MongoDB Ops Manager 데이터 백업, 데이터베이스 성능 모니터링 등과 같은 워크로드를 원활하게 처리하는 역할을 합니다. 멀티 클러스터 MongoDB Ops Manager 및 애플리케이션 데이터베이스 배포서버 전체 데이터 센터 또는 구역 장애에 대해 복원력 있게 만들려면 MongoDB Ops Manager 애플리케이션 및 애플리케이션 데이터베이스를 여러 Kubernetes 클러스터에 배포 .
전제 조건
다음 절차를 시작하기 전에 다음 조치를 수행하세요.
kubectl설치.GKE 클러스터 절차 또는 이에 상응하는 절차를 완료합니다.
TLS 인증서 절차 또는 이에 상응하는 절차를 완료합니다.
ExternalDNS 절차 또는 이에 상응하는 절차를 완료합니다.
MongoDB 연산자 배포 절차를 완료합니다.
다음과 같이 필수 환경 변수를 설정합니다.
# This script builds on top of the environment configured in the setup guides. # It depends (uses) the following env variables defined there to work correctly. # If you don't use the setup guide to bootstrap the environment, then define them here. # ${K8S_CLUSTER_0_CONTEXT_NAME} # ${K8S_CLUSTER_1_CONTEXT_NAME} # ${K8S_CLUSTER_2_CONTEXT_NAME} # ${OM_NAMESPACE} # ${CUSTOM_DOMAIN} # ${DNS_ZONE} # Defaults for the RustFS setup module and the MongoDBOpsManager backup stores. # If you use your own S3 storage - override any of these. export S3_OPLOG_BUCKET_NAME="${S3_OPLOG_BUCKET_NAME:-s3-oplog-store}" export S3_SNAPSHOT_BUCKET_NAME="${S3_SNAPSHOT_BUCKET_NAME:-s3-snapshot-store}" export S3_ENDPOINT="${S3_ENDPOINT:-rustfs.rustfs.svc.cluster.local}" export S3_ACCESS_KEY="${S3_ACCESS_KEY:-rustfsadmin}" export S3_SECRET_KEY="${S3_SECRET_KEY:-rustfsadmin123}" export OPS_MANAGER_VERSION="8.0.5" export APPDB_VERSION="8.0.5-ent" export OPS_MANAGER_EXTERNAL_DOMAIN="opsmanager.${CUSTOM_DOMAIN}" export APPDB_CLUSTER_0_EXTERNAL_DOMAIN="${K8S_CLUSTER_0}.${CUSTOM_DOMAIN}" export APPDB_CLUSTER_1_EXTERNAL_DOMAIN="${K8S_CLUSTER_1}.${CUSTOM_DOMAIN}" export APPDB_CLUSTER_2_EXTERNAL_DOMAIN="${K8S_CLUSTER_2}.${CUSTOM_DOMAIN}" # Run-scoped names for project-global GCP load balancer resources (KUBE-268). # Multiple CI runs share the same GCP project; with fixed global names, one run's # pre-clean/teardown deletes a concurrent run's load balancer mid-flight. # Derive the run-specific suffix from ${DNS_ZONE} (set in the ExternalDNS setup # guide). For docs users there is no run suffix and the names stay unchanged. lb_suffix="${DNS_ZONE#"mongodb"}" export OM_FIREWALL_RULE_NAME="fw-ops-manager-hc${lb_suffix}" export OM_HEALTHCHECK_NAME="om-healthcheck${lb_suffix}" export OM_BACKEND_SERVICE_NAME="om-backend-service${lb_suffix}" export OM_URL_MAP_NAME="om-url-map${lb_suffix}" export OM_LB_PROXY_NAME="om-lb-proxy${lb_suffix}" export OM_CERTIFICATE_NAME="om-certificate${lb_suffix}" export OM_FORWARDING_RULE_NAME="om-forwarding-rule${lb_suffix}" # Retry wrapper for gcloud commands to handle transient GCP API errors # (ConnectionError, RemoteDisconnected, etc.). Functions are inherited by # subshells, so this is available inside snippet functions run by sample_test_runner. gcloud_retry() { for attempt in 1 2 3; do if gcloud "$@"; then return 0; fi if (( attempt < 3 )); then echo "gcloud failed (attempt ${attempt}/3), retrying in $((attempt * 5))s..." >&2 sleep $((attempt * 5)) fi done return 1 }
소스 코드
포함된 모든 소스 코드 MongoDB Kubernetes Operator 리포지토리 에서 찾을 수 있습니다.
