+ Create OCNE Clusters Running on Microsoft Azure +
+Configure Oracle Cloud Native Environment self-managed clusters to run on Microsoft Azure
+From 7a6d154a2125f5955adf2b622e1b5d649b13d0e2 Mon Sep 17 00:00:00 2001 From: verrazzanobot <70212020+verrazzanobot@users.noreply.github.com> Date: Mon, 20 Nov 2023 20:00:58 +0000 Subject: [PATCH] Updates --- v1.7/404.html | 2 +- v1.7/docs/advanced/index.html | 1288 +++++ v1.7/docs/advanced/index.xml | 5030 +++++++++++++++++ v1.7/docs/advanced/ocne-azure/index.html | 3114 ++++++++++ v1.7/docs/advanced/ocne-vsphere/index.html | 4443 +++++++++++++++ .../about-applications/index.html | 21 +- .../applications/delivery/deploy/index.html | 21 +- .../applications/delivery/enable/index.html | 21 +- v1.7/docs/applications/delivery/index.html | 21 +- v1.7/docs/applications/index.html | 21 +- .../kubernetes/auth_policy/index.html | 21 +- .../kubernetes/certificate/index.html | 21 +- .../kubernetes/create_kubernetes/index.html | 21 +- .../gateway_virtual_service/index.html | 21 +- v1.7/docs/applications/kubernetes/index.html | 21 +- .../kubernetes/wiring-metrics/index.html | 21 +- .../docs/applications/multicluster/index.html | 21 +- .../multicluster/intro/index.html | 21 +- .../multicluster/mcresources/index.html | 21 +- .../verrazzanomanagedcluster/index.html | 21 +- .../index.html | 21 +- .../multiclusterresourcestatus/index.html | 21 +- .../placement/placement/index.html | 21 +- .../project/verrazzanoproject/index.html | 21 +- .../applications/oam/deploy-app/index.html | 21 +- v1.7/docs/applications/oam/index.html | 21 +- .../oam/traits/about-traits/index.html | 21 +- v1.7/docs/applications/oam/traits/index.html | 21 +- .../oam/traits/ingress/ingress/index.html | 21 +- .../oam/traits/logging/logging/index.html | 21 +- .../oam/traits/metrics/metrics/index.html | 21 +- .../oam/verrazzanoproject/index.html | 21 +- .../oam/workloads/about-workloads/index.html | 21 +- .../workloads/coherence/coherence/index.html | 21 +- .../oam/workloads/helidon/helidon/index.html | 21 +- .../applications/oam/workloads/index.html | 21 +- .../oam/workloads/weblogic/index.html | 21 +- .../index.html | 21 +- v1.7/docs/backup/argocd/index.html | 21 +- v1.7/docs/backup/index.html | 21 +- v1.7/docs/backup/keycloak/index.html | 21 +- v1.7/docs/backup/opensearch/index.html | 21 +- v1.7/docs/backup/rancher/index.html | 21 +- v1.7/docs/examples/argo-cd/index.html | 21 +- v1.7/docs/examples/helidon-config/index.html | 21 +- v1.7/docs/examples/hello-helidon/index.html | 21 +- v1.7/docs/examples/index.html | 21 +- .../microservices/hello-world/index.html | 21 +- v1.7/docs/examples/microservices/index.html | 21 +- .../microservices/sock-shop/index.html | 21 +- .../microservices/spring-boot/index.html | 21 +- .../multicluster/hello-helidon/index.html | 21 +- v1.7/docs/examples/multicluster/index.html | 21 +- .../multicluster/sock-shop/index.html | 21 +- .../multicluster/todo-list/index.html | 21 +- .../examples/wls-coh/bobs-books/index.html | 21 +- v1.7/docs/examples/wls-coh/index.html | 21 +- .../examples/wls-coh/todo-list/index.html | 21 +- v1.7/docs/guides/ha/ha/index.html | 21 +- v1.7/docs/guides/ha/index.html | 21 +- v1.7/docs/guides/ha/node-failure/index.html | 21 +- v1.7/docs/guides/ha/prod-upgrade/index.html | 21 +- v1.7/docs/guides/index.html | 21 +- .../lift-and-shift/lift-and-shift/index.html | 21 +- v1.7/docs/guides/sidecar/index.html | 21 +- v1.7/docs/index.html | 21 +- v1.7/docs/index.xml | 2293 +++++++- .../docs/introduction/architecture/index.html | 21 +- v1.7/docs/introduction/features/index.html | 21 +- v1.7/docs/introduction/index.html | 21 +- .../verrazzanomulticluster/index.html | 21 +- .../introduction/verrazzanooam/index.html | 21 +- v1.7/docs/networking/index.html | 21 +- v1.7/docs/networking/istio/index.html | 21 +- .../security/certificates/index.html | 21 +- v1.7/docs/networking/security/index.html | 21 +- v1.7/docs/networking/traffic/dns/index.html | 21 +- .../networking/traffic/externallbs/index.html | 21 +- v1.7/docs/networking/traffic/index.html | 21 +- .../networking/traffic/ingress/index.html | 21 +- .../traffic/ociloadbalancerips/index.html | 21 +- v1.7/docs/observability/index.html | 21 +- .../logging/configure-opensearch/index.html | 21 +- .../opensearch/index.html | 21 +- .../logging/fluent-operator/index.html | 21 +- .../logging/fluentd/fluentd/index.html | 21 +- .../observability/logging/fluentd/index.html | 21 +- v1.7/docs/observability/logging/index.html | 21 +- .../observability/logging/logs/index.html | 21 +- .../logging/oci-logging/index.html | 21 +- .../observability/logging/search/index.html | 21 +- .../logging/troubleshoot/index.html | 21 +- .../monitoring/configure-metrics/index.html | 21 +- .../configure/alertmanager/index.html | 21 +- .../configure/grafana/grafana/index.html | 21 +- .../monitoring/configure/grafana/index.html | 21 +- .../monitoring/configure/index.html | 21 +- .../configure/prometheus/index.html | 21 +- .../monitoring/configure/thanos/index.html | 21 +- v1.7/docs/observability/monitoring/index.html | 21 +- .../multicluster-metrics/index.html | 21 +- .../troubleshooting-prometheus/index.html | 21 +- v1.7/docs/observability/storage/index.html | 21 +- .../tracing/application-tracing/index.html | 21 +- .../tracing/capture-traces/index.html | 21 +- .../tracing/configure-tracing/index.html | 21 +- v1.7/docs/observability/tracing/index.html | 21 +- .../tracing/view-traces/index.html | 21 +- v1.7/docs/reference/index.html | 21 +- v1.7/docs/reference/migration/index.html | 21 +- .../vao-clusters-v1alpha1/index.html | 21 +- .../reference/vao-oam-v1alpha1/index.html | 21 +- .../vco-clusters-v1alpha1/index.html | 21 +- .../vpo-verrazzano-v1alpha1/index.html | 21 +- .../vpo-verrazzano-v1beta1/index.html | 21 +- v1.7/docs/releasenotes/index.html | 23 +- .../security/accounts/accounts/index.html | 21 +- v1.7/docs/security/appsec/appsec/index.html | 21 +- v1.7/docs/security/index.html | 21 +- v1.7/docs/security/keycloak/index.html | 21 +- .../security/keycloak/keycloak/index.html | 21 +- .../security/proxies/authproxy/index.html | 21 +- v1.7/docs/security/proxies/index.html | 21 +- v1.7/docs/security/rbac/rbac/index.html | 21 +- .../access/console-credentials/index.html | 21 +- .../docs/setup/access/console-urls/index.html | 21 +- v1.7/docs/setup/access/index.html | 21 +- v1.7/docs/setup/access/password/index.html | 21 +- v1.7/docs/setup/index.html | 21 +- v1.7/docs/setup/install/index.html | 21 +- .../perform/cli-installation/index.html | 21 +- .../perform/helm-installation/index.html | 21 +- v1.7/docs/setup/install/perform/index.html | 21 +- .../perform/kubectl-installation/index.html | 21 +- .../setup/install/perform/profiles/index.html | 21 +- .../install/prepare/cli-setup/index.html | 21 +- v1.7/docs/setup/install/prepare/index.html | 21 +- .../platforms/generic/generic/index.html | 21 +- .../install/prepare/platforms/index.html | 21 +- .../prepare/platforms/kind/kind/index.html | 21 +- .../prepare/platforms/oci/oci/index.html | 21 +- .../prepare/platforms/olcne/index.html | 21 +- .../prepare/platforms/olcne/nfs/index.html | 21 +- .../olcne/private-registry/index.html | 21 +- .../prepare/platforms/vcn-oci/index.html | 21 +- .../setup/install/prepare/prereqs/index.html | 21 +- .../install/verify/cli-verify/index.html | 21 +- v1.7/docs/setup/install/verify/index.html | 21 +- .../install/verify/kubectl-verify/index.html | 21 +- .../setup/install/verify/softwares/index.html | 21 +- .../setup/installationoverrides/index.html | 21 +- .../mc-install/advanced-mc-install/index.html | 21 +- .../mc-install/deregister-install/index.html | 21 +- v1.7/docs/setup/mc-install/index.html | 21 +- .../setup/mc-install/multicluster/index.html | 21 +- .../docs/setup/mc-install/register/index.html | 21 +- .../register/register-kubectl/index.html | 21 +- .../register/syncclusters/index.html | 21 +- .../register/ui-register/index.html | 21 +- .../troubleshooting-multicluster/index.html | 21 +- .../mc-install/verify-install/index.html | 21 +- .../docs/setup/modify-installation/index.html | 21 +- .../private-registry/index.html | 21 +- .../setup/provision-cluster/capi/index.html | 43 +- .../provision-cluster/clusterapi/index.html | 21 +- v1.7/docs/setup/provision-cluster/index.html | 21 +- v1.7/docs/setup/provision-cluster/index.xml | 16 +- .../managed-cluster-vz/index.html | 21 +- .../provision-cluster/ocne-oci/index.html | 21 +- .../provision-cluster/oke-oci/index.html | 21 +- v1.7/docs/setup/quickstart/index.html | 21 +- v1.7/docs/setup/uninstall/index.html | 21 +- v1.7/docs/setup/upgrade/index.html | 21 +- .../upgrade/kubernetes-upgrade/index.html | 21 +- v1.7/docs/setup/upgrade/perform/index.html | 21 +- v1.7/docs/setup/upgrade/prepare/index.html | 21 +- v1.7/docs/setup/upgrade/upgrade-mc/index.html | 21 +- v1.7/docs/setup/upgrade/verify/index.html | 21 +- v1.7/docs/support/index.html | 21 +- .../clusterapiclusterissues/index.html | 23 +- .../externaldnsconfiguration/index.html | 23 +- .../imagepullbackoff/index.html | 23 +- .../imagepullnotfound/index.html | 23 +- .../imagepullratelimit/index.html | 23 +- .../imagepullservice/index.html | 23 +- .../diagnostictools/analysisadvice/index.html | 23 +- .../ingressinstallfailure/index.html | 23 +- .../ingressinvalidshape/index.html | 23 +- .../ingresslblimitexceeded/index.html | 23 +- .../ingressnoloadbalancerip/index.html | 23 +- .../ingressociiplimitexceeded/index.html | 23 +- .../analysisadvice/installfailure/index.html | 23 +- .../analysisadvice/insufficientcpu/index.html | 23 +- .../insufficientmemory/index.html | 23 +- .../index.html | 23 +- .../istioloadbalancercreationissue/index.html | 23 +- .../keycloakdatamigrationfailure/index.html | 23 +- .../nginxloadbalancercreationissue/index.html | 23 +- .../analysisadvice/pendingpods/index.html | 23 +- .../podproblemsnotreported/index.html | 23 +- .../analysisadvice/rancherissues/index.html | 23 +- .../diagnostictools/index.html | 23 +- .../verrazzanoanalysistool/index.html | 23 +- .../diagnostictools/vzbugreportcli/index.html | 23 +- v1.7/docs/troubleshooting/faq/index.html | 23 +- v1.7/docs/troubleshooting/index.html | 33 +- v1.7/docs/troubleshooting/index.xml | 4 +- .../troubleshooting-clusterapi/index.html | 23 +- .../troubleshooting-fluentd/index.html | 23 +- .../troubleshooting-mysql/index.html | 23 +- v1.7/index.html | 2 +- ...dex.13ff848cfb3b604d1b98dbe4670a5f81.json} | 2 +- v1.7/search/index.html | 2 +- v1.7/sitemap.xml | 15 +- 214 files changed, 19609 insertions(+), 938 deletions(-) create mode 100644 v1.7/docs/advanced/index.html create mode 100644 v1.7/docs/advanced/index.xml create mode 100644 v1.7/docs/advanced/ocne-azure/index.html create mode 100644 v1.7/docs/advanced/ocne-vsphere/index.html rename v1.7/{offline-search-index.8a7cacfee38b8368de755719837c99b7.json => offline-search-index.13ff848cfb3b604d1b98dbe4670a5f81.json} (53%) diff --git a/v1.7/404.html b/v1.7/404.html index 52de84e847..c05676ae84 100644 --- a/v1.7/404.html +++ b/v1.7/404.html @@ -90,7 +90,7 @@ aria-label="Search this site…" autocomplete="off" - data-offline-search-index-json-src="./offline-search-index.8a7cacfee38b8368de755719837c99b7.json" + data-offline-search-index-json-src="./offline-search-index.13ff848cfb3b604d1b98dbe4670a5f81.json" data-offline-search-base-href="./" data-offline-search-max-results="10" > diff --git a/v1.7/docs/advanced/index.html b/v1.7/docs/advanced/index.html new file mode 100644 index 0000000000..ffb0800d8c --- /dev/null +++ b/v1.7/docs/advanced/index.html @@ -0,0 +1,1288 @@ + + +
+ + + + + + + + + + + + + + + + + + +Configure Oracle Cloud Native Environment self-managed clusters to run on Microsoft Azure
+Configure Oracle Cloud Native Environment self-managed clusters to run on VMware vSphere
+Was this page helpful?
