Showing posts with label OCI. Show all posts
Showing posts with label OCI. Show all posts

Uploading image thru Docker in OCI

Upload of image thru GUI OCI console or you can either user cloudshell or thru OCI executable.
To upload you need
- auth key
- tag
- registry name

Auth key generation

You can have maximum of 2 auth keys for the user and make sure you save key when its generated.

oci ce cluster generate-token --cluster-id ocid1.cluster.oc1.iad.....


This should generate less than 20chars and keep it safe.


Docker login

Login into docker using your id. If you are using your corporate SSO, you have to use your OCI federated id and auth token is the password.


docker login us-ashburn-1.ocir.io

Username: <tenancy>/oracleidentitycloudservice/ajit.solomon

Password:

Login Succeeded


Now from your local docker repo you can upload to OCI repository by tagging it.


Docker push

To tag, you have provide region/tenanency/registry_name

docker tag cd14cecfdb3a us-ashburn-1.ocir.io/<tenanency>/jenkins:latest


Prerequisite for pushing an image is to create manually an empty repo/image thru OCI gui. For example, if you want to push the above tagged image jenkins, then go to Container Registry --> Create Registry as jenkins


Now you can push image to OCI registry


docker push us-ashburn-1.ocir.io/<tenanency>/jenkins:latest


If it doesn't find the registry, then OCI will attempt to create it under root compartment.

You can view if it's successful in Developer Services --> Registry(OCIR)




OCI - Manual creation of Instance from scratch

All the action provided here can be done from OCI console thru clicks. This is when you want to scripting thru OCI cli. You can either use cloudshell or install OCI module for your desktop.
Most of values we use is either configured in config or oci_cli_rc files.
As I use some of the resource very frequently, I had put, 
- user
- fingerprint
- key_file
- tenancy
- region
- compartment-id
- availability-domain

I had used CLI to configure from compartment to instance creation.

oci iam compartment create --name 'Ajit' --description "Testing OCI"

{

  "data": {

    "compartment-id": "ocid1.tenancy.oc1.....",

  ------------------------------------------------------------------------------------------------------------------------------

With that you have place to create your resources with assumption that proper quota is allocated.

Each compartment needs to have VCN for proper seperation.


oci network vcn create --cidr-block 192.168.0.0/16 --display-name AjitVcn1 --dns-label AjitDns1


This will allow us to carve out subnet in the vcn

oci network subnet create --cidr-block 192.168.10.0/24 --vcn-id ocid1.vcn.oc1.iad.... --security-list-ids '["ocid1.securitylist.oc1...."]'

Both vcn-id and security-list-ids is taken from "oci network vcn create" output


  ------------------------------------------------------------------------------------------------------------------------------

Now we can move to connect the vcn to connect to outside the instance vcn.

oci network internet-gateway create --is-enabled true --vcn-id ocid1.vcn.oc1.iad.... --display-name AjitGW

After opening up the Gateway for the vcn, we need to streamline who can connect to our GW.

Route table info can be seen in "oci network subnet create" output.

oci network route-table update --rt-id ocid1.routetable.oc1.iad.... --route-rules '[{"cidrBlock":"0.0.0.0/0","networkEntityId":"ocid1.internetgateway.oc1.iad...."}]'

  ------------------------------------------------------------------------------------------------------------------------------


All our setup to spin up compute is ready. Make sure you generate ssh key before you spin up the compute.

oci compute instance launch --display-name AjitVm --image-id ocid1.image.oc1.iad.... --subnet-id ocid1.subnet.oc1.iad.... --shape VM.Standard2.1 --assign-public-ip true --metadata '{"ssh_authored_keys":"ajit"}'


You can confirm the creation using "oci compute instance get"

Using the key, you can login thru opc user.