mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-09-28 14:08:55 +00:00
Remove unneeded intermediate folders
This commit is contained in:
+152
@@ -0,0 +1,152 @@
|
||||
---
|
||||
title: Setting up the Amazon Cloud Provider
|
||||
weight: 1
|
||||
aliases:
|
||||
- /rancher/v2.x/en/cluster-provisioning/rke-clusters/cloud-providers/amazon/
|
||||
---
|
||||
|
||||
When using the `Amazon` cloud provider, you can leverage the following capabilities:
|
||||
|
||||
- **Load Balancers:** Launches an AWS Elastic Load Balancer (ELB) when choosing `Layer-4 Load Balancer` in **Port Mapping** or when launching a `Service` with `type: LoadBalancer`.
|
||||
- **Persistent Volumes**: Allows you to use AWS Elastic Block Stores (EBS) for persistent volumes.
|
||||
|
||||
See [cloud-provider-aws README](https://kubernetes.github.io/cloud-provider-aws/) for all information regarding the Amazon cloud provider.
|
||||
|
||||
To set up the Amazon cloud provider,
|
||||
|
||||
1. [Create an IAM role and attach to the instances](#1-create-an-iam-role-and-attach-to-the-instances)
|
||||
2. [Configure the ClusterID](#2-configure-the-clusterid)
|
||||
|
||||
### 1. Create an IAM Role and attach to the instances
|
||||
|
||||
All nodes added to the cluster must be able to interact with EC2 so that they can create and remove resources. You can enable this interaction by using an IAM role attached to the instance. See [Amazon documentation: Creating an IAM Role](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-roles-for-amazon-ec2.html#create-iam-role) how to create an IAM role. There are two example policies:
|
||||
|
||||
* The first policy is for the nodes with the `controlplane` role. These nodes have to be able to create/remove EC2 resources. The following IAM policy is an example, please remove any unneeded permissions for your use case.
|
||||
* The second policy is for the nodes with the `etcd` or `worker` role. These nodes only have to be able to retrieve information from EC2.
|
||||
|
||||
While creating an [Amazon EC2 cluster]({{<baseurl>}}/rancher/v2.5/en/cluster-provisioning/rke-clusters/node-pools/ec2/), you must fill in the **IAM Instance Profile Name** (not ARN) of the created IAM role when creating the **Node Template**.
|
||||
|
||||
While creating a [Custom cluster]({{<baseurl>}}/rancher/v2.5/en/cluster-provisioning/rke-clusters/custom-nodes), you must manually attach the IAM role to the instance(s).
|
||||
|
||||
IAM Policy for nodes with the `controlplane` role:
|
||||
|
||||
```json
|
||||
{
|
||||
"Version": "2012-10-17",
|
||||
"Statement": [
|
||||
{
|
||||
"Effect": "Allow",
|
||||
"Action": [
|
||||
"autoscaling:DescribeAutoScalingGroups",
|
||||
"autoscaling:DescribeLaunchConfigurations",
|
||||
"autoscaling:DescribeTags",
|
||||
"ec2:DescribeInstances",
|
||||
"ec2:DescribeRegions",
|
||||
"ec2:DescribeRouteTables",
|
||||
"ec2:DescribeSecurityGroups",
|
||||
"ec2:DescribeSubnets",
|
||||
"ec2:DescribeVolumes",
|
||||
"ec2:CreateSecurityGroup",
|
||||
"ec2:CreateTags",
|
||||
"ec2:CreateVolume",
|
||||
"ec2:ModifyInstanceAttribute",
|
||||
"ec2:ModifyVolume",
|
||||
"ec2:AttachVolume",
|
||||
"ec2:AuthorizeSecurityGroupIngress",
|
||||
"ec2:CreateRoute",
|
||||
"ec2:DeleteRoute",
|
||||
"ec2:DeleteSecurityGroup",
|
||||
"ec2:DeleteVolume",
|
||||
"ec2:DetachVolume",
|
||||
"ec2:RevokeSecurityGroupIngress",
|
||||
"ec2:DescribeVpcs",
|
||||
"elasticloadbalancing:AddTags",
|
||||
"elasticloadbalancing:AttachLoadBalancerToSubnets",
|
||||
"elasticloadbalancing:ApplySecurityGroupsToLoadBalancer",
|
||||
"elasticloadbalancing:CreateLoadBalancer",
|
||||
"elasticloadbalancing:CreateLoadBalancerPolicy",
|
||||
"elasticloadbalancing:CreateLoadBalancerListeners",
|
||||
