Migración de aplicaciones y datos Cloud Object Storage (COS) entre cuentas IBM Cloud
Infraestructura clásica Nube privada virtual
En este tutorial, migrará una aplicación COS y los datos de un clúster IBM Cloud Kubernetes Service en una cuenta a un clúster Red Hat OpenShift on IBM Cloud en otra cuenta.
Requisitos previos
Cuenta 1
En la Cuenta 1, debe tener lo siguiente.
-
Un clúster IBM Cloud Kubernetes Service.
-
Una instancia COS y un conjunto de credenciales HMAC. Para más información, ver Credenciales de servicio.
Cuenta 2
En la Cuenta 2, la cuenta de destino a migrar, debe tener lo siguiente.
-
Un Red Hat OpenShift on IBM Cloud grupo.
-
Una instancia COS y un conjunto de credenciales HMAC. Para más información, ver Credenciales de servicio.
-
Un cubo vacío en su instancia COS.
Opcional: Implementar una aplicación en su clúster
Cuenta 1
Si aún no tiene una aplicación que desee migrar, puede desplegar la siguiente aplicación de ejemplo.
-
Cree un PVC que haga referencia a su configuración de almacenamiento de objetos.
kind: PersistentVolumeClaim apiVersion: v1 metadata: name: demo #Enter a name for your PVC. namespace: default annotations: ibm.io/auto-create-bucket: "true" ibm.io/auto-delete-bucket: "false" ibm.io/secret-name: SECRET-NAME #Enter the name of the secret you created earlier. ibm.io/secret-namespace: NAMESPACE #Enter the namespace where you want to create the PVC. spec: accessModes: - ReadWriteOnce resources: requests: storage: 10Gi storageClassName: ibmc-s3fs-cos #The storage class that you want to use. -
Cree la PVC en el clúster.
oc apply -f pvc-cos.yaml -
Cree un archivo de configuración YAML para un pod que monte el PVC que ha creado.
apiVersion: v1 kind: Pod metadata: name: demo-pod namespace: default spec: securityContext: runAsUser: 2000 fsGroup: 2000 volumes: - name: demo-vol persistentVolumeClaim: claimName: demo containers: - name: test image: nginxinc/nginx-unprivileged imagePullPolicy: Always volumeMounts: - name: demo-vol mountPath: /mnt/cosvol -
Cree el pod en el clúster.
oc apply -f demo-pod.yaml -
Verifique que el pod se ha desplegado. Tenga en cuenta que puede tardar unos minutos en entrar en el estado
Running.oc get podsNAME READY STATUS RESTARTS AGE demo-pod 1/1 Running 0 2m58s -
Verifique que la aplicación puede grabar en el volumen de almacenamiento de bloques iniciando sesión en el pod.
oc exec demo-pod -- bash -c "ls /mnt/cosvol"
Obtenga los detalles de su aplicación
Cuenta 1
- Enumera las vainas y los PVC.
oc get pods - Describa su PVC y revise los detalles y anote el nombre del cubo.
oc describe PVC -o yaml
Instalar rclone
Siga la documentación rclone para pasos de instalación.
Configure ' rclone ' para su cubo en la Cuenta 1
Cuenta 1
Una vez instalado rclone, debe generar un archivo de configuración que defina la instancia de COS desde la que desea migrar los datos.
-
Ejecute el mandato
rclone config.rclone configSalida de ejemplo
2020/01/16 09:39:33 NOTICE: Config file "/Users/ryan/.config/rclone/rclone.conf" not found - using defaults No remotes found - make a new one n) New remote s) Set configuration password q) Quit config -
Ingresar
npara configurar un nuevo control remoto y luego proporcione un nombre para su control remoto.n/s/q> nEjemplo de nombre remoto
name> cos-instance-1 -
De la lista de proveedores, seleccione
Amazon S3 Compliant Storage Providerque incluyeIBM COS.Enter a string value. Press Enter for the default (""). Choose a number from below, or type in your own value 1 / 1Fichier \ "fichier" 2 / Alias for an existing remote \ "alias" 3 / Amazon Drive \ "amazon cloud drive" 4 / Amazon S3 Compliant Storage Provider (AWS, Alibaba, Ceph, Digital Ocean, Dreamhost, IBM COS, Minio, etc) \ "s3" 5 / Backblaze B2 \ "b2" ... provider> 4 -
Seleccione
IBM COScomo su s3 proveedor.Choose your S3 provider. Enter a string value. Press Enter for the default (""). Choose a number from below, or type in your own value 1 / Amazon Web Services (AWS) S3 \ "AWS" 2 / Alibaba Cloud Object Storage System (OSS) formerly Aliyun \ "Alibaba" 3 / Ceph Object Storage \ "Ceph" 4 / Digital Ocean Spaces \ "DigitalOcean" 5 / Dreamhost DreamObjects \ "Dreamhost" 6 / IBM COS S3 \ "IBMCOS" 7 / Minio Object Storage \ "Minio" 8 / Netease Object Storage (NOS) \ "Netease" 9 / Wasabi Object Storage \ "Wasabi" 10 / Any other S3 compatible provider \ "Other" -
