Updating the Control Plane certificates in Cloudera Data Engineering
Learn about how to update the Control Plane certificates in Cloudera Data Engineering when you renew certificates on CDP Private Cloud Data Services.
-
Download
cde-utils.sh
to your local machine. -
Create a directory to store the files, and change to that directory:
mkdir -p /tmp/cde-utils && cd /tmp/cde-utils
-
Copy the script
Embedded Container Service (ECS)
Copy the extracted utility script (
cde-utils.sh
) to the Embedded Container Service (ECS) cluster host which has the ECS Master installed. To identify the ECS cluster hosts:- Log in to the Cloudera Manager web interface.
- Click Clusters tab.
- Click the relevant ECS cluster from the list of the clusters displayed.
- Under Status, click Hosts link.
- Select the master host from the list and copy the script to that host.
Red Hat OpenShift Container Platform (OCP)
Copy the extracted utility script (
cde-utils.sh
) and the OpenShiftkubeconfig
file to one of the HDFS service gateway hosts, and install thekubectl
utility:- Log in to the Cloudera Manager web interface.
- Go to Clusters > Base Cluster > HDFS > Instances.
- Select one of the Gateway hosts, log in using the security password that was set, and copy the script to that host.
- Copy the OCP kubeconfig file to the same host.
- Export the OCP kubeconfig
file:
export KUBECONFIG=[***path_of_the_copied_OCP_Kubeconfig_file***]
- On that host, install the
kubectl
utility following the instructions in the Kubernetes documentation. Cloudera recommends installing the version that matches the Kubernetes version installed on the OpenShift cluster.
-
On the cluster host that you copied the script to, set the script permissions to be
executable:
chmod +x /path/to/cde-utils.sh
-
Identify the virtual cluster endpoint:
- In the Cloudera Manager web UI, go to the Data Services page, and then click Open CDP Private Cloud Data Services.
- Click the Data Engineering tile.
- Select the CDE service containing the virtual cluster you want to activate.
- Click Cluster Details.
- Click JOBS API URL to copy the URL to your clipboard.
- Paste the URL into a text editor to identify the endpoint host. For example, the URL
is similar to the
following:
http://dfdj6kgx.cde-2cdxw5x5.apps.ecs-demo.example.com/dex/api/v1
The endpoint host is
dfdj6kgx.cde-2cdxw5x5.apps.ecs-demo.example.com
.
-
Run the following command to update the Control Plane certificates:
./cde-utils.sh update-control-plane-certificates -h [***ENDPOINT HOST***] -n [***CONTROL PLANE NAMESPACE***]
For example,./cde-utils.sh update-control-plane-certificates -h dfdfgkm4.cde-rqjsj7w4.apps.apps.shared-rke-dev-01.kcloud.cloudera.com -n cdp