"elasticloadbalancing:ConfigureHealthCheck",
|
||||
"elasticloadbalancing:DeleteLoadBalancer",
|
||||
"elasticloadbalancing:DeleteLoadBalancerListeners",
|
||||
"elasticloadbalancing:DescribeLoadBalancers",
|
||||
"elasticloadbalancing:DescribeLoadBalancerAttributes",
|
||||
"elasticloadbalancing:DetachLoadBalancerFromSubnets",
|
||||
"elasticloadbalancing:DeregisterInstancesFromLoadBalancer",
|
||||
"elasticloadbalancing:ModifyLoadBalancerAttributes",
|
||||
"elasticloadbalancing:RegisterInstancesWithLoadBalancer",
|
||||
"elasticloadbalancing:SetLoadBalancerPoliciesForBackendServer",
|
||||
"elasticloadbalancing:AddTags",
|
||||
"elasticloadbalancing:CreateListener",
|
||||
"elasticloadbalancing:CreateTargetGroup",
|
||||
"elasticloadbalancing:DeleteListener",
|
||||
"elasticloadbalancing:DeleteTargetGroup",
|
||||
"elasticloadbalancing:DescribeListeners",
|
||||
"elasticloadbalancing:DescribeLoadBalancerPolicies",
|
||||
"elasticloadbalancing:DescribeTargetGroups",
|
||||
"elasticloadbalancing:DescribeTargetHealth",
|
||||
"elasticloadbalancing:ModifyListener",
|
||||
"elasticloadbalancing:ModifyTargetGroup",
|
||||
"elasticloadbalancing:RegisterTargets",
|
||||
"elasticloadbalancing:SetLoadBalancerPoliciesOfListener",
|
||||
"iam:CreateServiceLinkedRole",
|
||||
"kms:DescribeKey"
|
||||
],
|
||||
"Resource": [
|
||||
"*"
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
IAM policy for nodes with the `etcd` or `worker` role:
|
||||
|
||||
```json
|
||||
{
|
||||
"Version": "2012-10-17",
|
||||
"Statement": [
|
||||
{
|
||||
"Effect": "Allow",
|
||||
"Action": [
|
||||
"ec2:DescribeInstances",
|
||||
"ec2:DescribeRegions",
|
||||
"ecr:GetAuthorizationToken",
|
||||
"ecr:BatchCheckLayerAvailability",
|
||||
"ecr:GetDownloadUrlForLayer",
|
||||
"ecr:GetRepositoryPolicy",
|
||||
"ecr:DescribeRepositories",
|
||||
"ecr:ListImages",
|
||||
"ecr:BatchGetImage"
|
||||
],
|
||||
"Resource": "*"
|
||||
}
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
### 2. Configure the ClusterID
|
||||
|
||||
The following resources need to tagged with a `ClusterID`:
|
||||
|
||||
- **Nodes**: All hosts added in Rancher.
|
||||
- **Subnet**: The subnet used for your cluster.
|
||||
- **Security Group**: The security group used for your cluster.
|
||||
|
||||
>**Note:** Do not tag multiple security groups. Tagging multiple groups generates an error when creating an Elastic Load Balancer (ELB).
|
||||
|
||||
When you create an [Amazon EC2 Cluster]({{<baseurl>}}/rancher/v2.5/en/cluster-provisioning/rke-clusters/node-pools/ec2/), the `ClusterID` is automatically configured for the created nodes. Other resources still need to be tagged manually.
|
||||
|
||||
Use the following tag:
|
||||
|
||||
**Key** = `kubernetes.io/cluster/CLUSTERID` **Value** = `owned`
|
||||
|
||||
`CLUSTERID` can be any string you like, as long as it is equal across all tags set.
|
||||
|
||||
Setting the value of the tag to `owned` tells the cluster that all resources with this tag are owned and managed by this cluster. If you share resources between clusters, you can change the tag to:
|
||||
|
||||
**Key** = `kubernetes.io/cluster/CLUSTERID` **Value** = `shared`.
|
||||
|
||||
### Using Amazon Elastic Container Registry (ECR)
|
||||
|
||||
The kubelet component has the ability to automatically obtain ECR credentials, when the IAM profile mentioned in [Create an IAM Role and attach to the instances](#1-create-an-iam-role-and-attach-to-the-instances) is attached to the instance(s). When using a Kubernetes version older than v1.15.0, the Amazon cloud provider needs be configured in the cluster. Starting with Kubernetes version v1.15.0, the kubelet can obtain ECR credentials without having the Amazon cloud provider configured in the cluster.
