mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-09-26 21:18:04 +00:00
Last fixes for HA and airgap (#96)
This commit is contained in:
committed by
Mark Bishop
parent
dc4ac5f2fc
commit
4e902c8819
@@ -8,15 +8,17 @@ This section contains instructions for installing Rancher in development and pro
|
|||||||
|
|
||||||
## Objectives
|
## Objectives
|
||||||
|
|
||||||
1. Install Rancher Server. We have instructions for three use cases. Pick the right one for you:
|
1. Install Rancher Server. We have instructions for these use cases. Pick the right one for you:
|
||||||
|
|
||||||
a. [Single-Node Rancher Server Installation]({{< baseurl >}}/rancher/v2.x/en/installation/server-installation/single-node-install): In this simple install scenario, you install Rancher on a single Linux host.
|
- [Single Node Installation]({{< baseurl >}}/rancher/v2.x/en/installation/server-installation/single-node-install): In this simple install scenario, you install Rancher on a single Linux host.
|
||||||
|
|
||||||
b. [High-Availablity Rancher Server Installation]({{< baseurl >}}/rancher/v2.x/en/installation/server-installation/ha-server-install/): This install scenario creates a new Kubernetes cluster dedicated to running Rancher Server in a high-availabilty (HA) configuration.
|
- [Single Node Install With External Loadbalancer]({{< baseurl >}}/rancher/v2.x/en/installation/server-installation/single-node-install-external-lb): In this scenario, you install Rancher on a single Linux host and access it using an external loadbalancer/proxy.
|
||||||
|
|
||||||
c. [Air Gap Installation]({{< baseurl >}}/rancher/v2.x/en/installation/air-gap-installation/): We also have instructions for a more specialized use case where you install Rancher Server in an environment without an Internet connection.
|
- [High Availablity Installation]({{< baseurl >}}/rancher/v2.x/en/installation/server-installation/ha-server-install/): This install scenario creates a new Kubernetes cluster dedicated to running Rancher Server in a high-availabilty (HA) configuration.
|
||||||
|
|
||||||
2. **Optional:** Configure an external Load Balancer. A load balancer acts like a traffic cop for connections incoming to your Kubernetes cluster. You options are:
|
- [Air Gap Installation]({{< baseurl >}}/rancher/v2.x/en/installation/air-gap-installation/): We also have instructions for a more specialized use case where you install Rancher Server in an environment without an Internet connection.
|
||||||
|
|
||||||
|
<!-- 2. **Optional:** Configure an external Load Balancer. A load balancer acts like a traffic cop for connections incoming to your Kubernetes cluster. You options are:
|
||||||
|
|
||||||
a. [Amazon Application Load Balancer]({{< baseurl >}}/rancher/v2.x/en/installation/load-balancing-config/config-amazon-alb/)
|
a. [Amazon Application Load Balancer]({{< baseurl >}}/rancher/v2.x/en/installation/load-balancing-config/config-amazon-alb/)
|
||||||
|
|
||||||
@@ -24,4 +26,4 @@ This section contains instructions for installing Rancher in development and pro
|
|||||||
|
|
||||||
c. [Nginx]({{< baseurl >}}/rancher/v2.x/en/installation/load-balancing-config/config-Nginx/)
|
c. [Nginx]({{< baseurl >}}/rancher/v2.x/en/installation/load-balancing-config/config-Nginx/)
|
||||||
|
|
||||||
3. Configure SSL communication. Set up SSL by installing certificates on your Kubernetes nodes. You have a variety of options for [SSL Configuration]({{< baseurl >}}/rancher/v2.x/en/installation/ssl-config/).
|
3. Configure SSL communication. Set up SSL by installing certificates on your Kubernetes nodes. You have a variety of options for [SSL Configuration]({{< baseurl >}}/rancher/v2.x/en/installation/ssl-config/). -->
|
||||||
|
|||||||
@@ -5,4 +5,72 @@ weight: 345
|
|||||||
|
|
||||||
# Air Gap Installation
|
# Air Gap Installation
|
||||||
|
|
||||||
If you want to set up Rancher in a network that's disconnected from the Internet (i.e. an air gap installation), you can do so using a private registry.
