Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  • OLD_LDAP_SERVER_NAME → Name of the server from Openstack → you can find the name from openstack server list command
  • OLD_LDAP_PRIVATE_IP → logging in Morpheus → Provisioning → Instances, check your OLD LDAP VM IP address
  • OLD_LDAP_HOSTNAME → logging in Morpheus → Tools → Cypher and check the following secret → secret/ldap_hostname
  • NEW_LDAP_SERVER_NAME → Name of the server from Openstack → you can find the name from openstack server list command
  • NEW_LDAP_PRIVATE_IP → logging in Morpheus → Provisioning → Instances, check your new LDAP VM IP address
  • NEW_LDAP_HOSTNAME → <name-of-the-machine>.<tenancy-domain> where tenancy-domain → logging in Morpheus → Tools → Cypher and check the following secret → secret/ldap_domain (e.g. ldap-test-rocky.eumetsat.sandbox.ewc)
  • DNS_HOSTED_ZONE→ logging in Morpheus → Tools → Cypher and check the following secret → secret/ldap_hostname


Start user procedure:

  1. Create LDAP DNS Reverse zone (see );
  2. Edit LDAP Security Group (see );
  3. Backup existing LDAP machine using the following documentation: EWC - How to create and restore backups from VMs
  4. Check the Operating System of your LDAP (either from Morpheus, Provisioning → Instances → select LDAP machine Image Added;
    1. If your LDAP is rocky 8 based → jump to step 8. 
    2. If your LDAP is centos7 based → continue to step 4.
  5. Create LDAP replica instance type to move from centos7 to rocky 8 (see MigratefromCentos7toRocky8);
  6. Prepare new LDAP machine (see PreparenewLDAPmachine );
  7. Switch IP interfaces between LDAPs (see SwitchIPinterfacesbetweenLDAP );
  8. Update Morpheus (see UpdateMorpheus );
  9. Check everything is fine (see Tests);
  10. Create LDAP replica instance type to move from rocky 8 to rocky 9 (see MigratefromRocky8toRocky9)
  11. Prepare new LDAP machine (see PreparenewLDAPmachine );
  12. Switch IP interfaces between LDAPs (see SwitchIPinterfacesbetweenLDAP );
  13. Update Morpheus (see UpdateMorpheus );
  14. Check everything is fine (see Tests);
  15. Delete old LDAP machine/s to free resources (see Delete a VM from Morpheus).



Tasks


Create LDAP DNS reverse zone

  1. SSH into the OLD LDAP machine (your current one) and create DNS reverse zone (NAME_FROM_IP = LDAP IP or using IP range ) (https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/7/html/linux_domain_identity_authentication_and_policy_guide/managing-reverse-dns-zones
    Code Block
    ipa dnszone-add --name-from-ip=NAME_FROM_IP


Edit LDAP security group

  1. ssh to the VM with Openstack Client and run the following commands (see EWC - OpenStack Command-Line client for more details):
    1. List ldap security group rule 
      Code Block
      openstack security group rule list ldap
    2. add port 636 TCP.749 TCP,464 UDP to ldap security group if they are missing
      Code Block
      openstack security group rule create ldap --protocol tcp --ingress --dst-port 636 --remote-ip 0.0.0.0/0 --ethertype IPv4
      openstack security group rule create ldap --protocol tcp --ingress --dst-port 749 --remote-ip 0.0.0.0/0 --ethertype IPv4
      openstack security group rule create ldap --protocol udp --ingress --dst-port 464 --remote-ip 0.0.0.0/0 --ethertype IPv4
    3. Backup existing LDAP machine using the following documentation: EWC - How to create and restore backups from VMs
  2. Check the Operating System of your LDAP (either from Morpheus, Provisioning → Instances → select LDAP machine Image Removed;
    1. If your LDAP is rocky 8 based → jump to step 8. 
    2. If your LDAP is centos7 based → continue to step 4.
  3. Create LDAP replica instance type to move from centos7 to rocky 8 (see MigratefromCentos7toRocky8);
  4. Prepare new LDAP machine (see);
  5. Switch IP interfaces between LDAPs (see SwitchIPinterfacesbetweenLDAP );
  6. Update Morpheus (see UpdateMorpheus );
  7. Check everything is fine (see Tests);
  8. Create LDAP replica instance type to move from rocky 8 to rocky 9 (see MigratefromRocky8toRocky9)
  9. Prepare new LDAP machine (see);
  10. Switch IP interfaces between LDAPs (see SwitchIPinterfacesbetweenLDAP );
  11. Update Morpheus (see UpdateMorpheus );
  12. Check everything is fine (see Tests);
  13. Remove old LDAPs machines to free resources (from Morpheus)

...


Migrate from Centos7 to Rocky 8

...