Automation Suite
2023.10
false
Migrating to an external OCI-compliant registry - Automation Suite 2023.10
Banner background image
logo
Automation Suite on Linux Installation Guide
Last updated Feb 13, 2024

Migrating to an external OCI-compliant registry

Note:

This step is required if you want to use an external registry for the Automation Suite artifacts. This is the recommended approach and improves the overall experience of using Automation Suite because of the ease of use, global availability, security and access control, and integration.

#

Step

1.

Update the cluster_config.json file with the external OCI-compliant registry details.

2.

Copy the installer and cluster_config.json to the other machines.

3.

Configure all the nodes to use the external registry.

4.

Configure ArgoCD to use the external registry.

Copying the installer and cluster_config.json to the other machines

If you configure the external registry during the upgrade, you must copy the installer file and cluster_config.json from the first server to all the other machines before proceeding.

Files

Location on all the machines

as-installer

/opt/UiPathAutomationSuite/latest/installer

cluster_config.json

/opt/UiPathAutomationSuite/cluster_config.json

Configuring all the nodes to use the external registry

To configure the nodes to use the external registry, take the following steps one by one on all the nodes in the cluster:
  1. Set the PATH variable to use the uipathctl tool, and navigate to the installer folder:
    export PATH=$PATH:/opt/UiPathAutomationSuite/latest/installer/binexport PATH=$PATH:/opt/UiPathAutomationSuite/latest/installer/bin
    cd /opt/UiPathAutomationSuite/latest/installercd /opt/UiPathAutomationSuite/latest/installer
  2. Verify the connectivity to the new registry on all nodes:
    uipathctl prereq run --location local --included "Registry_Connectivity" /opt/UiPathAutomationSuite/cluster_config.json --versions versions/helm-charts.jsonuipathctl prereq run --location local --included "Registry_Connectivity" /opt/UiPathAutomationSuite/cluster_config.json --versions versions/helm-charts.json
  3. Update the containerd configuration and restart rke2 on all nodes:
    uipathctl rke2 generate-registries /opt/UiPathAutomationSuite/cluster_config.json --current-config-path /etc/rancher/rke2/registries.yaml > /etc/rancher/rke2/registries.yaml.tmp
    
    mv -f /etc/rancher/rke2/registries.yaml.tmp /etc/rancher/rke2/registries.yaml
    
    systemctl restart rke2-server || systemctl restart rke2-agentuipathctl rke2 generate-registries /opt/UiPathAutomationSuite/cluster_config.json --current-config-path /etc/rancher/rke2/registries.yaml > /etc/rancher/rke2/registries.yaml.tmp
    
    mv -f /etc/rancher/rke2/registries.yaml.tmp /etc/rancher/rke2/registries.yaml
    
    systemctl restart rke2-server || systemctl restart rke2-agent
  4. Verify that containerd can pull images after the configuration update on all the server nodes:
    uipathctl prereq run --location local --included "Registry_Pull" /opt/UiPathAutomationSuite/cluster_config.json --versions versions/helm-charts.jsonuipathctl prereq run --location local --included "Registry_Pull" /opt/UiPathAutomationSuite/cluster_config.json --versions versions/helm-charts.json

Configuring ArgoCD to use the external registry

To configure ArgoCD to use the external registry, take the following steps:

  1. Update the ArgoCD registry configuration on any of the server nodes by running the following commands on any server node:
    export PATH=$PATH:/opt/UiPathAutomationSuite/latest/installer/binexport PATH=$PATH:/opt/UiPathAutomationSuite/latest/installer/bin
    cd /opt/UiPathAutomationSuite/latest/installercd /opt/UiPathAutomationSuite/latest/installer
  2. Back up and update the registry configuration. This is needed to maintain connectivity with the old registry during the migration.
    kubectl get secret helm-credentials -n argocd -o json | \
     jq '.metadata = {name: "old-helm-credentials", namespace: .metadata.namespace, labels: .metadata.labels}' | \
     kubectl apply -f -
    
    uipathctl config argocd registry update --host <OCI_registry_host> --username <optional_username> --password <optional_password>kubectl get secret helm-credentials -n argocd -o json | \
     jq '.metadata = {name: "old-helm-credentials", namespace: .metadata.namespace, labels: .metadata.labels}' | \
     kubectl apply -f -
    
    uipathctl config argocd registry update --host <OCI_registry_host> --username <optional_username> --password <optional_password>
  3. Update the trusted CA certificates, if needed:
    uipathctl config argocd ca-certificates update --cacert rootCA.crtuipathctl config argocd ca-certificates update --cacert rootCA.crt
  4. Verify that ArgoCD can create an empty application after the configuration update on any node:
    uipathctl health test --versions versions.json --included argocduipathctl health test --versions versions.json --included argocd
Support and Services icon
Get The Help You Need
UiPath Academy icon
Learning RPA - Automation Courses
UiPath Forum icon
UiPath Community Forum
Uipath Logo White
Trust and Security
© 2005-2024 UiPath. All rights reserved.