Skip to main content

Use Your Own Registry or Install Offline

Every Racora image is pulled from one namespace, registry.gitlab.com/cognitive-network-solutions/racora/* (the component images re-rooted to their basenames, third-party images as mirrored-*), at immutable tags with imagePullPolicy: IfNotPresent. The whole set re-roots with one value.

Re-root to Your Registry​

  • kubernetes platform: RACORA_REGISTRY=<your-registry> on the installer, or --set global.systemDefaultRegistry=<your-registry> on helm upgrade.
  • k3s platform: set global.systemDefaultRegistry in the one HelmChartConfig (Override Chart Values).

Mirror the release's image list (images.txt in the repository at the release tag, or the air-gap archive, see offline) into that registry first. Every non-comment, non-blank line of images.txt is a full reference under Racora's registry namespace, so a copy per line re-roots it:

grep -Ev '^(#|$)' images.txt | while read -r img; do
crane copy "$img" "registry.example.com/racora/${img#registry.gitlab.com/cognitive-network-solutions/racora/}"
done

The charts set no imagePullSecrets. A registry that needs credentials is configured on the nodes: on k3s in /etc/rancher/k3s/registries.yaml (k3s private registry configuration), elsewhere in your container runtime's or kubelet's credential configuration.

Offline / Air-Gap Install (k3s Platform)​

Every release publishes the assets an offline install needs except the image archive, which is built on request and listed on the release page when it exists: a release whose page lists no racora-airgap-images.tar.zst cannot be installed offline. The fetcher, scripts/fetch-bundle.sh, lives in the repository, not in the installer package. On a connected machine, take it from the repository at the release tag, assemble the bundle, carry it over, and install from it:

git clone --branch vX.Y.Z --depth 1 https://gitlab.com/cognitive-network-solutions/racora.git
racora/scripts/fetch-bundle.sh vX.Y.Z ./bundle # k3s binary + checksum, chart, CRDs, installer, images archive, all verified
INSTALL_RACORA_ARTIFACT_PATH=$(pwd)/bundle sh ./bundle/installer/install-racora.sh # on the target host

fetch-bundle.sh stops with an explanation when the release has no archive. The images archive is staged into k3s's containerd on servers and workers (INSTALL_RACORA_MODE=node with the same INSTALL_RACORA_ARTIFACT_PATH). A bundle fetched with --no-images installs with INSTALL_RACORA_ARTIFACT_NO_IMAGES=1 and pulls images from a registry the cluster can reach.

A bundle is a directory with the release's k3s binary and sha256sum-amd64.txt, k3s-version.txt, racora-<version>.tgz, racora-crds.yaml, chart-values.yaml, racora-installer-<tag>.tar.gz unpacked to installer/, SHA256SUMS, and, unless fetched with --no-images, racora-airgap-images.tar.zst (or its .partNN pieces) with AIRGAP-SHA256SUMS. fetch-bundle.sh verifies every checksum; the installer verifies the k3s binary again before installing it. What a release publishes is on Release Process.

Grafana's ClickHouse datasource is a plugin the pod installs at start from grafana.com (GF_INSTALL_PLUGINS); the image archive does not carry it, so an installation with no internet egress has no datasource for the log dashboards.