+ + ++ Glad to hear it! Please tell us how we can improve. +
++ Sorry to hear that. Please tell us how we can improve. +
+The Cluster API project provides a standard set of Kubernetes-style APIs for cluster management. Officially, Verrazzano currently only supports using Cluster API to provision OCNE and OKE clusters on OCI.
+However, you can also experiment with using the features of the Cluster API project directly to deploy OCNE clusters on Microsoft Azure.
+For more information on Cluster API or Cluster API with Azure, see:
+ + + +Verrazzano and Cluster API use slightly different terminology for the same concepts:
+Before you can deploy a Cluster API cluster, you need to set up a few resources in Azure.
+$ az group create --name <ResourceGroupName> --location <location>
+
$ az ad sp create-for-rbac --name myServicePrincipalName \
+ --role Contributor \
+ --scopes /subscriptions/mySubscriptionID/resourceGroups/myResourceGroupName
+
The Cluster API requires an initial cluster as a starting point to deploy its resources.
+Install kind. Follow the instructions at Installation in the kind documentation.
+Create a Kubernetes cluster using kind. Follow the instructions at Quick Start: Install and/or configure a Kubernetes cluster in The Cluster API Book.
+Install the clusterctl CLI tool. clusterctl manages the lifecycle operations of a cluster API admin cluster. Follow the instructions at Quick Start: Install clusterctl in the Cluster API Book.
+Install the Verrazzano CLI tool using the instructions at CLI Setup.
+Install Verrazzano on the cluster using either the dev
or prod
installation profile. Follow the instructions at Install with CLI. The certManager
and clusterAPI
components are required and must remain enabled.
On the cluster, set environment variables for the following Azure resource IDs from your Azure account and from the service principal you created:
+For example: + + +
# Azure resource IDs
+$ export AZURE_SUBSCRIPTION_ID="<SubscriptionId>"
+$ export AZURE_TENANT_ID="<Tenant>"
+$ export AZURE_CLIENT_ID="<AppId>"
+$ export AZURE_CLIENT_SECRET="<Password>"
+
+# Base64 encode the Azure Resource IDs
+$ export AZURE_SUBSCRIPTION_ID_B64="$(echo -n "$AZURE_SUBSCRIPTION_ID" | base64 | tr -d '\n')"
+$ export AZURE_TENANT_ID_B64="$(echo -n "$AZURE_TENANT_ID" | base64 | tr -d '\n')"
+$ export AZURE_CLIENT_ID_B64="$(echo -n "$AZURE_CLIENT_ID" | base64 | tr -d '\n')"
+$ export AZURE_CLIENT_SECRET_B64="$(echo -n "$AZURE_CLIENT_SECRET" | base64 | tr -d '\n')"
+
+# Settings needed for AzureClusterIdentity used by the AzureCluster
+$ export AZURE_CLUSTER_IDENTITY_SECRET_NAME="<cluster-identity-secret>"
+$ export CLUSTER_IDENTITY_NAME="<cluster-identity>"
+$ export AZURE_CLUSTER_IDENTITY_SECRET_NAMESPACE="default"
+
Create a secret that includes the password of the service principal identity created in Azure. This secret is referenced by the AzureClusterIdentity used by the AzureCluster. + + +
$ kubectl create secret generic "${AZURE_CLUSTER_IDENTITY_SECRET_NAME}" --from-literal=clientSecret="${AZURE_CLIENT_SECRET}" --namespace "${AZURE_CLUSTER_IDENTITY_SECRET_NAMESPACE}"
+
Install the Cluster API Azure infrastructure provider. + + +
$ clusterctl init -n verrazzano-capi -i azure
+
clusterctl will report when the admin cluster was successfully initialized.
+The Cluster API uses a cluster template to deploy a predefined set of Cluster API objects and create a managed cluster.
+Set the following environment variables so they are available to the cluster template. Update the values to reflect your own environment. + + +
# Base64 encoded SSH key for node access
+$ export AZURE_SSH_PUBLIC_KEY_B64="<sshKey>"
+
+# Select VM types.
+$ export AZURE_CONTROL_PLANE_MACHINE_TYPE="Standard_D2s_v3"
+$ export AZURE_NODE_MACHINE_TYPE="Standard_D2s_v3"
+
+# [Optional] Select resource group. The default value is ${CLUSTER_NAME}.
+$ export AZURE_RESOURCE_GROUP="<resourceGroupName>
+
+# Name of the Azure datacenter location. Change this value to your desired location.
+$ export AZURE_LOCATION="<location>"
+
+# Cluster name info
+$ export CLUSTER_NAME="capi-quickstart"
+$ export KUBERNETES_VERSION="<k8sVersion>"
+$ export NAMESPACE="default"
+$ export CONTROL_PLANE_MACHINE_COUNT="1"
+$ export WORKER_MACHINE_COUNT="1"
+
Copy the cluster template and save it locally as azure-capi.yaml
.
apiVersion: cluster.x-k8s.io/v1beta1
+kind: Cluster
+metadata:
+ name: ${CLUSTER_NAME}
+ namespace: default
+spec:
+ clusterNetwork:
+ pods:
+ cidrBlocks:
+ - 192.168.0.0/16
+ controlPlaneRef:
+ apiVersion: controlplane.cluster.x-k8s.io/v1beta1
+ kind: OCNEControlPlane
+ name: ${CLUSTER_NAME}-control-plane
+ infrastructureRef:
+ apiVersion: infrastructure.cluster.x-k8s.io/v1beta1
+ kind: AzureCluster
+ name: ${CLUSTER_NAME}
+---
+apiVersion: infrastructure.cluster.x-k8s.io/v1beta1
+kind: AzureCluster
+metadata:
+ name: ${CLUSTER_NAME}
+ namespace: default
+spec:
+ identityRef:
+ apiVersion: infrastructure.cluster.x-k8s.io/v1beta1
+ kind: AzureClusterIdentity
+ name: ${CLUSTER_IDENTITY_NAME}
+ location: ${AZURE_LOCATION}
+ networkSpec:
+ subnets:
+ - name: control-plane-subnet
+ role: control-plane
+ - name: node-subnet
+ role: node
+ vnet:
+ name: ${AZURE_VNET_NAME:=${CLUSTER_NAME}-vnet}
+ resourceGroup: ${AZURE_RESOURCE_GROUP:=${CLUSTER_NAME}}
+ subscriptionID: ${AZURE_SUBSCRIPTION_ID}
+---
+apiVersion: infrastructure.cluster.x-k8s.io/v1beta1
+kind: AzureMachineTemplate
+metadata:
+ name: ${CLUSTER_NAME}-control-plane
+ namespace: default
+spec:
+ template:
+ spec:
+ image:
+ marketplace:
+ publisher: "Oracle"
+ offer: "Oracle-Linux"
+ sku: "ol88-lvm-gen2"
+ version: "8.8.3"
+ dataDisks:
+ - diskSizeGB: 256
+ lun: 0
+ nameSuffix: etcddisk
+ osDisk:
+ diskSizeGB: 128
+ osType: Linux
+ sshPublicKey: ${AZURE_SSH_PUBLIC_KEY_B64:=""}
+ vmSize: ${AZURE_CONTROL_PLANE_MACHINE_TYPE}
+---
+apiVersion: cluster.x-k8s.io/v1beta1
+kind: MachineDeployment
+metadata:
+ name: ${CLUSTER_NAME}-md-0
+ namespace: default
+spec:
+ clusterName: ${CLUSTER_NAME}
+ replicas: ${WORKER_MACHINE_COUNT}
+ selector:
+ matchLabels: null
+ template:
+ spec:
+ bootstrap:
+ configRef:
+ apiVersion: bootstrap.cluster.x-k8s.io/v1beta1
+ kind: OCNEConfigTemplate
+ name: ${CLUSTER_NAME}-md-0
+ clusterName: ${CLUSTER_NAME}
+ infrastructureRef:
+ apiVersion: infrastructure.cluster.x-k8s.io/v1beta1
+ kind: AzureMachineTemplate
+ name: ${CLUSTER_NAME}-md-0
+ version: ${KUBERNETES_VERSION}
+---
+apiVersion: infrastructure.cluster.x-k8s.io/v1beta1
+kind: AzureMachineTemplate
+metadata:
+ name: ${CLUSTER_NAME}-md-0
+ namespace: default
+spec:
+ template:
+ spec:
+ image:
+ marketplace:
+ publisher: "Oracle"
+ offer: "Oracle-Linux"
+ sku: "ol88-lvm-gen2"
+ version: "8.8.3"
+ osDisk:
+ diskSizeGB: 128
+ osType: Linux
+ sshPublicKey: ${AZURE_SSH_PUBLIC_KEY_B64:=""}
+ vmSize: ${AZURE_NODE_MACHINE_TYPE}
+---
+apiVersion: infrastructure.cluster.x-k8s.io/v1beta1
+kind: AzureClusterIdentity
+metadata:
+ labels:
+ clusterctl.cluster.x-k8s.io/move-hierarchy: "true"
+ name: ${CLUSTER_IDENTITY_NAME}
+ namespace: default
+spec:
+ allowedNamespaces: {}
+ clientID: ${AZURE_CLIENT_ID}
+ clientSecret:
+ name: ${AZURE_CLUSTER_IDENTITY_SECRET_NAME}
+ namespace: ${AZURE_CLUSTER_IDENTITY_SECRET_NAMESPACE}
+ tenantID: ${AZURE_TENANT_ID}
+ type: ServicePrincipal
+---
+apiVersion: controlplane.cluster.x-k8s.io/v1alpha1
+kind: OCNEControlPlane
+metadata:
+ name: ${CLUSTER_NAME}-control-plane
+ namespace: default
+spec:
+ moduleOperator:
+ enabled: true
+ verrazzanoPlatformOperator:
+ enabled: true
+ controlPlaneConfig:
+ clusterConfiguration:
+ apiServer:
+ extraArgs:
+ cloud-provider: external
+ certSANs:
+ - localhost
+ - 127.0.0.1
+ dns:
+ imageRepository: ${OCNE_IMAGE_REPOSITORY=container-registry.oracle.com}/${OCNE_IMAGE_PATH=olcne}
+ imageTag: ${DNS_TAG=v1.9.3}
+ etcd:
+ local:
+ imageRepository: ${OCNE_IMAGE_REPOSITORY=container-registry.oracle.com}/${OCNE_IMAGE_PATH=olcne}
+ imageTag: ${ETCD_TAG=3.5.6}
+ controllerManager:
+ extraArgs:
+ cloud-provider: external
+ networking: {}
+ scheduler: {}