절차
TLS 인증서를 생성합니다.
kubectl --context "${K8S_CLUSTER_0_CONTEXT_NAME}" -n "${OM_NAMESPACE}" apply -f - <<EOF apiVersion: cert-manager.io/v1 kind: Certificate metadata: name: om-cert spec: dnsNames: - ${OPS_MANAGER_EXTERNAL_DOMAIN} duration: 240h0m0s issuerRef: name: my-ca-issuer kind: ClusterIssuer renewBefore: 120h0m0s secretName: cert-prefix-om-cert usages: - server auth - client auth --- apiVersion: cert-manager.io/v1 kind: Certificate metadata: name: om-db-cert spec: dnsNames: - "*.${APPDB_CLUSTER_0_EXTERNAL_DOMAIN}" - "*.${APPDB_CLUSTER_1_EXTERNAL_DOMAIN}" - "*.${APPDB_CLUSTER_2_EXTERNAL_DOMAIN}" duration: 240h0m0s issuerRef: name: my-ca-issuer kind: ClusterIssuer renewBefore: 120h0m0s secretName: cert-prefix-om-db-cert usages: - server auth - client auth EOF
GCP 에 TLS 인증서를 추가합니다.
mkdir -p certs kubectl --context "${K8S_CLUSTER_0_CONTEXT_NAME}" -n "${OM_NAMESPACE}" get secret cert-prefix-om-cert -o jsonpath="{.data['tls\.crt']}" | base64 --decode > certs/tls.crt kubectl --context "${K8S_CLUSTER_0_CONTEXT_NAME}" -n "${OM_NAMESPACE}" get secret cert-prefix-om-cert -o jsonpath="{.data['tls\.key']}" | base64 --decode > certs/tls.key gcloud_retry compute ssl-certificates create "${OM_CERTIFICATE_NAME}" --certificate=certs/tls.crt --private-key=certs/tls.key
로드 밸런서 에 필요한 Kubernetes 구성 요소를 만듭니다.
이 로드 밸런서 모든 3 클러스터에 걸쳐 MongoDB Ops Manager 의 모든 복제본 간에 트래픽을 분산합니다.
gcloud_retry compute firewall-rules create "${OM_FIREWALL_RULE_NAME}" \ --action=allow \ --direction=ingress \ --target-tags=mongodb \ --source-ranges=130.211.0.0/22,35.191.0.0/16 \ --rules=tcp:8443 gcloud_retry compute health-checks create https "${OM_HEALTHCHECK_NAME}" \ --use-serving-port \ --request-path=/monitor/health gcloud_retry compute backend-services create "${OM_BACKEND_SERVICE_NAME}" \ --protocol HTTPS \ --health-checks "${OM_HEALTHCHECK_NAME}" \ --global gcloud_retry compute url-maps create "${OM_URL_MAP_NAME}" \ --default-service "${OM_BACKEND_SERVICE_NAME}" gcloud_retry compute target-https-proxies create "${OM_LB_PROXY_NAME}" \ --url-map "${OM_URL_MAP_NAME}" \ --ssl-certificates="${OM_CERTIFICATE_NAME}" gcloud_retry compute forwarding-rules create "${OM_FORWARDING_RULE_NAME}" \ --global \ --target-https-proxy="${OM_LB_PROXY_NAME}" \ --ports=443
NAME NETWORK DIRECTION PRIORITY ALLOW DENY DISABLED fw-ops-manager-hc-6abb9ad2xf80-15370 default INGRESS 1000 tcp:8443 False NAME PROTOCOL om-healthcheck-6abb9ad2xf80-15370 HTTPS NAME BACKENDS PROTOCOL om-backend-service-6abb9ad2xf80-15370 HTTPS NAME DEFAULT_SERVICE om-url-map-6abb9ad2xf80-15370 backendServices/om-backend-service-6abb9ad2xf80-15370 NAME SSL_CERTIFICATES URL_MAP REGION CERTIFICATE_MAP om-lb-proxy-6abb9ad2xf80-15370 om-certificate-6abb9ad2xf80-15370 om-url-map-6abb9ad2xf80-15370
MongoDB Ops Manager 관리자의 자격 증명 생성합니다.
