Changes for page Rancher 2

Last modified by Diana Strebkova on 2026/04/20 09:21

From version 8.1
edited by Diana Strebkova
on 2025/12/08 15:42
Change comment: There is no comment for this version
To version 24.4
edited by Diana Strebkova
on 2026/04/20 09:15
Change comment: There is no comment for this version

Summary

Details

Page properties
Content
... ... @@ -159,7 +159,7 @@
159 159  == Add public helm chart ==
160 160  
161 161  {{warning width="70" title="Chartmuseum Deprecation"}}
162 -Chartmuseum is deprecated in new Harbor versions, we are migrating all helm charts to oci-compatible repositories in Harbor! New approach to add chart repositories in rancher.
162 +Chartmuseum is deprecated in new Harbor versions, we are migrating all helm charts to oci-compatible repositories in Harbor with "PKEY-helm" naming convention. For internal harbor repos, use new approach to add OCI chart repositories in rancher.
163 163  {{/warning}}
164 164  
165 165  In this section, we describe (% style="color:#172b4d" %)how to add public helm charts like the one of DevOps-as-a-Service to a cluster to allow manual deployments.
... ... @@ -177,51 +177,8 @@
177 177  (% class="p1" %)
178 178  [[image:attach:Screenshot 2023-04-25 at 13.30.33.png||data-xwiki-image-style-border="true" queryparams="effects=drop-shadow" height="127" width="1100"]]
179 179  
180 -(% id="H" class="p1" %)
181 -==== Target: http(s) URL ====
180 +To add public oci-repository, navigate to repository create button and click it. For target, use OCI Repository like shown below:
182 182  
183 -{{warning}}
184 -This example is being deprecated, you can still add other external repositories in that way, but all internal harbor-hosted repositories should be added as Target: OCI Repository
185 -{{/warning}}
186 -
187 -(% class="p1" %)
188 -In the "Repository: Create" dialog, simply fill in the following fields. Authentication is not required.
189 -
190 -(% class="wrapped" %)
191 -|=(((
192 -Field
193 -)))|=(((
194 -Value
195 -)))
196 -|=(((
197 -Name
198 -)))|(((
199 -devops-as-a-service
200 -)))
201 -|=(((
202 -Description
203 -)))|(((
204 -Public Helm charts as documented at [[https:~~/~~/docs.devops.t-systems.net>>url:https://docs.devops.t-systems.net||shape="rect"]]
205 -)))
206 -|=(((
207 -Index URL
208 -)))|(((
209 -[[https:~~/~~/registry.sdc.t-systems.net/chartrepo/devopsaas/>>url:https://registry.sdc.t-systems.net/chartrepo/devopsaas/||shape="rect"]]
210 -)))
211 -
212 -[[image:attach:image-2024-2-27_14-29-17.png||data-xwiki-image-style-border="true" queryparams="effects=drop-shadow" width="540"]]
213 -
214 -(% class="p1" %)
215 -Finally, click Create.
216 -
217 -The repository is now listed:
218 -
219 -[[image:Screenshot 2024-07-03 at 15.13.55.png||data-xwiki-image-style-border="true" height="149" width="785"]]
220 -
221 -==== Target: OCI Repository ====
222 -
223 -To add public oci-repository, navigate to repository create button and click it.
224 -
225 225  [[image:1765207154466-828.png||height="298" width="821"]]
226 226  
227 227  In the "Repository: Create" dialog, simply fill in the following fields. Authentication is not required.
... ... @@ -245,13 +245,17 @@
245 245  |=(((
246 246  Index URL
247 247  )))|(((
248 -oci:[[~~/~~/registry.sdc.t-systems.net/chartrepo/devopsaas-helm/>>url:https://registry.sdc.t-systems.net/chartrepo/devopsaas/||shape="rect"]]chartname, for example:
205 +oci:~/~/registry.sdc.t-systems.net/devopsaas-helm/**<chartname>**, for example:
249 249  
250 -oci:[[~~/~~/registry.sdc.t-systems.net/>>url:https://registry.sdc.t-systems.net/chartrepo/devopsaas/||shape="rect"]][[devopsaas-helm/jenkins-lib>>url:https://registry-manoni.devops.t-systems.net/harbor/projects/139/repositories/jenkins-lib]]
207 +oci:~/~/registry.sdc.t-systems.net/devopsaas-helm/jenkins-auto-agent
208 +
209 +{{box}}
210 +Take into account, that all internal harbor repositories with helm charts have PKEY-helm naming convention, adding repo with both docker images and helm charts is not supported in rancher.