+ imageRepository: ${OCNE_IMAGE_REPOSITORY=container-registry.oracle.com}/${OCNE_IMAGE_PATH=olcne}
+ files:
+ - contentFrom:
+ secret:
+ key: control-plane-azure.json
+ name: ${CLUSTER_NAME}-control-plane-azure-json
+ owner: root:root
+ path: /etc/kubernetes/azure.json
+ permissions: "0644"
+ initConfiguration:
+ nodeRegistration:
+ criSocket: /var/run/crio/crio.sock
+ kubeletExtraArgs:
+ cloud-provider: external
+ name: '{{ local_hostname }}'
+ joinConfiguration:
+ discovery: {}
+ nodeRegistration:
+ criSocket: /var/run/crio/crio.sock
+ kubeletExtraArgs:
+ cloud-provider: external
+ name: '{{ local_hostname }}'
+ preOCNECommands:
+ - hostnamectl set-hostname "{{ ds.meta_data.hostname }}"
+ - echo "::1 ipv6-localhost ipv6-loopback localhost6 localhost6.localdomain6"
+ >/etc/hosts
+ - echo "127.0.0.1 {{ ds.meta_data.hostname }} {{ local_hostname }} localhost
+ localhost.localdomain localhost4 localhost4.localdomain4" >>/etc/hosts
+ users:
+ - name: opc
+ sudo: ALL=(ALL) NOPASSWD:ALL
+ machineTemplate:
+ infrastructureRef:
+ apiVersion: infrastructure.cluster.x-k8s.io/v1beta1
+ kind: AzureMachineTemplate
+ name: ${CLUSTER_NAME}-control-plane
+ namespace: default
+ replicas: ${CONTROL_PLANE_MACHINE_COUNT}
+ version: ${KUBERNETES_VERSION}
+---
+apiVersion: bootstrap.cluster.x-k8s.io/v1alpha1
+kind: OCNEConfigTemplate
+metadata:
+ name: ${CLUSTER_NAME}-md-0
+ namespace: default
+spec:
+ template:
+ spec:
+ clusterConfiguration:
+ imageRepository: ${OCNE_IMAGE_REPOSITORY=container-registry.oracle.com}/${OCNE_IMAGE_PATH=olcne}
+ joinConfiguration:
+ nodeRegistration:
+ kubeletExtraArgs:
+ cloud-provider: external
+ name: '{{ local_hostname }}'
+ preOCNECommands:
+ - hostnamectl set-hostname "{{ ds.meta_data.hostname }}"
+ - echo "::1 ipv6-localhost ipv6-loopback localhost6 localhost6.localdomain6"
+ >/etc/hosts
+ - echo "127.0.0.1 {{ ds.meta_data.hostname }} {{ local_hostname }} localhost
+ localhost.localdomain localhost4 localhost4.localdomain4" >>/etc/hosts
+ users:
+ - name: opc
+ sudo: ALL=(ALL) NOPASSWD:ALL
+
Generate and apply the template by running the following command: + + +
$ clusterctl generate yaml --from azure-capi.yaml | kubectl apply -f -
+
To view the status of the cluster and its resources, run: + + +
$ clusterctl describe cluster $CLUSTER_NAME
+
To get the kubeconfig
file, run:
+
+
+
$ clusterctl get kubeconfig ${CLUSTER_NAME} > ${CLUSTER_NAME}.kubeconfig
+
After the cluster resources are created, you must perform some additional steps to finish the configuration of the cluster.
+$ helm install --kubeconfig=./${CLUSTER_NAME}.kubeconfig --repo https://raw.githubusercontent.com/kubernetes-sigs/cloud-provider-azure/master/helm/repo cloud-provider-azure --generate-name --set infra.clusterName=clusterName --set cloudControllerManager.clusterCIDR="192.168.0.0/16" --set cloudControllerManager.caCertDir=/etc/pki/ca-trust
+
$ helm repo add projectcalico https://docs.tigera.io/calico/charts --kubeconfig=./${CLUSTER_NAME}.kubeconfig && \
+$ helm install calico projectcalico/tigera-operator --kubeconfig=./${CLUSTER_NAME}.kubeconfig -f https://raw.githubusercontent.com/kubernetes-sigs/cluster-api-provider-azure/main/templates/addons/calico/values.yaml --namespace tigera-operator --create-namespace
+
Your admin cluster and first managed cluster are now up and running and ready to deploy applications. You can add more managed clusters as needed.
+For more information, refer to the documentation for Cluster API and Cluster API Azure:
+ +If the deployment of the Azure resources fails, then you can check the following log files to diagnose the issue:
+The Azure cluster controller provider logs: + + +
$ kubectl logs -n verrazzano-capi -l cluster.x-k8s.io/provider=infrastructure-azure
+
$ kubectl logs -n verrazzano-capi -l cluster.x-k8s.io/provider=control-plane-ocne
+
NOTE: If a pod enters a CrashLoopBackOff
state, then you can either restart the deployment or wait for the state to run its course. This is a known issue that should not affect the deployment of your cluster.
$ kubectl delete cluster $CLUSTER_NAME
+
$ kind delete cluster
+
Do not use kubectl delete -f capi-quickstart.yaml
to delete the entire cluster template at once because it might leave behind pending resources that you need to clean up manually.
Was this page helpful?
+ + ++ Glad to hear it! Please tell us how we can improve. +
++ Sorry to hear that. Please tell us how we can improve. +
+The Cluster API project provides a standard set of Kubernetes-style APIs for cluster management. Officially, Verrazzano currently only supports using Cluster API to provision OCNE and OKE clusters on OCI.
+However, you can also experiment with using the features of the Cluster API project directly to deploy OCNE clusters on VMware vSphere.
+For more information on Cluster API or Cluster API with vSphere, see:
+ + + +Verrazzano and Cluster API use slightly different terminology for the same concepts:
+If you have an existing vSphere environment, you can ignore Set up a VMware Software-Defined Data Center and start from Prepare the VM environment. Confirm that your environment meets the requirements as specified at Cluster API Provider vSphere: Install Requirements.
+Otherwise, create a vSphere environment. We recommend using the Oracle Cloud VMware Solution as described in Set up a VMware Software-Defined Data Center. It deploys a VMware software-defined data center (SDDC) on Oracle Cloud Infrastructure (OCI) and then integrates it with other Oracle services running on Oracle Cloud. This solution was developed in partnership with VMware to provide an environment that adheres to best practices recommended by VMware.
+For more information on the Oracle Cloud VMware Solution, see Deploy a highly available VMware-based SDDC to the cloud in the Oracle Help Architecture Center.
+Use the Oracle Cloud VMware Solution to rapidly create a VMware SDDC.
+Set up a virtual cloud network (VCN). You can choose to use an existing VCN or let the Oracle Cloud VMware Solution create its own VCN as part of the SDDC provisioning process. If you use an existing VCN, then make sure it meets the requirements defined in Prepare Your Deployment in the Oracle Help Architecture Center.
+Deploy the SDDC. To request a new VMware SDDC on OCI, follow the instructions at Deploy the SDDC in the Oracle Help Architecture Center.
+Ensure that the various components were created successfully. Follow the instructions at Monitor the SDDC Creation Process in the Oracle Help Architecture Center.
+Download an Oracle Linux 8 ISO image from Oracle Linux Installation Media.
+Upload the Oracle Linux 8 ISO image to vSphere. Use the steps at Upload ISO Image Installation Media for a Guest Operating System in the vSphere documentation.
+Deploy a VM by following the instructions at Create a Virtual Machine with the New Virtual Machine Wizard in the vSphere documentation.
+Install cloud-init on the VM. + + +
$ sudo yum install -y cloud-init
+
Initialize cloud-init. + + +
$ cloud-init init --local
+
$ cloud-init v. 20.1.0011 running 'init-local' at Fri, 01 Apr 2022 01:26:11 +0000. Up 38.70 seconds.
+
Shut down the VM.
+Convert the VM into a template and name it OL8-Base-Template
. Follow the instructions at Clone a Virtual Machine to a Template in the vSphere documentation.
The Cluster API requires an initial cluster as a starting point to deploy its resources.
+Install kind. Follow the instructions at Installation in the kind documentation.
+Create a Kubernetes cluster using kind. This cluster must be accessible by the VMware SDDC. Follow the instructions at Quick Start: Install and/or configure a Kubernetes cluster in The Cluster API Book.
+Install the clusterctl CLI tool. clusterctl manages the lifecycle operations of a cluster API admin cluster. Follow instructions at Quick Start: Install clusterctl in the Cluster API Book.
+Install the Verrazzano CLI tool using the instructions at CLI Setup.
+Install Verrazzano on the cluster using either the dev
or prod
profile. Follow the instructions at Install with CLI.