Agregue sus credenciales de COS seleccionando la opción
1.Option env_auth. Get AWS credentials from runtime (environment variables or EC2/ECS meta data if no env vars). Only applies if access_key_id and secret_access_key is blank. Choose a number from below, or type in your own boolean value (true or false). Press Enter for the default (false). 1 / Enter AWS credentials in the next step. \ (false) 2 / Get AWS credentials from the environment (env vars or IAM). \ (true) env_auth> 1 -
Cuando se le solicite, proporcione la
access_key_idysecret_access_keyde su instancia COS. Para más información, ver Credenciales de servicio.AWS Access Key ID. Leave blank for anonymous access or runtime credentials. Enter a string value. Press Enter for the default (""). access_key_id> xxxxxxxxxxxxxxxxxxxxx AWS Secret Access Key (password) Leave blank for anonymous access or runtime credentials. Enter a string value. Press Enter for the default (""). secret_access_key> xxxxxxxxxxxxxxxxxxxxxxxxxxxxx -
En el
Region to connect tomensaje, seleccione la opción1.Region to connect to. Leave blank if you are using an S3 clone and you don't have a region. Enter a string value. Press Enter for the default (""). Choose a number from below, or type in your own value 1 / Use this if unsure. Will use v4 signatures and an empty region. \ "" 2 / Use this only if v4 signatures don't work, eg pre Jewel/v10 CEPH. \ "other-v2-signature" region> 1 -
En el
Endpoint for IBM COS S3 APImensaje, seleccione la opción1.Endpoint for IBM COS S3 API. Specify if using an IBM COS On Premise. Enter a string value. Press Enter for the default (""). Choose a number from below, or type in your own value 1 / US Cross Region Endpoint \ "s3-api.us-geo.objectstorage.softlayer.net" 2 / US Cross Region Dallas Endpoint \ "s3-api.dal.us-geo.objectstorage.softlayer.net" 3 / US Cross Region Washington DC Endpoint \ "s3-api.wdc-us-geo.objectstorage.softlayer.net" ... endpoint> 1 -
En el
Location constraintmensaje, presione Devolver para utilizar el valor predeterminado.Location constraint - must match endpoint when using IBM Cloud Public. For on-prem COS, do not make a selection from this list, hit enter Enter a string value. Press Enter for the default (""). Choose a number from below, or type in your own value 1 / US Cross Region Standard \ "us-standard" 2 / US Cross Region Vault \ "us-vault" 3 / US Cross Region Cold \ "us-cold" 4 / US Cross Region Flex \ "us-flex" ... -
En el mensaje de política de ACL, seleccione
private.Note that this ACL is applied when server side copying objects as S3 doesn't copy the ACL from the source but rather writes a fresh one. Enter a string value. Press Enter for the default (""). Choose a number from below, or type in your own value 1 / Owner gets FULL_CONTROL. No one else has access rights (default). This acl is available on IBM Cloud (Infra), IBM Cloud (Storage), On-Premise COS \ "private" 2 / Owner gets FULL_CONTROL. The AllUsers group gets READ access. This acl is available on IBM Cloud (Infra), IBM Cloud (Storage), On-Premise IBM COS \ "public-read" 3 / Owner gets FULL_CONTROL. The AllUsers group gets READ and WRITE access. This acl is available on IBM Cloud (Infra), On-Premise IBM COS \ "public-read-write" 4 / Owner gets FULL_CONTROL. The AuthenticatedUsers group gets READ access. Not supported on Buckets. This acl is available on IBM Cloud (Infra) and On-Premise IBM COS \ "authenticated-read" acl> 1 -
Omita la opción de configuración avanzada y confirme su configuración.
Edit advanced config? (y/n) y) Yes n) No y/n> n Remote config -------------------- [cos-instance-1] type = s3 provider = IBMCOS env_auth = false access_key_id = xxxxxx secret_access_key = xxxxxxxxx endpoint = s3-api.us-geo.objectstorage.softlayer.net location_constraint = us-standard acl = private -------------------- y) Yes this is OK e) Edit this remote d) Delete this remote y/e/d> y Current remotes: Name Type ==== ==== cos-instance-1 s3 -
Repita los pasos anteriores para añadir la instancia COS en su segunda cuenta. Cuando haya verificado la información, pulse
qpara salir del proceso de configuración.