|
||||
+72
@@ -0,0 +1,72 @@
|
||||
---
|
||||
title: Setting up the Azure Cloud Provider
|
||||
weight: 2
|
||||
aliases:
|
||||
- /rancher/v2.x/en/cluster-provisioning/rke-clusters/cloud-providers/azure/
|
||||
---
|
||||
|
||||
When using the `Azure` cloud provider, you can leverage the following capabilities:
|
||||
|
||||
- **Load Balancers:** Launches an Azure Load Balancer within a specific Network Security Group.
|
||||
|
||||
- **Persistent Volumes:** Supports using Azure Blob disks and Azure Managed Disks with standard and premium storage accounts.
|
||||
|
||||
- **Network Storage:** Support Azure Files via CIFS mounts.
|
||||
|
||||
The following account types are not supported for Azure Subscriptions:
|
||||
|
||||
- Single tenant accounts (i.e. accounts with no subscriptions).
|
||||
- Multi-subscription accounts.
|
||||
|
||||
To set up the Azure cloud provider following credentials need to be configured:
|
||||
|
||||
1. [Set up the Azure Tenant ID](#1-set-up-the-azure-tenant-id)
|
||||
2. [Set up the Azure Client ID and Azure Client Secret](#2-set-up-the-azure-client-id-and-azure-client-secret)
|
||||
3. [Configure App Registration Permissions](#3-configure-app-registration-permissions)
|
||||
4. [Set up Azure Network Security Group Name](#4-set-up-azure-network-security-group-name)
|
||||
|
||||
### 1. Set up the Azure Tenant ID
|
||||
|
||||
Visit [Azure portal](https://portal.azure.com), login and go to **Azure Active Directory** and select **Properties**. Your **Directory ID** is your **Tenant ID** (tenantID).
|
||||
|
||||
If you want to use the Azure CLI, you can run the command `az account show` to get the information.
|
||||
|
||||
### 2. Set up the Azure Client ID and Azure Client Secret
|
||||
|
||||
Visit [Azure portal](https://portal.azure.com), login and follow the steps below to create an **App Registration** and the corresponding **Azure Client ID** (aadClientId) and **Azure Client Secret** (aadClientSecret).
|
||||
|
||||
1. Select **Azure Active Directory**.
|
||||
1. Select **App registrations**.
|
||||
1. Select **New application registration**.
|
||||
1. Choose a **Name**, select `Web app / API` as **Application Type** and a **Sign-on URL** which can be anything in this case.
|
||||
1. Select **Create**.
|
||||
|
||||
In the **App registrations** view, you should see your created App registration. The value shown in the column **APPLICATION ID** is what you need to use as **Azure Client ID**.
|
||||
|
||||
The next step is to generate the **Azure Client Secret**:
|
||||
|
||||
1. Open your created App registration.
|
||||
1. In the **Settings** view, open **Keys**.
|
||||
1. Enter a **Key description**, select an expiration time and select **Save**.
|
||||
1. The generated value shown in the column **Value** is what you need to use as **Azure Client Secret**. This value will only be shown once.
|
||||
|
||||
### 3. Configure App Registration Permissions
|
||||
|
||||
The last thing you will need to do, is assign the appropriate permissions to your App registration.
|
||||
|
||||
1. Go to **More services**, search for **Subscriptions** and open it.
|
||||
1. Open **Access control (IAM)**.
|
||||
1. Select **Add**.
|
||||
1. For **Role**, select `Contributor`.
|
||||
1. For **Select**, select your created App registration name.
|
||||
1. Select **Save**.
|
||||
|
||||
### 4. Set up Azure Network Security Group Name
|
||||
|
||||
A custom Azure Network Security Group (securityGroupName) is needed to allow Azure Load Balancers to work.
|
||||
|
||||
If you provision hosts using Rancher Machine Azure driver, you will need to edit them manually to assign them to this Network Security Group.
|
||||
|
||||
You should already assign custom hosts to this Network Security Group during provisioning.
|
||||
|
||||
Only hosts expected to be load balancer back ends need to be in this group.
