Add worker nodes and provision DPUs¶
After the DPF Operator and the hosted cluster are configured, adjust the OVN-Kubernetes CNI settings, add DPU-equipped worker nodes to the management cluster, and provision the DPUs.
Enable the OVN-Kubernetes resource injector¶
You can install the OVN-Kubernetes resource injector by using Helm to deploy a mutating admission webhook that automatically injects SR-IOV virtual function resource requests and network attachment annotations into each pod scheduled to a worker node.
Note
Virtual function resource capacity on worker nodes is provided by the NodeSRIOVDevicePluginConfig resource, which replaces the manual SR-IOV device plugin DaemonSet and control plane node patching used in earlier DPF versions.
Prerequisites
- You have access to the management cluster as a user with the
cluster-adminrole. - You have installed the
ocCLI. - You have installed the
helmCLI. - You have set the DPF Operator environment variables. For details, see "DPF Operator installation environment variables".
- You have created the
NodeSRIOVDevicePluginConfigresource.
Procedure
-
Install the OVN-Kubernetes resource injector by using Helm:
$ helm upgrade --install -n openshift-ovn-kubernetes ovn-kubernetes \ "$OVN_TEMPLATE_CHART_URL/ovn-kubernetes-chart" \ --version "${OVN_CHART_VERSION}" \ --skip-crds \ --set ovn-kubernetes-resource-injector.enabled=true \ --set ovn-kubernetes-resource-injector.resourceName="openshift.io/bf3_vfs" \ --set ovn-kubernetes-resource-injector.prioritizeOffloading=false \ --set ovn-kubernetes-resource-injector.controllerManager.hostNetwork=true \ --set ovn-kubernetes-resource-injector.controllerManager.webhookPort="19443" \ --set ovn-kubernetes-resource-injector.controllerManager.healthProbeBindAddress=":18081" \ --set ovn-kubernetes-resource-injector.controllerManager.webhook.image.pullPolicy=IfNotPresent \ --set "ovn-kubernetes-resource-injector.controllerManager.webhook.args={--leader-elect,--metrics-bind-address=:29091}" \ --set nodeWithDPUManifests.enabled=false \ --set nodeWithoutDPUManifests.enabled=false \ --set dpuManifests.enabled=false \ --set controlPlaneManifests.enabled=false \ --set commonManifests.enabled=false
Verification
-
Verify the resource injector mutating webhook configuration was applied:
OVN-Kubernetes DPU-Host mode¶
DPU-Host mode on worker nodes with accelerated OVN-Kubernetes CNI is automatically configured by the DPF provisioning controller.
When the DPFOperatorConfig resource is created and worker nodes with the worker-dpu label are provisioned, the DPF provisioning controller automatically configures the required settings for DPU-Host mode, including the network node identity and hardware offload configuration.
Add worker nodes by using the Bare Metal Operator¶
You can add DPU-equipped worker nodes to the management cluster by creating BareMetalHost resources that the Bare Metal Operator provisions.
Prerequisites
- You have access to the management cluster as a user with the
cluster-adminrole. - You have installed the
ocCLI. - You have installed the Bare Metal Operator on the management cluster.
- Physical worker servers with Redfish-compatible BMC, iDRAC, or iLO access are available.
- Network connectivity exists from the management cluster to the worker BMC interfaces.
- You have the BMC IP address and access credentials for each server.
- You have the MAC address of the management network interface for each server.
- You have the name of the root disk device for each server.
Procedure
-
Set the following environment variables for the worker node:
$ export BMC_IP=<bmc_ip_address> $ export BMC_USER=<bmc_username> $ export BMC_PASSWORD=<bmc_password> $ export WORKER_NAME=<worker_name> $ export BOOT_MAC=<management_interface_mac> $ export ROOT_DEVICE=<root_device_path>where:
<bmc_ip_address>- Specifies the IP address of the worker node BMC interface.
<bmc_username>- Specifies the username for BMC access.
<bmc_password>- Specifies the password for BMC access.
<worker_name>- Specifies a name for the worker node, such as
worker-01. <management_interface_mac>- Specifies the MAC address of the out-of-band management interface, such as
00:00:5E:00:53:01. <root_device_path>- Specifies the path to the root disk device, such as
/dev/nvme0n1.