Configure ' rclone ' para su cubo en la Cuenta 2
Cuenta 2
Repita los pasos para configurar rclone para la Cuenta 2.
-
Ejecute el mandato
rclone config.rclone configSalida de ejemplo
2020/01/16 09:39:33 NOTICE: Config file "/Users/ryan/.config/rclone/rclone.conf" not found - using defaults No remotes found - make a new one n) New remote s) Set configuration password q) Quit config -
Ingresar
npara configurar un nuevo control remoto y luego proporcione un nombre para su control remoto.n/s/q> nEjemplo de nombre remoto
name> cos-instance-2 -
De la lista de proveedores, seleccione
Amazon S3 Compliant Storage Providerque incluyeIBM COS.Enter a string value. Press Enter for the default (""). Choose a number from below, or type in your own value 1 / 1Fichier \ "fichier" 2 / Alias for an existing remote \ "alias" 3 / Amazon Drive \ "amazon cloud drive" 4 / Amazon S3 Compliant Storage Provider (AWS, Alibaba, Ceph, Digital Ocean, Dreamhost, IBM COS, Minio, etc) \ "s3" 5 / Backblaze B2 \ "b2" ... provider> 4 -
Seleccione
IBM COScomo su s3 proveedor.Choose your S3 provider. Enter a string value. Press Enter for the default (""). Choose a number from below, or type in your own value 1 / Amazon Web Services (AWS) S3 \ "AWS" 2 / Alibaba Cloud Object Storage System (OSS) formerly Aliyun \ "Alibaba" 3 / Ceph Object Storage \ "Ceph" 4 / Digital Ocean Spaces \ "DigitalOcean" 5 / Dreamhost DreamObjects \ "Dreamhost" 6 / IBM COS S3 \ "IBMCOS" 7 / Minio Object Storage \ "Minio" 8 / Netease Object Storage (NOS) \ "Netease" 9 / Wasabi Object Storage \ "Wasabi" 10 / Any other S3 compatible provider \ "Other" -
Agregue sus credenciales de COS seleccionando la opción
1.Option env_auth. Get AWS credentials from runtime (environment variables or EC2/ECS meta data if no env vars). Only applies if access_key_id and secret_access_key is blank. Choose a number from below, or type in your own boolean value (true or false). Press Enter for the default (false). 1 / Enter AWS credentials in the next step. \ (false) 2 / Get AWS credentials from the environment (env vars or IAM). \ (true) env_auth> 1 -
Cuando se le solicite, proporcione la
access_key_idysecret_access_keyde su instancia COS. Para más información, ver Credenciales de servicio.AWS Access Key ID. Leave blank for anonymous access or runtime credentials. Enter a string value. Press Enter for the default (""). access_key_id> xxxxxxxxxxxxxxxxxxxxx AWS Secret Access Key (password) Leave blank for anonymous access or runtime credentials. Enter a string value. Press Enter for the default (""). secret_access_key> xxxxxxxxxxxxxxxxxxxxxxxxxxxxx -
En el
Region to connect tomensaje, seleccione la opción1.Region to connect to. Leave blank if you are using an S3 clone and you don't have a region. Enter a string value. Press Enter for the default (""). Choose a number from below, or type in your own value 1 / Use this if unsure. Will use v4 signatures and an empty region. \ "" 2 / Use this only if v4 signatures don't work, eg pre Jewel/v10 CEPH. \ "other-v2-signature" region> 1 -
En el
Endpoint for IBM COS S3 APImensaje, seleccione la opción1.Endpoint for IBM COS S3 API. Specify if using an IBM COS On Premise. Enter a string value. Press Enter for the default (""). Choose a number from below, or type in your own value 1 / US Cross Region Endpoint \ "s3-api.us-geo.objectstorage.softlayer.net" 2 / US Cross Region Dallas Endpoint \ "s3-api.dal.us-geo.objectstorage.softlayer.net" 3 / US Cross Region Washington DC Endpoint \ "s3-api.wdc-us-geo.objectstorage.softlayer.net" ... endpoint> 1 -
En el
Location constraintmensaje, presione Devolver para utilizar el valor predeterminado.Location constraint - must match endpoint when using IBM Cloud Public. For on-prem COS, do not make a selection from this list, hit enter Enter a string value. Press Enter for the default (""). Choose a number from below, or type in your own value 1 / US Cross Region Standard \ "us-standard" 2 / US Cross Region Vault \ "us-vault" 3 / US Cross Region Cold \ "us-cold" 4 / US Cross Region Flex \ "us-flex" ... -
En el mensaje de política de ACL, seleccione
private.Note that this ACL is applied when server side copying objects as S3 doesn't copy the ACL from the source but rather writes a fresh one. Enter a string value. Press Enter for the default (""). Choose a number from below, or type in your own value 1 / Owner gets FULL_CONTROL. No one else has access rights (default). This acl is available on IBM Cloud (Infra), IBM Cloud (Storage), On-Premise COS \ "private" 2 / Owner gets FULL_CONTROL. The AllUsers group gets READ access. This acl is available on IBM Cloud (Infra), IBM Cloud (Storage), On-Premise IBM COS \ "public-read" 3 / Owner gets FULL_CONTROL. The AllUsers group gets READ and WRITE access. This acl is available on IBM Cloud (Infra), On-Premise IBM COS \ "public-read-write" 4 / Owner gets FULL_CONTROL. The AuthenticatedUsers group gets READ access. Not supported on Buckets. This acl is available on IBM Cloud (Infra) and On-Premise IBM COS \ "authenticated-read" acl> 1 -
Omita la opción de configuración avanzada y confirme su configuración.
