Installing Hybrid Manager on AWS EKS#
You can install Hybrid Manager (HM) on Amazon EKS using Helm and the bootstrap kit.
Important
Completed the Prerequisites for AI Factory on Hybrid Manager before you start this part of the installation process.
Set the version to install#
The version of the EDB Software Deployment platform is set by the environment variable EDB_PLATFORM_VERSION. This should be set to the version of the platform you wish to install. For example, to install version v1.2.0, you would set the environment variable as follows:
export EDB_PLATFORM_VERSION="v1.2.0"
Set your token#
This installation process requires that you save your EDB subscription token as an environment variable. You can obtain it by going to your EDB Account Profile . (Log in if prompted to.) There you will find an entry for Repos 2.0 token:
Repo Token#
Take this value and set it as an environment variable:
export EDB_SUBSCRIPTION_TOKEN="your-token"
Obtain the bootstrap kit#
Hybrid Manager is installed using a bootstrap kit. This kit is a collection of scripts and Helm charts that are used to install the EDB Software Deployment platform.
Copy all files to a directory on your local machine and cd into that
directory.
Install secrets#
The bootstrap process requires a number of secrets to be installed in the Kubernetes cluster. These secrets are used to authenticate with the EDB Download Repository and to store the credentials for the EDB Software Deployment platform.
to install the secrets required for the bootstrap process, run the
install-secrets.sh script. (As you already set the token as an
environment variable, you can pipe it into the script.)
echo $EDB_SUBSCRIPTION_TOKEN | $SHELL eks-install-secrets.sh
Enter the password for pgai-platform@docker.enterprisedb.com
Creating secret edb-cred
namespace/upm-replicator configured
secret/edb-cred configured
namespace/edbpgai-bootstrap configured
secret/edb-cred configured
secret/edb-cred annotated
PG_CONFOUNDING_KEY is 01234567890123456789ABCDEFG - store safely
Installation completed
This process creates secrets needed for Hybrid Manager to run. You can find out more about these secrets in:
** A secret for Griptape and DeltaLake object storage configuration (optional for GenAI Builder)**
** A secret for Catalog (optional for using Catalog)**
See also ** custom secrets for Migration Portal (optional to secure internal communications with Migration Portal)**
Prepare the values file#
The bootstrap process requires a number of values to be set in the Helm
chart. These values are stored in a file called values.yaml . You
can create this file by running the prepare.sh script, which uses
variables from the default-env.sh file. Edit the default-env.sh
file to set the values you require.
This is the default default-env.sh file:
# exports for EKS
export EDB_PLATFORM_VERSION="v1.2.0"
export EDB_TARGET_PLATFORM="eks"
export CONTAINER_REGISTRY_URI="docker.enterprisedb.com/pgai-platform"
export IMAGESET_REGISTRY_URI=$CONTAINER_REGISTRY_URI
export IMAGESET_AUTHTYPE="token"
export PORTAL_DOMAIN_NAME="portal.foo.network"
export TRANSPORTER_RW_SERVICE_DOMAIN_NAME="transporter.foo.network"
export BEACON_SERVICE_DOMAIN_NAME="beacon.foo.network"
export AUTHENTICATION_EMAIL="owner@mycompany.com"
export AUTHENTICATION_USER="owner@mycompany.com"
export LOCATION_NAME="default-location"
# Set a password hash for the user or pass a password to have it hashed for you.
# If you pass a password, you will need to remove it from your history.
# You can hash a password using the following command:
# echo -n "password" | htpasswd -BinC 10 admin | cut -d: -f2
#
# export AUTHENTICATION_PASSWORD="password"
export AUTHENTICATION_PASSWORD_HASH="$2y$10$vKOAXfLHbeV1OQxMpxlLdOIwnX.JAN.ZrD9ZU//ocrNQwhQIMtXhy"
Here is a brief guide to the variables in the default-env.sh file.
Variable |
Description |
|---|---|
EDB_TARGET_PLATFORM |
The target platform for the installation. Set to eks as we are installing on Amazon EKS. |
CONTAINER_REGISTRY_URI |
The URI of the container registry to use. This is set to the EDB Download Repository. |
IMAGESET_REGISTRY_URI |
The URI of the image set registry. This is set to the EDB Download Repository. |
IMAGESET_AUTHTYPE |
The authentication type for the image set registry. Set to token as we are using a token to authenticate with the EDB Download Repository. |
PORTAL_DOMAIN_NAME |
The domain will serve as the public URL for accessing the HM Console. See recommendation below. |
TRANSPORTER_RW_SERVICE_DOMAIN_NAME |
The domain name for the Data Migration Service (internally transporter). See recommendation below. |
BEACON_SERVICE_DOMAIN_NAME |
The domain name for the beacon service. |
AUTHENTICATION_EMAIL |
The email address of the user to create. |
AUTHENTICATION_USER |
The username of the user to create. |
AUTHENTICATION_PASSWORD |
The password of the user to create. This can be set as plain text or as a hash with AUTHENTICATION_PASSWORD_HASH. |
AUTHENTICATION_PASSWORD_HASH |
The hash of the password to create. |
LOCATION_NAME |
The location name for the Agent, formerly known as Beacon Agent. |
!!!note Recommendations for PORTAL_DOMAIN_NAME and TRANSPORTER_RW_SERVICE_DOMAIN_NAME
For consistency and ease of management, derive your
TRANSPORTER_RW_SERVICE_DOMAIN_NAME from your PORTAL_DOMAIN_NAME. The
most common approach is to replace the portal subdomain with dms
.