kubectl --context "${K8S_CLUSTER_0_CONTEXT_NAME}" --namespace "${OM_NAMESPACE}" create secret generic om-admin-user-credentials \ --from-literal=Username="admin" \ --from-literal=Password="Passw0rd@" \ --from-literal=FirstName="Jane" \ --from-literal=LastName="Doe"
MongoDB Ops Manager 배포합니다.
kubectl apply --context "${K8S_CLUSTER_0_CONTEXT_NAME}" -n "${OM_NAMESPACE}" -f - <<EOF apiVersion: mongodb.com/v1 kind: MongoDBOpsManager metadata: name: om spec: topology: MultiCluster version: "${OPS_MANAGER_VERSION}" adminCredentials: om-admin-user-credentials externalConnectivity: type: ClusterIP annotations: cloud.google.com/neg: '{"exposed_ports": {"8443":{}}}' opsManagerURL: "https://${OPS_MANAGER_EXTERNAL_DOMAIN}" security: certsSecretPrefix: cert-prefix tls: ca: ca-issuer clusterSpecList: - clusterName: "${K8S_CLUSTER_0_CONTEXT_NAME}" members: 1 - clusterName: "${K8S_CLUSTER_1_CONTEXT_NAME}" members: 2 applicationDatabase: version: "${APPDB_VERSION}" topology: MultiCluster security: certsSecretPrefix: cert-prefix tls: ca: ca-issuer clusterSpecList: - clusterName: "${K8S_CLUSTER_0_CONTEXT_NAME}" members: 2 externalAccess: externalDomain: "${APPDB_CLUSTER_0_EXTERNAL_DOMAIN}" externalService: annotations: external-dns.alpha.kubernetes.io/hostname: "{podName}.${APPDB_CLUSTER_0_EXTERNAL_DOMAIN}" - clusterName: "${K8S_CLUSTER_1_CONTEXT_NAME}" members: 2 externalAccess: externalDomain: "${APPDB_CLUSTER_1_EXTERNAL_DOMAIN}" externalService: annotations: external-dns.alpha.kubernetes.io/hostname: "{podName}.${APPDB_CLUSTER_1_EXTERNAL_DOMAIN}" - clusterName: "${K8S_CLUSTER_2_CONTEXT_NAME}" members: 1 externalAccess: externalDomain: "${APPDB_CLUSTER_2_EXTERNAL_DOMAIN}" externalService: annotations: external-dns.alpha.kubernetes.io/hostname: "{podName}.${APPDB_CLUSTER_2_EXTERNAL_DOMAIN}" backup: enabled: false EOF
Kubernetes Operator가 보류 중 상태 될 때까지 기다립니다.
애플리케이션 데이터베이스와 MongoDB Ops Manager 배포가 모두 완료될 때까지 기다립니다.
echo "Waiting for Application Database to reach Pending phase..." kubectl --context "${K8S_CLUSTER_0_CONTEXT_NAME}" -n "${OM_NAMESPACE}" wait --for=jsonpath='{.status.applicationDatabase.phase}'=Pending opsmanager/om --timeout=30s echo "Waiting for Ops Manager to reach Pending phase..." kubectl --context "${K8S_CLUSTER_0_CONTEXT_NAME}" -n "${OM_NAMESPACE}" wait --for=jsonpath='{.status.opsManager.phase}'=Pending opsmanager/om --timeout=600s
Waiting for Application Database to reach Pending phase... mongodbopsmanager.mongodb.com/om condition met Waiting for Ops Manager to reach Pending phase... mongodbopsmanager.mongodb.com/om condition met
로드 밸런서 서비스를 설정합니다.
