Use a customized Red Hat Enterprise Linux CoreOS (RHCOS) ISO image to add worker nodes to an OpenShift cluster that was created with the Agent-based Installer.
- Access the cluster by using the
oc command as a user who can read Machine Config Operator secrets.
- Install
coreos-installer on the system used to create the ISO image.
- Provide a web server that new nodes can access to download the worker Ignition configuration.
- Identify the target installation device for each new node. This procedure uses
/dev/sda as an example.
- Have a pull secret available for registry authentication.
This procedure creates a Day 2 ISO image, customizes its kernel arguments, and uses the image to provision a new worker node. The node downloads its Ignition configuration from the specified web server during installation.
Note
Use HTTP delivery of the Ignition configuration only in a controlled environment. Ensure that network security rules allow new nodes to access the web server.
-
On the system used to create the ISO image, create a working directory and set the registry authentication file.
export REGISTRY_AUTH_FILE=/home/opc/PullSecret.json
export DIR=day2
mkdir -p $DIR
cd $DIR
-
Export the worker Ignition configuration from the cluster.
oc -n openshift-machine-config-operator get secret worker-user-data \
-o jsonpath='{.data.userData}' | base64 -d > worker.ign
-
Copy the worker Ignition configuration to a web-server directory that the new node can access.
sudo mkdir -p /var/www/html/day2
sudo cp worker.ign /var/www/html/day2/worker.ign
sudo chmod 0644 /var/www/html/day2/worker.ign
-
Verify that the web server can provide the Ignition configuration and that the configuration is valid JSON.
curl -sS http://webserver/day2/worker.ign | head -n 2
curl -sS http://webserver/day2/worker.ign | jq -e . >/dev/null && echo OK
-
Create a Day 2 ISO image. Specify the MAC address and target installation device for the new node.
oc adm node-image create \
--mac-address=00:00:00:00:00:00 \
--root-device-hint=deviceName:/dev/sda
The command creates the node.x86_64.iso file. Use the actual MAC address when creating an ISO image for a specific host.
-
Customize the ISO image with the console, debugging, live-environment, installation-device, and Ignition URL kernel arguments.
coreos-installer iso customize -f \
--live-karg-append console=tty0 \
--live-karg-append console=ttyS0,115200n8 \
--live-karg-append rd.debug \
--live-karg-append rd.live.ram=1 \
--live-karg-append rd.live.overlay=none \
--live-karg-append rd.luks=0 \
--live-karg-append rd.lvm=0 \
--live-karg-append rd.md=0 \
--live-karg-append rd.dm=0 \
--live-karg-append coreos.liveiso.fromram \
--live-karg-append coreos.inst.install_dev=/dev/sda \
--live-karg-append coreos.inst.ignition_url=http://webserver/day2/worker.ign \
-o rhcos-auto-worker-oci-ram-debug-DAY2-1.iso \
node.x86_64.iso
Note
Replace /dev/sda and http://webserver/day2/worker.ign with values for the new node and your environment.
-
Verify the kernel arguments embedded in the customized ISO image.
coreos-installer iso kargs show rhcos-auto-worker-oci-ram-debug-DAY2-1.iso
-
Upload the customized ISO image to Object Storage, create an OCI custom image, and create a worker instance that uses the custom image.
-
On the new node, verify the kernel arguments and installation logs.
cat /proc/cmdline
journalctl -b -u coreos-installer -u ignition-*
-
From the cluster, monitor the node provisioning and join process.
oc adm node-image monitor --ip-addresses <node_IP_address>
Use the output to identify whether the node is blocked during Ignition retrieval, kubelet startup, certificate signing request approval, or readiness.