Changes for page Rancher 2

Last modified by Diana Strebkova on 2025/12/12 14:23

From version 10.5
edited by Diana Strebkova
on 2025/12/12 11:47
Change comment: There is no comment for this version
To version 14.3
edited by Diana Strebkova
on 2025/12/12 13:37
Change comment: There is no comment for this version

Summary

Details

Page properties
Content
... ... @@ -255,7 +255,7 @@
255 255  )))
256 256  
257 257  {{info}}
258 -Now all internal helm charts are stored in harbor folders with -helm suffix. Adding the whole public project doesn't work natively anymore, so each separate chart should be added as a separate repo. If you have a need in adding the w
258 +Now all internal helm charts are stored in harbor folders with -helm suffix. Adding the whole public project doesn't work natively anymore, so each separate chart should be added as a separate repo. //**If you have a need in adding the whole project with many repositories, please contact support for finding a possible solution.**//
259 259  {{/info}}
260 260  
261 261  === Deploy Helm charts ===
... ... @@ -268,7 +268,6 @@
268 268  
269 269  == Add private chart repository ==
270 270  
271 -
272 272  === Create a robot account in Harbor ===
273 273  
274 274  To add project specific helm charts to Rancher, a Harbor robot account is needed, that is able to read helm charts and pull repositories. If you don't have such an account yet, please follow the instructions given in the [[Create Robot Account section of the Harbor documentation>>doc:Harbor.Harbor 2\.7 Robot Accounts.WebHome||anchor="create_robot_account"]] and make sure to grant at least the following permissions:
... ... @@ -281,6 +281,8 @@
281 281  
282 282  (% class="p1" %)
283 283  In Rancher UI, switch to the intended cluster and go to Apps/Repositories using the left side menu.
283 +
284 +
284 284  [[image:attach:Screenshot 2023-04-25 at 13.11.48.png||data-xwiki-image-style-border="true" queryparams="effects=drop-shadow" height="400" width="209"]]
285 285  
286 286  (% class="p1" %)
... ... @@ -293,7 +293,7 @@
293 293  ==== Target: http(s) URL ====
294 294  
295 295  {{warning title="Chartmuseum Deprecation"}}
296 -Chartmuseum in Harbor is deprecated, meaning we won't be able to add repositories to Rancher that way anymore. Instead use Target: OCI repository.
297 +Chartmuseum in Harbor is deprecated, meaning we won't be able to add internal harbor repositories to Rancher that way anymore. Instead use Target: OCI repository.
297 297  {{/warning}}
298 298  
299 299  (% class="p1" %)
... ... @@ -314,14 +314,16 @@
314 314  ==== Target: OCI Repository ====
315 315  
316 316  {{info}}
317 -Now all internal helm charts are stored in harbor folders with -helm suffix. Adding the whole public project doesn't work natively anymore, so each separate chart should be added as a separate repo.
318 +Now all internal helm charts are stored in harbor folders with -helm suffix. Adding the whole public project doesn't work natively anymore, so each separate chart should be added as a separate repo.//** If you have a real need to add the whole project, please contact support for finding a possible solution.**//
318 318  {{/info}}
319 319  
320 320  (% class="p1" %)
321 -Choose OCI repository in Target and for url, use  ##oci:~/~/registry-<domain>.devops.t-systems.net/<project>-helm/<chatname>##
322 +Choose OCI repository in Target and for url, use  ##oci:~/~/registry-<domain>.devops.t-systems.net/<project>-helm/<chartname>##
322 322  
323 -(% class="p1" %)
324 -Replace ##<domain>## , ##<project>##  and ##<chatname> ##as necessary to match your set-up.
324 +(% class="box" %)
325 +(((
326 +Replace ##<domain>## , ##<project>##  and ##<chartname> ##as necessary to match your set-up. Your charts should be stored in ##<project>-helm ##repository in Harbor, which is created by default when project is created in portal.
327 +)))
325 325  
326 326  (% class="p1" %)
327 327  For Authentication, select "Create a HTTP Basic Auth Secret" and provide the Username and Password of the Harbor robot account from the previous section.
... ... @@ -332,8 +332,121 @@
332 332  (% class="wikigeneratedid" %)
333 333  Click Create.
334 334  
335 -= Automated deployments with Jenkins =
338 +(% class="wrapped" %)
339 +|=(((
340 +Field
341 +)))|=(((
342 +Value
343 +)))
344 +|=(((
345 +Name
346 +)))|(((
347 +sdcloud-sdportal
348 +)))
349 +|=(((
350 +Description
351 +)))|(((
352 +Sdportal charts of sdcloud project
353 +)))
354 +|=(((
355 +Index URL
356 +)))|(((
357 +oci:~/~/registry.sdc.t-systems.net/sdcloud-helm/sdportal
336 336  
359 +{{info}}
360 +Now we should target a chart repo directly, not the whole project. In you need to reference the whole project with a lot of repos, please contact support to find a possible solution.
361 +{{/info}}
362 +)))
363 +
364 +=== Migrating chart repositories in rancher to new OCI Repository format ===
365 +
366 +(% class="box warningmessage" %)
