Skip to content

Commit 60c0f4c

Browse files
authored
Merge pull request #726 from mhjacks/update_rdrsk_docs
Update RDR SK Docs for v1.3
2 parents a6aef5b + e0b666e commit 60c0f4c

20 files changed

Lines changed: 3186 additions & 67 deletions

‎content/patterns/ramendr-starter-kit/_index.adoc‎

Lines changed: 38 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -44,10 +44,29 @@ The setup process is relatively intricate; the goal of this pattern is to handle
4444
a functional DR-capable starting point for Virtual Machine workloads. In particular this pattern takes care to sequence
4545
installations and validate pre-requisites for all of the core components of the Disaster Recovery system.
4646

47-
In particular, this pattern must be customized to specify DNS basedomains for the managed clusters, which makes
48-
forking the pattern (which we generally recommend anyway, in case you want to make other customizations) effectively
49-
a requirement. The link:https://validatedpatterns/patterns/getting-started[**Getting Started**] doc has
50-
details on what needs to be changed and how to commit and push those changes.
47+
You might fork the repository to customize chart values (for example `aws.region` in
48+
link:https://github.com/validatedpatterns/ramendr-starter-kit/blob/main/charts/hub/rdr/values.yaml[`charts/hub/rdr/values.yaml`])
49+
or to select a non-default install variant. The link:/patterns/ramendr-starter-kit/getting-started/[Getting started] page describes variant
50+
selection, BYOC, required secrets, and verification steps.
51+
52+
[id="install-variants"]
53+
=== Install variants
54+
55+
The pattern ships three install variants under `variants/` in the repository. Set `main.variant` in
56+
link:https://github.com/validatedpatterns/ramendr-starter-kit/blob/main/values-global.yaml[`values-global.yaml`]
57+
before install. The default is `odf`.
58+
59+
[cols="1,1,3",options="header"]
60+
|===
61+
| Variant | `main.variant` | Purpose
62+
| `odf` | `odf` (default) | Full {ocp-data-short} Regional DR with {VirtProductName} workloads, MirrorPeer, and failover-capable VMs
63+
| `drpartner-s4` | `drpartner-s4` | Partner CSI foundation with hub S4 object storage: OADP, {VirtProductName}, Ramen/Multicluster Orchestrator; infrastructure DRClusters and a `2m-novm` DRPolicy without DRPC or VMs; Submariner disabled
64+
| `drpartner-minimal` | `drpartner-minimal` | Partner CSI foundation without S4, Submariner, or DRCluster sync/validation: OADP, {VirtProductName}, and Ramen/Multicluster Orchestrator only (Hive or BYOC bring-up)
65+
|===
66+
67+
Spoke configuration files nest under each variant as `variants/<variant>/values-<managedClusterGroup.name>.yaml`.
68+
See link:/patterns/ramendr-starter-kit/installation-details/#variant-installation-differences[Installation details] for what each variant deploys on the hub and managed clusters.
69+
For component schematics, connectivity paths, and TLS/CA handling, see link:/patterns/ramendr-starter-kit/architecture/[Architecture] and link:/patterns/ramendr-starter-kit/connectivity/[Connectivity].
5170

5271
=== Background
5372

@@ -74,7 +93,20 @@ This pattern uses OpenShift Virtualization (the productization of Kubevirt) to s
7493
* HashiCorp Vault (Community Edition)
7594
* External Secrets Operator (Community Edition)
7695

77-
=== Architecture
96+
=== Architecture overview
97+
98+
The default `odf` variant deploys a three-cluster Regional DR layout with {ocp-data-short}, Submariner, DRPC-protected VMs, and failover workflows documented in link:/patterns/ramendr-starter-kit/getting-started/[Getting started].
7899

