Special thanks to Ben Schmaus and his amazing blog post.
We also discussed the process here during the Ask an OpenShift Admin live stream on Oct 20th.
-
Pre-reqs
Download the tools we'll need.
Special thanks to Ben Schmaus and his amazing blog post.
We also discussed the process here during the Ask an OpenShift Admin live stream on Oct 20th.
Pre-reqs
Download the tools we'll need.
This was tested using a default OpenShift 4.11 IPI deployment to AWS. The worker nodes had 16GiB of memory.
First, we'll need a namespace to use for the below experiments.
oc new-project alloc
Before starting, we need to configure eviction thresholds
This follows the documentation for mirroring images.
Download the images
dryrun.sh
to get the `ImageContentSourcePolicy`` needed for the disconnected cluster.The values used for the destination registry, which are used for the ICSP, can be arbitrary and changed on the disconnected network to represent your scenario. This is useful if the hostnames / IPs are sensitive.
#! /usr/bin/env/sh | |
# | |
# this script has not been tested nor validated, it is not, in any way | |
# supported by Red Hat or NetApp. use at your own risk. | |
# | |
# | |
# the purpose of this script is to create an OpenShift MachineConfig | |
# to apply the NetApp recommended OS configuration to RHCOS machines. |
Understand AD LDAP structure and naming. Read the docs on the components
Refer to the OpenShift docs for the LDAP identity provider and LDAP group syncing.
Create the OAuth config
# create a secret for the bindDN user password