- 概述
- 要求
- 部署模板
- 手动:准备安装
- 手动:准备安装
- 步骤 2:为离线安装配置符合 OCI 的注册表
- 步骤 3:配置外部对象存储
- 步骤 4:配置 High Availability Add-on
- 步骤 5:配置 SQL 数据库
- 步骤 7:配置 DNS
- 步骤 8:配置磁盘
- 步骤 9:配置内核和操作系统级别设置
- 步骤 10:配置节点端口
- 步骤 11:应用其他设置
- 步骤 12:验证并安装所需的 RPM 包
- 步骤 13:生成 cluster_config.json
- Cluster_config.json 示例
- 常规配置
- 配置文件配置
- 证书配置
- 数据库配置
- 外部对象存储配置
- 预签名 URL 配置
- ArgoCD 配置
- Kerberos 身份验证配置
- 符合 OCI 的外部注册表配置
- Disaster Recovery:主动/被动和主动/主动配置
- High Availability Add-on 配置
- 特定于 Orchestrator 的配置
- Insights 特定配置
- Process Mining 特定配置
- Document Understanding 特定配置
- Automation Suite Robot 特定配置
- 监控配置
- 可选:配置代理服务器
- 可选:在多节点 HA 就绪生产集群中启用区域故障恢复
- 可选:传递自定义 resolv.conf
- 可选:提高容错能力
- 添加具有 GPU 支持的专用代理节点
- 为 Automation Suite Robot 添加专用代理节点
- 步骤 15:为离线安装配置临时 Docker 注册表
- 步骤 16:验证安装的先决条件
- 正在运行 uipathctl
- 手动:执行安装
- 安装后
- 集群管理
- 监控和警示
- 迁移和升级
- 特定于产品的配置
- 最佳实践和维护
- 故障排除
- 如何在安装过程中对服务进行故障排除
- 如何减少 NFS 备份目录的权限
- 如何卸载集群
- 如何清理离线工件以改善磁盘空间
- 如何清除 Redis 数据
- 如何启用 Istio 日志记录
- 如何手动清理日志
- 将 Ceph 退出只读模式
- 如何清理存储在 sf-logs 存储桶中的旧日志
- 如何禁用 AI Center 的流日志
- 如何对失败的 Automation Suite 安装进行调试
- 如何在升级后从旧安装程序中删除映像
- 如何禁用 TX 校验和卸载
- 如何手动将 ArgoCD 日志级别设置为 Info
- 如何扩展 AI Center 存储
- 如何为外部注册表生成已编码的 pull_secret_value
- 如何解决 TLS 1.2 中的弱密码问题
- 如何查看 TLS 版本
- 如何使用证书
- 如何计划 Ceph 备份和还原数据
- 如何使用集群内对象存储 (Ceph) 收集 DU 使用情况数据
- 如何在离线环境中安装 RKE2 SELinux
- 如何清理 NFS 服务器上的旧差异备份
- 如何在已启用 FIPS 的集群中部署 Insights
- 如何迁移到 cgroup v2
- 如何在虚拟机重新启动后恢复 Kerberos 身份验证
- 如何将本地 Docker 映像推送到集群内注册表
- 如何从备份中排除存储桶
- 无法获取沙盒映像
- Pod 未显示在 ArgoCD 用户界面中
- Redis 探测器失败
- RKE2 服务器无法启动
- ArgoCD 在首次安装后进入“进行中”状态
- 处于 CrashLoopBackOff 状态的 ArgoCD 存储库服务器 Pod
- 手动 ArgoCD 网络策略缓解措施 (MHSA-47m3-95c7-g2g8)
- 监控仪表板中缺少 Ceph-rook 指标
- 诊断性运行状况检查期间报告的错误不匹配
- 为 uipathctl 创建的工作负载配置资源请求和限制
- 无正常的上游问题
- 杀毒软件阻止了 Redis 启动
- 无法在启用 TLS 证书验证的情况下启动 AI Center 和 Document Understanding Pod
- Fluentd 不会在 IPv6 环境中导出日志
- Studio 桌面版无法加载 Integration Service 连接器和活动
- 使用 Process Mining 运行高可用性
- 使用 Kerberos 登录时 Process Mining 挖掘失败
- 无法使用 pyodbc 格式连接字符串连接到 AutomationSuite_ProcessMining_Warehouse 数据库
- Airflow 安装失败,并显示 sqlalchemy.exc.ArgumentError:无法从字符串“”中解析 rfc1738 URL
- 如何添加 IP 表格规则以使用 SQL Server 端口 1433
- 运行 CData Sync 的服务器不信任 Automation Suite 证书
- Process Mining fails to load after disabling and re-enabling it
