Python script to help with migrating pods & containers between servers. Uses SSH for communication between source and destination server.
- Communication via SSH.
- Image transfer between hosts, no need to redownload them.
- Volume Migration.
- Pod migration with all connected containers.
- Container migration.
- ENV file migration.
- Secrets migration (file based).
- Network aware migration (cannot create custom networks yet).
Download the latest version into a suitable folder on your system and then to get the script running you need to do some configuration in your system as well in the script.
The script needs a Python venv for best compatibility.
On Debian / Ubuntu the package needed is called python3-venv and must be installed before continuing, for other systems adjust needed package and the commands below so that they work for you system.
Install package.
sudo apt install python3-venvThe venv should always be created in the home folder of the user running the script.
When you are logged in to the user that should run the script change directory to the home folder.
cd ~/Then run the following command, this will create a virtual environment just for this script.
python3 -m venv .venv/oMigrateWhen the venv is created you need to install the paramiko Python package.
To install it do the following.
source .venv/oMigrate/bin/activate
pip3 install wheel
pip3 install paramiko
deactivateNow the Python virtual environment is ready for use.
The script needs som configuration so that it can do the work, each option to configure is explained within the script.
The top row in the script should point to your venv that you created before, for example if run as root it should look something like this.
#!/root/.venv/oMigrate/bin/python3To run the script as an executable change the permission like this, make sure only the user running the script has permissions on it.
chmod 770 path/to/the/script/oMigrate.pyThe script can migrate secrets if they are put into a file during the migration or pre created
The file name must be the name of the secret that the container create command points to with .tmp as suffix and be placed into the path set in vLocalSecDir inside the script.
Example:
Secret is called: MySuperSecret
File would be named: MySuperSecret.tmp
Alternative you can pre create the secrets on the new server beforhand and thus eliminating storing secrets on file level, the script lets you continue if desired without the files existing locally.
The script has a couple of input parameters that is required every time the script is run.
The following command line parameter takes either pod or container as value, this decides where to start the migration path going forward.
--typeThe following command line parameter takes the name of the pod or container to migrate.
--nameThe following command line parameter tells the script to what server to migrate the pod or container to.
--dstThe following command line parameter sets the port for SSH connection.
--portThe following command line parameter point out the name of the key file if vSftpUseKeyFile is set to yes and vSftpKeyFilePath is set, if using username/password this can be omitted.
--keyfileWhen using the script for migration it is important that the path for env files and secret files is exactly the same on both servers or else it will not work.
Migrating a pod with SSH key:
./oMigrate --type "pod" --name "MyFantasticPod" --dst "newserver" --port "22" --keyfile "newserver.key"Migrating a pod with username & password, will present an interactive prompt for SSH login:
./oMigrate --type "pod" --name "MyFantasticPod" --dst "newserver" --port "22"Migrating a container with a SSH key:
./oMigrate --type "container" --name "MySingleContainer" --dst "newserver" --port "22" --keyfile "newserver.key"Migrating a container with username & password, will present an interactive prompt for SSH login:
./oMigrate --type "container" --name "MySingleContainer" --dst "newserver" --port "22"The main security consideration is how the permissions is set on the script, always try to set as permissive as possible and use SSH keys if possible.
My homepage: Link