|
||||
+47
@@ -0,0 +1,47 @@
|
||||
---
|
||||
title: Setting up Cloud Providers
|
||||
weight: 2300
|
||||
aliases:
|
||||
- /rancher/v2.5/en/concepts/clusters/cloud-providers/
|
||||
- /rancher/v2.5/en/cluster-provisioning/rke-clusters/options/cloud-providers
|
||||
- /rancher/v2.x/en/cluster-provisioning/rke-clusters/cloud-providers/
|
||||
---
|
||||
A _cloud provider_ is a module in Kubernetes that provides an interface for managing nodes, load balancers, and networking routes.
|
||||
|
||||
When a cloud provider is set up in Rancher, the Rancher server can automatically provision new nodes, load balancers or persistent storage devices when launching Kubernetes definitions, if the cloud provider you're using supports such automation.
|
||||
|
||||
Your cluster will not provision correctly if you configure a cloud provider cluster of nodes that do not meet the prerequisites.
|
||||
|
||||
By default, the **Cloud Provider** option is set to `None`.
|
||||
|
||||
The following cloud providers can be enabled:
|
||||
|
||||
* Amazon
|
||||
* Azure
|
||||
* GCE (Google Compute Engine)
|
||||
* vSphere
|
||||
|
||||
### Setting up the Amazon Cloud Provider
|
||||
|
||||
For details on enabling the Amazon cloud provider, refer to [this page.]({{<baseurl>}}/rancher/v2.5/en/cluster-provisioning/rke-clusters/cloud-providers/amazon)
|
||||
|
||||
### Setting up the Azure Cloud Provider
|
||||
|
||||
For details on enabling the Azure cloud provider, refer to [this page.]({{<baseurl>}}/rancher/v2.5/en/cluster-provisioning/rke-clusters/cloud-providers/azure)
|
||||
|
||||
### Setting up the GCE Cloud Provider
|
||||
|
||||
For details on enabling the Google Compute Engine cloud provider, refer to [this page.]({{<baseurl>}}/rancher/v2.5/en/cluster-provisioning/rke-clusters/cloud-providers/gce)
|
||||
|
||||
### Setting up the vSphere Cloud Provider
|
||||
|
||||
For details on enabling the vSphere cloud provider, refer to [this page.](./vsphere)
|
||||
|
||||
### Setting up a Custom Cloud Provider
|
||||
|
||||
The `Custom` cloud provider is available if you want to configure any Kubernetes cloud provider.
|
||||
|
||||
For the custom cloud provider option, you can refer to the [RKE docs]({{<baseurl>}}/rke/latest/en/config-options/cloud-providers/) on how to edit the yaml file for your specific cloud provider. There are specific cloud providers that have more detailed configuration:
|
||||
|
||||
* [vSphere]({{<baseurl>}}/rke/latest/en/config-options/cloud-providers/vsphere/)
|
||||
* [OpenStack]({{<baseurl>}}/rke/latest/en/config-options/cloud-providers/openstack/)
|
||||
+56
@@ -0,0 +1,56 @@
|
||||
---
|
||||
title: Setting up the Google Compute Engine Cloud Provider
|
||||
weight: 3
|
||||
aliases:
|
||||
- /rancher/v2.x/en/cluster-provisioning/rke-clusters/cloud-providers/gce/
|
||||
---
|
||||
|
||||
In this section, you'll learn how to enable the Google Compute Engine (GCE) cloud provider for custom clusters in Rancher. A custom cluster is one in which Rancher installs Kubernetes on existing nodes.
|
||||
|
||||
The official Kubernetes documentation for the GCE cloud provider is [here.](https://kubernetes.io/docs/concepts/cluster-administration/cloud-providers/#gce)
|
||||
|
||||
> **Prerequisites:** The service account of `Identity and API` access on GCE needs the `Computer Admin` permission.
