- 概述
- 要求
- 部署模板
- 手动:准备安装
- 手动:准备安装
- 步骤 2:为离线安装配置符合 OCI 的注册表
- 步骤 3:配置外部对象存储
- 步骤 4:配置 High Availability Add-on
- 步骤 5:配置 SQL 数据库
- 步骤 7:配置 DNS
- 步骤 8:配置磁盘
- 步骤 9:配置内核和操作系统级别设置
- 步骤 10:配置节点端口
- 步骤 11:应用其他设置
- 步骤 12:验证并安装所需的 RPM 包
- 步骤 13:生成 cluster_config.json
- Cluster_config.json 示例
- 常规配置
- 配置文件配置
- 证书配置
- 数据库配置
- 外部对象存储配置
- 预签名 URL 配置
- ArgoCD 配置
- Kerberos 身份验证配置
- 符合 OCI 的外部注册表配置
- Disaster Recovery:主动/被动和主动/主动配置
- High Availability Add-on 配置
- 特定于 Orchestrator 的配置
- Insights 特定配置
- Process Mining 特定配置
- Document Understanding 特定配置
- Automation Suite Robot 特定配置
- 监控配置
- 可选:配置代理服务器
- 可选:在多节点 HA 就绪生产集群中启用区域故障恢复
- 可选:传递自定义 resolv.conf
- 可选:提高容错能力
- 添加具有 GPU 支持的专用代理节点
- 为 Automation Suite Robot 添加专用代理节点
- 步骤 15:为离线安装配置临时 Docker 注册表
- 步骤 16:验证安装的先决条件
- 正在运行 uipathctl
- 手动:执行安装
- 安装后
- 集群管理
- 监控和警示
- 迁移和升级
- 特定于产品的配置
- 最佳实践和维护
- 故障排除
- 如何在安装过程中对服务进行故障排除
- 如何减少 NFS 备份目录的权限
- 如何卸载集群
- 如何清理离线工件以改善磁盘空间
- 如何清除 Redis 数据
- 如何启用 Istio 日志记录
- 如何手动清理日志
- 将 Ceph 退出只读模式
- 如何清理存储在 sf-logs 存储桶中的旧日志
- 如何禁用 AI Center 的流日志
- 如何对失败的 Automation Suite 安装进行调试
- 如何在升级后从旧安装程序中删除映像
- 如何禁用 TX 校验和卸载
- 如何手动将 ArgoCD 日志级别设置为 Info
- 如何扩展 AI Center 存储
- 如何为外部注册表生成已编码的 pull_secret_value
- 如何解决 TLS 1.2 中的弱密码问题
- 如何查看 TLS 版本
- 如何使用证书
- 如何计划 Ceph 备份和还原数据
- 如何使用集群内对象存储 (Ceph) 收集 DU 使用情况数据
- 如何在离线环境中安装 RKE2 SELinux
- 如何清理 NFS 服务器上的旧差异备份
- 如何在已启用 FIPS 的集群中部署 Insights
- 如何迁移到 cgroup v2
- 如何在虚拟机重新启动后恢复 Kerberos 身份验证
- 如何将本地 Docker 映像推送到集群内注册表
- 如何从备份中排除存储桶
- 无法获取沙盒映像
- Pod 未显示在 ArgoCD 用户界面中
- Redis 探测器失败
- RKE2 服务器无法启动
- ArgoCD 在首次安装后进入“进行中”状态
- 处于 CrashLoopBackOff 状态的 ArgoCD 存储库服务器 Pod
- 手动 ArgoCD 网络策略缓解措施 (MHSA-47m3-95c7-g2g8)
- 监控仪表板中缺少 Ceph-rook 指标
- 诊断性运行状况检查期间报告的错误不匹配
- 为 uipathctl 创建的工作负载配置资源请求和限制
- 无正常的上游问题
- 杀毒软件阻止了 Redis 启动
- 无法在启用 TLS 证书验证的情况下启动 AI Center 和 Document Understanding Pod
- Fluentd 不会在 IPv6 环境中导出日志
- Studio 桌面版无法加载 Integration Service 连接器和活动
- 使用 Process Mining 运行高可用性
- 使用 Kerberos 登录时 Process Mining 挖掘失败
- 无法使用 pyodbc 格式连接字符串连接到 AutomationSuite_ProcessMining_Warehouse 数据库
- Airflow 安装失败,并显示 sqlalchemy.exc.ArgumentError:无法从字符串“”中解析 rfc1738 URL
- 如何添加 IP 表格规则以使用 SQL Server 端口 1433
- 运行 CData Sync 的服务器不信任 Automation Suite 证书
- Process Mining fails to load after disabling and re-enabling it
- 运行诊断工具
- 使用 Automation Suite 支持捆绑包
- 探索日志
对于 Automation Suite 工件,从集群内注册表迁移到符合 OCI 的外部注册表。
如果要对 Automation Suite 工件使用外部注册表,则需要执行此步骤。推荐使用此方法,该方法改善了使用 Automation Suite 的整体体验,因为其具有易用性、全局可用性、安全性和访问控制以及集成性。
| # | 步骤 |
|---|---|
| 1. | 使用符合 OCI 的外部注册表详细信息更新 cluster_config.json 文件。 有关详细信息,请参阅执行高级配置。 |
| 2. | 将安装程序和 cluster_config.json 复制到其他计算机。 详细信息... |
| 3. | 将所有节点配置为使用外部注册表。详细信息... |
| 4. | 将 ArgoCD 配置为使用外部注册表。 详细信息... |
| 5. | 此步骤取决于您的迁移方案:
|
| 6. | 卸载内部注册表。详细信息... |
将安装程序和 cluster_config.json 复制到其他计算机
如果在升级期间配置外部注册表,请确保安装程序文件和cluster_config.json文件在第一台服务器和所有其他计算机上可用,然后再继续。下表列出了所需文件及其预期位置。
| 文件 | 在所有计算机上的位置 |
|---|---|
as-installer | /opt/UiPathAutomationSuite/latest/installer |
cluster_config.json | /opt/UiPathAutomationSuite/cluster_config.json |
将所有节点配置为使用外部注册表
要将节点配置为使用外部注册表,请在集群中的所有节点上逐一执行以下步骤:
-
设置路径变量以使用
