Install the High Availability cluster

  • Ensure that you meet the system prerequisites. See High Availability system requirements.
  • Verify that all cluster nodes use the same approved NTP sources.
  • Verify that time synchronization is active on all cluster nodes.
  • Verify that node clocks differ by no more than 1 second.
  • Collect the IP address of each of the three cluster nodes.
  • Confirm that each cluster node has internet access.
  • Confirm entitlement information. See Runtime entitlements.
  • Decide on the administrator password that
    FactoryTalk® Optix™
    Studio uses to connect to the cluster. Set this password during installation, in the
    Credentials
    step. Store the password securely.
  • From Rockwell Automation Product Compatibility and Download Center (PCDC), download the FactoryTalk Optix High Availability Manager installer, the FactoryTalk Optix High Availability Package
    .tar.gz
    , the FactoryTalk Optix High Availability Package signature
    .tar.gz.sig
    , and the FactoryTalk Optix High Availability Package public key
    .pub
    . See Download Runtime Tools on the device.
    TIP: Always download the latest available packages from PCDC. Package version used must match the studio version number.
  • Reserve one extra free IP address for the VIP on the same network segment as the cluster nodes.
  1. To add a new cluster, run the High Availability Manager installer on the Windows workstation, launch the application, and select
    +New cluster
    .
    TIP:
    If you close the installer before selecting
    Install
    , you can save your progress and resume later, or discard the progress and start over.
  2. On the
    Get Started
    tab, select
    Browse
    , specify the path to the High Availability application
    .tar.gz
    file, accept the license agreement, and select
    Next
    .
    Make sure the FactoryTalk Optix High Availability Package signature
    .tar.gz.sig
    , and the FactoryTalk Optix High Availability Package public key
    .pub
    file are in the same folder. The manager automatically verifies the package signature when you select it, and displays a prompt if the verification succeeded or failed. You will not be able to continue until the correct files are provided.
  3. On the
    Cluster
    tab, enter the cluster information.
    IMPORTANT:
    Rockwell Automation
    is not responsible for any third-party software, including but not limited to its performance, security, updates, or compatibility with our products. Any use of third-party software is at your own risk, and we do not provide support, warranties, or guarantees for such software. Users should refer to the respective third-party providers for assistance and licensing terms.
    Cluster information fields
    Field
    Description
    Cluster name
    A unique name to identify the cluster.
    Kubernetes K3s version
    The K3s version that will be installed.
    Client access virtual IP
    The free IP address that you reserved for the Virtual IP.
    TIP: When you enter an IP address, validation runs automatically. The result shows whether the address is available, in use by another cluster, or invalid.
    Time zone
    The time zone that the cluster uses.
    IMPORTANT: Changing the time zone requires a restart of
    FactoryTalk Optix
    Runtime. A confirmation prompt displays.
  4. Select
    Next
    .
  5. On the
    Nodes
    tab, for each node, enter the node information.
    Node information fields
    Field
    Description
    Node name
    A display name, for example,
    Node 1
    . You can edit the default name.
    IP address
    The static IP address of the Ubuntu machine.
    Username
    The sudo-enabled SSH username on that node.
    Password (optional)
    The SSH password, if you use password authentication. Leave this field blank if the node uses SSH key authentication.
    TIP: If a node SSH host key is not verified, the
    Accept Host Keys
    dialog displays. Select each listed node, select
    Accept
    , and continue validation. If all nodes are already verified, this dialog does not display.
    If you set up SSH:
    • Store the keys in the default Windows SSH location.
    • Do not protect the keys by a passphrase.
    If High Availability Manager detects unsupported or non-compliant keys, it generates a new key pair for cluster provisioning.
  6. To validate connectivity, select
    Validate nodes
    .
    All three nodes must pass validation before you can continue.
  7. On the
    Credentials
    tab, enter the administrator password.
    Define a password that
    FactoryTalk Optix
    Studio will use to connect and download applications to the cluster.
    TIP: To change this password later, use the cluster management page in the
    FactoryTalk Optix
    High Availability Manager.
    IMPORTANT:
    Changing the administrator password requires a restart of
    FactoryTalk Optix
    Runtime. A confirmation prompt displays.
    Use a strong, unique password or passphrase for your account. A password of at least 16 characters is recommended, using a combination of words or characters that is difficult to guess. Avoid common words, predictable patterns, personal information, and passwords used for other accounts. Longer, unique passwords or passphrases provide better protection against password guessing and brute-force attacks.
