컨테이너화된 환경으로 SUSE Manager 서버 마이그레이션
1. 요구 사항 및 고려 사항
1.1. 일반
-
SUSE Manager 4.3 서버를 컨테이너로 마이그레이션하려면 SLE Micro 5.5 또는 SUSE Linux Enterprise Server 15 SP6 및
mgradm이 설치된 새 시스템이 필요합니다. -
선택한 호스트 운영 체제가 SLE Micro 5.5 또는 SUSE Linux Enterprise Server 15 SP6인지와 상관없이 SUSE Manager 4.3에서 5.0(으)로의 인플레이스 마이그레이션은 지원되지 않습니다.
-
SUSE Manager 4.3에서 5.0(으)로 마이그레이션하기 전에 기존 프록시를 포함한 기존의 모든 기존 클라이언트를 Salt로 마이그레이션해야 합니다.
-
기존 SUSE Manager 4.3 클라이언트를 Salt 클라이언트로 마이그레이션하는 방법에 대한 자세한 내용은 https://documentation.suse.com/suma/4.3/en/suse-manager/client-configuration/contact-methods-migrate-traditional.html에서 확인할 수 있습니다.
-
-
기존 연락 프로토콜은 SUSE Manager 5.0 이상에서 더 이상 지원되지 않습니다.
|
이 가이드에서는 SUSE Manager 4.3에서 5.0(으)로의 마이그레이션에 대해서만 다룹니다. 호스트 운영 체제를 SLE Micro 5.5에서 SUSE Linux Enterprise Server 15 SP6(으)로 또는 그 반대로 전환하는 동안 기존 SUSE Manager 5.0 인스턴스를 동일한 버전으로 마이그레이션하는 기능은 |
1.2. GPG 키
-
자체 신뢰 GPG 키는 마이그레이션되지 않습니다.
-
RPM 데이터베이스에서만 신뢰되는 GPG 키는 마이그레이션되지 않습니다. 따라서
spacewalk-repo-sync로 채널을 동기화하면 실패할 수 있습니다. -
관리자는 실제 서버 마이그레이션을 수행한 후 이러한 키를 4.3 설치에서 컨테이너 호스트로 수동으로 마이그레이션해야 합니다.
Procedure: Manual Migration of the 4.3 GPG Keys to New Server-
4.3 서버의 키를 새 서버의 컨테이너 호스트로 복사합니다.
-
그 후,
mgradm gpg add <PATH_TO_KEY_FILE>명령을 사용하여 마이그레이션된 서버에 각 키를 추가합니다.
-
2. 마이그레이션
2.1. Prepare SUSE Manager 5.0 Server Host
|
준비된 SLE Micro 5.5 또는 SUSE Linux Enterprise Server 15 SP6 시스템에 SUSE Manager을 사전 설치하지 마십시오. 마이그레이션 프로세스는 서버 설치를 자동으로 수행하도록 설계되었습니다. 다음 단계에서는 호스트 시스템 준비만 수행되며, 실제 SUSE Manager 5.0 서버를 설치하지 않습니다. |
2.1.1. SLE Micro 5.5 호스트 준비
2.1.1.1. Download the installation media
https://www.suse.com/download/sle-micro/에서 SLE Micro 5.5 설치 미디어를 찾습니다.
SLE-Micro-5.5-DVD-x86_64-GM-Media1.iso를 다운로드합니다.설치하기 위해 다운로드한
.iso이미지가 들어 있는 DVD 또는 USB 플래시 드라이브를 준비합니다.
2.1.1.2. SLE Micro 5.5 설치
Insert the DVD or USB flash drive (USB disk or key) containing the installation image for SLE Micro 5.5.
시스템을 부팅하거나 재부팅합니다.
화살표 키를 사용하여
설치를 선택합니다.Adjust Keyboard and language.
확인란을 클릭하여 라이선스 계약에 동의합니다.
다음을 클릭하여 계속합니다.Select the registration method. For this example, we will register the server with SUSE Customer Center.
The SUSE Manager 5.0 containers are installed as extensions. Depending on the specific extension needed from the list below, additional SUSE Customer Center registration codes will be required for each.
SUSE Manager 5.0 서버
SUSE Manager 5.0 프록시
SUSE Manager 5.0 Retail Branch Server
SLE Micro 5.5 권한은 SUSE Manager 권한에 포함되어 있으므로 별도의 등록 코드가 필요하지 않습니다.
Enter your SUSE Customer Center email address.
SLE Micro 5.5 등록 코드를 입력합니다.
다음을 클릭하여 계속합니다.To install a proxy, select the SUSE Manager 5.0 Proxy extension; to install a server, select the SUSE Manager 5.0 Server extension
Checkbox.
다음을 클릭하여 계속합니다.Enter your SUSE Manager 5.0 extension registration code.
다음을 클릭하여 계속합니다.
NTP 구성페이지에서 다음을 클릭합니다.
