commit | 3c59b43f28742ac4e3811adcd1612d0af24794ca | [log] [tgz] |
---|---|---|
author | HuynhKevin <35630180+HuynhKevin@users.noreply.github.com> | Sun Jun 26 07:01:48 2022 +0200 |
committer | GitHub <noreply@github.com> | Sun Jun 26 00:01:48 2022 -0500 |
tree | 36b3f5ea9079c4bf87eecd7aa9b3212f7e17e200 | |
parent | c05f659ff40f2274ac75e3baacddc0afd3bb220e [diff] |
Add imagePullSecrets zookeeper (#244) * Add imagePullSecrets for zookeeper * Add imagePullSecrets for zookeeper Co-authored-by: Kevin Huynh <khuynh@littlebigcode.fr> All components have the imagePullSecrets to avoid quota limit to init correctly the pods except zookeeper
This is the officially supported Helm Chart for installing Apache Pulsar on Kubernetes.
Read Deploying Pulsar on Kubernetes for more details.
This Helm Chart includes all the components of Apache Pulsar for a complete experience.
It includes support for:
In order to use this chart to deploy Apache Pulsar on Kubernetes, the followings are required.
Before proceeding to deploying Pulsar, you need to prepare your environment.
helm
and kubectl
need to be installed on your computer.
To add this chart to your local Helm repository:
helm repo add apache https://pulsar.apache.org/charts
To use the helm chart:
helm install <release-name> apache/pulsar
You need a Kubernetes cluster whose version is 1.18 or higher in order to use this chart, due to the usage of certain Kubernetes features.
We provide some instructions to guide you through the preparation: http://pulsar.apache.org/docs/en/helm-prepare/
Clone the Pulsar Helm charts repository.
git clone https://github.com/apache/pulsar-helm-chart
cd pulsar-helm-chart
Run prepare_helm_release.sh
to create required kubernetes resources for installing this Helm chart.
-c
is specified)broker-admin
, proxy-admin
, and admin
. By default, it generates asymmetric pubic/private key pair. You can choose to generate symmetric secret key by specifying --symmetric
in the following command.proxy-admin
role is used for proxies to communicate to brokers.broker-admin
role is used for inter-broker communications.admin
role is used by the admin tools../scripts/pulsar/prepare_helm_release.sh -n <k8s-namespace> -k <pulsar-release-name> -c
Use the Pulsar Helm charts to install Apache Pulsar.
This command installs and starts Apache Pulsar.
$ helm install <pulsar-release-name> apache/pulsar
Access the Pulsar cluster
The default values will create a ClusterIP
for the proxy you can use to interact with the cluster. To find the IP address of proxy use:
kubectl get service -n <k8s-namespace>
For more information, please follow our detailed quick start guide.
We provide a detailed guideline for you to customize the Helm Chart for a production-ready deployment.
You can also checkout out the example values file for different deployments.
Once your Pulsar Chart is installed, configuration changes and chart updates should be done using helm upgrade
.
helm repo add apache https://pulsar.apache.org/charts helm repo update helm get values <pulsar-release-name> > pulsar.yaml helm upgrade -f pulsar.yaml \ <pulsar-release-name> apache/pulsar
For more detailed information, see our Upgrading guide.
The 2.10.0+ Apache Pulsar docker image is a non-root container, by default. That complicates an upgrade to 2.10.0 because the existing files are owned by the root user but are not writable by the root group. In order to leverage this new security feature, the Bookkeeper and Zookeeper StatefulSet securityContexts are configurable in the values.yaml
. They default to:
securityContext: fsGroup: 0 fsGroupChangePolicy: "OnRootMismatch"
This configuration is ideal for regular Kubernetes clusters where the UID is stable across restarts. If the process UID is subject to change (like it is in OpenShift), you'll need to set fsGroupChangePolicy: "Always"
.
The official docker image assumes that it is run as a member of the root group.
If you upgrade to the latest version of the helm chart before upgrading to Pulsar 2.10.0, then when you perform your first upgrade to version >= 2.10.0, you will need to set fsGroupChangePolicy: "Always"
on the first upgrade and then set it back to fsGroupChangePolicy: "OnRootMismatch"
on subsequent upgrades. This is because the root file won't mismatch permissions, but the RocksDB lock file will. If you have direct access to the persistent volumes, you can alternatively run chgrp -R g+w /pulsar/data
before upgrading.