79100
.ramendr-architecture-diagram
80-
image::/images/ramendr-starter-kit/ramendr-architecture.drawio.png[ramendr-starter-kit-architecture,title="RamenDR Starter Kit Architecture"]
101+
image::/images/ramendr-starter-kit/ramendr-architecture-odf.png[ramendr-starter-kit-architecture,title="RamenDR Starter Kit architecture (odf)"]
102+
103+
draw.io source: link:/images/ramendr-starter-kit/ramendr-architecture-odf.drawio[`ramendr-architecture-odf.drawio`]
104+
105+
Partner variants use different S3 and replication models. See link:/patterns/ramendr-starter-kit/architecture/[Architecture] for per-variant schematics and draw.io sources, and link:/patterns/ramendr-starter-kit/connectivity/[Connectivity] for hub-to-managed network paths and ports.
106+
107+
=== Next steps
108+
109+
* link:/patterns/ramendr-starter-kit/architecture/[Architecture] — Component schematics, TLS/CA, draw.io sources
110+
* link:/patterns/ramendr-starter-kit/connectivity/[Connectivity] — Hub-to-managed connectivity by variant
111+
* link:/patterns/ramendr-starter-kit/getting-started/[Getting started] — Prerequisites, variant selection, BYOC, and deployment
112+
* link:/patterns/ramendr-starter-kit/installation-details/[Installation details] — Install sequence and pattern scripts
Lines changed: 105 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,105 @@
1+
---
2+
title: Architecture
3+
weight: 5
4+
aliases: /ramendr-starter-kit/architecture/
5+
---
6+
7+
:toc:
8+
:imagesdir: /images
9+
:_content-type: ASSEMBLY
10+
include::modules/comm-attributes.adoc[]
11+
12+
[id="ramendr-architecture"]
13+
= Architecture
14+
15+
This page describes component schematics, connectivity overview diagrams, and TLS/CA handling for each install variant. For hub-to-managed network paths and ports, see link:/patterns/ramendr-starter-kit/connectivity/[Connectivity].
16+
17+
[id="architecture-diagrams"]
18+
== Architecture diagrams
19+
20+
Each install variant has a full hub/spoke schematic exported as PNG from draw.io source. PNG and draw.io files live in `static/images/ramendr-starter-kit/`.
21+
22+
[cols="2,1,2,2",options="header"]
23+
|===
24+
| Diagram | Variant | PNG | draw.io source
25+
26+
| `ramendr-architecture-odf`
27+
| `odf`
28+
| link:/images/ramendr-starter-kit/ramendr-architecture-odf.png[`ramendr-architecture-odf.png`]
29+
| link:/images/ramendr-starter-kit/ramendr-architecture-odf.drawio[`ramendr-architecture-odf.drawio`]
30+
31+
| `ramendr-architecture-drpartner-s4`
32+
| `drpartner-s4`
33+
| link:/images/ramendr-starter-kit/ramendr-architecture-drpartner-s4.png[`ramendr-architecture-drpartner-s4.png`]
34+
| link:/images/ramendr-starter-kit/ramendr-architecture-drpartner-s4.drawio[`ramendr-architecture-drpartner-s4.drawio`]
35+
36+
| `ramendr-architecture-drpartner-minimal`
37+
| `drpartner-minimal`
38+
| link:/images/ramendr-starter-kit/ramendr-architecture-drpartner-minimal.png[`ramendr-architecture-drpartner-minimal.png`]
39+
| link:/images/ramendr-starter-kit/ramendr-architecture-drpartner-minimal.drawio[`ramendr-architecture-drpartner-minimal.drawio`]
40+
41+
| `hub-managed-connectivity`
42+
| All variants
43+
| link:/images/ramendr-starter-kit/hub-managed-connectivity-odf.png[`hub-managed-connectivity-odf.png`] (and per-variant tabs)
44+
| link:/images/ramendr-starter-kit/hub-managed-connectivity.drawio[`hub-managed-connectivity.drawio`]
45+
|===
46+
47+
[id="architecture-odf"]
48+
=== `odf` schematic
49+
50+
Full hub/spoke schematic. DRPolicies live on the hub with the RamenDR Hub Operator and become volume replications and volume group replications on the managed clusters. The hub operator orchestrates the RamenDR Cluster Operators, which manage those replications plus {ocp-data-short} and OpenShift ADP (Kubernetes object backups), along with Submariner and Edge GitOps VMs.
51+
52+
.ramendr-architecture-odf
53+
