DIGIT Urban
PlatformDomainsAcademyDesign SystemFeedback
v2.0
v2.0
  • What Is DIGIT Urban?
  • DIGIT Urban Architecture
  • Product & Modules
    • Brochures
    • User Manuals
      • Logging Into DIGIT
      • mCollect
        • Citizen User Manual
        • Employee User Manual
      • Trade License
        • Citizen User Manual
        • Employee User Manual
      • Public Grievance & Redressal
        • Citizen User Manual
        • Employee User Manual
        • Complaint Types List
      • Property Tax
        • Citizen User Manual
        • Employee User Manual
    • Services Overview
      • Core Services
        • Workflow Services
        • Location Services
        • User Services
        • Access Control Services
        • PDF Generation Service
        • MDMS (Master Data Management Service)
        • Payment Gateway Service
      • Business Service
      • Municipal Service
        • PGR Services
        • Trade-License Service
      • Utilities
    • Release Notes DIGIT 2.0
      • BPA Release Notes
      • Trade License Release Notes
      • Property Tax Release Notes
      • PGR Release Notes
      • Water & Sewerage Release Notes
      • Advance Payments Release Notes
      • Configuration Changes
    • DIGIT Roadmap
    • Product FAQs
    • Quality Assurance
  • Configure DIGIT
    • Git Repos
    • Setting up DIGIT
      • Configuring InfraOps
      • Setting up DIGIT Environment
      • Email And SMS Setup
      • FileStore Setup
      • Setting Up SSL Certificate
      • Periodic Log Cleanup
    • Setting up Master Data
      • MDMS Overview
      • Configuring Master Data
      • Adding New Master
      • Configuring Tenants
      • State Level Vs City Level Master
    • Master Data Collection Templates
      • Environment Setup
        • State Level Setup
          • Tenants Information
          • SMS Account Configuration
          • Email Account Configuration
          • Google Play Store Account
          • Payment Gateway Configuration
          • POS Integration Configuration
          • Domain Name Configuration
          • SSL Configuration
          • ULB Departments
          • ULB Designations
          • Localization
          • Google Map Configuration
        • ULB Level Setup
          • Boundary Hierarchies
          • Boundary Data
          • Cross Hierarchy Mapping
          • ULB Bank Accounts
      • Module Setup
        • Trade Licenses Templates
          • Trade Category
          • Trade Type
          • Trade Sub Type
          • Trade License Fee
          • Trade License Documents Attachment
          • Structure Type
          • Structure Sub Type
        • Property Tax Data Templates
          • Road Type
          • Construction Type
          • Property Type
          • Property Sub Type
          • Usage Category Major
          • Usage Category Minor
          • Usage Category Sub Minor
          • Usage Category Detail
          • Ownership Category
          • Ownership Sub Category
          • Owner Special Category
          • Special Category Documents
          • Unit Rates
          • Tax Rates
          • Interest Rates
          • Penalty Rates
          • Rebate Rates
          • Mutation Fee
        • PGR Data Templates
          • Grievance Type
          • Grievance Sub Type
          • Routing Matrix
          • Escalation Matrix
        • Fire NOC Data Templates
          • Building Usage Type
          • Building Sub Usage Type
          • Fire Station Master
          • Areas Served Master
          • Fire Station Mapping
          • Fire NOC Fee
        • mCollect Data Templates
          • Service Category
          • Service Sub Category
          • Service Sub Category GL Code Mapping
        • Web Portals Templates
          • State Portal
          • ULB Portal
        • OBPAS Data Templates
          • List Of Services
          • Service-Wise Documents
          • Building Occupancy
          • Building Sub Occupancy
          • Building Usage
          • Inspection Checklist
          • Stakeholders Type
          • Town Planning Schemes
          • NOC Departments
          • Fee Structure
          • eDCR Drawing
        • HRMS Data Templates
          • User Roles
          • System Users
        • Finance Data Templates
          • Chart Of Accounts
          • Funds
          • Functions
          • Contractors
          • Suppliers
          • Schemes
          • Sub Schemes
          • Bank
          • Bank Branch
          • Bank Account
          • Deductions
          • Opening Balances
          • Sub Ledger Category
          • Sub Ledger Master
        • Water Charges Data Templates
          • Pipe Size Types
          • Water Source Types
          • Water Rates (Metered)
          • Water Rates (Non-Metered)
          • Water Penalty Rates
          • Water Interest Rates
        • Sewerage Charges Data Templates
          • Sewerage Rates
          • Sewerage Penalty Rates
          • Sewerage Interest Rates
        • Billing And Payments Data Templates
          • Tax Heads
          • Receipt Format
          • Demand Bill Format
        • DSS Data Templates
          • KPI Acceptance
        • Workflow Data Templates
          • Workflow Actions
          • Workflow Levels
          • Workflow Process
          • Workflow Notifications
        • Common Configuration Details
          • Standard Document List
          • Service Document Mapping
          • Checklist
          • Configuring Data FAQs
    • Configuring Workflows
      • Setting Up Workflows
      • Configuring Workflows For An Entity
    • Configuring Services
      • API Dos and Don'ts
      • Setting Up Service Locally
      • Configuring New Reports
        • Types Of Reports Used In Report Service
      • Customizing PDF Notices And Certificates
    • Setting up a Language
      • Adding New Language
      • Setting Up Default Language For SMS & Emails
    • Configuring Localization
      • Setup Base Product Localization
      • Configure SMS and Email
    • Setting Up SMS Gateway
      • Using The Generic GET & POST SMS Gateway Interface
    • Configuration FAQs
    • Setting Up eDCR Service
    • Adding Roles To System
    • Mapping Roles With APIs
    • Setting Up Finance Service
    • Adding New APIs For Access
  • Customize DIGIT
    • Frontend/UI
    • DIGIT Customization
      • API Do's & Don'ts
      • Writing A New Customer
    • Services
      • Core Services
      • Business Services
      • Municipal Services
      • Infra Services
    • Master & Configuration data load kit
    • Data Migration
      • Data Migration Principles
      • Data Templates
      • Data Migration Kit
  • Deployment Tools
    • Setup DIGIT
      • Infra Requirements
      • Why Kubernetes for DIGIT
      • Supported Clouds
        • Google Cloud
        • Azure
        • AWS
        • VSphere
        • SDC
        • NIC
      • Infra Sizing
      • Infra Best Practices
      • Deployment Architecture
      • Deploy DIGIT
        • Routing Traffic
        • Backbone Deployment
    • Skills Needed
    • Resource Requests & Limits
    • Readiness & Liveness
    • Troubleshooting
      • Distributed Tracing
      • Logging
      • Monitoring & Alerts
    • CI/CD
    • Security Practices
  • DIGIT Training Materials
    • Training Calendar
    • Training Videos
  • DIGIT Support
    • eGov Enablement Support for DIGIT
    • Troubleshooting Guides
Powered by GitBook

