Changing FQDN (Fully Qualified Domain Name)#
Changing FQDN in Kubernetes setup
Note
janssen-config-cm in all examples refer to jans installation configuration parameters where janssen is the helm-release-name.
Warning
This feature is experimental and in alpha state, mostly used for development and testing.
Mandatory steps#
-
Create a file named
change-fqdn.yamlwith the following contents :apiVersion: batch/v1 kind: Job metadata: name: change-fqdn spec: template: metadata: annotations: sidecar.istio.io/inject: "false" spec: restartPolicy: Never containers: - name: change-fqdn image: ghcr.io/janssenproject/jans/cloudtools:replace-janssen-version-1 envFrom: - configMapRef: name: janssen-config-cm # This may be different in Helm args: ["change-fqdn", "new-demoexample.jans.io", "--old-fqdn", "demoexample.jans.io"]The
change-fqdncommand supports options (passed intoargs) to change the behavior of the running process:--old-fqdn: The old FQDN that need to changed (If omitted or empty, the value will be taken from existing configmaps).--dry-run: Simulate the process without persisting the changes (disabled by default).
-
Apply job:
kubectl apply -f change-fqdn.yaml -n <jans-namespace> -
Wait for the
job/change-fqdnbecome completed and no failure before proceeding to additional steps.
Additional steps#
Warning
Do not execute the following steps if dry-run mode is enabled.
-
Replace the certificate using
certmanager, see Certificate Management for further instructions. -
Modify the customized
values.yamland change all of the occurrences of old FQDN with the new one. -
Upgrade the setup, for example:
helm upgrade <helm-release-name> janssen-auth-server/janssen \ --version <helm-chart-version> \ -f values.yaml \ -n <jans-namespace>
Terraform users#
If the deployment is managed with the Janssen Terraform provider, the configuration and state still hold the old FQDN after change-fqdn runs. A later terraform apply sends the old values back (e.g. issuer and base_endpoint in jans_app_configuration, redirect_uris in jans_oidc_client) and undoes the change.
Warning
Do not run terraform apply between the change-fqdn job and the steps below.
-
Point the provider at the new FQDN, either
urlin theprovider "jans"block or theJANS_URLenvironment variable. -
Replace the old FQDN with the new one in all
.tfand.tfvarsfiles, for example:grep -rlF demoexample.jans.io --include='*.tf' --include='*.tfvars' . | xargs sed -i 's/demoexample\.jans\.io/new-demoexample.jans.io/g' -
Sync the state with the values already on the server:
terraform apply -refresh-only -
Run
terraform plan. It should report no changes. If it still shows the old FQDN, fix the configuration files, not the server.