On the cluster, set the following vSphere environment variables. Update the values to reflect your own environment. + + +
$ export VSPHERE_PASSWORD="<vmware-password>"
+$ export VSPHERE_USERNAME="administrator@vsphere.local"
+$ export VSPHERE_SERVER="<IP address or FQDN>"
+$ export VSPHERE_DATACENTER="<SDDC-Datacenter>"
+$ export VSPHERE_DATASTORE="<vSAN-Datastore>"
+$ export VSPHERE_NETWORK="workload"
+$ export VSPHERE_RESOURCE_POOL="*/Resources/Workload"
+$ export VSPHERE_FOLDER="<folder-name>"
+$ export VSPHERE_TEMPLATE="OL8-Base-Template"
+$ export VSPHERE_SSH_AUTHORIZED_KEY="<Public-SSH-Authorized-Key>"
+$ export VSPHERE_TLS_THUMBPRINT="<SHA1 thumbprint of vCenter certificate>"
+$ export VSPHERE_STORAGE_POLICY=""
+$ export CONTROL_PLANE_ENDPOINT_IP="<IP address or FQDN>"
+
Install the Cluster API Provider vSphere to initialize the admin cluster. + + +
$ clusterctl init -n verrazzano-capi -i vsphere
+
clusterctl will report when the admin cluster was successfully initialized.
+The Cluster API uses a cluster template to deploy a predefined set of Cluster API objects and create a managed cluster.
+Copy the cluster template and save it locally as vsphere-capi.yaml
.
apiVersion: cluster.x-k8s.io/v1beta1
+kind: Cluster
+metadata:
+ labels:
+ cluster.x-k8s.io/cluster-name: ${CLUSTER_NAME}
+ name: ${CLUSTER_NAME}
+ namespace: ${NAMESPACE}
+spec:
+ clusterNetwork:
+ pods:
+ cidrBlocks:
+ - ${POD_CIDR=192.168.0.0/16}
+ serviceDomain: cluster.local
+ services:
+ cidrBlocks:
+ - ${CLUSTER_CIDR=10.128.0.0/12}
+ controlPlaneRef:
+ apiVersion: controlplane.cluster.x-k8s.io/v1alpha1
+ kind: OCNEControlPlane
+ name: ${CLUSTER_NAME}-control-plane
+ namespace: ${NAMESPACE}
+ infrastructureRef:
+ apiVersion: infrastructure.cluster.x-k8s.io/v1beta1
+ kind: VSphereCluster
+ name: ${CLUSTER_NAME}
+ namespace: ${NAMESPACE}
+---
+apiVersion: infrastructure.cluster.x-k8s.io/v1beta1
+kind: VSphereCluster
+metadata:
+ name: ${CLUSTER_NAME}
+ namespace: ${NAMESPACE}
+spec:
+ controlPlaneEndpoint:
+ host: ${CONTROL_PLANE_ENDPOINT_IP}
+ port: 6443
+ identityRef:
+ kind: Secret
+ name: ${CLUSTER_NAME}
+ server: ${VSPHERE_SERVER}
+ thumbprint: '${VSPHERE_TLS_THUMBPRINT}'
+---
+apiVersion: infrastructure.cluster.x-k8s.io/v1beta1
+kind: VSphereMachineTemplate
+metadata:
+ name: ${CLUSTER_NAME}-control-plane
+ namespace: ${NAMESPACE}
+spec:
+ template:
+ spec:
+ cloneMode: linkedClone
+ datacenter: ${VSPHERE_DATACENTER=oci-w01dc}
+ datastore: ${VSPHERE_DATASTORE=vsanDatastore}
+ diskGiB: ${VSPHERE_DISK=200}
+ folder: ${VSPHERE_FOLDER=CAPI}
+ memoryMiB: ${VSPHERE_MEMORY=32384}
+ network:
+ devices:
+ - dhcp4: true
+ networkName: "${VSPHERE_NETWORK=workload}"
+ numCPUs: ${VSPHERE_CPU=4}
+ os: Linux
+ resourcePool: '${VSPHERE_RESOURCE_POOL=*/Resources/Workload}'
+ server: '${VSPHERE_SERVER=11.0.11.130}'
+ storagePolicyName: ${VSPHERE_STORAGE_POLICY=""}
+ template: ${VSPHERE_TEMPLATE=OL8-Base-Template}
+ thumbprint: '${VSPHERE_TLS_THUMBPRINT}'
+---
+apiVersion: infrastructure.cluster.x-k8s.io/v1beta1
+kind: VSphereMachineTemplate
+metadata:
+ name: ${CLUSTER_NAME}-md-0
+ namespace: ${NAMESPACE}
+spec:
+ template:
+ spec:
+ cloneMode: linkedClone
+ datacenter: ${VSPHERE_DATACENTER=oci-w01dc}
+ datastore: ${VSPHERE_DATASTORE=vsanDatastore}
+ diskGiB: ${VSPHERE_DISK=200}
+ folder: ${VSPHERE_FOLDER=CAPI}
+ memoryMiB: ${VSPHERE_MEMORY=32384}
+ network:
+ devices:
+ - dhcp4: true
+ networkName: "${VSPHERE_NETWORK=workload}"
+ numCPUs: ${VSPHERE_CPU=4}
+ os: Linux
+ resourcePool: '${VSPHERE_RESOURCE_POOL=*/Resources/Workload}'
+ server: '${VSPHERE_SERVER=11.0.11.130}'
+ storagePolicyName: ${VSPHERE_STORAGE_POLICY=""}
+ template: ${VSPHERE_TEMPLATE=OL8-Base-Template}
+ thumbprint: '${VSPHERE_TLS_THUMBPRINT}'
+---
+apiVersion: controlplane.cluster.x-k8s.io/v1alpha1
+kind: OCNEControlPlane
+metadata:
+ name: ${CLUSTER_NAME}-control-plane
+ namespace: ${NAMESPACE}
+spec:
+ moduleOperator:
+ enabled: true
+ verrazzanoPlatformOperator:
+ enabled: true
+ controlPlaneConfig:
+ clusterConfiguration:
+ apiServer:
+ extraArgs:
+ cloud-provider: external
+ certSANs:
+ - localhost
+ - 127.0.0.1
+ dns:
+ imageRepository: ${OCNE_IMAGE_REPOSITORY=container-registry.oracle.com}/${OCNE_IMAGE_PATH=olcne}
+ imageTag: ${DNS_TAG=v1.9.3}
+ etcd:
+ local:
+ imageRepository: ${OCNE_IMAGE_REPOSITORY=container-registry.oracle.com}/${OCNE_IMAGE_PATH=olcne}
+ imageTag: ${ETCD_TAG=3.5.6}
+ controllerManager:
+ extraArgs:
+ cloud-provider: external
+ networking: {}
+ scheduler: {}
+ imageRepository: ${OCNE_IMAGE_REPOSITORY=container-registry.oracle.com}/${OCNE_IMAGE_PATH=olcne}
+ files:
+ - content: |
+ apiVersion: v1
+ kind: Pod
+ metadata:
+ creationTimestamp: null
+ name: kube-vip
+ namespace: kube-system
+ spec:
+ containers:
+ - args:
+ - manager
+ env:
+ - name: cp_enable
+ value: "true"
+ - name: vip_interface
+ value: ""
+ - name: address
+ value: ${CONTROL_PLANE_ENDPOINT_IP}
+ - name: port
+ value: "6443"
+ - name: vip_arp
+ value: "true"
+ - name: vip_leaderelection
+ value: "true"
+ - name: vip_leaseduration
+ value: "15"
+ - name: vip_renewdeadline
+ value: "10"
+ - name: vip_retryperiod
+ value: "2"
+ image: ghcr.io/kube-vip/kube-vip:v0.5.11
+ imagePullPolicy: IfNotPresent
+ name: kube-vip
+ resources: {}
+ securityContext:
+ capabilities:
+ add:
+ - NET_ADMIN
+ - NET_RAW
+ volumeMounts:
+ - mountPath: /etc/kubernetes/admin.conf
+ name: kubeconfig
+ hostAliases:
+ - hostnames:
+ - kubernetes
+ ip: 127.0.0.1
+ hostNetwork: true
+ volumes:
+ - hostPath:
+ path: /etc/kubernetes/admin.conf
+ type: FileOrCreate
+ name: kubeconfig
+ status: {}
+ owner: root:root
+ path: /etc/kubernetes/manifests/kube-vip.yaml
+ initConfiguration:
+ nodeRegistration:
+ criSocket: /var/run/crio/crio.sock
+ kubeletExtraArgs:
+ cloud-provider: external
+ name: '{{ local_hostname }}'
+ joinConfiguration:
+ discovery: {}
+ nodeRegistration:
+ criSocket: /var/run/crio/crio.sock
+ kubeletExtraArgs:
+ cloud-provider: external
+ name: '{{ local_hostname }}'
+ verbosity: 9
+ preOCNECommands:
+ - hostnamectl set-hostname "{{ ds.meta_data.hostname }}"
+ - echo "::1 ipv6-localhost ipv6-loopback localhost6 localhost6.localdomain6"
+ >/etc/hosts
+ - echo "127.0.0.1 {{ ds.meta_data.hostname }} {{ local_hostname }} localhost
+ localhost.localdomain localhost4 localhost4.localdomain4" >>/etc/hosts
+ users:
+ - name: opc
+ sshAuthorizedKeys:
+ - ${VSPHERE_SSH_AUTHORIZED_KEY}
+ sudo: ALL=(ALL) NOPASSWD:ALL
+ machineTemplate:
+ infrastructureRef:
+ apiVersion: infrastructure.cluster.x-k8s.io/v1beta1
+ kind: VSphereMachineTemplate
+ name: ${CLUSTER_NAME}-control-plane
+ namespace: ${NAMESPACE}
+ replicas: ${CONTROL_PLANE_MACHINE_COUNT=1}
+ version: ${KUBERNETES_VERSION=v1.26.6}
+---
+apiVersion: bootstrap.cluster.x-k8s.io/v1alpha1
+kind: OCNEConfigTemplate
+metadata:
+ name: ${CLUSTER_NAME}-md-0
+ namespace: ${NAMESPACE}
+spec:
+ template:
+ spec:
+ clusterConfiguration:
+ imageRepository: ${OCNE_IMAGE_REPOSITORY=container-registry.oracle.com}/${OCNE_IMAGE_PATH=olcne}
+ joinConfiguration:
+ nodeRegistration:
+ kubeletExtraArgs:
+ cloud-provider: external
+ name: '{{ local_hostname }}'
+ verbosity: 9
+ preOCNECommands:
+ - hostnamectl set-hostname "{{ ds.meta_data.hostname }}"
+ - echo "::1 ipv6-localhost ipv6-loopback localhost6 localhost6.localdomain6"
+ >/etc/hosts
+ - echo "127.0.0.1 {{ ds.meta_data.hostname }} {{ local_hostname }} localhost
+ localhost.localdomain localhost4 localhost4.localdomain4" >>/etc/hosts
+ users:
+ - name: opc
+ sshAuthorizedKeys:
+ - ${VSPHERE_SSH_AUTHORIZED_KEY}
+ sudo: ALL=(ALL) NOPASSWD:ALL
+---
+apiVersion: cluster.x-k8s.io/v1beta1
+kind: MachineDeployment
+metadata:
+ labels:
+ cluster.x-k8s.io/cluster-name: ${CLUSTER_NAME}
+ name: ${CLUSTER_NAME}-md-0
+ namespace: ${NAMESPACE}
+spec:
+ clusterName: ${CLUSTER_NAME}
+ replicas: ${NODE_MACHINE_COUNT=3}
+ selector:
+ matchLabels: {}
+ template:
+ metadata:
+ labels:
+ cluster.x-k8s.io/cluster-name: ${CLUSTER_NAME}
+ spec:
+ bootstrap:
+ configRef:
+ apiVersion: bootstrap.cluster.x-k8s.io/v1alpha1
+ kind: OCNEConfigTemplate
+ name: ${CLUSTER_NAME}-md-0
+ clusterName: ${CLUSTER_NAME}
+ infrastructureRef:
+ apiVersion: infrastructure.cluster.x-k8s.io/v1beta1