|
Rancher supports installing from a private registry. In every [release](https://github.com/rancher/rancher/releases), we provide you with the needed system-images and scripts to mirror those images to your own registry. The system-images are used when nodes are added to a cluster, or when you enable features like pipelines or logging.
|
||||||
|
|
||||||
|
>**Prerequisite:** It is assumed you either have your own private registry or other means of distributing docker images to your machine. If you need help with creating a private registry, please refer to the [Docker documentation for private registries](https://docs.docker.com/registry/).
|
||||||
|
|
||||||
|
|
||||||
|
>**Note:** In Rancher v2.0.0, registries with authentication are not supported for installing from a private registry. The system-images can only be pulled from a registry without authentication enabled. This limitation only applies to system-images.
|
||||||
|
|
||||||
|
## Release files
|
||||||
|
|
||||||
|
* **rancher-images.txt**: Contains all images needed for that release.
|
||||||
|
* **rancher-save-images.sh**: This script will pull all needed images from DockerHub, and save all of the images as a compressed file called `rancher-images.tar.gz`. This file can be transferred to your on-premise host that can access your private registry.
|
||||||
|
* **rancher-load-images.sh**: This script will load images from rancher-images.tar.gz and push them to your private registry. You have to supply the hostname of your private registry as first argument to the script.<br/>`rancher-load-images.sh registry.yourdomain.com:5000`
|
||||||
|
|
||||||
|
### Making the Rancher images available
|
||||||
|
|
||||||
|
We will cover two scenarios:
|
||||||
|
|
||||||
|
* **Scenario 1**: You have one host that can access DockerHub to pull and save the images, and a separate host that access your private registry to push the images.
|
||||||
|
* **Scenario 2**: You have one host that can access both DockerHub and your private registry.
|
||||||
|
|
||||||
|
#### Scenario 1: One host that can access DockerHub, separate host that can access private registry
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
1. Browse to the release page of your version (i.e. `https://github.com/rancher/rancher/releases/tag/v2.0.0`) and download `rancher-save-images.sh` and `rancher-load-images.sh`
|
||||||
|
|
||||||
|
2. Transfer and run `rancher-save-images.sh` on the host the can access DockerHub. This will require at least 20GB of disk space.
|
||||||
|
|
||||||
|
3. Transfer the output file from step 2 (`rancher-images.tar.gz`) to the host that can access the private registry.
|
||||||
|
|
||||||
|
4. Transfer and run `rancher-load-images.sh` on the host that can access the private registry. It should be run in the same directory as `rancher-images.tar.gz`.
|
||||||
|
|
||||||
|
#### Scenario 2: You have one host that can access both DockerHub and your private registry.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
1. Browse to the release page of your version (i.e. `https://github.com/rancher/rancher/releases/tag/v2.0.0`) and download `rancher-images.txt`
|
||||||
|
|
||||||
|
2. Pull all the images present in `rancher-images.txt`, re-tag each image with the location of your registry, and push the image to the registry. This will require at least 20GB of disk space. See an example script below:
|
||||||
|
|
||||||
|
```
|
||||||
|
#!/bin/sh
|
||||||
|
IMAGES=`curl -s -L https://github.com/rancher/rancher/releases/download/v2.0.0/rancher-images.txt`
|
||||||
|
for IMAGE in $IMAGES; do
|
||||||
|
until docker inspect $IMAGE > /dev/null 2>&1; do
|
||||||
|
docker pull $IMAGE
|
||||||
|
done
|
||||||
|
docker tag $IMAGE registry.yourdomain.com:5000/$IMAGE
|
||||||
|
docker push registry.yourdomain.com:5000/$IMAGE
|
||||||
|
done
|
||||||
|
```
|
||||||
|
|
||||||
|
### Configuring Rancher to use the private registry
|
||||||
|
|
||||||
|
Rancher needs to be configured to use the private registry as source for the needed images.
