您目前查看的是 Apigee Edge 說明文件。
前往 Apigee X 說明文件。 info
本文說明如何使用替代方法,升級 Apigee Edge Private Cloud 叢集中伺服器的作業系統 (OS)。這種逐一節點升級的方法可讓您就地升級 OS,一次升級一部機器/節點,不必設定全新的平行資料中心。
相容性
在逐一啟動節點的 OS 升級作業前,請先確認目前的 Apigee Edge for Private Cloud 版本支援目標 OS 版本。如要確認,請參閱作業系統相容性矩陣。
必要條件
開始逐一升級節點前,請確認已完成下列工作:
備份所有節點
建議您先完整備份所有節點 (例如 VM 層級備份和/或元件層級備份),再按照程序操作,確保安全無虞。 以防後續步驟無法正常運作。如要進一步瞭解元件層級備份,請參閱「備份及還原」。
確認 Edge 正在執行
使用下列指令,確保 Edge 在更新程序期間正常運作:
/opt/apigee/apigee-service/bin/apigee-all status節點更換順序
建議您按照元件類型,依下列順序升級節點:
其他情況
逐一升級節點的 OS 時,如果現有設定包含下列任一設定,請考慮採取這些額外步驟:
- apigee-mtls - 如果啟用 apigee-mtls,這個設定就不支援節點對節點的 OS 升級 (輪流)。如要升級,請按照「升級 apigee-mtls 指南」操作。
Cassandra
更換 Cassandra 時,請先更換非種子節點,再更換種子節點。
以下是 Cassandra 的特殊案例:
- Cassandra Native-mTLS - 如果啟用並強制執行 Native-mTLS,請設定
conf_cassandra_client_encryption_optional=true,移除已啟用 mTLS 節點的強制執行作業。詳情請參閱原生 mTLS 說明文件。 - 已啟用 Cassandra 節點間加密 - 請參閱「啟用 Cassandra 節點間加密」,確保新取代節點的信任儲存區包含現有 Cassandra 節點的憑證,反之亦然。
更換 Cassandra 節點的步驟如下:
- 拍攝虛擬機器快照 (如有可能) 來備份節點,並在所有節點上使用下列指令,為 Cassandra 進行 Apigee 備份:
apigee-service apigee-cassandra backup
- 取得搭載升級版 OS 的新節點。
- 套用特定作業系統的必要條件。
- 下載並執行 Edge 檔案,安裝 apigee-service 公用程式。使用中的 Apigee 版本啟動程序,執行啟動程序以取得 apigee-service,並安裝 apigee-setup。
- 列出種子節點:
apigee-service apigee-cassandra configure -search conf_cassandra_seeds
- 更新設定檔,方法是變更現有 Cassandra 節點的 IP,並換成新節點的 IP 位址。
現有 CASS_HOSTS
CASS_HOSTS="$IP1 $IP2 $IP3"
新版 CASS_HOSTS
CASS_HOSTS="$IP1 $IP4 $IP3"
- 使用更新後的 Cassandra 節點 IP 重新設定叢集中的現有節點 (要替換的節點除外)。請參閱設定檔參考資料。
/opt/apigee/apigee-setup/bin/setup.sh -p c -f updatedConfigFile - 停止並取消註冊舊節點上的 Cassandra:
- 在要更換的節點上停止 Cassandra:
apigee-service apigee-cassandra stop
- 列出要停用的 Cassandra 節點 UUID (如果是多個資料中心,請相應考量):
apigee-adminapi.sh servers list -r dc-1 -p central -t application-datastore --admin AdminEmailID --pwd 'AdminPassword' --host localhost
- 取消註冊與現有 Cassandra UUID 相關聯的資料儲存區類型:
curl -u AdminEmailID:'AdminPassword' -X POST http://MS_IP:8080/v1/servers -d "type=cache-datastore&type=user-settings-datastore&type=scheduler-datastore&type=audit-datastore&type=apimodel-datastore&type=application-datastore&type=edgenotification-datastore&type=identityzone-datastore&type=auth-datastore®ion=dc-1&pod=central&uuid=old_cassandra_uuid&action=remove"
- 刪除伺服器。
curl -u AdminEmailID:AdminPassword -X DELETE http://MS_IP:8080/v1/servers/old_cassandra_uuid