+ kind: VSphereMachineTemplate
+ name: ${CLUSTER_NAME}-md-0
+ version: ${KUBERNETES_VERSION=v1.26.6}
+---
+apiVersion: addons.cluster.x-k8s.io/v1beta1
+kind: ClusterResourceSet
+metadata:
+ name: ${CLUSTER_NAME}-crs-0
+ namespace: ${NAMESPACE}
+spec:
+ clusterSelector:
+ matchLabels:
+ cluster.x-k8s.io/cluster-name: ${CLUSTER_NAME}
+ resources:
+ - kind: Secret
+ name: ${CLUSTER_NAME}-vsphere-csi-controller
+ - kind: ConfigMap
+ name: ${CLUSTER_NAME}-vsphere-csi-controller-role
+ - kind: ConfigMap
+ name: ${CLUSTER_NAME}-vsphere-csi-controller-binding
+ - kind: Secret
+ name: ${CLUSTER_NAME}-csi-vsphere-config
+ - kind: ConfigMap
+ name: csi.vsphere.vmware.com
+ - kind: ConfigMap
+ name: vsphere-csi-controller-sa
+ - kind: ConfigMap
+ name: vsphere-csi-node-sa
+ - kind: ConfigMap
+ name: ${CLUSTER_NAME}-vsphere-csi-node-cluster-role
+ - kind: ConfigMap
+ name: ${CLUSTER_NAME}-vsphere-csi-node-cluster-role-binding
+ - kind: ConfigMap
+ name: ${CLUSTER_NAME}-vsphere-csi-node-role
+ - kind: ConfigMap
+ name: ${CLUSTER_NAME}-vsphere-csi-node-binding
+ - kind: ConfigMap
+ name: ${CLUSTER_NAME}-internal-feature-states.csi.vsphere.vmware.com
+ - kind: ConfigMap
+ name: ${CLUSTER_NAME}-vsphere-csi-controller-service
+ - kind: ConfigMap
+ name: ${CLUSTER_NAME}-vsphere-csi-controller
+ - kind: ConfigMap
+ name: ${CLUSTER_NAME}-vsphere-csi-node
+ - kind: ConfigMap
+ name: ${CLUSTER_NAME}-vsphere-csi-node-windows
+ - kind: Secret
+ name: ${CLUSTER_NAME}-cloud-controller-manager
+ - kind: Secret
+ name: ${CLUSTER_NAME}-cloud-provider-vsphere-credentials
+ - kind: ConfigMap
+ name: ${CLUSTER_NAME}-cpi-manifests
+ strategy: Reconcile
+---
+apiVersion: v1
+kind: Secret
+metadata:
+ name: ${CLUSTER_NAME}
+ namespace: ${NAMESPACE}
+stringData:
+ password: ${VSPHERE_PASSWORD}
+ username: ${VSPHERE_USERNAME}
+---
+apiVersion: v1
+kind: ConfigMap
+metadata:
+ name: ${CLUSTER_NAME}-vsphere-csi-controller
+ namespace: ${NAMESPACE}
+data:
+ data: |
+ apiVersion: v1
+ kind: ServiceAccount
+ metadata:
+ name: vsphere-csi-controller
+ namespace: kube-system
+---
+apiVersion: v1
+data:
+ data: |
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRole
+ metadata:
+ name: vsphere-csi-controller-role
+ rules:
+ - apiGroups: [""]
+ resources: ["nodes", "pods", "configmaps"]
+ verbs: ["get", "list", "watch"]
+ - apiGroups: [""]
+ resources: ["persistentvolumeclaims"]
+ verbs: ["get", "list", "watch", "update"]
+ - apiGroups: [""]
+ resources: ["persistentvolumeclaims/status"]
+ verbs: ["patch"]
+ - apiGroups: [""]
+ resources: ["persistentvolumes"]
+ verbs: ["get", "list", "watch", "create", "update", "delete", "patch"]
+ - apiGroups: [""]
+ resources: ["events"]
+ verbs: ["get", "list", "watch", "create", "update", "patch"]
+ - apiGroups: ["coordination.k8s.io"]
+ resources: ["leases"]
+ verbs: ["get", "watch", "list", "delete", "update", "create"]
+ - apiGroups: ["storage.k8s.io"]
+ resources: ["storageclasses", "csinodes"]
+ verbs: ["get", "list", "watch"]
+ - apiGroups: ["storage.k8s.io"]
+ resources: ["volumeattachments"]
+ verbs: ["get", "list", "watch", "patch"]
+ - apiGroups: ["cns.vmware.com"]
+ resources: ["triggercsifullsyncs"]
+ verbs: ["create", "get", "update", "watch", "list"]
+ - apiGroups: ["cns.vmware.com"]
+ resources: ["cnsvspherevolumemigrations"]
+ verbs: ["create", "get", "list", "watch", "update", "delete"]
+ - apiGroups: ["apiextensions.k8s.io"]
+ resources: ["customresourcedefinitions"]
+ verbs: ["get", "create", "update"]
+ - apiGroups: ["storage.k8s.io"]
+ resources: ["volumeattachments/status"]
+ verbs: ["patch"]
+ - apiGroups: ["cns.vmware.com"]
+ resources: ["cnsvolumeoperationrequests"]
+ verbs: ["create", "get", "list", "update", "delete"]
+ - apiGroups: [ "snapshot.storage.k8s.io" ]
+ resources: [ "volumesnapshots" ]
+ verbs: [ "get", "list" ]
+ - apiGroups: [ "snapshot.storage.k8s.io" ]
+ resources: [ "volumesnapshotclasses" ]
+ verbs: [ "watch", "get", "list" ]
+ - apiGroups: [ "snapshot.storage.k8s.io" ]
+ resources: [ "volumesnapshotcontents" ]
+ verbs: [ "create", "get", "list", "watch", "update", "delete", "patch"]
+ - apiGroups: [ "snapshot.storage.k8s.io" ]
+ resources: [ "volumesnapshotcontents/status" ]
+ verbs: [ "update", "patch" ]
+ - apiGroups: [ "cns.vmware.com" ]
+ resources: [ "csinodetopologies" ]
+ verbs: ["get", "update", "watch", "list"]
+kind: ConfigMap
+metadata:
+ name: ${CLUSTER_NAME}-vsphere-csi-controller-role
+ namespace: ${NAMESPACE}
+---
+apiVersion: v1
+data:
+ data: |
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRoleBinding
+ metadata:
+ name: vsphere-csi-controller-binding
+ roleRef:
+ apiGroup: rbac.authorization.k8s.io
+ kind: ClusterRole
+ name: vsphere-csi-controller-role
+ subjects:
+ - kind: ServiceAccount
+ name: vsphere-csi-controller
+ namespace: kube-system
+kind: ConfigMap
+metadata:
+ name: ${CLUSTER_NAME}-vsphere-csi-controller-binding
+ namespace: ${NAMESPACE}
+---
+apiVersion: v1
+kind: Secret
+metadata:
+ name: ${CLUSTER_NAME}-csi-vsphere-config
+ namespace: ${NAMESPACE}
+stringData:
+ data: |
+ apiVersion: v1
+ kind: Secret
+ metadata:
+ name: csi-vsphere-config
+ namespace: kube-system
+ stringData:
+ csi-vsphere.conf: |+
+ [Global]
+ thumbprint = "${VSPHERE_TLS_THUMBPRINT}"
+ cluster-id = "${NAMESPACE}/${CLUSTER_NAME}"
+
+ [VirtualCenter "${VSPHERE_SERVER}"]
+ insecure-flag = "true"
+ user = "${VSPHERE_USERNAME}"
+ password = "${VSPHERE_PASSWORD}"
+ datacenters = "${VSPHERE_DATACENTER}"
+ targetvSANFileShareDatastoreURLs = "${VSPHERE_DATASTORE_URL_SAN}"
+
+ [Network]
+ public-network = "${VSPHERE_NETWORK=workload}"
+
+ type: Opaque
+type: addons.cluster.x-k8s.io/resource-set
+---
+apiVersion: v1
+data:
+ data: |
+ apiVersion: storage.k8s.io/v1
+ kind: CSIDriver
+ metadata:
+ name: csi.vsphere.vmware.com
+ spec:
+ attachRequired: true
+ podInfoOnMount: false
+kind: ConfigMap
+metadata:
+ name: csi.vsphere.vmware.com
+ namespace: ${NAMESPACE}
+---
+apiVersion: v1
+data:
+ data: |
+ kind: ServiceAccount
+ apiVersion: v1
+ metadata:
+ name: vsphere-csi-controller
+ namespace: kube-system
+kind: ConfigMap
+metadata:
+ name: vsphere-csi-controller-sa
+ namespace: ${NAMESPACE}
+---
+apiVersion: v1
+data:
+ data: |
+ kind: ServiceAccount
+ apiVersion: v1
+ metadata:
+ name: vsphere-csi-node
+ namespace: kube-system
+kind: ConfigMap
+metadata:
+ name: vsphere-csi-node-sa
+ namespace: ${NAMESPACE}
+---
+apiVersion: v1
+data:
+ data: |
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRole
+ metadata:
+ name: vsphere-csi-node-cluster-role
+ rules:
+ - apiGroups: ["cns.vmware.com"]
+ resources: ["csinodetopologies"]
+ verbs: ["create", "watch", "get", "patch"]
+ - apiGroups: [""]
+ resources: ["nodes"]
+ verbs: ["get"]
+kind: ConfigMap
+metadata:
+ name: ${CLUSTER_NAME}-vsphere-csi-node-cluster-role
+ namespace: ${NAMESPACE}
+---
+apiVersion: v1
+data:
+ data: |
+ kind: ClusterRoleBinding
+ apiVersion: rbac.authorization.k8s.io/v1
+ metadata:
+ name: vsphere-csi-node-cluster-role-binding
+ subjects:
+ - kind: ServiceAccount
+ name: vsphere-csi-node
+ namespace: kube-system
+ roleRef:
+ kind: ClusterRole
+ name: vsphere-csi-node-cluster-role
+ apiGroup: rbac.authorization.k8s.io
+kind: ConfigMap
+metadata:
+ name: ${CLUSTER_NAME}-vsphere-csi-node-cluster-role-binding
+ namespace: ${NAMESPACE}
+---
+apiVersion: v1
+data:
+ data: |
+ kind: Role
+ apiVersion: rbac.authorization.k8s.io/v1
+ metadata:
+ name: vsphere-csi-node-role
+ namespace: kube-system
+ rules:
+ - apiGroups: [""]
+ resources: ["configmaps"]
+ verbs: ["get", "list", "watch"]
+kind: ConfigMap
+metadata:
+ name: ${CLUSTER_NAME}-vsphere-csi-node-role
+ namespace: ${NAMESPACE}
+---
+apiVersion: v1
+data:
+ data: |
+ kind: RoleBinding
+ apiVersion: rbac.authorization.k8s.io/v1
+ metadata:
+ name: vsphere-csi-node-binding
+ namespace: kube-system
+ subjects:
+ - kind: ServiceAccount
+ name: vsphere-csi-node
+ namespace: kube-system
+ roleRef:
+ kind: Role
+ name: vsphere-csi-node-role
+ apiGroup: rbac.authorization.k8s.io
+kind: ConfigMap
+metadata:
+ name: ${CLUSTER_NAME}-vsphere-csi-node-binding
+ namespace: ${NAMESPACE}
+---
+apiVersion: v1
+data:
+ data: |
+ apiVersion: v1
+ data:
+ "csi-migration": "true"
+ "csi-auth-check": "true"