- 运行诊断工具
- 使用 Automation Suite 支持捆绑包
- 探索日志
参考,了解安装后通过 cluster_config.json 和 uipathctl 更新 Automation Suite FQDN。
如要更新 Automation Suite 的 FQDN,必须更新cluster_config.json文件并运行uipathctl安装程序。
FQDN 更新过程适用于单节点评估模式和多节点 HA 就绪生产模式。
更改 FQDN 需要新的服务器证书。 如果新证书不可用,您有两个选择:继续使用安装程序自动配置的新自签名证书,或停止安装并引入新的 CA 颁发的证书。
您可以通过cluster_config.json文件中的server_certificate字段配置证书。
使用新的 FQDN 值更新配置文件
我们仅支持小写 FQDN。不要在 FQDN 中使用大写字符。
您必须更新 input.json 文件中的以下参数。根据您的要求,可以使用这些值的任意组合。
fqdn- 使用访问集群所需的新 FQDN 更新此字段。fixed_rke_address- 如果此值与cluster_config.json中的fqdn字段相同,则必须确保两个值匹配以反映新的 FQDN。如果是主动/被动或主动/主动设置,则此值必须与cluster_fqdn匹配。cluster_fqdn- 更新主动/被动或主动/主动集群的此字段。备注:在负载均衡器级别更改任何集群的 DNS 配置时,需要
cluster_fqdn更新
以下示例显示了更新 FQDN 所需的 cluster_config.json 配置。
{
"fqdn": "new-automationsuite.mycompany.com" //this is the fqdn for accessing the automation suite cluster
"fixed_rke2_address": "new-automationsuite.mycompany.com,"//this is only required for the node joining, if customer wish to change "cluster_fqdn": "new-primary-automationsuite.mycompany.com" //this is only required for the a/p or a/a cluster
}
{
"fqdn": "new-automationsuite.mycompany.com" //this is the fqdn for accessing the automation suite cluster
"fixed_rke2_address": "new-automationsuite.mycompany.com,"//this is only required for the node joining, if customer wish to change "cluster_fqdn": "new-primary-automationsuite.mycompany.com" //this is only required for the a/p or a/a cluster
}
步骤 1:在基础架构级别更新 FQDN
如要在基础架构层更新 FQDN,请仅在第一台服务器计算机上运行安装程序。该操作将更新集群中的所有其他节点,包括其余的服务器节点、代理节点和专用代理节点。
要更新 FQDN,请运行以下命令:
./bin/uipathctl rke2 update-fqdn -i /path/to/cluster_config.json --versions versions/helm-charts.json
./bin/uipathctl rke2 update-fqdn -i /path/to/cluster_config.json --versions versions/helm-charts.json
如果运行带有--force标志的命令,它将覆盖警告提示并直接执行 FQDN 更改。
安装程序会警告您更新 FQDN 的后果。在继续操作之前,它会要求您确认。
[WARN] You are about to change the FQDN of the Automation Suite Cluster.
Changing the fqdn is a disruptive operation, and it will result in
disconnecting your robots, mobile orchestrator users, ML Activities,
and ML Skills and invalidating any pending user invites.
If you wish to continue type 'yes' and hit enter to continue.
[WARN] You are about to change the FQDN of the Automation Suite Cluster.