Here is a sample error you can expect if the RocksDB lock file is not correctly owned by the root group:
2022-05-14T03:45:06,903+0000 ERROR org.apache.bookkeeper.server.Main - Failed to build bookie server java.io.IOException: Error open RocksDB database at org.apache.bookkeeper.bookie.storage.ldb.KeyValueStorageRocksDB.<init>(KeyValueStorageRocksDB.java:199) ~[org.apache.bookkeeper-bookkeeper-server-4.14.4.jar:4.14.4] at org.apache.bookkeeper.bookie.storage.ldb.KeyValueStorageRocksDB.<init>(KeyValueStorageRocksDB.java:88) ~[org.apache.bookkeeper-bookkeeper-server-4.14.4.jar:4.14.4] at org.apache.bookkeeper.bookie.storage.ldb.KeyValueStorageRocksDB.lambda$static$0(KeyValueStorageRocksDB.java:62) ~[org.apache.bookkeeper-bookkeeper-server-4.14.4.jar:4.14.4] at org.apache.bookkeeper.bookie.storage.ldb.LedgerMetadataIndex.<init>(LedgerMetadataIndex.java:68) ~[org.apache.bookkeeper-bookkeeper-server-4.14.4.jar:4.14.4] at org.apache.bookkeeper.bookie.storage.ldb.SingleDirectoryDbLedgerStorage.<init>(SingleDirectoryDbLedgerStorage.java:169) ~[org.apache.bookkeeper-bookkeeper-server-4.14.4.jar:4.14.4] at org.apache.bookkeeper.bookie.storage.ldb.DbLedgerStorage.newSingleDirectoryDbLedgerStorage(DbLedgerStorage.java:150) ~[org.apache.bookkeeper-bookkeeper-server-4.14.4.jar:4.14.4] at org.apache.bookkeeper.bookie.storage.ldb.DbLedgerStorage.initialize(DbLedgerStorage.java:129) ~[org.apache.bookkeeper-bookkeeper-server-4.14.4.jar:4.14.4] at org.apache.bookkeeper.bookie.Bookie.<init>(Bookie.java:818) ~[org.apache.bookkeeper-bookkeeper-server-4.14.4.jar:4.14.4] at org.apache.bookkeeper.proto.BookieServer.newBookie(BookieServer.java:152) ~[org.apache.bookkeeper-bookkeeper-server-4.14.4.jar:4.14.4] at org.apache.bookkeeper.proto.BookieServer.<init>(BookieServer.java:120) ~[org.apache.bookkeeper-bookkeeper-server-4.14.4.jar:4.14.4] at org.apache.bookkeeper.server.service.BookieService.<init>(BookieService.java:52) ~[org.apache.bookkeeper-bookkeeper-server-4.14.4.jar:4.14.4] at org.apache.bookkeeper.server.Main.buildBookieServer(Main.java:304) ~[org.apache.bookkeeper-bookkeeper-server-4.14.4.jar:4.14.4] at org.apache.bookkeeper.server.Main.doMain(Main.java:226) [org.apache.bookkeeper-bookkeeper-server-4.14.4.jar:4.14.4] at org.apache.bookkeeper.server.Main.main(Main.java:208) [org.apache.bookkeeper-bookkeeper-server-4.14.4.jar:4.14.4] Caused by: org.rocksdb.RocksDBException: while open a file for lock: /pulsar/data/bookkeeper/ledgers/current/ledgers/LOCK: Permission denied at org.rocksdb.RocksDB.open(Native Method) ~[org.rocksdb-rocksdbjni-6.10.2.jar:?] at org.rocksdb.RocksDB.open(RocksDB.java:239) ~[org.rocksdb-rocksdbjni-6.10.2.jar:?] at org.apache.bookkeeper.bookie.storage.ldb.KeyValueStorageRocksDB.<init>(KeyValueStorageRocksDB.java:196) ~[org.apache.bookkeeper-bookkeeper-server-4.14.4.jar:4.14.4] ... 13 more
To uninstall the Pulsar Chart, run the following command:
helm delete <pulsar-release-name>
For the purposes of continuity, these charts have some Kubernetes objects that are not removed when performing helm delete
. These items we require you to conciously remove them, as they affect re-deployment should you choose to.
We‘ve done our best to make these charts as seamless as possible, occasionally troubles do surface outside of our control. We’ve collected tips and tricks for troubleshooting common issues. Please examine these first before raising an issue, and feel free to add to them by raising a Pull Request!
Bump the version in charts/pulsar/Chart.yaml.
Send a pull request for reviews.
After the pull request is approved, merge it. The release workflow will be triggered automatically.
pulsar-<version>
.charts/index.yaml
in Pulsar website.Trigger the Pulsar website build to make the release available under https://pulsar.apache.org/charts.