The following table illustrates this relationship using a variety of
examples based on the top-level domain examplecompany.com .
PORTAL_DOMAIN_NAME |
TRANSPORTER_RW_SERVICE_DOMAIN_NAME |
|---|---|
portal.examplecompany.com |
dms.examplecompany.com |
portal-dev.examplecompany.com |
dms-dev.examplecompany.com |
portal.hm001.examplecompany.com |
dms.hm001.examplecompany.com |
portal-hm-us-east-001.examplecompany.com |
dms-hm-us-east-001.examplecompany.com |
Run the prepare.sh script to create the values.yaml file.
$SHELL prepare.sh
This create a values.yaml file with the values set in the
default-env.sh file.
Install the Helm chart repo with the following command:
helm repo add edbpgai "https://downloads.enterprisedb.com/${EDB_SUBSCRIPTION_TOKEN}/pgai-platform/helm/charts"
Once the charts repository is added, ensure it is up to date:
helm repo update
Now you can create the values.yaml file from the helm repo using the
following command:
helm show values edbpgai/edbpgai-bootstrap > values.yaml
You now have a values.yaml file with the chart’s default values for
the bootstrap process.
You need to create two values for the bootstrap process. These are the AES_256_KEY and the AUTHENTICATION_PASSWORD_HASH. You can create these values with the following commands:
export AES_256_KEY=$(openssl rand -base64 32)
If you have a password to hash, you can do so with the following command:
export AUTHENTICATION_PASSWORD_HASH=$(echo -n $AUTHENTICATION_PASSWORD | htpasswd -BinC 10 admin | cut -d: -f2)
You now need to edit values.yaml file and set the values required
for your installation. Find the appropriate key in the values.yaml
file and set the values as follows. Replace $<name> entries with the
value you have set the environment variables of the same name to.
Sets
bootstrapImageNameto $CONTAINER_REGISTRY_URI followed by “/edbpgai-bootstrap/bootstrap-” and then $EDB_TARGET_PLATFORM. eg, given the values above, this would bedocker.enterprisedb.com/pgai-platform/edbpgai-bootstrap/bootstrap-eks.Set
bootstrapImageTagto $EDB_PLATFORM_VERSION.Set
parameters.upm-istio.cookie_aeskeyto $AES_256_KEY.Set
containerRegistryURLto $CONTAINER_REGISTRY_URI.Set
systemto $EDB_TARGET_PLATFORM.Set
parameters.global.portal_domain_nameto $PORTAL_DOMAIN_NAME.Set
parameters.transporter-rw-service.domain_nameto $TRANSPORTER_RW_SERVICE_DOMAIN_NAME.Set
parameters.transporter-dp-agent.rw_service_urltohttps://followed by $TRANSPORTER_RW_SERVICE_DOMAIN_NAME followed by/transporter. Following the first of the previously provided examples, this would behttps://dms.examplecompany.com/transporter.Set
parameters.upm-beacon.server_hostto $BEACON_SERVICE_DOMAIN_NAME. 10. Setpgai.portal.authentication.staticPasswords[0].emailto $AUTHENTICATION_EMAIL. 11. Setpgai.portal.authentication.staticPasswords[0].hashto $AUTHENTICATION_PASSWORD_HASH. 12. Setpgai.portal.authentication.staticPasswords[0].usernameto $AUTHENTICATION_USER. 13. Setpgai.portal.authentication.staticPasswords[0].userID“c5998173-a605-449a-a9a5-4a9c33e26df”. 14. SetbeaconAgent.locationto $LOCATION_NAME
Apply the Helm chart#
With the values.yaml file prepared, you can apply the Helm chart to
start the bootstrap process. This create the necessary resources in the
Kubernetes cluster to start the bootstrap process.
helm upgrade -n edbpgai-bootstrap \
--install -f ./values.yaml \
--version "${EDB_PLATFORM_VERSION/-appl/+appl}" \
edbpgai-bootstrap edbpgai/edbpgai-bootstrap
This command installs the bootstrap container in the Kubernetes cluster. The bootstrap container then installs the rest of the EDB Software Deployment platform.
