베어메탈 UPI 설치에서 부팅 전에 끝내 둘 준비다. 요구사항 의 머신 · DNS · 로드밸런서가 준비됐다는 전제에서, 설치 도구를 받고 Ignition 파일을 만들어 HTTP 로 서빙하는 데까지를 다룬다. 작업은 클러스터 밖의 리눅스 작업용 호스트(bastion)에서 한다.
openshift-install · oc 를 실행하고 Ignition 을 HTTP 로 서빙한다python3 -m http.server)console.redhat.com/openshift/install 에서 플랫폼을 고르면 openshift-install · oc 다운로드 링크와 pull secret 을 함께 준다. 미러 사이트에서 직접 받을 수도 있다[1].
OCP_VERSION=stable-4.22
curl -LO https://mirror.openshift.com/pub/openshift-v4/x86_64/clients/ocp/$OCP_VERSION/openshift-install-linux.tar.gz
curl -LO https://mirror.openshift.com/pub/openshift-v4/x86_64/clients/ocp/$OCP_VERSION/openshift-client-linux.tar.gz
tar xzf openshift-install-linux.tar.gz
tar xzf openshift-client-linux.tar.gz
sudo install -m 0755 openshift-install oc kubectl /usr/local/bin/
openshift-install version
oc version --client
console.redhat.com/openshift/install/pull-secret 에서 받아 pull-secret.json 으로 둔다. install-config.yaml 의 pullSecret 에 그대로 들어간다.
ssh-keygen -t ed25519 -N '' -f ~/.ssh/ocp
cat ~/.ssh/ocp.pub
공개키를 install-config.yaml 의 sshKey 에 넣는다. 노드에는 ssh core@<노드> 로 들어간다.
installer 가 기대하는 RHCOS 버전을 installer 자신이 알려준다. 그 버전의 라이브 ISO(또는 PXE 용 kernel · initramfs · rootfs)를 받는다.
openshift-install coreos print-stream-json | jq -r '.architectures.x86_64.artifacts.metal.formats.iso.disk.location'
curl -LO <위에서 나온 URL>
작업 디렉터리를 만들고 install-config.yaml 을 둔다. installer 가 이 파일을 소비해서 지우므로 사본을 따로 둔다.
mkdir ocp && cp install-config.yaml ocp/
cp install-config.yaml install-config.yaml.bak
openshift-install create manifests --dir ocp
UPI 베어메탈에서 control plane 에 워크로드를 올리지 않으려면 ocp/manifests/cluster-scheduler-02-config.yml 의 mastersSchedulable 을 false 로 바꾼다. compute 가 없는 3 노드 구성이면 true 로 둔다.
openshift-install create ignition-configs --dir ocp
ls ocp/*.ign
bootstrap.ign · master.ign · worker.ign 세 파일이 나온다. ocp/auth/kubeconfig 와 ocp/auth/kubeadmin-password 도 이때 만들어진다. Ignition 안의 인증서는 24 시간만 유효하므로 만든 뒤 하루 안에 부트스트랩을 끝낸다.
노드가 부팅 중 받아갈 수 있도록 Ignition 파일을 HTTP 로 연다.
sudo mkdir -p /var/www/html/ocp
sudo cp ocp/*.ign /var/www/html/ocp/
sudo chmod 644 /var/www/html/ocp/*.ign
curl -sI http://<bastion>/ocp/bootstrap.ign | head -1
노드를 RHCOS 라이브 ISO 로 부팅해 디스크에 설치한다 — Install bootstrap. 부팅 순서는 bootstrap → control plane → compute 이고, 진행 상황은 다음으로 본다.
openshift-install wait-for bootstrap-complete --dir ocp --log-level info
export KUBECONFIG=$PWD/ocp/auth/kubeconfig
oc get nodes
oc get csr
oc get clusteroperators
openshift-install wait-for install-complete --dir ocp
compute 노드의 CSR 은 자동 승인되지 않으므로 oc adm certificate approve <name> 으로 두 번(클라이언트 · 서빙) 승인한다.