image::/images/ramendr-starter-kit/ramendr-architecture-odf.png[RamenDR architecture for the odf variant,title="RamenDR Starter Kit architecture (odf)"]
54+
55+
draw.io source: link:/images/ramendr-starter-kit/ramendr-architecture-odf.drawio[`ramendr-architecture-odf.drawio`]
56+
57+
[id="architecture-drpartner-s4"]
58+
=== `drpartner-s4` schematic
59+
60+
Hub S4 Object store for OpenShift ADP Kubernetes object backups. Partner CSI on the managed clusters provides VM data replication. DRPolicies live on the hub and become volume replications and volume group replications on the managed clusters. The RamenDR Hub Operator orchestrates the cluster operators. The pattern does not create DRPC or VMs.
61+
62+
.ramendr-architecture-drpartner-s4
63+
image::/images/ramendr-starter-kit/ramendr-architecture-drpartner-s4.png[RamenDR architecture for the drpartner-s4 variant,title="RamenDR Starter Kit architecture (drpartner-s4)"]
64+
65+
draw.io source: link:/images/ramendr-starter-kit/ramendr-architecture-drpartner-s4.drawio[`ramendr-architecture-drpartner-s4.drawio`]
66+
67+
[id="architecture-drpartner-minimal"]
68+
=== `drpartner-minimal` schematic
69+
70+
{rh-rhacm-first} and partner operators only. S3-compatible storage for OpenShift ADP is bring-your-own; this variant does not deploy S4. DRPolicies live on the hub and become volume replications and volume group replications on the managed clusters. The pattern does not create DR CRs.
71+
72+
.ramendr-architecture-drpartner-minimal
73+
image::/images/ramendr-starter-kit/ramendr-architecture-drpartner-minimal.png[RamenDR architecture for the drpartner-minimal variant,title="RamenDR Starter Kit architecture (drpartner-minimal)"]
74+
75+
draw.io source: link:/images/ramendr-starter-kit/ramendr-architecture-drpartner-minimal.drawio[`ramendr-architecture-drpartner-minimal.drawio`]
76+
77+
[id="tls-and-ca"]
78+
== TLS and CA (current implementation)
79+
80+
Certificate handling is delivered by external charts deployed via Argo CD, not local policy YAML in the pattern repository.
81+
82+
[cols="2,3",options="header"]
83+
|===
84+
| Chart | Role
85+
86+
| **vp-manage-proxy-cluster-ca**
87+
| Differential CA bundle for cluster API/ingress CAs (all variants)
88+
89+
| **opp-policy-chart**
90+
| `s3CaInjector` injects `caCertificates` on Ramen `s3StoreProfiles` (`odf`, `drpartner-s4`)
91+
|===
92+
93+
Chart overrides live in the pattern repository:
94+
95+
* link:https://github.com/validatedpatterns/ramendr-starter-kit/blob/main/overrides/values-vp-manage-proxy-cluster-ca-hub.yaml[`overrides/values-vp-manage-proxy-cluster-ca-hub.yaml`]
96+
* link:https://github.com/validatedpatterns/ramendr-starter-kit/blob/main/overrides/values-vp-manage-proxy-cluster-ca-resilient.yaml[`overrides/values-vp-manage-proxy-cluster-ca-resilient.yaml`]
97+
98+
Manual CA and cluster helpers live under `scripts/` in the pattern repository. Verify resource names against the live cluster before using examples that reference {rh-rhacm} policy names.
99+
100+
[id="related-pages"]
101+
== Related pages
102+
103+
* link:/patterns/ramendr-starter-kit/connectivity/[Connectivity] — Hub-to-managed paths, ports, and variant comparison
104+
* link:/patterns/ramendr-starter-kit/installation-details/[Installation details] — Variant installation differences and pattern scripts
105+
* link:/patterns/ramendr-starter-kit/getting-started/[Getting started] — Variant selection, BYOC, and deployment
Lines changed: 151 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,151 @@
1+
---
2+
title: Connectivity
3+
weight: 15
4+
aliases: /ramendr-starter-kit/connectivity/
5+
---
6+
7+
:toc:
8+
:imagesdir: /images
9+
:_content-type: ASSEMBLY
10+
include::modules/comm-attributes.adoc[]
11+
12+
[id="ramendr-connectivity"]
13+
= Hub-to-managed connectivity
14+
15+
Three install variants (`main.variant` in `values-global.yaml`):
16+
17+
