Changes for page Rancher 2
Last modified by Diana Strebkova on 2025/12/12 14:23
From version 8.1
edited by Diana Strebkova
on 2025/12/08 15:42
on 2025/12/08 15:42
Change comment:
There is no comment for this version
To version 10.13
edited by Diana Strebkova
on 2025/12/12 12:06
on 2025/12/12 12:06
Change comment:
There is no comment for this version
Summary
-
Page properties (1 modified, 0 added, 0 removed)
Details
- Page properties
-
- Content
-
... ... @@ -159,7 +159,7 @@ 159 159 == Add public helm chart == 160 160 161 161 {{warning width="70" title="Chartmuseum Deprecation"}} 162 -Chartmuseum is deprecated in new Harbor versions, we are migrating all helm charts to oci-compatible repositories in Harbor !New approach to add chart repositories in rancher.162 +Chartmuseum is deprecated in new Harbor versions, we are migrating all helm charts to oci-compatible repositories in Harbor with "PKEY-helm" naming convention. For internal harbor repos, use new approach to add OCI chart repositories in rancher. 163 163 {{/warning}} 164 164 165 165 In this section, we describe (% style="color:#172b4d" %)how to add public helm charts like the one of DevOps-as-a-Service to a cluster to allow manual deployments. ... ... @@ -220,7 +220,7 @@ 220 220 221 221 ==== Target: OCI Repository ==== 222 222 223 -To add public oci-repository, navigate to repository create button and click it. 223 +To add public oci-repository, navigate to repository create button and click it. For target, use OCI Repository like shown below: 224 224 225 225 [[image:1765207154466-828.png||height="298" width="821"]] 226 226 ... ... @@ -245,13 +245,17 @@ 245 245 |=((( 246 246 Index URL 247 247 )))|((( 248 -oci: [[~~/~~/registry.sdc.t-systems.net/chartrepo/devopsaas-helm/>>url:https://registry.sdc.t-systems.net/chartrepo/devopsaas/||shape="rect"]]chartname,for example:248 +oci:~/~/registry.sdc.t-systems.net/devopsaas-helm/**<chartname>**, for example: 249 249 250 -oci:[[~~/~~/registry.sdc.t-systems.net/>>url:https://registry.sdc.t-systems.net/chartrepo/devopsaas/||shape="rect"]][[devopsaas-helm/jenkins-lib>>url:https://registry-manoni.devops.t-systems.net/harbor/projects/139/repositories/jenkins-lib]] 250 +oci:~/~/registry.sdc.t-systems.net/devopsaas-helm/jenkins-lib 251 + 252 +{{info}} 253 +Take into account, that all internal harbor repositories with helm charts have PKEY-helm naming convention, adding repo with both docker images and helm charts may not be supported in rancher. 254 +{{/info}} 251 251 ))) 252 252 253 253 {{info}} 254 -Now all internal helm charts are stored in harbor folders with -helm suffix. Adding the whole public project doesn't work natively anymore, so each separate chart should be added as a separate repo. 258 +Now all internal helm charts are stored in harbor folders with -helm suffix. Adding the whole public project doesn't work natively anymore, so each separate chart should be added as a separate repo. //**If you have a need in adding the whole project with many repositories, please contact support for finding a possible solution.**// 255 255 {{/info}} 256 256 257 257 === Deploy Helm charts === ... ... @@ -264,7 +264,6 @@ 264 264 265 265 == Add private chart repository == 266 266 267 - 268 268 === Create a robot account in Harbor === 269 269 270 270 To add project specific helm charts to Rancher, a Harbor robot account is needed, that is able to read helm charts and pull repositories. If you don't have such an account yet, please follow the instructions given in the [[Create Robot Account section of the Harbor documentation>>doc:Harbor.Harbor 2\.7 Robot Accounts.WebHome||anchor="create_robot_account"]] and make sure to grant at least the following permissions: ... ... @@ -277,6 +277,9 @@ 277 277 278 278 (% class="p1" %) 279 279 In Rancher UI, switch to the intended cluster and go to Apps/Repositories using the left side menu. 283 + 284 +(% class="p1" %) 285 + 280 280 [[image:attach:Screenshot 2023-04-25 at 13.11.48.png||data-xwiki-image-style-border="true" queryparams="effects=drop-shadow" height="400" width="209"]] 281 281 282 282 (% class="p1" %) ... ... @@ -285,12 +285,11 @@ 285 285 (% id="HTarget:http28s29URL-1" class="p1" %) 286 286 ==== [[image:attach:Screenshot 2023-04-25 at 13.30.33.png||data-xwiki-image-style-border="true" queryparams="effects=drop-shadow" height="127" width="1100"]] ==== 287 287 288 -(% class="p1" %) 289 -==== 290 -Target: http(s) URL ==== 294 +(% id="HTarget:http28s29URL-1" class="p1" %) 295 +==== Target: http(s) URL ==== 291 291 292 292 {{warning title="Chartmuseum Deprecation"}} 293 -Chartmuseum in Harbor is deprecated, meaning we won't be able to add repositories to Rancher that way anymore. Instead use Target: OCI repository. 