211 +{{/box}}
251 251  )))
252 252  
253 253  {{info}}
254 -Now all internal helm charts are stored in harbor folders with -helm suffix. Adding the whole public project doesn't work natively anymore, so each separate chart should be added as a separate repo.
215 +Now all internal helm charts are stored in harbor folders with -helm suffix. Adding the whole public project doesn't work natively anymore, so each separate chart should be added as a separate repo. //**If you have a need in adding the whole project with many repositories, please contact support for finding a possible solution.**//
255 255  {{/info}}
256 256  
257 257  === Deploy Helm charts ===
... ... @@ -264,12 +264,11 @@
264 264  
265 265  == Add private chart repository ==
266 266  
267 -
268 268  === Create a robot account in Harbor ===
269 269  
270 270  To add project specific helm charts to Rancher, a Harbor robot account is needed, that is able to read helm charts and pull repositories. If you don't have such an account yet, please follow the instructions given in the [[Create Robot Account section of the Harbor documentation>>doc:Harbor.Harbor 2\.7 Robot Accounts.WebHome||anchor="create_robot_account"]] and make sure to grant at least the following permissions:
271 271  
272 -* Read Helm Chart
232 +* Read Artifact
273 273  * Pull Repository
274 274  
275 275  (% id="HCreateAppRepositoryinRancher-1" class="p1" %)
... ... @@ -277,57 +277,147 @@
277 277  
278 278  (% class="p1" %)
279 279  In Rancher UI, switch to the intended cluster and go to Apps/Repositories using the left side menu.
240 +
280 280  [[image:attach:Screenshot 2023-04-25 at 13.11.48.png||data-xwiki-image-style-border="true" queryparams="effects=drop-shadow" height="400" width="209"]]
281 281  
282 282  (% class="p1" %)
283 283  Create a new Repository by pressing the Create button.
284 284  
246 +(% class="p1" id="HTarget:http28s29URL-1" %)
247 +[[image:attach:Screenshot 2023-04-25 at 13.30.33.png||data-xwiki-image-style-border="true" queryparams="effects=drop-shadow" height="127" width="1100"]]
248 +
285 285  (% id="HTarget:http28s29URL-1" class="p1" %)
286 -==== [[image:attach:Screenshot 2023-04-25 at 13.30.33.png||data-xwiki-image-style-border="true" queryparams="effects=drop-shadow" height="127" width="1100"]] ====
250 +==== ====
287 287  
288 -(% class="p1" %)
289 -====
290 -Target: http(s) URL ====
252 +{{info}}
253 +Now all internal helm charts are stored in harbor folders with -helm suffix. Adding the whole public project doesn't work natively anymore, so each separate chart should be added as a separate repo.//** If you have a real need to add the whole project, please contact support for finding a possible solution.**//
254 +{{/info}}
291 291  
292 -{{warning title="Chartmuseum Deprecation"}}
293 -Chartmuseum in Harbor is deprecated, meaning we won't be able to add repositories to Rancher that way anymore. Instead use Target: OCI repository.
294 -{{/warning}}
295 -
296 296  (% class="p1" %)
297 -A name for the Repository has to be set. In the screenshot, the project name CITEST is used, which corresponds to our example from above.
298 -Choose http(s) URL to an index generated by Helm and provide the Index URL ##https:~/~/registry-<domain>.devops.t-systems.net/chartrepo/<project>/##
257 +Choose OCI repository in Target and for url, use  ##oci:~/~/registry-<domain>.devops.t-systems.net/<project>-helm/<chartname>##
299 299  
300 -(% class="p1" %)
301 -Replace ##<domain>## and ##<project>## as necessary to match your set-up.
