift Container Platform.
The installation program creates a cluster-wide proxy named
clusterthat uses the proxy settings in theinstall-config.yamlfile. If you do not give proxy settings, the installation program still creates aclusterProxyobject, but it has a nilspec.Note
Only the
Proxyobject namedclusteris supported, and you cannot create additional proxies.
Creating the Kubernetes manifest and Ignition config files¶
Because you manually provision infrastructure, you must generate the Kubernetes manifest and Ignition config files that the cluster requires.
The installation program converts the installation configuration into Kubernetes manifests and then wraps them into Ignition configuration files. You use these Ignition files to configure the cluster machines.
Warning
- The Ignition config files that the OpenShift Container Platform installation program generates contain certificates that expire after 24 hours, which the system then renews. If you shut down the cluster before the system renews the certificates and you later restart the cluster after the 24 hours have elapsed, the cluster automatically recovers the expired certificates. The exception is that you must manually approve the pending
node-bootstrappercertificate signing requests (CSRs) to recover kubelet certificates. See the documentation for Recovering from expired control plane certificates for more information. - Use Ignition config files within 12 hours after you generate them, because the 24-hour certificate rotates from 16 to 22 hours after you install the cluster. By using the Ignition config files within 12 hours, you can avoid installation failure if the certificate update runs during installation.
Procedure
-
Change to the directory that contains the OpenShift Container Platform installation program and generate the Kubernetes manifests for the cluster:
where:
<installation_directory>- Specifies the installation directory that contains the
install-config.yamlfile you created.
-
Remove the Kubernetes manifest files that define the control plane machines:
By removing these files, you prevent the cluster from automatically generating control plane machines.
-
Remove the Kubernetes manifest files that define the control plane machine set:
-
Optional: If you do not want the cluster to provision compute machines, remove the Kubernetes manifest files that define the worker machines:
Warning
If you disabled the
MachineAPIcapability when installing a cluster on user-provisioned infrastructure, you must remove the Kubernetes manifest files that define the worker machines. Otherwise, your cluster fails to install.Because you create and manage the worker machines yourself, you do not need to initialize these machines.
-
Verify that the
mastersSchedulableparameter in the<installation_directory>/manifests/cluster-scheduler-02-config.ymlKubernetes manifest file is set tofalse. This setting prevents pods from being scheduled on the control plane machines:- Open the
<installation_directory>/manifests/cluster-scheduler-02-config.ymlfile. - Locate the
mastersSchedulableparameter and verify that it is set tofalse. - Save and exit the file.
- Open the
-
Optional: If you do not want the Ingress Operator to create DNS records on your behalf, remove the
privateZoneandpublicZonesections from the<installation_directory>/manifests/cluster-dns-02-config.ymlDNS configuration file:apiVersion: config.openshift.io/v1 kind: DNS metadata: creationTimestamp: null name: cluster spec: baseDomain: example.openshift.com privateZone: id: mycluster-100419-private-zone publicZone: id: example.openshift.com status: {}spec.privateZone: Remove this section completely.If you do so, you must add ingress DNS records manually in a later step.
-
To create the Ignition configuration files, run the following command from the directory that contains the installation program:
where:
<installation_directory>- Specifies the same installation directory. The installation program creates Ignition config files for the bootstrap, control plane, and compute nodes in the installation directory. The program also creates the
kubeadmin-passwordandkubeconfigfiles in the./<installation_directory>/authdirectory:
Additional resources
Extracting the infrastructure name¶
To identify your cluster resources in Google Cloud, extract the unique infrastructure name from the Ignition config files.
The Ignition config files contain a unique cluster identifier that you can use to uniquely identify your cluster in Google Cloud. The infrastructure name is also used to locate the appropriate Google Cloud resources during an OpenShift Container Platform installation. The provided Infrastructure Manager templates contain references to this infrastructure name, so you must extract it.
Warning
Do not run the openshift-install create manifests command again after creating any Google Cloud resources. Running the command again generates a new cluster identifier, which will cause errors in existing resources. If you need to regenerate the manifests because you modified the install-config.yaml file, delete any Google Cloud resources you created and re-create them with the new cluster identifier.
Prerequisites
- You installed the
jqpackage.
Procedure
-
To extract and view the infrastructure name from the Ignition config file metadata, run the following command:
where
<installation_directory>is the path to the directory that you stored the installation files in.The output of this command is your cluster name and a random string.
Exporting common variables for Infrastructure Manager templates¶
You must export a common set of variables that the Infrastructure Manager templates reference to provision the resources for a cluster that uses user-provisioned infrastructure on Google Cloud.
Note
Specific Infrastructure Manager templates can also require additional exported variables, which are detailed in their related procedures.
Procedure
-
Export the following common variables to be used by the provided Infrastructure Manager templates. For any command with
<installation_directory>, specify the path to the directory that you stored the installation files in.-
Export the
BASE_DOMAINvariable by running the following command:<base_domain>- If you are installing a cluster into a shared VPC, specify the value for the host project.
-
Export the
BASE_DOMAIN_ZONE_NAMEvariable by running the following command:<base_domain_zone_name>- Specifies the base domain zone name.
-
Export the
NETWORK_CIDRvariable by running the following command:<network_cidr>- Specifies the network CIDR your cluster uses. For example,
10.0.0.0/16.
-
Export the
MASTER_SUBNET_CIDRvariable by running the following command:<master_subnet_cidr>- Specifies the network CIDR that your cluster’s control plane uses. For example,
10.0.0.0/17.
-
Export the
WORKER_SUBNET_CIDRvariable by running the following command:<worker_subnet_cidr>- Specifies the network CIDR that your cluster’s compute machines use. For example,
10.0.128.0/17.
-
Export the
KUBECONFIGvariable by running the following command: -
Export the
CLUSTER_NAMEvariable by running the following command: -
Export the
INFRA_IDvariable by running the following command: -
Export the
PROJECT_NAMEvariable by running the following command: -
If you are installing a cluster into a shared VPC, export the
HOST_PROJECTvariable by running the following command:<host_project_name>specifies the name of the host project that contains the shared VPC. -
If you are installing a cluster into a shared VPC, export the
HOST_PROJECT_ACCOUNTvariable by running the following command:<host_project_account>specifies the name of an account that can access the host project that contains the shared VPC. -
Export the
REGIONvariable by running the following command: -
Export the
ZONE_0variable by running the following command: -
Export the
ZONE_1variable by running the following command: -
Export the
ZONE_2variable by running the following command: -
Export the
SERVICE_ACCOUNT_EMAILvariable by running the following command:<service_account_email>- Specifies the email address of the service account you used for the installation.
-
Export the
INSTALL_SERVICE_ACCOUNTvariable by running the following command: -
Export the
CLUSTER_DOMAINvariable by running the following command:
-
Creating a VPC in Google Cloud¶
You must create a VPC in Google Cloud for your OpenShift Container Platform cluster to use. You can customize the VPC to meet your requirements. One way to create the VPC is to modify the provided Infrastructure Manager template.
Note
If you do not use the provided Infrastructure Manager template to create your Google Cloud infrastructure, you must review the provided information and manually create the infrastructure. If your cluster does not initialize correctly, you might have to contact Red Hat support with your installation logs.
Prerequisites
- You have defined the variables in the Exporting common variables section.
Procedure
-
Copy the template from the Infrastructure Manager template for the VPC section of this topic and save it as
01_vpc.tfin a directory called01_vpcon your computer. This template describes the VPC that your cluster requires. -
Create a VPC by running the following command:
$ gcloud infra-manager deployments apply <vpc_deployment_name> \ --location=${REGION} \ --input-values=infra_id=${INFRA_ID},project=${PROJECT_NAME},region=${REGION},master_subnet_cidr=${MASTER_SUBNET_CIDR},worker_subnet_cidr=${WORKER_SUBNET_CIDR} \ --project=${PROJECT_NAME} \ --local-source=./01_vpc \ --service-account=${INSTALL_SERVICE_ACCOUNT}<vpc_deployment_name>specifies the name of the VPC deployment you create. -
Configure environment variables that will be used to create other cluster infrastructure.