|
||||||
|
|
||||||
|
1. Go into the Settings view.
|
||||||
|

|
||||||
|
2. Look for the setting called `system-default-registry` and choose **Edit**.
|
||||||
|

|
||||||
|
3. Change the value to your registry, i.e. `registry.yourdomain.com:5000`. Do not prefix the registry with `http://` or `https://`
|
||||||
|

|
||||||
|
|
||||||
|
|
||||||
|
>**Note:** If you want to configure the setting when starting the rancher/rancher container, you can use the environment variable `CATTLE_SYSTEM_DEFAULT_REGISTRY`. Example:
|
||||||
|
```
|
||||||
|
#!/bin/sh
|
||||||
|
docker run -d -p 80:80 -p 443:443 -e CATTLE_SYSTEM_DEFAULT_REGISTRY=registry.yourdomain.com:5000 registry.yourdomain.com:5000/rancher/rancher:v2.0.0
|
||||||
|
```
|
||||||
|
|||||||
-68
@@ -1,68 +0,0 @@
|
|||||||
---
|
|
||||||
title: Installing From a Private Registry
|
|
||||||
weight: 350
|
|
||||||
---
|
|
||||||
# Installing From a Private Registry
|
|
||||||
|
|
||||||
Rancher supports installing from a private registry. In every [release](https://github.com/rancher/rancher/releases), we provide you with the needed system-images and scripts to mirror those images to your own registry. The system-images are used when nodes are added to a cluster, or when you enable features like pipelines or logging.
|
|
||||||
|
|
||||||
>**Prerequisite:** It is assumed you either have your own private registry or other means of distributing docker images to your machine. If you need help with creating a private registry, please refer to the [Docker documentation for private registries](https://docs.docker.com/registry/).
|
|
||||||
|
|
||||||
|
|
||||||
>**Note:** In Rancher v2.0.0, registries with authentication are not supported for installing from a private registry. The system-images can only be pulled from a registry without authentication enabled. This limitation only applies to system-images. See [Configure Registry for Workloads](#dummy) how to configure private registries for your workloads.
|
|
||||||
|
|
||||||
## Release files
|
|
||||||
|
|
||||||
* **rancher-images.txt**: Contains all images needed for that release.
|
|
||||||
* **rancher-save-images.sh**: This script will pull all needed images from DockerHub, and save all of the images as a compressed file called `rancher-images.tar.gz`. This file can be transferred to your on-premise host that can access your private registry.
|
|
||||||
* **rancher-load-images.sh**: This script will load images from rancher-images.tar.gz and push them to your private registry. You have to supply the hostname of your private registry as first argument to the script.<br/>`rancher-load-images.sh registry.yourdomain.com:5000`
|
|
||||||
|
|
||||||
### Making the Rancher images available
|
|
||||||
|
|
||||||
We will cover two scenarios:
|
|
||||||
|
|
||||||
* **Scenario 1**: You have one host that can access DockerHub to pull and save the images, and a separate host that access your private registry to push the images.
|
|
||||||
* **Scenario 2**: You have one host that can access both DockerHub and your private registry.
|
|
||||||
|
|
||||||
#### Scenario 1: One host that can access DockerHub, separate host that can access private registry
|
|
||||||
|
|
||||||
1. Browse to the release page of your version (i.e. `https://github.com/rancher/rancher/releases/tag/v2.0.0`) and download `rancher-save-images.sh` and `rancher-load-images.sh`
|
|
||||||
|
|
||||||
2. Transfer and run `rancher-save-images.sh` on the host the can access DockerHub. This will require at least 20GB of disk space.
|
|
||||||
|
|
||||||
3. Transfer the output file from step 2 (`rancher-images.tar.gz`) to the host that can access the private registry.
|
|
||||||
|
|
||||||
4. Transfer and run `rancher-load-images.sh` on the host that can access the private registry. It should be run in the same directory as `rancher-images.tar.gz`.
