rancher-charts/charts/rancher-vsphere-cpi/100.0.0
Steven Crespo 102db092cd Team 4 - update rancher-version and kube-version annotations 2022-06-29 12:51:11 -07:00
..
templates make standardize 2022-01-06 11:08:03 -08:00
Chart.yaml Team 4 - update rancher-version and kube-version annotations 2022-06-29 12:51:11 -07:00
README.md make standardize 2022-01-06 11:08:03 -08:00
app-readme.md make standardize 2022-01-06 11:08:03 -08:00
questions.yaml make standardize 2022-01-06 11:08:03 -08:00
values.yaml make standardize 2022-01-06 11:08:03 -08:00

README.md

vSphere Cloud Provider Interface (CPI)

vSphere Cloud Provider Interface (CPI) is responsible for running all the platform specific control loops that were previously run in core Kubernetes components like the KCM and the kubelet, but have been moved out-of-tree to allow cloud and infrastructure providers to implement integrations that can be developed, built and released independent of Kubernetes core. The official documentation and tutorials can be found here.

Prerequisites

  • vSphere 6.7 U3+
  • Kubernetes v1.14+
  • A Secret on your Kubernetes cluster that contains vSphere credentials (Refer to README or Detailed Descriptions)

Installation

This chart requires a Secret in your Kubernetes cluster that contains the server URL and credentials to connect to the vCenter. You can have the chart generate it for you, or create it yourself and provide the name of the Secret during installation.

Warning: When the option to generate the Secret is enabled, the credentials are visible in the API to authorized users. If you create the Secret yourself they will not be visible.

You can create a Secret in one of the following ways:

Option 1: Create a Secret using the Rancher UI

Go to your cluster's project (Same project you will be installing the chart) > Resources > Secrets > Add Secret.

# Example of data required in the Secret
<host-1>.username: <username>
<host-1>.password: <password>

Option 2: Create a Secret using kubectl

Replace placeholders with actual values, and execute the following:

cat <<EOF | kubectl apply -f -
apiVersion: v1
kind: Secret
type: Opaque
metadata:
    name: <secret-name>
    namespace: <charts-namespace>
data:
    <host-1>.username: <base64encoded-username>
    <host-1>.password: <base64encoded-password>
EOF

More information on managing Secrets using kubectl here.

Migration

If using this chart to migrate volumes provisioned by the in-tree provider to the out-of-tree CPI + CSI, you need to taint all nodes with the following:

node.cloudprovider.kubernetes.io/uninitialized=true:NoSchedule

To perform this operation on all nodes in your cluster, the following script has been provided for your convenience:

# Note: Since this script uses kubectl, ensure that you run `export KUBECONFIG=<path-to-kubeconfig-for-cluster>` before running this script
for node in $(kubectl get nodes | awk '{print $1}' | tail -n +2); do
	kubectl taint node $node node.cloudprovider.kubernetes.io/uninitialized=true:NoSchedule
done