- 在要更換的節點上停止 Cassandra:
- 準備 apigee-cassandra 主機的新節點。在新的 Cassandra 節點上,於
/opt/apigee/customer/application/cassandra.properties下方的 cassandra.properties 檔案中新增下列這行 (如果沒有這個檔案,請建立):conf_jvm_options_custom_settings=-Dcassandra.replace_address=IPOfOldCassandraNode -Dcassandra.allow_unsafe_replace=true
- 確認 cassandra.properties 檔案中的擁有者和群組已設為
apigee:apigee。視需要使用下列指令更新擁有者和群組:chown apigee:apigee /opt/apigee/customer/application/cassandra.properties
- 在新增節點上安裝 Cassandra 並執行設定:
apigee-service apigee-cassandra install
apigee-service apigee-cassandra setup -f updatedConfigFile
- 設定新節點後,請移除新增至
/opt/apigee/customer/application/cassandra.properties的額外設定,然後重新啟動 apigee-cassandra:conf_jvm_options_custom_settings=-Dcassandra.replace_address=IPOfOldCassandraNode -Dcassandra.allow_unsafe_replace=true
apigee-service apigee-cassandra restart
- 檢查新更換節點的狀態:
apigee-service apigee-cassandra status
/opt/apigee/apigee-cassandra/bin/nodetool status - 重新建構新增至叢集的節點:
/opt/apigee/apigee-cassandra/bin/nodetool rebuild -dc dc-1 - 在設定檔中更新新的 Cassandra 節點 IP,重新設定 Router、Message-Processor、Qpid、Postgres 和 Management 伺服器的現有節點:
/opt/apigee/apigee-setup/bin/setup.sh -p r|mp|qs|ps|ms|mo -f updatedConfigFile - 從舊節點移除/解除安裝 Cassandra:
apigee-service apigee-cassandra uninstall
- 對叢集中的其他 Cassandra 節點重複執行上述步驟。
Zookeeper
請參閱下列步驟,更換 Zookeeper 節點。建議先更換追隨者節點,再更換領導者節點,確保集合維持法定人數。
- 備份節點,方法是建立虛擬機器快照 (如有可能),並在所有節點上備份 Zookeeper 的 Apigee。
- 停止並解除安裝現有節點上的 Zookeeper:
apigee-service apigee-zookeeper stop
apigee-service apigee-zookeeper uninstall
- 取得搭載升級版 OS 的新節點。
- 套用特定作業系統的必要條件。
- 下載所用 Apigee 版本的啟動程序,執行啟動程序以取得 apigee-service,並安裝 apigee-setup。
- 更新設定檔,移除過時/已刪除的節點 IP 位址,並替換為 Zookeeper 的新節點 IP。詳情請參閱設定檔參考資料:
現有 ZK 設定
ZK_HOSTS="$IP1 $IP2 $IP3" ZK_CLIENT_HOSTS="$IP1 $IP2 $IP3"
已更新 ZK 設定
ZK_HOSTS="$IP1 $IP4 $IP3" ZK_CLIENT_HOSTS="$IP1 $IP4 $IP3"
- 使用更新後的設定檔,在新節點上安裝、設定及啟動 Zookeeper:
/opt/apigee/apigee-setup/bin/setup.sh -p zk -f updatedConfigFile - 使用 updatedConfigFile 變更現有的 Zookeeper 節點:
/opt/apigee/apigee-setup/bin/setup.sh -p zk -f updatedConfigFile - 更新設定檔中的新 Zookeeper 節點 IP,重新設定現有的 Router、Message-Processor、Qpid、Postgres 和 Management 伺服器節點:
/opt/apigee/apigee-setup/bin/setup.sh -p r|mp|qs|ps|ms|mo -f updatedConfigFile - 針對所有 Zookeeper 節點重複上述步驟。
Postgres