-
Verify BMC connectivity from one of the control plane nodes:
-
Verify that the Bare Metal Operator is available:
-
Create a file named
provisioning.yamlwith the following content to disable the provisioning network:apiVersion: metal3.io/v1alpha1 kind: Provisioning metadata: name: provisioning-configuration spec: provisioningNetwork: "Disabled" watchAllNamespaces: falseWarning
When
provisioningNetworkis set toDisabled, servers boot by using Redfish virtual media instead of PXE. -
Apply the
Provisioningresource: -
Create a file named
bmc-secret.yamlwith the following content to store the BMC credentials: -
Apply the BMC credentials secret:
-
Create a file named
baremetalhost.yaml. TheuserDatasecret determines the node type:-
For a DPU-equipped worker node, reference the
worker-dpu-user-data-managedsecret:apiVersion: metal3.io/v1alpha1 kind: BareMetalHost metadata: name: ${WORKER_NAME} namespace: openshift-machine-api spec: online: true bootMACAddress: ${BOOT_MAC} rootDeviceHints: deviceName: ${ROOT_DEVICE} bmc: address: redfish-virtualmedia+https://${BMC_IP} credentialsName: ${WORKER_NAME}-bmc-secret disableCertificateVerification: true customDeploy: method: install_coreos userData: name: worker-dpu-user-data-managed namespace: openshift-machine-api -
For a regular worker node without a DPU, reference the
worker-user-data-managedsecret instead:apiVersion: metal3.io/v1alpha1 kind: BareMetalHost metadata: name: ${WORKER_NAME} namespace: openshift-machine-api spec: online: true bootMACAddress: ${BOOT_MAC} rootDeviceHints: deviceName: ${ROOT_DEVICE} bmc: address: redfish-virtualmedia+https://${BMC_IP} credentialsName: ${WORKER_NAME}-bmc-secret disableCertificateVerification: true customDeploy: method: install_coreos userData: name: worker-user-data-managed namespace: openshift-machine-apiWarning
Adding a regular worker node without a DPU is a Technology Preview feature.
-
-
Apply the
BareMetalHostresource:
Verification
-
Monitor the provisioning progress:
Approve worker node CSRs¶
You must approve the pending certificate signing requests (CSRs) for worker nodes that join the management cluster.
Note
Worker nodes provisioned by using a BareMetalHost resource do not have an associated Machine object, so the default OpenShift machine approver does not automatically approve their certificate signing requests (CSRs). You must manually approve the kube-apiserver-client-kubelet CSR from the node-bootstrapper service account and the kubelet-serving CSR from the node for each worker node.
Prerequisites
- You have access to the management cluster as a user with the
cluster-adminrole. - You have installed the
ocCLI. - Worker nodes are booted and attempting to join the management cluster.
Procedure
-
Watch for pending CSRs:
-
Approve all pending CSRs:
$ oc get csr -o go-template='{{range .items}}{{if not .status}}{{.metadata.name}}{{"\n"}}{{end}}{{end}}' | xargs oc adm certificate approveExample outputcertificatesigningrequest.certificates.k8s.io/csr-27bgq approved certificatesigningrequest.certificates.k8s.io/csr-69g65 approved certificatesigningrequest.certificates.k8s.io/csr-7r862 approved certificatesigningrequest.certificates.k8s.io/csr-f5vk7 approvedRepeat this step until no pending CSRs remain. Each node typically generates multiple CSRs.
-
Verify that the worker nodes joined the cluster:
Example outputNAME STATUS ROLES AGE VERSION host-worker1 NotReady worker 68s v1.35.6 host-worker2 NotReady worker 75s v1.35.6 master-0 Ready control-plane,master,worker 4d22h v1.35.6 master-1 Ready control-plane,master,worker 4d21h v1.35.6 master-2 Ready control-plane,master,worker 4d22h v1.35.6Note
The worker nodes show a status of
NotReadyuntil the DPU provisioning process is fully completed and all OVN-Kubernetes CNI components on the host and the DPU are running. Do not proceed to the next steps until all pending CSRs are approved.
