7장. Target environment
Prepare, configure, and validate your target Ansible Automation Platform environment.
7.1. Container-based Ansible Automation Platform 링크 복사링크가 클립보드에 복사되었습니다!
Prepare and assess your target container-based Ansible Automation Platform environment, and import and reconcile your migrated content.
7.1.1. Preparing and assessing the target environment 링크 복사링크가 클립보드에 복사되었습니다!
Transfer the migration artifact, install containerized Ansible Automation Platform, and configure the inventory file to match your source environment topology and database settings.
Procedure
- Validate the file system home folder size and make sure it has enough space to transfer the artifact.
-
Transfer the artifact to the nodes where you will be working by using
scpor any preferred file transfer method. It is recommended that you work from the platform gateway node as it has access to most systems. However, if you have access or file system space limitations due to the PostgreSQL dumps, work from the database node instead. - Download the latest version of containerized Ansible Automation Platform from the Ansible Automation Platform download page.
- Validate the artifact checksum.
Extract the artifact on the home folder for the user running the containers.
$ cd ~$ sha256sum --check artifact.tar.sha256$ tar xf artifact.tar$ cd artifact$ sha256sum --check sha256sum.txtGenerate an inventory file for your containerized deployment.
Configure the inventory file to match the same topology as the source environment. Configure the component database names and the
secret_keyvalues from the artifact’ssecrets.ymlfile.You can do this in two ways:
- Set the extra variables in the inventory file.
Use the
secrets.ymlfile as an additional variables file when running the installation program.Option 1: Extra variables in the inventory file
$ egrep 'pg_database|_key' inventory controller_pg_database=<redacted> controller_secret_key=<redacted> gateway_pg_database=<redacted> gateway_secret_key=<redacted> hub_pg_database=<redacted> hub_secret_key=<redacted> __hub_database_fields=<redacted>참고The
__hub_database_fieldsvalue comes from thehub_db_fields_encryption_keyvalue in your secret.Option 2: Additional variables file
$ ansible-playbook -i inventory ansible.containerized_installer.install -e @~/artifact/secrets.yml -e "__hub_database_fields='{{ hub_db_fields_encryption_key }}'"
- Install and configure the containerized target environment.
- Verify PostgreSQL database version is on version 15.
Create a backup of the initial containerized environment.
$ ansible-playbook -i <path_to_inventory> ansible.containerized_installer.backup- Verify the fresh installation functions correctly.
7.1.2. Importing the migration content to the target environment 링크 복사링크가 클립보드에 복사되었습니다!
To import your migration content into the target environment, stop the containerized services, import the database dumps, and then restart the services.
Procedure
Stop the containerized services, except the database.
In all nodes, if Performance Co-Pilot is configured, run the following command:
$ systemctl --user stop pcpAccess the automation controller node and run:
$ systemctl --user stop automation-controller-task automation-controller-web automation-controller-rsyslog $ systemctl --user stop receptorAccess the automation hub node and run:
$ systemctl --user stop automation-hub-api automation-hub-content automation-hub-web automation-hub-worker-1 automation-hub-worker-2Access the Event-Driven Ansible node and run:
$ systemctl --user stop automation-eda-scheduler automation-eda-daphne automation-eda-web automation-eda-api automation-eda-worker-1 automation-eda-worker-2 automation-eda-activation-worker-1 automation-eda-activation-worker-2Access the platform gateway node and run:
$ systemctl --user stop automation-gateway automation-gateway-proxyAccess the platform gateway node when using standalone Redis, or all nodes from the Redis group in your inventory file when using clustered Redis, and run:
$ systemctl --user stop redis-unix redis-tcp참고In an enterprise deployment, the components run on different nodes. Run the commands on each component node.
Import database dumps to the containerized environment.