-
Configure the
CLUSTER_NETWORKenvironment variable by running the following command: -
Configure the
CONTROL_SUBNETenvironment variable by running the following command: -
Configure the
COMPUTE_SUBNETenvironment variable by running the following command:
-
Verification
-
Verify the deployment is active by running the following command:
Replace
<deployment_name>with the name of the deployment you created.
Infrastructure Manager template for the VPC¶
You can use the following 01_vpc.tf Infrastructure Manager template to deploy the VPC that you need for your OpenShift Container Platform cluster:
terraform {
# Infra manager supports specific Terraform versions; ensure compatibility
required_version = ">=1.2.3"
required_providers {
google = {
source = "hashicorp/google"
version = ">= 4.0.0"
}
google-beta = {
source = "hashicorp/google-beta",
version = ">= 4.0.0"
}
}
}
provider "google-beta" {
project = "${var.project}"
region = "${var.region}"
}
variable "infra_id" {
type = string
description = "OpenShift Installer Infrastructure ID"
}
variable "project" {
type = string
description = "Project ID"
}
variable "region" {
type = string
description = "GCP Region where the resources will be created."
default = "us-central1"
}
variable "master_subnet_cidr" {
type = string
description = "CIDR for the control plane subnet."
}
variable "worker_subnet_cidr" {
type = string
description = "CIDR for the compute subnet."
}
resource "google_compute_network" "cluster_network" {
provider = google-beta
name = "${var.infra_id}-network"
auto_create_subnetworks = false
}
resource "google_compute_subnetwork" "master_subnet" {
provider = google-beta
name = "${var.infra_id}-master-subnet"
ip_cidr_range = "${var.master_subnet_cidr}"
region = "${var.region}"
network = google_compute_network.cluster_network.self_link
}
resource "google_compute_subnetwork" "worker_subnet" {
provider = google-beta
name = "${var.infra_id}-worker-subnet"
ip_cidr_range = "${var.worker_subnet_cidr}"
region = "${var.region}"
network = google_compute_network.cluster_network.self_link
}
#tfimport-terraform import google_compute_router._router __project__//-router
resource "google_compute_router" "router" {
provider = google-beta
name = "${var.infra_id}-router"
network = google_compute_network.cluster_network.self_link
region = "${var.region}"
}
resource "google_compute_router_nat" "master_nat" {
provider = google-beta
name = "${var.infra_id}-nat-master"
source_subnetwork_ip_ranges_to_nat = "LIST_OF_SUBNETWORKS"
nat_ip_allocate_option = "AUTO_ONLY"
min_ports_per_vm = 7168
subnetwork {
name = google_compute_subnetwork.master_subnet.self_link
source_ip_ranges_to_nat = ["ALL_IP_RANGES"]
}
router = google_compute_router.router.name
region = "${var.region}"
depends_on = [
google_compute_router.router
]
}
resource "google_compute_router_nat" "worker_nat" {
provider = google-beta
name = "${var.infra_id}-nat-worker"
source_subnetwork_ip_ranges_to_nat = "LIST_OF_SUBNETWORKS"
nat_ip_allocate_option = "AUTO_ONLY"
min_ports_per_vm = 512
subnetwork {
name = google_compute_subnetwork.worker_subnet.self_link
source_ip_ranges_to_nat = ["ALL_IP_RANGES"]
}
router = google_compute_router.router.name
region = "${var.region}"
depends_on = [
google_compute_router.router
]
}
Networking requirements for user-provisioned infrastructure¶
You must configure networking for all the Red Hat Enterprise Linux CoreOS (RHCOS) machines in initramfs during boot, so that they can fetch their Ignition config files.
Setting the cluster node hostnames through DHCP¶
On Red Hat Enterprise Linux CoreOS (RHCOS) machines, the hostname is set through NetworkManager. By default, the machines obtain their hostname through DHCP. If the hostname is not provided by DHCP, set statically through kernel arguments, or another method, it is obtained through a reverse DNS lookup. Reverse DNS lookup occurs after the network has been initialized on a node and can take time to resolve. Other system services can start before this and detect the hostname as localhost or similar. You can avoid this by using DHCP to provide the hostname for each cluster node.
Additionally, setting the hostnames through DHCP can bypass any manual DNS record name configuration errors in environments that have a DNS split-horizon implementation.
Network connectivity requirements¶
You must configure the network connectivity between machines to allow OpenShift Container Platform cluster components to communicate. Each machine must be able to resolve the hostnames of all other machines in the cluster.
This section provides details about the ports that are required.
Ports used for all-machine to all-machine communications
| Protocol | Port | Description |
|---|---|---|
| ICMP | N/A | Network reachability tests |
| TCP | 1936 |
Metrics |
9000-9999 |
Host level services, including the node exporter on ports 9100-9101 and the Cluster Version Operator on port 9099. |
|
10250-10259 |
The default ports that Kubernetes reserves | |
22623 |
The port handles traffic from the Machine Config Server and directs the traffic to the control plane machines. | |
| UDP | 6081 |
Geneve |
9000-9999 |
Host level services, including the node exporter on ports 9100-9101. |
|
500 |
IPsec IKE packets | |
4500 |
IPsec NAT-T packets | |
123 |
Network Time Protocol (NTP) on UDP port 123. If an external NTP time server is configured, you must open UDP port 123. |
|
| TCP/UDP | 30000-32767 |
Kubernetes node port |
| ESP | N/A | IPsec Encapsulating Security Payload (ESP) |
Ports used for all-machine to control plane communications
| Protocol | Port | Description |
|---|---|---|
| TCP | 6443 |
Kubernetes API |
Ports used for control plane machine to control plane machine communications
| Protocol | Port | Description |
|---|---|---|
| TCP | 2379-2380 |
etcd server and peer ports |
Creating load balancers in Google Cloud¶
You must configure load balancers in Google Cloud for your OpenShift Container Platform cluster to use. One way to create these components is to modify the provided Infrastructure Manager template.
Note
If you do not use the provided template to create your Google Cloud infrastructure, you must review the provided information and manually create the infrastructure. If your cluster does not initialize correctly, you might have to contact Red Hat support with your installation logs.
Prerequisites
- You have defined the variables in the Exporting common variables section.
- If you are not installing a cluster into a shared VPC, you have defined the variables in the Creating a VPC in Google Cloud section.
Procedure
-
If you are installing a cluster into a shared VPC, set environment variables for the cluster network and control plane subnet.
-
Determine the shared VPC network name by running the following command:
-
Set the
CLUSTER_NETWORKvariable by running the following command:$ export CLUSTER_NETWORK=$(gcloud compute networks describe <network_name> --format json | jq -r .selfLink)<network_name>specifies the name of the network you determined. -
List the available network subnets by running the following command:
<network_name>specifies the name of the network you determined. -
Select a subnet from the list, and set the
CONTROL_SUBNETvariable by running the following command:<control_subnet>specifies the name of the subnet you selected from the list of subnets.