* **odf** (default) — full {ocp-data-short} Regional DR; MCG S3 on managed clusters; Submariner required for Ceph RBD replication
18+
* **drpartner-s4** — partner CSI + hub S4; array-native volume replication; **Submariner disabled** (`submariner.enabled: false` in `opp-policy`)
19+
* **drpartner-minimal** — partner CSI operators and Hive/BYOC plumbing only; no S4, DRClusters, or Submariner
20+
21+
Draw.io source with one tab per variant: link:/images/ramendr-starter-kit/hub-managed-connectivity.drawio[`hub-managed-connectivity.drawio`].
22+
23+
[id="variant-comparison"]
24+
== Variant comparison
25+
26+
[cols="2,1,1,1",options="header"]
27+
|===
28+
| Concern | odf | drpartner-s4 | drpartner-minimal
29+
30+
| S3 / DR metadata | MCG buckets on each managed cluster | Hub S4 buckets (`vp-s4-storage`) | None
31+
| Hub S3 reachability | Hub → each managed MCG endpoint | Hub + managed → hub S4 | n/a
32+
| Peer S3 | Managed ↔ managed object-bucket metadata | Not used | Not used
33+
| Volume replication | {ocp-data-short}/Ceph over Submariner | VSA ↔ VSA (array-native) | External / out of pattern
34+
| Submariner | Required for Regional-DR volumes | **Disabled by default** | **Disabled**
35+
| DRClusters / DRPolicy | MirrorPeer / MCO / regionaldr | regionaldr (`infrastructureEnabled`) | None
36+
| DRPC / VMs | Yes (regionaldr resources) | No (`resourcesEnabled: false`) | No
37+
| {rh-rhacm} + DNS | Required | Required | Required
38+
|===
39+
40+
[id="connectivity-odf"]
41+
== `odf`
42+
43+
{rh-rhacm-first} needs DNS resolvability of managed cluster APIs. S3 metadata buckets (MCG) live **on each managed cluster** — hub and peers both reach those endpoints. **Submariner is required** for {ocp-data-short} RBD cross-site replication.
44+
45+
.ramendr-hub-managed-connectivity-odf
46+
image::/images/ramendr-starter-kit/hub-managed-connectivity-odf.png[odf hub-to-managed connectivity,title="odf connectivity"]
47+
48+
draw.io source: link:/images/ramendr-starter-kit/hub-managed-connectivity.drawio[`hub-managed-connectivity.drawio`] (**odf** tab).
49+
50+
[id="managed-mcg-s3-detail"]
51+
=== Managed MCG S3 detail
52+
53+
++++
54+
<pre class="mermaid">
55+
flowchart LR
56+
Hub["Ramen Hub Operator"] --> MCG1["Primary MCG S3"]
57+
Hub --> MCG2["Secondary MCG S3"]
58+
MCG1 ---|"Peer metadata"| MCG2
59+
</pre>
60+
++++
61+
62+
[id="connectivity-drpartner-s4"]
63+
== `drpartner-s4`
64+
65+
{rh-rhacm-first} needs DNS resolvability of managed cluster APIs. S3 metadata lives on **hub S4** (`vp-s4-storage`). Volume DR is array-native (VSA ↔ VSA). The `regional-dr` application creates hub DRClusters and a `2m-novm` DRPolicy only — no DRPC or VMs. **Submariner is not deployed** (`values-opp-policy.yaml` sets `submariner.enabled: false`).
66+
67+
.ramendr-drpartner-s4-connectivity
68+
image::/images/ramendr-starter-kit/drpartner-s4-connectivity.png[drpartner-s4 hub-to-managed connectivity,title="drpartner-s4 connectivity"]
69+
70+
PNG from draw.io: link:/images/ramendr-starter-kit/hub-managed-connectivity-drpartner-s4.png[`hub-managed-connectivity-drpartner-s4.png`]. SVG source: link:/images/ramendr-starter-kit/drpartner-s4-connectivity.svg[`drpartner-s4-connectivity.svg`]. draw.io source: link:/images/ramendr-starter-kit/hub-managed-connectivity.drawio[`hub-managed-connectivity.drawio`] (**drpartner-s4** tab).
71+
72+
[id="hub-s4-detail"]
73+
=== Hub S4 detail
74+
75+
++++
76+
<pre class="mermaid">
77+
flowchart LR
78+
Ramen["Ramen Hub Operator"] --> S4["Hub S4 buckets"]
79+
P["Primary DR operator"] --> S4
80+
S["Secondary DR operator"] --> S4
81+
</pre>
82+
++++
83+
84+
No managed ↔ managed S3 and no Submariner in `drpartner-s4`.
85+
86+
[id="connectivity-drpartner-minimal"]
87+
== `drpartner-minimal`
88+
89+