​All content on this page by eGov Foundation is licensed under a Creative Commons Attribution 4.0 International License.

On this page
  • Overview
  • VM Images
  • Importing the OVA
  • Importing the QCOW2
  • Modifications
  • VM Folder
  • Credentials / Cloud-Config
  • Permissions
  • Seed Cluster
  • User Cluster
  • Volume Detach Bug

Was this helpful?

Edit on Git
Export as PDF
  1. Deployment Tools
  2. Setup DIGIT
  3. Supported Clouds

VSphere

PreviousAWSNextSDC

Last updated 4 years ago

Was this helpful?

Overview

The Kubernetes vSphere driver contains bugs related to detaching volumes from offline nodes. See the section for more details.

VM Images

When creating worker nodes for a user cluster, the user can specify an existing image. Defaults may be set in the .

Supported operating systems

  • Ubuntu 18.04

  • CoreOS

  • CentOS 7

Importing the OVA

  1. Go into the VSphere WebUI, select your data centre, right-click onto it and choose “Deploy OVF Template”

  2. Fill in the “URL” field with the appropriate URL

  3. Click through the dialogue until “Select storage”

  4. Select the same storage you want to use for your machines

  5. Select the same network you want to use for your machines

  6. Leave everything in the “Customize Template” and “Ready to complete” dialogue as it is

  7. Wait until the VM got fully imported and the “Snapshots” => “Create Snapshot” button is not greyed out anymore.

  8. The template VM must have the disk.enable UUID flag set to 1, this can be done using the with the following command:

govc vm.change -e="disk.enableUUID=1" -vm='/PATH/TO/VM'

Importing the QCOW2

  1. Convert it to vmdk: qemu-img convert -f qcow2 -O vmdk CentOS-7-x86_64-GenericCloud.qcow2 CentOS-7-x86_64-GenericCloud.vmdk

  2. Upload it to a Datastore of your vSphere installation

  3. Create a new virtual machine that uses the uploaded vmdk as rootdisk.

Modifications

Modifications like Network, disk size, etc. must be done in the ova template before creating a worker node from it. If user clusters have dedicated networks, all user clusters, therefore, need a custom template.