259 +(% class="box" %)
260 +(((
261 +Replace ##<domain>## , ##<project>##  and ##<chartname> ##as necessary to match your set-up. Your charts should be stored in ##<project>-helm ##repository in Harbor, which is created by default when project is created in portal.
262 +)))
302 302  
303 303  (% class="p1" %)
304 304  For Authentication, select "Create a HTTP Basic Auth Secret" and provide the Username and Password of the Harbor robot account from the previous section.
305 -[[image:attach:Screenshot 2023-04-26 at 18.10.15.png||data-xwiki-image-style-border="true" queryparams="effects=drop-shadow" height="468" width="1100"]]
306 306  
307 -(% class="p1" %)
267 +(% class="wikigeneratedid" %)
268 +[[image:1765208347952-345.36.18.png||height="449" width="849"]]
269 +
270 +(% class="wikigeneratedid" %)
308 308  Click Create.
309 309  
310 -==== Target: OCI Repository ====
273 +(% class="wrapped" %)
274 +|=(((
275 +Field
276 +)))|=(((
277 +Value
278 +)))
279 +|=(((
280 +Name
281 +)))|(((
282 +sdcloud-sdportal
283 +)))
284 +|=(((
285 +Description
286 +)))|(((
287 +Sdportal charts of sdcloud project
288 +)))
289 +|=(((
290 +Index URL
291 +)))|(((
292 +oci:~/~/registry.sdc.t-systems.net/sdcloud-helm/sdportal
311 311  
312 312  {{info}}
313 -Now all internal helm charts are stored in harbor folders with -helm suffix. Adding the whole public project doesn't work natively anymore, so each separate chart should be added as a separate repo.
295 +Now we should target a chart repo directly, not the whole project. In you need to reference the whole project with a lot of repos, please contact support to find a possible solution.
314 314  {{/info}}
297 +)))
315 315  
316 -(% class="p1" %)
317 -Choose OCI repository in Target and for url, use  ##oci:~/~/registry-<domain>.devops.t-systems.net/<project>-helm/<chatname>##
299 +== Migrating chart repositories in rancher to new OCI Repository format ==
318 318  
319 -(% class="p1" %)
320 -Replace ##<domain>## , ##<project>##  and ##<chatname> ##as necessary to match your set-up.
301 +(% class="box warningmessage" %)
302 +(((
303 +ChartMuseum is being deprecated. After the migration is complete, **all harbor charts will be removed from ChartMuseum**, and **old HTTP(S)-based chart repositories will no longer work in Rancher (for internal harbor charts)**.
304 +)))
321 321  
322 -(% class="p1" %)
323 -For Authentication, select "Create a HTTP Basic Auth Secret" and provide the Username and Password of the Harbor robot account from the previous section.
306 +(% class="box" %)
307 +(((
308 +**All your charts are available in the corresponding  `<pkey>-helm` OCI project.**
309 +)))
324 324  
325 -(% class="wikigeneratedid" %)
326 -[[image:1765208347952-345.36.18.png||height="449" width="849"]]
311 +There are two ways to migrate your repositories:
327 327  
328 -(% class="wikigeneratedid" %)
329 -Click Create.
313 +1. ##Direct Transition (Editing the Existing Repository)##
314 +1*. Change the target to “OCI Repository”.
315 +1*. Update the URL as required (the repository name cannot be changed) and add a new robot account for hel, check documentation above
316 +1*. After saving, installed apps will automatically start using the updated repository.
317 +1*. (% class="box" %)
318 +(((
319 +Important limitation: OCI repositories must point directly to a single chart repository, not to a parent folder.
320 +If your old repository included several charts (for example “bitbucket” and “jira”), then after switching to OCI you can only target one chart (e.g. “bitbucket”).
321 +The other charts will no longer receive updates through this repo, and you will still need to create additional repositories for each individual chart.
322 +)))
323 +1. Add New Repositories One by One (Recommended), preserve the old one till the end. This approach allows a smooth transition while the old ChartMuseum repository continues to function. You can:
324 +1*. Create a new OCI repository for each chart,
325 +1*. Keep the old ChartMuseum repo enabled during the migration,
326 +1*. Migrate applications gradually following the steps described here.