Edit advanced config? (y/n) y) Yes n) No y/n> n Remote config -------------------- [cos-instance-2] type = s3 provider = IBMCOS env_auth = false access_key_id = xxxxxx secret_access_key = xxxxxxxxx endpoint = s3-api.us-geo.objectstorage.softlayer.net location_constraint = us-standard acl = private -------------------- y) Yes this is OK e) Edit this remote d) Delete this remote y/e/d> y Current remotes: Name Type ==== ==== cos-instance-1 s3 cos-instance-2 s3 -
Repita los pasos anteriores para añadir la instancia COS en su segunda cuenta. Cuando haya verificado la información, pulse
qpara salir del proceso de configuración.
Ver el contenido de sus cubos COS
Cuenta 1 Cuenta 2
Después de configurar rclone, revisa el contenido de cada cubo y, a continuación, sincroniza los datos entre los cubos de cada cuenta.
-
Vea el contenido del depósito en primera instancia.
rclone ls cos-instance-1:bucket-1 45338 test.txt -
Vea el contenido del depósito en la instancia 2. En este ejemplo el nombre del cubo es
bucket-2.rclone ls cos-instance-2:bucket-2
Sincronizar contenidos entre depósitos
Cuenta 1 Cuenta 2
-
Para mover los datos de un depósito a otro, puede utilizar el
rclone syncdominio. En este ejemplocos-instance-1:bucket-1está en una cuenta mientrascos-instance-2:bucket-2es una segunda instancia de COS en una cuenta separada.Ejemplo
rclone sync -P cos-instance-1:bucket-1 cos-instance-2:bucket-2Salida de ejemplo
Transferred: 754.933k / 754.933 kBytes, 100%, 151.979 kBytes/s, ETA 0s Errors: 0 Checks: 0 / 0, - Transferred: 18 / 18, 100% Elapsed time: 4.9 -
Verifique el contenido del balde en
cos-instance-1se han sincronizado con el depósito encos-instance-2.rclone ls cos-instance-2:bucket-2Salida de ejemplo
45338 test.txt
Vuelve a desplegar tu aplicación en la Cuenta 2
Cuenta 2
-
Copie el siguiente PVC y guárdelo en un archivo llamado
pvc.yamlkind: PersistentVolumeClaim apiVersion: v1 metadata: name: demo # Enter a name for your PVC. namespace: default annotations: ibm.io/bucket-name: "bucket-2" # Enter the name of the bucket in Account 2 ibm.io/auto-create-bucket: "false" ibm.io/auto-delete-bucket: "false" ibm.io/secret-name: SECRET-NAME #Enter the name of the secret you created earlier. ibm.io/secret-namespace: NAMESPACE #Enter the namespace where you want to create the PVC. spec: accessModes: - ReadWriteOnce resources: requests: storage: 10Gi storageClassName: ibmc-s3fs-cos #The storage class that you want to use. -
Cree la PVC en el clúster.
oc apply -f pvc.yaml -
Cree un archivo de configuración YAML para un pod que monte el PVC que ha creado.
apiVersion: v1 kind: Pod metadata: name: demo-pod namespace: default spec: securityContext: runAsUser: 2000 fsGroup: 2000 volumes: - name: demo-vol persistentVolumeClaim: claimName: demo containers: - name: test image: nginxinc/nginx-unprivileged imagePullPolicy: Always volumeMounts: - name: demo-vol mountPath: /mnt/cosvol -
Cree el pod en el clúster.
oc apply -f demo-pod.yaml -
Verifique que el pod se ha desplegado. Tenga en cuenta que puede tardar unos minutos en entrar en el estado
Running.oc get podsNAME READY STATUS RESTARTS AGE demo-pod 1/1 Running 0 2m58s -
Verifique que la aplicación puede grabar en el volumen de almacenamiento de bloques iniciando sesión en el pod.
oc exec demo-pod -- bash -c "ls /mnt/cosvol"test.txt