# SLE-Micro - RKE Cluster Build

**URL:** <https://forums.suse.com/t/sle-micro-rke-cluster-build/40759>\
**Category:** SLE Software Developer Kit (SDK)\
**Created:** [May 24, 2023, 12:47pm UTC](https://forums.suse.com/t/sle-micro-rke-cluster-build/40759 "2023-05-24T12:47:41Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![penguinpages](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/penguinpages/32/10214_2.png) [@penguinpages](https://forums.suse.com/u/penguinpages)\
**Post date:** [May 24, 2023, 12:47pm UTC](https://forums.suse.com/t/sle-micro-rke-cluster-build/40759/1 "2023-05-24T12:47:41Z")

</div>

Not sure where to post this or find correct user forum for SLE-Micro questions. So if this is in wrong category.. my apologies.

Goal: To Deploy RKE2 full NSPOF cluster , leaning into UBI based stack. Such as SLE-Micro.

Several things I am struggling with:

1. Base Packages for bastion host that would be needed for cluster ignition of supervisor cluster and admin / debug for Day2 operations:

Ex:

### 

transactional-update register -r 7blahE

transactional-update

transactional-update pkg install kubectl tmux git-core arp ### Broken Repo broken

transactional-update pkg install apparmor-parser

### 

1. How to install packages and update OS certification and setup services to start

Ex: Deploying front end IPLB in HA Active/Passive with nginx

## 

- Create directory: mkdir /etc/ssl/nginx/
- Move nginx-repo.key and nginx-repo.crt files to /etc/ssl/nginx/ directory
- Run cat /etc/ssl/nginx/nginx-repo.crt /etc/ssl/nginx/nginx-repo.key \> /etc/ssl/nginx/nginx-repo-bundle.crt
- Run “zypper install ca-certificates” or in case of SLE-Micro "transactional-update
- Run zypper addrepo -G -t yum -c ‘[https://pkgs.nginx.com/plus/sles/15?ssl\_clientcert=/etc/ssl/nginx/nginx-repo-bundle.crt&ssl\_verify=peer](https://pkgs.nginx.com/plus/sles/15?ssl_clientcert=/etc/ssl/nginx/nginx-repo-bundle.crt&ssl_verify=peer)’ nginx-plus
- If you have modsecurity subscription, run zypper addrepo -G -t yum -c ‘[https://pkgs.nginx.com/modsecurity/sles/15?ssl\_clientcert=/etc/ssl/nginx/nginx-repo-bundle.crt&ssl\_verify=peer](https://pkgs.nginx.com/modsecurity/sles/15?ssl_clientcert=/etc/ssl/nginx/nginx-repo-bundle.crt&ssl_verify=peer)’ nginx-modsecurity
- Run "zypper install nginx-plus nginx-ha-keepalived "to install nginx-plus package

## 

zypper commands wrapped in transactional-udpate fail.

I think this is just some fundamental set of steps to enable SLE-Micro to add SLES channels or run more traditional OS services commands that I am not seeing documentation on how to

---

<div class="post-metadata">

**Author:** ![malcolmlewis1](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/malcolmlewis1/32/10022_2.png) [@malcolmlewis1](https://forums.suse.com/u/malcolmlewis1)\
**Post date:** [May 24, 2023, 1:09pm UTC](https://forums.suse.com/t/sle-micro-rke-cluster-build/40759/2 "2023-05-24T13:09:43Z")

</div>

@penguinpages Hi, use combustion or ignition when bringing up the node and you can setup requirements prior to the system going read only. Once up use the likes of `transaction-update pkg install <some_package>`. Likewise for RKE installation, use `transactional-update shell` perform other steps (eg your `zypper command`), exit the shell and reboot to the new snapshot… Look at using the `-c` option to continue until happy…

I use combustion here with vagrant and bare-metal installs…