+ "online-volume-extend": "true"
+ "trigger-csi-fullsync": "false"
+ "async-query-volume": "true"
+ "improved-csi-idempotency": "true"
+ "improved-volume-topology": "true"
+ "block-volume-snapshot": "true"
+ "csi-windows-support": "false"
+ "use-csinode-id": "true"
+ "list-volumes": "false"
+ "pv-to-backingdiskobjectid-mapping": "false"
+ "cnsmgr-suspend-create-volume": "true"
+ "topology-preferential-datastores": "true"
+ "max-pvscsi-targets-per-vm": "true"
+ kind: ConfigMap
+ metadata:
+ name: internal-feature-states.csi.vsphere.vmware.com
+ namespace: kube-system
+kind: ConfigMap
+metadata:
+ name: ${CLUSTER_NAME}-internal-feature-states.csi.vsphere.vmware.com
+ namespace: ${NAMESPACE}
+---
+apiVersion: v1
+data:
+ data: |
+ apiVersion: v1
+ kind: Service
+ metadata:
+ name: vsphere-csi-controller
+ namespace: kube-system
+ labels:
+ app: vsphere-csi-controller
+ spec:
+ ports:
+ - name: ctlr
+ port: 2112
+ targetPort: 2112
+ protocol: TCP
+ - name: syncer
+ port: 2113
+ targetPort: 2113
+ protocol: TCP
+ selector:
+ app: vsphere-csi-controller
+kind: ConfigMap
+metadata:
+ name: ${CLUSTER_NAME}-vsphere-csi-controller-service
+ namespace: ${NAMESPACE}
+---
+apiVersion: v1
+data:
+ data: |
+ kind: Deployment
+ apiVersion: apps/v1
+ metadata:
+ name: vsphere-csi-controller
+ namespace: kube-system
+ spec:
+ replicas: 1
+ strategy:
+ type: RollingUpdate
+ rollingUpdate:
+ maxUnavailable: 1
+ maxSurge: 0
+ selector:
+ matchLabels:
+ app: vsphere-csi-controller
+ template:
+ metadata:
+ labels:
+ app: vsphere-csi-controller
+ role: vsphere-csi
+ spec:
+ affinity:
+ podAntiAffinity:
+ requiredDuringSchedulingIgnoredDuringExecution:
+ - labelSelector:
+ matchExpressions:
+ - key: "app"
+ operator: In
+ values:
+ - vsphere-csi-controller
+ topologyKey: "kubernetes.io/hostname"
+ serviceAccountName: vsphere-csi-controller
+ nodeSelector:
+ node-role.kubernetes.io/control-plane: ""
+ tolerations:
+ - key: node-role.kubernetes.io/master
+ operator: Exists
+ effect: NoSchedule
+ - key: node-role.kubernetes.io/control-plane
+ operator: Exists
+ effect: NoSchedule
+ # uncomment below toleration if you need an aggressive pod eviction in case when
+ # node becomes not-ready or unreachable. Default is 300 seconds if not specified.
+ #- key: node.kubernetes.io/not-ready
+ # operator: Exists
+ # effect: NoExecute
+ # tolerationSeconds: 30
+ #- key: node.kubernetes.io/unreachable
+ # operator: Exists
+ # effect: NoExecute
+ # tolerationSeconds: 30
+ dnsPolicy: "Default"
+ containers:
+ - name: csi-attacher
+ image: k8s.gcr.io/sig-storage/csi-attacher:v3.5.0
+ args:
+ - "--v=4"
+ - "--timeout=300s"
+ - "--csi-address=$(ADDRESS)"
+ - "--leader-election"
+ - "--kube-api-qps=100"
+ - "--kube-api-burst=100"
+ env:
+ - name: ADDRESS
+ value: /csi/csi.sock
+ volumeMounts:
+ - mountPath: /csi
+ name: socket-dir
+ - name: csi-resizer
+ image: k8s.gcr.io/sig-storage/csi-resizer:v1.5.0
+ args:
+ - "--v=4"
+ - "--timeout=300s"
+ - "--handle-volume-inuse-error=false"
+ - "--csi-address=$(ADDRESS)"
+ - "--kube-api-qps=100"
+ - "--kube-api-burst=100"
+ - "--leader-election"
+ env:
+ - name: ADDRESS
+ value: /csi/csi.sock
+ volumeMounts:
+ - mountPath: /csi
+ name: socket-dir
+ - name: vsphere-csi-controller
+ image: gcr.io/cloud-provider-vsphere/csi/release/driver:v2.7.0
+ args:
+ - "--fss-name=internal-feature-states.csi.vsphere.vmware.com"
+ - "--fss-namespace=$(CSI_NAMESPACE)"
+ imagePullPolicy: "Always"
+ env:
+ - name: CSI_ENDPOINT
+ value: unix:///csi/csi.sock
+ - name: X_CSI_MODE
+ value: "controller"
+ - name: X_CSI_SPEC_DISABLE_LEN_CHECK
+ value: "true"
+ - name: X_CSI_SERIAL_VOL_ACCESS_TIMEOUT
+ value: 3m
+ - name: VSPHERE_CSI_CONFIG
+ value: "/etc/cloud/csi-vsphere.conf"
+ - name: LOGGER_LEVEL
+ value: "PRODUCTION" # Options: DEVELOPMENT, PRODUCTION
+ - name: INCLUSTER_CLIENT_QPS
+ value: "100"
+ - name: INCLUSTER_CLIENT_BURST
+ value: "100"
+ - name: CSI_NAMESPACE
+ valueFrom:
+ fieldRef:
+ fieldPath: metadata.namespace
+ volumeMounts:
+ - mountPath: /etc/cloud
+ name: vsphere-config-volume
+ readOnly: true
+ - mountPath: /csi
+ name: socket-dir
+ ports:
+ - name: healthz
+ containerPort: 9808
+ protocol: TCP
+ - name: prometheus
+ containerPort: 2112
+ protocol: TCP
+ livenessProbe:
+ httpGet:
+ path: /healthz
+ port: healthz
+ initialDelaySeconds: 10
+ timeoutSeconds: 3
+ periodSeconds: 5
+ failureThreshold: 3
+ - name: liveness-probe
+ image: k8s.gcr.io/sig-storage/livenessprobe:v2.7.0
+ args:
+ - "--v=4"
+ - "--csi-address=/csi/csi.sock"
+ volumeMounts:
+ - name: socket-dir
+ mountPath: /csi
+ - name: vsphere-syncer
+ image: gcr.io/cloud-provider-vsphere/csi/release/syncer:v2.7.0
+ args:
+ - "--leader-election"
+ - "--fss-name=internal-feature-states.csi.vsphere.vmware.com"
+ - "--fss-namespace=$(CSI_NAMESPACE)"
+ imagePullPolicy: "Always"
+ ports:
+ - containerPort: 2113
+ name: prometheus
+ protocol: TCP
+ env:
+ - name: FULL_SYNC_INTERVAL_MINUTES
+ value: "30"
+ - name: VSPHERE_CSI_CONFIG
+ value: "/etc/cloud/csi-vsphere.conf"
+ - name: LOGGER_LEVEL
+ value: "PRODUCTION" # Options: DEVELOPMENT, PRODUCTION
+ - name: INCLUSTER_CLIENT_QPS
+ value: "100"
+ - name: INCLUSTER_CLIENT_BURST
+ value: "100"
+ - name: GODEBUG
+ value: x509sha1=1
+ - name: CSI_NAMESPACE
+ valueFrom:
+ fieldRef:
+ fieldPath: metadata.namespace
+ volumeMounts:
+ - mountPath: /etc/cloud
+ name: vsphere-config-volume
+ readOnly: true
+ - name: csi-provisioner
+ image: k8s.gcr.io/sig-storage/csi-provisioner:v3.2.1
+ args:
+ - "--v=4"
+ - "--timeout=300s"
+ - "--csi-address=$(ADDRESS)"
+ - "--kube-api-qps=100"
+ - "--kube-api-burst=100"
+ - "--leader-election"
+ - "--default-fstype=ext4"
+ # needed only for topology aware setup
+ #- "--feature-gates=Topology=true"
+ #- "--strict-topology"
+ env:
+ - name: ADDRESS
+ value: /csi/csi.sock
+ volumeMounts:
+ - mountPath: /csi
+ name: socket-dir
+ - name: csi-snapshotter
+ image: k8s.gcr.io/sig-storage/csi-snapshotter:v6.0.1
+ args:
+ - "--v=4"
+ - "--kube-api-qps=100"
+ - "--kube-api-burst=100"
+ - "--timeout=300s"
+ - "--csi-address=$(ADDRESS)"
+ - "--leader-election"
+ env:
+ - name: ADDRESS
+ value: /csi/csi.sock
+ volumeMounts:
+ - mountPath: /csi
+ name: socket-dir
+ volumes:
+ - name: vsphere-config-volume
+ secret:
+ secretName: csi-vsphere-config
+ - name: socket-dir
+ emptyDir: {}
+
+kind: ConfigMap
+metadata:
+ name: ${CLUSTER_NAME}-vsphere-csi-controller
+ namespace: ${NAMESPACE}
+---
+apiVersion: v1
+data:
+ data: |
+ kind: DaemonSet
+ apiVersion: apps/v1
+ metadata:
+ name: vsphere-csi-node
+ namespace: kube-system
+ spec:
+ selector:
+ matchLabels:
+ app: vsphere-csi-node
+ updateStrategy:
+ type: "RollingUpdate"
+ rollingUpdate:
+ maxUnavailable: 1
+ template:
+ metadata:
+ labels:
+ app: vsphere-csi-node
+ role: vsphere-csi
+ spec:
+ nodeSelector:
+ kubernetes.io/os: linux
+ serviceAccountName: vsphere-csi-node
+ hostNetwork: true
+ dnsPolicy: "ClusterFirstWithHostNet"
+ containers:
+ - name: node-driver-registrar
+ image: k8s.gcr.io/sig-storage/csi-node-driver-registrar:v2.5.1
+ args:
+ - "--v=5"
+ - "--csi-address=$(ADDRESS)"
+ - "--kubelet-registration-path=$(DRIVER_REG_SOCK_PATH)"
+ env:
+ - name: ADDRESS
+ value: /csi/csi.sock
+ - name: DRIVER_REG_SOCK_PATH
+ value: /var/lib/kubelet/plugins/csi.vsphere.vmware.com/csi.sock
+ volumeMounts:
+ - name: plugin-dir
+ mountPath: /csi
+ - name: registration-dir
+ mountPath: /registration
+ livenessProbe:
+ exec:
+ command:
+ - /csi-node-driver-registrar
+ - --kubelet-registration-path=/var/lib/kubelet/plugins/csi.vsphere.vmware.com/csi.sock
+ - --mode=kubelet-registration-probe
+ initialDelaySeconds: 3
+ - name: vsphere-csi-node
+ image: gcr.io/cloud-provider-vsphere/csi/release/driver:v2.7.0
+ args:
+ - "--fss-name=internal-feature-states.csi.vsphere.vmware.com"
+ - "--fss-namespace=$(CSI_NAMESPACE)"
+ imagePullPolicy: "Always"
+ env:
+ - name: NODE_NAME
+ valueFrom:
+ fieldRef:
+ fieldPath: spec.nodeName
+ - name: CSI_ENDPOINT
+ value: unix:///csi/csi.sock
+ - name: MAX_VOLUMES_PER_NODE
+ value: "59" # Maximum number of volumes that controller can publish to the node. If value is not set or zero Kubernetes decide how many volumes can be published by the controller to the node.