-
-
Copy the template from the Infrastructure Manager template for the internal load balancer section of this topic and save it as
02_lb_int.tfin a directory called02_lb_inton your computer. This template describes the internal load balancing objects that your cluster requires.-
Create an internal load balancer by running the following command:
$ gcloud infra-manager deployments apply <internal_lb_deployment_name> \ --location=${REGION} \ --input-values=infra_id=${INFRA_ID},project=${PROJECT_NAME},region=${REGION},cluster_network=${CLUSTER_NETWORK},control_subnet=${CONTROL_SUBNET},zone_0=${ZONE_0},zone_1=${ZONE_1},zone_2=${ZONE_2} \ --project=${PROJECT_NAME} \ --local-source=./02_lb_int \ --service-account=${INSTALL_SERVICE_ACCOUNT}<internal_lb_deployment_name>specifies the name of the internal load balancer deployment you create. -
Export the
CLUSTER_IPvariable by running the following command:
-
-
Optional: For a public or externally available cluster, copy the template from the Infrastructure Manager template for the external load balancer section of this topic and save it as
02_lb_ext.tfin a directory called02_lb_exton your computer. This template describes the external load balancing objects that your cluster requires.-
Create an external load balancer by running the following command:
$ gcloud infra-manager deployments apply <external_lb_deployment_name> \ --location=${REGION} \ --input-values=infra_id=${INFRA_ID},project=${PROJECT_NAME},region=${REGION} \ --project=${PROJECT_NAME} \ --local-source=./02_lb_ext \ --service-account=${INSTALL_SERVICE_ACCOUNT}<external_lb_deployment_name>specifies the name of the external load balancer deployment you create. -
Export the
CLUSTER_PUBLIC_IPvariable by running the following command:
-
Verification
-
Verify the deployment is active by running the following command:
Replace
<deployment_name>with the name of the deployment you created.
Infrastructure Manager template for the external load balancer¶
You can use the following 02_lb_ext.tf Infrastructure Manager template to deploy the external load balancer that you need for your OpenShift Container Platform cluster:
terraform {
# Infra manager supports specific Terraform versions; ensure compatibility
required_version = ">=1.2.3"
required_providers {
google = {
source = "hashicorp/google"
version = ">= 4.0.0"
}
google-beta = {
source = "hashicorp/google-beta",
version = ">= 4.0.0"
}
}
}
provider "google-beta" {
project = "${var.project}"
region = "${var.region}"
}
variable "infra_id" {
type = string
description = "OpenShift Installer Infrastructure ID"
}
variable "project" {
type = string
description = "Project ID"
}
variable "region" {
type = string
description = "GCP Region where the resources will be created."
default = "us-central1"
}
resource "google_compute_address" "cluster_public_ip" {
provider = google-beta
name = "${var.infra_id}-cluster-public-ip"
region = "${var.region}"
}
resource "google_compute_http_health_check" "api_http_health_check" {
provider = google-beta
name = "${var.infra_id}-api-http-health-check"
port = 6080
request_path = "/readyz"
}
resource "google_compute_target_pool" "api_target_pool" {
provider = google-beta
name = "${var.infra_id}-api-target-pool"
region = "${var.region}"
health_checks = [
google_compute_http_health_check.api_http_health_check.id
]
}
resource "google_compute_forwarding_rule" "api_forwarding_rule" {
provider = google-beta
name = "${var.infra_id}-api-forwarding-rule"
ip_address = google_compute_address.cluster_public_ip.address
port_range = "6443"
region = "${var.region}"
target = google_compute_target_pool.api_target_pool.id
}
Infrastructure Manager template for the internal load balancer¶
You can use the following 02_lb_int.tf Infrastructure Manager template to deploy the internal load balancer that you need for your OpenShift Container Platform cluster:
terraform {
# Infra manager supports specific Terraform versions; ensure compatibility
required_version = ">=1.2.3"
required_providers {
google = {
source = "hashicorp/google"
version = ">= 4.0.0"
}
google-beta = {
source = "hashicorp/google-beta",
version = ">= 4.0.0"
}
}
}
provider "google-beta" {
project = "${var.project}"
region = "${var.region}"
}
variable "infra_id" {
type = string
description = "OpenShift Installer Infrastructure ID"
}
variable "project" {
type = string
description = "Project ID"
}
variable "region" {
type = string
description = "GCP Region where the resources will be created."
default = "us-central1"
}
variable "control_subnet" {
type = string
description = "Subnet for the control plane instances."
}
variable "cluster_network" {
type = string
description = "Full link to the cluster network."
}
# Terraform handles lists but the infra-manager --input-values only
# supports scalar types.
# If you require more or less zones, you must manually add them below
# as a single variable for each. You must add the zones to the
# locals `zones` list below.
variable "zone_0" {
type = string
description = "Zone 1 for the instance types."
}
variable "zone_1" {
type = string
description = "Zone 2 for the instance types."
}
variable "zone_2" {
type = string
description = "Zone 3 for the instance types."
}
locals {
zones = ["${var.zone_0}", "${var.zone_1}", "${var.zone_2}"]
}
resource "google_compute_address" "cluster_ip" {
provider = google-beta
name = "${var.infra_id}-cluster-ip"
address_type = "INTERNAL"
region = "${var.region}"
subnetwork = "${var.control_subnet}"
}
resource "google_compute_health_check" "api_internal_health_check" {
provider = google-beta
name = "${var.infra_id}-api-internal-health-check"
https_health_check {
port = 6443
}
}
resource "google_compute_region_backend_service" "api_internal" {
provider = google-beta
name = "${var.infra_id}-api-internal"
timeout_sec = 120
protocol = "TCP"
region = "${var.region}"
load_balancing_scheme = "INTERNAL"
health_checks = [
google_compute_health_check.api_internal_health_check.id
]
dynamic "backend" {
for_each = google_compute_instance_group.master_ig
content {
balancing_mode = "CONNECTION"
group = backend.value.self_link
}
}
}
resource "google_compute_forwarding_rule" "api_internal_forwarding_rule" {
provider = google-beta
name = "${var.infra_id}-api-internal-forwarding-rule"
ip_address = google_compute_address.cluster_ip.address
backend_service = google_compute_region_backend_service.api_internal.id
load_balancing_scheme = "INTERNAL"
ports = [
"6443",
"22623"
]
region = "${var.region}"
subnetwork = "${var.control_subnet}"
}
resource "google_compute_instance_group" "master_ig" {
provider = google-beta
for_each = toset(local.zones)
name = "${var.infra_id}-master-${each.key}-ig"
network = "${var.cluster_network}"
zone = "${each.key}"
named_port {
name = "ignition"
port = 22623
}
named_port {
name = "https"
port = 6443
}
}
Creating a private DNS zone in Google Cloud¶
You must configure a private DNS zone in Google Cloud for your OpenShift Container Platform cluster to use. One way to create this component is to modify the provided Infrastructure Manager template.
Note
If you do not use the provided template to create your Google Cloud infrastructure, you must review the provided information and manually create the infrastructure. If your cluster does not initialize correctly, you might have to contact Red Hat support with your installation logs.
Prerequisites
- Ensure you defined the variables in the Exporting common variables and Creating load balancers in Google Cloud sections.
Procedure
-
Copy the template from the Infrastructure Manager template for the private DNS section of this topic and save it as
02_dns.tfin a folder called02_dnson your computer. This template describes the private DNS objects that your cluster requires. -
If you are installing a cluster into a shared VPC, and the host project already has a private DNS zone, skip this step. Create the DNS zone by running the following command:
$ gcloud infra-manager deployments apply <dns_zone_deployment_name> \ --location=${REGION} \ --input-values=infra_id=${INFRA_ID},project=${PROJECT_NAME},region=${REGION},cluster_domain=${CLUSTER_DOMAIN},cluster_network=${CLUSTER_NETWORK} \ --project=${PROJECT_NAME} \ --local-source=./02_dns \ --service-account=${INSTALL_SERVICE_ACCOUNT}<dns_zone_deployment_name>specifies the name of the DNS zone deployment you create. -
The templates do not create DNS entries due to limitations of Infrastructure Manager, so you must create them manually:
-
Add the internal DNS entries by running the following commands:
$ gcloud dns record-sets transaction add ${CLUSTER_IP} --name api.${CLUSTER_NAME}.${BASE_DOMAIN}. --ttl 60 --type A --zone ${INFRA_ID}-private-zone -
For an external cluster, also add the external DNS entries by running the following commands:
-
Verification
-
Verify the deployment is active by running the following command:
Replace
<deployment_name>with the name of the deployment you created.