svcneg0=$(kubectl --context "${K8S_CLUSTER_0_CONTEXT_NAME}" -n "${OM_NAMESPACE}" get svcneg -o=jsonpath='{.items[0].metadata.name}') kubectl --context "${K8S_CLUSTER_0_CONTEXT_NAME}" -n "${OM_NAMESPACE}" \ wait svcneg "${svcneg0}" --for=condition=Initialized --timeout=300s \ || { kubectl --context "${K8S_CLUSTER_0_CONTEXT_NAME}" -n "${OM_NAMESPACE}" get svcneg "${svcneg0}" -o yaml; exit 1; } gcloud_retry compute backend-services add-backend "${OM_BACKEND_SERVICE_NAME}" \ --global \ --network-endpoint-group="${svcneg0}" \ --network-endpoint-group-zone="${K8S_CLUSTER_0_ZONE}" \ --balancing-mode RATE --max-rate-per-endpoint 5
svcneg1=$(kubectl --context "${K8S_CLUSTER_1_CONTEXT_NAME}" -n "${OM_NAMESPACE}" get svcneg -o=jsonpath='{.items[0].metadata.name}') kubectl --context "${K8S_CLUSTER_1_CONTEXT_NAME}" -n "${OM_NAMESPACE}" \ wait svcneg "${svcneg1}" --for=condition=Initialized --timeout=300s \ || { kubectl --context "${K8S_CLUSTER_1_CONTEXT_NAME}" -n "${OM_NAMESPACE}" get svcneg "${svcneg1}" -o yaml; exit 1; } gcloud_retry compute backend-services add-backend "${OM_BACKEND_SERVICE_NAME}" \ --global \ --network-endpoint-group="${svcneg1}" \ --network-endpoint-group-zone="${K8S_CLUSTER_1_ZONE}" \ --balancing-mode RATE --max-rate-per-endpoint 5
MongoDB Ops Manager 실행 상태 될 때까지 기다립니다.
echo "Waiting for Application Database to reach Running phase..." kubectl --context "${K8S_CLUSTER_0_CONTEXT_NAME}" -n "${OM_NAMESPACE}" wait --for=jsonpath='{.status.applicationDatabase.phase}'=Running opsmanager/om --timeout=1200s echo; echo "Waiting for Ops Manager to reach Running phase..." kubectl --context "${K8S_CLUSTER_0_CONTEXT_NAME}" -n "${OM_NAMESPACE}" wait --for=jsonpath='{.status.opsManager.phase}'=Running opsmanager/om --timeout=1200s echo; echo "MongoDBOpsManager resource" kubectl --context "${K8S_CLUSTER_0_CONTEXT_NAME}" -n "${OM_NAMESPACE}" get opsmanager/om echo; echo "Pods running in cluster ${K8S_CLUSTER_0_CONTEXT_NAME}" kubectl --context "${K8S_CLUSTER_0_CONTEXT_NAME}" -n "${OM_NAMESPACE}" get pods echo; echo "Pods running in cluster ${K8S_CLUSTER_1_CONTEXT_NAME}" kubectl --context "${K8S_CLUSTER_1_CONTEXT_NAME}" -n "${OM_NAMESPACE}" get pods
Waiting for Application Database to reach Running phase... mongodbopsmanager.mongodb.com/om condition met Waiting for Ops Manager to reach Running phase... mongodbopsmanager.mongodb.com/om condition met MongoDBOpsManager resource NAME REPLICAS VERSION STATE (OPSMANAGER) STATE (APPDB) STATE (BACKUP) AGE WARNINGS om 8.0.5 Running Running Disabled 18m Pods running in cluster gke_scratch-kubernetes-team_europe-central2-a_k8s-mdb-0-6abb9ad27d6x076f80-15370 NAME READY STATUS RESTARTS AGE om-0-0 1/1 Running 0 15m om-db-0-0 2/2 Running 0 5m14s om-db-0-1 2/2 Running 0 6m15s Pods running in cluster gke_scratch-kubernetes-team_europe-central2-b_k8s-mdb-1-6abb9ad27d6x076f80-15370 NAME READY STATUS RESTARTS AGE om-1-0 1/1 Running 0 15m om-1-1 1/1 Running 0 10m om-db-1-0 2/2 Running 0 3m22s om-db-1-1 2/2 Running 0 4m20s
선택 사항. 테스트를 위해 S3호환 저장 배포합니다.
이 단계에서는 테스트 목적으로 간단한 RustFS 인스턴스 배포하는 스크립트 제공합니다. AWS S3 또는 기타 S3호환 버킷을 사용할 수 있는 경우 이 단계를 건너뛸 수 있습니다.