+ - name: X_CSI_MODE
+ value: "node"
+ - name: X_CSI_SPEC_REQ_VALIDATION
+ value: "false"
+ - name: X_CSI_SPEC_DISABLE_LEN_CHECK
+ value: "true"
+ - name: LOGGER_LEVEL
+ value: "PRODUCTION" # Options: DEVELOPMENT, PRODUCTION
+ - name: GODEBUG
+ value: x509sha1=1
+ - name: CSI_NAMESPACE
+ valueFrom:
+ fieldRef:
+ fieldPath: metadata.namespace
+ - name: NODEGETINFO_WATCH_TIMEOUT_MINUTES
+ value: "1"
+ securityContext:
+ privileged: true
+ capabilities:
+ add: ["SYS_ADMIN"]
+ allowPrivilegeEscalation: true
+ volumeMounts:
+ - name: plugin-dir
+ mountPath: /csi
+ - name: pods-mount-dir
+ mountPath: /var/lib/kubelet
+ # needed so that any mounts setup inside this container are
+ # propagated back to the host machine.
+ mountPropagation: "Bidirectional"
+ - name: device-dir
+ mountPath: /dev
+ - name: blocks-dir
+ mountPath: /sys/block
+ - name: sys-devices-dir
+ mountPath: /sys/devices
+ ports:
+ - name: healthz
+ containerPort: 9808
+ protocol: TCP
+ livenessProbe:
+ httpGet:
+ path: /healthz
+ port: healthz
+ initialDelaySeconds: 10
+ timeoutSeconds: 5
+ periodSeconds: 5
+ failureThreshold: 3
+ - name: liveness-probe
+ image: k8s.gcr.io/sig-storage/livenessprobe:v2.7.0
+ args:
+ - "--v=4"
+ - "--csi-address=/csi/csi.sock"
+ volumeMounts:
+ - name: plugin-dir
+ mountPath: /csi
+ volumes:
+ - name: registration-dir
+ hostPath:
+ path: /var/lib/kubelet/plugins_registry
+ type: Directory
+ - name: plugin-dir
+ hostPath:
+ path: /var/lib/kubelet/plugins/csi.vsphere.vmware.com
+ type: DirectoryOrCreate
+ - name: pods-mount-dir
+ hostPath:
+ path: /var/lib/kubelet
+ type: Directory
+ - name: device-dir
+ hostPath:
+ path: /dev
+ - name: blocks-dir
+ hostPath:
+ path: /sys/block
+ type: Directory
+ - name: sys-devices-dir
+ hostPath:
+ path: /sys/devices
+ type: Directory
+ tolerations:
+ - effect: NoExecute
+ operator: Exists
+ - effect: NoSchedule
+ operator: Exists
+kind: ConfigMap
+metadata:
+ name: ${CLUSTER_NAME}-vsphere-csi-node
+ namespace: ${NAMESPACE}
+---
+apiVersion: v1
+data:
+ data: |
+ kind: DaemonSet
+ apiVersion: apps/v1
+ metadata:
+ name: vsphere-csi-node-windows
+ namespace: kube-system
+ spec:
+ selector:
+ matchLabels:
+ app: vsphere-csi-node-windows
+ updateStrategy:
+ type: RollingUpdate
+ rollingUpdate:
+ maxUnavailable: 1
+ template:
+ metadata:
+ labels:
+ app: vsphere-csi-node-windows
+ role: vsphere-csi-windows
+ spec:
+ nodeSelector:
+ kubernetes.io/os: windows
+ serviceAccountName: vsphere-csi-node
+ containers:
+ - name: node-driver-registrar
+ image: k8s.gcr.io/sig-storage/csi-node-driver-registrar:v2.5.1
+ args:
+ - "--v=5"
+ - "--csi-address=$(ADDRESS)"
+ - "--kubelet-registration-path=$(DRIVER_REG_SOCK_PATH)"
+ env:
+ - name: ADDRESS
+ value: 'unix://C:\\csi\\csi.sock'
+ - name: DRIVER_REG_SOCK_PATH
+ value: 'C:\\var\\lib\\kubelet\\plugins\\csi.vsphere.vmware.com\\csi.sock'
+ volumeMounts:
+ - name: plugin-dir
+ mountPath: /csi
+ - name: registration-dir
+ mountPath: /registration
+ livenessProbe:
+ exec:
+ command:
+ - /csi-node-driver-registrar.exe
+ - --kubelet-registration-path=C:\\var\\lib\\kubelet\\plugins\\csi.vsphere.vmware.com\\csi.sock
+ - --mode=kubelet-registration-probe
+ initialDelaySeconds: 3
+ - name: vsphere-csi-node
+ image: gcr.io/cloud-provider-vsphere/csi/release/driver:v2.7.0
+ args:
+ - "--fss-name=internal-feature-states.csi.vsphere.vmware.com"
+ - "--fss-namespace=$(CSI_NAMESPACE)"
+ imagePullPolicy: "Always"
+ env:
+ - name: NODE_NAME
+ valueFrom:
+ fieldRef:
+ apiVersion: v1
+ fieldPath: spec.nodeName
+ - name: CSI_ENDPOINT
+ value: 'unix://C:\\csi\\csi.sock'
+ - name: MAX_VOLUMES_PER_NODE
+ value: "59" # Maximum number of volumes that controller can publish to the node. If value is not set or zero Kubernetes decide how many volumes can be published by the controller to the node.
+ - name: X_CSI_MODE
+ value: node
+ - name: X_CSI_SPEC_REQ_VALIDATION
+ value: 'false'
+ - name: X_CSI_SPEC_DISABLE_LEN_CHECK
+ value: "true"
+ - name: LOGGER_LEVEL
+ value: "PRODUCTION" # Options: DEVELOPMENT, PRODUCTION
+ - name: X_CSI_LOG_LEVEL
+ value: DEBUG
+ - name: CSI_NAMESPACE
+ valueFrom:
+ fieldRef:
+ fieldPath: metadata.namespace
+ - name: NODEGETINFO_WATCH_TIMEOUT_MINUTES
+ value: "1"
+ volumeMounts:
+ - name: plugin-dir
+ mountPath: 'C:\csi'
+ - name: pods-mount-dir
+ mountPath: 'C:\var\lib\kubelet'
+ - name: csi-proxy-volume-v1
+ mountPath: \\.\pipe\csi-proxy-volume-v1
+ - name: csi-proxy-filesystem-v1
+ mountPath: \\.\pipe\csi-proxy-filesystem-v1
+ - name: csi-proxy-disk-v1
+ mountPath: \\.\pipe\csi-proxy-disk-v1
+ - name: csi-proxy-system-v1alpha1
+ mountPath: \\.\pipe\csi-proxy-system-v1alpha1
+ ports:
+ - name: healthz
+ containerPort: 9808
+ protocol: TCP
+ livenessProbe:
+ httpGet:
+ path: /healthz
+ port: healthz
+ initialDelaySeconds: 10
+ timeoutSeconds: 5
+ periodSeconds: 5
+ failureThreshold: 3
+ - name: liveness-probe
+ image: k8s.gcr.io/sig-storage/livenessprobe:v2.7.0
+ args:
+ - "--v=4"
+ - "--csi-address=/csi/csi.sock"
+ volumeMounts:
+ - name: plugin-dir
+ mountPath: /csi
+ volumes:
+ - name: registration-dir
+ hostPath:
+ path: 'C:\var\lib\kubelet\plugins_registry\'
+ type: Directory
+ - name: plugin-dir
+ hostPath:
+ path: 'C:\var\lib\kubelet\plugins\csi.vsphere.vmware.com\'
+ type: DirectoryOrCreate
+ - name: pods-mount-dir
+ hostPath:
+ path: \var\lib\kubelet
+ type: Directory
+ - name: csi-proxy-disk-v1
+ hostPath:
+ path: \\.\pipe\csi-proxy-disk-v1
+ type: ''
+ - name: csi-proxy-volume-v1
+ hostPath:
+ path: \\.\pipe\csi-proxy-volume-v1
+ type: ''
+ - name: csi-proxy-filesystem-v1
+ hostPath:
+ path: \\.\pipe\csi-proxy-filesystem-v1
+ type: ''
+ - name: csi-proxy-system-v1alpha1
+ hostPath:
+ path: \\.\pipe\csi-proxy-system-v1alpha1
+ type: ''
+ tolerations:
+ - effect: NoExecute
+ operator: Exists
+ - effect: NoSchedule
+ operator: Exists
+kind: ConfigMap
+metadata:
+ name: ${CLUSTER_NAME}-vsphere-csi-node-windows
+ namespace: ${NAMESPACE}
+---
+apiVersion: v1
+kind: Secret
+metadata:
+ name: ${CLUSTER_NAME}-cloud-controller-manager
+ namespace: ${NAMESPACE}
+stringData:
+ data: |
+ apiVersion: v1
+ kind: ServiceAccount
+ metadata:
+ labels:
+ component: cloud-controller-manager
+ vsphere-cpi-infra: service-account
+ name: cloud-controller-manager
+ namespace: kube-system
+type: addons.cluster.x-k8s.io/resource-set
+---
+apiVersion: v1
+kind: Secret
+metadata:
+ name: ${CLUSTER_NAME}-cloud-provider-vsphere-credentials
+ namespace: ${NAMESPACE}
+stringData:
+ data: |
+ apiVersion: v1
+ kind: Secret
+ metadata:
+ labels:
+ component: cloud-controller-manager
+ vsphere-cpi-infra: secret
+ name: cloud-provider-vsphere-credentials
+ namespace: kube-system
+ stringData:
+ ${VSPHERE_SERVER}.password: ${VSPHERE_PASSWORD}
+ ${VSPHERE_SERVER}.username: ${VSPHERE_USERNAME}
+ type: Opaque
+type: addons.cluster.x-k8s.io/resource-set
+---
+apiVersion: v1
+data:
+ data: |
+ ---
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRole
+ metadata:
+ labels:
+ component: cloud-controller-manager
+ vsphere-cpi-infra: role
+ name: system:cloud-controller-manager
+ rules:
+ - apiGroups:
+ - ""
+ resources:
+ - events
+ verbs:
+ - create
+ - patch
+ - update
+ - apiGroups:
+ - ""
+ resources:
+ - nodes
+ verbs:
+ - '*'
+ - apiGroups:
+ - ""
+ resources:
+ - nodes/status
+ verbs:
+ - patch
+ - apiGroups:
+ - ""
+ resources:
+ - services
+ verbs:
+ - list
+ - patch
+ - update
+ - watch
+ - apiGroups:
+ - ""
+ resources:
+ - services/status
+ verbs:
+ - patch
+ - apiGroups:
+ - ""
+ resources:
+ - serviceaccounts
+ verbs:
+ - create
+ - get
+ - list
+ - watch
+ - update
+ - apiGroups:
+ - ""
+ resources:
+ - persistentvolumes
+ verbs:
+ - get
+ - list
+ - watch
+ - update
+ - apiGroups:
+ - ""
+ resources:
+ - endpoints
+ verbs:
+ - create
+ - get
+ - list
+ - watch
+ - update
+ - apiGroups:
+ - ""
+ resources:
+ - secrets
+ verbs:
+ - get
+ - list
+ - watch
+ - apiGroups:
+ - coordination.k8s.io
+ resources:
+ - leases
+ verbs:
+ - get
+ - watch
+ - list
+ - update
+ - create
+ ---
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRoleBinding
+ metadata:
+ labels:
+ component: cloud-controller-manager