uipathctl工具,并导航到安装程序文件夹:export PATH=$PATH:/opt/UiPathAutomationSuite/latest/installer/binexport PATH=$PATH:/opt/UiPathAutomationSuite/latest/installer/bincd /opt/UiPathAutomationSuite/latest/installercd /opt/UiPathAutomationSuite/latest/installer -
在所有节点上验证与新注册表的连接:
./bin/uipathctl prereq run --location local --included "Registry_Connectivity" /opt/UiPathAutomationSuite/cluster_config.json --versions versions/helm-charts.json./bin/uipathctl prereq run --location local --included "Registry_Connectivity" /opt/UiPathAutomationSuite/cluster_config.json --versions versions/helm-charts.json -
更新
containerd配置并在所有节点上重新启动rke2:./bin/uipathctl rke2 generate-registries /opt/UiPathAutomationSuite/cluster_config.json --current-config-path /etc/rancher/rke2/registries.yaml > /etc/rancher/rke2/registries.yaml.tmp mv -f /etc/rancher/rke2/registries.yaml.tmp /etc/rancher/rke2/registries.yaml systemctl restart rke2-server || systemctl restart rke2-agent./bin/uipathctl rke2 generate-registries /opt/UiPathAutomationSuite/cluster_config.json --current-config-path /etc/rancher/rke2/registries.yaml > /etc/rancher/rke2/registries.yaml.tmp mv -f /etc/rancher/rke2/registries.yaml.tmp /etc/rancher/rke2/registries.yaml systemctl restart rke2-server || systemctl restart rke2-agent -
验证
containerd是否可以在所有服务器节点上的配置更新后拉取映像:./bin/uipathctl prereq run --location local --included "Registry_Pull" /opt/UiPathAutomationSuite/cluster_config.json --versions versions/helm-charts.json./bin/uipathctl prereq run --location local --included "Registry_Pull" /opt/UiPathAutomationSuite/cluster_config.json --versions versions/helm-charts.json
将 ArgoCD 配置为使用外部注册表
要将 ArgoCD 配置为使用外部注册表,请执行以下步骤:
-
通过在任意服务器节点上运行以下命令,更新任意服务器节点上的 ArgoCD 注册表配置:
export PATH=$PATH:/opt/UiPathAutomationSuite/latest/installer/binexport PATH=$PATH:/opt/UiPathAutomationSuite/latest/installer/bincd /opt/UiPathAutomationSuite/latest/installercd /opt/UiPathAutomationSuite/latest/installer -
备份并更新注册表配置。为在迁移期间保持与旧注册表的连接,此为必要操作。
kubectl get secret helm-credentials -n argocd -o json | \ jq '.metadata = {name: "old-helm-credentials", namespace: .metadata.namespace, labels: .metadata.labels}' | \ kubectl apply -f - ./bin/uipathctl config argocd registry update --host <OCI_registry_host> --username <optional_username> --password <optional_password>kubectl get secret helm-credentials -n argocd -o json | \ jq '.metadata = {name: "old-helm-credentials", namespace: .metadata.namespace, labels: .metadata.labels}' | \ kubectl apply -f - ./bin/uipathctl config argocd registry update --host <OCI_registry_host> --username <optional_username> --password <optional_password> -
按需更新外部注册表的受信任 CA 证书:
/bin/uipathctl config argocd ca-certificates update --cacert <external-registry-rootCA.crt>/bin/uipathctl config argocd ca-certificates update --cacert <external-registry-rootCA.crt> -
在任意节点上更新配置后,验证 ArgoCD 是否可以创建空应用程序:
./bin/uipathctl health test --versions versions/helm-charts.json --included argocd./bin/uipathctl health test --versions versions/helm-charts.json --included argocd