Onboarding a virtual server image for Power Virtual Server
This tutorial walks you through how to onboard a sample virtual server image for Power Virtual Server to your account. By completing this tutorial, you learn how to create a private catalog, import the sample, validate that it can be installed on a selected deployment target, and make the virtual server image available to users who have access to your account.
This tutorial uses a sample virtual server image for Power Systems Virtual Server as part of the process to onboard a virtual server image. As you complete the tutorial, adapt each step to match your organization's goal.
The tutorial includes steps for deploying a virtual server image to a target Power Virtual Server. As a result, you incur associated infrastructure charges.
Before you begin
-
Verify that you're using a Pay-As-You-Go or Subscription account. See Viewing your account type for more details.
-
Create your Power Virtual Server instance and convert it into a public image.
-
After your image is converted into a public image, create your Terraform template.
-
Upload your Terraform template and readme file to your GitHub repository.
Use the latest release of the sample code as an example of how to set up your repository.
-
Make sure you're assigned the IBM Cloud Identity and Access Management (IAM) editor role on the catalog management service. See Assigning access to account management services for more information.
Create a private catalog
- In the IBM Cloud console, go to Manage > Catalogs, and click Create a catalog.
- Select Product default as the catalog type.
- Enter the name of your catalog, for example,
Sample virtual server image. - Select No products to exclude all products in the IBM Cloud® catalog from your catalog.
- Click Create.
Import the virtual server image to your private catalog
- From the Private products page, click Add.
- Select Virtual server image for Power Systems as the deployment method.
- Confirm that Public repository is selected as the repository type.
- Enter
https://github.com/IBM-Cloud/isv-power-vsi-product-deploy-sampleas your source URL. - Enter
1.0.0as the software version. - Click Add product.
Review the version details
- From the Version list table, click the row that contains your virtual server image.
- Review your version details from the Review the version details section. After you review your version details, click Next.
Configure the deployment details
- If you need to specify the Terraform runtime version that you want Schematics to use, click the Override the default Terraform runtime version checkbox and enter a version.
- From the Configure the deployment details section, click Add deployment values.
- Select Parameter to select all options, and click Add.
- To customize which parameters are required for users to specify during the installation and which ones are hidden altogether, select a parameter and click Edit. For the purposes of this tutorial, configure each parameter as described in the following table.
| Parameter | Description | Required for users to specify? | Hidden from users? |
|---|---|---|---|
crn |
The Power Virtual Server CRN | True |
False |
instance_name |
The name of the virtual server instance. | True |
False |
memory |
The amount of memory that you want to assign to your instance in gigabytes. | False |
False |
network_name |
The network ID or name to assign to the instance, as defined for the selected Power Virtual Server CRN. | True |
False |
processor_type |
The type of processor mode in which the VM runs. Specify shared, capped, or dedicated. |
False |
False |
processors |
The number of vCPUs to assign to the VM as visible within the guest OS. | False |
False |
ssh_key_name |
The name of the public SSH RSA key to use when you create the instance, as defined for the selected Power Virtual Server CRN. | True |
False |
sys_type |
The type of system on which to create the VM: s922, e880, e980, e1080, or s1022. |
False |
False |
Next, update the configuration type of the crn and processors parameters:
- From the Deployment values table, select the
crnparameter and click Edit. - Open the Value details menu and select Power Systems Virtual Server.
- Click Save.
- From the Deployment values table, select the
processorsparameter and click Edit. - Open the Value details menu and select Float.
Edit output value descriptions
You can improve the descriptions for your Terraform template's output values to help users better understand the purpose of the parameters. The description of any output value that you include in your template can be updated.
To add output values, you need to include them in a new imported version of your Terraform template.
Complete the following steps to edit the product's output value descriptions:
- Click Configure version > Next.
- From the Output value descriptions section, provide a new description for the parameter that you want to update.
- Click Next.
Define IAM access
After you configure your deployment values, you can add the service access and platform access roles that are required to install your product.
Use the following steps to define your product's access:
- Click Configure version > Next > Next.
- Click Add.
- Select the service and the required service and platform access.
- The service access role allows access for using the service and performing service API calls.
- The platform access role enables actions to be carried out on platform resources. For example, creating an instance, connecting instances to apps, and assigning user access.
- Click Save.
Set the license requirements
If users are required to accept any license agreements beyond the IBM Cloud Services Agreement, provide the URL to each agreement. Or, if users can bring their own licenses, you can provide that URL as well.
- Click Add license agreements > Add.
- Enter the name and URL, and click Update.
- Click Next.
Review your readme file
The TGZ file that you imported to your private catalog includes a readme file that provides product information for the virtual server image. If you want to make updates to the readme file, you can edit it directly from your private catalog. For the purposes of this tutorial, the following steps describe how to edit the description of the readme file.
- Click the Edit icon
, and update the description with the following sentence:
Create and deploy a virtual server with ease by using a custom image.
- Click Save > Next.
Validate the virtual server image
Validate that you can deploy the virtual server image to your Power Virtual Server instance.
-
From the Validate product tab, enter the name of your Schematics workspace, select a resource group, select a Schematics region, and click Next.
In the Tags field, you can enter a name of a specific tag to attach to your virtual server image. Tags provide a way to organize, track usage costs, and manage access to the resources in your account.
-
From the Deployment values section, review your parameter values, and click Next.
-
In the Validation product section, select I have read and agree to the following license agreements.
-
Click Validate.
To monitor the progress of the validation process, click View logs.
Manage compliance
You can add controls to your software to prove that it meets security and compliance requirements. To claim compliance, you must add inventory results from Workload Protection. Only controls that are supported by Workload Protection appear in the catalog. You can add controls from policies and import controls from module references.
Add controls
To add controls, complete the following steps:
Adding compliance controls
-
On the Manage compliance page, select Add controls.
-
Select a Workload Protection instance, then a policy.
If you haven't provisioned a Workload Protection instance yet, you must set up one from the IBM Cloud catalog and enable Cloud Security Posture Management (CSPM) for your IBM Cloud account. Then, complete the steps to integrate with either an existing Workload Protection instance or a new instance.
-
Select whether you want to add the entire policy or only a subset of controls.
-
If you select to add an entire policy, continue to the next step. If you select to add a subset of controls, select the controls that you want to add.
-
Click Add.
Add inventory results from Workload Protection
You can add inventory results from Workload Protection so that users can see the claimed compliance when they evaluate your product in the catalog.
In Workload Protection, your inventory is updated once every day. You must deploy your resources and wait for the inventory to be updated before you add the inventory to your catalog listing. For more information, go to Inventory.
To add inventory results, complete the following steps:
- On the Manage compliance page, click Add results.
- Select the Workload Protection instance that you provisioned previously.
- Click Apply to apply the latest inventory results.
Review requirements
You must complete validation and any other requirements to publish your product to your account.
Next steps
After you onboard and validate your virtual server image, you're ready to publish it to your account. From the Actions menu, select Publish to account. As a result, the virtual server image for Power Systems
is available only to users who have access to the Sample virtual server image private catalog in your account.