Infrastructure Manager template for the private DNS¶
You can use the following 02_dns.tf Infrastructure Manager template to deploy the private DNS that you need for your OpenShift Container Platform cluster:
terraform {
# Infra manager supports specific Terraform versions; ensure compatibility
required_version = ">=1.2.3"
required_providers {
google = {
source = "hashicorp/google"
version = ">= 4.0.0"
}
google-beta = {
source = "hashicorp/google-beta",
version = ">= 4.0.0"
}
}
}
provider "google-beta" {
project = "${var.project}"
region = "${var.region}"
}
variable "infra_id" {
type = string
description = "OpenShift Installer Infrastructure ID"
}
variable "project" {
type = string
description = "Project ID"
}
variable "region" {
type = string
description = "GCP Region where the resources will be created."
default = "us-central1"
}
variable "cluster_domain" {
type = string
description = "ClusterName.BaseDomain"
}
variable "cluster_network" {
type = string
description = "Full link to the cluster network."
}
resource "google_dns_managed_zone" "private_zone" {
provider = google-beta
name = "${var.infra_id}-private-zone"
dns_name = "${var.cluster_domain}."
description = "OpenShift Installer UPI create private DNS zone."
visibility = "private"
private_visibility_config {
networks {
network_url = "${var.cluster_network}"
}
}
force_destroy = false
}
Creating firewall rules and IAM roles in Google Cloud¶
You must create firewall rules and IAM roles in Google Cloud for your OpenShift Container Platform cluster to use. One way to create these components is to modify the provided Infrastructure Manager template. If you are installing a cluster into a shared VPC and the host project already has the necessary firewall rules and IAM roles, you can skip creating these resources.
Note
If you do not use the provided Infrastructure Manager template to create your Google Cloud infrastructure, you must review the provided information and manually create the infrastructure. If your cluster does not initialize correctly, you might have to contact Red Hat support with your installation logs.
Prerequisites
- Ensure you defined the variables in the Exporting common variables and Creating load balancers in Google Cloud sections.
Procedure
-
Copy the template from the Infrastructure Manager template for firewall rules and IAM roles section of this topic and save it as
03_security.tfin a folder called03_securityon your computer. This template describes the security groups that your cluster requires. -
Create the firewall rules and IAM roles by running the following command:
$ gcloud infra-manager deployments apply <security_deployment_name> \ --location=${REGION} \ --project=${PROJECT_NAME} \ --local-source=./03_security \ --input-values=infra_id=${INFRA_ID},project=${PROJECT_NAME},region=${REGION},cluster_network=${CLUSTER_NETWORK},network_cidr=${NETWORK_CIDR} \ --service-account=${INSTALL_SERVICE_ACCOUNT}<security_deployment_name>specifies the name of the deployment of firewall rules and IAM roles. -
Configure service account variables based on the roles you created by running the following commands:
Verification
-
Verify the deployment is active by running the following command:
Replace
<deployment_name>with the name of the deployment you created.
Infrastructure Manager template for firewall rules and IAM roles¶
You can use the following 03_security.tf Infrastructure Manager template to deploy the firewall rules and IAM roles that you need for your OpenShift Container Platform cluster:
terraform {
# Infra manager supports specific Terraform versions; ensure compatibility
required_version = ">=1.2.3"
required_providers {
google = {
source = "hashicorp/google"
version = ">= 4.0.0"
}
google-beta = {
source = "hashicorp/google-beta",
version = ">= 4.0.0"
}
}
}
provider "google-beta" {
project = "${var.project}"
region = "${var.region}"
}
variable "infra_id" {
type = string
description = "OpenShift Installer Infrastructure ID"
}
variable "project" {
type = string
description = "Project ID"
}
variable "region" {
type = string
description = "GCP Region where the resources will be created."
default = "us-central1"
}
variable "cluster_network" {
type = string
description = "Full link to the cluster network."
}
variable "network_cidr" {
type = string
description = "CIDR for network of the cluster."
}
variable "allowed_external_cidr" {
type = string
description = "Allowed external CIDR for firewall rule."
default = "0.0.0.0/0"
}
resource "google_compute_firewall" "bootstrap_in_ssh" {
provider = google-beta
name = "${var.infra_id}-bootstrap-in-ssh"
source_ranges = [
"${var.allowed_external_cidr}"
]
target_tags = [
"${var.infra_id}-bootstrap"
]
network = "${var.cluster_network}"
allow {
protocol = "tcp"
ports = ["22"]
}
}
resource "google_compute_firewall" "api" {
provider = google-beta
name = "${var.infra_id}-api"
source_ranges = [
"${var.allowed_external_cidr}"
]
target_tags = [
"${var.infra_id}-master"
]
network = "${var.cluster_network}"
allow {
protocol = "tcp"
ports = ["6443"]
}
}
resource "google_compute_firewall" "health_checks" {
provider = google-beta
name = "${var.infra_id}-health-checks"
source_ranges = [
"35.191.0.0/16",
"130.211.0.0/22",
"209.85.152.0/22",
"209.85.204.0/22"
]
target_tags = [
"${var.infra_id}-master"
]
network = "${var.cluster_network}"
allow {
protocol = "tcp"
ports = ["6080", "6443", "22624"]
}
}
resource "google_compute_firewall" "etcd" {
provider = google-beta
name = "${var.infra_id}-etcd"
source_tags = [
"${var.infra_id}-master"
]
target_tags = [
"${var.infra_id}-master"
]
network = "${var.cluster_network}"
allow {
protocol = "tcp"
ports = ["2379-2380"]
}
}
resource "google_compute_firewall" "control_plane" {
provider = google-beta
name = "${var.infra_id}-control-plane"
source_tags = [
"${var.infra_id}-master",
"${var.infra_id}-worker"
]
target_tags = [
"${var.infra_id}-master"
]
network = "${var.cluster_network}"
allow {
protocol = "tcp"
ports = ["10257"]
}
allow {
protocol = "tcp"
ports = ["10259"]
}
allow {
protocol = "tcp"
ports = ["22623"]
}
}
resource "google_compute_firewall" "internal_network" {
provider = google-beta
name = "${var.infra_id}-internal-network"
source_ranges = [
"${var.network_cidr}"
]
target_tags = [
"${var.infra_id}-master",
"${var.infra_id}-worker"
]
network = "${var.cluster_network}"
allow {
protocol = "icmp"
}
allow {
protocol = "tcp"
ports = ["22"]
}
}
resource "google_compute_firewall" "internal_cluster" {
provider = google-beta
name = "${var.infra_id}-internal-cluster"
source_tags = [
"${var.infra_id}-master",
"${var.infra_id}-worker"
]
target_tags = [
"${var.infra_id}-master",
"${var.infra_id}-worker"
]
network = "${var.cluster_network}"
allow {
protocol = "udp"
ports = ["4789", "6081"]
}
allow {
protocol = "udp"
ports = ["500", "4500"]
}
allow {
protocol = "esp"
}
allow {
protocol = "tcp"
ports = ["9000-9999"]
}
allow {
protocol = "udp"
ports = ["9000-9999"]
}
allow {
protocol = "tcp"
ports = ["10250"]
}
allow {
protocol = "tcp"
ports = ["30000-32767"]
}
allow {
protocol = "udp"
ports = ["30000-32767"]
}
}
resource "google_service_account" "master_node_sa" {
provider = google-beta
account_id = "${var.infra_id}-m"
display_name = "${var.infra_id}-master-node"
}
resource "google_service_account" "worker_node_sa" {
provider = google-beta
account_id = "${var.infra_id}-w"
display_name = "${var.infra_id}-worker-node"
}
Creating IAM policy bindings in Google Cloud¶
You must create IAM policy bindings in Google Cloud for your OpenShift Container Platform cluster to use.
Prerequisites
- You have defined the variables in the Exporting common variables section.