시스템 인증페이지에서 루트 사용자의 비밀번호를 입력합니다. 다음을 클릭합니다.
설치 설정페이지에서 설치를 클릭합니다.
This concludes installation of SLE Micro 5.5 and SUSE Manager 5.0 as an extension. For more information about preparing your machines (virtual or physical), see SLE Micro 5.5 Deployment Guide.
2.1.1.3. OPTIONAL: Registration from the command line
SLE Micro 5.5 설치 중에 SUSE Manager 5.0을(를) 확장자로 추가한 경우 이 절차를 건너뛸 수 있습니다. 그러나 선택적으로 등록 건너뛰기 버튼을 선택하여 SLE Micro 5.5 설치 중에 등록을 건너뛸 수 있습니다. 이 섹션에서는 SLE Micro 5.5 설치 후 제품 등록에 대한 단계를 제공합니다.
|
The following steps register a SUSE Manager 5.0 extension with the x86-64 architecture and thus require a registration code for the x86-64 architecture. To register ARM or s390x architectures use the correct registration code. |
List available extensions with the following command:
transactional-update --quiet register --list-extensionsFrom the list of available extensions, select the one you wish to install:
If installing the Server, use your SUSE Manager Server Extension 5.0 x86_64 registration code with following command:
transactional-update register -p SUSE-Manager-Server/5.0/x86_64 -r <reg_code>If installing the Proxy, use your SUSE Manager Proxy Extension 5.0 x86_64 registration code with following command:
transactional-update register -p SUSE-Manager-Proxy/5.0/x86_64 -r <reg_code>재부팅합니다.
2.1.1.4. 시스템 업데이트
root로 로그인합니다.
transactional-update 실행:
transactional-update재부팅합니다.
SLE Micro는 기본적으로 자동으로 업데이트되도록 설계되어 있으며, 업데이트를 적용한 이후에는 재부팅됩니다. 그러나 SUSE Manager 환경에서 이는 올바른 동작이 아닙니다. SUSE Manager은(는) 서버에서 자동 업데이트를 방지하기 위해 부트스트랩 프로세스 중에 트랜잭션 업데이트 타이머를 비활성화합니다.
SLE Micro 기본 동작을 사용하려면 다음 명령을 실행하여 타이머를 활성화합니다.
systemctl enable --now transactional-update.timer
2.1.2. SUSE Linux Enterprise Server 15 SP6 호스트 준비
또는 SUSE Linux Enterprise Server 15 SP6에 SUSE Manager을(를) 배포할 수도 있습니다.
The following procedure describes the main steps of the installation process.
https://www.suse.com/download/sles/에서 SUSE Linux Enterprise Server 15 SP6
.iso를 찾아 다운로드합니다.Make sure that you have registration codes both for the host operating system (SUSE Linux Enterprise Server 15 SP6) and extensions.
SUSE Linux Enterprise Server 15 SP6 설치를 시작합니다.
On the
Language, keyboard and product selectionselect the product to install.
라이선스 계약에서 계약서를 읽고라이선스 약관에 동의합니다에 체크 표시합니다.Select the registration method. For this example, we will register the server with SUSE Customer Center.
Enter your SUSE Customer Center email address.
SLE Micro 5.5 등록 코드를 입력합니다.
다음을 클릭하여 계속합니다.
SUSE Linux Enterprise Server 15 SP6의 경우 유효한 SUSE Linux Enterprise Server 구독과 해당 등록 코드가 있어야 하며, 이 화면에서 해당 정보를 제공해야 합니다. 아래에 SUSE Manager 확장 프로그램 등록 코드를 입력해야 합니다.
In the screen
Extensions and Modules Selectioncheck the following:
Select the SUSE Manager Server Extension to install the Server, or the SUSE Manager Proxy Extension to install the Proxy.
Basesystem Module
Containers Module
다음을 클릭하여 계속합니다.Enter your SUSE Manager 5.0 extension registration code.
다음을 클릭하여 계속합니다.
설치를 완료합니다.
When the installation completes, log in to the newly installed server as root.
Update the System (optional, if the system was not set to download updates during install):
zypper up재부팅합니다.
루트 권한으로 로그인한 후 제품 패키지를 설치합니다.
서버에서:
zypper in podman zypper in -t product SUSE-Manager-Server프록시에서:
zypper in podman zypper in -t product SUSE-Multi-Manager-Proxy
podman패키지가 설치되어 있는지 확인합니다. 또한 서버에는mgradm및mgradm-bash-completion이 설치되고, 프록시 서버에는mgrpxy및mgrpxy-bash-completion이 추가로 설치되어야 합니다.Start the Podman service by rebooting the system, or running a command:
systemctl enable --now podman.service
2.2. SSH 연결 준비
이 단계에서는 비밀번호를 요구하지 않고 SSH를 통해 기존 4.3 서버에 연결할 수 있도록 새 SUSE Manager 5.0 서버를 설정합니다. 여기에는 SSH 키를 생성 및 구성하고, SSH 에이전트를 설정하며, 공개 키를 이전 서버에 복사하는 작업이 포함됩니다.
