About Migration Toolkit for Virtualization (MTV) providers¶
To migrate a virtual machine (VM) across OpenShift Container Platform clusters, you must configure an OpenShift Container Platform provider for each cluster that you are including in the migration. If MTV is already installed on a cluster, a local provider already exists.
Configuring the root certificate authority for providers¶
You must configure an OpenShift Container Platform provider for each cluster that you are including in a migration, and each provider requires a certificate authority (CA) for the cluster. Configure the root CA for the entire cluster to avoid CA expiration, which causes the provider to fail.
Procedure
-
Run the following command against the cluster for which you are creating the provider:
-
Copy the printed certificate.
-
In the Migration Toolkit for Virtualization (MTV) web console, create a provider and select OpenShift Virtualization.
-
Paste the certificate into the CA certificate field, as shown in the following example:
Creating the long-lived service account and token to use with MTV providers¶
When you register an OpenShift Virtualization provider in the Migration Toolkit for Virtualization (MTV) web console, you must create a service account and cluster role binding, which gives MTV persistent permissions to read and create virtual machine resources during migration.
Procedure
-
Create the cluster role as shown in the following example:
apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: live-migration-role rules: - apiGroups: - forklift.konveyor.io resources: - '*' verbs: - get - list - watch - apiGroups: - "" resources: - secrets - namespaces - configmaps - persistentvolumes - persistentvolumeclaims verbs: - get - list - watch - create - update - patch - delete - apiGroups: - k8s.cni.cncf.io resources: - network-attachment-definitions verbs: - get - list - watch - apiGroups: - storage.k8s.io resources: - storageclasses verbs: - get - list - watch - apiGroups: - kubevirt.io resources: - virtualmachines - virtualmachines/finalizers - virtualmachineinstancemigrations verbs: - get - list - watch - create - update - patch - delete - apiGroups: - kubevirt.io resources: - kubevirts - virtualmachineinstances verbs: - get - list - watch - apiGroups: - cdi.kubevirt.io resources: - datavolumes - datavolumes/finalizers verbs: - get - list - watch - create - update - patch - delete - apiGroups: - apps resources: - deployments verbs: - get - list - watch - create - update - patch - delete - apiGroups: - instancetype.kubevirt.io resources: - virtualmachineclusterpreferences - virtualmachineclusterinstancetypes verbs: - get - list - watch - apiGroups: - instancetype.kubevirt.io resources: - virtualmachinepreferences - virtualmachineinstancetypes verbs: - get - list - watch - create - update - patch - delete -
Create the cluster role by running the following command:
-
Create a service account by running the following command:
-
Create a cluster role binding that links the service account to the cluster role, by running the following command:
-
Create a secret to hold the token by saving the following manifest as a YAML file:
-
Apply the manifest by running the following command:
-
After the secret is populated, run the following command to get the service account bearer token:
-
Copy the printed token.
-
In the Migration Toolkit for Virtualization (MTV) web console, when you create a provider and select OpenShift Virtualization, paste the token into the Service account bearer token field.
Additional resources