本節將說明如何以零停機時間的方式升級 Postgres 節點,並完成所述步驟。後續小節會提供完成每個步驟的詳細說明。
- 將任何現有的待命節點換成目標作業系統。
- 將新的待命節點升級為主要節點。
- 停用舊主機。
- 繼續更換其他待機節點。
建議先停止 edge-qpid-server,再開始更換作業,盡量避免遺失任何可能的 Analytics 訊息。
apigee-service edge-qpid-server stop
待命中
- 取得 edge-postgres-server 節點的 UUID:
curl http://pg_standby_ip:8084/v1/servers/self
- 停止 Postgres:
apigee-service edge-postgres-server stop
apigee-service apigee-postgresql stop
- 按照這些步驟,從 Analytics 群組中移除現有的 Postgres 待命伺服器。
- 解除安裝 apigee-postgres 和 postgres-server:
apigee-service edge-postgres-server uninstall
apigee-service apigee-postgresql uninstall
- 取得搭載升級版 OS 的新節點。
- 套用特定作業系統的必要條件。
- 下載所用 Apigee 版本的啟動程序,執行啟動程序以取得 apigee-service,並安裝 apigee-setup。
- 在現有主要執行個體上設定主要/待命複寫,方法是使用 EXISTING_PG_MASTER_IP 和 NEW_PG_STANDBY_IP 更新設定檔。詳情請參閱設定檔參考資料:
PG_MASTER=EXISTING_PG_MASTER_IP
PG_STANDBY=NEW_PG_STANDBY_IP
apigee-service apigee-postgresql setup-replication-on-master -f updatedConfigFile
- 在新待命節點上,使用主要/待命設定安裝、設定及啟動 Postgres:
PG_MASTER=EXISTING_PG_MASTER_IP
PG_STANDBY=NEW_PG_STANDBY_IP
/opt/apigee/apigee-setup/bin/setup.sh -p ps -f updatedConfigFile - 驗證待命設定:
apigee-service apigee-postgresql postgres-check-standby
主要執行個體
- 取得現有 Postgres 主節點的 UUID:
curl http://pg_ip:8084/v1/servers/self
- 將升級後的新作業系統待命節點升級為主要節點。
- 停止現有主要執行個體上的 Postgres:
apigee-service apigee-postgresql stop
apigee-service edge-postgres-server stop
- 將新的待機節點升級為主要節點:
apigee-service apigee-postgresql promote-standby-to-master EXISTING_PG_MASTER_IP
- 從 Analytics 和消費者群組中移除舊的主節點。
- 將新主節點新增至 Analytics 和消費者群組。
- 如果使用營利功能,請更新新的 Postgres 主要節點,並按照下列步驟操作。
- 主要節點更換完畢後,即可使用更新後的主要節點設定啟動 edge-qpid-server:
apigee-service edge-qpid-server start
- 如果您使用營利功能,也請重新啟動管理伺服器和訊息處理器:
apigee-service edge-management-server restart
- 在舊版主機上停止並解除安裝 apigee-postgres 和 postgres-server:
apigee-service edge-postgres-server uninstall
apigee-service apigee-postgresql uninstall
新增備用裝置
- 取得搭載升級版 OS 的新節點。
- 套用特定作業系統的必要條件。
- 下載所用 Apigee 版本的啟動程序,執行啟動程序以取得 apigee-service,並安裝 apigee-setup。
- 使用新主要執行個體 IP 和新待命節點 IP,在新主要執行個體和新待命節點設定檔中設定主要執行個體/待命節點複製作業。詳情請參閱設定檔參考資料:
apigee-service apigee-postgresql setup-replication-on-master -f updatedConfigFile
- 在新待命節點上安裝及設定:
/opt/apigee/apigee-setup/bin/setup.sh -p ps -f updatedConfigFile - 按照設定主要待命裝置的步驟,將新的待命裝置新增至分析群組。
LDAP
更換 LDAP 節點時,管理伺服器必須停止運作,且在更換節點期間,任何管理 API 都會視為無法使用。