327 +1*. This avoids disruptions and allows controlled migration.
328 +
329 +1. //Special Case: Old Repo Targeting Multiple Chart Repos//
330 +If your existing repository targets multiple chart repositories and you need the new OCI setup to behave the same way, please **contact support.**
330 330  
332 +To ensure a smooth transition, we recommend to **add an OCI-based repository alongside the existing ChartMuseum repository** during the migration phase. If you don't w
333 +
334 +| Term | Meaning
335 +| **Old Repository** | The existing HTTP/HTTPS Harbor ChartMuseum repository.
336 +| **New Repository** | The new OCI-based Helm chart repository created for your project (e.g. `<chart-repo-name>` in `<pkey>-helm`).
337 +
338 +##__**Why This Migration Is Required:**__##
339 +
340 +* ##ChartMuseum is deprecated and will be removed.##
341 +* ##Applications deployed from old repos keep a reference to that repo inside their labels.##
342 +* ##Without updating the application to point to the new OCI repo, **Rancher will not detect new chart versions from new repository**.##
343 +
344 +## Migration Steps:##
345 +
346 +1. ##Create the New OCI Repository in Rancher##
347 +11. Go to **Apps → Repositories**.
348 +11. Add a new repository of type **OCI**.
349 +11. Name it similarly to your old repo name (e.g. `<chart-repo-name>-oci`). __**You can't name it the same and can't rename it later.**__
350 +11. Point it to the new OCI endpoint.
351 +1. ##Disable the Old ChartMuseum Repository Temporarily## 
352 +##This step ensures that Rancher resolves charts from the new OCI repo.##
353 +11. Go to **Apps → Repositories**.
354 +11. Disable the old HTTP(S)-based repository.
355 +11. Keep it disabled until the migration is done.
356 +[[image:1765548124989-482.59.06.png||height="152" width="485"]]
357 +1. ##Update Existing Applications to Use the New OCI Repo##
358 +Applications deployed with the old repository still contain the old repo name in their metadata. You must upgrade them once to transition.
359 +11. Go to **Apps → Installed Apps**.
360 +11. Open the application that was deployed using the old repo.
361 +11. Click **Edit/Upgrade**.
362 +[[image:1765548598644-830.png||height="138" width="811"]]
363 +11. In the list of available chart repositories (scroll to the bottom), select the **new OCI repository**. Or enter the chart name in search bar:
364 +[[image:1765548750604-334.png||height="293" width="308"]]
365 +11. Choose the chart version you want to deploy (same or newer).
366 +11. Click **Upgrade**.
367 +1. ##Re-enable the Old Repository (Optional) ##
368 +If you still need the old repo for other apps, re-enable it after the migration steps above.
369 +**Note:** Even if a newer chart version exists in the old repository, your migrated app **will not see it**, because it is no longer connected to that repo
370 +
371 +##If you want to move an app back to the old repository:##
372 +
373 +1. Temporarily disable the new OCI repo.
374 +1. Enable the old ChartMuseum repo.
375 +1. Open the application → **Upgrade**.
376 +1. Select the chart from the old repo.
377 +1. Save.
378 +
379 +This will reconnect the app to the old repository.
380 +
331 331  = Automated deployments with Jenkins =
332 332  
333 333  In this section, we describe(% style="color:#172b4d" %) how to set-up **automated builds, tests and deployments** for Jenkins.
1765548124989-482.59.06.png
Author
... ... @@ -1,0 +1,1 @@
1 +xwiki:XWiki.dianastrebkovat-systemscom
Size
... ... @@ -1,0 +1,1 @@
1 +64.4 KB
Content
1765548598644-830.png
Author
... ... @@ -1,0 +1,1 @@
1 +xwiki:XWiki.dianastrebkovat-systemscom
Size
... ... @@ -1,0 +1,1 @@
1 +153.4 KB
Content
1765548750604-334.png
Author
... ... @@ -1,0 +1,1 @@
1 +xwiki:XWiki.dianastrebkovat-systemscom
Size
... ... @@ -1,0 +1,1 @@
1 +103.0 KB
Content