Changing the fqdn is a disruptive operation, and it will result in
disconnecting your robots, mobile orchestrator users, ML Activities,
and ML Skills and invalidating any pending user invites.
If you wish to continue type 'yes' and hit enter to continue.
步骤 2:启用维护模式
在组件和服务级别触发 FQDN 更新之前,必须启用维护模式。这将关闭入口控制器和所有 UiPath™ 服务,并阻止所有传入 Automation Suite 集群的流量。
要将集群置于维护模式,请运行:
./bin/uipathctl cluster maintenance enable
./bin/uipathctl cluster maintenance enable
要验证集群是否处于维护模式,请运行:
./bin/uipathctl cluster maintenance is-enabled
./bin/uipathctl cluster maintenance is-enabled
步骤 3:在组件和服务级别更新 FQDN
要更新 FQDN,请运行以下命令:
./bin/uipathctl manifest apply /path/to/cluster_config.json --versions versions/helm-charts.json
./bin/uipathctl manifest apply /path/to/cluster_config.json --versions versions/helm-charts.json
如果运行带有--force标志的命令,它将覆盖警告提示并直接执行 FQDN 更改。
安装程序会警告您更新 FQDN 的后果。在继续操作之前,它会要求您确认。
[WARN] You are about to change the FQDN of the Automation Suite Cluster.
Changing the fqdn is a disruptive operation, and it will result in
disconnecting your robots, mobile orchestrator users, ML Activities,
and ML Skills and invalidating any pending user invites.
If you wish to continue type 'yes' and hit enter to continue.
[WARN] You are about to change the FQDN of the Automation Suite Cluster.
Changing the fqdn is a disruptive operation, and it will result in
disconnecting your robots, mobile orchestrator users, ML Activities,
and ML Skills and invalidating any pending user invites.
If you wish to continue type 'yes' and hit enter to continue.
如果没有与 FQDN 相关的新的有效证书,安装程序也会向您发出警告。如果证书验证失败,安装程序会要求您提供由 CA 颁发的新证书或继续使用新的自签名证书。
************************************************************************************
[ERROR] Validating certificate... Failed
[ERROR] Certificate doesn't have new-automationsuite.mycompany.com in the SAN
************************************************************************************
Certificate provided is invalid for the new fqdn, would you like us to configure the new self signed certificate?
If you wish to continue type `yes` and hit enter to continue.
************************************************************************************
[ERROR] Validating certificate... Failed
[ERROR] Certificate doesn't have new-automationsuite.mycompany.com in the SAN
************************************************************************************
Certificate provided is invalid for the new fqdn, would you like us to configure the new self signed certificate?
If you wish to continue type `yes` and hit enter to continue.
确保清除 Redis 数据库中的所有数据。 您可以通过运行 FLUSHALL 命令来执行此操作。
步骤 4:禁用维护模式
更新 FQDN 后,禁用维护模式以恢复 Automation Suite 集群的流量。
要禁用维护模式,请运行:
./bin/uipathctl cluster maintenance disable
./bin/uipathctl cluster maintenance disable
有关详细信息,请参阅uipathctl cluster Maintenance disable 。
在主动/主动部署中更新 FQDN
如果您在主动/主动设置中更改主集群的 FQDN,则需要执行以下额外步骤:
-
在主集群上启用维护模式:
./bin/uipathctl cluster maintenance enable./bin/uipathctl cluster maintenance enable -
为主集群生成新的 kubeconfig。
-
在辅助集群的
cluster_config.json中的other_kube_config下添加新的 kubeconfig。 -
在辅助集群上,运行以下命令:
uipathctl manifest apply cluster_config.json --versions versions/helm-charts.jsonuipathctl manifest apply cluster_config.json --versions versions/helm-charts.json -
在主集群上禁用维护模式:
./bin/uipathctl cluster maintenance disable./bin/uipathctl cluster maintenance disable有关详细信息,请参阅uipathctl cluster Maintenance disable 。