|
||||
|
||||
If you are using Calico,
|
||||
|
||||
1. Go to the cluster view in the Rancher UI, and click **⋮ > Edit.**
|
||||
1. Click **Edit as YAML,** and enter the following configuration:
|
||||
|
||||
```
|
||||
rancher_kubernetes_engine_config:
|
||||
cloud_provider:
|
||||
name: gce
|
||||
customCloudProvider: |-
|
||||
[Global]
|
||||
project-id=<your project ID, optional>
|
||||
network-name=<your network, optional if using default network>
|
||||
subnetwork-name=<your subnetwork of the above network, optional if using default network>
|
||||
node-instance-prefix=<your instance group name/your instance name specific prefix, required>
|
||||
node-tags=<your network tags, must patch one or some tags, required>
|
||||
network:
|
||||
options:
|
||||
calico_cloud_provider: "gce"
|
||||
plugin: "calico"
|
||||
```
|
||||
|
||||
If you are using Canal or Flannel,
|
||||
|
||||
1. Go to the cluster view in the Rancher UI, and click **⋮ > Edit.**
|
||||
1. Click **Edit as YAML,** and enter the following configuration:
|
||||
|
||||
```
|
||||
rancher_kubernetes_engine_config:
|
||||
cloud_provider:
|
||||
name: gce
|
||||
customCloudProvider: |-
|
||||
[Global]
|
||||
project-id=<your project ID, optional>
|
||||
network-name=<your network, optional if using default network>
|
||||
subnetwork-name=<your subnetwork of the above network, optional if using default network>
|
||||
node-instance-prefix=<your instance group name/your instance name specific prefix, required>
|
||||
node-tags=<your network tags, must patch one or some tags, required>
|
||||
services:
|
||||
kube_controller:
|
||||
extra_args:
|
||||
configure-cloud-routes: true # we need to allow the cloud provider configure the routes for the hosts
|
||||
```
|
||||
+26
@@ -0,0 +1,26 @@
|
||||
---
|
||||
title: How to Configure In-tree vSphere Cloud Provider
|
||||
shortTitle: In-tree Cloud Provider
|
||||
weight: 10
|
||||
aliases:
|
||||
- /rancher/v2.x/en/cluster-provisioning/rke-clusters/cloud-providers/vsphere/in-tree/
|
||||
---
|
||||
|
||||
To set up the in-tree vSphere cloud provider, follow these steps while creating the vSphere cluster in Rancher:
|
||||
|
||||
1. Set **Cloud Provider** option to `Custom` or `Custom (In-Tree)`.
|
||||
|
||||
{{< img "/img/rancher/vsphere-node-driver-cloudprovider.png" "vsphere-node-driver-cloudprovider">}}
|
||||
|
||||
1. Click on **Edit as YAML**
|
||||
1. Insert the following structure to the pre-populated cluster YAML. This structure must be placed under `rancher_kubernetes_engine_config`. Note that the `name` *must* be set to `vsphere`.
|
||||
|
||||
```yaml
|
||||
rancher_kubernetes_engine_config:
|
||||
cloud_provider:
|
||||
name: vsphere
|
||||
vsphereCloudProvider:
|
||||
[Insert provider configuration]
|
||||
```
|
||||
|
||||
Rancher uses RKE (the Rancher Kubernetes Engine) to provision Kubernetes clusters. Refer to the [vSphere configuration reference in the RKE documentation]({{<baseurl>}}/rke/latest/en/config-options/cloud-providers/vsphere/config-reference/) for details about the properties of the `vsphereCloudProvider` directive.
|
||||
+59
@@ -0,0 +1,59 @@
|
||||
---
|
||||
title: How to Configure Out-of-tree vSphere Cloud Provider
|
||||
shortTitle: Out-of-tree Cloud Provider
|
||||
weight: 10
|
||||
aliases:
|
||||
- /rancher/v2.x/en/cluster-provisioning/rke-clusters/cloud-providers/vsphere/out-of-tree/
|
||||
---
|
||||
_Available as of v2.5+_
|
||||
|
||||
Kubernetes is moving away from maintaining cloud providers in-tree. vSphere has an out-of-tree cloud provider that can be used by installing the vSphere cloud provider and cloud storage plugins.
|
||||
|
||||
This page covers how to install the Cloud Provider Interface (CPI) and Cloud Storage Interface (CSI) plugins after bringing up a cluster.
|
||||
|
||||
# Prerequisites
|
||||
|
||||
The vSphere versions supported:
|
||||
|
||||
* 6.7u3
|
||||
* 7.0u1 or higher.
|
||||
|
||||
The Kubernetes version must be 1.19 or higher.
|
||||
|
||||
Using the vSphere out-of-tree cloud provider requires Linux nodes and is not supported on Windows.
|
||||
|
||||
# Installation
|
||||
|
||||
The Cloud Provider Interface (CPI) should be installed first before installing the Cloud Storage Interface (CSI).