If you are using an Ansible Automation Platform managed database, you must create a temporary container to run the
psqlandpg_restorecommands. Run this command from the database node:$ podman run -it --rm --name postgresql_restore_temp --network host --volume ~/aap/tls/extracted:/etc/pki/ca-trust/extracted:z --volume ~/aap/postgresql/server.crt:/var/lib/pgsql/server.crt:ro,z --volume ~/aap/postgresql/server.key:/var/lib/pgsql/server.key:ro,z --volume ~/artifact:/var/lib/pgsql/backups:ro,z registry.redhat.io/rhel8/postgresql-15:latest bash참고The command above opens a shell inside the container named
postgresql_restore_tempwith the artifact mounted at/var/lib/pgsql/backups. Additionally, it mounts the PostgreSQL certificates to ensure that you can resolve the correct certificates.The command assumes the image
registry.redhat.io/rhel8/postgresql-15:latestis available. If you are missing the image, check the available images for the user withpodman images ls.It also assumes that the artifact is located in the current user’s home folder. If the artifact is located elsewhere, change the
~/artifactwith the required path.-
If you are using a customer-provided (external) database, you can run the
psqlandpg_restorecommands from any node that has these commands installed and that has access to the database. Reach out to your database administrator if you are unsure. From inside the container, access the database and ensure the users have the
CREATEDBrole.bash-4.4$ psql -h <pg_hostname> -U postgres postgres=# \l Name | Owner | Encoding | Collate | Ctype | ICU Locale | Locale Provider | Access privileg es -------------------------+---------------+----------+-------------+-------------+------------+-----------------+------------------ ----- automationedacontroller | eda | UTF8 | en_US.UTF-8 | en_US.UTF-8 | | libc | automationhub | automationhub | UTF8 | en_US.UTF-8 | en_US.UTF-8 | | libc | awx | awx | UTF8 | en_US.UTF-8 | en_US.UTF-8 | | libc | gateway | gateway | UTF8 | en_US.UTF-8 | en_US.UTF-8 | | libc | ...For each component name, add the
CREATEDBrole to theOwner. For example:postgres=# ALTER ROLE awx WITH CREATEDB; postgres=# \qReplace
awxwith the database owner.With the
CREATEDBin place, access the path where the artifact is mounted, and run thepg_restorecommands.bash$ cd /var/lib/pgsql/backups bash$ pg_restore --clean --create --no-owner -h <pg_hostname> -U <component_pg_user> -d template1 <component>/<component>.pgcAfter the restore, remove the permissions from the user. For example:
postgres=# ALTER ROLE awx WITH NOCREATEDB; postgres=# \qReplace
awxwith each user containing the role.
Start the containerized services, except the database.
참고In an enterprise deployment, the components run on different nodes. Run the commands on each component node.
In all nodes, if Performance Co-Pilot is configured, run the following command:
$ systemctl --user start pcpAccess the automation controller node and run:
$ systemctl --user start automation-controller-task automation-controller-web automation-controller-rsyslog $ systemctl --user start receptorAccess the automation hub node and run:
$ systemctl --user start automation-hub-api automation-hub-content automation-hub-web automation-hub-worker-1 automation-hub-worker-2Access the Event-Driven Ansible node and run:
$ systemctl --user start automation-eda-scheduler automation-eda-daphne automation-eda-web automation-eda-api automation-eda-worker-1 automation-eda-worker-2 automation-eda-activation-worker-1 automation-eda-activation-worker-2Access the platform gateway node and run:
$ systemctl --user start automation-gateway automation-gateway-proxyAccess the platform gateway node when using standalone Redis, or all nodes from the Redis group in your inventory when using clustered Redis, and run:
$ systemctl --user start redis-unix redis-tcp
7.1.3. Reconciling the target environment post-import 링크 복사링크가 클립보드에 복사되었습니다!
Perform the following post-import reconciliation steps to verify your target environment functions correctly.
Procedure
Deprovision the platform gateway configuration.
To deprovision platform gateway configuration, SSH to the host serving an
automation-gatewaycontainer as the same rootless user from 4.2.6 and run the following to remove the platform gateway proxy configuration:$ podman exec -it automation-gateway bash $ aap-gateway-manage migrate $ aap-gateway-manage shell_plus >>> HTTPPort.objects.all().delete(); ServiceNode.objects.all().delete(); ServiceCluster.objects.all().delete()
Transfer custom configurations and settings.
-
Edit the inventory file and apply any relevant
extra_settingsto each component by using thecomponent_extra_settings.
-
Edit the inventory file and apply any relevant
Remove all resource server key secrets to be repopulated by the installation program:
$ for i in `podman secret ls | egrep 'resource_server' | awk '{print $2}'`; do podman secret rm $i; done- Re-run the installation program on the target environment by using the same inventory from the installation.