Follow the bootstrap process#
The bootstrap process takes time to complete. You can follow the progress by looking at the logs of the bootstrap container:
kubectl logs -f -l app=edbpgai-bootstrap -n edbpgai-bootstrap
Configure host name resolution#
Obtain the IP address of your ingress gateway. Run:
kubectl -n istio-system get service istio-ingressgateway -o jsonpath={.status.loadBalancer.ingress[0].hostname} | strings | nslookup
This command returns output like:
Server: 192.168.111.1
Address: 192.168.111.1#53
Non-authoritative answer:
Name: k8s-istiosys-istioing-b3dc9b4f3c-81dc5c45b1d5f6d2.elb.us-east-1.amazonaws.com
Address: 52.70.180.102
You now need to configure your DNS service or your /etc/hosts file
to point the domains specified in default-env.sh to the IP address
you obtained from the command above. Those domains are in
PORTAL_DOMAIN_NAME , TRANSPORTER_RW_SERVICE_DOMAIN_NAME , and
BEACON_SERVICE_DOMAIN_NAME . In the example above, they are set to
portal.examplecompany.com , dms.examplecompany.com , and
beacon.examplecompany.com respectively.
Configure DNS#
In your DNS configuration, create a CNAME record for each of these
domains that points to the IP address you obtained. So for our example,
you would create the following records in your DNS zone file for
examplecompany.com :
cluster IN A 52.70.180.102
portal IN CNAME cluster.examplecompany.com
transporter IN CNAME cluster.examplecompany.com
beacon IN CNAME cluster.examplecompany.com
This is a simplified example. The actual configuration will depend on your DNS provider and how you manage your DNS records.
Configure /etc/hosts (if no DNS service)#
If you don’t have a DNS service configured, consider adding the IP
address to your local /etc/hosts file. This addition allows you to
access Hybrid Manager Console using the domain name you set in the
default-env.sh file.
You can then add the IP address to your /etc/hosts file like this:
echo "52.70.180.102 portal.examplecompany.com dms.examplecompany.com beacon.examplecompany.com" | sudo tee -a /etc/hosts
Substitute the IP address with the value you obtained earlier. This is a
temporary solution and should not be used in production environments. We
recommend that you use a proper DNS service for production deployments.
The settings in the /etc/hosts file work only on the machine where
you set them.
Next steps#
You can now verify the installation by connecting to the HM Console .
default-env.sh#
# exports for EKS
export EDB_PLATFORM_VERSION="v1.2.0"
export EDB_TARGET_PLATFORM="eks"
export CONTAINER_REGISTRY_URI="docker.enterprisedb.com/pgai-platform"
export IMAGESET_REGISTRY_URI=$CONTAINER_REGISTRY_URI
export IMAGESET_AUTHTYPE="token"
export PORTAL_DOMAIN_NAME="portal.foo.network"
export TRANSPORTER_RW_SERVICE_DOMAIN_NAME="transporter.foo.network"
export BEACON_SERVICE_DOMAIN_NAME="beacon.foo.network"
export AUTHENTICATION_EMAIL="owner@mycompany.com"
export AUTHENTICATION_USER="owner@mycompany.com"
export LOCATION_NAME="default-location"