VM Folder

Credentials / Cloud-Config

Kubernetes needs to talk to the vSphere to enable Storage inside the cluster. For this, kubernetes needs a config called cloud-config. This config contains all details to connect to a vCenter installation, including credentials.

As this Config must also be deployed onto each worker node of a user cluster, its recommended to have individual credentials for each user cluster.

Permissions

The VSphere user must have the following permissions on the correct resources

Seed Cluster

  • Role k8c-storage-vmfolder-propagate

    • Granted at VM Folder and Template Folder, propagated

    • Permissions

      • Virtual machine

        • Change Configuration

          • Add existing disk

          • Add new disk

          • Add or remove the device

          • Remove disk

      • Folder

        • Create folder

        • Delete folder

  • Role k8c-storage-datastore-propagate

    • Granted at Datastore, propagated

    • Permissions

      • Datastore

        • Allocate space

        • Low-level file operations

  • Role Read-only (predefined)

    • Granted at …, not propagated

      • Datacenter

User Cluster

  • Role k8c-user-vcenter

    • Granted at vcentre level, not propagated

    • Needed to customize VM during provisioning

    • Permissions

      • VirtualMachine

        • Provisioning

          • Modify customization specification

          • Read customization specifications

  • Role k8c-user-datacenter

    • Granted at datacentre level, not propagated

    • Needed for cloning the template VM (obviously this is not done in a folder at this time)

    • Permissions

      • Datastore

        • Allocate space

        • Browse datastore

        • Low-level file operations

        • Remove file

      • vApp

        • vApp application configuration

        • vApp instance configuration

      • Virtual Machine

        • Change CPU count

        • Memory

        • Settings

      • Inventory

        • Create from existing

  • Role k8c-user-cluster-propagate

    • Granted at the cluster level, propagated

    • Needed for upload of cloud-init.iso (Ubuntu and CentOS) or defining the Ignition config into Guestinfo (CoreOS)

    • Permissions

      • Host

        • Configuration

          • System Management

        • Local operations

          • Reconfigure virtual machine

      • Resource

        • Assign virtual machine to the resource pool

        • Migrate powered off the virtual machine

        • Migrate powered-on virtual machine

      • vApp

        • vApp application configuration

        • vApp instance configuration

  • Role k8s-network-attach

    • Granted for each network that should be used

    • Permissions

      • Network

        • Assign network

  • Role k8c-user-datastore-propagate

    • Granted at datastore/datastore cluster level, propagated

    • Permissions

      • Datastore

        • Allocate space

        • Browse datastore

        • Low-level file operations

  • Role k8c-user-folder-propagate

    • Granted at VM Folder and Template Folder level, propagated

    • Needed for managing the node VMs

    • Permissions

      • Folder

        • Create folder

        • Delete folder

      • Global

        • Set custom attribute

      • Virtual machine

        • Change Configuration

        • Edit Inventory

        • Guest operations

        • Interaction

        • Provisioning

        • Snapshot management

The described permissions have been tested with vSphere 6.7 and might be different for other vSphere versions.

Volume Detach Bug

After a node is powered-off, the Kubernetes vSphere driver doesn’t detach disks associated with PVCs mounted on that node. This makes it impossible to reschedule pods using these PVCs until the disks are manually detached in vCenter.

Upstream Kubernetes has been working on the issue for a long time now and tracking it under the following tickets:

During the creation of a user cluster Kubermatic creates a dedicated VM folder in the root path on the Datastore (Defined in the ). That folder will contain all worker nodes of a user cluster.

datacenters.yaml
https://github.com/kubernetes/kubernetes/issues/63577
https://github.com/kubernetes/kubernetes/issues/61707
https://github.com/kubernetes/kubernetes/issues/67900
https://github.com/kubernetes/kubernetes/issues/71829
https://github.com/kubernetes/kubernetes/issues/75342
datacenters.yaml
ova
ova
qcow2
govc tool
Volume detach bug