참고
RustFS는 테스트용이며 프로덕션에는 적합하지 않습니다. 프로덕션의 경우 자체 S3 저장 사용합니다.
kubectl --context "${K8S_CLUSTER_0_CONTEXT_NAME}" create namespace "${RUSTFS_NAMESPACE}" --dry-run=client -o yaml | \ kubectl --context "${K8S_CLUSTER_0_CONTEXT_NAME}" apply -f - kubectl --context "${K8S_CLUSTER_0_CONTEXT_NAME}" -n "${RUSTFS_NAMESPACE}" delete job rustfs-create-buckets --ignore-not-found=true || true kubectl --context "${K8S_CLUSTER_0_CONTEXT_NAME}" -n "${RUSTFS_NAMESPACE}" apply -f - <<EOF apiVersion: cert-manager.io/v1 kind: Certificate metadata: name: rustfs-cert spec: dnsNames: - rustfs.${RUSTFS_NAMESPACE}.svc.cluster.local duration: 240h0m0s issuerRef: name: my-ca-issuer kind: ClusterIssuer renewBefore: 120h0m0s secretName: rustfs-tls usages: - server auth --- apiVersion: v1 kind: Service metadata: name: rustfs labels: app: rustfs spec: selector: app: rustfs ports: - name: s3-https port: 443 targetPort: 9000 - name: s3 port: 9000 targetPort: 9000 --- apiVersion: apps/v1 kind: Deployment metadata: name: rustfs labels: app: rustfs spec: replicas: 1 selector: matchLabels: app: rustfs template: metadata: labels: app: rustfs annotations: # RustFS needs no mesh sidecar; keep behavior identical with and # without Istio. sidecar.istio.io/inject: "false" spec: securityContext: runAsNonRoot: true runAsUser: 10001 runAsGroup: 10001 fsGroup: 10001 seccompProfile: type: RuntimeDefault containers: - name: rustfs image: quay.io/rustfs/rustfs:1.0.0 securityContext: allowPrivilegeEscalation: false capabilities: drop: ["ALL"] runAsNonRoot: true env: - name: RUSTFS_ACCESS_KEY value: "${S3_ACCESS_KEY}" - name: RUSTFS_SECRET_KEY value: "${S3_SECRET_KEY}" - name: RUSTFS_VOLUMES value: /data - name: RUSTFS_ADDRESS value: 0.0.0.0:9000 - name: RUSTFS_CONSOLE_ENABLE value: "false" - name: RUSTFS_TLS_PATH value: /opt/tls ports: - name: s3 containerPort: 9000 readinessProbe: httpGet: scheme: HTTPS path: /health port: 9000 initialDelaySeconds: 5 periodSeconds: 3 volumeMounts: - name: data mountPath: /data - name: tls mountPath: /opt/tls readOnly: true volumes: - name: data emptyDir: {} - name: tls secret: secretName: rustfs-tls items: - key: tls.crt path: rustfs_cert.pem - key: tls.key path: rustfs_key.pem --- apiVersion: batch/v1 kind: Job metadata: name: rustfs-create-buckets spec: backoffLimit: 1 template: metadata: annotations: # istio-proxy keeps running after the aws-cli container exits, so an # injected Job never reaches Complete. sidecar.istio.io/inject: "false" spec: restartPolicy: Never containers: - name: aws-cli image: public.ecr.aws/aws-cli/aws-cli:latest env: - name: AWS_ACCESS_KEY_ID value: "${S3_ACCESS_KEY}" - name: AWS_SECRET_ACCESS_KEY value: "${S3_SECRET_KEY}" - name: AWS_DEFAULT_REGION value: us-east-1 - name: S3_ENDPOINT value: "https://${S3_ENDPOINT}" - name: S3_OPLOG_BUCKET_NAME value: "${S3_OPLOG_BUCKET_NAME}" - name: S3_SNAPSHOT_BUCKET_NAME value: "${S3_SNAPSHOT_BUCKET_NAME}" command: ["sh", "-ec"] args: - | aws_opts="--endpoint-url \$S3_ENDPOINT --no-verify-ssl --cli-connect-timeout 5 --cli-read-timeout 10" attempt=0 until aws \$aws_opts s3api list-buckets; do attempt=\$((attempt + 1)) if [ "\$attempt" -ge 24 ]; then echo "RustFS endpoint \$S3_ENDPOINT not reachable after \$attempt attempts" >&2 exit 1 fi sleep 5 done aws \$aws_opts s3api create-bucket --bucket "\$S3_OPLOG_BUCKET_NAME" aws \$aws_opts s3api create-bucket --bucket "\$S3_SNAPSHOT_BUCKET_NAME" EOF kubectl --context "${K8S_CLUSTER_0_CONTEXT_NAME}" -n "${RUSTFS_NAMESPACE}" wait --for=condition=available deployment/rustfs --timeout=300s kubectl --context "${K8S_CLUSTER_0_CONTEXT_NAME}" -n "${RUSTFS_NAMESPACE}" wait --for=condition=complete job/rustfs-create-buckets --timeout=240s
MongoDB Ops Manager 백업을 위한 Kubernetes 시크릿을 구성합니다.
