Changes for page Rancher 2
Last modified by Diana Strebkova on 2026/04/20 09:21
From version 1.5
edited by Diana Strebkova
on 2025/12/08 15:09
on 2025/12/08 15:09
Change comment:
There is no comment for this version
To version 28.1
edited by Diana Strebkova
on 2026/04/20 09:21
on 2026/04/20 09:21
Change comment:
There is no comment for this version
Summary
-
Page properties (1 modified, 0 added, 0 removed)
-
Attachments (0 modified, 7 added, 0 removed)
Details
- Page properties
-
- Content
-
... ... @@ -158,10 +158,6 @@ 158 158 159 159 == Add public helm chart == 160 160 161 -{{warning width="70" title="Chartmuseum Deprecation"}} 162 -Chartmuseum is deprecated in new Harbor versions, we are migrating all helm charts to oci-compatible repositories in Harbor! New approach to add chart repositories in rancher. 163 -{{/warning}} 164 - 165 165 In this section, we describe (% style="color:#172b4d" %)how to add public helm charts like the one of DevOps-as-a-Service to a cluster to allow manual deployments. 166 166 167 167 (% id="HCreateAppRepositoryinRancher" class="p1" %) ... ... @@ -177,10 +177,10 @@ 177 177 (% class="p1" %) 178 178 [[image:attach:Screenshot 2023-04-25 at 13.30.33.png||data-xwiki-image-style-border="true" queryparams="effects=drop-shadow" height="127" width="1100"]] 179 179 180 -(% class="p1" %) 181 -==== Target: htt ==== 176 +To add public oci-repository, navigate to repository create button and click it. For target, use OCI Repository like shown below: 182 182 183 -(% class="p1" %) 178 +[[image:1765207154466-828.png||height="298" width="821"]] 179 + 184 184 In the "Repository: Create" dialog, simply fill in the following fields. Authentication is not required. 185 185 186 186 (% class="wrapped" %) ... ... @@ -192,7 +192,7 @@ 192 192 |=((( 193 193 Name 194 194 )))|((( 195 -devops -as-a-service191 +devopsaas-jenkins-auto-agent 196 196 ))) 197 197 |=((( 198 198 Description ... ... @@ -202,18 +202,19 @@ 202 202 |=((( 203 203 Index URL 204 204 )))|((( 205 -[[https:~~/~~/registry.sdc.t-systems.net/chartrepo/devopsaas/>>url:https://registry.sdc.t-systems.net/chartrepo/devopsaas/||shape="rect"]] 206 -))) 201 +oci:~/~/registry.sdc.t-systems.net/devopsaas-helm/**<chartname>**, for example: 207 207 208 - [[image:attach:image-2024-2-27_14-29-17.png||data-xwiki-image-style-border="true" queryparams="effects=drop-shadow" width="540"]]203 +oci:~/~/registry.sdc.t-systems.net/devopsaas-helm/jenkins-auto-agent 209 209 210 -(% class="p1" %) 211 -Finally, click Create. 205 +{{box}} 206 +Take into account, that all internal harbor repositories with helm charts have PKEY-helm naming convention, adding repo with both docker images and helm charts is not supported in rancher. 207 +{{/box}} 208 +))) 212 212 213 -The repository is now listed: 210 +{{info}} 211 +Now all internal helm charts are stored in harbor folders with -helm suffix. Adding the whole public project doesn't work natively anymore, so each separate chart should be added as a separate repo. //**If you have a need in adding the whole project with many repositories, please contact support for finding a possible solution.**// 212 +{{/info}} 214 214 215 -[[image:Screenshot 2024-07-03 at 15.13.55.png||data-xwiki-image-style-border="true" height="149" width="785"]] 216 - 217 217 === Deploy Helm charts === 218 218 219 219 Now go to Apps>Charts and filter if necessary for the devops-as-a-service Helm chart repository. Like shown below, a list of available charts is displayed. Simply click on one of the tiles to deploy them to your cluster. ... ... @@ -224,12 +224,11 @@ 224 224 225 225 == Add private chart repository == 226 226 227 - 228 228 === Create a robot account in Harbor === 229 229 230 230 To add project specific helm charts to Rancher, a Harbor robot account is needed, that is able to read helm charts and pull repositories. If you don't have such an account yet, please follow the instructions given in the [[Create Robot Account section of the Harbor documentation>>doc:Harbor.Harbor 2\.7 Robot Accounts.WebHome||anchor="create_robot_account"]] and make sure to grant at least the following permissions: 231 231 232 -* Read Helm Chart228 +* Read Artifact 233 233 * Pull Repository 234 234 235 235 (% id="HCreateAppRepositoryinRancher-1" class="p1" %) ... ... @@ -237,27 +237,144 @@ 237 237 238 238 (% class="p1" %) 239 239 In Rancher UI, switch to the intended cluster and go to Apps/Repositories using the left side menu. 236 + 240 240 [[image:attach:Screenshot 2023-04-25 at 13.11.48.png||data-xwiki-image-style-border="true" queryparams="effects=drop-shadow" height="400" width="209"]] 241 241 242 242 (% class="p1" %) 243 243 Create a new Repository by pressing the Create button. 