Contact Us 1-800-596-4880

Installing Anypoint Platform PCE on OpenShift

Before installing Anypoint Platform Private Cloud Edition (Anypoint Platform PCE) on OpenShift configure Security Context Constraints (SCC) to grant the required permissions for pods and create roles for Prometheus, allowing it to collect metrics from the services. After these configurations are complete, proceed with installing Anypoint Platform PCE.

Contact MuleSoft Professional Services or your Anypoint PCE Certified Partner to perform the installation or upgrade of Anypoint Platform PCE.
You must have an operational OpenShift cluster prior to installing Anypoint Platform PCE. If you do not have one set up, refer to the OpenShift documentation for setup instructions.
Anypoint Platform PCE 4.2.1 is installed and validated on OpenShift 4.18 and 4.20.
It isn’t supported to in-place upgrade from an existing Openshift PCE 4.1.x cluster that’s been installed with full admin privilege to 4.2.1 or higher with no admin scope. If this is your case, consult Migrating Anypoint Platform PCE to v4.x.

Configure the Openshift Environment

To configure the OpenShift Environment, configure Security Context Constraints (SCC) and roles for Prometheus.

Configure Security Context Constraints (SCC)

This snippet contains the SCC configuration:

apiVersion: security.openshift.io/v1
kind: SecurityContextConstraints
metadata:
  name: anypoint-anyuid
allowHostDirVolumePlugin: false
allowHostIPC: false
allowHostNetwork: false
allowHostPID: false
allowHostPorts: false
allowPrivilegeEscalation: false
allowPrivilegedContainer: false
allowedCapabilities: null
defaultAddCapabilities: null
fsGroup:
  type: RunAsAny
users: []
groups: []
readOnlyRootFilesystem: false
requiredDropCapabilities:
  - MKNOD
runAsUser:
  type: MustRunAs
  uid: 2020
seLinuxContext:
  type: MustRunAs
seccompProfiles:
  - runtime/default
supplementalGroups:
  type: RunAsAny
volumes:
  - configMap
  - csi
  - downwardAPI
  - emptyDir
  - ephemeral
  - persistentVolume
  - persistentVolumeClaim
  - projected
  - secret
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  name: anypoint-scc
  namespace: pce-core
rules:
  - apiGroups: [ "security.openshift.io" ]
    resourceNames:
      - anypoint-anyuid
    resources: [ "securitycontextconstraints" ]
    verbs: [ "use" ]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: anypoint-scc
roleRef:
  apiGroup: rbac.authorization.k8s.io
  kind: ClusterRole
  name: anypoint-scc
subjects:
  - kind: ServiceAccount
    name: pce-cluster-ssl-app
    namespace: pce-core
  - kind: ServiceAccount
    name: default
    namespace: pce-core
  - kind: ServiceAccount
    name: anypoint
    namespace: pce-core
  - kind: ServiceAccount
    name: anypoint-install
    namespace: pce-core
  - kind: ServiceAccount
    name: anypoint-install-anypoint-services
    namespace: pce-core
  - kind: ServiceAccount
    name: anypoint-install-cluster-ssl
    namespace: pce-core
  - kind: ServiceAccount
    name: anypoint-install-namespaces-job
    namespace: pce-core
  - kind: ServiceAccount
    name: anypoint-install-seaweedfs
    namespace: pce-core
  - kind: ServiceAccount
    name: anypoint-prometheus-install
    namespace: pce-core
  - kind: ServiceAccount
    name: anypoint-grafana-install
    namespace: pce-core
  - kind: ServiceAccount
    name: anypoint-install
    namespace: dias
  - kind: ServiceAccount
    name: default
    namespace: pce
  - kind: ServiceAccount
    name: default
    namespace: access-management
  - kind: ServiceAccount
    name: authentication-server-service-account
    namespace: access-management
  - kind: ServiceAccount
    name: default
    namespace: api-console-proxy
  - kind: ServiceAccount
    name: default
    namespace: amf
  - kind: ServiceAccount
    name: default
    namespace: arm
  - kind: ServiceAccount
    name: default
    namespace: api-manager
  - kind: ServiceAccount
    name: default
    namespace: mozart
  - kind: ServiceAccount
    name: default
    namespace: mocking
  - kind: ServiceAccount
    name: default
    namespace: api-manager
  - kind: ServiceAccount
    name: default
    namespace: audit-log
  - kind: ServiceAccount
    name: default
    namespace: trusted-domains
  - kind: ServiceAccount
    name: default
    namespace: api-designer
  - kind: ServiceAccount
    name: monitoring
    namespace: pce
  - kind: ServiceAccount
    name: default
    namespace: exchange
  - kind: ServiceAccount
    name: xapi-service-deployment-manager
    namespace: exchange
  - kind: ServiceAccount
    name: default
    namespace: core-paas
  - kind: ServiceAccount
    name: default
    namespace: monitoring-center
  - kind: ServiceAccount
    name: default
    namespace: visualizer
  - kind: ServiceAccount
    name: secrets-robot
    namespace: dias
  - kind: ServiceAccount
    name: default
    namespace: dias
  - kind: ServiceAccount
    name: default
    namespace: amc
  - kind: Group
    name: system:serviceaccounts:monitoring
  - kind: ServiceAccount
    name: default
    namespace: anypoint-flash
  - kind: ServiceAccount
    name: default
    namespace: design-center

---

apiVersion: security.openshift.io/v1
kind: SecurityContextConstraints
metadata:
  name: anypoint-anyuid-privileged
allowHostDirVolumePlugin: false
allowHostIPC: false
allowHostNetwork: false
allowHostPID: false
allowHostPorts: false
allowPrivilegeEscalation: true
allowPrivilegedContainer: false
allowedCapabilities: null
defaultAddCapabilities: null
fsGroup:
  type: RunAsAny
users: []
groups: []
readOnlyRootFilesystem: false
requiredDropCapabilities:
  - MKNOD
runAsUser:
  type: RunAsAny
seLinuxContext:
  type: MustRunAs
seccompProfiles:
  - runtime/default
supplementalGroups:
  type: RunAsAny
volumes:
  - configMap
  - csi
  - downwardAPI
  - emptyDir
  - ephemeral
  - persistentVolume
  - persistentVolumeClaim
  - projected
  - secret
  - nfs
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  name: anypoint-scc-privileged
rules:
  - apiGroups: [ "security.openshift.io" ]
    resourceNames:
      - anypoint-anyuid-privileged
    resources: [ "securitycontextconstraints" ]
    verbs: [ "use" ]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: anypoint-scc-privileged
roleRef:
  apiGroup: rbac.authorization.k8s.io
  kind: ClusterRole
  name: anypoint-scc-privileged
subjects:
- kind: ServiceAccount
  name: stolon
  namespace: pce-core
- kind: ServiceAccount
  name: default
  namespace: pce-core
- kind: ServiceAccount
  name: anypoint-install
  namespace: pce-core
- kind: ServiceAccount
  name: seaweedfs-rw-sa
  namespace: pce-core
- kind: ServiceAccount
  name: default
  namespace: api-manager
- kind: ServiceAccount
  name: default
  namespace: design-center
- kind: ServiceAccount
  name: default
  namespace: exchange
- kind: ServiceAccount
  name: default
  namespace: logging-internal
- kind: ServiceAccount
  name: default
  namespace: pce
- kind: ServiceAccount
  name: monitoring
  namespace: pce
- kind: ServiceAccount
  name: default
  namespace: trusted-domains
- kind: ServiceAccount
  name: default
  namespace: mocking

---
apiVersion: security.openshift.io/v1
kind: SecurityContextConstraints
metadata:
  name: anypoint-pce-monitoring
allowHostDirVolumePlugin: false
allowHostIPC: false
allowHostNetwork: false
allowHostPID: false
allowHostPorts: false
allowPrivilegeEscalation: false
allowPrivilegedContainer: false
allowedCapabilities: null
defaultAddCapabilities: null
fsGroup:
  type: RunAsAny
users: []
groups: []
readOnlyRootFilesystem: false
requiredDropCapabilities:
  - MKNOD
runAsUser:
  type: MustRunAs
  uid: 472
seLinuxContext:
  type: MustRunAs
seccompProfiles:
  - runtime/default
supplementalGroups:
  type: RunAsAny
volumes:
  - configMap
  - csi
  - downwardAPI
  - emptyDir
  - ephemeral
  - persistentVolumeClaim
  - projected
  - secret
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  name: anypoint-pce-monitoring
rules:
  - apiGroups: [ "security.openshift.io" ]
    resourceNames:
      - anypoint-pce-monitoring
    resources: [ "securitycontextconstraints" ]
    verbs: [ "use" ]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: anypoint-pce-monitoring
roleRef:
  apiGroup: rbac.authorization.k8s.io
  kind: ClusterRole
  name: anypoint-pce-monitoring
subjects:
- kind: ServiceAccount
  name: grafana
  namespace: monitoring

Save this file as openshift-scc.yaml and apply it to the OpenShift cluster:

oc apply -f openshift-scc.yaml

Configure Roles for Prometheus

Prometheus requires specific roles to collect metrics from Anypoint Platform PCE services. The following snippet provides the necessary roles configuration:

apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  name: pce-prometheus
rules:
  - apiGroups:
      - ""
    resources:
      - endpoints
      - pods
      - services
      - nodes
      - secrets
    verbs:
      - get
      - list
      - watch
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: pce-prometheus
roleRef:
  apiGroup: rbac.authorization.k8s.io
  kind: ClusterRole
  name: pce-prometheus
subjects:
  - kind: ServiceAccount
    name: prometheus-k8s
    namespace: openshift-monitoring

Save this file as openshift-monitoring.yaml and apply it to the OpenShift cluster:

oc apply -f openshift-monitoring.yaml

Install Anypoint Platform PCE on OpenShift

Create an input.yaml file using this template and update it with your environment details. This template matches the PCE 4.2 installation configuration, with monitoring settings for OpenShift:

# Container Registry configuration to upload PCE images
containerRegistry:
  endpoint: "" # Container Registry Endpoint
  username: "" # Provide either Username/Password OR Certificate to authenticate with container registry
  password: ""
  certificate: "/etc/registry/certificate/ca.crt"
  subproject: "mulesoft" # Container registry subproject under which all the PCE images will be part of.
  tlsSkipVerify: True  # True or False.
# Platform configuration using CSI driver for filesystem access
platformConfiguration:
  platformDNS: ""
  fileSystemCsiDriverName: "" # CSI driver name (e.g., nfs.csi.k8s.io, efs.csi.aws.com)
  # Provide NFS DNS and path (not required if using EFS CSI Driver)
  # fileSystemDNS: ""
  # fileSystemPath: ""
  # Provide individual NFS volume handles (all 4 are required if using EFS CSI Driver. You'll need to create 4 access points pointing to the same dir in the EFS)
  fileSystemWcCsiVolumeHandle: "" # CSI volume handle for wc filesystem. E.g.: fs-0835b0d1eb7588eb1::fsap-03f6c68563ceb5acf
  fileSystem01CsiVolumeHandle: "" # CSI volume handle for 01 filesystem
  fileSystemBareCsiVolumeHandle: "" # CSI volume handle for bare filesystem
  fileSystemBackupRestoreCsiVolumeHandle: "" # CSI volume handle for backup-restore filesystem
  platformCertificate: /path/to/platform/certificate/cert.crt
  platformCertificateKey: path/to/platform/certificate/cert.key
  firstUserAccount:
    organizationName: 'Test Org'
    username: 'username'
    email: 'username@mulesoft.com'
    password: '<a-valid-password>'
# Storage class configuration for persistent data services
storageConfiguration:
  pceobjectstore:
    type: "persistentVolumeClaim"
    storageClass: "<storage-class-name>"
    controlPlaneSize: "10Gi" # Optional. Defaults to 10Gi
    volumeSize: "100Gi" # Optional. Defaults to 100Gi
    volumeIndexSize: "10Gi" # Optional. Defaults to 10Gi
  stolon:
    type: "persistentVolumeClaim"
    storageClass: "<storage-class-name>"
    size: "100Gi" # Optional. Defaults to 100Gi
  backupRestoreTmp:
    storageClass: "<storage-class-name>" # Storage class for backup/restore temporary storage
# Configuration options for monitoring stack
monitoringAppConfiguration:
  monitoringStack:
    enabled: False # Defaults to True. Must be set to False for Openshift clusters.
# Grafana configuration for OpenShift. Disable the monitoring stack because OpenShift includes Prometheus by default.
  grafana:
    enabled: True # Defaults to False.
    values: |
      datasources:
        datasources.yaml:
          apiVersion: 1
          datasources:
          - name: Prometheus
            type: prometheus
            url: https://prometheus-k8s.openshift-monitoring.svc:9091
            access: proxy
            isDefault: true
            jsonData:
              tlsSkipVerify: true
              httpHeaderName1: 'Authorization'
            secureJsonData:
              httpHeaderValue1: 'Bearer <Token>'

In the monitoringAppConfiguration section, set monitoringStack.enabled to False and enable only Grafana. Disable the Anypoint Platform PCE monitoring stack because OpenShift includes Prometheus by default. Enable Grafana and configure its datasource to connect to Prometheus.

To obtain the token for connecting to Prometheus, run this command:

oc create token prometheus-k8s -n openshift-monitoring --duration=87600h

After you complete the installation, run these commands to allow Prometheus in OpenShift to collect metrics from platform services:

oc label namespace default openshift.io/cluster-monitoring="true" --overwrite
oc label namespace pce openshift.io/cluster-monitoring="true" --overwrite