Installing DevOps Plan with DevOps Control
DevOps Control provides Git hosting, code review, and team collaboration. It is similar to GitHub, Bitbucket, and GitLab. DevOps Control is based on the open-source Gitea project.
Procedure
-
Install Emissary-ingress into your cluster.
You can install Emissary-ingress using Helm. For more information, see the Emissary-ingress quick start guide.
- To install Emissary-ingress into your cluster using
Helm:
# Add the Repo: helm repo add datawire https://app.getambassador.io helm repo update # Create Namespace and Install: kubectl create namespace emissary && \ kubectl apply -f https://app.getambassador.io/yaml/emissary/3.9.1/emissary-crds.yaml kubectl wait --timeout=90s --for=condition=available deployment emissary-apiext -n emissary-system helm install emissary-ingress --namespace emissary datawire/emissary-ingress && \ kubectl -n emissary wait --for condition=available --timeout=90s deploy -lapp.kubernetes.io/instance=emissary-ingress -
If emissary-ingress service EXTERNAL-IP is in a pending state, then you must use Port Forwarding to Access Applications in a Cluster.
kubectl port-forward deployment/emissary-ingress --address [Your_External_IP_Address] 443:8443 -n emissary
- To install Emissary-ingress into your cluster using
Helm:
-
Set Ingress Domain address and Namespace name:
INGRESS_DOMAIN=[Your_External_IP_Address].nip.io NAMESPACE=[namespace_name] CHART_DIR="hcl-devopsplan-prod" HELM_NAME="devopsplan" -
Create ingress secrets:
kubectl create namespace $NAMESPACE \ && helm pull devops-plan/$CHART_DIR --untar \ && chmod +x $CHART_DIR/files/*.sh \ && bash $CHART_DIR/files/certificate.sh -n $NAMESPACE -s ingress $INGRESS_DOMAIN -
Create an additional NodePort setting to enable SSH access to DevOps Control for git
operations.
This is required when deploying to a cluster using Emissary Ingress. DevOps Control requires exclusive use of SSH port number (port/TargetPort). If the default port 9022 is already in use, you must customize the
SSH_PORTvalue for DevOps Control in your deployment before deploying DevOps Plan or DevOps Loop.- Edit the ingress listener configuration before deploying the helm chart. This sample command
opens a text editor for you to edit and save the
configuration:
kubectl edit -n emissary service emissary-ingress - In the ports section of the spec object, add a port.
Choose an unused nodePort number close to another entry's nodePort (for example, one higher). Use
the value of
SSH_PORTthat you configured, or use 9022 for the default:- name: ssh-control nodePort: 32221 port: 9022 protocol: TCP targetPort: 9022
- Edit the ingress listener configuration before deploying the helm chart. This sample command
opens a text editor for you to edit and save the
configuration:
-
Modify the Helm command to install DevOps Plan with DevOps Control.
Note: To install DevOps Control within a DevOps Plan instance, you must also add
control.gitea.config.server.SSH_PORTto the following code example.helm upgrade --install $HELM_NAME ./$CHART_DIR \ --namespace $NAMESPACE \ --set global.imagePullSecrets={[secret-name]} \ --set global.certSecretName=ingress \ --set global.domain=$INGRESS_DOMAIN \ --set control.enabled=true --set control.gitea.config.indexer.REPO_INDEXER_SKIP_TLS_VERIFY=true --set control.gitea.config.migrations.ALLOWED_DOMAINS="<the domain from where you want to migrate>"Note: When setting--set control.gitea.config.migrations.ALLOWED_DOMAINS, include the domains allowlist for migrating repositories. Multiple domains can be configured by separating them with commas. Wildcards are supported. For example,github.com,*.github.com.Note: DevOps Control uses DevOps Plan OpenSearch to search and fetch DevOps Plan work items and to associate them with Pull Requests. The DevOps Plan OpenSearch instance endpoint is secured by self-signed certificate.REPO_INDEXER_SKIP_TLS_VERIFYmust be set to true and is used by DevOps Control to determine if it should skip server certificate validation while using DevOps Plan OpenSearch endpoints. -
Run helm status $HELM_NAME -n $NAMESPACE to retrieve the DevOps
Control URL, username and password for DevOps Control and the DevOps Control PostgreSQL
database. Youc an also run the following command to get the DevOps Control URL:
echo "https://devopsplan-control.$INGRESS_DOMAIN/control"Helm rollback is not supported in Control 2.0.2 due to the following reasons:
-
These include storage and runtime topology changes in Control, such as PersistentVolumeClaim (PVC) naming transitions and cache component transitions.
-
Helm rollback attempts to restore old manifest expectations, but the cluster resources now adhere to new names and ownership. This discrepancy can lead to rollback failures even when data and resources are available.
-
Rollback in this scenario can also remount legacy PVC paths and risk serving stale data instead of the migrated data.
Supported method to return to an older version:
-
Use a
downgrade by upgrade, not aHelm rollback. - Upgrade to the target older chart version with explicit persistence pinning so
Control continues to use the migrated
nfsv3PVC. - During the downgrade, install the Helm chart with the following
configuration:
--set control.persistence.create=false --set-string control.persistence.claimName=hcl-devopsplan-control-shared-storage-nfsv3 --set control.persistence.nfsV3.enabled=false
-
What to do next
--set control.postgresql.host=[CONTROL_DATABASE_SERVER_NAME] \
--set control.postgresql.dbName=[CONTROL_DATABASE_NAME] \
--set control.postgresql.username=[CONTROL_DATABASE_USERNAME] \
--set control.postgresql.password=[CONTROL_DATABASE_PASSWORD] The SMTP Server configuration is optional in DevOps Control. To include SMTP settings, see Installing DevOps Plan with external databases and optional email server settings.