Pre-upgrade preparation and checks on OpenShift
Prepare your API Connect deployment on OpenShift or Cloud Pak for Integration for upgrade.
This topic covers all the preparation steps you must complete before you can start the upgrade process.
Before following the steps in this topic, review the Planning your API Connect upgrade on OpenShift to ensure that you are following a supported upgrade path and that you understand important changes that might affect your deployment.
Run the Pre-upgrade health-checks during your upgrade planning stage to identify any problems as early as possible. Run the checks again just before upgrade to confirm API Connect is still ready for upgrade.
Obtaining upgrade files
- Obtain the API Connect files from IBM
Fix Central. From the IBM Fix Central site, download the following files:
- IBM® API Connect <version> for Containers
- Docker images for all API Connect subsystems. Filename is apiconnect-image-tool_<version>.
- IBM® API Connect <version> Operator Release Files for Containers
- Kubernetes operators and API Connect Custom Resource (CR) templates. Filename is apiconnect-operator-release-files_<version>.
- IBM API Connect <version> Security Signature Bundle File
- Signature files for verifying the integrity of your downloads.
Filename is signatures_<version>.
- IBM API Connect <version> Toolkit for <operating_system>
- Toolkit command-line utility. Packaged as a stand-alone file, or with API Designer:
- IBM API Connect <version> Toolkit for <operating_system>
- IBM API Connect <version> Toolkit Designer for <operating_system>
Not required during initial installation. After installation, you can download directly from the Cloud Manager UI and API Manager UI as explained in Installing the toolkit.
- Complete the steps in Verifying the integrity of IBM product files to verify that the downloaded product files are not corrupted.
- Extract the
IBM API Connect <version> Operator Release Files for Containersthat you downloaded in step 1.Create a directory called
helper_filesand extract the contents ofhelper_files.zipfrom the release_files.zip into thehelper_filesdirectory.
Pre-upgrade health-checks
- Verify that the API Connect operator and
subsystems are all running.
To verify the health of each subsystem, run the following commands:
Confirm that all pods areoc get ManagementCluster -n <management namespace> oc get GatewayCluster -n <gateway namespace> oc get PortalCluster -n <portal namespace> oc get FederatedAPIManagementCluster -n <namespace> oc get WmAPIGatewayCluster -n <namespace> oc get DevPortalCluster -n <namespace> oc get AnalyticsCluster -n <analyticsnamespace>READY, for example:oc get PortalCluster -n apic NAME READY STATUS VERSION RECONCILED VERSION AGE portal 3/3 Running 12.1.1.1 12.1.1.1-95 57m - Upgrading from V10.0.5.x: Verify that the management subsystem's
pgclusteris working correctly:- Get the name of the
pgcluster:oc get pgcluster -n <management namespace>The response displays the name of the postgres cluster that is running in the specified namespace.
- Check the status of the
pgcluster:oc get pgcluster <pgcluster_name> -n <APIC_namespace> -o yaml | grep status -A 2 | tail -n3A successful response looks like the following example, where the state isInitialized:status: message: Cluster has been initialized state: pgcluster InitializedImportant: If thepgclusterreturns any other state, then do not proceed with the upgrade.- If backup or restore jobs are running, wait until they complete and then check the status again.
Do not proceed with the upgrade until the status is
Initialized. - If all background jobs are complete but the
pgclusterdoes not returnstate: pgcluster Initialized, then contact IBM Support for assistance.
- If backup or restore jobs are running, wait until they complete and then check the status again.