  8. On the
    Ports
    tab, review the preconfigured ports, and change any settings as needed.
    Preconfigured ports
    Port name
    Default port
    Purpose
    Web presentation engine (http)
    80
    Web browser client connections over HTTP.
    IMPORTANT: The Web presentation engine port must match the
    WebPresentationEngine
    port configured in your
    FactoryTalk Optix
    project. If you change this port, update your project settings to match.
    Web presentation engine (https)
    443
    Web browser client connections over HTTPS.
    IMPORTANT: The Web presentation engine port must match the
    WebPresentationEngine
    port configured in your
    FactoryTalk Optix
    project. If you change this port, update your project settings to match.
    OPC UA server (opcua)
    59100
    OPC UA client connections.
    MQTT broker (mqtt)
    8883
    MQTT client connections.
    You can edit any preconfigured port, or add a port for another service. Select
    Add port
    . You can only delete ports that you add. You cannot delete preconfigured ports.
    IMPORTANT: Adding, editing, or deleting a port requires a restart of
    FactoryTalk Optix
    Runtime. A confirmation prompt displays.
    TIP: You can also add or change ports later, on an installed cluster by selecting the
    add/edit port
    button.
  9. To install the cluster, select
    Install
    .
    IMPORTANT: If you cancel during installation, the manager does not return the cluster to its original state. The cluster can remain partially installed.
    An installation progress dialog displays while the manager configures K3s and all High Availability services on all three nodes. This takes several minutes.
  10. To activate an entitlement, in the High Availability Manager select
    Manage Entitlements
    .
    The
    Manage Entitlements
    window displays the installed entitlements.
    TIP: To upgrade entitlements, you must use the Entitlement Manager.
  11. Under
    Activate a new entitlement
    , select
    Offline
    or
    Online
    , and select
    Next
    .
    • For an offline activation, select
      Offline
      .
      TIP: Go to the export step or the install step, depending on whether you need to generate a request or install an activated file.
    • For an online activation, select
      Online
      .
  12. If you selected
    Online
    :
    1. On the
      Enter Entitlement Keys
      tab, enter the base entitlement key and the extended entitlement key, if available.
      If you only have a base key, you can add an extended key later.
      IMPORTANT: Double-check that you entered the correct keys.
      The confirmation dialog warns that
      FactoryTalk Optix
      Runtime restarts.
    2. Select
      Activate
      .
    3. At the restart confirmation, select
      Save
      .
  13. If you selected
    Offline
    and need an activation request:
    1. On the
      Export or install
      tab, select
      Export an entitlement Activation Request to a file
      .
    2. On the next page, enter the entitlement key, select an export folder, and continue.
      The manager creates a
      .req
      file.
    3. Activate the
      .req
      file in Entitlement Manager on a device with internet access.
      Entitlement Manager creates an activated
      .ent
      file.
  14. If you selected
    Offline
    and already have an activated entitlement file:
    1. On the
      Export or install
      tab, select
      Install an already activated entitlement file
      .
    2. Browse to the activated
      .ent
      file, select
      Install
      , and at the restart confirmation select
      Save
      .
      TIP: A message confirms "Activated entitlement file. Verify in Entitlement Manager." If the file is invalid, an error message reports "Error importing entitlement file", and the manager does not delete the file.
      If the file is valid, the manager installs the entitlement, and deletes the file from disk.
  15. To rehost an entitlement, in
    Manage Entitlements
    select the entitlement, select
    Rehost
    , and select
    Yes
    .
    IMPORTANT: Rehosting restarts
    FactoryTalk Optix
    Runtime and removes the entitlement from this cluster.
    • If you activated the entitlement online, the manager releases the entitlement and removes it from the cluster immediately.
    • If you activated the entitlement offline, select an export folder when prompted. The manager generates a rehost request file there, and removes the entitlement from the
      Installed entitlements
      list. Complete the rehost in Entitlement Manager on a device with internet access.
  16. To export diagnostics, on the cluster dashboard select
    Export diagnostics
    .
    1. In the
      Select Export Folder
      dialog, select a destination folder.
    2. Select
      Select Folder
      .
      The manager collects diagnostics for all nodes in the cluster and saves the diagnostics to the selected folder.
Provide Feedback
Have questions or feedback about this documentation? Please submit your feedback here.
Normal