367 +(((
368 +ChartMuseum is being deprecated. After the migration is complete, **all harbor charts will be removed from ChartMuseum**, and **old HTTP(S)-based chart repositories will no longer work in Rancher (for internal harbor charts)**.
369 +)))
370 +
371 +There are two ways to migrate your repositories:
372 +
373 +1. ##Direct Transition (Editing the Existing Repository)##
374 +1*. Change the target to “OCI Repository”.
375 +1*. Update the URL as required (the repository name cannot be changed).
376 +1*. After saving, installed apps will automatically start using the updated repository.
377 +1*. (% class="box" %)
378 +(((
379 +Important limitation: OCI repositories must point directly to a single chart repository, not to a parent folder.
380 +If your old repository included several charts (for example “bitbucket” and “jira”), then after switching to OCI you can only target one chart (e.g. “bitbucket”).
381 +The other charts will no longer receive updates through this repo, and you will still need to create additional repositories for each individual chart.
382 +)))
383 +1. Add New Repositories One by One (Recommended), prese
384 +This approach allows a smooth transition while the old ChartMuseum repository continues to function. You can:
385 +
386 +* Create a new OCI repository for each chart,
387 +* Keep the old ChartMuseum repo enabled during the migration,
388 +* Migrate applications gradually following the steps described in the main migration guide.
389 +
390 +This avoids disruptions and allows controlled migration.
391 +
392 +Special Case: Old Repo Targeting Multiple Chart Repos
393 +
394 +If your existing repository targets multiple chart repositories and you need the new OCI setup to behave the same way, please contact support. OCI does not support multi-chart endpoints within a single repository, and we can help you find an appropriate solution.
395 +
396 +To ensure a smooth transition, we recommend to **add an OCI-based repository alongside the existing ChartMuseum repository** during the migration phase. If you don't w
397 +
398 +(% class="box" %)
399 +(((
400 +**We will make your charts available in the corresponding new `<pkey>-helm` OCI projects.**
401 +)))
402 +
403 +| Term | Meaning
404 +| **Old Repository** | The existing HTTP/HTTPS Harbor ChartMuseum repository.
405 +| **New Repository** | The new OCI-based Helm chart repository created for your project (e.g. `<chart-repo-name>` in `<pkey>-helm`).
406 +
407 +##__**Why This Migration Is Required:**__##
408 +
409 +* ##ChartMuseum is deprecated and will be removed.##
410 +* ##Applications deployed from old repos keep a reference to that repo inside their labels.##
411 +* ##Without updating the application to point to the new OCI repo, **Rancher will not detect new chart versions from new repository**.##
412 +
413 +## Migration Steps:##
414 +
415 +1. ##Create the New OCI Repository in Rancher##
416 +11. Go to **Apps → Repositories**.
417 +11. Add a new repository of type **OCI**.
418 +11. Name it similarly to your old repo name (e.g. `<chart-repo-name>-oci`). You can't name it the same.
419 +11. Point it to the new OCI endpoint.
420 +1. ##Disable the Old ChartMuseum Repository Temporarily## 
421 +##This step ensures that Rancher resolves charts from the new OCI repo.##
422 +11. Go to **Apps → Repositories**.
423 +11. Disable the old HTTP(S)-based repository.
424 +11. Keep it disabled until the migration is done.
425 +1. ##Update Existing Applications to Use the New OCI Repo##
426 +Applications deployed with the old repository still contain the old repo name in their metadata. You must upgrade them once to transition.
427 +11. Go to **Apps → Installed Apps**.
428 +11. Open the application that was deployed using the old repo.
429 +11. Click **Upgrade**.
430 +11. In the list of available chart repositories (scroll to the bottom), select the **new OCI repository**.
431 +11. Choose the chart version you want to deploy (same or newer).
432 +11. Click **Upgrade**.
433 +1. ##Re-enable the Old Repository (Optional) ##
434 +If you still need the old repo for other apps, re-enable it after the migration steps above.
435 +**Note:** Even if a newer chart version exists in the old repository, your migrated app **will not see it**, because it is no longer connected to that repo
436 +
437 +----
438 +
439 +## Reverting the Migration (If Needed)
440 +If you want to move an app back to the old repository:##
441 +
442 +1. Temporarily disable the new OCI repo.
443 +1. Enable the old ChartMuseum repo.
444 +1. Open the application → **Upgrade**.
445 +1. Select the chart from the old repo.
446 +1. Save.
447 +
448 +This will reconnect the app to the old repository.
449 +
450 +=
451 +Automated deployments with Jenkins =
452 +
337 337  In this section, we describe(% style="color:#172b4d" %) how to set-up **automated builds, tests and deployments** for Jenkins.
338 338  
339 339  == Prerequisites ==