Upgrade SDS in Kubernetes and OpenShift
Download the Latest Artifacts
-
In Strategy Community, in the Federated Data Connectors category, download the following artifacts for Secure Data Service (SDS):
-
The Helm chart package:
secure-data-service-helm.tgz -
The matching SDS container package:
secure-data-service-container.zip
Do not install the chart before preparing the corresponding image. The chart contains only Kubernetes manifests; it does not include the SDS container image. Do not mix a chart from one release with a container package from a different release.
-
-
Extract the two artifacts into separate directories. For example:
Copymkdir -p "$HOME/sds-release/chart" "$HOME/sds-release/image"
tar -xzf secure-data-service-helm.tgz -C "$HOME/sds-release/chart"
unzip secure-data-service-container.zip -d "$HOME/sds-release/image"
find "$HOME/sds-release" -name dgs-sds.tar -o -name Chart.yaml -
The container package contains
dgs-sds.tar, a Docker image archive. The embedded image name includes the release build tag. Note that name before loading the image:Copydocker load --input "$HOME/sds-release/image/dgs-sds.tar"This command prints the loaded image reference (including the tag). Use that reference in the next step. If
dgs-sds.taris extracted into a different subdirectory, use its actual path in thedocker loadcommand.
Make the SDS Image Available to the Cluster
-
Push the SDS image to a registry that is reachable from all cluster nodes, preferably a private registry.
-
Tag the image loaded in the previous step with your fully qualified repository name and an immutable release tag and push the image. Replace the example values with your registry, repository, and release version:
Copydocker tag dgs-sds:<embedded-build-tag> \
registry.example.com/microstrategy/dgs-sds:<release-version>
docker push registry.example.com/microstrategy/dgs-sds:<release-version> -
For production environments, obtain the image digest after pushing and use the digest in the Helm installation.
-
If the registry requires authentication, create an image pull Secret in the target namespace and provide its name as image.pullSecret in the Helm values and commands used in the following steps of the next section.
-
For Kubernetes:
Copykubectl create namespace <namespace>
kubectl -n <namespace> create secret docker-registry sds-registry \
--docker-server=registry.example.com \
--docker-username='<registry-user>' \
--docker-password='<registry-password>' -
For RedHat OpenShift:
Copyoc create namespace <namespace>
oc -n <namespace> create secret docker-registry sds-registry \
--docker-server=registry.example.com \
--docker-username='<registry-user>' \
--docker-password='<registry-password>'
Where required, use your organization's approved secret-management process instead of storing registry credentials in a shell history or local configuration files.
-
Perform the Upgrade
Review the release notes for any configuration changes or data migration requirements.
-
For Kubernetes:
Copyhelm upgrade sds . \
--namespace <namespace> \
--values sds-values.yaml \
--set image.tag=<new-release-version> \
--set image.digest=sha256:<new-64-hex-digest> \
--wait \
--timeout 10m
kubectl rollout status statefulset/sds -n <namespace> --timeout=10m -
For OpenShift:
Copyhelm upgrade sds . \
--namespace <namespace> \
--values sds-values.yaml \
--set image.tag=<new-release-version> \
--set image.digest=sha256:<new-64-hex-digest> \
--wait \
--timeout 10m
oc rollout status statefulset/sds -n <namespace> --timeout=10m
If the original installation used a values file, reuse that file for the upgrade, or use --reuse-values only after reviewing the resulting configuration.
Do not silently change to a default image or latest during an upgrade. Before modifying any data-affected settings, back up the PVCs and retain an upgrade record for future reference.
