LFR
-
Log in to the Artifactory site using Virsec-provided credentials from the local machine
-
Navigate to the directory vsp > releases > public > 2 > 2.9 > <Patch_Version> > Helm
-
Right-click on the file vsp-lfr-<version>.tgz, listed on the page and download it to the local system
-
Install VSP LFR by executing the below steps:
-
Log in to the Management Node
-
Copy the downloaded file vsp-lfr-<version>.tgz
-
-
Execute the below command to display the configurable parameters:
-
helm inspect values ./vsp-lfr-<version>.tgz
-
-
(Optional) Instead of a complete LFR refresh, only the required LFR files can be downloaded in an incremental refresh
When prompted, provide the Artifactory username and password.
-
CMS_SYNC: Update all the CMS files. Once the script execution is complete, ensure that the script setup.sh is also executed
-
VSP_OS_LIST: Specify the required Operating System (comma separated without spaces)
-
VSP_OS_VERSIONS: Provide the version numbers for the specified Operating System (comma separated without spaces)
-
VSP_OS_SKUS: Provide the required SKU. Allowed values are web, host, mem. By default, files related to all SKUs are downloaded
-
image.env.RELEASE: VSP Release Version. Example: 2.9.0
-
-
Execute the below commands to install LFR and display the LFR URL (using either Method 1 or 2)
-
Method 1: Using helm upgrade command
-
For On-Premise environments:
-
Helm 3:
helm upgrade vsp-lfr ./vsp-lfr-<RELEASE_VERSION>.tgz --set artifactory.username="<ARTIFACTORY_USERNAME>" --set artifactory.password='<ARTIFACTORY_PASSWORD>' --set artifactory.token="<ARTIFACTORY_TOKEN>" --namespace virsec
-
Helm 2:
helm upgrade --name vsp-lfr ./vsp-lfr-<RELEASE_VERSION>.tgz --set artifactory.username="<ARTIFACTORY_USERNAME>" --set artifactory.password='<ARTIFACTORY_PASSWORD>' --set artifactory.token="<ARTIFACTORY_TOKEN>" --namespace virsec
-
-
For AWS EKS/ GOOGLE GKE environments:
-
Helm 3:
helm upgrade vsp-lfr ./vsp-lfr-<RELEASE_VERSION>.tgz --set cloudProvider=eks --set artifactory.username="<ARTIFACTORY_USERNAME>" --set artifactory.password='<ARTIFACTORY_PASSWORD>' --set artifactory.token="<ARTIFACTORY_TOKEN>" --namespace virsec
-
Helm 2:
helm upgrade --name vsp-lfr ./vsp-lfr-<RELEASE_VERSION>.tgz --set cloudProvider=eks --set artifactory.username="<ARTIFACTORY_USERNAME>" --set artifactory.password='<ARTIFACTORY_PASSWORD>' --set artifactory.token="<ARTIFACTORY_TOKEN>" --namespace virsec
-
-
Verification: Execute the below command to verify the upgrade:
helm status vsp-lfr
-
Execute the provided commands to retrieve LFR URL:
kubectl -n virsec get pods -o wide -l run=vsp-lfr | grep vsp-lfr | awk '{print $7}' | xargs -I {} kubectl -n virsec get node -o wide {} | tail -n 1 | awk '{print $6}') | xargs -I {} kubectl patch service vsp-lfr -n virsec -p '{"spec":{"externalIPs": [ "{}" ]}}'
export SERVICE_IP=$(kubectl get svc --namespace virsec vsp-lfr -o jsonpath='{.spec.externalIPs[0]}')
echo https://$SERVICE_IP:8443/vsp
-
-
Method 2: Using kubectl command
-
For On-Premise environments:
-
Helm 3:
helm template vsp-lfr ./vsp-lfr-<RELEASE_VERSION>.tgz --set artifactory.username="<ARTIFACTORY_USERNAME>" --set artifactory.password='<ARTIFACTORY_PASSWORD>' --set artifactory.token="<ARTIFACTORY_TOKEN>" --namespace virsec > vsp-lfr.yaml
-
Helm 2:
helm template --name vsp-lfr ./vsp-lfr-<RELEASE_VERSION>.tgz --set artifactory.username="<ARTIFACTORY_USERNAME>" --set artifactory.password='<ARTIFACTORY_PASSWORD>' --set artifactory.token="<ARTIFACTORY_TOKEN>" --namespace virsec > vsp-lfr.yaml
-
-
For AWS EKS/ GOOGLE GKE environments:
-
Helm 3:
helm template vsp-lfr ./vsp-lfr-<RELEASE_VERSION>.tgz --set cloudProvider=eks --set artifactory.username="<ARTIFACTORY_USERNAME>" --set artifactory.password='<ARTIFACTORY_PASSWORD>' --set artifactory.token="<ARTIFACTORY_TOKEN>" --namespace virsec > vsp-lfr.yaml
-
Helm 2:
helm template --name vsp-lfr ./vsp-lfr-<RELEASE_VERSION>.tgz --set cloudProvider=eks --set artifactory.username="<ARTIFACTORY_USERNAME>" --set artifactory.password='<ARTIFACTORY_PASSWORD>' --set artifactory.token="<ARTIFACTORY_TOKEN>" --namespace virsec > vsp-lfr.yaml
-
-
Execute the below commands to deploy LFR URL:
kubectl apply -f vsp-lfr.yaml
-
Execute the below commands to retrieve LFR URL:
kubectl -n virsec get pods -o wide -l run=vsp-lfr | grep vsp-lfr | awk '{print $7}' | xargs -I {} kubectl -n virsec get node -o wide {} | tail -n 1 | awk '{print $6}') | xargs -I {} kubectl patch service vsp-lfr -n virsec -p '{"spec":{"externalIPs": [ "{}" ]}}'
export SERVICE_IP=$(kubectl get svc --namespace virsec vsp-lfr -o jsonpath='{.spec.externalIPs[0]}')
echo https://$SERVICE_IP:8443/vsp
-
-