Procedure
-
Export the variable for the subnet that hosts the compute machines by running the following command:
-
The templates do not create the policy bindings due to limitations of Infrastructure Manager, so you must create them manually by running the following commands:
$ gcloud projects add-iam-policy-binding ${PROJECT_NAME} --member "serviceAccount:${MASTER_SERVICE_ACCOUNT}" --role "roles/compute.instanceAdmin"$ gcloud projects add-iam-policy-binding ${PROJECT_NAME} --member "serviceAccount:${MASTER_SERVICE_ACCOUNT}" --role "roles/compute.networkAdmin"$ gcloud projects add-iam-policy-binding ${PROJECT_NAME} --member "serviceAccount:${MASTER_SERVICE_ACCOUNT}" --role "roles/compute.securityAdmin"$ gcloud projects add-iam-policy-binding ${PROJECT_NAME} --member "serviceAccount:${MASTER_SERVICE_ACCOUNT}" --role "roles/iam.serviceAccountUser"$ gcloud projects add-iam-policy-binding ${PROJECT_NAME} --member "serviceAccount:${MASTER_SERVICE_ACCOUNT}" --role "roles/storage.admin" -
Create a service account key and store it locally for later use by running the following command:
Creating the RHCOS cluster image for the Google Cloud infrastructure¶
To deploy OpenShift Container Platform nodes on Google Cloud, you must create a valid Red Hat Enterprise Linux CoreOS (RHCOS) image in your Google Cloud project because RHCOS images are not pre-published on Google Cloud.
Prerequisites
- You have downloaded the
openshift-installbinary.
Procedure
-
Obtain the image name by running the following command:
-
Obtain the project name by running the following command:
-
Create the image by running the following command:
Creating the bootstrap machine in Google Cloud¶
You must create the bootstrap machine in Google Cloud to use during OpenShift Container Platform cluster initialization. One way to create this machine is to modify the provided Infrastructure Manager template.
Note
If you do not use the provided Infrastructure Manager template to create your bootstrap machine, you must review the provided information and manually create the infrastructure. If your cluster does not initialize correctly, you might have to contact Red Hat support with your installation logs.
If you need to redeploy the bootstrap machine for any reason, delete the existing bootstrap VM first. If you redeploy the bootstrap machine without deleting the existing VM, Infrastructure Manager will update the metadata and appear to succeed, but the Ignition file will not be executed again. This will result in the VM still being based on the old Ignition data.
Prerequisites
- Ensure you defined the variables in the Exporting common variables and Creating load balancers in Google Cloud sections.
Procedure
-
Copy the template from the Infrastructure Manager template for the bootstrap machine section of this topic and save it as
04_bootstrap.tfin a folder called04_bootstrapon your computer. This template describes the bootstrap machine that your cluster requires.-
You can edit the
04_bootstrap.tffile to add additional tags to the bootstrap machine, by modifying the existingtagsstanza as follows:
-
-
Export the location of the Red Hat Enterprise Linux CoreOS (RHCOS) image that the installation program requires by running the following command:
-
Create a bucket by running the following command:
-
Upload the
bootstrap.ignfile by running the following command: -
Create a signed URL for the bootstrap instance and export the URL from the output as a variable by running the following command:
-
Create the bootstrap deployment by running the following command:
$ gcloud infra-manager deployments apply <bootstrap_deployment_name> \ --location=${REGION} \ --project=${PROJECT_NAME} \ --local-source=./04_bootstrap \ --input-values=infra_id=${INFRA_ID},project=${PROJECT_NAME},region=${REGION},zone=${ZONE_0},cluster_network=${CLUSTER_NETWORK},subnet=${CONTROL_SUBNET},image=${CLUSTER_IMAGE},bootstrap_ign="${BOOTSTRAP_IGN}",is_public_cluster=<public_cluster_status> \ --service-account=${INSTALL_SERVICE_ACCOUNT}where:
<bootstrap_deployment_name>- Specifies the name of the bootstrap deployment.
<public_cluster_status>- Specifies whether the cluster is public or private. If it is a public cluster, specify
true. If it is a private cluster, specifyfalse.
-
The templates do not manage load balancer membership due to limitations of Infrastructure Manager, so you must add the bootstrap machine manually.
-
Add the bootstrap instance to the internal load balancer instance group by running the following command:
-
Add the bootstrap instance group to the internal load balancer backend service by running the following command:
-
Verification
-
Verify the deployment is active by running the following command:
Replace
<deployment_name>with the name of the deployment you created.
Infrastructure Manager template for the bootstrap machine¶
You can use the following 04_bootstrap.tf Infrastructure Manager template to deploy the bootstrap machine that you need for your OpenShift Container Platform cluster:
terraform {
# Infra manager supports specific Terraform versions; ensure compatibility
required_version = ">=1.2.3"
required_providers {
google = {
source = "hashicorp/google"
version = ">= 4.0.0"
}
google-beta = {
source = "hashicorp/google-beta",
version = ">= 4.0.0"
}
}
}
provider "google-beta" {
project = "${var.project}"
region = "${var.region}"
}
variable "infra_id" {
type = string
description = "OpenShift Installer Infrastructure ID"
}
variable "project" {
type = string
description = "Project ID"
}
variable "region" {
type = string
description = "GCP Region where the resources will be created."
default = "us-central1"
}
variable "zone" {
type = string
description = "Zone inside of the region where the bootstrap node is created."
}
variable "cluster_network" {
type = string
description = "Full link to the cluster network."
}
variable "subnet" {
type = string
description = "Control plane subnet."
}
variable "image" {
type = string
description = "Cluster Image."
}
variable "machine_type" {
type = string
description = "Machine type for the bootstrap machine."
default = "n1-standard-4"
}
variable "root_volume_size" {
type = string
description = "Size in GB for the root volume."
default = "128"
}
variable "bootstrap_ign" {
type = string
description = "Bootstrap ignition data."
}
variable "is_public_cluster" {
type = bool
default = true
description = "Whether the publish policy is the default External"
}
resource "google_compute_address" "bootstrap_public_ip" {
provider = google-beta
count = var.is_public_cluster ? 1 : 0
name = "${var.infra_id}-bootstrap-public-ip"
region = "${var.region}"
}
resource "google_compute_instance" "bootstrap" {
provider = google-beta
name = "${var.infra_id}-bootstrap"
zone = "${var.zone}"
machine_type = "${var.machine_type}"
tags = [
"${var.infra_id}-master",
"${var.infra_id}-bootstrap"
]
boot_disk {
auto_delete = true
initialize_params {
size = "${var.root_volume_size}"
image = "${var.image}"
}
}
network_interface {
subnetwork = "${var.subnet}"
# Dynamic block to conditionally create access_config
dynamic "access_config" {
for_each = var.is_public_cluster ? [1] : []
content {
nat_ip = google_compute_address.bootstrap_public_ip[0].address
}
}
}
metadata = {
user-data = "{\"ignition\":{\"config\":{\"replace\":{\"source\":\"${var.bootstrap_ign}\"}},\"version\":\"3.2.0\"}}"
}
}
resource "google_compute_instance_group" "bootstrap_ig" {
provider = google-beta
name = "${var.infra_id}-bootstrap-ig"
network = "${var.cluster_network}"
zone = "${var.zone}"
named_port {
name = "ignition"
port = 22623
}
named_port {
name = "https"
port = 6443
}
}
Creating the control plane machines in Google Cloud¶
You must create the control plane machines in Google Cloud for your cluster to use. One way to create these machines is to modify the provided Infrastructure Manager template.
Note
If you do not use the provided template to create your control plane machines, you must review the provided information and manually create the infrastructure. If your cluster does not initialize correctly, you might have to contact Red Hat support with your installation logs.
Prerequisites
- You defined the variables in the Exporting common variables, Creating load balancers in Google Cloud, Creating IAM roles in Google Cloud, and Creating the bootstrap machine in Google Cloud sections.
- You created the bootstrap machine.
- You created the Ignition configuration files.