kubectl --context "${K8S_CLUSTER_0_CONTEXT_NAME}" -n "${OM_NAMESPACE}" create secret generic s3-access-secret \ --from-literal=accessKey="${S3_ACCESS_KEY}" \ --from-literal=secretKey="${S3_SECRET_KEY}" RustFS serves a cert-manager certificate; OM must trust the CA that signed it. kubectl --context "${K8S_CLUSTER_0_CONTEXT_NAME}" -n "${OM_NAMESPACE}" create secret generic s3-ca-cert \ --from-literal=ca.crt="$(kubectl --context "${K8S_CLUSTER_0_CONTEXT_NAME}" -n "${RUSTFS_NAMESPACE}" get secret rustfs-tls -o jsonpath="{.data['ca\.crt']}" | base64 --decode)"
Ops Manager 에서 S3 백업을 활성화합니다.
kubectl apply --context "${K8S_CLUSTER_0_CONTEXT_NAME}" -n "${OM_NAMESPACE}" -f - <<EOF apiVersion: mongodb.com/v1 kind: MongoDBOpsManager metadata: name: om spec: topology: MultiCluster version: "${OPS_MANAGER_VERSION}" adminCredentials: om-admin-user-credentials externalConnectivity: type: ClusterIP annotations: cloud.google.com/neg: '{"exposed_ports": {"8443":{}}}' opsManagerURL: "https://${OPS_MANAGER_EXTERNAL_DOMAIN}" security: certsSecretPrefix: cert-prefix tls: ca: ca-issuer clusterSpecList: - clusterName: "${K8S_CLUSTER_0_CONTEXT_NAME}" members: 1 backup: members: 0 - clusterName: "${K8S_CLUSTER_1_CONTEXT_NAME}" members: 2 backup: members: 0 - clusterName: "${K8S_CLUSTER_2_CONTEXT_NAME}" members: 0 backup: members: 1 applicationDatabase: version: "${APPDB_VERSION}" topology: MultiCluster security: certsSecretPrefix: cert-prefix tls: ca: ca-issuer clusterSpecList: - clusterName: "${K8S_CLUSTER_0_CONTEXT_NAME}" members: 2 externalAccess: externalDomain: "${APPDB_CLUSTER_0_EXTERNAL_DOMAIN}" externalService: annotations: external-dns.alpha.kubernetes.io/hostname: "{podName}.${APPDB_CLUSTER_0_EXTERNAL_DOMAIN}" - clusterName: "${K8S_CLUSTER_1_CONTEXT_NAME}" members: 2 externalAccess: externalDomain: "${APPDB_CLUSTER_1_EXTERNAL_DOMAIN}" externalService: annotations: external-dns.alpha.kubernetes.io/hostname: "{podName}.${APPDB_CLUSTER_1_EXTERNAL_DOMAIN}" - clusterName: "${K8S_CLUSTER_2_CONTEXT_NAME}" members: 1 externalAccess: externalDomain: "${APPDB_CLUSTER_2_EXTERNAL_DOMAIN}" externalService: annotations: external-dns.alpha.kubernetes.io/hostname: "{podName}.${APPDB_CLUSTER_2_EXTERNAL_DOMAIN}" backup: enabled: true s3Stores: - name: my-s3-block-store s3SecretRef: name: "s3-access-secret" pathStyleAccessEnabled: true s3BucketEndpoint: "${S3_ENDPOINT}" s3BucketName: "${S3_SNAPSHOT_BUCKET_NAME}" customCertificateSecretRefs: - name: s3-ca-cert key: ca.crt s3OpLogStores: - name: my-s3-oplog-store s3SecretRef: name: "s3-access-secret" s3BucketEndpoint: "${S3_ENDPOINT}" s3BucketName: "${S3_OPLOG_BUCKET_NAME}" pathStyleAccessEnabled: true customCertificateSecretRefs: - name: s3-ca-cert key: ca.crt EOF
MongoDB Ops Manager 실행 상태 될 때까지 기다립니다.