# Set a password hash for the user or pass a password to have it hashed for you.
# If you pass a password, you will need to remove it from your history.
# You can hash a password using the following command:
# echo -n "password" | htpasswd -BinC 10 admin | cut -d: -f2
#
# export AUTHENTICATION_PASSWORD="password"
# If setting AUTHENTICATION_PASSWORD_HASH, ensure it is single quoted to prevent variable expansion (e.g. $2y$10$...).
export AUTHENTICATION_PASSWORD_HASH=$2y$10$vKOAXfLHbeV1OQxMpxlLdOIwnX.JAN.ZrD9ZU//ocrNQwhQIMtXhy
eks-install-secrets.sh#
registry="docker.enterprisedb.com"
username="pgai-platform"
password=""
echo "Enter the password for ${username}@${registry}"
read -s password
if [ -z "$password" ]; then
echo 1>&2 "Error: password is required" >&2
echo 1>&2
usage
exit 1
fi
kubectl create ns edbpgai-bootstrap
kubectl create ns upm-replicator
kubectl create secret docker-registry edb-cred \
-n edbpgai-bootstrap \
--docker-server="${registry}" \
--docker-username="${username}" \
--docker-password="${password}"
kubectl create secret docker-registry edb-cred \
-n upm-replicator \
--docker-server="${registry}" \
--docker-username="${username}" \
--docker-password="${password}"
kubectl annotate secret -n upm-replicator edb-cred replicator.v1.mittwald.de/replicate-to="*" --overwrite
kubectl create namespace upm-griptape
FERNET_KEY=$(dd if=/dev/urandom bs=32 count=1 2>/dev/null | base64)
kubectl apply -f - <<EOF
apiVersion: v1
kind: Secret
metadata:
name: fernet-secret
namespace: upm-griptape
stringData:
FERNET_KEY: ${FERNET_KEY}
EOF
kubectl create namespace upm-lakekeeper
PG_CONFOUNDING_KEY=$(dd if=/dev/urandom bs=32 count=1 2>/dev/null | base64)
kubectl apply -f - <<EOF
apiVersion: v1
kind: Secret
metadata:
name: pg-confounding-key
namespace: upm-lakekeeper
stringData:
PG_CONFOUNDING_KEY: ${PG_CONFOUNDING_KEY}
EOF
echo "PG_CONFOUNDING_KEY is ${PG_CONFOUNDING_KEY} - store safely"
prepare.sh#
# !/bin/bash
echo "HM Helm values.yaml preparation\n"
# If EDB_PLATFORM_VERSION is not set, error and exit
if [ -z "$EDB_PLATFORM_VERSION" ]; then
echo "EDB_PLATFORM_VERSION is not set, please set it to the version of EDB Platform you are deploying"
exit
fi
# Test for the presence of yq
if ! command -v yq &> /dev/null
then
echo "yq could not be found, please install it"
exit
fi
# Import the eks-default-env file
source ./default-env.sh
# Test for presence of helm repo
value=`helm repo list -o yaml | yq eval contains([{ "name":"edbpgai"}]) -`
if [[ "$value" == "false" ]]; then
echo "EDB Platform Helm repository not found, adding in now"
helm repo add edbpgai "https://downloads.enterprisedb.com/${EDB_SUBSCRIPTION_TOKEN}/pgai-platform/helm/charts/"
fi
# Always update the helm repo
helm repo update
helm show values edbpgai/edbpgai-bootstrap --version $EDB_PLATFORM_VERSION > values.yaml
echo "\n\n"
# Prepare version dependent values
export AES_256_KEY=$(openssl rand -base64 32)
if [[ "$EDB_PLATFORM_VERSION" == v1.2.* ]]; then
echo "EDB Platform version is v1.2.*"
yq -i .bootstrapImageName = env(CONTAINER_REGISTRY_URI)+"/edbpgai-bootstrap/bootstrap-"+env(EDB_TARGET_PLATFORM) |
.bootstrapImageTag=env(EDB_PLATFORM_VERSION) |
del(.bootstrapImage) |
.parameters.upm-istio-gateway.cookie_aeskey = env(AES_256_KEY) |
del(.parameters.upm-beacon-ff-base) |
.beaconAgent.provisioning.imagesetDiscoveryContainerRegistryURL= env(IMAGESET_REGISTRY_URI) |
.beaconAgent.provisioning.imagesetDiscoveryContainerRegistryAuthType= env(IMAGESET_AUTHTYPE) |
.containerRegistryURL = env(CONTAINER_REGISTRY_URI) values.yaml
fi
# Prepare values.yaml for EKS
# if AUTHENTICATION_PASSWORD_HASH is not set, generate it
if [ -z "$AUTHENTICATION_PASSWORD_HASH" ]; then
echo "Generating password hash - please ensure you remove the password from your history"
export AUTHENTICATION_PASSWORD_HASH=$(echo -n $AUTHENTICATION_PASSWORD | htpasswd -BinC 10 admin | cut -d: -f2)
else
echo "Using prehashed password"
fi
yq -i .system = env(EDB_TARGET_PLATFORM) |
.parameters.global.portal_domain_name = env(PORTAL_DOMAIN_NAME) |
.parameters.transporter-rw-service.domain_name = env(TRANSPORTER_RW_SERVICE_DOMAIN_NAME) |
.parameters.transporter-dp-agent.rw_service_url= "https://"+env(TRANSPORTER_RW_SERVICE_DOMAIN_NAME)+"/transporter" |
.parameters.upm-beacon.server_host= env(BEACON_SERVICE_DOMAIN_NAME) |
.pgai.portal.authentication.staticPasswords[0].email=env(AUTHENTICATION_EMAIL) |
.pgai.portal.authentication.staticPasswords[0].hash=env(AUTHENTICATION_PASSWORD_HASH) |
.pgai.portal.authentication.staticPasswords[0].username=env(AUTHENTICATION_USER) |
.pgai.portal.authentication.staticPasswords[0].userID="c5998173-a605-449a-a9a5-4a9c33e26df" |
.beaconAgent.location=env(LOCATION_NAME) values.yaml
echo "Your values.yaml file is ready"