Do not proceed with the upgrade until the status is
- Get the name of the
- Run the pre-upgrade health check:
- Verify that the
apicopsutility is installed and that you have the latest version by running the following command:apicops --versionFor more information about the
apicopsutility, see The API Connect operations tool: apicops. - Run the following command to set the KUBECONFIG environment variable.
export KUBECONFIG=</path/to/kubeconfig> - Run the apicops pre-upgrade check:
- If using the top-level CR, the check can be run against all subsystems with a single
command:
apicops system:pre-upgrade-check apiccluster -n <namespace> [--iscp4i]Note: Before upgrading, run the following command to check for encryption issues and invalid gateway extensions:For a full check (requires admin password to verify topology)
apicops preupgrade -n <namespace>To skip topology verification (no admin password needed)apicops preupgrade --no-topology -n <namespace> If using individual subsystem CRs:
Run the check separately for each subsystem:
- Management
subsystem:
apicops system:pre-upgrade-check management -n <namespace> [--iscp4i]Note: Before upgrading, run the following command to check for encryption issues and invalid gateway extensions:For a full check (requires admin password to verify topology)
apicops preupgrade -n <namespace>To skip topology verification (no admin password needed)apicops preupgrade --no-topology -n <namespace> - Portal subsystem:
apicops system:pre-upgrade-check portal -n namespaceIf your portal includes custom modules or custom themes, run a Drupal compatibility scan before you upgrade. Identifying compatibility issues early helps prevent upgrade failures. Choose one of the following options, depending on the level of validation that you need.
- Run a basic Drupal compatibility check for the portal subsystem:
apicops system:pre-upgrade-check portal -n namespace --drupal-scan-version <TARGET_DRUPAL_VERSION> - Run a comprehensive Drupal version compatibility scan and identifies potentially risky custom
code
patterns:
apicops portal:compat-check -n namespace --drupal-scan-version <TARGET_DRUPAL_VERSION>
Important: TheUse the Drupal core version that corresponds to your target API Connect version.--drupal-scan-versionflag is required. The Drupal compatibility scan runs only when you include this flag.Table 1. Drupal versions API ConnectVersion Drupal Version 10.0.5.3 - 10.0.8.2 10 10.0.8.3 and later 11 12.1.0.1 and later 11 - Run a basic Drupal compatibility check for the portal subsystem:
- Analytics
subsystem:
apicops system:pre-upgrade-check analytics -n namespace - For additional cluster types not covered by apicops, manually verify their status:
oc get FederatedAPIManagementCluster -n namespace oc get WmAPIGatewayCluster -n namespace oc get DevPortalCluster -n namespaceConfirm that all pods are
READYand the status isRunning.
If your API Connect installation is part of Cloud Pak for Integration, then include the argument
--iscp4iwhen you run the command.If your API Connect deployment is working correctly, the output shows no error messages.
If the pre-upgrade check returns any errors, then collect the output and open a support case.
- If using the top-level CR, the check can be run against all subsystems with a single
command:
Note: Cloud Pak for Integration: If you are upgrading API Connect in Cloud Pak for Integration and the pre-upgrade check indicates duplicate user accounts in the registry, resolve them now as explained in Resolving duplicate users before upgrade on Cloud Pak for Integration. - Verify that the
Additional pre-upgrade operations
Extra operations to review and complete before you start the upgrade.
- If analytics database backups are configured, or you want to enable them in future, then ensure that you have an extra Physical Volume available for the local backup storage. The default size is 150Gi. You can override the size during the upgrade procedure.
- If you used any microservice image overrides in any of your API Connect subsystem CRs, remove the image overrides before upgrade.
- If you are upgrading an air-gapped (disconnected from the internet) installation, configure the catalog sources for the target API Connect version on your bastion host or portable storage device:
- If your CMS Portal
includes custom themes or modules, the upgrade might fail. API Connect does not support
any upgrade issues caused by custom themes or modules as these issues are outside the scope of IBM
technical support. To avoid any upgrade issues, review the following considerations before upgrading
your API Connect deployment:
- Test the upgrade in a staging environment. Use the same set of custom modules and themes, and upgrade between the same versions planned for the production deployment to validate compatibility and functionality.
- Remove problematic custom modules or themes. You can re-apply the custom themes or modules after the upgrade, if needed.
- Take a portal backup.
- If there are any issues related custom modules or themes, contact the developer who added the modules and themes to the CMS Portal.
Backup your API Connect deployment
If upgrade fails, rollback is not possible. Before upgrade complete the disaster recovery preparation for all your subsystems.
For instructions on backing up and disaster recovery preparation, see Backing up, restoring, and disaster recovery.