298 +Chartmuseum in Harbor is deprecated, meaning we won't be able to add internal harbor repositories to Rancher that way anymore. Instead use Target: OCI repository. 294 294 {{/warning}} 295 295 296 296 (% class="p1" %) ... ... @@ -307,17 +307,20 @@ 307 307 (% class="p1" %) 308 308 Click Create. 309 309 315 +(% id="HTarget:OCIRepository-1" class="p1" %) 310 310 ==== Target: OCI Repository ==== 311 311 312 312 {{info}} 313 -Now all internal helm charts are stored in harbor folders with -helm suffix. Adding the whole public project doesn't work natively anymore, so each separate chart should be added as a separate repo. 319 +Now all internal helm charts are stored in harbor folders with -helm suffix. Adding the whole public project doesn't work natively anymore, so each separate chart should be added as a separate repo.//** If you have a real need to add the whole project, please contact support for finding a possible solution.**// 314 314 {{/info}} 315 315 316 316 (% class="p1" %) 317 -Choose OCI repository in Target and for url, use ##oci:~/~/registry-<domain>.devops.t-systems.net/<project>-helm/<chatname>## 323 +Choose OCI repository in Target and for url, use ##oci:~/~/registry-<domain>.devops.t-systems.net/<project>-helm/<chartname>## 318 318 319 -(% class="p1" %) 320 -Replace ##<domain>## , ##<project>## and ##<chatname> ##as necessary to match your set-up. 325 +(% class="box" %) 326 +((( 327 +Replace ##<domain>## , ##<project>## and ##<chartname> ##as necessary to match your set-up. Your charts should be stored in ##<project>-helm ##repository in Harbor, which is created by default when project is created in portal. 328 +))) 321 321 322 322 (% class="p1" %) 323 323 For Authentication, select "Create a HTTP Basic Auth Secret" and provide the Username and Password of the Harbor robot account from the previous section. ... ... @@ -328,6 +328,37 @@ 328 328 (% class="wikigeneratedid" %) 329 329 Click Create. 330 330 339 + 340 +(% class="wrapped" %) 341 +|=((( 342 +Field 343 +)))|=((( 344 +Value 345 +))) 346 +|=((( 347 +Name 348 +)))|((( 349 +sdcloud-sdportal 350 +))) 351 +|=((( 352 +Description 353 +)))|((( 354 +Sdportal charts of sdcloud project 355 +))) 356 +|=((( 357 +Index URL 358 +)))|((( 359 +oci:~/~/registry.sdc.t-systems.net/sdcloud-helm/sdportal 360 + 361 +{{info}} 362 +Now we should target a chart repo directly, not the whole project. In you need to reference the whole project with a lot of repos, please contact support to find a possible solution. 363 +{{/info}} 364 +))) 365 + 366 +=== Migrating chart repositories in rancher to new OCI Repository format === 367 + 368 +As chartmuseum is getting deprecated, after the full migration the charts will be deleted from chartmuseum and old repositories won't be working in rancher anymore. For smooth migration, we recommend adding an OCI Repository along with the olf http(s) based one during migration process, as we will make the charts available in the new <pkey>-helm projects for you. If you deployed the apps using the previous chart repo, the app contains chart repo name in its labels, so transition process need few steps. First, create <chart-repo-name> OCI repo in rancher. Then disable the old repo for some time in your repositories. After that, go the the application which was deployed using the chart from older repo anf click upgrade, there you will see all available chart repository in your cluster. Scroöö till the end till you find the new repo, choose the chart with the same or different version, and click update. Now you app is connected to new oci repositories and will show upgrade sign when a new version is available. Enable the old repo if you still use it. After this process, even if a new version for the app is availalbe in old repository, you won't see it as its not connected to it anymore. To change it, repeat the previous procees in revet. 369 + 331 331 = Automated deployments with Jenkins = 332 332 333 333 In this section, we describe(% style="color:#172b4d" %) how to set-up **automated builds, tests and deployments** for Jenkins.