|
||||
|
||||
### 1. Create a vSphere cluster
|
||||
|
||||
1. On the Clusters page, click on **Add Cluster** and select the **vSphere** option or **Existing Nodes** option.
|
||||
1. Under **Cluster Options** in the **Cloud Provider** section, select **External (Out-of-tree)**. This sets the cloud provider option on the Kubernetes cluster to `external` which sets your Kubernetes cluster up to be configured with an out-of-tree cloud provider.
|
||||
1. Finish creating your cluster.
|
||||
|
||||
### 2. Install the CPI plugin
|
||||
|
||||
1. From the **Cluster Explorer** view, go to the top left dropdown menu and click **Apps & Marketplace.**
|
||||
1. Select the **vSphere CPI** chart. Fill out the required vCenter details.
|
||||
1. vSphere CPI initializes all nodes with ProviderID which is needed by the vSphere CSI driver. Check if all nodes are initialized with the ProviderID before installing CSI driver with the following command:
|
||||
|
||||
```
|
||||
kubectl describe nodes | grep "ProviderID"
|
||||
```
|
||||
|
||||
### 3. Installing the CSI plugin
|
||||
|
||||
1. From the **Cluster Explorer** view, go to the top left dropdown menu and click **Apps & Marketplace.**
|
||||
1. Select the **vSphere CSI** chart. Fill out the required vCenter details.
|
||||
2. Set **Enable CSI Migration** to **false**.
|
||||
3. This chart creates a StorageClass with the `csi.vsphere.vmware.com` as the provisioner. Fill out the details for the StorageClass and launch the chart.
|
||||
|
||||
|
||||
# Using the CSI driver for provisioning volumes
|
||||
|
||||
The CSI chart by default creates a storageClass.
|
||||
|
||||
If that option was not selected while launching the chart, create a storageClass with the `csi.vsphere.vmware.com` as the provisioner.
|
||||
|
||||
All volumes provisioned using this StorageClass will get provisioned by the CSI driver.
|
||||
+102
@@ -0,0 +1,102 @@
|
||||
---
|
||||
title: Migrating vSphere In-tree Volumes to CSI
|
||||
weight: 5
|
||||
aliases:
|
||||
- /rancher/v2.x/en/cluster-provisioning/rke-clusters/cloud-providers/vsphere/out-of-tree/vsphere-volume-migration/
|
||||
---
|
||||
_Available as of v2.5+_
|
||||
|
||||
Kubernetes is moving away from maintaining cloud providers in-tree. vSphere has an out-of-tree cloud provider that can be used by installing the vSphere cloud provider and cloud storage plugins.
|
||||
|
||||
This page covers how to migrate from the in-tree vSphere cloud provider to out-of-tree, and manage the existing VMs post migration.
|
||||
|
||||
It follows the steps provided in the official [vSphere migration documentation](https://vsphere-csi-driver.sigs.k8s.io/features/vsphere_csi_migration.html) and provides the steps to be performed in Rancher.
|
||||
|
||||
### Cloud-config Format Limitation
|
||||
|
||||
Existing volumes that were provisioned using the following cloud-config format will NOT get migrated due to an existing bug in vsphere CSI.
|
||||
|
||||
If the cloud-config has this format for datastore and resource pool path, vsphere CSI driver cannot recognize it:
|
||||
|
||||
```yaml
|
||||
default-datastore: </datacenter>/datastore/<default-datastore-name>
|
||||
resourcepool-path: "</datacenter>/host/<cluster-name>/Resources/<resource-pool-name>"
|
||||
```
|
||||
|
||||
Volumes provisioned with the in-tree provider using the following format will get migrated correctly:
|
||||
|
||||
```yaml
|
||||
default-datastore: <default-datastore-name>
|
||||
resourcepool-path: "<cluster-name>/Resources/<resource-pool-name>"
|
||||
```
|
||||
|
||||
Upstream bug: https://github.com/kubernetes-sigs/vsphere-csi-driver/issues/628
|
||||
|
||||
Rancher issue tracking this bug: https://github.com/rancher/rancher/issues/31105
|
||||
|
||||
# Prerequisites
|
||||
|
||||
- vSphere CSI Migration requires vSphere 7.0u1. In order to be able to manage existing in-tree vSphere volumes, upgrade vSphere to 7.0u1.
|
||||
- The Kubernetes version must be 1.19 or higher.
