Chapter 2. Installing and publishing a bootc image to a registry
MicroShift is built and published as image mode containers. When installing a Red Hat Enterprise Linux (RHEL) bootable container image with MicroShift, use either a prebuilt bootable container image or build your own custom bootable container image.
2.1. The image mode for RHEL with MicroShift workflow Copy linkLink copied to clipboard!
Before you use image mode for RHEL, ensure that the following resources are available:
- A RHEL 9.6 host with an active Red Hat subscription for building MicroShift bootc images.
-
A remote registry for storing and accessing
rhel-bootcimages. - An AArch64 or x86_64 system architecture.
The workflow for using image mode for RHEL with MicroShift includes the following steps:
- Find and use a prebuilt MicroShift container image to install RHEL.
- If the prebuilt MicroShift container image requires customization, build a custom MicroShift container image.
- Run the container image.
The rpm-ostree file system used by RHEL for Edge is not supported in image mode for RHEL. Do not use the rpm-ostree file system to modify deployments that use image mode for RHEL.
2.2. Get or build your bootc image Copy linkLink copied to clipboard!
Either get an existing bootc image or create one, then you can publish that image to a remote registry for use.
2.2.1. Getting the published bootc image for MicroShift Copy linkLink copied to clipboard!
You can use the MicroShift container images to install image mode for RHEL.
Prerequisites
- You have an x86_64 or AArch64 platform.
-
You have access to the
registry.redhat.ioregistry.
Procedure
- Navigate to the Red Hat Ecosystem Catalog.
-
Search for the MicroShift container image by using the
microshift-bootckeyword. - Open the container image page of the MicroShift container image.
-
Select the
Get this imagetab to view instructions for downloading the image. Get access to the latest image on x86_64 and AArch64 platforms by logging into the registry using the following command:
$ sudo podman login registry.redhat.ioDownload the bootc image by running the following command:
$ podman pull registry.redhat.io/openshift4/microshift-bootc-rhel9:v4.19
2.2.2. Building the bootc image Copy linkLink copied to clipboard!
Build your Red Hat Enterprise Linux (RHEL) that contains MicroShift as a bootable container image by using a Containerfile.
Prerequisites
- A RHEL 9.6 host with an active Red Hat subscription for building MicroShift bootc images and running containers.
-
You logged into the RHEL 9.6 host by using the user credentials that have
sudopermissions. -
The
rhocpandfast-datapathrepositories are accessible in the host subscription. The repositories do not necessarily need to be enabled on the host. - You have a remote registry such as {quay} for storing and accessing bootc images.
-
You used the
dnf install -y container-toolscommand to install thecontainer-toolsmeta-package on the host. The meta-package contains all container tools, such as Podman, Buildah, and Skopeo for additional support and troubleshooting. These tools are required for obtaining assistance from Red Hat Support when you are building and installing the image.
Procedure
Create a Containerfile that includes the following instructions:
Example Containerfile for RHEL image mode
FROM registry.redhat.io/rhel9/rhel-bootc:9.6 ARG USHIFT_VER=4.19 RUN dnf config-manager \ --set-enabled rhocp-${USHIFT_VER}-for-rhel-9-$(uname -m)-rpms \ --set-enabled fast-datapath-for-rhel-9-$(uname -m)-rpms RUN dnf install -y firewalld microshift && \ systemctl enable microshift && \ dnf clean all # Create a default 'redhat' user with the specified password. # Add it to the 'wheel' group to allow for running sudo commands. ARG USER_PASSWD RUN if [ -z "${USER_PASSWD}" ] ; then \ echo USER_PASSWD is a mandatory build argument && exit 1 ; \ fi RUN useradd -m -d /var/home/redhat -G wheel redhat && \ echo "redhat:${USER_PASSWD}" | chpasswd # Mandatory firewall configuration RUN firewall-offline-cmd --zone=public --add-port=22/tcp && \ firewall-offline-cmd --zone=trusted --add-source=10.42.0.0/16 && \ firewall-offline-cmd --zone=trusted --add-source=169.254.169.1 # Create a systemd unit to recursively make the root filesystem subtree # shared as required by OVN images RUN cat > /etc/systemd/system/microshift-make-rshared.service <<'EOF' [Unit] Description=Make root filesystem shared Before=microshift.service ConditionVirtualization=container [Service] Type=oneshot ExecStart=/usr/bin/mount --make-rshared / [Install] WantedBy=multi-user.target EOF RUN systemctl enable microshift-make-rshared.service
Podman uses the host subscription information and repositories inside the container when building the container image. If the rhocp and fast-datapath repositories are not available on the host, the build fails.
Set the
PULL_SECRETenvironment variable:$ PULL_SECRET=~/.pull-secret.jsonConfigure the
USER_PASSWDenvironment variable:$ USER_PASSWD=<redhat_user_password>1 - 1
- Replace <redhat_user_password> with your password.
Configure the
IMAGE_NAMEenvironment variable:$ IMAGE_NAME=microshift-4.19-bootcCreate a local bootc image by running the following image build command:
$ sudo podman build --authfile "${PULL_SECRET}" -t "${IMAGE_NAME}" \ --build-arg USER_PASSWD="${USER_PASSWD}" \ -f ContainerfileImportantHow secrets are used during the image build:
-
The podman
--authfileargument is required to pull the baserhel-bootc:9.6image from theregistry.redhat.ioregistry. -
The build
USER_PASSWDargument is used to set a password for theredhatuser.
-
The podman
Verification
Verify that the local MicroShift bootc image was created by running the following command:
$ sudo podman images "${IMAGE_NAME}"Example output
REPOSITORY TAG IMAGE ID CREATED SIZE localhost/microshift-4.19-bootc latest 193425283c00 2 minutes ago 2.31 GB
2.3. Publishing the bootc image to the remote registry Copy linkLink copied to clipboard!
Publish your bootc image to the remote registry so that the image can be used for running the container on another host, or for when you want to install a new operating system with the bootc image layer.
Prerequisites
-
You are logged in to the RHEL 9.6 host where the image was built using the user credentials that have
sudopermissions. - You have a remote registry such as {quay} for storing and accessing bootc images.
- You created the Containerfile and built the image.
Procedure
Set the
REGISTRY_URLvariable for the image by running the following command:$ REGISTRY_URL=<quay.io>1 - 1
- Replace <quay.io> with the URL for your image registry.
Log in to your remote registry by running the following command:
$ sudo podman login "${REGISTRY_URL}"Set the
IMAGE_NAMEvariable for the image by running the following command:$ IMAGE_NAME=<microshift-4.19-bootc>1 - 1
- Replace <microshift-4.19-bootc> with the name of the image you want to publish.
Set the
REGISTRY_IMGvariable for the image by running the following command:$ REGISTRY_IMG=<myorg/mypath>/"${IMAGE_NAME}"1 - 1
- Replace <myorg/mypath> with your remote registry organization name and path.
Publish the image by running the following command:
$ sudo podman push localhost/"${IMAGE_NAME}" "${REGISTRY_URL}/${REGISTRY_IMG}"
Verification
- Run the container using the image you pushed to your registry as described in the "Running the MicroShift bootc container" section.