Sync platform gateway resources if Event-Driven Ansible is present:
$ podman exec -it automation-eda-api bash $ aap-eda-manage resource_syncValidate instances for automation execution.
SSH to the host serving an
automation-controller-taskcontainer as the rootless user, and run the following commands to validate and remove instances that are orphaned from the source artifact:$ podman exec -it automation-controller-task bash$ awx-manage list_instancesFind nodes that are no longer part of this cluster. A good indicator is nodes with 0 capacity as they have failed their health checks:
[ungrouped capacity=0] [DISABLED] node1.example.org capacity=0 node_type=hybrid version=X.Y.Z heartbeat="..." [DISABLED] node2.example.org capacity=0 node_type=execution version=ansible-runner-X.Y.Z heartbeat="..."Remove those nodes with
awx-manage, leaving only theaap-controller-taskinstance:awx-manage deprovision_instance --hostname=node1.example.org awx-manage deprovision_instance --hostname=node2.example.org
Repair orphaned automation hub content links for Pulp.
Run the following command from any host that has direct access to the automation hub address:
$ curl -d '{\"verify_checksums\": true }' -X POST -k https://<gateway url>/api/galaxy/pulp/api/v3/repair/ -u <gateway_admin_user>:<gateway_admin_password>
Reconcile instance groups configuration:
-
Go to
. - Select the Instance Group and then select the Instances tab.
- Associate or disassociate instances as required.
-
Go to
Reconcile decision environments and credentials:
-
Go to
. - Edit each decision environment which references a registry URL either unrelated or no longer accessible to this new environment. For example, the automation hub decision environment might require modification for the target automation hub environment.
- Select each associated credential to these decision environments and ensure their addresses align with the new environment.
-
Go to
Reconcile execution environments and credentials:
-
Go to
. - Check each execution environment image and verify their addresses against the new environment.
-
Go to
. - Edit each credential and ensure that all environment specific information aligns with the new environment.
-
Go to
- Verify any further customizations or configurations after the migration, such as RBAC rules with instance groups.
7.1.4. Validating the target environment 링크 복사링크가 클립보드에 복사되었습니다!
After completing the migration, validate that all components in your target environment function correctly.
Procedure
Verify all migrated components function correctly.
-
Platform gateway: Access the Ansible Automation Platform URL at
https://<gateway_hostname>/and verify that the dashboard loads correctly. Check that the platform gateway service is running and connected to automation controller. - Automation controller: Under Automation Execution, check that projects, inventories, and job templates are present and configured.
- Automation hub: Under Automation Content, verify that collections, namespaces, and their contents are visible.
- Event-Driven Ansible (if applicable): Under Automation Execution Decisions, verify that rule audits, rulebook activations, and projects are accessible.
For each component, check the logs to ensure there are no startup errors or warnings:
podman logs <container_name>
-
Platform gateway: Access the Ansible Automation Platform URL at
Test workflows and automation processes.
- Run job templates: Run several key job templates, including those with dependencies on various credential types.
- Test workflow templates: Run workflow templates to ensure that workflow nodes run in the correct order and that the workflow completes successfully.
- Verify execution environments: Ensure that jobs run in the appropriate execution environments and can access required dependencies.
- Check job artifacts: Verify that job artifacts are properly stored and accessible.
- Validate job scheduling: Test scheduled jobs to ensure they run at the expected times.
Validate user access and permissions.
- User authentication: Test login functionality with various user accounts to ensure authentication works correctly.
- Role-based access controls: Verify that users have appropriate permissions for organizations, projects, inventories, and job templates.
- Team memberships: Confirm that team memberships and team-based permissions are intact.
- API access: Test API tokens and ensure that API access is functioning properly.
- SSO integration (if applicable): Verify that Single Sign-On authentication is working correctly.
Confirm content synchronization and availability.
- Collection synchronization: Check that you can synchronize collections from a remote.
- Collection Upload: Check that you can upload collections.
- Collection repositories: Verify that automation hub makes collections available and that execution environments can use them.
- Project synchronization: Check that projects can sync content from source control repositories.
- External content sources: Test synchronization from automation hub and Ansible Galaxy (if configured).
- Execution environment availability: Confirm that all required execution environments exist and that execution nodes can access them.
- Content dependencies: Verify that the system correctly resolves content dependencies when running jobs.