Verify DPU provisioning¶
After the worker nodes join the management cluster, the DPUSet controller automatically detects nodes with the feature.node.kubernetes.io/dpu-enabled label, which the Node Feature Discovery Operator applies to DPU-equipped nodes. The controller then creates a DPU object for each node and starts the provisioning process. You can monitor the provisioning stages to verify progress.
Prerequisites
- You have access to the management cluster as a user with the
cluster-adminrole. - You have installed the
ocCLI. - The worker node CSRs are approved and the nodes have joined the management cluster.
Procedure
-
Watch for
DPUobject creation:Example outputNAME READY OPERATIONAL PHASE AGE <node-name>-<dpu-id> Unknown Node Effect 25s <node-name>-<dpu-id> Unknown Initialize Interface 26s <node-name>-<dpu-id> Unknown Config FW Parameters 28s <node-name>-<dpu-id> Unknown Prepare BFB 28s <node-name>-<dpu-id> Unknown OS Installing 5m28s <node-name>-<dpu-id> Unknown DPU Config 15m <node-name>-<dpu-id> Unknown Rebooting 26m <node-name>-<dpu-id> Unknown Host Network Configuration 27m <node-name>-<dpu-id> False DPU Cluster Config 64m <node-name>-<dpu-id> Unknown Node Effect Removal 71m <node-name>-<dpu-id> True True Ready 71mThe
DPUobjects progress through the following provisioning stages:Initializing- The
DPUobject is created. OS Installing- The BFB installation is in progress.
Rebooting- The host and DPU are resetting.
DPU Cluster Config- The DPU Kubernetes node join procedure is in progress. DPU CSRs are automatically approved by the DPF HCP Provisioner Operator.
Host Network Configuration- Networking configuration adjustments are applied on the host.
Ready- The DPU is successfully provisioned and ready to use.
Error- Provisioning failed. Check events and conditions for details.
Warning
When the provisioning stage reaches
DPU Cluster Config, proceed to "Configure authorization for the hosted cluster" to complete the DPU node join process. -
Monitor detailed provisioning progress:
-
Optional: View detailed status for a specific
DPUobject:In the following command, replace
<dpu_name>with the name of theDPUresource: -
Optional: Follow the provisioning controller logs for a specific DPU:
In the following command, replace
<dpu_name>with the name of theDPUresource:
Configure authorization for the hosted cluster¶
DPF services running on DPU nodes require privileged access to host networking and devices. You must create a ClusterRoleBinding on the hosted cluster that grants the privileged security context constraint (SCC) to all service accounts in the dpf-operator-system namespace.
Prerequisites
- You have access to the hosted cluster as a user with the
cluster-adminrole. - You have installed the
ocCLI. - The hosted cluster kubeconfig file is available.
- DPU provisioning has reached the
DPU Cluster Configstage.
Procedure
-
Get the hosted cluster kubeconfig:
-
Switch to the hosted cluster context:
-
Create a file named
dpu-cluster-scc.yamlwith the following content:apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: dpf-system-scc-privileged labels: app.kubernetes.io/component: rbac app.kubernetes.io/part-of: dpu-services roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: system:openshift:scc:privileged subjects: - kind: Group apiGroup: rbac.authorization.k8s.io name: system:serviceaccounts:dpf-operator-system -
Apply the resource file on the hosted cluster:
Verify full system readiness¶
After the DPU provisioning process completes, you can verify that all worker nodes, SR-IOV virtual functions, and DPU services are operational on the management cluster.
Prerequisites
- You have access to the management cluster as a user with the
cluster-adminrole. - You have installed the
ocCLI. - DPU provisioning has completed.
Procedure
-
Switch back to the management cluster context:
-
Verify that all worker nodes are in a
Readystate: -
Verify that SR-IOV virtual functions are registered as Kubernetes node resources on the worker nodes:
-
Verify that all DPU services are in a
Successphase:Example outputNAME READY PHASE AGE doca-telemetry-service-7s8pb True Success 42m flannel True Success 26h hbn-gffmv True Success 25m kube-state-metrics-rbac True Success 4h10m node-problem-detector True Success 4h10m nvidia-k8s-ipam-node True Success 4h10m ovn-f49zx True Success 17m ovs-cni True Success 26h servicechainset-rbac-and-crds True Success 138m sfc-controller True Success 26h sriov-device-plugin True Success 26h -
Optional: View detailed DPU service status: