Embed workload container images for offline use
To embed container images in devices at the edge that do not have any network connection, you must create a new container, mount the ISO, and then copy the contents into the file system.
-
You have root access to the host.
-
Application RPMs have been added to a blueprint.
-
You installed the OpenShift CLI (
oc).
-
Render the manifests, extract all of the container image references, and translate the application image to blueprint container sources by running the following command:
$ oc kustomize ~/manifests | grep "image:" | grep -oE '[^ ]+$' | while read line; do echo -e "[[containers]]\nsource = \"${line}\"\n"; done >><my_blueprint>.toml -
Push the updated blueprint to image builder by running the following command:
$ sudo composer-cli blueprints push <my_blueprint>.toml -
If your workload containers are located in a private repository, you must provide image builder with the necessary pull secrets:
-
Set the
auth_file_pathin the[containers]section in the/etc/osbuild-worker/osbuild-worker.tomlconfiguration file to point to the pull secret. -
If needed, create a directory and file for the pull secret, for example:
Example directory and file[containers] auth_file_path = "/<path>/pull-secret.json"Use the custom location previously set for copying and retrieving images.
-
-
Build the container image by running the following command:
$ sudo composer-cli compose start-ostree <my_blueprint> edge-commit -
Proceed with your preferred
rpm-ostreeimage flow, such as waiting for the build to complete, exporting the image and integrating it into yourrpm-ostreerepository or creating a bootable ISO.