echo; echo "Waiting for Backup to reach Running phase..." kubectl --context "${K8S_CLUSTER_0_CONTEXT_NAME}" -n "${OM_NAMESPACE}" wait --for=jsonpath='{.status.backup.phase}'=Running opsmanager/om --timeout=1200s echo "Waiting for Application Database to reach Running phase..." kubectl --context "${K8S_CLUSTER_0_CONTEXT_NAME}" -n "${OM_NAMESPACE}" wait --for=jsonpath='{.status.applicationDatabase.phase}'=Running opsmanager/om --timeout=1200s echo; echo "Waiting for Ops Manager to reach Running phase..." kubectl --context "${K8S_CLUSTER_0_CONTEXT_NAME}" -n "${OM_NAMESPACE}" wait --for=jsonpath='{.status.opsManager.phase}'=Running opsmanager/om --timeout=1200s echo; echo "MongoDBOpsManager resource" kubectl --context "${K8S_CLUSTER_0_CONTEXT_NAME}" -n "${OM_NAMESPACE}" get opsmanager/om echo; echo "Pods running in cluster ${K8S_CLUSTER_0_CONTEXT_NAME}" kubectl --context "${K8S_CLUSTER_0_CONTEXT_NAME}" -n "${OM_NAMESPACE}" get pods echo; echo "Pods running in cluster ${K8S_CLUSTER_1_CONTEXT_NAME}" kubectl --context "${K8S_CLUSTER_1_CONTEXT_NAME}" -n "${OM_NAMESPACE}" get pods echo; echo "Pods running in cluster ${K8S_CLUSTER_2_CONTEXT_NAME}" kubectl --context "${K8S_CLUSTER_2_CONTEXT_NAME}" -n "${OM_NAMESPACE}" get pods
Waiting for Backup to reach Running phase... mongodbopsmanager.mongodb.com/om condition met Waiting for Application Database to reach Running phase... mongodbopsmanager.mongodb.com/om condition met Waiting for Ops Manager to reach Running phase... mongodbopsmanager.mongodb.com/om condition met MongoDBOpsManager resource NAME REPLICAS VERSION STATE (OPSMANAGER) STATE (APPDB) STATE (BACKUP) AGE WARNINGS om 8.0.5 Running Running Running 21m Pods running in cluster gke_scratch-kubernetes-team_europe-central2-a_k8s-mdb-0-6abb9ad27d6x076f80-15370 NAME READY STATUS RESTARTS AGE om-0-0 1/1 Running 0 18m om-db-0-0 2/2 Running 0 7m58s om-db-0-1 2/2 Running 0 8m59s Pods running in cluster gke_scratch-kubernetes-team_europe-central2-b_k8s-mdb-1-6abb9ad27d6x076f80-15370 NAME READY STATUS RESTARTS AGE om-1-0 1/1 Running 0 18m om-1-1 1/1 Running 0 12m om-db-1-0 2/2 Running 0 6m5s om-db-1-1 2/2 Running 0 7m3s Pods running in cluster gke_scratch-kubernetes-team_europe-central2-c_k8s-mdb-2-6abb9ad27d6x076f80-15370 NAME READY STATUS RESTARTS AGE om-2-backup-daemon-0 1/1 Running 0 2m35s om-db-2-0 2/2 Running 0 5m11s
MongoDB 조직을 생성하고 자격 증명 가져옵니다.
자격 증명 구성하려면 MongoDB Ops Manager 조직 생성하고, MongoDB Ops Manager UI 에서 프로그래밍 방식의 API 키를 생성하고, 로드 밸런서 IP 로 시크릿 을 생성해야 합니다. 자세한 학습 은 Kubernetes Operator에 대한 자격 증명 생성 을 참조하세요.