+ vsphere-cpi-infra: cluster-role-binding
+ name: system:cloud-controller-manager
+ roleRef:
+ apiGroup: rbac.authorization.k8s.io
+ kind: ClusterRole
+ name: system:cloud-controller-manager
+ subjects:
+ - kind: ServiceAccount
+ name: cloud-controller-manager
+ namespace: kube-system
+ - kind: User
+ name: cloud-controller-manager
+ ---
+ apiVersion: v1
+ data:
+ vsphere.conf: |
+ global:
+ port: 443
+ secretName: cloud-provider-vsphere-credentials
+ secretNamespace: kube-system
+ thumbprint: '${VSPHERE_TLS_THUMBPRINT}'
+ vcenter:
+ ${VSPHERE_SERVER}:
+ datacenters:
+ - '${VSPHERE_DATACENTER}'
+ server: '${VSPHERE_SERVER}'
+ kind: ConfigMap
+ metadata:
+ name: vsphere-cloud-config
+ namespace: kube-system
+ ---
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: RoleBinding
+ metadata:
+ labels:
+ component: cloud-controller-manager
+ vsphere-cpi-infra: role-binding
+ name: servicecatalog.k8s.io:apiserver-authentication-reader
+ namespace: kube-system
+ roleRef:
+ apiGroup: rbac.authorization.k8s.io
+ kind: Role
+ name: extension-apiserver-authentication-reader
+ subjects:
+ - kind: ServiceAccount
+ name: cloud-controller-manager
+ namespace: kube-system
+ - kind: User
+ name: cloud-controller-manager
+ ---
+ apiVersion: apps/v1
+ kind: DaemonSet
+ metadata:
+ labels:
+ component: cloud-controller-manager
+ tier: control-plane
+ name: vsphere-cloud-controller-manager
+ namespace: kube-system
+ spec:
+ selector:
+ matchLabels:
+ name: vsphere-cloud-controller-manager
+ template:
+ metadata:
+ labels:
+ component: cloud-controller-manager
+ name: vsphere-cloud-controller-manager
+ tier: control-plane
+ spec:
+ affinity:
+ nodeAffinity:
+ requiredDuringSchedulingIgnoredDuringExecution:
+ nodeSelectorTerms:
+ - matchExpressions:
+ - key: node-role.kubernetes.io/control-plane
+ operator: Exists
+ - matchExpressions:
+ - key: node-role.kubernetes.io/master
+ operator: Exists
+ containers:
+ - args:
+ - --v=2
+ - --cloud-provider=vsphere
+ - --cloud-config=/etc/cloud/vsphere.conf
+ image: gcr.io/cloud-provider-vsphere/cpi/release/manager:v1.25.3
+ name: vsphere-cloud-controller-manager
+ resources:
+ requests:
+ cpu: 200m
+ volumeMounts:
+ - mountPath: /etc/cloud
+ name: vsphere-config-volume
+ readOnly: true
+ hostNetwork: true
+ priorityClassName: system-node-critical
+ securityContext:
+ runAsUser: 1001
+ serviceAccountName: cloud-controller-manager
+ tolerations:
+ - effect: NoSchedule
+ key: node.cloudprovider.kubernetes.io/uninitialized
+ value: "true"
+ - effect: NoSchedule
+ key: node-role.kubernetes.io/master
+ operator: Exists
+ - effect: NoSchedule
+ key: node-role.kubernetes.io/control-plane
+ operator: Exists
+ - effect: NoSchedule
+ key: node.kubernetes.io/not-ready
+ operator: Exists
+ volumes:
+ - configMap:
+ name: vsphere-cloud-config
+ name: vsphere-config-volume
+ updateStrategy:
+ type: RollingUpdate
+kind: ConfigMap
+metadata:
+ name: ${CLUSTER_NAME}-cpi-manifests
+ namespace: ${NAMESPACE}
+
+
+
+
+---
+apiVersion: addons.cluster.x-k8s.io/v1beta1
+kind: ClusterResourceSet
+metadata:
+ name: ${CLUSTER_NAME}-calico-module-resource
+ namespace: ${NAMESPACE}
+spec:
+ clusterSelector:
+ matchLabels:
+ cluster.x-k8s.io/cluster-name: ${CLUSTER_NAME}
+ resources:
+ - kind: ConfigMap
+ name: ${CLUSTER_NAME}-calico-module-cr
+ strategy: Reconcile
+---
+apiVersion: v1
+data:
+ calico.yaml: |
+ apiVersion: platform.verrazzano.io/v1alpha1
+ kind: Module
+ metadata:
+ name: calico
+ namespace: default
+ spec:
+ moduleName: calico
+ targetNamespace: default
+ values:
+ tigeraOperator:
+ version: ${TIGERA_TAG=v1.29.0}
+ installation:
+ cni:
+ type: Calico
+ calicoNetwork:
+ bgp: Disabled
+ ipPools:
+ - cidr: ${POD_CIDR=192.168.0.0/16}
+ encapsulation: VXLAN
+ registry: ${OCNE_IMAGE_REPOSITORY=container-registry.oracle.com}
+ imagePath: ${OCNE_IMAGE_PATH=olcne}
+kind: ConfigMap
+metadata:
+ annotations:
+ note: generated
+ labels:
+ type: generated
+ name: ${CLUSTER_NAME}-calico-module-cr
+ namespace: ${NAMESPACE}
+
Generate and apply the template by running the following command: + + +
$ clusterctl generate yaml --from vsphere-capi.yaml | kubectl apply -f -
+
To get the kubeconfig
file, run:
+
+
+
$ clusterctl get kubeconfig kluster1 -n kluster1 > kluster1
+
After the cluster resources are created, you must perform some additional steps to finish the configuration of the cluster.
+If vSphere does not have a load balancer, then you can deploy MetalLB. + + +
$ export KUBECONFIG=kluster1
+
+ADDRESS_RANGE=${1:-"subnet-from-vSphere-network"};
+
+$ kubectl apply -f https://raw.githubusercontent.com/metallb/metallb/v0.13.7/config/manifests/metallb-native.yaml --wait=true;
+$ kubectl rollout status deployment -n metallb-system controller -w;
+$ kubectl apply -f - <<EOF1
+ apiVersion: metallb.io/v1beta1
+ kind: IPAddressPool
+ metadata:
+ name: vzlocalpool
+ namespace: metallb-system
+ spec:
+ addresses:
+ - ${ADDRESS_RANGE}
+EOF1
+
+$ kubectl apply -f - <<-EOF2
+ apiVersion: metallb.io/v1beta1
+ kind: L2Advertisement
+ metadata:
+ name: vzmetallb
+ namespace: metallb-system
+ spec:
+ ipAddressPools:
+ - vzlocalpool
+EOF2
+
+$ sleep 10;
+$ kubectl wait --namespace metallb-system --for=condition=ready pod --all --timeout=300s
+
Create a default storage class on the cluster. + + +
$ export KUBECONFIG=kluster1
+$ kubectl apply -f - <<-EOF
+ kind: StorageClass
+ apiVersion: storage.k8s.io/v1
+ metadata:
+ name: vmware-sc
+ annotations:
+ storageclass.kubernetes.io/is-default-class: "true"
+ provisioner: csi.vsphere.vmware.com
+ volumeBindingMode: WaitForFirstConsumer
+EOF
+
Install Verrazzano on the managed cluster. + + +
$ export KUBECONFIG=kluster1
+
+$ vz install -f - <<EOF
+ apiVersion: install.verrazzano.io/v1beta1
+ kind: Verrazzano
+ metadata:
+ name: example-verrazzano
+ spec:
+ profile: dev
+ defaultVolumeSource:
+ persistentVolumeClaim:
+ claimName: verrazzano-storage
+ volumeClaimSpecTemplates:
+ - metadata:
+ name: verrazzano-storage
+ spec:
+ resources:
+ requests:
+ storage: 2Gi
+EOF
+
Your admin cluster and first managed cluster are now up and running and ready to deploy applications. You can also add more managed clusters.
+For more information, refer to the documentation for Cluster API and Cluster API vSphere:
+ +If the deployment of the vSphere resources fails, then you can check the log files to diagnose the issue.
+The vSphere cluster controller provider logs: + + +
$ kubectl logs -n verrazzano-capi -l cluster.x-k8s.io/provider=infrastructure-vsphere
+
The OCNE control plane provider logs: + + +
$ kubectl logs -n verrazzano-capi -l cluster.x-k8s.io/provider=control-plane-ocne
+
NOTE: If the CSI pod deploys before Calico, then the pod may enter a CrashLoop
state. Restart the pod to fix the issue.
$ kubectl --kubeconfig kluster1 scale deploy -n kube-system vsphere-csi-controller --replicas=0
+$ kubectl --kubeconfig kluster1 scale deploy -n kube-system vsphere-csi-controller --replicas=1
+
$ kubectl delete cluster $CLUSTER_NAME
+
$ kind delete cluster
+
Do not use kubectl delete -f capi-quickstart.yaml
to delete the entire cluster template at once because it might leave behind pending resources that you need to clean up manually.
Was this page helpful?
+ + ++ Glad to hear it! Please tell us how we can improve. +
++ Sorry to hear that. Please tell us how we can improve. +
+Verrazzano and Cluster API use slightly different terminology for the same concepts:
+Next, a CAPI infrastructure provider will provision the first instance on the cloud provider and generate a provider ID, a unique identifier that any future nodes and clusters will use to associate with the instance. It will also create a kubeconfig file. The first control plane node is ready after these are created.
After the admin cluster is up and running, you can use the clusterAPI component to create additional managed clusters.
+ +clusterctl
, to manage the lifecycle operations of a cluster API admin cluster. Do not use clusterctl
to manage any OCNE or OKE clusters on OCI that you created in the console. You will create conflicts between changes made in the console and changes made with clusterctl
.
+
+