마이그레이션 프로세스를 수동 개입 없이 실행하려면 이 설정이 필요합니다.
-
새 5.0 서버에
root에 대한 SSH 키가 있는지 확인합니다. 키가 없는 경우 다음을 사용하여 키를 만듭니다.ssh-keygen -t rsa
-
새 서버에서 비밀번호를 요청하지 않는 4.3 서버에 연결할 수 있도록 SSH 구성 및 에이전트가 준비되어 있어야 합니다.
eval $(ssh-agent); ssh-add
비밀번호를 요청하지 않는 연결을 설정하기 위해 마이그레이션 스크립트는 새 서버에서 실행 중인 SSH 에이전트를 활용합니다. 에이전트가 아직 활성화되어 있지 않은 경우,
eval $(ssh-agent)를 실행하여 에이전트를 시작합니다. 그런 다음ssh-add를 실행한 후 개인 키의 경로를 입력하여 실행 중인 에이전트에 SSH 키를 추가합니다. 이 프로세스 중에는 개인 키의 비밀번호를 입력하라는 메시지가 표시됩니다. -
ssh-copy-id를 사용하여 SUSE Manager 4.3 서버(<oldserver.fqdn>)에 공개 SSH 키를 복사합니다.<oldserver.fqdn>을 4.3 서버의 FQDN으로 바꿉니다.ssh-copy-id <old server.fqdn>
SSH 키는 기존 서버의
~/.ssh/authorized_keys파일에 복사됩니다. 자세한 내용은ssh-copy-id사용자 지정 페이지에서 확인할 수 있습니다. -
새 서버에서 기존 SUSE Manager 서버로 SSH 연결을 설정하여 비밀번호가 필요하지 않은지 확인합니다. 호스트 지문에도 문제가 없어야 합니다. 문제가 있는 경우
~/.ssh/known_hosts파일에서 기존 지문을 제거합니다. 그런 다음 다시 시도합니다. 지문은 로컬~/.ssh/known_hosts파일에 저장됩니다.
2.3. 마이그레이션 수행
When planning your migration from SUSE Manager 4.3 to SUSE Manager 5.0, ensure that your target instance meets or exceeds the specifications of the old setup.
여기에는 메모리(RAM), CPU 코어 수, 스토리지 및 네트워크 대역폭이 포함되지만, 이에 국한되지 않습니다.
-
이 단계는 선택 사항입니다. 인프라에 사용자 정의 영구 스토리지가 필요한 경우
mgr-storage-proxy도구를 사용하십시오.mgr-storage-server에 대한 자세한 내용은 installation-and-upgrade:hardware-requirements.adoc#install-hardware-requirements-storage에서 확인할 수 있습니다. -
새 SUSE Manager 서버를 설치하려면 다음 명령을 실행합니다. <oldserver.fqdn>은 4.3 서버의 FQDN으로 대체합니다.
마이그레이션 프로세스를 시작하기 전에 반드시 4.3 서버를 업그레이드하고 사용 가능한 모든 업데이트를 적용해야 합니다. 또한 불필요한 채널을 제거하여 전체 마이그레이션 시간을 단축하는 데 도움이 되도록 하십시오.
The migration can take a very long time depending on the amount of data that needs to be replicated. To reduce downtime it is possible to run the migration multiple times in a process of initial replication, re-replication, or final replication and switch over while all the services on the old server can stay up and running.
Only during the final migration the processes on the old server need to be stopped.
For all non-final replications add the parameter
--prepareto prevent the automatic stopping the services on the old server. For example on SUSE Manager server:mgradm migrate podman <oldserver.fqdn> --prepare
-
Stop the SUSE Manager services on 4.3 Server:
spacewalk-service stop
-
4.3 서버에서 PostgreSQL 서비스를 중지합니다.
systemctl stop postgresql
-
Perform the migration on SUSE Manager server
mgradm migrate podman <oldserver.fqdn>
-
신뢰할 수 있는 SSL CA 인증서를 마이그레이션합니다.
2.3.1. 인증서 마이그레이션
Trusted SSL CA certificates that were installed as part of an RPM and stored on SUSE Manager 4.3 in the /usr/share/pki/trust/anchors/ directory will not be migrated. Because SUSE does not install RPM packages in the container, the administrator must migrate these certificate files manually from the 4.3 installation after the migration.
-
Copy the file from the 4.3 server to the new server. For example, as
/local/ca.file. -
다음을 사용하여 파일을 컨테이너에 복사합니다.
mgrctl cp /local/ca.file server:/etc/pki/trust/anchors/
|
5.0 서버로 리디렉션하려면 인프라 수준(DHCP 및 DNS)에서 새 서버의 이름을 4.3 서버와 동일한 FQDN 및 IP 주소를 사용하도록 변경해야 합니다. |