|
|
||||||
|
|
||||||
#### Scenario 2: You have one host that can access both DockerHub and your private registry.
|
|
||||||
|
|
||||||
1. Browse to the release page of your version (i.e. `https://github.com/rancher/rancher/releases/tag/v2.0.0`) and download `rancher-images.txt`
|
|
||||||
|
|
||||||
2. Pull all the images present in `rancher-images.txt`, re-tag each image with the location of your registry, and push the image to the registry. This will require at least 20GB of disk space. See an example script below:
|
|
||||||
|
|
||||||
```
|
|
||||||
#!/bin/sh
|
|
||||||
IMAGES=`curl -s -L https://github.com/rancher/rancher/releases/download/v2.0.0/rancher-images.txt`
|
|
||||||
for IMAGE in $IMAGES; do
|
|
||||||
until docker inspect $IMAGE > /dev/null 2>&1; do
|
|
||||||
docker pull $IMAGE
|
|
||||||
done
|
|
||||||
docker tag $IMAGE registry.yourdomain.com:5000/$IMAGE
|
|
||||||
docker push registry.yourdomain.com:5000/$IMAGE
|
|
||||||
done
|
|
||||||
```
|
|
||||||
|
|
||||||
### Configuring Rancher to use the private registry
|
|
||||||
|
|
||||||
Rancher needs to be configured to use the private registry as source for the needed images.
|
|
||||||
|
|
||||||
1. Go into the Settings view.
|
|
||||||
2. Look for the setting called `system-default-registry` and choose **Edit**.
|
|
||||||
3. Change the value to your registry, i.e. `registry.yourdomain.com:5000`. Do not prefix the registry with `http://` or `https://`
|
|
||||||
|
|
||||||
If you want to configure the setting when starting the rancher/rancher container, you can use the environment variable `CATTLE_SYSTEM_DEFAULT_REGISTRY`. Example:
|
|
||||||
|
|
||||||
```
|
|
||||||
#!/bin/sh
|
|
||||||
docker run -d -p 80:80 -p 443:443 -e CATTLE_SYSTEM_DEFAULT_REGISTRY=registry.yourdomain.com:5000 registry.yourdomain.com:5000/rancher/rancher:v2.0.0
|
|
||||||
```
|
|
||||||
@@ -1,6 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: Load Balancing
|
title: Load Balancing
|
||||||
weight: 300
|
weight: 300
|
||||||
|
draft: true
|
||||||
---
|
---
|
||||||
|
|
||||||
# Load Balancer Configuration
|
# Load Balancer Configuration
|
||||||
|
|||||||
+7
-6
@@ -83,7 +83,7 @@ rke version v<N.N.N>
|
|||||||
RKE uses a `.yml` config file to install and configure your Kubernetes cluster. There are 2 templates to choose from, depending on the SSL certificate you want to use.
|
RKE uses a `.yml` config file to install and configure your Kubernetes cluster. There are 2 templates to choose from, depending on the SSL certificate you want to use.
|
||||||
|
|
||||||
- [Template for using Self Signed Certificate (3-node-certificate.yml)](https://raw.githubusercontent.com/rancher/rancher/master/rke-templates/3-node-certificate.yml)
|
- [Template for using Self Signed Certificate (3-node-certificate.yml)](https://raw.githubusercontent.com/rancher/rancher/master/rke-templates/3-node-certificate.yml)
|
||||||
- [Template for using Certificate Signed By A Recognized Certificate Authority (3-node-certificate-recognizedca.yml)](https://raw.githubusercontent.com/rancher/rancher/master/rke-templates/3-node-certificate.yml)
|
- [Template for using Certificate Signed By A Recognized Certificate Authority (3-node-certificate-recognizedca.yml)](https://raw.githubusercontent.com/rancher/rancher/master/rke-templates/3-node-certificate-recognizedca.yml)
|
||||||
|
|
||||||
## Configure nodes section
|
## Configure nodes section
|
||||||
|
|
||||||
@@ -137,7 +137,7 @@ In the `kind: Secret` with `name: cattle-keys-ingress`:
|
|||||||
* Replace `<BASE64_CRT>` with the base64 encoded string of the Certificate file (usually called `cert.pem` or `domain.crt`)
|
* Replace `<BASE64_CRT>` with the base64 encoded string of the Certificate file (usually called `cert.pem` or `domain.crt`)
|
||||||
* Replace `<BASE64_KEY>` with the base64 encoded string of the Certificate Key file (usually called `key.pem` or `domain.key`)
|