|
||||
|
||||
# Migration
|
||||
|
||||
### 1. Install the CPI plugin
|
||||
|
||||
Before installing CPI, we need to taint all nodes with `node.cloudprovider.kubernetes.io/uninitialized=true:NoSchedule`.
|
||||
|
||||
This can be done by running the following commands:
|
||||
|
||||
```
|
||||
curl -O https://raw.githubusercontent.com/rancher/helm3-charts/56b622f519728378abeddfe95074f1b87ab73b1e/charts/vsphere-cpi/taints.sh
|
||||
```
|
||||
|
||||
Or:
|
||||
|
||||
```
|
||||
wget https://raw.githubusercontent.com/rancher/helm3-charts/56b622f519728378abeddfe95074f1b87ab73b1e/charts/vsphere-cpi/taints.sh
|
||||
chmod +x taints.sh
|
||||
./taints.sh <path to kubeconfig if running the command outside the cluster>
|
||||
```
|
||||
|
||||
Once all nodes are tainted by the running the script, launch the Helm vSphere CPI chart.
|
||||
|
||||
1. From the **Cluster Explorer** view, go to the top left dropdown menu and click **Apps & Marketplace.**
|
||||
2. Select the **vSphere CPI** chart.
|
||||
3. Fill out the required vCenter details and click **Launch**.
|
||||
|
||||
vSphere CPI initializes all nodes with ProviderID, which is needed by the vSphere CSI driver.
|
||||
|
||||
Check if all nodes are initialized with the ProviderID with the following command:
|
||||
|
||||
```
|
||||
kubectl describe nodes | grep "ProviderID"
|
||||
```
|
||||
|
||||
### 2. Install the CSI driver
|
||||
|
||||
1. From the **Cluster Explorer** view, go to the top left dropdown menu and click **Apps & Marketplace.**
|
||||
1. Select the **vSphere CSI** chart.
|
||||
1. Fill out the required vCenter details and click **Launch**.
|
||||
1. Set **Enable CSI Migration** to **true**.
|
||||
1. This chart creates a StorageClass with the `csi.vsphere.vmware.com` as the provisioner. You can provide the URL of the datastore to be used for CSI volume provisioning while creating this StorageClass. The datastore URL can be found in the vSphere client by selecting the datastore and going to the Summary tab. Fill out the details for the StorageClass and click **Launch**.
|
||||
|
||||
### 3. Edit the cluster to enable CSI migration feature flags
|
||||
|
||||
1. While editing the cluster, if the Kubernetes version is less than 1.19, select Kubernetes version 1.19 or higher from the **Kubernetes Version** dropdown.
|
||||
2. For enabling feature flags, click on "Edit as YAML", and add the following under kube-controller and kubelet:
|
||||
|
||||
```yaml
|
||||
extra_args:
|
||||
feature-gates: "CSIMigration=true,CSIMigrationvSphere=true"
|
||||
```
|
||||
|
||||
### 4. Drain worker nodes
|
||||
|
||||
Worker nodes must be drained during the upgrade before changing the kubelet and kube-controller-manager args.
|
||||
|
||||
1. Click **Edit as Form** and then click on "Advanced Options."
|
||||
1. Set the field **Maximum Worker Nodes Unavailable** to count of 1.
|
||||
1. To drain the nodes during upgrade, select **Drain Nodes > Yes**.
|
||||
1. Set **Force** and **Delete Local Data** to **true**.
|
||||
1. Click **Save** to upgrade the cluster.
|
||||
+18
@@ -0,0 +1,18 @@
|
||||
---
|
||||
title: Setting up the vSphere Cloud Provider
|
||||
weight: 4
|
||||
aliases:
|
||||
- /rancher/v2.x/en/cluster-provisioning/rke-clusters/cloud-providers/vsphere/
|
||||
---
|
||||
|
||||
In this section, you'll learn how to set up a vSphere cloud provider for a Rancher managed RKE Kubernetes cluster in vSphere.
|
||||
|
||||
# In-tree Cloud Provider
|
||||
|
||||
To use the in-tree vSphere cloud provider, you will need to use an RKE configuration option. For details, refer to [this page.](./in-tree)
|
||||
|
||||
# Out-of-tree Cloud Provider
|
||||
|
||||
_Available as of v2.5+_
|
||||
|
||||
To set up the out-of-tree vSphere cloud provider, you will need to install Helm charts from the Rancher marketplace. For details, refer to [this page.](./out-of-tree)
|
||||
Reference in New Issue
Block a user