Preparing an air gap environment

If your cluster is not connected to the internet, you can install Cloud Pak for Business Automation in an air gap environment. Use either a bastion host, a portable compute device, or a compute device with the aid of a portable storage device to transfer the images to your air gap environment.

About this task

The following progress bar shows you where you are in the installation process. You can click the completed parts in the diagram to go back and check that you did everything that you needed to do.

Progress bar = prepare Planning for a production deployment
Important: When you install an air gap, you do not need to complete the instructions in Preparing for a production deployment. However, you do need to download the cert-kubernetes repository to get access to the scripts and custom resource templates that are needed when you create a Cloud Pak for Business Automation instance. For more information, see Preparing a client to connect to the cluster.

It is common in production to have a cluster that cannot access the internet. In these cases, you can still install Cloud Pak for Business Automation and OpenShift Container Platform (OCP) in an air-gapped (otherwise known as offline or disconnected) environment. An air-gapped installation uses the IBM operator catalog to mimic a typical online installation except that the Cloud Pak images are in your own registry. You can use a bastion host or a compute device (like a laptop), with or without portable storage (like an external hard disk drive) to transfer the images to an air-gapped network.

All of these scenarios use Container Application Software for Enterprises (CASE) files to mirror content from a source to a target. CASE is a specification that defines metadata and structure for packaging, managing, and unpacking containerized applications.

The following diagram provides an overview of the air-gapped installation options.

Air gap scenarios

You can install multiple Cloud Pak for Business Automation production deployments on the same cluster. When you have multiple deployments on a cluster, the Cloud Pak foundational services are shared between them. The user repositories are also shared in the common Identity and Access Management (IAM) service. If you use multiple LDAPs with IAM, you must make sure that the usernames are unique across them. Your Cloud Pak for Business Automation deployments can either use the same LDAP or make sure that your users are unique. For more information, see Configuring LDAP connection.