244 244 245 -(% class="p1" %) 242 +(% class="p1" id="HTarget:http28s29URL-1" %) 246 246 [[image:attach:Screenshot 2023-04-25 at 13.30.33.png||data-xwiki-image-style-border="true" queryparams="effects=drop-shadow" height="127" width="1100"]] 247 -\\A name for the Repository has to be set. In the screenshot, the project name CITEST is used, which corresponds to our example from above. 248 -Choose http(s) URL to an index generated by Helm and provide the Index URL ##https:~/~/registry-<domain>.devops.t-systems.net/chartrepo/<project>/## 249 249 245 +(% id="HTarget:http28s29URL-1" class="p1" %) 246 + 247 +{{info}} 248 +Now all internal helm charts are stored in harbor folders with -helm suffix. Adding the whole public project doesn't work natively anymore, so each separate chart should be added as a separate repo.//** If you have a real need to add the whole project, please contact support for finding a possible solution.**// 249 +{{/info}} 250 + 250 250 (% class="p1" %) 251 - Replace ##<domain>## and##<project>## as necessaryto match your set-up.252 +Choose OCI repository in Target and for url, use ##oci:~/~/registry-<domain>.devops.t-systems.net/<project>-helm/<chartname>## 252 252 254 +(% class="box" %) 255 +((( 256 +Replace ##<domain>## , ##<project>## and ##<chartname> ##as necessary to match your set-up. Your charts should be stored in ##<project>-helm ##repository in Harbor, which is created by default when project is created in portal. 257 +))) 258 + 253 253 (% class="p1" %) 254 254 For Authentication, select "Create a HTTP Basic Auth Secret" and provide the Username and Password of the Harbor robot account from the previous section. 255 -[[image:attach:Screenshot 2023-04-26 at 18.10.15.png||data-xwiki-image-style-border="true" queryparams="effects=drop-shadow" height="468" width="1100"]] 256 256 257 -(% class="p1" %) 262 +(% class="wikigeneratedid" %) 263 +[[image:1765208347952-345.36.18.png||height="449" width="849"]] 264 + 265 +(% class="wikigeneratedid" %) 258 258 Click Create. 259 259 268 +(% class="wrapped" %) 269 +|=((( 270 +Field 271 +)))|=((( 272 +Value 273 +))) 274 +|=((( 275 +Name 276 +)))|((( 277 +sdcloud-sdportal 278 +))) 279 +|=((( 280 +Description 281 +)))|((( 282 +Sdportal charts of sdcloud project 283 +))) 284 +|=((( 285 +Index URL 286 +)))|((( 287 +oci:~/~/registry.sdc.t-systems.net/sdcloud-helm/sdportal 260 260 289 +{{info}} 290 +Now we should target a chart repo directly, not the whole project. In you need to reference the whole project with a lot of repos, please contact support to find a possible solution. 291 +{{/info}} 292 +))) 293 + 294 +== Migrating chart repositories in rancher to new OCI Repository format == 295 + 296 +(% class="box warningmessage" %) 297 +((( 298 +ChartMuseum is deprecated. **All harbor charts are removed from ChartMuseum**, and **old HTTP(S)-based chart repositories no longer work in Rancher (for internal harbor charts)**. 299 +))) 300 + 301 +(% class="box" %) 302 +((( 303 +**All your charts are available in the corresponding `<pkey>-helm` OCI project.** 304 +))) 305 + 306 +There are two ways to migrate your repositories: 307 + 308 +1. ##Direct Transition (Editing the Existing Repository)## 309 +1*. Change the target to “OCI Repository”. 310 +1*. Update the URL as required (the repository name cannot be changed) and add a new robot account for helm project, check documentation above 311 +1*. After saving, installed apps will automatically start using the updated repository. 312 +1*. (% class="box" %) 313 +((( 314 +Important limitation: OCI repositories must point directly to a single chart repository, not to a parent folder. 315 +If your old repository included several charts (for example “bitbucket” and “jira”), then after switching to OCI you can only target one chart (e.g. “bitbucket”). 316 +The other charts will no longer receive updates through this repo, and you will still need to create additional repositories for each individual chart. 