Procedure
-
Copy the template from the Infrastructure Manager template for control plane machines section of this topic and save it as
05_control_plane.tfin a folder called05_control_planeon your computer. This template describes the control plane machines that your cluster requires.-
You can edit the
05_control_plane.tffile to add additional tags to the control plane machines, by modifying the existingtagsstanza. The following example adds a custom tag to the first control plane machine, which is namedmaster_0:
-
-
Copy the
master.ignfile from your installation directory into the05_control_planefolder by running the following command:<installation_directory>specifies the directory where you created the Ignition configuration files. -
Create the control plane deployment by running the following command:
$ gcloud infra-manager deployments apply <control_plane_deployment> \ --location=${REGION} \ --project=${PROJECT_NAME} \ --local-source=./05_control_plane \ --input-values=infra_id=${INFRA_ID},project=${PROJECT_NAME},region=${REGION},zone_0=${ZONE_0},zone_1=${ZONE_1},zone_2=${ZONE_2},subnet=${CONTROL_SUBNET},image=${CLUSTER_IMAGE},service_account_email=${MASTER_SERVICE_ACCOUNT} \ --service-account=${INSTALL_SERVICE_ACCOUNT}<control_plane_deployment>specifies the name of the control plane deployment. -
Delete the temporary ignition file from the
05_control_planefolder by running the following command: -
The templates do not manage load balancer membership due to limitations of Infrastructure Manager, so you must add the control plane machines manually.
-
Add the first control plane machine to an internal load balancer instance group by running the following command:
-
Add the second control plane machine to an internal load balancer instance group by running the following command:
-
Add the third control plane machine to an internal load balancer instance group by running the following command:
-
-
For an external cluster, you must also add the control plane machines to external load balancer target pools.
-
Add the first control plane machine to an external load balancer pool by running the following command:
-
Add the second control plane machine to an external load balancer pool by running the following command:
-
Add the third control plane machine to an external load balancer pool by running the following command:
-
Verification
-
Verify the deployment is active by running the following command:
Replace
<deployment_name>with the name of the deployment you created.
Infrastructure Manager template for control plane machines¶
You can use the following 05_control_plane.tf Infrastructure Manager template to deploy the control plane machines that you need for your OpenShift Container Platform cluster:
terraform {
# Infra manager supports specific Terraform versions; ensure compatibility
required_version = ">=1.2.3"
required_providers {
google = {
source = "hashicorp/google"
version = ">= 4.0.0"
}
google-beta = {
source = "hashicorp/google-beta",
version = ">= 4.0.0"
}
local = {
source = "hashicorp/local",
version = ">= 2.0.0"
}
}
}
provider "google-beta" {
project = "${var.project}"
region = "${var.region}"
}
variable "infra_id" {
type = string
description = "OpenShift Installer Infrastructure ID"
}
variable "project" {
type = string
description = "Project ID"
}
variable "region" {
type = string
description = "GCP Region where the resources will be created."
default = "us-central1"
}
# Terraform handles lists but the infra-manager --input-values only
# supports scalar types.
# If you require more or less zones, you must manually add them below
# as a single variable for each. You must add the zones to the
# locals `zones` list below.
variable "zone_0" {
type = string
description = "Zone 1 for the instance types."
}
variable "zone_1" {
type = string
description = "Zone 2 for the instance types."
}
variable "zone_2" {
type = string
description = "Zone 3 for the instance types."
}
variable "subnet" {
type = string
description = "Control plane subnet."
}
variable "image" {
type = string
description = "Cluster Image."
}
variable "machine_type" {
type = string
description = "Machine type for the control plane machine."
default = "n1-standard-4"
}
variable "disk_size" {
type = string
description = "Size in GB for the root volume."
default = "128"
}
variable "disk_type" {
type = string
description = "Type of storage disk for the vm."
default = "pd-ssd"
}
variable "service_account_email" {
type = string
description = "Email for the service account attached to the control planes."
}
data "local_file" "ignition_file" {
filename = "${path.module}/master.ign"
}
resource "google_compute_instance" "master_0" {
provider = google-beta
name = "${var.infra_id}-master-0"
zone = "${var.zone_0}"
machine_type = "${var.machine_type}"
tags = [
"${var.infra_id}-master"
]
boot_disk {
auto_delete = true
initialize_params {
size = "${var.disk_size}"
image = "${var.image}"
type = "${var.disk_type}"
}
}
network_interface {
subnetwork = "${var.subnet}"
}
metadata = {
user-data = data.local_file.ignition_file.content
}
service_account {
email = "${var.service_account_email}"
scopes = ["https://www.googleapis.com/auth/cloud-platform"]
}
}
resource "google_compute_instance" "master_1" {
provider = google-beta
name = "${var.infra_id}-master-1"
zone = "${var.zone_1}"
machine_type = "${var.machine_type}"
tags = [
"${var.infra_id}-master"
]
boot_disk {
auto_delete = true
initialize_params {
size = "${var.disk_size}"
image = "${var.image}"
type = "${var.disk_type}"
}
}
network_interface {
subnetwork = "${var.subnet}"
}
metadata = {
user-data = data.local_file.ignition_file.content
}
service_account {
email = "${var.service_account_email}"
scopes = ["https://www.googleapis.com/auth/cloud-platform"]
}
}
resource "google_compute_instance" "master_2" {
provider = google-beta
name = "${var.infra_id}-master-2"
zone = "${var.zone_2}"
machine_type = "${var.machine_type}"
tags = [
"${var.infra_id}-master"
]
boot_disk {
auto_delete = true
initialize_params {
size = "${var.disk_size}"
image = "${var.image}"
type = "${var.disk_type}"
}
}
network_interface {
subnetwork = "${var.subnet}"
}
metadata = {
user-data = data.local_file.ignition_file.content
}
service_account {
email = "${var.service_account_email}"
scopes = ["https://www.googleapis.com/auth/cloud-platform"]
}
}
Creating additional worker machines in Google Cloud¶
You can create worker machines in Google Cloud for your cluster by using the Infrastructure Manager template. You can adjust the number of machines by modifying the number of google_compute_instance resources in the provided template.
Note
If you do not use the provided Infrastructure Manager template to create your compute machines, you must review the provided information and manually create the infrastructure. If your cluster does not initialize correctly, you might have to contact Red Hat support with your installation logs.
If you are installing a three-node cluster, skip this step. A three-node cluster consists of three control plane machines, which also act as compute machines.
Prerequisites
- Ensure you defined the variables in the Exporting common variables, Creating load balancers in Google Cloud, and Creating the bootstrap machine in Google Cloud sections.
- Create the bootstrap machine.
- Create the control plane machines.
Procedure
-
Copy the template from the Infrastructure Manager template for worker machines section of this topic and save it as
06_worker.tfin a folder called06_workeron your computer. This template describes the worker machines that your cluster requires.-
You can edit the
06_worker.tffile to add additional tags to the compute machines, by modifying the existingtagsstanza as follows:
-
-
Copy the
worker.ignfile from your installation directory into the06_workerfolder by running the following command:<installation_directory>specifies the directory where you created the Ignition configuration files. -
Create the deployment by running the following command:
$ gcloud infra-manager deployments apply <worker_deployment_name> \ --location=${REGION} \ --project=${PROJECT_NAME} \ --local-source=./06_worker \ --input-values=infra_id=${INFRA_ID},project=${PROJECT_NAME},region=${REGION},zone_0=${ZONE_0},zone_1=${ZONE_1},subnet=${COMPUTE_SUBNET},image=${CLUSTER_IMAGE},service_account_email=${WORKER_SERVICE_ACCOUNT} \ --service-account=${INSTALL_SERVICE_ACCOUNT}<worker_deployment_name>specifies the name of the deployment. -
Remove the
worker.ignfile by running the following command:
Verification
-
Verify the deployment is active by running the following command:
Replace
<deployment_name>with the name of the deployment you created.