{rh-rhacm-first} needs DNS resolvability of managed cluster APIs. The pattern deploys partner operators (MCO/Ramen, {VirtProductName}, OADP) and Hive/BYOC plumbing only — **no `vp-s4-storage`**, no DRClusters, no `s3StoreProfiles`, and **no Submariner**. Volume DR and S3 metadata are outside this pattern.
90+
91+
.ramendr-drpartner-minimal-connectivity
92+
image::/images/ramendr-starter-kit/drpartner-minimal-connectivity.png[drpartner-minimal hub-to-managed connectivity,title="drpartner-minimal connectivity"]
93+
94+
PNG from draw.io: link:/images/ramendr-starter-kit/hub-managed-connectivity-drpartner-minimal.png[`hub-managed-connectivity-drpartner-minimal.png`]. SVG source: link:/images/ramendr-starter-kit/drpartner-minimal-connectivity.svg[`drpartner-minimal-connectivity.svg`]. draw.io source: link:/images/ramendr-starter-kit/hub-managed-connectivity.drawio[`hub-managed-connectivity.drawio`] (**drpartner-minimal** tab).
95+
96+
[id="shared-requirements"]
97+
== Shared requirements
98+
99+
* **{rh-rhacm} + DNS** — Hub must resolve each managed cluster API hostname, then connect over HTTPS 443 / kube API 6443.
100+
* **TLS / CA trust** — Trust custom certs for S4 (`drpartner-s4`) or MCG endpoints (`odf`) via `opp-policy` `s3CaInjector` where S3 is used.
101+
* **Globalnet** — For `odf`, enable if managed cluster/service CIDRs overlap.
102+
103+
[id="ports"]
104+
== Ports
105+
106+
[cols="2,2,2",options="header"]
107+
|===
108+
| Path | When | Protocol / ports
109+
110+
| Hub DNS → managed API | All variants | DNS UDP/TCP 53
111+
| Hub ↔ managed API | All variants | HTTPS 443; kube API 6443
112+
| Clients → hub S4 | `drpartner-s4` | HTTPS 443
113+
| Hub / peers → managed MCG | `odf` | HTTPS 443
114+
| Cluster ↔ local VSA | `drpartner-s4`, `drpartner-minimal` | Vendor CSI / iSCSI / NVMe / mgmt
115+
| VSA ↔ VSA replication | `drpartner-s4`, `drpartner-minimal` | Vendor replication ports
116+
| Submariner | `odf` only | UDP 4500 / 4800 / 4490
117+
|===
118+
119+
[id="related-diagrams"]
120+
== Related diagrams
121+
122+
[cols="2,2,2",options="header"]
123+
|===
124+
| Artifact | PNG | draw.io / other
125+
126+
| Full component schematic (`odf`)
127+
| link:/images/ramendr-starter-kit/ramendr-architecture-odf.png[`ramendr-architecture-odf.png`]
128+
| link:/images/ramendr-starter-kit/ramendr-architecture-odf.drawio[`ramendr-architecture-odf.drawio`]
129+
130+
| Full component schematic (`drpartner-s4`)
131+
| link:/images/ramendr-starter-kit/ramendr-architecture-drpartner-s4.png[`ramendr-architecture-drpartner-s4.png`]
132+
| link:/images/ramendr-starter-kit/ramendr-architecture-drpartner-s4.drawio[`ramendr-architecture-drpartner-s4.drawio`]
133+
134+
| Full component schematic (`drpartner-minimal`)
135+
| link:/images/ramendr-starter-kit/ramendr-architecture-drpartner-minimal.png[`ramendr-architecture-drpartner-minimal.png`]
136+
| link:/images/ramendr-starter-kit/ramendr-architecture-drpartner-minimal.drawio[`ramendr-architecture-drpartner-minimal.drawio`]
137+
138+
| Connectivity overview (`odf`)
139+
| link:/images/ramendr-starter-kit/hub-managed-connectivity-odf.png[`hub-managed-connectivity-odf.png`]
140+
| link:/images/ramendr-starter-kit/hub-managed-connectivity.drawio[`hub-managed-connectivity.drawio`]
141+
142+
| Connectivity overview (`drpartner-s4`)
143+
| link:/images/ramendr-starter-kit/hub-managed-connectivity-drpartner-s4.png[`hub-managed-connectivity-drpartner-s4.png`]
144+
| link:/images/ramendr-starter-kit/drpartner-s4-connectivity.svg[`drpartner-s4-connectivity.svg`]
145+
146+
| Connectivity overview (`drpartner-minimal`)
147+
| link:/images/ramendr-starter-kit/hub-managed-connectivity-drpartner-minimal.png[`hub-managed-connectivity-drpartner-minimal.png`]
148+
| link:/images/ramendr-starter-kit/drpartner-minimal-connectivity.svg[`drpartner-minimal-connectivity.svg`]
149+
|===
150+
151+
See also link:/patterns/ramendr-starter-kit/architecture/[Architecture] for TLS/CA handling and full schematic context.

0 commit comments

Comments
 (0)