- 在所有節點上停止管理伺服器:
apigee-service edge-management-server stop
- 停用現有 LDAP 節點:
- 為 LDAP 節點建立 VM 層級的備份/快照。
- 停止 LDAP 前,請務必擷取 LDAP 資料的計數,以便稍後驗證,例如:
ldapsearch -o ldif-wrap=no -b "dc=apigee,dc=com" -D "cn=manager,dc=apigee,dc=com" -H ldap://:10389 -LLL -x -w Secret123 | wc -l
- 如要設定主動/被動轉送:
- 在被動節點上新增
mark_writable.ldif檔案,並加入以下內容,將目前的被動節點設為作用中:dn: olcDatabase={2}bdb,cn=config changetype: modify replace: olcReadOnly olcReadOnly: FALSE
- 在被動節點上執行下列指令,將其設為作用中:
ldapmodify -a -x -w "$APIGEE_LDAPPW" -D "$CONFIG_BIND_DN" -H "ldap://:10389" -f mark_writable.ldif
- 如果採用主動-主動架構,請繼續執行步驟 d),停用節點。
- 在被動節點上新增
- 在 Active-Active LDAP 設定中,中斷兩個 LDAP 節點之間的複製作業,然後更新設定。按照 LDAP 停用文件中列出的步驟操作。
- 停止並備份 LDAP 資料,然後解除安裝現有 LDAP 節點 (如果已完成主動-主動設定,請略過此步驟):
apigee-service apigee-openldap stop
apigee-service apigee-openldap backup
apigee-service apigee-openldap uninstall
- 取得搭載升級版 OS 的新節點。
- 套用特定作業系統的必要條件。
- 下載所用 Apigee 版本的啟動程序,執行啟動程序以取得 apigee-service,並安裝 apigee-setup。
- 設定新的 LDAP 節點:
- 根據設定更新新節點的 configFile,您可以參閱「Edge 設定檔參考資料」,根據僅限主動或主動/主動設定:
LDAP_TYPELDAP_PEERLDAP_SIDUSE_LDAP_REMOTE_HOST=y/n
- 使用 updatedConfigFile 在新節點上設定並啟動 LDAP:
/opt/apigee/apigee-setup/bin/setup.sh -p ld -f updatedConfigFile - 從舊節點備份 LDAP 資料 (如果可以略過主動-主動設定):
- 在新節點上進行備份範例,這樣系統就會產生預設備份資料夾/路徑:
apigee-service apigee-openldap backup
- 將備份資料從舊節點移至產生的備份資料夾。
- 還原資料前,請先停止 apigee-openldap:
apigee-service apigee-openldap stop
- 還原從舊節點建立的備份:
apigee-service apigee-openldap restore backup_file
例如:
apigee-service apigee-openldap restore 2026.02.09,10.28.20
- 在新節點上進行備份範例,這樣系統就會產生預設備份資料夾/路徑:
- 根據設定更新新節點的 configFile,您可以參閱「Edge 設定檔參考資料」,根據僅限主動或主動/主動設定:
- 針對其他 LDAP 節點重複執行上述步驟 (如果為作用中-作用中)。
- 使用更新的 LDAP 主機設定重新設定並啟動管理伺服器:
/opt/apigee/apigee-setup/bin/setup.sh -p mt -f updatedConfigFile - 重新設定並啟動單一登入 (SSO) (如適用):
apigee-service apigee-sso setup -f updatedConfigFile
apigee-service apigee-sso restart
- (選用) 按照說明文件中的步驟,將第二個 Active Directory 設定為唯讀。
Qpid
如要以升級的 OS 節點取代現有 Qpid 節點,請務必執行下列步驟:
- 停止接收訊息處理器傳送至現有節點佇列的任何訊息。
- 排除佇列中的現有訊息。
- 停止並停用現有節點。
停用現有節點。為確保郵件不會遺失,請採取下列額外措施:
- 停止 Qpid 代理程式:
apigee-service apigee-qpidd stop
- 封鎖所有訊息處理器從通訊埠 5672 傳入的流量:
iptables -A INPUT -p tcp --dport 5672 -s MP_IP -j DROP
- 再次啟動 Qpid 代理,排空現有訊息:
apigee-service apigee-qpidd start
- 開始停用前,請務必將佇列中的所有訊息排空至消費者。
- 取得 edge-qpid-server 節點的 UUID:
curl http://qpid_node_ip:8083/v1/servers/self
- 完成 Qpid 的停用或移除步驟,從 Analytics 移除 apigee-qpidd 和 edge-qpid-server。
- 停止並解除安裝 apigee-qpidd 和 edge-qpid-server:
apigee-service apigee-qpidd stop
apigee-service edge-qpid-server stop
apigee-service apigee-qpidd uninstall
apigee-service edge-qpid-server uninstall
新增節點:
- 取得搭載升級版 OS 的新節點。
- 套用特定作業系統的必要條件。
- 下載所用 Apigee 版本的啟動程序,執行啟動程序以取得 apigee-service,並安裝 apigee-setup。
- 在新節點上設定及執行 Qpid 服務,然後按照這些步驟將服務加入消費者群組。如要新增其他群組 (例如營利),請按照相同步驟操作。
- 如果已啟用營利服務,請重新啟動管理伺服器和訊息處理器:
apigee-service edge-management-server restart
apigee-service edge-message-processor restart
- 在所有 Qpid 節點上重複上述步驟。
Message-processor
- 取得 edge-message-processor 節點的 UUID:
curl http://mp_ip:8082/v1/servers/self
- 停用並解除安裝訊息處理器節點。
- 如果已啟用營利服務,請解除安裝 edge-mint-message-processor。
- 解除安裝訊息處理工具:
apigee-service edge-message-processor uninstall
- 取得搭載升級版 OS 的新節點。
- 套用特定作業系統的必要條件。
- 下載所用 Apigee 版本的啟動程序,執行啟動程序以取得 apigee-service,並安裝 apigee-setup。
- 按照這些步驟,將訊息處理器新增至叢集、完成設定並啟動。
- 如果啟用營利功能,請一併設定營利服務和訊息處理器。詳情請參閱以下說明文件。
路由器
- 取得 edge-router 節點的 UUID:
curl http://router_ip:8081/v1/servers/self
- 停用可連線性並驗證是否可連線:
iptables -A INPUT -i eth0 -p tcp --dport 15999 -j REJECT
curl -vvv -X GET http://router_ip:15999/v1/servers/self/reachable
- 停用並解除安裝路由器節點。
- 解除安裝路由器:
apigee-service edge-router uninstall
- 取得搭載升級版 OS 的新節點。
- 套用特定作業系統的必要條件。
- 下載所用 Apigee 版本的啟動程序,執行啟動程序以取得 apigee-service,並安裝 apigee-setup。
- 將路由器新增、設定及啟動至叢集。
管理伺服器
僅限單一管理伺服器
- 取得搭載升級版 OS 的新節點。
- 套用特定作業系統的必要條件。
- 下載所用 Apigee 版本的啟動程序,執行啟動程序以取得 apigee-service,並安裝 apigee-setup。
- 使用更新後的 IP 和設定檔新增管理伺服器 (請參閱這裡),然後執行設定指令:
/opt/apigee/apigee-setup/bin/setup.sh -p mt -f updatedConfigFile - 使用新的管理 IP 設定重新設定並重新啟動 UI。
/opt/apigee/apigee-setup/bin/setup.sh -p ui -f updatedConfigFile - 使用新的管理 IP 設定重新設定 SSO (如適用):
/opt/apigee/apigee-setup/bin/setup.sh -p sso -f updatedConfigFile - 使用新的管理 IP 設定重新設定新版 UI (UE) (如適用):
/opt/apigee/apigee-setup/bin/setup.sh -p ue -f updatedConfigFile - 如果已啟用營利功能:
- 重新設定營利 MS,並採用新的管理 IP 設定 (如適用),請參閱營利設定說明文件。
/opt/apigee/apigee-setup/bin/setup.sh -p mo -f updatedConfigFile - 重新啟動管理伺服器:
apigee-service edge-management-server restart
- 重新設定營利 MS,並採用新的管理 IP 設定 (如適用),請參閱營利設定說明文件。
- 按照這些步驟,在現有/舊節點上停用管理伺服器。
- 如果已啟用營利功能,請從 Analytics 群組中移除管理伺服器 UUID。範例:
curl -v -u AdminEmail:AdminPassword -X DELETE "http://localhost:8080/v1/analytics/groups/ax/mint_axgroup/servers?uuid=MS_UUID&type=consumer-server"
- 解除安裝營利管理伺服器:
apigee-service edge-mint-management-server uninstall
多個管理伺服器
- 使用現有節點上的另一個管理伺服器,按照這些步驟停用其中一個管理伺服器。
- 停止並解除安裝管理伺服器:
apigee-service edge-management-server stop
apigee-service edge-management-server uninstall
- 取得搭載升級版 OS 的新節點。
- 套用特定作業系統的必要條件。
- 下載所用 Apigee 版本的啟動程序,執行啟動程序以取得 apigee-service,並安裝 apigee-setup。
- 使用更新後的 IP 和設定檔新增管理伺服器 (請參閱這裡),然後執行設定指令:
/opt/apigee/apigee-setup/bin/setup.sh -p mt -f updatedConfigFile - 使用更新的管理 IP 設定重新設定並重新啟動 UI:
/opt/apigee/apigee-setup/bin/setup.sh -p ui -f updatedConfigFile - (僅在啟用 SSO 時) 使用更新的管理 IP 設定重新設定並重新啟動 SSO:
/opt/apigee/apigee-setup/bin/setup.sh -p sso -f updatedConfigFile - (僅適用於啟用新版 UI 的情況) 使用更新後的管理 IP 設定重新設定並重新啟動新版 UI:
/opt/apigee/apigee-setup/bin/setup.sh -p ue -f updatedConfigFile - 對其他管理伺服器重複上述步驟。
UI/UE
- 備份 UI 節點/建立 UI 節點的 VM 快照。
- 停止並解除安裝 UI:
apigee-service edge-ui stop
apigee-service edge-ui uninstall
- (僅限使用新版 UI) 停止並解除安裝新版 UI:
apigee-service edge-management-ui stop
apigee-service edge-management-ui uninstall
- 取得搭載升級版 OS 的新節點。
- 套用特定作業系統的必要條件。
- 下載所用 Apigee 版本的啟動程序,執行啟動程序以取得 apigee-service,並安裝 apigee-setup。
- 在新節點上設定及執行 edge-ui,並更新 IP 設定:
/opt/apigee/apigee-setup/bin/setup.sh -p ui -f updatedConfigFile - (僅在啟用 SSO 時) 視需要使用 UI 新節點 IP 設定,重新設定並執行 SSO:
/opt/apigee/apigee-setup/bin/setup.sh -p sso -f updatedConfigFile - (僅在啟用新版 UI 時) 在新節點上設定及執行新版 UI,並更新 IP 設定:
/opt/apigee/apigee-setup/bin/setup.sh -p ue -f updatedConfigFileapigee-service edge-management-ui configure-sso -f updatedConfigFile
apigee-service edge-ui configure-sso -f updatedConfigFile
SSO
- 備份 UI 節點/建立 UI 節點的 VM 快照。
- 停止並解除安裝單一登入 (SSO):
apigee-service apigee-sso stop
apigee-service apigee-sso uninstall
- 取得搭載升級版 OS 的新節點。
- 套用特定作業系統的必要條件。
- 下載所用 Apigee 版本的啟動程序,執行啟動程序以取得 apigee-service,並安裝 apigee-setup。
- 按照指南新增 SSO 的設定和金鑰,並考量新節點 IP。
- 設定及啟動單一登入:
/opt/apigee/apigee-setup/bin/setup.sh -p sso -f updatedConfigFile - 使用新的 SSO 節點 IP 更新設定,並重新設定 UI 的 SSO:
apigee-service edge-ui configure-sso -f updatedConfigFile
- (如果使用新版 UI) 在新版 UI 節點上執行 configure-sso,請參閱說明文件:
apigee-service edge-management-ui configure-sso -f updatedConfigFile
apigee-service edge-ui configure-sso -f updatedConfigFile