Upgrade Calico on OpenShift 4
About upgrading Calico
Before you start, review the upgrade notes for changes in each release that need your attention.
This page covers upgrading to v3.33 from the two previous Calico releases.
It applies to an existing Calico cluster on OpenShift 4.
Upgrading Calico on OpenShift 4
Apply the updated manifests.
oc apply --server-side --force-conflicts -f https://raw.githubusercontent.com/projectcalico/calico/v3.33.0/manifests/tigera-operator-ocp-upgrade.yaml
Optional: To enable the flow logs API and Calico Whisker (introduced in version 3.30), apply the Goldmane and Whisker custom resources.
kubectl apply -f - <<EOF
apiVersion: operator.tigera.io/v1
kind: Goldmane
metadata:
name: default
---
apiVersion: operator.tigera.io/v1
kind: Whisker
metadata:
name: default
EOF
You can now monitor the upgrade progress with the following command:
watch oc get tigerastatus
Migrating to auto host endpoints
In order to migrate existing all-interfaces host endpoints to Calico-managed auto host endpoints:
Add any labels on existing all-interfaces host endpoints to their corresponding OpenShift nodes. Calico manages labels on automatic host endpoints by syncing labels from their nodes. Any labels on existing all-interfaces host endpoints should be added to their respective nodes. For example, if your existing all-interface host endpoint for node node1 has the label environment: dev, then you must add that same label to its node:
oc label node node1 environment=devEnable auto host endpoints by following the enable automatic host endpoints how-to guide. Note that automatic host endpoints are created with a profile attached that allows all traffic in the absence of network policy.
calicoctl patch kubecontrollersconfiguration default --patch ={"spec": {"controllers": {"node": {"hostEndpoint": {"autoCreate": "Enabled"}}}}}Delete old all-interfaces host endpoints. You can distinguish host endpoints managed by Calico from others in several ways. First, automatic host endpoints have the label projectcalico.org/created-by: calico-kube-controllers. Secondly, automatic host endpoints' name have the suffix -auto-hep.
calicoctl delete hostendpoint <old_hostendpoint_name>