Infrastructure Manager template for worker machines¶
You can use the following 06_worker.tf Infrastructure Manager template to deploy the worker machines that you need for your OpenShift Container Platform cluster:
terraform {
# Infra manager supports specific Terraform versions; ensure compatibility
required_version = ">=1.2.3"
required_providers {
google = {
source = "hashicorp/google"
version = ">= 4.0.0"
}
}
}
provider "google-beta" {
project = "${var.project}"
region = "${var.region}"
}
variable "infra_id" {
type = string
description = "OpenShift Installer Infrastructure ID"
}
variable "project" {
type = string
description = "Project ID"
}
variable "region" {
type = string
description = "GCP Region where the resources will be created."
default = "us-central1"
}
# Terraform handles lists but the infra-manager --input-values only
# supports scalar types.
# If you require more or less zones, you must manually add them below
# as a single variable for each. You must add the zones to the
# locals `zones` list below.
variable "zone_0" {
type = string
description = "Zone 1 for the instance types."
}
variable "zone_1" {
type = string
description = "Zone 2 for the instance types."
}
variable "subnet" {
type = string
description = "Compute subnet."
}
variable "image" {
type = string
description = "Cluster Image."
}
variable "machine_type" {
type = string
description = "Machine type for the compute machine."
default = "n1-standard-4"
}
variable "disk_size" {
type = string
description = "Size in GB for the root volume."
default = "128"
}
variable "disk_type" {
type = string
description = "Type of storage disk for the vm."
default = "pd-ssd"
}
variable "service_account_email" {
type = string
description = "Email for the service account attached to the compute nodes."
}
data "local_file" "ignition_file" {
filename = "${path.module}/worker.ign"
}
resource "google_compute_instance" "worker_0" {
provider = google-beta
name = "${var.infra_id}-worker-0"
zone = "${var.zone_0}"
machine_type = "${var.machine_type}"
tags = [
"${var.infra_id}-worker"
]
boot_disk {
auto_delete = true
initialize_params {
size = "${var.disk_size}"
image = "${var.image}"
type = "${var.disk_type}"
}
}
network_interface {
subnetwork = "${var.subnet}"
}
metadata = {
user-data = data.local_file.ignition_file.content
}
service_account {
email = "${var.service_account_email}"
scopes = ["https://www.googleapis.com/auth/cloud-platform"]
}
}
resource "google_compute_instance" "worker_1" {
provider = google-beta
name = "${var.infra_id}-worker-1"
zone = "${var.zone_1}"
machine_type = "${var.machine_type}"
tags = [
"${var.infra_id}-worker"
]
boot_disk {
auto_delete = true
initialize_params {
size = "${var.disk_size}"
image = "${var.image}"
type = "${var.disk_type}"
}
}
network_interface {
subnetwork = "${var.subnet}"
}
metadata = {
user-data = data.local_file.ignition_file.content
}
service_account {
email = "${var.service_account_email}"
scopes = ["https://www.googleapis.com/auth/cloud-platform"]
}
}
Removing bootstrap resources in Google Cloud¶
After the bootstrap process completes on your Google Cloud infrastructure, you can remove the bootstrap resources to reclaim the capacity that they consume, because the cluster no longer requires them.
Prerequisites
- Ensure you defined the variables in the Exporting common variables and Creating load balancers in Google Cloud sections.
- Create the bootstrap machine.
- Create the control plane machines.
Procedure
-
Change to the directory that includes the installation program and run the following command:
where:
<installation_directory>- Specifies the path to the directory where you stored the installation files.
--log-level- Specifies the log level. To view different installation details, specify
warn,debug, orerrorinstead ofinfo.
If the command exits without a
FATALwarning, your production control plane has initialized. -
To remove the bootstrap instance group from the backend services' backends, run the following commands:
$ gcloud compute backend-services remove-backend ${INFRA_ID}-api-internal --region=${REGION} --instance-group=${INFRA_ID}-bootstrap-ig --instance-group-zone=${ZONE_0}$ ingress_backendservice=$(gcloud compute backend-services list --filter="backends.group~${INFRA_ID}" --format='value(name)' | grep -v "${INFRA_ID}")-
If
ingress_backendserviceis not empty, run the followingdescribecommand for the bootstrap group: -
If the
describecommand displays that the bootstrap group is one of its backends, run the followingremove-backendcommand to remove the bootstrap group from the backends: -
To remove the bucket and the deployment, run the following commands:
$ gcloud infra-manager deployments delete <bootstrap_deployment_name> \ --project=${PROJECT_NAME} --location=${REGION} --quietSpecify the name of the bootstrap deployment you created for
<bootstrap_deployment_name>.
-
Logging in to the cluster by using the CLI¶
To log in to your cluster as the default system user, export the kubeconfig file. This configuration enables the CLI to authenticate and connect to the specific API server created during OpenShift Container Platform installation.
The kubeconfig file is specific to a cluster and OpenShift Container Platform generates it during installation.
Prerequisites
- You installed the OpenShift CLI (
oc). - Ensure the bootstrap process completed successfully.
Procedure
-
Export the
kubeadmincredentials by running the following command:where:
<installation_directory>- Specifies the path to the directory that stores the installation files.
-
Verify you can run
occommands successfully using the exported configuration by running the following command:
Next steps
- "Customize your cluster"
- "Remote health reporting"
Disabling the default software catalog sources¶
To use only trusted or locally available Operator catalogs, disable the default software catalog sources that OpenShift Container Platform configures during installation. In a restricted network environment, you must disable the default catalogs as a cluster administrator.
Procedure
-
Disable the sources for the default catalogs by adding
disableAllDefaultSources: trueto theOperatorHubobject:$ oc patch OperatorHub cluster --type json \ -p '[{"op": "add", "path": "/spec/disableAllDefaultSources", "value": true}]'Tip
Or, you can use the web console to manage catalog sources. From the Administration → Cluster Settings → Configuration → OperatorHub page, click the Sources tab, where you can create, update, delete, disable, and enable individual sources.
Approve the certificate signing requests for your machines¶
To allow newly added machines to join your OpenShift Container Platform cluster, confirm that the cluster approves pending certificate signing requests (CSRs), or approve them yourself. Approve client requests first, then server requests.
Prerequisites
- You added machines to your cluster.
Procedure
-
Confirm that the cluster recognizes the machines:
Example outputNAME STATUS ROLES AGE VERSION master-0 Ready master 63m v1.35.4 master-1 Ready master 63m v1.35.4 master-2 Ready master 64m v1.35.4The output lists all of the machines that you created.
Note
The preceding output might not include the compute nodes until you approve some CSRs.
-
Review the pending CSRs and ensure that you see the client requests with the
PendingorApprovedstatus for each machine that you added to the cluster:Example outputNAME AGE REQUESTOR CONDITION csr-8b2br 15m system:serviceaccount:openshift-machine-config-operator:node-bootstrapper Pending csr-8vnps 15m system:serviceaccount:openshift-machine-config-operator:node-bootstrapper Pending ...In this example, two machines are joining the cluster. You might see more approved CSRs in the list.
-
If the CSRs were not approved, after all of the pending CSRs for the machines you added are in
Pendingstatus, approve the CSRs for your cluster machines:Note
You must approve your CSRs within an hour of adding the machines to the cluster. If you do not approve them within an hour, the certificates rotate, and more than two certificates are present for each node. You must approve all of these certificates. After you approve the client CSR, the kubelet creates a secondary CSR for the serving certificate, which requires manual approval. The
machine-approverthen automatically approves later serving certificate renewal requests if the kubelet requests a new certificate with the same parameters.Note
For clusters running on platforms that are not machine API enabled, such as bare metal and other user-provisioned infrastructure, you must implement a method of automatically approving the kubelet serving certificate requests (CSRs). If you do not approve a request, the
oc exec,oc rsh, andoc logscommands cannot succeed, because the API server requires a serving certificate when it connects to the kubelet. Any operation that contacts the kubelet endpoint requires this certificate approval to be in place. The method must watch for new CSRs, confirm that thenode-bootstrapperservice account in thesystem:nodeorsystem:admingroups submitted the CSR, and confirm the identity of the node.-
To approve them individually, run the following command for each valid CSR:
where:
<csr_name>- Specifies the name of a CSR from the list of current CSRs.