317 +))) 318 +1. Add New Repositories One by One (Recommended), preserve the old one till the end. This approach allows a smooth transition while the old ChartMuseum repository continues to function. You can: 319 +1*. Create a new OCI repository for each chart, 320 +1*. Keep the old ChartMuseum repo enabled during the migration, 321 +1*. Migrate applications gradually following the steps described here. 322 +1*. This avoids disruptions and allows controlled migration. 323 + 324 +1. //Special Case: Old Repo Targeting Multiple Chart Repos// 325 +If your existing repository targets multiple chart repositories and you need the new OCI setup to behave the same way, please **contact support.** 326 + 327 +| Term | Meaning 328 +| **Old Repository** | The existing HTTP/HTTPS Harbor ChartMuseum repository. 329 +| **New Repository** | The new OCI-based Helm chart repository created for your project (e.g. `<chart-repo-name>` in `<pkey>-helm`). 330 + 331 +##__**Why This Migration Is Required:**__## 332 + 333 +* ##ChartMuseum is deprecated.## 334 +* ##Applications deployed from old repos keep a reference to that repo inside their labels.## 335 +* ##Without updating the application to point to the new OCI repo, **Rancher will not detect new chart versions from new repository**.## 336 + 337 +## Migration Steps:## 338 + 339 +1. ##Create the New OCI Repository in Rancher## 340 +11. Go to **Apps → Repositories**. 341 +11. Add a new repository of type **OCI**. 342 +11. Name it similarly to your old repo name (e.g. `<chart-repo-name>-oci`). __**You can't name it the same and can't rename it later.**__ 343 +11. Point it to the new OCI endpoint. 344 +1. ##Disable the Old ChartMuseum Repository Temporarily## 345 +##This step ensures that Rancher resolves charts from the new OCI repo.## 346 +11. Go to **Apps → Repositories**. 347 +11. Disable the old HTTP(S)-based repository. 348 +11. Keep it disabled until the migration is done. 349 +[[image:1765548124989-482.59.06.png||height="152" width="485"]] 350 +1. ##Update Existing Applications to Use the New OCI Repo## 351 +Applications deployed with the old repository still contain the old repo name in their metadata. You must upgrade them once to transition. 352 +11. Go to **Apps → Installed Apps**. 353 +11. Open the application that was deployed using the old repo. 354 +11. Click **Edit/Upgrade**. 355 +[[image:1765548598644-830.png||height="138" width="811"]] 356 +11. In the list of available chart repositories (scroll to the bottom), select the **new OCI repository**. Or enter the chart name in search bar: 357 +[[image:1765548750604-334.png||height="293" width="308"]] 358 +11. Choose the chart version you want to deploy (same or newer). 359 +11. Click **Upgrade**. 360 +1. ##Re-enable the Old Repository (Optional) ## 361 +If you still need the old repo for other apps, re-enable it after the migration steps above. 362 +**Note:** Even if a newer chart version exists in the old repository, your migrated app **will not see it**, because it is no longer connected to that repo 363 + 364 +##If you want to move an app back to the old repository:## 365 + 366 +1. Temporarily disable the new OCI repo. 367 +1. Enable the old ChartMuseum repo. 368 +1. Open the application → **Upgrade**. 369 +1. Select the chart from the old repo. 370 +1. Save. 371 + 372 +This will reconnect the app to the old repository. 373 + 261 261 = Automated deployments with Jenkins = 262 262 263 263 In this section, we describe(% style="color:#172b4d" %) how to set-up **automated builds, tests and deployments** for Jenkins.
- 1765206888644-487.png
-
- Author
-
... ... @@ -1,0 +1,1 @@ 1 +xwiki:XWiki.dianastrebkovat-systemscom - Size
-
... ... @@ -1,0 +1,1 @@ 1 +142.4 KB - Content
- 1765207032873-684.png
-
- Author
-
... ... @@ -1,0 +1,1 @@ 1 +xwiki:XWiki.dianastrebkovat-systemscom - Size
-
... ... @@ -1,0 +1,1 @@ 1 +142.1 KB - Content
- 1765207154466-828.png
-
- Author
-
... ... @@ -1,0 +1,1 @@ 1 +xwiki:XWiki.dianastrebkovat-systemscom - Size
-
... ... @@ -1,0 +1,1 @@ 1 +143.6 KB - Content
- 1765208347952-345.36.18.png
-
- Author
-
... ... @@ -1,0 +1,1 @@ 1 +xwiki:XWiki.dianastrebkovat-systemscom - Size
-
... ... @@ -1,0 +1,1 @@ 1 +199.3 KB - Content
- 1765548124989-482.59.06.png
-
- Author
-
... ... @@ -1,0 +1,1 @@ 1 +xwiki:XWiki.dianastrebkovat-systemscom - Size
-
... ... @@ -1,0 +1,1 @@ 1 +64.4 KB - Content
- 1765548598644-830.png
-
- Author
-
... ... @@ -1,0 +1,1 @@ 1 +xwiki:XWiki.dianastrebkovat-systemscom - Size
-
... ... @@ -1,0 +1,1 @@ 1 +153.4 KB - Content
- 1765548750604-334.png
-
- Author
-
... ... @@ -1,0 +1,1 @@ 1 +xwiki:XWiki.dianastrebkovat-systemscom - Size
-
... ... @@ -1,0 +1,1 @@ 1 +103.0 KB - Content