* Replace `<BASE64_KEY>` with the base64 encoded string of the Certificate Key file (usually called `key.pem` or `domain.key`)
|
||||||
|
|
||||||
See the example below:
|
After replacing the values, the file should look like the example below (the base64 encoded strings should be different):
|
||||||
|
|
||||||
```
|
```
|
||||||
---
|
---
|
||||||
@@ -156,7 +156,7 @@ In the `kind: Secret` with `name: cattle-keys-server`:
|
|||||||
|
|
||||||
* Replace `<BASE64_CA>` with the base64 encoded string of the CA Certificate file (usually called `ca.pem` or `ca.crt`)
|
* Replace `<BASE64_CA>` with the base64 encoded string of the CA Certificate file (usually called `ca.pem` or `ca.crt`)
|
||||||
|
|
||||||
See the example below:
|
After replacing the value, the file should look like the example below (the base64 encoded string should be different):
|
||||||
|
|
||||||
```
|
```
|
||||||
---
|
---
|
||||||
@@ -179,7 +179,7 @@ In the `kind: Secret` with `name: cattle-keys-ingress`:
|
|||||||
* Replace `<BASE64_CRT>` with the base64 encoded string of the Certificate file (usually called `cert.pem` or `domain.crt`)
|
* Replace `<BASE64_CRT>` with the base64 encoded string of the Certificate file (usually called `cert.pem` or `domain.crt`)
|
||||||
* Replace `<BASE64_KEY>` with the base64 encoded string of the Certificate Key file (usually called `key.pem` or `domain.key`)
|
* Replace `<BASE64_KEY>` with the base64 encoded string of the Certificate Key file (usually called `key.pem` or `domain.key`)
|
||||||
|
|
||||||
See the example below:
|
After replacing the values, the file should look like the example below (the base64 encoded strings should be different):
|
||||||
|
|
||||||
```
|
```
|
||||||
---
|
---
|
||||||
@@ -203,7 +203,7 @@ In the `kind: Ingress` with `name: cattle-ingress-http`:
|
|||||||
|
|
||||||
* Replace `<FQDN>` with the FQDN chosen in [Configure DNS](#configure-dns).
|
* Replace `<FQDN>` with the FQDN chosen in [Configure DNS](#configure-dns).
|
||||||
|
|
||||||
See the example below:
|
After replacing `<FQDN>` wit the FQDN chosen in [Configure DNS](#configure-dns), the file should look like the example below (`rancher.yourdomain.com` is the FQDN used in this example):
|
||||||
|
|
||||||
```
|
```
|
||||||
---
|
---
|
||||||
@@ -273,4 +273,5 @@ INFO[0101] Finished building Kubernetes cluster successfully
|
|||||||
|
|
||||||
Log in to Rancher to make sure it deployed successfully. Open a web browser and navigate to the FQDN chosen in [Configure DNS](#configure-dns).
|
Log in to Rancher to make sure it deployed successfully. Open a web browser and navigate to the FQDN chosen in [Configure DNS](#configure-dns).
|
||||||
|
|
||||||
If you are using a [Certificate Signed By A Recognized Certificate Authority](#certificate-signed-by-a-recognized-certificate-authority), you will need to clear the `cacerts` value from the CA (until [GitHub #11388](https://github.com/rancher/rancher/issues/11388) is resolved). This can be done under `Settings` -> `cacerts`, choose `Edit` and remove the contents and click `Save`.
|
>**Note:**
|
||||||
|
> If you are using a [Certificate Signed By A Recognized Certificate Authority](#certificate-signed-by-a-recognized-certificate-authority), you will need to clear the `cacerts` value from the CA (until [GitHub #11388](https://github.com/rancher/rancher/issues/11388) is resolved). This can be done under `Settings` -> `cacerts`, choose `Edit` and remove the contents and click `Save`.
|
||||||
|
|||||||
Binary file not shown.
|
After Width: | Height: | Size: 20 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 80 KiB |
File diff suppressed because one or more lines are too long
|
After Width: | Height: | Size: 12 KiB |
File diff suppressed because one or more lines are too long
|
After Width: | Height: | Size: 6.1 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 20 KiB |
Reference in New Issue
Block a user