-
To approve all pending CSRs, run the following command:
$ oc get csr -o go-template='{{range .items}}{{if not .status}}{{.metadata.name}}{{"\n"}}{{end}}{{end}}' | xargs --no-run-if-empty oc adm certificate approveNote
Some Operators might not become available until you approve some CSRs. Each node submits two CSRs, so you might need to run the command to approve CSRs many times.
-
-
After you approve your client requests, review the server requests for each machine that you added to the cluster:
-
If the remaining CSRs are not approved, and are in the
Pendingstatus, approve the CSRs for your cluster machines:-
To approve them individually, run the following command for each valid CSR:
where:
<csr_name>- Specifies the name of a CSR from the list of current CSRs.
-
To approve all pending CSRs, run the following command:
-
-
After you approve all client and server CSRs, the machines have the
Readystatus. Verify this by running the following command:Example outputNAME STATUS ROLES AGE VERSION master-0 Ready master 73m v1.35.4 master-1 Ready master 73m v1.35.4 master-2 Ready master 74m v1.35.4 worker-0 Ready worker 11m v1.35.4 worker-1 Ready worker 11m v1.35.4Note
You might need to wait a few minutes after approval of the server CSRs for the machines to reach the
Readystatus.
Adding the ingress DNS records¶
If you removed the DNS zone configuration when creating Kubernetes manifests and generating Ignition configs, you must manually create DNS records that point at the ingress load balancer so that external clients can reach the applications that run on your cluster.
You can create either a wildcard *.apps.{baseDomain}. or specific records. You can use A, CNAME, and other records per your requirements.
Prerequisites
- Ensure you defined the variables in the Exporting common variables section.
- Remove the DNS Zone configuration when creating Kubernetes manifests and generating Ignition configs.
- Ensure the bootstrap process completed successfully.
Procedure
-
Wait for the Ingress router to create a load balancer and populate the
EXTERNAL-IPfield: -
Add the A record to your zones:
-
To use A records:
-
Export the variable for the router IP address:
-
Add the A record to the private zones:
-
For an external cluster, also add the A record to the public zones:
-
-
To add explicit domains instead of using a wildcard, create entries for each of the cluster’s current routes:
$ oc get --all-namespaces -o jsonpath='{range .items[*]}{range .status.ingress[*]}{.host}{"\n"}{end}{end}' routesExample outputoauth-openshift.apps.your.cluster.domain.example.com console-openshift-console.apps.your.cluster.domain.example.com downloads-openshift-console.apps.your.cluster.domain.example.com alertmanager-main-openshift-monitoring.apps.your.cluster.domain.example.com prometheus-k8s-openshift-monitoring.apps.your.cluster.domain.example.com
-
Completing a Google Cloud installation on user-provisioned infrastructure¶
After you start the OpenShift Container Platform installation on Google Cloud user-provisioned infrastructure, you can monitor the cluster events to confirm that the installation completes successfully and the cluster is ready for use.
Prerequisites
- Ensure the bootstrap process completed successfully.
Procedure
-
Complete the cluster installation:
where
<installation_directory>specifies the path to the directory that you stored the installation files in.Warning
- The Ignition config files that the installation program generates contain certificates that expire after 24 hours, which are then renewed at that time. If the cluster is shut down before renewing the certificates and the cluster is later restarted after the 24 hours have elapsed, the cluster automatically recovers the expired certificates. The exception is that you must manually approve the pending
node-bootstrappercertificate signing requests (CSRs) to recover kubelet certificates. See the documentation for Recovering from expired control plane certificates for more information. - It is recommended that you use Ignition config files within 12 hours after they are generated because the 24-hour certificate rotates from 16 to 22 hours after the cluster is installed. By using the Ignition config files within 12 hours, you can avoid installation failure if the certificate update runs during installation.
- The Ignition config files that the installation program generates contain certificates that expire after 24 hours, which are then renewed at that time. If the cluster is shut down before renewing the certificates and the cluster is later restarted after the 24 hours have elapsed, the cluster automatically recovers the expired certificates. The exception is that you must manually approve the pending
-
Observe the running state of your cluster.
-
Run the following command to view the current cluster version and status:
-
Run the following command to view the Operators managed on the control plane by the Cluster Version Operator (CVO):
Example outputNAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE authentication 4.5.4 True False False 7m56s cloud-credential 4.5.4 True False False 31m cluster-autoscaler 4.5.4 True False False 16m console 4.5.4 True False False 10m csi-snapshot-controller 4.5.4 True False False 16m dns 4.5.4 True False False 22m etcd 4.5.4 False False False 25s image-registry 4.5.4 True False False 16m ingress 4.5.4 True False False 16m insights 4.5.4 True False False 17m kube-apiserver 4.5.4 True False False 19m kube-controller-manager 4.5.4 True False False 20m kube-scheduler 4.5.4 True False False 20m kube-storage-version-migrator 4.5.4 True False False 16m machine-api 4.5.4 True False False 22m machine-config 4.5.4 True False False 22m marketplace 4.5.4 True False False 16m monitoring 4.5.4 True False False 10m network 4.5.4 True False False 23m node-tuning 4.5.4 True False False 23m openshift-apiserver 4.5.4 True False False 17m openshift-controller-manager 4.5.4 True False False 15m openshift-samples 4.5.4 True False False 16m operator-lifecycle-manager 4.5.4 True False False 22m operator-lifecycle-manager-catalog 4.5.4 True False False 22m operator-lifecycle-manager-packageserver 4.5.4 True False False 18m service-ca 4.5.4 True False False 23m service-catalog-apiserver 4.5.4 True False False 23m service-catalog-controller-manager 4.5.4 True False False 23m storage 4.5.4 True False False 17m -
Run the following command to view your cluster pods:
Example outputNAMESPACE NAME READY STATUS RESTARTS AGE kube-system etcd-member-ip-10-0-3-111.us-east-2.compute.internal 1/1 Running 0 35m kube-system etcd-member-ip-10-0-3-239.us-east-2.compute.internal 1/1 Running 0 37m kube-system etcd-member-ip-10-0-3-24.us-east-2.compute.internal 1/1 Running 0 35m openshift-apiserver-operator openshift-apiserver-operator-6d6674f4f4-h7t2t 1/1 Running 1 37m openshift-apiserver apiserver-fm48r 1/1 Running 0 30m openshift-apiserver apiserver-fxkvv 1/1 Running 0 29m openshift-apiserver apiserver-q85nm 1/1 Running 0 29m ... openshift-service-ca-operator openshift-service-ca-operator-66ff6dc6cd-9r257 1/1 Running 0 37m openshift-service-ca apiservice-cabundle-injector-695b6bcbc-cl5hm 1/1 Running 0 35m openshift-service-ca configmap-cabundle-injector-8498544d7-25qn6 1/1 Running 0 35m openshift-service-ca service-serving-cert-signer-6445fc9c6-wqdqn 1/1 Running 0 35m openshift-service-catalog-apiserver-operator openshift-service-catalog-apiserver-operator-549f44668b-b5q2w 1/1 Running 0 32m openshift-service-catalog-controller-manager-operator openshift-service-catalog-controller-manager-operator-b78cr2lnm 1/1 Running 0 31mWhen the current cluster version is
AVAILABLE, the installation is complete.
-
Telemetry access for OpenShift Container Platform¶
To provide metrics about cluster health and the success of updates, the Telemetry service requires internet access. When connected, this service runs automatically by default and registers your cluster to OpenShift Cluster Manager.
After you confirm that your OpenShift Cluster Manager inventory is correct, either maintained automatically by Telemetry or manually by using OpenShift Cluster Manager,use subscription watch to track your OpenShift Container Platform subscriptions at the account or multi-cluster level. For more information about subscription watch, see "Data Gathered and Used by Red Hat’s subscription services" in the Additional resources section.
Additional resources